Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

The downside is that smartphones are pretty terrible in terms of security. Lose your smartphone and you give away the keys to everything. Given how easily phones are stolen, that's a pretty bad single point of failure. With my laptop, I can use a password manager together with full-disk encryption with a decent password. That beats this suggestion hands-down.


A smartphone isn't any less secure than a laptop... I could say "lost your laptop and you give away the keys to everything" just as you said the same for smartphone... It's up to the user to decide what security they put on their devices. On iPhone at least, everything is really well encrypted out of the box. Most people don't put passwords on their laptops either.


Most people don't put passwords on their laptops either.

I don't know about most. Certainly many people do, and it's fairly convenient to have one.

On the other hand, the input capabilities of smartphones are so limited that I find it hard to imagine finding anybody - even otherwise computer-savvy people - whose smartphone data is encrypted using a reasonably secure keyphrase.


Smartphones are arguable exposed to theft risk in more scenarios than laptops are, and the security on a smartphone is generally weaker than on a laptop (at least one with whole-disk encryption).


I agree with the first part, but I've been pretty impressed by the security used and developed in iOS: http://www.apple.com/ipad/business/docs/iOS_Security_Feb14.p...

At the end of the day, as you said, phones are easier lost and stolen, but there is barely a difference now in the functionality of security between a phone, laptop, and desktop; they're all the same. Now, for convenience, many users don't bother having a password on their phone. That's not functionality though, that's just how a user has decided to protect their phone's content...


Why not have a two factor auth? Then loss of a smartphone won't be a big deal.

Or three factors: biometric / password on phone, show OTP to site, then enter some password in site




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: