{"id":36819,"date":"2022-08-22T16:52:40","date_gmt":"2022-08-22T20:52:40","guid":{"rendered":"https:\/\/mjtsai.com\/blog\/?p=36819"},"modified":"2022-08-29T11:53:33","modified_gmt":"2022-08-29T15:53:33","slug":"too-secure","status":"publish","type":"post","link":"https:\/\/mjtsai.com\/blog\/2022\/08\/22\/too-secure\/","title":{"rendered":"Too Secure"},"content":{"rendered":"<p><a href=\"https:\/\/www.manton.org\/2022\/08\/22\/i-continue-to.html\">Manton Reece<\/a>:<\/p>\n<blockquote cite=\"https:\/\/www.manton.org\/2022\/08\/22\/i-continue-to.html\"><p>I continue to think that my devices are now too secure. Face ID shouldn&rsquo;t freak out multiple times a day, requiring a pin. Safari shouldn&rsquo;t scrap cookies every week, requiring needless extra web sign-ins. Any security beyond unlocking my Mac is usually unnecessary friction.<\/p><\/blockquote>\n\n<p>I think there&rsquo;s something to this. There is often a tradeoff between security and convenience, so it&rsquo;s important to find the right balance and to limit the annoying stuff to where it actually helps a lot.<\/p>\n\n<p>Face ID requires my passcode multiple times per day, which tempts me to choose one that&rsquo;s less secure. Safari is more annoying than other browsers because the &ldquo;Remember me&rdquo; checkbox on so many sites doesn&rsquo;t work. Apple&rsquo;s sites seemingly <em>always<\/em> require logging in. My old iMessages are nearly impossible to access, and cannot be directly downloaded, ostensibly because they are end-to-end encrypted. Yet, in practice, that&rsquo;s a mirage, so it feels like Apple has more access to them than I do. Transparency Consent and Control (TCC) seemed like a reasonable idea but remains failure-prone and confusing&mdash;as if the thinking was that making it smoother would be less secure. And, of course, the App Store provides&mdash;at great cost&mdash;arguably much more the appearance of security than actual security.<\/p>\n\n<p>Previously:<\/p>\n<ul>\n<li><a href=\"https:\/\/mjtsai.com\/blog\/2022\/08\/04\/imessage-and-the-secret-service\/\">iMessage and the Secret Service<\/a><\/li>\n<li><a href=\"https:\/\/mjtsai.com\/blog\/2022\/05\/16\/apple-platform-security-guide-may-2022\/\">Apple Platform Security Guide (May 2022)<\/a><\/li>\n<li><a href=\"https:\/\/mjtsai.com\/blog\/2022\/04\/29\/apple-watch-late-adopter\/\">Apple Watch Late Adopter<\/a><\/li>\n<li><a href=\"https:\/\/mjtsai.com\/blog\/2022\/03\/15\/ios-15-4-and-ipados-15-4\/\">iOS 15.4 and iPadOS 15.4<\/a><\/li>\n<li><a href=\"https:\/\/mjtsai.com\/blog\/2022\/02\/12\/the-time-to-fix-web-security-bugs\/\">The Time to Fix Web Security Bugs<\/a><\/li>\n<li><a href=\"https:\/\/mjtsai.com\/blog\/2022\/01\/27\/ios-15-4-and-ipados-15-4-beta\/\">iOS 15.4 and iPadOS 15.4 Beta<\/a><\/li>\n<li><a href=\"https:\/\/mjtsai.com\/blog\/2021\/07\/27\/safari-frustrations\/\">Safari Frustrations<\/a><\/li>\n<li><a href=\"https:\/\/mjtsai.com\/blog\/2021\/02\/02\/ios-14-5-unlock-an-iphone-while-wearing-a-mask\/\">iOS 14.5: Unlock an iPhone While Wearing a Mask<\/a><\/li>\n<li><a href=\"https:\/\/mjtsai.com\/blog\/2021\/01\/14\/reminder-imessage-not-meaningfully-e2e\/\">Reminder: iMessage Not Meaningfully E2E<\/a><\/li>\n<li><a href=\"https:\/\/mjtsai.com\/blog\/2019\/07\/23\/annoying-catalina-security-features\/\">Annoying Catalina Security Features<\/a><\/li>\n<li><a href=\"https:\/\/mjtsai.com\/blog\/2019\/02\/05\/mojave-privacy-protection-aftermath\/\">Mojave Privacy Protection Aftermath<\/a><\/li>\n<li><a href=\"https:\/\/mjtsai.com\/blog\/2018\/05\/07\/requesting-your-personal-data-from-apple\/\">Requesting Your Personal Data From Apple<\/a><\/li>\n<\/ul>\n\n<p id=\"too-secure-update-2022-08-29\">Update (2022-08-29): <a href=\"https:\/\/pxlnv.com\/linklog\/device-security-disconnect\/\">Nick Heer<\/a>:<\/p>\n<blockquote cite=\"https:\/\/pxlnv.com\/linklog\/device-security-disconnect\/\">\n<p>I agree with Reece&rsquo;s diagnosis of the problem, but not its cause. If someone is logged into a user account on a Mac, everything in the keychain is probably unlocked and available to them as well. And if they have text message forwarding enabled on their iPhone, an SMS-based two-factor code will appear in Message. Despite what is basically security theatre, I need to reauthenticate several times weekly on websites and in applications I use all the time.<\/p>\n<\/blockquote>","protected":false},"excerpt":{"rendered":"<p>Manton Reece: I continue to think that my devices are now too secure. Face ID shouldn&rsquo;t freak out multiple times a day, requiring a pin. Safari shouldn&rsquo;t scrap cookies every week, requiring needless extra web sign-ins. Any security beyond unlocking my Mac is usually unnecessary friction. I think there&rsquo;s something to this. There is often [&hellip;]<\/p>\n","protected":false},"author":1,"featured_media":0,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"apple_news_api_created_at":"2022-08-22T20:52:49Z","apple_news_api_id":"f38e0646-96ae-4d15-979f-52b9662b8f0d","apple_news_api_modified_at":"2022-08-29T15:53:36Z","apple_news_api_revision":"AAAAAAAAAAAAAAAAAAAAAA==","apple_news_api_share_url":"https:\/\/apple.news\/A844GRpauTRWXn1K5ZiuPDQ","apple_news_coverimage":0,"apple_news_coverimage_caption":"","apple_news_is_hidden":false,"apple_news_is_paid":false,"apple_news_is_preview":false,"apple_news_is_sponsored":false,"apple_news_maturity_rating":"","apple_news_metadata":"\"\"","apple_news_pullquote":"","apple_news_pullquote_position":"","apple_news_slug":"","apple_news_sections":"\"\"","apple_news_suppress_video_url":false,"apple_news_use_image_component":false,"footnotes":""},"categories":[2],"tags":[1572,140,31,2078,30,2077,2237,355,103,48,1960,96],"class_list":["post-36819","post","type-post","status-publish","format-standard","hentry","category-technology","tag-face-id","tag-imessage","tag-ios","tag-ios-15","tag-mac","tag-macos-12","tag-messages-in-icloud","tag-privacy","tag-safari","tag-security","tag-transparency-consent-and-control-tcc","tag-web"],"apple_news_notices":[],"_links":{"self":[{"href":"https:\/\/mjtsai.com\/blog\/wp-json\/wp\/v2\/posts\/36819","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/mjtsai.com\/blog\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/mjtsai.com\/blog\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/mjtsai.com\/blog\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/mjtsai.com\/blog\/wp-json\/wp\/v2\/comments?post=36819"}],"version-history":[{"count":2,"href":"https:\/\/mjtsai.com\/blog\/wp-json\/wp\/v2\/posts\/36819\/revisions"}],"predecessor-version":[{"id":36879,"href":"https:\/\/mjtsai.com\/blog\/wp-json\/wp\/v2\/posts\/36819\/revisions\/36879"}],"wp:attachment":[{"href":"https:\/\/mjtsai.com\/blog\/wp-json\/wp\/v2\/media?parent=36819"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/mjtsai.com\/blog\/wp-json\/wp\/v2\/categories?post=36819"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/mjtsai.com\/blog\/wp-json\/wp\/v2\/tags?post=36819"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}