TE
TechEcho
Home24h TopNewestBestAskShowJobs
GitHubTwitter
Home

TechEcho

A tech news platform built with Next.js, providing global tech news and discussions.

GitHubTwitter

Home

HomeNewestBestAskShowJobs

Resources

HackerNews APIOriginal HackerNewsNext.js

© 2025 TechEcho. All rights reserved.

iPhone Mirroring at work may expose employees’ personal information

58 pointsby jjguy7 months ago

11 comments

dml21357 months ago
Don’t you need to be signed in to the same iCloud account on both your laptop and phone to use this feature? That would mean that in order to encounter this issue you already need to be using a work account on a personal device, or vice versa.<p>Since that’t the case I fail to see how this is a large vulnerability. The article doesn’t seem to address this point (possible I just missed this).
评论 #41777769 未加载
评论 #41777782 未加载
评论 #41778989 未加载
评论 #41780447 未加载
评论 #41777721 未加载
sigio7 months ago
Duh, don&#x27;t mix work and private devices &#x2F; data
评论 #41777723 未加载
评论 #41777755 未加载
mustyoshi7 months ago
The PSA should just be don&#x27;t mix your personal and work devices.
评论 #41778108 未加载
notinmykernel7 months ago
FYI: Amazon has been doing this to all employees who download any work related apps, since at least 2020.
deckar017 months ago
There also seems to be a bug in the VPN that requires sending all traffic when the VPN address is on a different subnet. It should be possible to manually specify subnet mask, but it seems to be ignored. I’m not sure if the VPN is advertising this incorrectly, but it worked fine before upgrading.
Havoc7 months ago
Two phones all the way. For most knowledge workers the cost of an mid tier iPhone is inconsequential anyway
dcchambers7 months ago
I miss out on a lot of nice MacOS features because I refuse to sign into my personal iCloud account on my work mac, even though we are allowed to do so.<p>Oh well. Gotta draw the line somewhere I guess.
likeabatterycar7 months ago
So the threshold of concern by a &quot;security&quot; company is &quot;they might audit your apps and find out you&#x27;re gay!&quot;<p>Yet not a single concern about tethering an iPhone (with an external connection) to a PC on the company&#x27;s internal network, bypassing all firewalls, proxies, and other protections. That is grounds for immediate dismissal at some places.<p>I expect security people to think more like network engineers and less like teenagers gossiping in the canteen.
评论 #41778180 未加载
评论 #41778149 未加载
评论 #41849864 未加载
评论 #41778212 未加载
lxgr7 months ago
Speaking of iPhone Mirroring: Doesn&#x27;t this effectively downgrade two-factor authentication to a single factor for flows like &quot;tap &#x27;yes&#x27; on your phone to login&quot;?<p>I&#x27;ve been wondering if there is a way for iOS authenticator apps to opt out of mirroring, but haven&#x27;t found anything so far.
评论 #41778365 未加载
seneca7 months ago
It&#x27;s incredible to me how many people log into personal account on work devices. People should really research the amount of data security tools harvest.
评论 #41777728 未加载
评论 #41777603 未加载
评论 #41777574 未加载
评论 #41779600 未加载
评论 #41778201 未加载
ein0p7 months ago
Anyone who uses their personal iPhone and&#x2F;or iCloud account for work is a moron.