Live data from Hacker News

There are no secure smartphones

devever.net

101–110 of 124 posts

Re: There are no secure smartphones

#101
post #7
post #3

The folks at http://neo900.org/ are well aware of this and that phone is designed accordingly (details at http://neo900.org/faq#privacy ). Hype-driven products like BlackPhone misrepresent their devices as being perfectly secure when this significant attack vector is completely unmitigated. On the Neo900, the modem is connected via USB (bus; there is no physical connector) which means it doesn't have DMA. There is no…

I have kind of confusion, your rant about people on HN not understanding that "re-programmable computers that, at a low level, run the code you ask them to" and the fact that no one has a complete ownership of all the parts inside that phone or any other option makes difficult to sustain an option as secure, because those options would comprise several different cpus. The closest way I can see to get something to be…

Yes, security is hard.

I like RockChip ChromeBooks, with no microcode and libreboot support. You can buy them brand new, unlike x200.

Re: There are no secure smartphones

#102
post #78
post #58

Earlier quoted context omitted.

I don't think you should trust the baseband. My objection is with the idea that you can look at a design, not see an IOMMU, and extrapolate from that the notion that the baseband has full access to the memory of the other chips in the design. That's a reasonable assumption in a PC design. There may have been a point, for some phones, where it was a valid assumption for phones. It's not with a modern phone design.

In my research on phones from the Unrevoked project (admittedly, 4+ years ago), this was the case: the baseband and the CPU shared the same memory. The baseband memory was carved out from the CPU such that the CPU could not access it, but the microcontrollers serving the baseband had CPU access, as I recall from the Qualcomm boot documentation: the chain of trust from CPU boot was established by the baseband processo…

The baseband doesn't have full control over phone systems.

Re: There are no secure smartphones

#104
post #92

Earlier quoted context omitted.

A LOT. But on the other side of the fence. LEO are paying like mad for secure communication solutions. And breaking into others.

* ethics not included

Good money are extremely good at tuning your ethics compass.

Re: There are no secure smartphones

#105
post #3

The folks at http://neo900.org/ are well aware of this and that phone is designed accordingly (details at http://neo900.org/faq#privacy ). Hype-driven products like BlackPhone misrepresent their devices as being perfectly secure when this significant attack vector is completely unmitigated. On the Neo900, the modem is connected via USB (bus; there is no physical connector) which means it doesn't have DMA. There is no…

There is also https://www.freecalypso.org/ which aims to produce libre firmware for the TI Calypso baseband chipset.

Their mailing list is fairly active.

Re: There are no secure smartphones

#106
post #3

The folks at http://neo900.org/ are well aware of this and that phone is designed accordingly (details at http://neo900.org/faq#privacy ). Hype-driven products like BlackPhone misrepresent their devices as being perfectly secure when this significant attack vector is completely unmitigated. On the Neo900, the modem is connected via USB (bus; there is no physical connector) which means it doesn't have DMA. There is no…

The only problem with the Neo 900 is it's in the ballpark of $1000 and production is very limited because it relies on rare parts.

Re: There are no secure smartphones

#107
post #97

Earlier quoted context omitted.

Well any RF equipment that you either modified or built yourself is per default illegal to use. You can buy a bluetooth-stack-on-a-chip and talk to it with your Arduino but once you sell that as a product you'll still require FCC certification. But the FCC isn't overly concerned if you're doing WiFi or Bluetooth, their area are the broad analog strokes, correct bandwidth and correct power. As such, if you use somethi…

Well, that's actually a problem: if you are forced to use something like OsmocomBB, law enforcement will be more than glad to see they have a new reason to have you in jail.

I'm not convinced that you're average beat cop is looking for OsmocomBB on your phone in order to trump up a reason to nab you. The tried and true method of following you for a couple blocks and interpreting traffic laws strictly is sufficient and requires much less knowledge and work.

Re: There are no secure smartphones

#108

The article asserts: > It would, in my view, be abject insanity not to > assume that half a dozen or more nation-states (or > their associated contractors) have code execution > exploits against popular basebands in stock. To me this ignores the flip-side of the argument. If US intelligence services really thought the Chinese and Russians could remotely and invisibly hack all/most smartphones then no-one with access…

Following your logic, then any other sovereign non-US states must forbid their their citizens and companies to use US technology in order to avoid US stealing the data. At least they should forbid it to those organisations and citizens who as you say access sensitive information.

Still, even after Snowden, the whole world uses Microsoft, Apple, Intel, Google technology everyday.

This is not a prove that your logic is wrong, but I am wondering how much today's intelligence services are interested in protecting their own companies and citizens from data breaches. It might be that they are more interested into stealing as much data as possible themselves in order to be able to negotiate with foreign states/services.

Re: There are no secure smartphones

#110
post #70

Or you can just use WIFI and turn the baseband off like I do. The cell companies are all crooks anyways (in the US), and I don't want to do business with them.

Problem is, when you use VoIP over WiFi, you loose echo-cancellation, because the echo cancel hardware resides in the baseband and is not used in WiFi calls.

Just use a headset that supports echo cancellation in hardware?
Post reply on HN