Earlier quoted context omitted.
Not too sure about this. Keep in mind that in most commercially sold Android phones, closed source, self updating, Google Play Services is installed by the manufacturer with system level privileges. That alone is enough to create a non insignificant back door.
Or, said differently, Play Services are already a backdoor. They can (and do) install updates or other software pushed by server automatically, without you being able to do anything about it. And they have access to anything on the phone.
A Message to Our Customers
251–260 of 1001 posts
Re: A Message to Our Customers
#252Earlier quoted context omitted.
Not all of CyanogenMod is free software (you still have a bunch of binary blobs, and everyone has to use Google Play Services anyway because every app seems to implicitly require it). Replicant would be a much better alternative if it actually supported anything newer than 2G.
> and everyone has to use Google Play Services anyway This isn't true. You can stick to app repositories like F-Droid and use Raccoon to download Play Store apps via your desktop without using a Google account on your phone.
Re: A Message to Our Customers
#253Earlier quoted context omitted.
Nobody builds their Android from source. Nobody uses Cyanogenmod. And nobody runs Android on a phone where the entire stack is open source and blob free. Anyone who does is a rounding error.
> And nobody runs Android on a phone where the entire stack is open source and blob free. > Anyone who does is a rounding error. I'm actually curious if there is literally anyone who uses no proprietary software, including the radios and the SoC, on their Android device. My bet is that there's not even a single device out there for which this is possible. (If there is, I'd love to see it.)
Re: A Message to Our Customers
#254Earlier quoted context omitted.
Nobody builds their Android from source. Nobody uses Cyanogenmod. And nobody runs Android on a phone where the entire stack is open source and blob free. Anyone who does is a rounding error.
> And nobody runs Android on a phone where the entire stack is open source and blob free. > Anyone who does is a rounding error. I'm actually curious if there is literally anyone who uses no proprietary software, including the radios and the SoC, on their Android device. My bet is that there's not even a single device out there for which this is possible. (If there is, I'd love to see it.)
Re: A Message to Our Customers
#255Earlier quoted context omitted.
Nobody builds their Android from source. Nobody uses Cyanogenmod. And nobody runs Android on a phone where the entire stack is open source and blob free. Anyone who does is a rounding error.
> And nobody runs Android on a phone where the entire stack is open source and blob free. > Anyone who does is a rounding error. I'm actually curious if there is literally anyone who uses no proprietary software, including the radios and the SoC, on their Android device. My bet is that there's not even a single device out there for which this is possible. (If there is, I'd love to see it.)
Re: A Message to Our Customers
#256If the UK record on anti-terror scope creep is anything to go by, not creating this backdoor is a very good idea. In the UK, laws originally intended for surveilling terrorists were/are routinely used by local councils (similar to districts I think) to monitor whether citizens are putting the correct rubbish/recycling into the correct bin. [1] This is a pandora's box, and the correct answer is not to debate whether w…
Re: A Message to Our Customers
#257Publicizing the case themselves in a very good move. However, the iPhone of the attacker is an iPhone 5C, which does not have Touch ID or a Secure Enclave. This means that the time between passcode unlock attempts is not enforced by the cryptographic coprocessor. More generally, there's no software integrity protection, and the encryption key is relatively weak (since it is only based on the user's passcode). The amo…
[1] - http://i2.wp.com/ioshacker.com/wp-content/uploads/2014/09/Pa...
Re: A Message to Our Customers
#258Earlier quoted context omitted.
In the world of cryptography, it is always possible, because you can always be lucky and guess the right "unlock" code. In fact, social engineering is normally used to find the right "unlock" code[0]. The FBI can also unsolder the components in the phone, make a full image of the content, find the encrypted section and then brute-force. This is what is done for SSD. They do not power up the drive, unsolder, put the m…
It's kind of hard to social engineer dead people, though.
Re: A Message to Our Customers
#259Earlier quoted context omitted.
> and everyone has to use Google Play Services anyway This isn't true. You can stick to app repositories like F-Droid and use Raccoon to download Play Store apps via your desktop without using a Google account on your phone.
It is true that you can get Play Store apps without a Google Account, but the Place Services framework does a lot more than this. Many apps rely upon the framework for certain pieces of functionality from Google's libraries.
I don't use them personally but I imagine Goole Now, GMail and Google Maps would need Play Services.
The apps I do use (non-google) tend to function well enough without Play Services though.
Re: A Message to Our Customers
#260Earlier quoted context omitted.
See other comment: https://news.ycombinator.com/item?id=11116439 Potentially, Apple cannot circumvent their own protections on some models (in software anyway), and could in others.
Thanks. This explains it. I was just thinking about my old Thinkpad X41. That had TPM module and hardware encryption. There's nothing that IBM or the TPM manufacturer could've done to decrypt it (unless the TPM module already had backdoors, haha). Latest iPhones are basically the same?