Live data from Hacker News

Pixel Security

security.googleblog.com

41–50 of 152 posts

Re: Pixel Security

#41
post #12

I have not seen so many gotos in many many years. I guess it's the programming model in this case. I am sure this bit of code is going to be audited quite closely.

The use of goto in C for error and exception handling is good practice. It keeps the code easy to read, and also provides common code for error and/or exit handling. You'll see this paradigm used a lot in large open source C projects, such as the Linux kernel and QEMU. In my experience, a lot of closed source C projects ban goto outright, in (IMO) an overly dogmatic adherence to the idea that all goto use is spaghett…

I have used them myself for error handling many times many years ago. When you don't have exceptions and longjmp scares the shit out of you, gotos for error handling are fine by me too. I agree, dogmatic banning of them precludes the useful case of error handling but it is a slippery slope that they seem to be already sliding with got_key:.

Re: Pixel Security

#42
post #13

Just FYI in case anyone is considering buying a Pixel: I strongly urge you not to. http://kasrarahjerdi.com/2016/11/dont-buy-anything-made-by-g... They have no Google provided support, if you drop the phone and break it your only option (if you didn't buy the third-party warranty upsell) is to take it to a repair shop. I called the ones near me, none had seen or touched the device before. Don't spend $800 on a phone…

Thats why I use case

Re: Pixel Security

#43
post #23
post #18

Earlier quoted context omitted.

I don't know of any phone vendor that offers a warranty against accidental damage (that doesn't cost extra). By the way: "Google and uBreakiFix offer walk-in repairs for Pixel and Pixel XL" http://www.androidauthority.com/google-ubreakifix-repairs-pi...

I called the uBreakiFix in Denver: "we've never seen that phone before, but yeah I think I could fix it". I'm not upset that they don't have an accidental damage warranty, I'm upset that I can't send it to them and pay them the $100/$200/$300 or whatever it is directly for _them_ to fix it, not some random dude who's never seen the Pixel before.

Google will never do anything that involves hiring O(N) employees to support N customers. They'll always outsource things like support, repairs, etc. so that someone else can handle scaling people, while they just go on scaling machines. Given that, the only real possibility is that "some random dude" is going to end up fixing your Pixel.

On the other hand, the "who's never seen the Pixel before" part? C'mon, the phone just came out—if an i-device breaks on the first day, you'd better believe that if you take it to an Apple Store someone's fixing it who has never seen that device before. That's the fundamental problem of new hardware designs (especially when coupled to bathtub curves); you can't blame Google for it. Give them a month and every repair shop around you will have fixed plenty of Pixels.

Re: Pixel Security

#44

Given recent news about mass surveillance, it's important to note that Pixel's security model does not and can not seek to protect your data for use for private messaging, conversation with attorneys, for journalists, or to organize for political reasons. If you are interested in a communications device that can be used for any of these things, Pixel's security model will not cover you and you will need to look for a…

Which alternative product would you recommend? And I really hope you don't say the iPhone.

Re: Pixel Security

#45

Earlier quoted context omitted.

How would Google protect its customers from law enforcement and mass surveillance programs? The government can just force them to do whatever and issue a gag order to keep them quiet. Apple is just putting on a show with their tough security rhetoric, they can't resist the US government if they really want some data.

Apple is doing more than putting on a show. They've actively trying to build ML products that don't involve sending everything back to the mothership ala Google, FB, etc., but rather store and execute on the local device. (The efficacy and user experience of these products remains to be determined.) From a security standpoint, Apple wouldn't have anything to turn over, because they never had it to begin with. Google…

No, he's right. Apple is putting on a PR show. If a warrant is served to Apple they'll hand over whatever data they have on you including any metadata on your encrypted data. They also have teams working 24/7 to serve up this data to government officials and law enforcement. It's all in the leaked Apple/Podesta emails.

Re: Pixel Security

#46
post #33

Earlier quoted context omitted.

Is that a common thing? Being able to send your device back to the manufacturer for user inflicted issues for repair? I can't say I've ever done that with any product ever...

It's quite common. HTC even advertise it as something you can do for free: http://www.htc.com/us/uh-oh-protection/

Only if you buy that one phone from them on their website.

You could not get that phone second hand (or from any other reseller) and send it in to them for repair.

That's basically "insurance" included in the price of the phone, not a "pay for what you broke" repair center.

Re: Pixel Security

#47
post #8

Earlier quoted context omitted.

>Unlike other phone manufacturers, Google does not promise potential customers that your data will be protected from Google, it's partners and from law enforcement and mass surveillance programmes. Are you referring to Apple? Because they don't promise that either.

I used the term 'motivate' specifically because of the PR language intending for customers to evaluate the Apple product as something that could be used by those who need to use their phone for private and/or sensitive reasons. Apple of course backdoors their phones for government surveillance access. But they do motivate a threat model that includes government surveillance. I know parsing my comment in this way may…

> Apple of course backdoors their phones for government surveillance access.

Nice job slipping a completely unfounded lie into your response.

Starting with iOS 10, you can actually just mount the root filesystem disk image from iOS restore images. You are able to reverse engineer and audit any application or daemon that the OS runs. You can use open source tools (Such as idevicerestore) to perform an OS restore on your device, and point it directly at the filesystem disk image that you just audited the binaries of. That way you can be sure of what is being flashed onto your device if you have any doubts that the OS you just audited is the one going onto your device. No "blackbox" at all in this process.

I am looking forward to hearing any form of evidence regarding your claim.

Re: Pixel Security

#48

Earlier quoted context omitted.

Apple is doing more than putting on a show. They've actively trying to build ML products that don't involve sending everything back to the mothership ala Google, FB, etc., but rather store and execute on the local device. (The efficacy and user experience of these products remains to be determined.) From a security standpoint, Apple wouldn't have anything to turn over, because they never had it to begin with. Google…

No, he's right. Apple is putting on a PR show. If a warrant is served to Apple they'll hand over whatever data they have on you including any metadata on your encrypted data. They also have teams working 24/7 to serve up this data to government officials and law enforcement. It's all in the leaked Apple/Podesta emails.

Your framing is disingenuous, considering that any large company will have staff ready to respond to legal / discovery demands. This is a legal process, not something Apple is doing out of their own volition.

Re: Pixel Security

#49
post #13

Just FYI in case anyone is considering buying a Pixel: I strongly urge you not to. http://kasrarahjerdi.com/2016/11/dont-buy-anything-made-by-g... They have no Google provided support, if you drop the phone and break it your only option (if you didn't buy the third-party warranty upsell) is to take it to a repair shop. I called the ones near me, none had seen or touched the device before. Don't spend $800 on a phone…

It's funny, I'm this exact same boat. My pixel died a little after two week (which is the requirement to get a return). I filled out their warranty claim thing, and >48 hours finally got a response, which is a trouble shooting guide. I replied that I tried all that stuff, and had to wait another 2 days for another response (asking for information I already gave). I'm extremely disappointed. I thought with their whole…

> It's funny, I'm this exact same boat. My pixel died a little after two week (which is the requirement to get a return). I filled out their warranty claim thing, and >48 hours finally got a response, which is a trouble shooting guide. I replied that I tried all that stuff, and had to wait another 2 days for another response (asking for information I already gave).

Are you not in the US? Maybe it's different elsewhere, but my nexus 5x died a little while ago, and I only had the default warranty, not the extra protection, and it was insanely easy to get a replacement.

I filled out the form[1] (saying I had already tried the usual android-saving moves), got a call back in two minutes as promised by that form, the customer service person accepted I had already tried things and didn't ask me to do anything else, then I immediately got the email with the link to get a new phone shipped to me. Was probably less than 15 minutes of my time.

(you also seem to be talking about something else than the OP. If your phone died in two weeks that's definitely under the warranty, regardless of if you purchased extra protection).

[1] linked here: https://support.google.com/store/answer/6301527?hl=en

Re: Pixel Security

#50

Earlier quoted context omitted.

Perhaps I am not following your logic correctly, but it sounds like you are saying "Apple says government threats are an issue, but then backdoors the phones for the government anyways." which, to me, paints Apple in a very poor light.

You are following my logic correctly. To be fair, the amount of leverage the US exerts on businesses for military purposes is astounding. This should be factored into the understanding.

[deleted]
Post reply on HN