Live data from Hacker News

Pixel Security

security.googleblog.com

131–140 of 152 posts

Re: Pixel Security

#131
post #114

Earlier quoted context omitted.

> Apple of course backdoors their phones for government surveillance access. Nice job slipping a completely unfounded lie into your response. Starting with iOS 10, you can actually just mount the root filesystem disk image from iOS restore images. You are able to reverse engineer and audit any application or daemon that the OS runs. You can use open source tools (Such as idevicerestore) to perform an OS restore on yo…

Chronic: but the bootloader of the device is still encrypted and not subject to your audit (well, maybe you can audit it, but most people can't ;P), which totally undermines the chain of trust you just laid out...

Not for 32-bit, although fair point for 64-bit.

That said, an iBoot-level backdoor may not be as useful these days, considering Data partition is still protected with passphrase (and 10-attempt limit being SEP-enforced now).

I suppose you could argue root filesydtem access would be a concern, yet you would still need multiple zero-days to get persistence, defeat CS, etc.

While the argument regarding auditing is valid (for 64-bit), we both are aware that certain parties have privately been able to decrypt those. I highly doubt they would not say something if they had discovered a backdoor in iBoot.

Re: Pixel Security

#132
post #59

Earlier quoted context omitted.

Nothing listed is a backdoor. US law means that Apple must turn over data when demanded by authorities. These are access logs or files stored on Apple servers. A backdoor would be granting access into your device so that authorities could access your non-icloud email, or data saved locally on device.

> Nothing listed is a backdoor. I'm baffled. I like to think of the quality of HN comments as much higher. Apple had options to make this data unavailable by design to themselves and to law enforcement. They chose a design so that they could provide this information. The phone does it without the user's consent. However, I understand that there are people who would rather redefine terminology to suit their cognitive…

There is no redefinition occurring here. Your claim was this:

> Yes Apple backdoors their phones for government surveillance access.

That very specifically is referring to the phone itself. Nobody would be arguing if you had said:

"Apple hands over non-encrypted information (such as webmail and other data that cannot be encrypted at a higher level) from iCloud and iTunes Store servers, in response to a valid legal demand"

Re: Pixel Security

#133
post #103

Earlier quoted context omitted.

I was thinking about it, my credit card has always been extremely good about stuff like this. However, I use google for everything , my entire life is on it. I'd rather lose the $649 I paid for the pixel, then get blackballed from google services. So for now, I'm just patiently awaiting their response and hopefully they'll give me the green light to mail it in for a replacement or something.

I think that the parent is saying that your credit-card company might be the 3rd party insurance, and you might be able to make a claim to take advantage of that insurance.

To add - many "good" credit cards provide "return protection" which allows you to make a claim against the card to get a refund within the first 30 days if the original vendor won't accept a return, and warranty extension which extends the original manufacturer's warranty a year. I have used both benefits quite a bit, and have always had a great experience.

Re: Pixel Security

#135
post #97
post #96

Earlier quoted context omitted.

I appreciate what you're trying to do, but unfortunately this is kind of the problem with the Google culture. Everything has to be done with automation and better tools because they simply do not have the ability to go through the massive amounts of customers that they have without them. Unfortunately, at some point you need a human on the other end that can make a decision, especially with refund/warranty cases.

Sorry that my first post wasn't emphatic enough. The tools the team I'm a part of builds are used by real people (including other Googlers) fielding real telephone calls helping real customers through warranty and refund cases. None of it is automated for use without a human in the loop. Everyone on the team I'm a part of recognizes the perception you've eloquently provided, and very much care to scale with humans in…

Out of interest, this "in the loop" terminology sounds odd to me and sounds like business speak. Is this common in Google?

I remember once contacting Sun for info on software many years ago and received an email where they promised that someone would "reach out to me".

I didn't want to be reached out for - I just wanted some text answering my question.

Re: Pixel Security

#136

Earlier quoted context omitted.

> Apple of course backdoors their phones for government surveillance access. Nice job slipping a completely unfounded lie into your response. Starting with iOS 10, you can actually just mount the root filesystem disk image from iOS restore images. You are able to reverse engineer and audit any application or daemon that the OS runs. You can use open source tools (Such as idevicerestore) to perform an OS restore on yo…

How can you say you're able to audit any application or daemon without viewing the actual source code? Case in point - if the sslKeyExchange.c code had not been published the "goto fail" bug would likely still be in the wild.

That is not true. In fact, the "goto fail" bug was only known because it was patched in iOS and then some folks dug into the SecureTransport sources. You may be thinking of the fact that, from what I understand, OS X was not yet patched at the time so this was considered big news (See here: https://nakedsecurity.sophos.com/2014/02/24/anatomy-of-a-got...).

Definitely an issue, but seeing as it was patched in iOS (and thus discovered in the SecureTransport source code), it would most certainly not still be in the wild.

With regards to auditing: The machine code is available for review, you just need to invest some time into learning the ARM instruction set. Most users of HN have invested time into learning various programming languages and that is why the trope of "open source == more secure" is often repeated, but the truth is that ARM assembly is just another programming language and is almost never obfuscated to a point in which you would not be able to read through it and understand what is happening once you understand the instruction set.

Re: Pixel Security

#137
post #13

Just FYI in case anyone is considering buying a Pixel: I strongly urge you not to. http://kasrarahjerdi.com/2016/11/dont-buy-anything-made-by-g... They have no Google provided support, if you drop the phone and break it your only option (if you didn't buy the third-party warranty upsell) is to take it to a repair shop. I called the ones near me, none had seen or touched the device before. Don't spend $800 on a phone…

Sounds similar to the level of support I've gotten out of Samsung. My primary consideration on phones is now: either cheap enough to chuck in the trash and buy a new one, or completely user repairable. So far I've been using $30~50 android phones off of Amazon, but I'm looking forward to the Fairphone.

Re: Pixel Security

#138
post #69

Earlier quoted context omitted.

Good, now whenever I need tech support, all I need to do is get my gripes published in a global news site and trend on Hacker News so I can get Google to respond to me...

And this is exactly why I am currently migrating to fastmail...

Should be enough to use Gmail with your own domain (and regular backups)? In that case you can still use all Google services but have an easy migration in the (still unlikely) case they lock you out

Re: Pixel Security

#139

And as a bonus, if you onsell it, we'll wipe your Google account without warning.

No, we'll block your account if you never wanted to own the phone, but ordered it directly to a reseller to make money. We block the account because it's a violation of the ToS you agreed to.

However, we reinstate the account after a few days. [1]

[1] http://www.slashgear.com/pixel-phone-flipping-scheme-googles...

Re: Pixel Security

#140
post #138

Earlier quoted context omitted.

And this is exactly why I am currently migrating to fastmail...

Should be enough to use Gmail with your own domain (and regular backups)? In that case you can still use all Google services but have an easy migration in the (still unlikely) case they lock you out

Yeah, I just migrated all my mail over night and connected my gmail account with my fastmail account. Works great!
Post reply on HN