Live data from Hacker News

Nobody’s Cellphone Is Really That Secure

theatlantic.com

31–40 of 76 posts

Re: Nobody’s Cellphone Is Really That Secure

#31
post #16
post #9

Earlier quoted context omitted.

> They may keep up to date with patches, but you have very little knowledge or control of what they collect from you and what they do with it. It's not an ominous mystery. Google is extremely explicit about what they collect from you and what they do with it. https://myaccount.google.com/privacy https://policies.google.com/privacy I have not seen any evidence that they violate their own policies, even when I worked t…

If you were an engineer working at Google on one of the services that handles, say, location data from phones, how difficult would it be for you to go into the environment and find a specific person's location history? Also, what logging or other audit trail is there for that access?

Google has amazing controls and audit capabilities around access to customer data. When I worked on the security team there the number of people who could access a specific person's data without an audit record and an alert being triggered was zero.

Re: Nobody’s Cellphone Is Really That Secure

#32

I would think the secrete service would put an always on VPN connection on cell phones, have all calls go through a self hosted VoIP service, and then the device is arguably as secure as any other computing device someone in the federal government with high security clearance might use.

These people have blackers and all the rest. That's not the issue. The issue is that Trump doesn't want a security hardened phone. He's being petulant.

Re: Nobody’s Cellphone Is Really That Secure

#33
post #9
post #7

Earlier quoted context omitted.

Make no mistake: their phones are data gathering devices serving one master. They may keep up to date with patches, but you have very little knowledge or control of what they collect from you and what they do with it.

> They may keep up to date with patches, but you have very little knowledge or control of what they collect from you and what they do with it. It's not an ominous mystery. Google is extremely explicit about what they collect from you and what they do with it. https://myaccount.google.com/privacy https://policies.google.com/privacy I have not seen any evidence that they violate their own policies, even when I worked t…

Okay, so that's the outward intent. The practice is a little different. If they get hacked or an employee does misuse data, the public will probably not find out. Most of the company probably doesn't even know.

Eg last week: https://www.cnbc.com/2018/10/08/google-reportedly-exposed-pr...

Re: Nobody’s Cellphone Is Really That Secure

#34
Nobody’s phone is really that secure... but an iPhone vulnerability costs more than an average Bay Area house, while an Android vulnerability is more like the cost of cleaning that house once.

Edit: turns out the figure for an Android vulnerability is off by several orders of magnitude. What a garbage article!

Re: Nobody’s Cellphone Is Really That Secure

#35
post #2

> Google now has its own phone—Pixel—that gets security updates quickly and regularly. The Nexus 5 line used to have this until Google decided after three years to stop supporting it despite the hardware continuing to last well beyond that.

three years of frequent updates is pretty much the best support you're going to get with any android phone. i personally love my pixel 2, but they sold about half as many pixels in 2017 as samsung sold phones in a week. [0][1] samsung does give monthly security updates to its flagship products, but it won't support anything for more than two years. i think it's clear that consumers don't actually give a shit about updates when they choose their next phone, so i find it hard to fault google for having the best update policy on a series of phones that they struggle to break even on.

[0] https://www.theverge.com/2018/2/13/17007104/google-pixel-tot...

[1] https://www.statista.com/statistics/299144/samsung-smartphon...

Re: Nobody’s Cellphone Is Really That Secure

#36
post #16
post #9

Earlier quoted context omitted.

> They may keep up to date with patches, but you have very little knowledge or control of what they collect from you and what they do with it. It's not an ominous mystery. Google is extremely explicit about what they collect from you and what they do with it. https://myaccount.google.com/privacy https://policies.google.com/privacy I have not seen any evidence that they violate their own policies, even when I worked t…

If you were an engineer working at Google on one of the services that handles, say, location data from phones, how difficult would it be for you to go into the environment and find a specific person's location history? Also, what logging or other audit trail is there for that access?

I wonder about facebook also, in terms of access/audit trails.

Re: Nobody’s Cellphone Is Really That Secure

#37
post #9
post #7

Earlier quoted context omitted.

Make no mistake: their phones are data gathering devices serving one master. They may keep up to date with patches, but you have very little knowledge or control of what they collect from you and what they do with it.

> They may keep up to date with patches, but you have very little knowledge or control of what they collect from you and what they do with it. It's not an ominous mystery. Google is extremely explicit about what they collect from you and what they do with it. https://myaccount.google.com/privacy https://policies.google.com/privacy I have not seen any evidence that they violate their own policies, even when I worked t…

We know from the Snowden leaks that there were direct data links between Google and the NSA. Despite their vehement denials and public outrage, I still find it hard to believe that it was possible for the NSA to install such massive surveillance without some complicity from Google.

Technically this might have been possible without any Google involvement, I agree with that, but given past involvement of other companies like e.g. AT&T with the NSA, this seems kind of unlikely to me. It just seems more credible to assume that some people in the higher ranks of Google willfully complied, and I wouldn't be surprised if something similar still occurred.

Re: Nobody’s Cellphone Is Really That Secure

#38
post #2

> Google now has its own phone—Pixel—that gets security updates quickly and regularly. The Nexus 5 line used to have this until Google decided after three years to stop supporting it despite the hardware continuing to last well beyond that.

three years of frequent updates is pretty much the best support you're going to get with any android phone. i personally love my pixel 2, but they sold about half as many pixels in 2017 as samsung sold phones in a week. [0][1] samsung does give monthly security updates to its flagship products, but it won't support anything for more than two years. i think it's clear that consumers don't actually give a shit about up…

> three years of frequent updates is pretty much the best support you're going to get with any android phone

That’s one of the reasons why I finally switched to an iPhone Xs Max.

Before that, I had a Nexus 5x. My last iPhone was the 3GS.

Re: Nobody’s Cellphone Is Really That Secure

#39
post #34

Nobody’s phone is really that secure... but an iPhone vulnerability costs more than an average Bay Area house, while an Android vulnerability is more like the cost of cleaning that house once. Edit: turns out the figure for an Android vulnerability is off by several orders of magnitude. What a garbage article!

Any stats/references to back that up? And does this extend to first party devices from Google as well?

Re: Nobody’s Cellphone Is Really That Secure

#40
post #31
post #16

Earlier quoted context omitted.

If you were an engineer working at Google on one of the services that handles, say, location data from phones, how difficult would it be for you to go into the environment and find a specific person's location history? Also, what logging or other audit trail is there for that access?

Google has amazing controls and audit capabilities around access to customer data. When I worked on the security team there the number of people who could access a specific person's data without an audit record and an alert being triggered was zero.

Is that for someone going through the user interface, or is it a fundamental feature of the database (or whatever)? In other words, is there no case where someone could log into a server and see some PII in a debugger or a direct query without being detected?
Post reply on HN