Live data from Hacker News

U.S. Navy bans TikTok from government-issued mobile devices

reuters.com

141–150 of 170 posts

Re: U.S. Navy bans TikTok from government-issued mobile devices

#141
post #62

What sort of vetting does Microsoft do on drivers written by manufacturers that ship with Windows?

Traditionally they have done testing for WHQL certification. It may make sense for them to do analysis or reversing in order to raise the bar. Or maybe change the design of the NT kernel to isolate device drivers better.

Does that do anything to uncover backdoors? Particularly if they have all the appearance of a bug.

Re: U.S. Navy bans TikTok from government-issued mobile devices

#143
post #88

Earlier quoted context omitted.

Please don't post unsubstantive comments here, and certainly not nationalistic flamebait. We don't need yet another nationalistic flamewar. https://news.ycombinator.com/newsguidelines.html

I'm not sure that's fair. To me GP comes over as jingoistic nationalism, but it also seems to have a substantive basis - the idea that foreign nations should be ejected at all levels from a governments internal systems? I'd really like to ask "should other nations eject all USA companies products from their governmental systems too?" (because I'm really curious how an apparent ultra-nationalist sees that?), but you'v…

I understand your point, and I agree. It's impossible to audit all that software and hardware and it is not an irrational decision to completely eject an adversarial government's technology, I don't know why this guy is giving you a hard time. I certainly wouldn't blame a Chinese or Russian government policy that bans technology from the USA.

Re: U.S. Navy bans TikTok from government-issued mobile devices

#144
post #126

Sino bashing is apparently an acceptable form of racism in 2020. This is no different than the "jap bashing" of the 80s. What coercive things China does do, is mostly for internal stability, a few small border disputes with neighboring areas that were arguably at one point Chinese, and to maintain harmonious trade arrangements. It's a kitten compared to what the CIA has done internationally.

Denying apps from an adversarial country on military personnel phones is not "Sino bashing". I wouldn't see it as American bashing if the Chinese government did similar. I'd just shrug and say "that makes sense".

Re: U.S. Navy bans TikTok from government-issued mobile devices

#145

Doesn't matter, they have it on their personal phone. App security is so bad that you pretty much need to virtualize the phone and feed it fake sensor data. The whole idea of unrestricted network access is stupid.

> App security is so bad that you pretty much need to virtualize the phone and feed it fake sensor data. Yeah, this is really bizarre to me. I was trying to check on volume levels through walls in my apartment, so I wanted to find some random decibel measuring app and lock it down so I don't have to worry too much about trusting it. But somehow Apple's permission model, which provides a whole pile of privilege switch…

Honest question: but what’s the threat model for wanting an OS to block this? I’ve so far only thought of leaking IP address and Bitcoin mining. But any website already easily has both capabilities (with somewhat arbitrary open sockets after the WebSockets handshake). Is the expectation that an app implementation should have less permissions than an equivalent website and so be the “safer” option?

Re: U.S. Navy bans TikTok from government-issued mobile devices

#146
post #91

Earlier quoted context omitted.

A simple approach is to just ban personal phones while at work. You can forward your number to a work phone while you're on duty, you don't need to carry a personal device with you.

That is what all units in USSOCOM do. No personal cell phones, smart watches, etc allowed in the office. Guests have lock boxes outside main entrance to secure their phone. About once a week security folks wander through the offices looking for phones with some type of detector. God help the person who brought their phone in.

You may have seen people doing the two minute sprint then?

That's when you check the TOTP code on your phone, put it back on the stack of phones, and race as fast as you can back to your desk to enter the code before it expires.

Re: U.S. Navy bans TikTok from government-issued mobile devices

#147
post #104

Doesn't matter, they have it on their personal phone. App security is so bad that you pretty much need to virtualize the phone and feed it fake sensor data. The whole idea of unrestricted network access is stupid.

How would restricted network access help? If you permit a dodgy app to talk to only one remote endpoint, it can exfiltrate whatever it wants.

Why would a flashlight app need to talk to the internet at all?

(Advertising.)

Re: U.S. Navy bans TikTok from government-issued mobile devices

#148
post #32

Earlier quoted context omitted.

Installing a firewall app and checking the connection log on my Android phone really spooked me. There's a ton of traffic in the background that shouldn't be there. It's absolutely crazy that Android doesn't have a first party firewall or the ability to disable internet access permission per app, but that would impact Google's ad revenue, so of course we can't have that.

I don't know if this is a feature of Android or of the alternative ROM I'm using, but I can disable network access on a per app basis. In my Android Pie based ROM, in Settings / Network & Internet / Data Usage / App data usage I can select any app and disable WiFi, Cellular data or both.

That must be the custom OS build. Many official builds allow you to disable cellular, though very time consuming.

Re: U.S. Navy bans TikTok from government-issued mobile devices

#150
post #111

Earlier quoted context omitted.

wouldn't surprise me if the military makes you strip naked, put your clothes in a microwave, then put them back on before getting on the plane to the black site. Each and every time. Anything less than such ridiculous methods would be insecure. You can literally embed chips in the fabric of your clothing. https://www.rfidjournal.com/articles/view?11587

... Why would you not simply issue them new clothes instead of (potentially dangerously) microwaving theirs?

How do you ensure the new clothes aren't embedded with some chip placed by a spy who has access to the supply chain but not the black-site?

I'd assume they give them new clothes & microwave said new clothes. along with other precautions.

Post reply on HN