Live data from Hacker News

Linux PinePhone has physical kill switches for its cameras, mic, data, BT, Wi-Fi

androidpolice.com

41–50 of 149 posts

Re: Linux PinePhone has physical kill switches for its cameras, mic, data, BT, Wi-Fi

#41
post #12
post #6

GNU/Linux Librem 5 phone not just has the kill switches, but they are easily accessible and therefore more useful: https://puri.sm/products/librem-5/

The librem phone is $750 and the pinephone is $150.

With the Librem Phone, the extra money is also paying for the development of the software ecosystem. I would argue that's worth the investment.

For reference, a lot of the Pinephone distros are using the software developed by Purism. I am not saying that's bad, thats the whole spirit of open source!

Re: Linux PinePhone has physical kill switches for its cameras, mic, data, BT, Wi-Fi

#42
post #12

Earlier quoted context omitted.

The librem phone is $750 and the pinephone is $150.

Also a crucial difference: You can get your hands on a Pine Phone, while Librem has yet to ship a phone.

??? They have shipped a number of phones? Or do you mean they haven't entered production?

Re: Linux PinePhone has physical kill switches for its cameras, mic, data, BT, Wi-Fi

#43

Off-topic but IMHO what is really needed these days is a privacy feature allowing all the UIDs to be changed freely by the user (without the need for rooting and firmware thinkering). Including randomized IMEIs and randomized Android ID (In addition to the already offered randomized MAC and Ad tracking ID changes). Especially IMEIs which are commonly used by many applications and law enforcement to track users (see B…

I was almost certain changing your IMEI was a serious federal crime in the US.

Re: Linux PinePhone has physical kill switches for its cameras, mic, data, BT, Wi-Fi

#44

Off-topic but IMHO what is really needed these days is a privacy feature allowing all the UIDs to be changed freely by the user (without the need for rooting and firmware thinkering). Including randomized IMEIs and randomized Android ID (In addition to the already offered randomized MAC and Ad tracking ID changes). Especially IMEIs which are commonly used by many applications and law enforcement to track users (see B…

You may actually be very interested in the work here:

https://xnux.eu/devices/feature/modem-pp.html

https://xnux.eu/devices/feature/modem-pp-reveng.html

They were able to get root access within the modem. Depending on how the IMEI value is stored, it may actually be feasible here.

Re: Linux PinePhone has physical kill switches for its cameras, mic, data, BT, Wi-Fi

#45

Off-topic but IMHO what is really needed these days is a privacy feature allowing all the UIDs to be changed freely by the user (without the need for rooting and firmware thinkering). Including randomized IMEIs and randomized Android ID (In addition to the already offered randomized MAC and Ad tracking ID changes). Especially IMEIs which are commonly used by many applications and law enforcement to track users (see B…

In Germany it's punishable by law indirectly ( https://tipps.computerbild.de/hardware/firmware/imei-nummer-... ), in UK it is a direct crime that may yield 5 years of jail time ( https://www.legislation.gov.uk/ukpga/2002/31/notes?view=plai... ). Be fucking careful when you are traveling with a phone that has an IMEI in the software that does not match the one on the sticker.

I don't really see an issue for manufacturers there. We have the same regulatory issue with Wi-Fi power which will adjust transmission power differently based on the country it's sold in. The phone could easily enable to disable a feature depending on where it is. Remember Bolivia dBm limits ? :)

Regarding your German link. It's about tampering with evidence which I suppose means it's about changing the IMEI after a crime to hide yourself. I suppose that would be illegal everywhere?

Regarding your UK example, the law in question (https://www.legislation.gov.uk/ukpga/2002/31/section/1) mentions circumstances and gives exceptions:

" But a person does not commit an offence under this section if—

(a)he is the manufacturer of the device, or

(b)he does the act mentioned in subsection (1) with the written consent of the manufacturer of the device. "

So I guess it's okay in the UK if the manufacturer allows it and is okay with it?

But of course I'm not trying to promote this feature for illegal use but mostly to hinder "inescapable" tracking from Advertisers , Mobile Operators, ISPs, Phone Manufacturers and ...

Re: Linux PinePhone has physical kill switches for its cameras, mic, data, BT, Wi-Fi

#46
post #43

Off-topic but IMHO what is really needed these days is a privacy feature allowing all the UIDs to be changed freely by the user (without the need for rooting and firmware thinkering). Including randomized IMEIs and randomized Android ID (In addition to the already offered randomized MAC and Ad tracking ID changes). Especially IMEIs which are commonly used by many applications and law enforcement to track users (see B…

I was almost certain changing your IMEI was a serious federal crime in the US.

Absolutely not (yet).

Re: Linux PinePhone has physical kill switches for its cameras, mic, data, BT, Wi-Fi

#47

If you're this worried about leakage from signals, cameras, etc. what about the tradeoff of security where now you need to patch and monitor for any attacks on your device, now that you're off of any normal OEM's support? What's the risk of that being done poorly by you, versus having better control over these physical switches?

I would argue they are doing what I wish any normal OEM would do: upstream their patches to make it much easier to maintain. "normal OEM Support" for phones means you are stuck on whatever LTS kernel the OEM used, then good luck trying to upgrade past that.

For reference, I am typing this on a laptop from 2008. I am not worried about OEM support because all of the hardware support was upstreamed long ago.

Re: Linux PinePhone has physical kill switches for its cameras, mic, data, BT, Wi-Fi

#48
post #33

So, I like the accessibility of physical switches but how are they more trusting than software ones? Or light indicators such as Apple's green Dot? Already trusting Open Source requires non technical people to trust others who can read the code to vouch for it. Here, we would need to expect an electronics engineer to understand (from looking at a disassembled device) that the switch actually does what it says it does…

With software ones you still have to trust the hardware and firmware in addition to the software. With light indicators like Apple's you also need to trust the hardware - and since the designs aren't open it's more difficult to do so - but once verified that they work as advertised having kill switches is a much more active security function than an indicator light.

International standards can also be zero days. For example, the international standard for called ID, uses a dial up modem protocol which means the hardware has to have capabilities to read this data which means the hardware has dialup modem capabilities. So if you can compromise the firmware of the modem, a backdoor into a device is via the very telephone network you later rely on to communicate. https://en.wikipedia.org/wiki/Caller_ID#Operation

Chips fall into 3 categories, fused by manufacturer, fused by branding company, or not fused allowing future updates, like bios chips. Even if the chip is fused, a backdoor may still exist, in some cases standard behaviour can be the backdoor.

With zero days appearing in hardware, software and standards, its very easy if you have the knowledge to get a persistent backdoor into a device beit a PinePhone, Librem 5 or Necunos to name just a couple. https://forums.puri.sm/t/comparing-specs-of-upcoming-linux-p... https://tuxphones.com/yet-another-librem-5-and-pinephone-lin... Its probably why people like Cobham, Thales and other openly public military manufacturers make their own kits for militaries around the world. https://www.cobham.com/ https://www.thalesgroup.com/en

I even think its possible to hack the communication systems of the new Lockheed Martin F35, because the manufacturers are walking a logical development path (their mistake), but I've yet to have a go at it, so cant say for sure yet. https://www.youtube.com/watch?v=_C25CwNlVjA

Re: Linux PinePhone has physical kill switches for its cameras, mic, data, BT, Wi-Fi

#50
post #33

So, I like the accessibility of physical switches but how are they more trusting than software ones? Or light indicators such as Apple's green Dot? Already trusting Open Source requires non technical people to trust others who can read the code to vouch for it. Here, we would need to expect an electronics engineer to understand (from looking at a disassembled device) that the switch actually does what it says it does…

Physical switches typically are a lot harder to circumvent and a lot easier to verify than software ones.

> Here, we would need to expect an electronics engineer to understand (from looking at a disassembled device) that the switch actually does what it says it does, right?

Sure. This is a lot better than just trusting a manufacturer's word, since they have an incentive to hide vulnerabilities and independent researchers have an incentive to publish them.

Having designs available makes their work a whole lot easier and potentially lowers the barrier of entry so much someone with some interest and time could do the checks themselves. The more eyes, the better.

Post reply on HN