Live data from Hacker News

MikroPhone: A privacy enhanced, simple and featured RISC-V mobile phone

mikrophone.net

61–70 of 90 posts

Re: MikroPhone: A privacy enhanced, simple and featured RISC-V mobile phone

#61
post #50
post #11

It's a bit of an annoyance when products talk a lot about "privacy" and "security", but never once mention what sort of threat model they are private/secure against. Then add in something like a bespoke (unvetted?) communication protocol on top and my eyes really start to roll. The people who really want privacy & security enough to be willing to buy something like this will want a lot more detail than what is offere…

As someone who has worked in cybersecurity for decades, it's remarkable to see how security concerns are finally permeating everyday life. We could always predict that the explosion of connected devices would dramatically expand the threat model, but witnessing it unfold in society is something else entirely. This extends beyond just technology: it's now embedded in politics, conflicts, and nearly every aspect of lif…

Unfortunately, I’m not convinced the dialog is connected to actual improvements - this project is somewhat of a perfect example.

I remember the boom of “privacy first” products that launched after the Snowden leaks, but they were all money grabs by folks who probably moved on to blockchain later and now AI.

I agree it’s wild how much of a common topic it is. I do miss the days when it was smart curious folks tinkering around.. but so goes every young field.

Re: MikroPhone: A privacy enhanced, simple and featured RISC-V mobile phone

#62
post #30
post #18

Earlier quoted context omitted.

> ...but never once mention what sort of threat model they are private/secure against. You know, they're Secure(TM)! Against Threats(TM)! Buy me if you're scared of Threats(TM)! Threat modeling ("Secure from who? Under what conditions?") sort of stuff just doesn't seem to be a thing that's taught these days outside certain weird circles. And certainly something this project hasn't touched on in the slightest. But, ye…

Er, no, that would be locked-down GrapheneOS, on a Pixel. There's a multitude of reasons - but here's the biggest one: Apple's Lockdown mode is all or nothing. You can't selectively enable certain features that you may truly depend upon. On the other hand, GrapheneOS allows you to selectively disable individual security features that may be too overbearing. It would be far easier to daily drive a GrapheneOS Pixel tha…

I'm not sure, all of the recent Pixels were on the Cellebrite leak list as accessible without brute-force even while cold. Of course, the recent iPhones were too. Maybe there is no solution, or maybe Cellebrite is lying a little bit with their ads.

Re: MikroPhone: A privacy enhanced, simple and featured RISC-V mobile phone

#63
less a criticism (as this is a fantastic project) and more a general comment about security protocols. The protocol (https://mikrophone.net/ecp.html) for privacy appears to require another MikroPhone device on the other side to communicate with.

the cryptographic backdoors I have encountered in my work were in closed loop systems where having a standards based interface to facilitate separate or independent implementations would have foiled the schemes, as replicating the sabotage in another project would have been far more complex.

the first student project is building this, the next really interesting one is reasoning about that security protocol.

the ideal protocol described provides good forward secrecy, and speculatively if I were looking for implementation sabotage I would look for where the padding nulls were used instead of bytes of the nonce to reduce its entropy to something brute-forcible, and off hand as far as threads to pull, whether the parity bit on the key could reduce the search space by %50 as either even or odd.

from a design perspective, if it only talks to copies of itself, why add the complexity of a new protocol? from a mass interception perspective, the "don't roll your own crypto" cliché is probably one of the most successful psyops of all time and I don't think it's a useful admonition in this case, but imo the question of "why" for a new protocol is the most interesting one.

Re: MikroPhone: A privacy enhanced, simple and featured RISC-V mobile phone

#64
post #16

This is like, barely risc-v. As far as I can tell, there's a risc-v management micro, an esp32 that I'm not easily finding a part number for so may as well be Tenscilica, and an app processor that's ARM based. I don't understand the GPU chip if you have the app processor, and I don't understand the management micro if you have custom ESP32 firmware. And a lot of SoMs have WiFi + Bluetooth on board. So I also don't un…

I was just wrapping my head around on how do they even run linux on the RISC-V microcontroller they use. Turns out there is a separate ARM for application processor.

Re: MikroPhone: A privacy enhanced, simple and featured RISC-V mobile phone

#65
post #50
post #11

It's a bit of an annoyance when products talk a lot about "privacy" and "security", but never once mention what sort of threat model they are private/secure against. Then add in something like a bespoke (unvetted?) communication protocol on top and my eyes really start to roll. The people who really want privacy & security enough to be willing to buy something like this will want a lot more detail than what is offere…

As someone who has worked in cybersecurity for decades, it's remarkable to see how security concerns are finally permeating everyday life. We could always predict that the explosion of connected devices would dramatically expand the threat model, but witnessing it unfold in society is something else entirely. This extends beyond just technology: it's now embedded in politics, conflicts, and nearly every aspect of lif…

[deleted]

Re: MikroPhone: A privacy enhanced, simple and featured RISC-V mobile phone

#66
post #39
post #18

Earlier quoted context omitted.

> ...but never once mention what sort of threat model they are private/secure against. You know, they're Secure(TM)! Against Threats(TM)! Buy me if you're scared of Threats(TM)! Threat modeling ("Secure from who? Under what conditions?") sort of stuff just doesn't seem to be a thing that's taught these days outside certain weird circles. And certainly something this project hasn't touched on in the slightest. But, ye…

>As far as I understand the boot process, Apple has largely fixed a lot of the "before first unlock" type attacks with their secure enclave. They fixed that rather well after the battle with the FBI, and seem to have continued hardening and improving that process (hence my recommendation for the latest generation or two of device - there are changes in the boot security flows every now and then, and I assume they mat…

And this is a good reason to keep your smartphone turned off regularly.

I really don't have a great answer. I'm aware Graphene offers some substantial benefits too, but it's also somewhat harder for a non-technical user to use. Unfortunately, when the attacker has unlimited physical access, a device can and will fall, given time and resources.

Re: MikroPhone: A privacy enhanced, simple and featured RISC-V mobile phone

#67
post #30
post #18

Earlier quoted context omitted.

> ...but never once mention what sort of threat model they are private/secure against. You know, they're Secure(TM)! Against Threats(TM)! Buy me if you're scared of Threats(TM)! Threat modeling ("Secure from who? Under what conditions?") sort of stuff just doesn't seem to be a thing that's taught these days outside certain weird circles. And certainly something this project hasn't touched on in the slightest. But, ye…

Er, no, that would be locked-down GrapheneOS, on a Pixel. There's a multitude of reasons - but here's the biggest one: Apple's Lockdown mode is all or nothing. You can't selectively enable certain features that you may truly depend upon. On the other hand, GrapheneOS allows you to selectively disable individual security features that may be too overbearing. It would be far easier to daily drive a GrapheneOS Pixel tha…

I'm genuinely curious - what issues have you run into with Lockdown? I've been using it enabled for the times I have been carrying an iOS device (vs my preferred flip phone), and I've yet to run into anything I consider a deal breaker.

I can't get animated gifs in MMS/texting threads. Oh darn. Doesn't bother me, they're usually content free fluff anyway.

WebGL being disabled means I can't use that one guy's awesome website on my phone - except, if I want to, I can disable Lockdown on a per-site basis for trusted sites (which then allows those things to work again).

... I can't get Facetime calls from random numbers? That's never been a problem for me one way or another, and, good.

I do occasionally run into websites that use some image format that doesn't render, and if I really care, I can disable Lockdown on the per-site basis there too, but I usually don't bother.

I'm just curious as to what the actual issues you've found with it are. I turned it on in a beta and haven't found any reason to turn it off since then.

Re: MikroPhone: A privacy enhanced, simple and featured RISC-V mobile phone

#68
post #2

Tbh I would accept anything usable without being bound neither to Google nor Apple. Like a Linux phone but with usable apps which is quite important. For example Samsung gets free MP3 player and more important, background-running voice recorder, which is extremely important for me, but was impossible to find on OnePlus One.

Jolla's Sailfish is another alternative. Linux, quite a few native apps and an Android emulation layer that makes it easy to use most F-Droid and Play Store applications.

Re: MikroPhone: A privacy enhanced, simple and featured RISC-V mobile phone

#69
post #58
post #51

Earlier quoted context omitted.

The problem is the hardware, not the software. Also, what you want as a paranoid person is your baseband not part of the SoC running your computer - this project hear does that, Jolla and others are using standard Android SoCs. Jolla added libhybris to make it easy to use Android hardware adaptations - which at that time was needed to get a phone out (ste, which the first Jolla phone was supposed to be based on, deci…

I'd argue software is the main problem. If you want to make a new smartphone OS, just target a pixel or something. The driver + kernel stack as pretty close to as open as you'll find anywhere. The hardware is flagship-grade, updated every year, and shipping now. I've had zero luck putting a non-Android daily driver OS on it though. I'll define daily driver as "all of this works tolerably well": Phone, SMS/MMS, web br…

Jolla's Sailfish OS is used as a daily driver by a small niche in EU, probably tens of thousands of users taking into consideration download and update traffic.

It's definitely usable as a daily driver. There are some rough edges if you only want to use native applications and want to avoid Android applications, which go through an emulation layer. But it's still pretty nice! Things like offline mapping work really well.

Re: MikroPhone: A privacy enhanced, simple and featured RISC-V mobile phone

#70

Are all the needed software drivers open source? Or will this phone end up by using blobs, just like all other devices?

> just like all other devices Except Pinephone and Librem 5, which have all free drivers.

Why downvotes? Only firmware is closed on both devices.
Post reply on HN