Live data from Hacker News

Blackphone

blackphone.ch

61–70 of 210 posts

Re: Blackphone

#61
post #57

The privacy issue in smartphones isn't the freaking application processor running Android. Sure, that ones terrible enough. But the actual problem is the baseband processor running completely non-free software, with an enormous attack surface and access to all the interesting periphery (GPS, microphone). There is not just opportunity to compromise your privacy, Qualcomm and others actively implement such features at…

The solution is for your phone to not be a phone. Strip out the baseband entirely, use usb or wifi to a 4G LTE dongle, do VoIP. Extra benefit that you can explicitly know when you're radiating (and thus being location-tracked). Blackphone is pretty lame, IMO. There's something better coming from a trusted source in weeks, and plenty of work being done on the "there is no phone" phone concept.

> There's something better coming from a trusted source in weeks...

Could you provide more concrete info on what you are referencing there?

Re: Blackphone

#62

"and anonymize your activity through a VPN." iOS and Android support VPN but it needs to be manually activated each time, making it rather useless unless you're using some public wifi. If I understand correctly there is a possibility for large companies to integrate VPN but for the average guy it's rather useless if you have to activate it. If this phone has VPN really integrated that'd be great.

I understood that this had been fixed in Android a while back so it would start up automatically? Personally, I'm still on 2.3 which requires a manual startup...

Re: Blackphone

#63
post #57

The privacy issue in smartphones isn't the freaking application processor running Android. Sure, that ones terrible enough. But the actual problem is the baseband processor running completely non-free software, with an enormous attack surface and access to all the interesting periphery (GPS, microphone). There is not just opportunity to compromise your privacy, Qualcomm and others actively implement such features at…

The solution is for your phone to not be a phone. Strip out the baseband entirely, use usb or wifi to a 4G LTE dongle, do VoIP. Extra benefit that you can explicitly know when you're radiating (and thus being location-tracked). Blackphone is pretty lame, IMO. There's something better coming from a trusted source in weeks, and plenty of work being done on the "there is no phone" phone concept.

>There's something better

Is this IndiePhone by Aral Balkan?

Re: Blackphone

#64

The privacy issue in smartphones isn't the freaking application processor running Android. Sure, that ones terrible enough. But the actual problem is the baseband processor running completely non-free software, with an enormous attack surface and access to all the interesting periphery (GPS, microphone). There is not just opportunity to compromise your privacy, Qualcomm and others actively implement such features at…

Absolutely correct. This is why such a device should isolate the hardware components used for communication from the main CPU/device, consider the former "hostile" and communicate with them using a simple, safe interface (like USB or serial). Using a throwaway external 3G/LTE adapter (USB) would be even better. This way, a compromised baseband processor or SIM card cannot access the host's memory (using DMA like in current smartphones) and as long as the host uses secure encryption, it can still communicate securely (but of course the device will be detected and identified).

Re: Blackphone

#65
post #44
post #43

Earlier quoted context omitted.

Not really, iOS permissions are more granular sometimes - iOS will ask you before an app accesses your phonebook, and you can deny the access. You can't do that with Android.

> iOS permissions are more granular sometimes Not true, http://developer.android.com/reference/android/Manifest.perm...

Android permissions are all or none at install time. iOS allows permissions to be individually toggled at any time. Some people define flexibility differently.

Re: Blackphone

#66
post #57

The privacy issue in smartphones isn't the freaking application processor running Android. Sure, that ones terrible enough. But the actual problem is the baseband processor running completely non-free software, with an enormous attack surface and access to all the interesting periphery (GPS, microphone). There is not just opportunity to compromise your privacy, Qualcomm and others actively implement such features at…

The solution is for your phone to not be a phone. Strip out the baseband entirely, use usb or wifi to a 4G LTE dongle, do VoIP. Extra benefit that you can explicitly know when you're radiating (and thus being location-tracked). Blackphone is pretty lame, IMO. There's something better coming from a trusted source in weeks, and plenty of work being done on the "there is no phone" phone concept.

Except nobody wants to carry a dongle around in their pocket. Your security measure is useless if it's too much hassle to use day-to-day because most of the time (closing in on 100%) it does not matter.

Re: Blackphone

#67
I don't really feel like a slave, maybe I am under reacting here. I am pissed the NSA is collecting data, I am upset at all the recent revelations we have had about data privacy in the last 6-8 months, but I certainly don't feel like a slave.

These products should be advertised on theblaze and infowares.

Sure there is a need for better privacy, but I don't really care for the fearmongering...

Re: Blackphone

#68
I agree with the fact that the website is still a little bit unspecific but this project is backed by Phil Zimmermann, he was the creator of PGP, it doesn't guarantee anything but it definitely means some smart people who are worried about privacy are behind it.

Re: Blackphone

#69
post #61
post #57

Earlier quoted context omitted.

The solution is for your phone to not be a phone. Strip out the baseband entirely, use usb or wifi to a 4G LTE dongle, do VoIP. Extra benefit that you can explicitly know when you're radiating (and thus being location-tracked). Blackphone is pretty lame, IMO. There's something better coming from a trusted source in weeks, and plenty of work being done on the "there is no phone" phone concept.

> There's something better coming from a trusted source in weeks... Could you provide more concrete info on what you are referencing there?

Sorry, no -- it's not my product to announce. By way of validation, it's something I'm planning to use personally, even though it doesn't go as far as I'd ultimately like, until something better exists (which I might be involved in; unclear if client devices are the right focus since end users are so picky about non-security aspects of them, and for me, iOS is generally good against non-NSA threats, and NSA isn't my personal adversary.)

Re: Blackphone

#70
post #27
post #8

How does this protect me from my carrier? No matter which phone I use they still need to record who I call for "billing purposes" and know which cell is closest to route my calls.

You could use p2p VoIP.

Not in Germany, where opening your WIFI makes you liable for all the things that might happen with this.

But only if you are a private person (or a small cafe/venue). If you are an ISP, you can operate hotspots wherever you want and charge whatever anyone is willing to pay. And you do not need to fear being held liable for your users actions.

[Edit] Meant to say, that since this change of law we do not have a lot of open WIFI-Spots anymore.

Post reply on HN