Earlier quoted context omitted.
The most crucial step in that recipe is using a device without a GSM baseband. That rules out anything sold as a 'phone,' such as the OnePlus One.
Thanks for the reminder. For those who understand why that's important, what do you think about CM11 on a Samsung Galaxy Player (no GSM), using wifi VPN to a cheap phone/hotspot which does have GSM baseband, e.g. Firefox phone? Or two Firefox phones, if Android apps aren't important?
A review of the Blackphone, the Android for the paranoid
11–20 of 58 posts
Re: A review of the Blackphone, the Android for the paranoid
#12Re: A review of the Blackphone, the Android for the paranoid
#13Re: A review of the Blackphone, the Android for the paranoid
#14Earlier quoted context omitted.
Thanks for the reminder. For those who understand why that's important, what do you think about CM11 on a Samsung Galaxy Player (no GSM), using wifi VPN to a cheap phone/hotspot which does have GSM baseband, e.g. Firefox phone? Or two Firefox phones, if Android apps aren't important?
Without GSM, you only eliminate the excuse for a baseband backdoor. How do you eliminate their motivation for adding the backdoor? What if they put it it another chip connected to the bus?
Some protection against malicious firmware/hardware can come from ARM's IOMMU with an open-source Type-1 hypervisor, but these are not mainstream yet.
Whatever the technical merits of Blackphone, their marketing is increasing awareness of mobile security. If they can prove demand for this category of solution, it will increase security audits of all mobile hardware & software stacks.
Re: A review of the Blackphone, the Android for the paranoid
#15Re: A review of the Blackphone, the Android for the paranoid
#16Earlier quoted context omitted.
Without GSM, you only eliminate the excuse for a baseband backdoor. How do you eliminate their motivation for adding the backdoor? What if they put it it another chip connected to the bus?
Motivation is likely stable :) Some protection against malicious firmware/hardware can come from ARM's IOMMU with an open-source Type-1 hypervisor, but these are not mainstream yet. Whatever the technical merits of Blackphone, their marketing is increasing awareness of mobile security. If they can prove demand for this category of solution, it will increase security audits of all mobile hardware & software stacks.
That I agree and I really hope that it works. But on that note, I don't like the name Blackphone. When I hear "black" I associate it with nefarious activities; and that meaning suggests that only those with criminal purposes need privacy.
Re: A review of the Blackphone, the Android for the paranoid
#17This has a closed source baseband that was also not designed by the company producing the phone. The baseband is pretty much guaranteed to be backdoored by your favorite state security agency, so why get this over any other Android phone?
Re: A review of the Blackphone, the Android for the paranoid
#18* the microphone
* the GPS chip (or if not possible, the GPS antenna)
* the GSM chip (or if not possible, the GSM antennae)
* the camera(s)
I have talked to the Silent Circle people at MWC in barcelona and they acknowledged the current security issue with the closed source, black box baseband. This first blackphone is of course just a first step.
However, physical switches could help against certain attack scenarios.
Re: A review of the Blackphone, the Android for the paranoid
#19See also the OnePlus One with Cyanogenmod 11, $299 unlocked, but for now can't be purchased without an invite. CM11 hardening: https://blog.torproject.org/blog/mission-impossible-hardenin...
[1] http://www.ishoppstore.com/en/quad-core/4707-oneplus-one-55-...
[2] http://www.gsmarena.com/oneplus_one_in_stock_at_one_retailer...
Re: A review of the Blackphone, the Android for the paranoid
#20This has a closed source baseband that was also not designed by the company producing the phone. The baseband is pretty much guaranteed to be backdoored by your favorite state security agency, so why get this over any other Android phone?
Raising the bar (e.g. open-source software stacks) against smaller attackers helps everyone.