Live data from Hacker News

A review of the Blackphone, the Android for the paranoid

arstechnica.com

11–20 of 58 posts

Re: A review of the Blackphone, the Android for the paranoid

#11

Earlier quoted context omitted.

The most crucial step in that recipe is using a device without a GSM baseband. That rules out anything sold as a 'phone,' such as the OnePlus One.

Thanks for the reminder. For those who understand why that's important, what do you think about CM11 on a Samsung Galaxy Player (no GSM), using wifi VPN to a cheap phone/hotspot which does have GSM baseband, e.g. Firefox phone? Or two Firefox phones, if Android apps aren't important?

Without GSM, you only eliminate the excuse for a baseband backdoor. How do you eliminate their motivation for adding the backdoor? What if they put it it another chip connected to the bus?

Re: A review of the Blackphone, the Android for the paranoid

#14
post #11

Earlier quoted context omitted.

Thanks for the reminder. For those who understand why that's important, what do you think about CM11 on a Samsung Galaxy Player (no GSM), using wifi VPN to a cheap phone/hotspot which does have GSM baseband, e.g. Firefox phone? Or two Firefox phones, if Android apps aren't important?

Without GSM, you only eliminate the excuse for a baseband backdoor. How do you eliminate their motivation for adding the backdoor? What if they put it it another chip connected to the bus?

Motivation is likely stable :)

Some protection against malicious firmware/hardware can come from ARM's IOMMU with an open-source Type-1 hypervisor, but these are not mainstream yet.

Whatever the technical merits of Blackphone, their marketing is increasing awareness of mobile security. If they can prove demand for this category of solution, it will increase security audits of all mobile hardware & software stacks.

Re: A review of the Blackphone, the Android for the paranoid

#16
post #11

Earlier quoted context omitted.

Without GSM, you only eliminate the excuse for a baseband backdoor. How do you eliminate their motivation for adding the backdoor? What if they put it it another chip connected to the bus?

Motivation is likely stable :) Some protection against malicious firmware/hardware can come from ARM's IOMMU with an open-source Type-1 hypervisor, but these are not mainstream yet. Whatever the technical merits of Blackphone, their marketing is increasing awareness of mobile security. If they can prove demand for this category of solution, it will increase security audits of all mobile hardware & software stacks.

> their marketing is increasing awareness of mobile security

That I agree and I really hope that it works. But on that note, I don't like the name Blackphone. When I hear "black" I associate it with nefarious activities; and that meaning suggests that only those with criminal purposes need privacy.

Re: A review of the Blackphone, the Android for the paranoid

#17
post #15

This has a closed source baseband that was also not designed by the company producing the phone. The baseband is pretty much guaranteed to be backdoored by your favorite state security agency, so why get this over any other Android phone?

Reducing the number of possible attack vectors is not necessarily useless. That said, I wonder whether that phone's operating system is itself free software or not...

Re: A review of the Blackphone, the Android for the paranoid

#18
Why does the blackphone lack a physical switch for

* the microphone

* the GPS chip (or if not possible, the GPS antenna)

* the GSM chip (or if not possible, the GSM antennae)

* the camera(s)

I have talked to the Silent Circle people at MWC in barcelona and they acknowledged the current security issue with the closed source, black box baseband. This first blackphone is of course just a first step.

However, physical switches could help against certain attack scenarios.

Re: A review of the Blackphone, the Android for the paranoid

#19

See also the OnePlus One with Cyanogenmod 11, $299 unlocked, but for now can't be purchased without an invite. CM11 hardening: https://blog.torproject.org/blog/mission-impossible-hardenin...

The OnePlus One can be purchased without an invite[1][2], it's far more expensive, but purchasable.

[1] http://www.ishoppstore.com/en/quad-core/4707-oneplus-one-55-...

[2] http://www.gsmarena.com/oneplus_one_in_stock_at_one_retailer...

Re: A review of the Blackphone, the Android for the paranoid

#20
post #15

This has a closed source baseband that was also not designed by the company producing the phone. The baseband is pretty much guaranteed to be backdoored by your favorite state security agency, so why get this over any other Android phone?

There are many attackers in the world beyond nation-states.

Raising the bar (e.g. open-source software stacks) against smaller attackers helps everyone.

Post reply on HN