Live data from Hacker News

A review of the Blackphone, the Android for the paranoid

arstechnica.com

21–30 of 58 posts

Re: A review of the Blackphone, the Android for the paranoid

#21
For my own understanding on the issue with a closed source baseband. Is it analogous to having a network card in every desktop computer that can directly access the screen, keyboard and microphone and therefore compromise all interaction with the phone regardless of tunnelled networks?

Re: A review of the Blackphone, the Android for the paranoid

#22

See also the OnePlus One with Cyanogenmod 11, $299 unlocked, but for now can't be purchased without an invite. CM11 hardening: https://blog.torproject.org/blog/mission-impossible-hardenin...

The most crucial step in that recipe is using a device without a GSM baseband. That rules out anything sold as a 'phone,' such as the OnePlus One.

I think that's possibly overkill. Provided the baseband processor is independent of the apps processor, communicates over a managed bus (usb, high speed serial, dedicated dual-port ram), instead of having direct access to main system memory, and the apps processor has the ability to power it up and down at will, you're in a pretty good state and you can still hop on a cellular voice or data network when you want to.

This scenario is true of plenty of smartphones shipping today, but of course it's not something that manufacturers advertise and it's potentially difficult to verify.

One should probably also be concerned about wifi firmware, though smartphone wifi is almost exclusively connected via sdio and not able to directly affect main memory.

The biggest concern in systems where baseband and wifi radios are not-too-deeply integrated is driver bugs where input from those subsystems is overly-trusted or not adequately validated -- of course solid drivers should never trust the hardware, even if not actively malicious, it can be horribly buggy.

Re: A review of the Blackphone, the Android for the paranoid

#23
post #15

This has a closed source baseband that was also not designed by the company producing the phone. The baseband is pretty much guaranteed to be backdoored by your favorite state security agency, so why get this over any other Android phone?

I remember getting the OpenMoko phone and pretty sure this was an issue way back then

Re: A review of the Blackphone, the Android for the paranoid

#25

See also the OnePlus One with Cyanogenmod 11, $299 unlocked, but for now can't be purchased without an invite. CM11 hardening: https://blog.torproject.org/blog/mission-impossible-hardenin...

The most crucial step in that recipe is using a device without a GSM baseband. That rules out anything sold as a 'phone,' such as the OnePlus One.

Project ARA can't ship fast enough.

Re: A review of the Blackphone, the Android for the paranoid

#28
post #24

"We found that Blackphone lives up to its privacy hype." In all fairness I wouldn't say Ars Technica, good though some of their coverage is, are really the people to determine this. Especially in an article in which at no point do they ask "where's the source?".

On the other hand, how could they skip this topic in an article about a "privacy" phone?

If find the trustworthy value of a phone is about equal to the privacy leak bounty. If each customer trusts the phone with, say $300 worth of information, then that should be a hell of a big bounty.

So Ars Technica should have talked about "where's the source" and "how much is the bounty".

Re: A review of the Blackphone, the Android for the paranoid

#29
post #18

Why does the blackphone lack a physical switch for * the microphone * the GPS chip (or if not possible, the GPS antenna) * the GSM chip (or if not possible, the GSM antennae) * the camera(s) I have talked to the Silent Circle people at MWC in barcelona and they acknowledged the current security issue with the closed source, black box baseband. This first blackphone is of course just a first step. However, physical sw…

Mike switch alone would go a long way. It would also make a great marketing point.
Post reply on HN