A review of the Blackphone, the Android for the paranoid
21–30 of 58 posts
Re: A review of the Blackphone, the Android for the paranoid
#22See also the OnePlus One with Cyanogenmod 11, $299 unlocked, but for now can't be purchased without an invite. CM11 hardening: https://blog.torproject.org/blog/mission-impossible-hardenin...
The most crucial step in that recipe is using a device without a GSM baseband. That rules out anything sold as a 'phone,' such as the OnePlus One.
This scenario is true of plenty of smartphones shipping today, but of course it's not something that manufacturers advertise and it's potentially difficult to verify.
One should probably also be concerned about wifi firmware, though smartphone wifi is almost exclusively connected via sdio and not able to directly affect main memory.
The biggest concern in systems where baseband and wifi radios are not-too-deeply integrated is driver bugs where input from those subsystems is overly-trusted or not adequately validated -- of course solid drivers should never trust the hardware, even if not actively malicious, it can be horribly buggy.
Re: A review of the Blackphone, the Android for the paranoid
#23This has a closed source baseband that was also not designed by the company producing the phone. The baseband is pretty much guaranteed to be backdoored by your favorite state security agency, so why get this over any other Android phone?
Re: A review of the Blackphone, the Android for the paranoid
#24In all fairness I wouldn't say Ars Technica, good though some of their coverage is, are really the people to determine this.
Especially in an article in which at no point do they ask "where's the source?".
Re: A review of the Blackphone, the Android for the paranoid
#25See also the OnePlus One with Cyanogenmod 11, $299 unlocked, but for now can't be purchased without an invite. CM11 hardening: https://blog.torproject.org/blog/mission-impossible-hardenin...
The most crucial step in that recipe is using a device without a GSM baseband. That rules out anything sold as a 'phone,' such as the OnePlus One.
Re: A review of the Blackphone, the Android for the paranoid
#26Re: A review of the Blackphone, the Android for the paranoid
#27Re: A review of the Blackphone, the Android for the paranoid
#28"We found that Blackphone lives up to its privacy hype." In all fairness I wouldn't say Ars Technica, good though some of their coverage is, are really the people to determine this. Especially in an article in which at no point do they ask "where's the source?".
If find the trustworthy value of a phone is about equal to the privacy leak bounty. If each customer trusts the phone with, say $300 worth of information, then that should be a hell of a big bounty.
So Ars Technica should have talked about "where's the source" and "how much is the bounty".
Re: A review of the Blackphone, the Android for the paranoid
#29Why does the blackphone lack a physical switch for * the microphone * the GPS chip (or if not possible, the GPS antenna) * the GSM chip (or if not possible, the GSM antennae) * the camera(s) I have talked to the Silent Circle people at MWC in barcelona and they acknowledged the current security issue with the closed source, black box baseband. This first blackphone is of course just a first step. However, physical sw…
Re: A review of the Blackphone, the Android for the paranoid
#30missed a beat, should have been called "Paranoid Android".