Live data from Hacker News

A review of the Blackphone, the Android for the paranoid

arstechnica.com

31–40 of 58 posts

Re: A review of the Blackphone, the Android for the paranoid

#31
post #15

This has a closed source baseband that was also not designed by the company producing the phone. The baseband is pretty much guaranteed to be backdoored by your favorite state security agency, so why get this over any other Android phone?

Risk assessment is an important part of security. I'm not sure the black phone really does this very well.

Being very clear about what they can do, as well as what they can't do, would be a very good thing.

Mobile telephones are a difficult item to make secure. Getting telcos to cooperate with law enforcement doesn't seem to have posed many problems so far.

Re: A review of the Blackphone, the Android for the paranoid

#32
One thing I hate about Android phones these days are the opt-out sync features. All my data is synced to a magical location, and once synced they can never be erased. If you make a single mistake, then all your data has been essentially stolen.

For example, I created a 'Samsung account' to try out the heart rate monitor on S5. I didn't know that if I create an account like that, the phone instantly uploads (syncs) my pictures, contacts etc. to a server somewhere. Sure, maybe that was mentioned in the long EULAs, but it's not practical to read through all the EULAs everytime I crete an account.

In addition, the 'Samsung account sync' app was installed on default, so I didn't even get to accept the app (or even read what access rights it had).

Re: A review of the Blackphone, the Android for the paranoid

#33

Earlier quoted context omitted.

The most crucial step in that recipe is using a device without a GSM baseband. That rules out anything sold as a 'phone,' such as the OnePlus One.

Project ARA can't ship fast enough.

Yes, will be interesting to see how Android will support distribution of drivers to customers for modular hardware components.

Re: A review of the Blackphone, the Android for the paranoid

#34

not to be a bummer, but it doesn't seem like anything special was done with this special purpose hardware. why go to the trouble to engineer and advertise this as a piece of security enhancing hardware when it's really just "PrivOS"? also, any plans on open sourcing "PrivOS"? did I miss something in the writeup? OSS modem firmware, OS wifi chipset, anything hardware or firmware related?

You're missing the fact that this can be sold (at an outrageous markup) to large enterprises and government agencies because it looks secure/private. Beyond that, it provides literally nothing that you can't install for free on any Android device. I could make you an equally "secure" or "private" device for $300 and an hour's time.

> Beyond that, it provides literally nothing that you can't install for free on any Android device. I could make you an equally "secure" or "private" device for $300 and an hour's time.

Yeah, this was my takeaway from the article. They even link to the Google Play store entries for the software that comes packaged on the phone. Missed opportunity, I think.

Re: A review of the Blackphone, the Android for the paranoid

#36
post #9

No mention of the baseband source code. Unless everything running on the phone is open source, there cannot be a guarantee of privacy.

If i understand it correctly there is no open source baseband available because of various patented technologies and it is imposible to create one. But why not treat the baseband as part of insecure transit network? I'd like to see phone where voice data and text messages would be securely encrypted before sending to baseband chip and securely decrypted on the other side. I think there would be great demand for such device but i don't see any in existence. Am i missing something?

Re: A review of the Blackphone, the Android for the paranoid

#37
post #32

One thing I hate about Android phones these days are the opt-out sync features. All my data is synced to a magical location, and once synced they can never be erased. If you make a single mistake, then all your data has been essentially stolen. For example, I created a 'Samsung account' to try out the heart rate monitor on S5. I didn't know that if I create an account like that, the phone instantly uploads (syncs) my…

This looks more like a Samsung problem. AFAIK all Google services ask for explicit permission to do this.

Re: A review of the Blackphone, the Android for the paranoid

#38
post #32

One thing I hate about Android phones these days are the opt-out sync features. All my data is synced to a magical location, and once synced they can never be erased. If you make a single mistake, then all your data has been essentially stolen. For example, I created a 'Samsung account' to try out the heart rate monitor on S5. I didn't know that if I create an account like that, the phone instantly uploads (syncs) my…

Is Apple any better on this? I'm thinking that my next phone is going to be an iPhone because of the regular updates over Android, but is it as hard to stay away from iCloud and not accidentally send everything there?

Re: A review of the Blackphone, the Android for the paranoid

#39
post #38
post #32

One thing I hate about Android phones these days are the opt-out sync features. All my data is synced to a magical location, and once synced they can never be erased. If you make a single mistake, then all your data has been essentially stolen. For example, I created a 'Samsung account' to try out the heart rate monitor on S5. I didn't know that if I create an account like that, the phone instantly uploads (syncs) my…

Is Apple any better on this? I'm thinking that my next phone is going to be an iPhone because of the regular updates over Android, but is it as hard to stay away from iCloud and not accidentally send everything there?

From my experience, iOS rather asks twice than not at all. I have yet to detect a sharing feature where the intentions are not clear. Also, every privacy related access is prompted separately, a freshly installed app has no permissions on anything - so it's usually a non issue when installing apps.

Re: A review of the Blackphone, the Android for the paranoid

#40
I'm really getting tired of writers who keep casually equating those who value their own privacy to those who are suffering from paranoia. It implies that people are mentally unstable just for wanting privacy.

Even in jest, it's insulting and increasingly out of touch in our post-Snowden world to keep calling privacy-minded people paranoid and I wish people would knock it off.

Post reply on HN