Blackphone
111–120 of 210 posts
Re: Blackphone
#112Jokes aside, I think it's a great initiative, looking forward to see what comes out of it.
Re: Blackphone
#113Earlier quoted context omitted.
I can revoke permissions on any Android app with App Settings[1]. [1] https://mediacru.sh/DRUrAHvxdlfS
In which Android versions? Cyanogenmod supports this functionality, but most stock builds don't, up through the most recent Kitkat releases. (The first shipped Kitkat builds supported a form of this, but it was quickly removed, amidst complaints from privacy advocates: https://www.eff.org/deeplinks/2013/12/google-removes-vital-p... So, there are a few shipped phones which can have this functionality made accessible v…
Re: Blackphone
#114How does this protect me from my carrier? No matter which phone I use they still need to record who I call for "billing purposes" and know which cell is closest to route my calls.
2) Access Internet (and VOIP) only via VPN or better yet TOR.
3) Only give out your VOIP number. No one must know your direct number, it’s only for emergencies.
This severs all the important connections to make any use of that data, assuming you don’t have any leaks.
Re: Blackphone
#115The privacy issue in smartphones isn't the freaking application processor running Android. Sure, that ones terrible enough. But the actual problem is the baseband processor running completely non-free software, with an enormous attack surface and access to all the interesting periphery (GPS, microphone). There is not just opportunity to compromise your privacy, Qualcomm and others actively implement such features at…
Absolutely correct. This is why such a device should isolate the hardware components used for communication from the main CPU/device, consider the former "hostile" and communicate with them using a simple, safe interface (like USB or serial). Using a throwaway external 3G/LTE adapter (USB) would be even better. This way, a compromised baseband processor or SIM card cannot access the host's memory (using DMA like in c…
http://flors.wordpress.com/2009/08/27/software-freedom-lover...
Re: Blackphone
#116Re: Blackphone
#117If you're "picked up" or detained and you have a Blackphone, or someone observes you using your Blackphone I doubt very much it would help your pricacy concerns.
If however you have a seemingly normal phone it might be overlooked and simply using it wouldn't raise suspicion.
My point is that this type of phone is more for the "regular" person who simply doesn't want to be monitored (as much) and not covert agents looking for a secure phone/platform for communication.
Re: Blackphone
#118The irony is almost too much.
Re: Blackphone
#119The privacy issue in smartphones isn't the freaking application processor running Android. Sure, that ones terrible enough. But the actual problem is the baseband processor running completely non-free software, with an enormous attack surface and access to all the interesting periphery (GPS, microphone). There is not just opportunity to compromise your privacy, Qualcomm and others actively implement such features at…
> But the actual problem is the baseband processor running completely non-free software True, and once that one will be made open-source too, there's still the NSA tracking mobile phones worldwide and generating all kinds of privacy-invading data based on it: http://www.washingtonpost.com/world/national-security/nsa-tr... (And until that is resolved, my mobile phone will stay in flight mode only.) So once again, whil…
The point made elsewhere in this thread is that even an open-source implementation can be exploited. If the baseband is tightly integrated, then that exploit gains the attacker full access.
From a security perspective, even a closed-source baseband could be ok as if it has proper separation from the rest of the system (though open-source would obviously be better).
Re: Blackphone
#120As others have pointed out, the baseband is not your friend. Was thinking about this recently, and saw no reason why existing POCSAG (pager) networks couldn't be reused to provide a completely passive receiver. Imagine a phone where the baseband was off by default, unless attempting to make a call. Voicemail/e-mail summaries were broadcast encrypted via POCSAG, and generate notifications just like a new mail summary…
> " Imagine a phone where the baseband was off by default, unless attempting to make a call." Except if everyone started using a phone like that, you wouldn't be able to call anyone.