Live data from Hacker News

Blackphone

blackphone.ch

121–130 of 210 posts

Re: Blackphone

#121
post #72
post #57

Earlier quoted context omitted.

The solution is for your phone to not be a phone. Strip out the baseband entirely, use usb or wifi to a 4G LTE dongle, do VoIP. Extra benefit that you can explicitly know when you're radiating (and thus being location-tracked). Blackphone is pretty lame, IMO. There's something better coming from a trusted source in weeks, and plenty of work being done on the "there is no phone" phone concept.

"Strip out the baseband" of a dongle and you won't have a device that can connect to the network, authenticate, shift cells or anything else. It's like stripping the firmware off your disk drive. Fully support the initiative for an open baseband. One reason it's not open is the (fairly legit) fear that intentional and unintentional DoS attacks would occur, affecting everyone in the area. It's really really simple to…

Fully support the initiative for an open baseband.

I would love to live in a world where this can happen. But we don't live in that world.

The carriers have paid billions of dollars for exclusive use of their frequency bands. And their hundreds of billions of dollars of revenue depend upon smooth operation of all devices on the network using those bands. They will use whatever means to protect this.

OK, so let's talk to the FCC (and all the other agencies around the world), and get some other frequency band we can use for our totally open phones.

Well... there aren't any open ones left in the good range of approximately 700MHz to 2GHz. This is the part of the frequency spectrum that has decent carrying capacity, good penetration, and not too high power requirements. It is basic physics. Go lower in frequency, and you can't carry enough bits to be useful. Go higher in frequency and you start getting stopped by walls and such.

All the good bands have been allocated in the USA and elsewhere for TV, existing carriers, military, satellite, and so on. At a minimum, you'd need tens of billions to lobby for and buy a decent chunk of spectrum. And you need to get the current users moved off, which they won't like.

All we have left are the 'crap' bands like 2.4GHz (microwave oven interference). 5GHz isn't too bad (not a lot of other interferers) but it is short range with the current regulations. Another open band for unlicensed use at 60GHz gets stopped by walls, air (oxygen)...

Re: Blackphone

#122
post #66
post #57

Earlier quoted context omitted.

The solution is for your phone to not be a phone. Strip out the baseband entirely, use usb or wifi to a 4G LTE dongle, do VoIP. Extra benefit that you can explicitly know when you're radiating (and thus being location-tracked). Blackphone is pretty lame, IMO. There's something better coming from a trusted source in weeks, and plenty of work being done on the "there is no phone" phone concept.

Except nobody wants to carry a dongle around in their pocket. Your security measure is useless if it's too much hassle to use day-to-day because most of the time (closing in on 100%) it does not matter .

I carry a SIM card around...

Re: Blackphone

#123
I'd really like a phone that had the following features:

* physical switches for GPS, WIFI, Radio, Camera, Mic, write/read access to disk (go diskless),

* a secondary low power eInk display that is wired directly into the hardware that shows when the last time GPS, mic, camera were turned on (and for how long) and how much data has been sent over the radio and read from disk,

* a FS which encrypts certain files with a key that is stored remotely. If your phone is stolen you can delete this remote key. The key is changed on every decrypt. You also get a remote log of all times this remote key was accessed.

* hardware support for read-only, write-only files,

* hardware support for real secure delete on the SSD,

* the ability to change all my HW identifiers at will (IMEI, SIM, etc),

* a log, stored on a separate SD card, of all data sent and received using a HW tap on the radio/WIFI. The log should be encrypted such that only someone with the private key can read it (public key used to encrypt an AES session key which is rotated out every 5 minutes). If you think someone has compromised your phone you can audit this log for both exploitation and data exfiltration. Since the log is implemented in HW, no rootkit can alter it.

Re: Blackphone

#124
post #39

Android having the most granular permission system ever seen on any operating system is already the most secure operating system. The biggest security hole next to the baseband processor and the SIM is the user who installs every app in seconds without checking permissions.

Not even remotely granular. Install XPrivacy[1] (which is still not granular enough for me, as it lacks filtering over function arguments) and see that categories are very broad. [1]: https://github.com/M66B/XPrivacy#xprivacy

Argument-level filtering would be awesome, but I don't know, the existing app+function level filtering seems to be working fine for me so far. The only real complaint I have with xprivacy now is the atrocious UI, and I'd really like some way for it to automatically fetch filters from somewhere so I don't have to bother with the permissions every time an app updates.

Re: Blackphone

#125
post #72

Earlier quoted context omitted.

"Strip out the baseband" of a dongle and you won't have a device that can connect to the network, authenticate, shift cells or anything else. It's like stripping the firmware off your disk drive. Fully support the initiative for an open baseband. One reason it's not open is the (fairly legit) fear that intentional and unintentional DoS attacks would occur, affecting everyone in the area. It's really really simple to…

Fully support the initiative for an open baseband. I would love to live in a world where this can happen. But we don't live in that world. The carriers have paid billions of dollars for exclusive use of their frequency bands. And their hundreds of billions of dollars of revenue depend upon smooth operation of all devices on the network using those bands. They will use whatever means to protect this. OK, so let's talk…

I don't understand. If I come to a carrier and say "Here's a codebase for your baseband. It's OSS, well tested, secure, and supported. Buy support from me." why won't they go for it. Surely, an OSS solution is cheaper for them than developing an in-house crap solution that I'm sure it is now.

Also, is there any harm in just open sourcing their baseband code? It seems to me that it's worthless without the license to use the frequency anyways, so who cares if the code is open from a losing business point of view. On the other hand, things like security review are to the carriers' and manufacturers' benefit, no?

Re: Blackphone

#126
post #72
post #57

Earlier quoted context omitted.

The solution is for your phone to not be a phone. Strip out the baseband entirely, use usb or wifi to a 4G LTE dongle, do VoIP. Extra benefit that you can explicitly know when you're radiating (and thus being location-tracked). Blackphone is pretty lame, IMO. There's something better coming from a trusted source in weeks, and plenty of work being done on the "there is no phone" phone concept.

"Strip out the baseband" of a dongle and you won't have a device that can connect to the network, authenticate, shift cells or anything else. It's like stripping the firmware off your disk drive. Fully support the initiative for an open baseband. One reason it's not open is the (fairly legit) fear that intentional and unintentional DoS attacks would occur, affecting everyone in the area. It's really really simple to…

> Fully support the initiative for an open baseband.

How do you ensure that the manufacturer doesn't modify the baseband code?

Re: Blackphone

#127
Anyone thinking of making a video to sell a privacy product to mass consumers should probably stay away from creepy music and women walking around in all black hoods. Instead go for soccer moms buying stuff with her credit card or librarians doing research for a school kid. Let's not make secure/private communications something weird and creepy but something normal that everyone does.

Re: Blackphone

#128
post #30

Mozilla could take great strides towards this type of phone if they cared. Integrate tor, Whisper Systems RedPhone and SercureText, HTML tracking disabled, etc. I'm surprised their Firefox OS looks and works so much like every other phone out there.

Mozilla would have an awful lot of security work to do. If you check the CVEs for Firefox, there was, on average, a remote code execution vulnerability each week in the last 3 months.

http://web.nvd.nist.gov/view/vuln/search-results?query=firef...

Re: Blackphone

#129
post #88

I would hate to say this, but people here and there, are cashing in NSA fiasco. I would have loved it more, if this was more focused on 'features' than playing with people's emotions. this is valid for everything currently cashing-in NSA issue. As for, NSA spying how exactly can this phone ensure 100% secrecy. Given a user would have to use the same apps, and above all, the carrier that other smartphone users use. Po…

The only thing missing in the video is Julian Assange as the narrator ;-)

Basically, this seems like a lifestyle device for pseudo-"hacktivists". And I expect people to install WhatsApp and Facebook on it. There was this article a few days ago: "When I was young there were beatniks. Hippies. Punks. Gangsters. Now you're a hacktivist. Which I would probably be if I was 20. Shuttin' down MasterCard. But there's no look to that lifestyle! Besides just wearing a bad outfit with bad posture. Has WikiLeaks caused a look? No! I'm mad about that."

http://online.wsj.com/news/articles/SB1000142405270230463640...

Re: Blackphone

#130
post #57

The privacy issue in smartphones isn't the freaking application processor running Android. Sure, that ones terrible enough. But the actual problem is the baseband processor running completely non-free software, with an enormous attack surface and access to all the interesting periphery (GPS, microphone). There is not just opportunity to compromise your privacy, Qualcomm and others actively implement such features at…

The solution is for your phone to not be a phone. Strip out the baseband entirely, use usb or wifi to a 4G LTE dongle, do VoIP. Extra benefit that you can explicitly know when you're radiating (and thus being location-tracked). Blackphone is pretty lame, IMO. There's something better coming from a trusted source in weeks, and plenty of work being done on the "there is no phone" phone concept.

Do tell, what's coming in a few weeks?
Post reply on HN