Live data from Hacker News

Blackphone

blackphone.ch

131–140 of 210 posts

Re: Blackphone

#131
It's interesting that all the work being done on this "secure" phone is being done on non-secure hardware and networks. Presumably if interested parties think this is a threat, they can access all comms/data about this new phone, inject themselves where they see fit and compromise the final product.

Oh, and never mind compromising the people involved.

Re: Blackphone

#132

The privacy issue in smartphones isn't the freaking application processor running Android. Sure, that ones terrible enough. But the actual problem is the baseband processor running completely non-free software, with an enormous attack surface and access to all the interesting periphery (GPS, microphone). There is not just opportunity to compromise your privacy, Qualcomm and others actively implement such features at…

Yes, the other OS is way worse. "You can even brick phones permanently" --http://www.osnews.com/story/27416/The_second_operating_syste... which was on hn recently.

Re: Blackphone

#133

A site peddling a product that is supposedly about user control and privacy that won't even load without javascript... The irony is almost too much.

Why? Check out the page source, everything is un-obfuscated, there for you to see.

Re: Blackphone

#134
post #38

The privacy issue in smartphones isn't the freaking application processor running Android. Sure, that ones terrible enough. But the actual problem is the baseband processor running completely non-free software, with an enormous attack surface and access to all the interesting periphery (GPS, microphone). There is not just opportunity to compromise your privacy, Qualcomm and others actively implement such features at…

Came here to say this exactly. The world needs an open-source baseband processor/firmware.

[deleted]

Re: Blackphone

#135
post #38

The privacy issue in smartphones isn't the freaking application processor running Android. Sure, that ones terrible enough. But the actual problem is the baseband processor running completely non-free software, with an enormous attack surface and access to all the interesting periphery (GPS, microphone). There is not just opportunity to compromise your privacy, Qualcomm and others actively implement such features at…

Came here to say this exactly. The world needs an open-source baseband processor/firmware.

Osmocom baseband tried this. Works on older motorola phones, then just buy a turbosim with encrypted voice, sms and code your own OTA blocking. Or use a small tablet with no sim using wifi

Re: Blackphone

#136

Earlier quoted context omitted.

Fully support the initiative for an open baseband. I would love to live in a world where this can happen. But we don't live in that world. The carriers have paid billions of dollars for exclusive use of their frequency bands. And their hundreds of billions of dollars of revenue depend upon smooth operation of all devices on the network using those bands. They will use whatever means to protect this. OK, so let's talk…

I don't understand. If I come to a carrier and say "Here's a codebase for your baseband. It's OSS, well tested, secure, and supported. Buy support from me." why won't they go for it. Surely, an OSS solution is cheaper for them than developing an in-house crap solution that I'm sure it is now. Also, is there any harm in just open sourcing their baseband code? It seems to me that it's worthless without the license to u…

Ironically, the market seems to be not optimizing for optimal net revenue (income minus costs, where here you're minimizing costs), but for control. This is partly because of the control freak nature of these companies, partly because the government demands it, but also, again ironically, because of long term thinking: if these companies can lock people out and control them, that helps to guarantee future profits. The free market can sometimes be a cruel bitch bent on the end-user's oppression.

Re: Blackphone

#137

Earlier quoted context omitted.

Fully support the initiative for an open baseband. I would love to live in a world where this can happen. But we don't live in that world. The carriers have paid billions of dollars for exclusive use of their frequency bands. And their hundreds of billions of dollars of revenue depend upon smooth operation of all devices on the network using those bands. They will use whatever means to protect this. OK, so let's talk…

I don't understand. If I come to a carrier and say "Here's a codebase for your baseband. It's OSS, well tested, secure, and supported. Buy support from me." why won't they go for it. Surely, an OSS solution is cheaper for them than developing an in-house crap solution that I'm sure it is now. Also, is there any harm in just open sourcing their baseband code? It seems to me that it's worthless without the license to u…

If I come to a carrier and say "Here's a codebase for your baseband.

The carriers don't want baseband code, they just want finished products to sell.

It's OSS, well tested, secure, and supported. Buy support from me." why won't they go for it. Surely, an OSS solution is cheaper for them than developing an in-house crap solution that I'm sure it is now.

OK, assuming you get a current-generation baseband chip for free (it actually costs a ton of money to develop) with full documentation, you're still talking hundreds of millions to develop that software. GSM (a 2G technology) is complicated. UMTS / HSPA (one of the 3G techs) is an order of magnitude more complex. LTE (4G) is another order of magnitude more complex than 3G. The baseband code, plus all the testing code, plus all the testing required by the FCC, standards bodies and the carriers is a ton of money.

It costs millions to take an existing chipset (which has already been approved), an existing baseband codebase (which has also already been approved for use with that chipset) and put that into a modem and get that approved.

The chip vendors have their own baseband code now, and they are all in fierce competition with each other. They aren't going to just use your code, and they aren't going to let you use their chips either.

Re: Blackphone

#138
post #114
post #8

How does this protect me from my carrier? No matter which phone I use they still need to record who I call for "billing purposes" and know which cell is closest to route my calls.

1) Buy prepaid card with data plan. 2) Access Internet (and VOIP) only via VPN or better yet TOR. 3) Only give out your VOIP number. No one must know your direct number, it’s only for emergencies. This severs all the important connections to make any use of that data, assuming you don’t have any leaks.

To expand on this, does anyone know of a reliable service provider (accepting bitcoins is a bonus) for SIP Trunking[0]? Or any VoIP workflow that can perform calls to PSTN[1] (the regular landline/mobile telephone network). Or even any VoIP provider that offers a basic answering service, where the voice mail box can be checked over the internet a la google voice/skype voicemail?

[0] https://en.wikipedia.org/wiki/SIP_Trunking

[1] https://en.wikipedia.org/wiki/Pstn

Edit: A quick search gave me this[2] by Plivo. Does any one know of any other options?

[2] http://plivo.com/blog/sip-trunking-to-replace-my-landline-ph...

Re: Blackphone

#139

The privacy issue in smartphones isn't the freaking application processor running Android. Sure, that ones terrible enough. But the actual problem is the baseband processor running completely non-free software, with an enormous attack surface and access to all the interesting periphery (GPS, microphone). There is not just opportunity to compromise your privacy, Qualcomm and others actively implement such features at…

I totally agree that adding privacy features to what is essentially a tracking device isn't addressing the right issues. Why not start out with simply a free, private laptop? Something that uses Coreboot and doesn't require any firmware driver blobs. This is something that so far, only one Chinese company has been able to do, albeit producing only a rather underpowered model [1]. Where are the private laptops that rival the Macbook Pro?

1. https://en.wikipedia.org/wiki/Lemote#Netbook_computers

Post reply on HN