Live data from Hacker News

Blackphone

blackphone.ch

191–200 of 210 posts

Re: Blackphone

#191
post #168
post #167

Earlier quoted context omitted.

I'm curious what you'd like to see in a travel router. Is it mainly the software or hardware you think needs work, or both? On the software front, I have an OpenWRT image which I think works pretty well for travel which I've been meaning to publish (routes all traffic over an OpenVPN tunnel and can act simultaneously as a WIFI client to the hotel network and as an access point for your own network). The hardware is n…

Hardware. USB powered. Dual radio, ideally dual dual band (so 4 radios which can be 1-4 in use). Ethernet port. Probably a USB port for 4g. Ideally a good form factor. Probably no battery, use a USB battery or laptop. My goal would be to never ever connect my devices to wifi, and run everything through the device. There are lots of attempts to make current hw work for this, but while you can get close, nothing is goo…

For a portable firewall/router, I use a cubieboard running OpenBSD. It has a USB to DC cable that powers the device (no hdd attached) and runs LTE sticks fine. Costs $50 and runs a complete install to run Tor or whatever you want. Right now I have it running pf filtered VLANs to segregate devices, an authenticated AES wireless hotspot and Jondonym mix, which I tunnel all traffic through including Tor and i2p traffic. That way the local wireless carrier who you're using doesn't see any tor traffic.

Re: Blackphone

#192

Earlier quoted context omitted.

Fully support the initiative for an open baseband. I would love to live in a world where this can happen. But we don't live in that world. The carriers have paid billions of dollars for exclusive use of their frequency bands. And their hundreds of billions of dollars of revenue depend upon smooth operation of all devices on the network using those bands. They will use whatever means to protect this. OK, so let's talk…

I don't understand. If I come to a carrier and say "Here's a codebase for your baseband. It's OSS, well tested, secure, and supported. Buy support from me." why won't they go for it. Surely, an OSS solution is cheaper for them than developing an in-house crap solution that I'm sure it is now. Also, is there any harm in just open sourcing their baseband code? It seems to me that it's worthless without the license to u…

If it's OSS, then users are empowered to modify the code for their own purposes in ways that degrade or deny service to others.

Code could be released for inspection, but you can't be allowed to actually run modified code on real radios outside of RF-isolated testing facilities.

Re: Blackphone

#193
post #56

Completely useless web page. All wooly 'feel-good' words and no hard, concrete information. So I guess we just have to take it on trust then? Also, their privacy policy is laughable: We turn the logging level on our systems to log only protocol-related errors - great! the pages on our main web site pull in javascript files from a third party. This allows our web developers and salespeople to know which pages are bein…

"Blackphone is re-shaping the landscape of personal communications. Pre-ordering begins..." How is it re-shaping anything before it's started shipping?

They should have s/re-shaping/disrupting/g if/when the referrer is HN.

Re: Blackphone

#194

With all the respect what they have done so far, I can't see any reason why this is securer than the other mobile phones.. With the latest NSA stuff, I came to conclusion that a true secure system can only be built under these conditions and just to put it out there, this is just my opinion; - A computer company that manufactures their own hardware such as hard drive, ram, cables, network cards. - An OS that is newly…

You're probably right about what's involved in building a truly secure smartphone from scratch that we can trust. It's an interesting thought experiment, but I wonder if we can satisfy many use cases without having to build a truly secure smartphone. For example, if I just want to have voice calls to a handful of people with the content of the calls encrypted, then perhaps I can just plug in a "scrambler box" between…

"Sounds like a hardware kickstarter project :)" Exactly!!!

We may as well try it out! The concern will be the goal of the project...

What will be the output ?

Will it be just an experiment or business based project?

Never the less, it is exciting to see that a unique device can be made actually!

I would love to see how secure it would be at the end!

Re: Blackphone

#195
post #82

As others have pointed out, the baseband is not your friend. Was thinking about this recently, and saw no reason why existing POCSAG (pager) networks couldn't be reused to provide a completely passive receiver. Imagine a phone where the baseband was off by default, unless attempting to make a call. Voicemail/e-mail summaries were broadcast encrypted via POCSAG, and generate notifications just like a new mail summary…

I'd imagine the POCSAG network would be quite overloaded, quite quickly. It doesn't have a lot of bandwidth, and unless the network knows where you are, messages destined to you would have to be broadcast everywhere.

Re: Blackphone

#196
post #27
post #8

How does this protect me from my carrier? No matter which phone I use they still need to record who I call for "billing purposes" and know which cell is closest to route my calls.

You could use p2p VoIP.

They could still track you though. You'll need a sim card, and you'll need to attach to the network - which means the carrier can track your location.

Re: Blackphone

#197

Earlier quoted context omitted.

I don't understand. If I come to a carrier and say "Here's a codebase for your baseband. It's OSS, well tested, secure, and supported. Buy support from me." why won't they go for it. Surely, an OSS solution is cheaper for them than developing an in-house crap solution that I'm sure it is now. Also, is there any harm in just open sourcing their baseband code? It seems to me that it's worthless without the license to u…

If I come to a carrier and say "Here's a codebase for your baseband. The carriers don't want baseband code, they just want finished products to sell. It's OSS, well tested, secure, and supported. Buy support from me." why won't they go for it. Surely, an OSS solution is cheaper for them than developing an in-house crap solution that I'm sure it is now. OK, assuming you get a current-generation baseband chip for free…

Are you aware of Fabrice Bellard's 4G LTE software base station?

http://bellard.org/lte/

Re: Blackphone

#198
post #74

Earlier quoted context omitted.

The idea is that your "high side" device is a phone, with all your apps, etc. It communicates over a well defined interface (USB seems like the best, but bt or wifi could be adequate given certain considerations) to a fully-functional mifi dongle or whatever which does normal cell/public-wifi/etc. functionality. No compromise of the external cell modem can get at high side data. The current "baseband can DMA your mai…

Snapdragon and every other baseband coming out has them on an 'all in one' chip which is application CPU and baseband sharing direct memory. Unless you have a microscope you can't build a hw firewall. Cryptophone uses an older Samsung to do this but has no SIM protection. The firewall isn't foolproof either it only detects extended use of the baseband cpu without the application cpu being busy then shuts down the dev…

How can having two phones be an indicator that you are up to something? It is extremely common for working professionals to have both a personal mobile and a company mobile these days.

Re: Blackphone

#199

Earlier quoted context omitted.

Snapdragon and every other baseband coming out has them on an 'all in one' chip which is application CPU and baseband sharing direct memory. Unless you have a microscope you can't build a hw firewall. Cryptophone uses an older Samsung to do this but has no SIM protection. The firewall isn't foolproof either it only detects extended use of the baseband cpu without the application cpu being busy then shuts down the dev…

How can having two phones be an indicator that you are up to something? It is extremely common for working professionals to have both a personal mobile and a company mobile these days.

They do really complex analysis of patterns of how phones move, how they're powered up, call history, etc. It's actually really fascinating if you think about it and dig into it a bit, just like being able to largely identify (and sometimes effectively decipher) network traffic through analysis of encrypted message flows.

Just carrying two phones with you isn't the most interesting thing; it's a pair of people who normally have one phone during normal activity, and then at some location turn that phone off and turn on another phone which isn't used for anything except calling the other person briefly and hanging up without saying anything, and then those phones moving closely together, etc.

In my proposed case, there's no actual "second phone" on the cellphone network; your "phone" is a wifi only device which talks to a box which talks over data.

Traffic analysis is one of the things NSA does exceptionally well; the open crypto world is like 5 and maybe NSA is 7, but the open traffic analysis world is more like 2 and NSA is a 9.

Post reply on HN