Live data from Hacker News

Nobody’s Cellphone Is Really That Secure

theatlantic.com

21–30 of 76 posts

Re: Nobody’s Cellphone Is Really That Secure

#21
post #2

> Google now has its own phone—Pixel—that gets security updates quickly and regularly. The Nexus 5 line used to have this until Google decided after three years to stop supporting it despite the hardware continuing to last well beyond that.

The problem was hardware manufacturers ie processor etc would not support newer versions of the OS and kernals. Thats why they have come up with project treble with that you would be able to install newer versions of android long after they themselves stop giving updates.

That is what business contracts are for.

Treble doesn't help anything because OEMs are the ones still pushing updates, and only devices released with Oreo are oblieged to be compliant with Treble.

Which is why even in 2018 most new devices have been released with 7, upgradable to 8.

But I am glad OEMs keep ignoring Google, as they finally added update clasues on their licensing contracts.

After one year, Oero has achieved a meager 21.5%.

EDIT: 11% => 21.5%

Re: Nobody’s Cellphone Is Really That Secure

#22
post #12

Earlier quoted context omitted.

A three year old Nexus 5 won't be usable due to the battery anyway.

You can always change the battery.

But you often can't buy an original battery. And buying a fake battery can be magically worse than a depleted original battery.

Re: Nobody’s Cellphone Is Really That Secure

#23
> "I’d say that the major international powers like China and Russia...It’s safe to say that President Trump is not the only one being targeted..."

Who is doing it? Anyone - not just govs - that are capable, and where the reward outshines the risk.

Who are they doing it to? Anyone whose conversations offer (potential) rewards that outshine the costs / risks. Finding the critical nodes isn't that difficult. Hiding likely impossible.

Yea, ttat's a pretty wide net, and getting wider all the time.

Re: Nobody’s Cellphone Is Really That Secure

#24

> iPhones are harder to hack, which is reflected in the prices companies pay for new exploit capabilities. In 2016, the vulnerability broker Zerodium offered $1.5 million for an unknown iOS exploit and only $200 for a similar Android exploit. I'm curious, given the fragmentation of the Android ecosystem, how many phones each of those two exploits would affect.

I think there are several things driving up the prices of iPhone exploits:

1. Supply: iPhones are more secure so exploits are harder to come by

2. Demand: It is worth more money to break into an iPhone because the users are more likely to be wealthy or politically interesting (or rather, such people are more likely to own iPhones)

3. Demand: Fragmentation—an exploit for the latest iOS version is going to be able to hit a lot more phones than one for some version of Android (maybe limited to specific hardware too)

4. Supply: If Apple discover an exploit they will patch it and people will soon have software upgrades which counter it. Now that exploit is worthless and so the supply has decreased. When an Android exploit is discovered it will be fixed but those who were vulnerable probably won’t get updates and so there is no need for another exploit targeting that platform.

Re: Nobody’s Cellphone Is Really That Secure

#25
post #20

Earlier quoted context omitted.

Which is why you swap the battery - be careful of those nasty small plastic clips when you open the thing - after which it'll happily chug along for another 3 years. BTW, I'm using a number of 8 year old phones, with 8 year old batteries which still keep enough charge for about 2-3 days. A typical lithium-ion battery in typical operating conditions (i.e. body temperature, cycling between 20-40% and 100% charge) can g…

For me battery life in phones used heavily seems to typically loose 50% in two years and then rapidly become unusable. Which kind of sucks if they can barely last one day when they are brand new. Fakes are of course much worse, and getting original parts when you can't officially replace the battery can be very challenging. Yes, I still have a Nexus 5 I bought on launch day. Yes I've replaced the battery twice. Yes t…

Are you discharging the battery to very low levels regularly? That wreaks havoc on capacity. My two year old iPhone still reports 90% of its maximum capacity, but I can count the number of times I let it go below 20% on the fingers of my hands.

Re: Nobody’s Cellphone Is Really That Secure

#26
I would think the secrete service would put an always on VPN connection on cell phones, have all calls go through a self hosted VoIP service, and then the device is arguably as secure as any other computing device someone in the federal government with high security clearance might use.

Re: Nobody’s Cellphone Is Really That Secure

#27
post #20

Earlier quoted context omitted.

For me battery life in phones used heavily seems to typically loose 50% in two years and then rapidly become unusable. Which kind of sucks if they can barely last one day when they are brand new. Fakes are of course much worse, and getting original parts when you can't officially replace the battery can be very challenging. Yes, I still have a Nexus 5 I bought on launch day. Yes I've replaced the battery twice. Yes t…

Are you discharging the battery to very low levels regularly? That wreaks havoc on capacity. My two year old iPhone still reports 90% of its maximum capacity, but I can count the number of times I let it go below 20% on the fingers of my hands.

I'd say that 10% is very common, sometimes 20%, somtimes less than 10.

But to combat this my previous phone was a moto z with a battery-mod that kept it at 80%. But the constant charging/discharging was probably too much for it. After 20 months the battery was beyond useless without the battery-mod.

And I only did the above to be able to prolong the life of the phone, yet it lasted much shorter than any previous phone I've had.

Re: Nobody’s Cellphone Is Really That Secure

#28
post #16
post #9

Earlier quoted context omitted.

> They may keep up to date with patches, but you have very little knowledge or control of what they collect from you and what they do with it. It's not an ominous mystery. Google is extremely explicit about what they collect from you and what they do with it. https://myaccount.google.com/privacy https://policies.google.com/privacy I have not seen any evidence that they violate their own policies, even when I worked t…

If you were an engineer working at Google on one of the services that handles, say, location data from phones, how difficult would it be for you to go into the environment and find a specific person's location history? Also, what logging or other audit trail is there for that access?

FWIW, the ex-googlers I've asked about this claim it would be very hard for an individual to do this surreptitiously. One even claimed that Larry Page would probably get caught if he tried.

Re: Nobody’s Cellphone Is Really That Secure

#29
post #20

Earlier quoted context omitted.

For me battery life in phones used heavily seems to typically loose 50% in two years and then rapidly become unusable. Which kind of sucks if they can barely last one day when they are brand new. Fakes are of course much worse, and getting original parts when you can't officially replace the battery can be very challenging. Yes, I still have a Nexus 5 I bought on launch day. Yes I've replaced the battery twice. Yes t…

Are you discharging the battery to very low levels regularly? That wreaks havoc on capacity. My two year old iPhone still reports 90% of its maximum capacity, but I can count the number of times I let it go below 20% on the fingers of my hands.

you also have to consider the climate that the user lives in. one can be very diligent about discharge levels, but if you spend a lot of time outside in the heat, you are subjecting the battery to worst case operating conditions a lot.

Re: Nobody’s Cellphone Is Really That Secure

#30
post #16
post #9

Earlier quoted context omitted.

> They may keep up to date with patches, but you have very little knowledge or control of what they collect from you and what they do with it. It's not an ominous mystery. Google is extremely explicit about what they collect from you and what they do with it. https://myaccount.google.com/privacy https://policies.google.com/privacy I have not seen any evidence that they violate their own policies, even when I worked t…

If you were an engineer working at Google on one of the services that handles, say, location data from phones, how difficult would it be for you to go into the environment and find a specific person's location history? Also, what logging or other audit trail is there for that access?

From the Google people I've talked to, the easiest way to get fired at Google is to inappropriately gain access to user data.

And yes there is anaudit trail on accessing that stuff.

Post reply on HN