Live data from Hacker News

Blackphone

store.blackphone.ch

21–30 of 102 posts

Re: Blackphone

#21
post #13

A prerequisite for security is free software. Critical applications like the Silent Circle ones are proprietary, afaict. I have zero trust in the Blackphone and would not purchase one.

This Verge article [1] says “The company will open source the vast majority of its code for the phone in order for third parties to properly audit its techniques, find holes, and ultimately help to improve the product.” 1. http://www.theverge.com/2014/2/24/5441642/blackphone-silent-...

If they do, that would go a long way to convincing me this is a tidbit more secure than any other random Android device.

They should really have released their code at the same time they released their phone though.

Re: Blackphone

#22
post #5

I hate to break it to you, but this is not going to keep you safe from a state-level adversary. I could drone on about this for pages and pages, but the sad fact is that if you are a target, it doesn't matter that you are using a "secure phone", "secure OS", or "encryption". Time and time again, these systems have been broken or breached with simple tradecraft and subtle sabotage. The Pentagon has a concerted (and ex…

So in fewer words, your solution to state spying is "don't even try fighting it".

Re: Blackphone

#23
post #17
post #5

I hate to break it to you, but this is not going to keep you safe from a state-level adversary. I could drone on about this for pages and pages, but the sad fact is that if you are a target, it doesn't matter that you are using a "secure phone", "secure OS", or "encryption". Time and time again, these systems have been broken or breached with simple tradecraft and subtle sabotage. The Pentagon has a concerted (and ex…

Generally, there are some trivial precautions that will frustrate all but the most concentrated effort. Things like TRESOR, grsecurity, /boot on an USB stick, etc.

Uh huh. What if I have a deal with Intel and your TRESOR code compiled into the kernel is easily profiled by the microcode and the key is itself silently transmitted/stored by the CPU?

Same with your USB stick.

Go read up on how the CIA sabotaged the Iranian nuclear enrichment centrifuges by compromising the supply chain of the power supplies (not the computer controls).

Re: Blackphone

#24
post #4

Transparently marketing fear. Apparently this phone is for you if you ever [0]: > speak personally with a partner > worry about your kids Shameful. [0] https://www.blackphone.ch/individuals/

I think most people need some fear about state spying. Most are still treating it like it's no big deal. It's like the Stasi are here and no one gives a damn. That should scare people. Maybe we're deeper into Huxley's world than we thought.

Re: Blackphone

#25
post #5

I hate to break it to you, but this is not going to keep you safe from a state-level adversary. I could drone on about this for pages and pages, but the sad fact is that if you are a target, it doesn't matter that you are using a "secure phone", "secure OS", or "encryption". Time and time again, these systems have been broken or breached with simple tradecraft and subtle sabotage. The Pentagon has a concerted (and ex…

So in fewer words, your solution to state spying is "don't even try fighting it".

No. It's UNDERSTAND YOUR ADVERSARY.

If I'm trying to protect myself from hackers, I choose one route. From my ISP, another. From FB/Google, another.

And from my government or your government, yet another.

What's missing here is honest dialogue about the limits of the technology. The best technology has yet to save people from their own foolishness.

Re: Blackphone

#26

It's a bit disconcerting to see that it comes with software "enabled for at least 2 years of usage".

Why? I believe that sentence refers to extra software/services that’d normally be paid.

Re: Blackphone

#28
post #8

For $629 you could by quite a few one-time or short-time use trac phones that you buy with cash. Wouldn't that be more secure/private than this?

Maybe if you speak in code the whole time, and never reveal the identities of both of you. The contents of the conversation will not be secure, so you have to assume they are hearing it, but don't understand what you're talking about. That may be a little difficult.

Re: Blackphone

#29
I am not sure why do anyone needs that.

You can have basically secure messaging on the phone today. You can use Replicant (libre software) on many phones where there probably are no backdoors, you can use OTR with Xabber (you can build it yourself), there are probably applications for PGP too.

Yeah, Replicant will fail to work on many phones and on those that work, half of the functionality is missing ( http://redmine.replicant.us/projects/replicant/wiki/Replican... ) - but trying to sell non-free phone as "secure" is snake-oil anyway. In my humble opinion.

Re: Blackphone

#30
post #5

I hate to break it to you, but this is not going to keep you safe from a state-level adversary. I could drone on about this for pages and pages, but the sad fact is that if you are a target, it doesn't matter that you are using a "secure phone", "secure OS", or "encryption". Time and time again, these systems have been broken or breached with simple tradecraft and subtle sabotage. The Pentagon has a concerted (and ex…

> I hate to break it to you, but this is not going to keep you safe from a state-level adversary.

I don't really like this kind of anti-crypto argument. At this point I think making normal communications between normal people less embarrassingly mass-snoopable is a very worthy goal. For the time being, people who really, really have something to hide need to be extra careful (as has always been the case).

Which is not to say I'm feeling particularly enthusiastic about this device.

Post reply on HN