Live data from Hacker News

Blackphone

blackphone.ch

31–40 of 210 posts

Re: Blackphone

#31
post #25

How difficult is it really to make a truly open source phone ? All it takes is one dedicated hardware company and a software company coming together. Hackers have built some amazing hardware in past and we all know about how open source communities have built some of worlds best software. Google, Apple etc. are building devices where they act as gatekeepers and charge us for all nonsensical stuff. If you make a websi…

Openmoko did that before Android. Sadly, it had a very lukewarm response owing to a not-so-good hardware.

Re: Blackphone

#32

I'm weird enough to be interested in these kind of things, but the whole site is really .. just fluff. Ignoring that and focusing on the sparse details of the actual thing: - High-End Android device - Privacy features in the (custom) Android version - "Secure communication builtin" Again, I like the idea. But so far the details match CyanogenMod (with TextSecure for SMS, maybe XPrivacy on top)?

Yes, looks like an Android powered device. So, at the end is just another OS right?

One of the big drawbacks when I first started my nexus5 was that I was being spyed. Why the hell do I need a gmail account to get started?!

I wonder if it would be possible to install this Android flavour in a Nexus device ?

Re: Blackphone

#33
The privacy issue in smartphones isn't the freaking application processor running Android. Sure, that ones terrible enough.

But the actual problem is the baseband processor running completely non-free software, with an enormous attack surface and access to all the interesting periphery (GPS, microphone). There is not just opportunity to compromise your privacy, Qualcomm and others actively implement such features at the behest of governments and carriers.

Oh, and if you plug that enormous hole, you get to the SIM card, yet another processor that you have zero control over, but which has access to enough juicy data to compromise your privacy. I highly recommend everyone to watch a talk from 30C3 by Karsten Nohl, where he shows a live attack on an improperly configured SIM card that remotely implants a Java app on the SIM card which continuously sends your cell ID (your approximate location) to the attacker by short message (without notification to the application processor, e.g. Android or iOS):

http://www.youtube.com/watch?v=5B7XyVWgoxg

Carriers can do this today. (edit: that's a bit nonsensical, because carriers of course already know your cell id. Anyone with the ability to run a fake basestation momentarily (think IMSI catcher) can do this.)

Re: Blackphone

#34

Completely useless web page. All wooly 'feel-good' words and no hard, concrete information. So I guess we just have to take it on trust then? Also, their privacy policy is laughable: We turn the logging level on our systems to log only protocol-related errors - great! the pages on our main web site pull in javascript files from a third party. This allows our web developers and salespeople to know which pages are bein…

Expecting people to write their own metrics stack for a promo site is a bit OTT - there are a lot of good analytics stacks out there which let you get up and running very quickly, complete with dashboards, metrics, etc.

Re: Blackphone

#35
post #32

I'm weird enough to be interested in these kind of things, but the whole site is really .. just fluff. Ignoring that and focusing on the sparse details of the actual thing: - High-End Android device - Privacy features in the (custom) Android version - "Secure communication builtin" Again, I like the idea. But so far the details match CyanogenMod (with TextSecure for SMS, maybe XPrivacy on top)?

Yes, looks like an Android powered device. So, at the end is just another OS right? One of the big drawbacks when I first started my nexus5 was that I was being spyed. Why the hell do I need a gmail account to get started?! I wonder if it would be possible to install this Android flavour in a Nexus device ?

You don't actually need a gmail account for what its worth - Google just makes it difficult. On the screen where it requests a login you (seriously) need to tap each corner of the screen in clockwise order starting from the top left. That should skip the step.

Re: Blackphone

#36
post #25

How difficult is it really to make a truly open source phone ? All it takes is one dedicated hardware company and a software company coming together. Hackers have built some amazing hardware in past and we all know about how open source communities have built some of worlds best software. Google, Apple etc. are building devices where they act as gatekeepers and charge us for all nonsensical stuff. If you make a websi…

The baseband or "The secret second operating system that could make every mobile phone insecure". It's used by all phones and it's unsecure. Do they rely on the same baseband? Source: http://www.extremetech.com/computing/170874-the-secret-secon...

Re: Blackphone

#37
post #21

This maybe a bit off topic but, why did Switzerland get the .ch domain instead of china. China seems to have a lousy CN domain ,( which reminds me of cartoon network for reasons that are irrelevant here).

Same reason the abbreviation for the Swiss Franc is CHF.

Re: Blackphone

#38

The privacy issue in smartphones isn't the freaking application processor running Android. Sure, that ones terrible enough. But the actual problem is the baseband processor running completely non-free software, with an enormous attack surface and access to all the interesting periphery (GPS, microphone). There is not just opportunity to compromise your privacy, Qualcomm and others actively implement such features at…

Came here to say this exactly. The world needs an open-source baseband processor/firmware.

Re: Blackphone

#39
Android having the most granular permission system ever seen on any operating system is already the most secure operating system.

The biggest security hole next to the baseband processor and the SIM is the user who installs every app in seconds without checking permissions.

Re: Blackphone

#40
True privacy on a smartphone can only be expected when software and hardware are 100% open sourced. This of course includes the source code for the 3 Os's that typically run on a smartphone. Anything that's running server-side cannot be trusted either. So we need client-side encryption/decryption as well.
Post reply on HN