Live data from Hacker News

Blackphone

store.blackphone.ch

31–40 of 102 posts

Re: Blackphone

#31
How compatible is the OS with 'normal' android apps?

Since 4.4 I have been able to, at least to some level, revoke some basic rights that apps have, like seeing my contacts (through app shield or whatever). If I am able to download apps from the 'normal' Android store, is access that those apps have somehow controlled as well? Some sort of sandbox mode would be nice.

Re: Blackphone

#32
post #5

I hate to break it to you, but this is not going to keep you safe from a state-level adversary. I could drone on about this for pages and pages, but the sad fact is that if you are a target, it doesn't matter that you are using a "secure phone", "secure OS", or "encryption". Time and time again, these systems have been broken or breached with simple tradecraft and subtle sabotage. The Pentagon has a concerted (and ex…

> When I need to communicate secretly I BUY SOMEONE A BEER. Hi Richard, it has come to our attention that you have been secretively discussing leaking government information to our enemy in a pub in central London. What's that you say? You didn't discuss private information? Then why did you try to conceal your handwriting on the napkin from our CCTV security cameras? We'd like to take you in for questioning. If you…

The Soviets used to have a custom of taking long walks in the park when they wanted to have a private conversation.

It had the notable benefit of avoiding the hidden listening devices in their places of work/rest/play.

Re: Blackphone

#33
I hate this circlejerk around privacy.

Not as a concept though. It seems like every geek-oriented app or device is "private and secure" with "state-of-the-art encryption capabilities" nowadays, even though they continue to use pretty much same software and hardware as they did a year ago, before Snowden.

As for this phone -- they don't even have exact specifications and they plan to ship it in June, just four months away. Come on, ">2GHz Quad Core CPU" is a placeholder and not a real deal, especially with a "certain specifications are subject to change" in small font. I do not think that it will be released in June, and, if it will actually be released, I don't really think it will get popular enough to break the "friends and relatives of the developer" barrier.

I may be a little too tough (sorry!), but I got really tired of all these startups that propose nothing new besides illusive security with a bad implementation.

Re: Blackphone

#34
post #30
post #5

I hate to break it to you, but this is not going to keep you safe from a state-level adversary. I could drone on about this for pages and pages, but the sad fact is that if you are a target, it doesn't matter that you are using a "secure phone", "secure OS", or "encryption". Time and time again, these systems have been broken or breached with simple tradecraft and subtle sabotage. The Pentagon has a concerted (and ex…

> I hate to break it to you, but this is not going to keep you safe from a state-level adversary. I don't really like this kind of anti-crypto argument. At this point I think making normal communications between normal people less embarrassingly mass-snoopable is a very worthy goal. For the time being, people who really, really have something to hide need to be extra careful (as has always been the case). Which is no…

It's not anti-crypto. It's PRO-tradecraft.

Introducing technology into a system can WEAKEN your security. Knowing that is almost 90% of the battle.

Re: Blackphone

#35
post #32

Earlier quoted context omitted.

> When I need to communicate secretly I BUY SOMEONE A BEER. Hi Richard, it has come to our attention that you have been secretively discussing leaking government information to our enemy in a pub in central London. What's that you say? You didn't discuss private information? Then why did you try to conceal your handwriting on the napkin from our CCTV security cameras? We'd like to take you in for questioning. If you…

The Soviets used to have a custom of taking long walks in the park when they wanted to have a private conversation. It had the notable benefit of avoiding the hidden listening devices in their places of work/rest/play.

There can be mikes in the park too, of course. In 1984 there are, IIRC.

Re: Blackphone

#36
post #25

Earlier quoted context omitted.

So in fewer words, your solution to state spying is "don't even try fighting it".

No. It's UNDERSTAND YOUR ADVERSARY. If I'm trying to protect myself from hackers, I choose one route. From my ISP, another. From FB/Google, another. And from my government or your government, yet another. What's missing here is honest dialogue about the limits of the technology. The best technology has yet to save people from their own foolishness.

But that seems a little like saying "the Internet is a spying machine - don't use it if you want privacy". I just think that's way too defeatist for my taste. If the Internet is a spying machine, then we need to find a way to communicate securely on it. I feel the same way about the phones.

Both the Internet and mobile phones are here to stay, and billions use them. You can't just say "don't use them". That's a big cop-out.

You can choose not to use certain providers, like using DDG instead of Google, or using Blackphone instead of the iPhone 5S. But you can't just use blanket statements like "don't use anything that's a big part of everyone's lives today."

Security is never a guaranteed thing - with or without NSA. That doesn't mean you shouldn't do your best to secure yourself. I feel the same about Blackphone. Granted, I'd prefer something that's fully open source, and I think those solutions are coming (perhaps an even more secure version of CyanogenMod with TextSecure v2 and RedPhone integrated into it), but I think every little bit helps, and I do think we're moving in the right direction - securing our conversations and networks. It's a process, not a goal.

Re: Blackphone

#37
post #25

Earlier quoted context omitted.

So in fewer words, your solution to state spying is "don't even try fighting it".

No. It's UNDERSTAND YOUR ADVERSARY. If I'm trying to protect myself from hackers, I choose one route. From my ISP, another. From FB/Google, another. And from my government or your government, yet another. What's missing here is honest dialogue about the limits of the technology. The best technology has yet to save people from their own foolishness.

We really need to rewrite the entire stack, carefully and with the intent of security, from open-source-DIY hardware up, to have any trust in technology.

Re: Blackphone

#40
Shipping in June is not exactly 'here'. Come back when independent people can verify and reproduce the software it is running.

Open sourcing "vast majority of its code" is not good enough -- this thing is selling security and if you can't rebuild it all yourself there's really no point.

Post reply on HN