> Google now has its own phone—Pixel—that gets security updates quickly and regularly. The Nexus 5 line used to have this until Google decided after three years to stop supporting it despite the hardware continuing to last well beyond that.
Nobody’s Cellphone Is Really That Secure
41–50 of 76 posts
Re: Nobody’s Cellphone Is Really That Secure
#42> Google now has its own phone—Pixel—that gets security updates quickly and regularly. The Nexus 5 line used to have this until Google decided after three years to stop supporting it despite the hardware continuing to last well beyond that.
'No update' planned obsolescence.
of all the companies out there, i really doubt that google deliberately makes their phones obsolete. just look at how they run their phone business; i don't think they ever expect it to be a profit center.
Re: Nobody’s Cellphone Is Really That Secure
#43Earlier quoted context omitted.
three years of frequent updates is pretty much the best support you're going to get with any android phone. i personally love my pixel 2, but they sold about half as many pixels in 2017 as samsung sold phones in a week. [0][1] samsung does give monthly security updates to its flagship products, but it won't support anything for more than two years. i think it's clear that consumers don't actually give a shit about up…
> three years of frequent updates is pretty much the best support you're going to get with any android phone That’s one of the reasons why I finally switched to an iPhone Xs Max. Before that, I had a Nexus 5x. My last iPhone was the 3GS.
Re: Nobody’s Cellphone Is Really That Secure
#44Earlier quoted context omitted.
Google has amazing controls and audit capabilities around access to customer data. When I worked on the security team there the number of people who could access a specific person's data without an audit record and an alert being triggered was zero.
Is that for someone going through the user interface, or is it a fundamental feature of the database (or whatever)? In other words, is there no case where someone could log into a server and see some PII in a debugger or a direct query without being detected?
Logging into production servers is audited and triggers alarms. There's basically no-one who has "root" level access to a large number of boxes (when I left in 2013 there were only a handful of people who could login to arbitrary boxes and systems were being built so that their access would no longer be necessary). Logging into a server that holds live data would be investigated and so would running a custom query against a production database. The goal was to have it basically impossible for an engineer or admin to directly access data on boxes to force people to use the tools.
The tools themselves had a great permission system as well as a way for users to elevate their permissions in emergency (triggering an investigation). It worked well because it was also easy to create dummy databases to develop on (for example by requesting a database extract of your own location data).
In my career to date I have yet to see a more privacy conscious / secure approach to handling customer data.
Re: Nobody’s Cellphone Is Really That Secure
#45Earlier quoted context omitted.
'No update' planned obsolescence.
lol, so google can lose even more money selling you the next phone? of all the companies out there, i really doubt that google deliberately makes their phones obsolete. just look at how they run their phone business; i don't think they ever expect it to be a profit center.
Re: Nobody’s Cellphone Is Really That Secure
#46Nobody’s phone is really that secure... but an iPhone vulnerability costs more than an average Bay Area house, while an Android vulnerability is more like the cost of cleaning that house once. Edit: turns out the figure for an Android vulnerability is off by several orders of magnitude. What a garbage article!
Any stats/references to back that up? And does this extend to first party devices from Google as well?
Re: Nobody’s Cellphone Is Really That Secure
#47Nobody’s phone is really that secure... but an iPhone vulnerability costs more than an average Bay Area house, while an Android vulnerability is more like the cost of cleaning that house once. Edit: turns out the figure for an Android vulnerability is off by several orders of magnitude. What a garbage article!
Going to Zerodium itself [2] shows the same (in their rather weird little chart[3] at the bottom): They’ll pay up to $1.5million for a zero-click iOS remote jailbreak, and $200,000 for an Android Chrome RCE with sandbox escape.
[1] https://arstechnica.com/information-technology/2016/09/1-5-m...
Re: Nobody’s Cellphone Is Really That Secure
#48I submit for your approval: https://www.punkt.ch/en/mp02-4g-mobile-phone/
https://en.wikipedia.org/wiki/Nucleus_RTOS
Their new phone, the MP02, uses a cut down version of Android managed by Blackberry. Ostensibly, Blackberry has produced some secure devices in the past, but it's still Android, which is a large, complicated code base and the there're dozens of comments around here about the insecurities in the Android ecosystem. Now, given how cut down their version of Android is, is it more secure? Possibly, but I don't think Punkt or Blackberry has committed to releasing their source and, even if they did, it's a somewhat niche market, so it's not clear to me that an appropriate, public audit would occur.
I really do like this device and may end up buying one, but I'm not confident that this is the ultimate in secure devices that I'd love to have.
As an aside, it seems like all the 4G feature phones use Android or some derivative. Does anyone know why? I can find non-Android 2G feature phones, but 4G seems universally Android and it's not clear to me why a phone that can't run much for apps needs that.
Re: Nobody’s Cellphone Is Really That Secure
#49Nobody’s phone is really that secure... but an iPhone vulnerability costs more than an average Bay Area house, while an Android vulnerability is more like the cost of cleaning that house once. Edit: turns out the figure for an Android vulnerability is off by several orders of magnitude. What a garbage article!
Re: Nobody’s Cellphone Is Really That Secure
#50Nobody’s phone is really that secure... but an iPhone vulnerability costs more than an average Bay Area house, while an Android vulnerability is more like the cost of cleaning that house once. Edit: turns out the figure for an Android vulnerability is off by several orders of magnitude. What a garbage article!
The article (which says in 2016 Zerodium offered up to $1.5 million for an iOS zero day and only $200 for android) seems to have a typo. The source it links to [1] quotes $1.5 million for iOS and $200,000 for Android, which makes more intuitive sense. Going to Zerodium itself [2] shows the same (in their rather weird little chart[3] at the bottom): They’ll pay up to $1.5million for a zero-click iOS remote jailbreak,…