Live data from Hacker News

Blackphone

store.blackphone.ch

41–50 of 102 posts

Re: Blackphone

#41
post #23
post #17

Earlier quoted context omitted.

Generally, there are some trivial precautions that will frustrate all but the most concentrated effort. Things like TRESOR, grsecurity, /boot on an USB stick, etc.

Uh huh. What if I have a deal with Intel and your TRESOR code compiled into the kernel is easily profiled by the microcode and the key is itself silently transmitted/stored by the CPU? Same with your USB stick. Go read up on how the CIA sabotaged the Iranian nuclear enrichment centrifuges by compromising the supply chain of the power supplies (not the computer controls).

In that case, airgap and strict media discipline (once media touches the secure network, it's never used on insecure networks again) should do, no?

But my point is that most us aren't foreign states trying to make nuclear reactors against the wishes of a superpower. We're more worried about things like common theft and border seizures.

Re: Blackphone

#42
post #5

I hate to break it to you, but this is not going to keep you safe from a state-level adversary. I could drone on about this for pages and pages, but the sad fact is that if you are a target, it doesn't matter that you are using a "secure phone", "secure OS", or "encryption". Time and time again, these systems have been broken or breached with simple tradecraft and subtle sabotage. The Pentagon has a concerted (and ex…

> I hate to break it to you, but this is not going to keep you safe from a state-level adversary.

The creators acknowledged that fact [1]: "There is no such device that is NSA-proof," said Mike Janke, co-founder and CEO of Silent Circle, in an interview with Mashable, ahead of the launch. "If you are on the terrorist wanted list or a criminal, intelligence services will get into your device... There's no such thing as 100% secure phone."

[1] http://mashable.com/2014/02/24/what-is-blackphone/

(For a humorous take on nation-state threat models, read the hilarious usenix article This World of Ours by James Mickens: http://research.microsoft.com/en-us/people/mickens/thisworld...)

Re: Blackphone

#43
post #34
post #30

Earlier quoted context omitted.

> I hate to break it to you, but this is not going to keep you safe from a state-level adversary. I don't really like this kind of anti-crypto argument. At this point I think making normal communications between normal people less embarrassingly mass-snoopable is a very worthy goal. For the time being, people who really, really have something to hide need to be extra careful (as has always been the case). Which is no…

It's not anti-crypto. It's PRO-tradecraft. Introducing technology into a system can WEAKEN your security. Knowing that is almost 90% of the battle.

I think you're focusing on people who are under a specific, clear and present surveillance threat. Different arguments apply to those people to the majority of people who "value their privacy" in a more nebulous sense.

Re: Blackphone

#44
post #29

I am not sure why do anyone needs that. You can have basically secure messaging on the phone today. You can use Replicant (libre software) on many phones where there probably are no backdoors, you can use OTR with Xabber (you can build it yourself), there are probably applications for PGP too. Yeah, Replicant will fail to work on many phones and on those that work, half of the functionality is missing ( http://redmin…

Yes, one can do all that but I think the market Blackphone is going for is the paranoid but less tech savvy crowd that wants a working solution out of the box. I am not saying this implementation is an actual working solution...

Re: Blackphone

#45
post #4

Transparently marketing fear. Apparently this phone is for you if you ever [0]: > speak personally with a partner > worry about your kids Shameful. [0] https://www.blackphone.ch/individuals/

I think most people need some fear about state spying. Most are still treating it like it's no big deal. It's like the Stasi are here and no one gives a damn. That should scare people. Maybe we're deeper into Huxley's world than we thought.

Amusingly enough, I think a large part of why people aren't more scared are sentiments like the ones you just expressed. It is plainly not "just like the Stasi are here" and the average person can see that. By overstating the threat we de-legitimise our concerns and apathy grows (similar to the effect the DARE program had on drug use). Is the expansion of state level surveillance cause for concern? Of course it is! However, we are by no means living in a police state and saying so is an insult towards the people working very hard to effect policy to keep it that way. In short, in my opinion, we should spread less fear mongering and more political activism if we want to see change in these policies.

Re: Blackphone

#46
post #30
post #5

I hate to break it to you, but this is not going to keep you safe from a state-level adversary. I could drone on about this for pages and pages, but the sad fact is that if you are a target, it doesn't matter that you are using a "secure phone", "secure OS", or "encryption". Time and time again, these systems have been broken or breached with simple tradecraft and subtle sabotage. The Pentagon has a concerted (and ex…

> I hate to break it to you, but this is not going to keep you safe from a state-level adversary. I don't really like this kind of anti-crypto argument. At this point I think making normal communications between normal people less embarrassingly mass-snoopable is a very worthy goal. For the time being, people who really, really have something to hide need to be extra careful (as has always been the case). Which is no…

This line of reasoning is sound; it's better than the current situation, and it's likely to work for a while as a minority solution to unsurveilled communications.

For a discussion of the _huge_ value of _international_ telecommunications, which can't be replicated by in-person communication, I reccomend "Talking to Vula" by the ANC (who were considered a terrorist group in many countries for a long time): http://www.anc.org.za/show.php?id=4693

Re: Blackphone

#48
post #5

I hate to break it to you, but this is not going to keep you safe from a state-level adversary. I could drone on about this for pages and pages, but the sad fact is that if you are a target, it doesn't matter that you are using a "secure phone", "secure OS", or "encryption". Time and time again, these systems have been broken or breached with simple tradecraft and subtle sabotage. The Pentagon has a concerted (and ex…

Simplest way doesn't mean it's the best nor that it's always an option.

First of all, if you're under targetted surveillance, you're possibly better using electronic communications than meeting in-person. Then, it's not always possible to meet in person.

Re: Blackphone

#49
It seems like just avoiding mainstream popular services is enough to regain a lot of privacy, if the agencies look no further than Verizon, Google, Twitter, Facebook. They know exactly what my parents activities are.

Re: Blackphone

#50
post #13

A prerequisite for security is free software. Critical applications like the Silent Circle ones are proprietary, afaict. I have zero trust in the Blackphone and would not purchase one.

This Verge article [1] says “The company will open source the vast majority of its code for the phone in order for third parties to properly audit its techniques, find holes, and ultimately help to improve the product.” 1. http://www.theverge.com/2014/2/24/5441642/blackphone-silent-...

"the vast majority" is exactly not enough.
Post reply on HN