Live data from Hacker News

A review of the Blackphone, the Android for the paranoid

arstechnica.com

41–50 of 58 posts

Re: A review of the Blackphone, the Android for the paranoid

#41
post #15

This has a closed source baseband that was also not designed by the company producing the phone. The baseband is pretty much guaranteed to be backdoored by your favorite state security agency, so why get this over any other Android phone?

I remember getting the OpenMoko phone and pretty sure this was an issue way back then

It always was an issue and still will be for a long time. Neo900 project takes another way to neutralize the modem - by sandboxing and monitoring its activity. This alone probably makes it much more secure and privacy-friendly than Blackphone.

Re: A review of the Blackphone, the Android for the paranoid

#42

Earlier quoted context omitted.

The most crucial step in that recipe is using a device without a GSM baseband. That rules out anything sold as a 'phone,' such as the OnePlus One.

I think that's possibly overkill. Provided the baseband processor is independent of the apps processor, communicates over a managed bus (usb, high speed serial, dedicated dual-port ram), instead of having direct access to main system memory, and the apps processor has the ability to power it up and down at will, you're in a pretty good state and you can still hop on a cellular voice or data network when you want to.…

Which phones have this memory architecture vs. dma?

Re: A review of the Blackphone, the Android for the paranoid

#43
post #9

No mention of the baseband source code. Unless everything running on the phone is open source, there cannot be a guarantee of privacy.

If i understand it correctly there is no open source baseband available because of various patented technologies and it is imposible to create one. But why not treat the baseband as part of insecure transit network? I'd like to see phone where voice data and text messages would be securely encrypted before sending to baseband chip and securely decrypted on the other side. I think there would be great demand for such…

I think its because the baseband processor can access the microphone, screen and RAM semi-directly so its pointless having any encryption when you can just "key log" the screen as the user inputs the message. Please someone correct me.

(I posted a sort of question below along these lines but not yet had a response)

Re: A review of the Blackphone, the Android for the paranoid

#44
post #38
post #32

One thing I hate about Android phones these days are the opt-out sync features. All my data is synced to a magical location, and once synced they can never be erased. If you make a single mistake, then all your data has been essentially stolen. For example, I created a 'Samsung account' to try out the heart rate monitor on S5. I didn't know that if I create an account like that, the phone instantly uploads (syncs) my…

Is Apple any better on this? I'm thinking that my next phone is going to be an iPhone because of the regular updates over Android, but is it as hard to stay away from iCloud and not accidentally send everything there?

There is absolutely no need to use iCloud with your iPhone and the settings page allows very fine grained selection of what should be synced through iCloud. I also have yet to find a 3rd party app that activates syncing through iCloud (of its content) automatically, this is generally all opt-in.

Re: A review of the Blackphone, the Android for the paranoid

#47
post #37
post #32

One thing I hate about Android phones these days are the opt-out sync features. All my data is synced to a magical location, and once synced they can never be erased. If you make a single mistake, then all your data has been essentially stolen. For example, I created a 'Samsung account' to try out the heart rate monitor on S5. I didn't know that if I create an account like that, the phone instantly uploads (syncs) my…

This looks more like a Samsung problem. AFAIK all Google services ask for explicit permission to do this.

When I took my first couple of (private) photos with my old galaxy nexus, my phone proudly informed me that my photos had been uploaded to Google plus. (They were marked private on plus - but the app was itching to share them with everybody.)

I was shocked and horrified. It might have been fixed since then - I've become much more paranoid and turn that crap off.

Re: A review of the Blackphone, the Android for the paranoid

#48

not to be a bummer, but it doesn't seem like anything special was done with this special purpose hardware. why go to the trouble to engineer and advertise this as a piece of security enhancing hardware when it's really just "PrivOS"? also, any plans on open sourcing "PrivOS"? did I miss something in the writeup? OSS modem firmware, OS wifi chipset, anything hardware or firmware related?

You're missing the fact that this can be sold (at an outrageous markup) to large enterprises and government agencies because it looks secure/private. Beyond that, it provides literally nothing that you can't install for free on any Android device. I could make you an equally "secure" or "private" device for $300 and an hour's time.

I think you missed this part of the article:

"What sells this phone is the software and services it is bundled with, which separately would sell for $879"

The software bundled with the phone makes the phone worth buying.

Re: A review of the Blackphone, the Android for the paranoid

#49

Earlier quoted context omitted.

If i understand it correctly there is no open source baseband available because of various patented technologies and it is imposible to create one. But why not treat the baseband as part of insecure transit network? I'd like to see phone where voice data and text messages would be securely encrypted before sending to baseband chip and securely decrypted on the other side. I think there would be great demand for such…

I think its because the baseband processor can access the microphone, screen and RAM semi-directly so its pointless having any encryption when you can just "key log" the screen as the user inputs the message. Please someone correct me. (I posted a sort of question below along these lines but not yet had a response)

Basically, baseband can read the RAM. If you can ram dump you can do virtually anything, including get encryption keys.

Re: A review of the Blackphone, the Android for the paranoid

#50
This phone seems like a better option for people worried about privacy http://www.cryptophone.de/en/company/news/gsmk-introduces-ne...

"Baseband firewall: Based upon three years of cutting-edge research in baseband processor security, the new patent-pending GSMK CryptoPhone Baseband Firewall™ offers unique protection against over-the-air attacks with constant monitoring of baseband processor activity, baseband attack detection, and automated initiation of countermeasures. A global first, the CryptoPhone 500’s Baseband Firewall provides a revolutionary line of defence against over-the-air attacks not available on any other product."

Post reply on HN