Nobody’s phone is really that secure... but an iPhone vulnerability costs more than an average Bay Area house, while an Android vulnerability is more like the cost of cleaning that house once. Edit: turns out the figure for an Android vulnerability is off by several orders of magnitude. What a garbage article!
Consider deleting your false statement, now that aaronharnly has posted a correction.
Nobody’s Cellphone Is Really That Secure
51–60 of 76 posts
Re: Nobody’s Cellphone Is Really That Secure
#52Earlier quoted context omitted.
> They may keep up to date with patches, but you have very little knowledge or control of what they collect from you and what they do with it. It's not an ominous mystery. Google is extremely explicit about what they collect from you and what they do with it. https://myaccount.google.com/privacy https://policies.google.com/privacy I have not seen any evidence that they violate their own policies, even when I worked t…
We know from the Snowden leaks that there were direct data links between Google and the NSA. Despite their vehement denials and public outrage, I still find it hard to believe that it was possible for the NSA to install such massive surveillance without some complicity from Google. Technically this might have been possible without any Google involvement, I agree with that, but given past involvement of other companie…
Your understanding of PRISM matches Greenwald's incorrect reporting, which was based on a high school dropout's misreading of some slides he found on the SharePoint system he administered. Greenwald could have gotten the story correct if he had bothered to run the documents by an expert first, but instead he made ridiculous errors like thinking that DITU is a government system running inside the companies' networks instead of the FBI's Data Intercept Technology Unit, whose court-ordered wiretaps PRISM actually accesses.
Re: Nobody’s Cellphone Is Really That Secure
#53https://www.theverge.com/platform/amp/circuitbreaker/2018/5/...
Re: Nobody’s Cellphone Is Really That Secure
#54Nobody’s phone is really that secure... but an iPhone vulnerability costs more than an average Bay Area house, while an Android vulnerability is more like the cost of cleaning that house once. Edit: turns out the figure for an Android vulnerability is off by several orders of magnitude. What a garbage article!
Re: Nobody’s Cellphone Is Really That Secure
#55Nokia 6.1 (2018 model) costs $270 USD with Android One (at least 2 years of monthly security updates), metal body, fingerprint sensor (no notch), headphone jack and hardware-based remote attestation for tamper detection. https://www.theverge.com/platform/amp/circuitbreaker/2018/5/...
Re: Nobody’s Cellphone Is Really That Secure
#56> Google now has its own phone—Pixel—that gets security updates quickly and regularly. The Nexus 5 line used to have this until Google decided after three years to stop supporting it despite the hardware continuing to last well beyond that.
three years of frequent updates is pretty much the best support you're going to get with any android phone. i personally love my pixel 2, but they sold about half as many pixels in 2017 as samsung sold phones in a week. [0][1] samsung does give monthly security updates to its flagship products, but it won't support anything for more than two years. i think it's clear that consumers don't actually give a shit about up…
The people that do give a shit pick ios. Security and updates was the #1 reason I moved from Android to iOS.
Re: Nobody’s Cellphone Is Really That Secure
#57Earlier quoted context omitted.
lol, so google can lose even more money selling you the next phone? of all the companies out there, i really doubt that google deliberately makes their phones obsolete. just look at how they run their phone business; i don't think they ever expect it to be a profit center.
Would you accept the same logic for the software in a car? I don't think it would be acceptable if e.g. Tesla, a company that relies heavily on software in the car, would stop fixing security (and safety) issues after three or even five years after you bought the car. Like the phone, you can still use it, but it might just not be safe anymore to do so. To prevent this problem and the waste of resources that goes with…
yeah, i would be pretty mad if my car stopped getting critical updates after three years, but there are a lot of reasons why this is not an apples-to-apples comparison. software defects in a car directly risk your physical safety. vulnerabilities in a phone can also have severe consequences, but it's a very different kind of risk.
let's also not forget that a new car costs at least fifteen times as much as a new phone, and cars are regularly driven for ten to twenty years before they are scrapped. during this time, the manufacturer is getting a steady stream of revenue from selling replacement parts that they can use to offset the cost of providing safety recalls for old models. and even car companies aren't obligated to do recalls after fifteen years.
> To prevent this problem and the waste of resources that goes with it, it would even be okay for me to have laws that sanctions abandoning software like this.
do you really think the typical consumer cares about updates or security? they don't buy a new phone because the old one isn't getting updates. they buy a new one because they've smashed the shit out of their old one or they just want a new thing. i'm not sure what "resources" would be saved by forcing phone manufacturers to support old models that consumers don't want anyway. you would just end up deleting the $100-200 range of phones.
Re: Nobody’s Cellphone Is Really That Secure
#58Earlier quoted context omitted.
Make no mistake: their phones are data gathering devices serving one master. They may keep up to date with patches, but you have very little knowledge or control of what they collect from you and what they do with it.
> They may keep up to date with patches, but you have very little knowledge or control of what they collect from you and what they do with it. It's not an ominous mystery. Google is extremely explicit about what they collect from you and what they do with it. https://myaccount.google.com/privacy https://policies.google.com/privacy I have not seen any evidence that they violate their own policies, even when I worked t…
Whether Google violates their policies today is the wrong question to ask. Nothing about these policies is long-term legally binding for Google and they can be changed on a whim.
While Google includes this language:
> We will not reduce your rights under this Privacy Policy without your explicit consent.
I'm not sure that covers them increasing their own rights to collect, share, and sell data.
Remember - nothing lasts forever. One day Google will be in a financially desperate situation and their investors will demand that they do anything they can to stop the losses. Meanwhile they will have a valuable trove of data on millions of people.
This is not just hypothetical. When Google decided that Google+ was a priority and only real names should be allowed many were forced to de-annonymize formerly anonymous Youtube and Gmail profiles or be removed from the service.
The only real way to assure the security and privacy of data is to not collect it. The only way ensure that the likes of Google/Apple/Facebook won't collect the data is through legislation that gives privacy policies real teeth when they're violated and gives users power to choose to reject changes to these policies in whole or in part.
Re: Nobody’s Cellphone Is Really That Secure
#59Nokia 6.1 (2018 model) costs $270 USD with Android One (at least 2 years of monthly security updates), metal body, fingerprint sensor (no notch), headphone jack and hardware-based remote attestation for tamper detection. https://www.theverge.com/platform/amp/circuitbreaker/2018/5/...
Can I unlock the bootloader?
Re: Nobody’s Cellphone Is Really That Secure
#60Earlier quoted context omitted.
If you were an engineer working at Google on one of the services that handles, say, location data from phones, how difficult would it be for you to go into the environment and find a specific person's location history? Also, what logging or other audit trail is there for that access?
Google has amazing controls and audit capabilities around access to customer data. When I worked on the security team there the number of people who could access a specific person's data without an audit record and an alert being triggered was zero.
If I had to trust a company with private data, there is no other company I would trust more to keep it safe from rogue employees and accidental leaks/hacks.