Live data from Hacker News

The protester's guide to smartphone security

privacyguides.org

51–60 of 246 posts

Re: The protester's guide to smartphone security

#51
post #44

Earlier quoted context omitted.

I meant at the server. We have no way to know that is running there.

The server is open source too. You could download it and run your own server, afaik.

Signal occasionally drops something that could be the server code.

When they were working on their cryptocurrency they didn't release anything for over a year.

Re: The protester's guide to smartphone security

#52

Earlier quoted context omitted.

While this is good info, it should also be known that in the USA, a judge (maybe and police officer?) can legally command you to unlock your phone via biometrics, but they cannot legally command you to unlock via password or passphrase. “Legally command” = command you to do something with the force of law, and legally punish you if you resist

The reasoning behind this is that your fingerprints and face etc. are public knowledge. Whereas you can retain your right to remain silent (about your password/PIN), failing to provide these aspects of your person can be viewed as not cooperating.

>The reasoning behind this is that your fingerprints and face etc. are public knowledge.

Not really. You can be compelled to give blood sample for alcohol testing, but your blood is hardly "public knowledge". Same thing with strip searches.

Re: The protester's guide to smartphone security

#53

Earlier quoted context omitted.

I wonder how useful purism phones are for this (all external communication, including GPS, has hardware shutoffs). They are expensive though...

Couldn't you achieve the same by just enabling airplane mode or similar on regular devices? I don't think niche devices with hardware killswitches should be necessary

My S23 enters airplane mode and the WiFi and Bluetooth are still connected... Airplane mode isn't what it used to be!

Re: The protester's guide to smartphone security

#54

Earlier quoted context omitted.

How safe is Bluetooth really? Cities has scanners used to track devices for monitoring road congestion, malls have scanners to measure foot traffic. I have to believe that anyone with access to stingray type of device can track Bluetooth as well.

Don’t both Apple and Android implement random BT MAC addresses specifically to prevent this kind of tracking?

How about my smartwatch, or my $29 earbuds? They are always conveniently near the 'random mac' and can be used to fingerprint.

Re: The protester's guide to smartphone security

#55
Also Meshtastic.org is a cheap (various It supports strong encryption layer and over 1 km/mile per “hop” in most circumstances.

Designed originally for off grid, it’s very flexible and pretty polished.

Abstracts your phone into a UI. Has a whole ecosystem behind it. I’ve been using it for festivals and tracking my vehicles (high theft area) for years.

Very handy should infra not be available. Should be great for protests also :)

Re: The protester's guide to smartphone security

#57

Old phones are an underappreciated resource, imo. I keep a few handsets around for apps I don't want on my daily driver (ex:food ordering, 2FA). More in line with the article: For alternate cell/SMS service I have a RedPocket SIM. (note: I see now it's $45/yr on ebay. I'm paying less, prob grandfathered).

>Old phones are an underappreciated resource, imo.

Not really. Old phones don't receive security patches and can be trivially unlocked to extract all relevant information. Sure, it might not have your nudes or bank login, but if you're using it to coordinate the protest that's plenty of incriminating evidence for the police.

>For alternate cell/SMS service I have a RedPocket SIM. (note: I see now it's $45/yr on ebay.

You have to be very careful with this, otherwise it's trivial to tie the phone/SIM back to you. Off the top of my head:

* the billing/shipping address used to order the SIM

* any payment information used to top-up the account

* location correlations with any other devices you own (for instance, if your burner phone pings the same towers as your primary phone for an extended period of time)

* using it for anything other than protests (eg. as a "burner" number when applying for jobs to avoid spam)

Re: The protester's guide to smartphone security

#59
post #30

Earlier quoted context omitted.

Signal is open source and ships with verified builds, so yes, we have a way to know what they actually collect.

I meant at the server. We have no way to know that is running there.

How can the server collect data you aren't sending to it?
Post reply on HN