Live data from Hacker News

A review of the Blackphone, the Android for the paranoid

arstechnica.com

51–58 of 58 posts

Re: A review of the Blackphone, the Android for the paranoid

#51
post #6

not to be a bummer, but it doesn't seem like anything special was done with this special purpose hardware. why go to the trouble to engineer and advertise this as a piece of security enhancing hardware when it's really just "PrivOS"? also, any plans on open sourcing "PrivOS"? did I miss something in the writeup? OSS modem firmware, OS wifi chipset, anything hardware or firmware related?

I don't think you missed anything. I don't see any reason to trust blackphone more than a properly configured Nexus. The OS might have some neat UI for privacy stuff, but fundamentally if it's closed source and has a closed baseband (afaik, there's no phone with an open baseband), then there's no real security.

> then there's no real security.

Is there no middle ground? Doesn't a device that changes your threat model from 'passive dragnet' to 'active compromise by a nation state' have some value?

Re: A review of the Blackphone, the Android for the paranoid

#52

Earlier quoted context omitted.

I remember getting the OpenMoko phone and pretty sure this was an issue way back then

It always was an issue and still will be for a long time. Neo900 project takes another way to neutralize the modem - by sandboxing and monitoring its activity. This alone probably makes it much more secure and privacy-friendly than Blackphone.

http://neo900.org/faq#privacy

Re: A review of the Blackphone, the Android for the paranoid

#53
post #15

This has a closed source baseband that was also not designed by the company producing the phone. The baseband is pretty much guaranteed to be backdoored by your favorite state security agency, so why get this over any other Android phone?

That wouldn't be a problem for me, provided that the baseband processor didn't have DMA access to all of system memory.

If I could be reasonably certain that the baseband only communicated with the rest of the phone via a limited modem(/similar) protocol at the hardware level - which should be possible - then I'd be happy provided that 100% of software running on the main CPU was Free Software, with sources available.

That means the bootloader, the kernel, all drivers - including video drivers, zero binary blobs - the display manager, and all provided apps, need to be Free Software. Unfortunately, as far as I can tell, the Blackphone doesn't even do that. (But I'm not 100% sure. I can't find that much info about the core OS software/drivers anywhere.)

Re: A review of the Blackphone, the Android for the paranoid

#54
post #15

This has a closed source baseband that was also not designed by the company producing the phone. The baseband is pretty much guaranteed to be backdoored by your favorite state security agency, so why get this over any other Android phone?

you do realize that people like dragorn are part of the black phone project, right? someone with that kind of clout doesn't really just get pushed around by (insert state agency here)

Re: A review of the Blackphone, the Android for the paranoid

#55
post #42

Earlier quoted context omitted.

I think that's possibly overkill. Provided the baseband processor is independent of the apps processor, communicates over a managed bus (usb, high speed serial, dedicated dual-port ram), instead of having direct access to main system memory, and the apps processor has the ability to power it up and down at will, you're in a pretty good state and you can still hop on a cellular voice or data network when you want to.…

Which phones have this memory architecture vs. dma?

I know no recent LTE baseband phones that have this isolation.

Re: A review of the Blackphone, the Android for the paranoid

#57
post #42

Earlier quoted context omitted.

I think that's possibly overkill. Provided the baseband processor is independent of the apps processor, communicates over a managed bus (usb, high speed serial, dedicated dual-port ram), instead of having direct access to main system memory, and the apps processor has the ability to power it up and down at will, you're in a pretty good state and you can still hop on a cellular voice or data network when you want to.…

Which phones have this memory architecture vs. dma?

Galaxy Nexus did (though that's not particularly recent).

I suspect most Tegra-based devices do -- though they introduced a combo apps/model Tegra 4i last year, which likely shares resources.

Generally if it has a standalone apps processor that's provided by a different vendor than the modem it probably does.

Even with unified apps/modem designs, some newer SoCs are designed to provide isolation between the cores, but from a tinfoil hat perspective that requires you to trust the SoC vendor (and perhaps the fab), so if you're paranoid you'd probably avoid any combo designs.

Re: A review of the Blackphone, the Android for the paranoid

#58
post #28
post #24

"We found that Blackphone lives up to its privacy hype." In all fairness I wouldn't say Ars Technica, good though some of their coverage is, are really the people to determine this. Especially in an article in which at no point do they ask "where's the source?".

On the other hand, how could they skip this topic in an article about a "privacy" phone? If find the trustworthy value of a phone is about equal to the privacy leak bounty. If each customer trusts the phone with, say $300 worth of information, then that should be a hell of a big bounty. So Ars Technica should have talked about "where's the source" and "how much is the bounty".

Not all information has a monetary value.
Post reply on HN