Live data from Hacker News

Blackphone

store.blackphone.ch

61–70 of 102 posts

Re: Blackphone

#61
post #29

I am not sure why do anyone needs that. You can have basically secure messaging on the phone today. You can use Replicant (libre software) on many phones where there probably are no backdoors, you can use OTR with Xabber (you can build it yourself), there are probably applications for PGP too. Yeah, Replicant will fail to work on many phones and on those that work, half of the functionality is missing ( http://redmin…

Reminds of this classic comment: https://news.ycombinator.com/item?id=9224

Guy complaining that dropbox is useless because "For a Linux user, you can already build such a system yourself quite trivially by getting an FTP account, mounting it locally with curlftpfs, and then using SVN or CVS on the mounted filesystem."

Re: Blackphone

#62
post #32

Earlier quoted context omitted.

The Soviets used to have a custom of taking long walks in the park when they wanted to have a private conversation. It had the notable benefit of avoiding the hidden listening devices in their places of work/rest/play.

Great point. While you still could be spied on, for instance with a bug stuck onto your back or classified nano-drone (if it exists yet)... that would be extremely expensive. If they wanted you that bad, it's like, fine. Listen to me talk about my motorcycle. The issue with computers is they are so, so, so cost effective to tap & data mine. And storage just keeps getting cheaper. Hence, illegal mass surveillance. Als…

EXACTLY.

By providing ready access to a stream of digital data and metadata about yourself, you're making their job easier.

Even if you use crypto, the mere fact that you use crypto is interesting enough to draw attention.

The point is to blend into the background. Do you think that crossing a border using the Blackphone isn't going to raise eyebrows? In denied areas the idea is to use equipment that looks ordinary and boring: a wristwatch or a calculator.

If for no other reason than an adversary might not know who you are, you reveal yourself to them by using a special-purpose tool.

Re: Blackphone

#65
post #5

I hate to break it to you, but this is not going to keep you safe from a state-level adversary. I could drone on about this for pages and pages, but the sad fact is that if you are a target, it doesn't matter that you are using a "secure phone", "secure OS", or "encryption". Time and time again, these systems have been broken or breached with simple tradecraft and subtle sabotage. The Pentagon has a concerted (and ex…

> I hate to break it to you, but this is not going to keep you safe from a state-level adversary.

Assuming it's not being built as a honeypot by a state-level adversary, it's also going to attract attention to you. Want to avoid surveillance -- as much as practical act like someone who isn't worried about surveillance.

BTW: "Buy someone a beer" -- True Detective episode 6 reference?

Re: Blackphone

#66
post #26

It's a bit disconcerting to see that it comes with software "enabled for at least 2 years of usage".

Why? I believe that sentence refers to extra software/services that’d normally be paid.

It does, you get 2 years' worth of subscription to various services.

Re: Blackphone

#67
post #14

A prerequisite for security is free software. Critical applications like the Silent Circle ones are proprietary, afaict. I have zero trust in the Blackphone and would not purchase one.

The irony is that bad crypto like this is worse than no crypto. It is probably more valuable to specifically target users of this phone because they "have something to hide".

I don't know, Phil Zimmermann, Jon Callas et al are hardly known for bad crypto.

Full disclosure: I work for Silent Circle and it's pretty damn secure. It's also open-source: https://github.com/SilentCircle

Re: Blackphone

#68
post #30
post #5

I hate to break it to you, but this is not going to keep you safe from a state-level adversary. I could drone on about this for pages and pages, but the sad fact is that if you are a target, it doesn't matter that you are using a "secure phone", "secure OS", or "encryption". Time and time again, these systems have been broken or breached with simple tradecraft and subtle sabotage. The Pentagon has a concerted (and ex…

> I hate to break it to you, but this is not going to keep you safe from a state-level adversary. I don't really like this kind of anti-crypto argument. At this point I think making normal communications between normal people less embarrassingly mass-snoopable is a very worthy goal. For the time being, people who really, really have something to hide need to be extra careful (as has always been the case). Which is no…

I think the problem with a device like this is that the kind of person who would be interested to use this just may be precisely the kind of person that the NSA would like to keep tabs on, just in case. Enough so, that an NSA worried about the Snowden leaks could theoretically come up with this idea as a way to corral folks trying to escape the "conventional" channels. Particularly with an ex-Navy Seal as CEO (no longer trusts the US government?), what's to say that there isn't some other vulnerability built into the core of this device. “Just because you're paranoid doesn't mean they aren't after you”. ― Joseph Heller

Re: Blackphone

#69
post #21
post #13

Earlier quoted context omitted.

This Verge article [1] says “The company will open source the vast majority of its code for the phone in order for third parties to properly audit its techniques, find holes, and ultimately help to improve the product.” 1. http://www.theverge.com/2014/2/24/5441642/blackphone-silent-...

If they do, that would go a long way to convincing me this is a tidbit more secure than any other random Android device. They should really have released their code at the same time they released their phone though.

I've talked to Silent Circle at conferences and what not. It is not like they have some crypto noob working on their project...They have Phil Zimmerman.

But, knowing nothing about them, when I asked them ``How does your protocol compare to TextSecure's Axolotl?'' the response was ``We have Phil Zimmerman''. So....I'm still a bit put off by them.

Some of their code is already open-sourced here. https://github.com/SilentCircle

Post reply on HN