Live data from Hacker News

Essential Phone, available now

essential.com

671–680 of 695 posts

Re: Essential Phone, available now

#671
post #669

Earlier quoted context omitted.

Well Pope Francis is not a denier, and in some sense the Church scientists are the least biased in the world, since they are beholden to no one but God. They don't need to be published or get tenure. They can go with or against both academic and political orthodoxy as they choose. So if Francis came out and said climate change is not a concern I would actually pay pretty serious attention to that. And I'm not even Ca…

> So if Francis came out and said climate change is not a concern I would actually pay pretty serious attention to that. And I'm not even Catholic. Are you paying pretty serious attention when they claim that dinosaurs bones were sprinkled around the world by their god to test our faith?

Has the Catholic church actually said that, or are you perhaps confusing them with another group?

Re: Essential Phone, available now

#672
post #642

Earlier quoted context omitted.

I wish that Google could start supporting that. I am not that convinced that it is in their best interest though .. Last time I got saw numbers on this, non-geeks did not care at all about updates.

I know, but from an environmental perspective it would be nice to be confident that I could get a reasonable 4-year-life out of a new flagship phone, rather than going through rare earths and energy to make disposable 2-year phones.

It would. On the plus side Google has invested a ton of effort this year into making this possible.

Project treble is a major platform change.

OEMs need to get onboard though.

I would love to see Google ship the Pixel 2 with a ten years support warranty.. that would show the way but I will believe it when it happens

Re: Essential Phone, available now

#673

Earlier quoted context omitted.

Does it have a floppydrive?

Could you recommend a pair of cheap, studio quality, headphones that use bluetooth? Also a pair of good value, audiophile quality earbuds that use bluetooth? Please don't suggest Beats by Dre, or Apple. They aren't either.

Depending on what you call "cheap", Plantronics' Backbeat Pro. Works well with a cable attached to a sound desk, works well on Bluetooth with an Android phone, works well plugged into a Macbook, just about works on Bluetooth with a Macbook when you turn the Magic Trackpad off and make sure the Mac is trying to send it a high quality stream.

Slightly off-topic: my experience with Bluetooth does make me wonder how many people have been put off by Apple's Bluetooth stack. But given the alternative is a work-provided USB headset, I just plug the headphones in.

Re: Essential Phone, available now

#674
post #669

Earlier quoted context omitted.

> So if Francis came out and said climate change is not a concern I would actually pay pretty serious attention to that. And I'm not even Catholic. Are you paying pretty serious attention when they claim that dinosaurs bones were sprinkled around the world by their god to test our faith?

Has the Catholic church actually said that, or are you perhaps confusing them with another group?

I grew up in a Catholic family, that's what they teach you in catechism. They also teach you that the universe was created in literally seven days. But if you keep your chain of asking "how?" long enough before they yell at you, they'll also tell you that such statement is not to take "literally".

Re: Essential Phone, available now

#675
post #395

Earlier quoted context omitted.

The app-level "mitigation" is that media isn't automatically loaded. You are still just as vulnerable after you decide to play that innocuous-looking MP4 file.

I wasn't aware, thanks for mentioning that. However, the videos I watch are on YouTube and news sites and such... not sketchy sites. And I never play MP4s on my phone directly (unless they're videos I've recorded). I'm not sure many others do either, frankly. So how much do I need to worry and how much of a justification is this to upgrade the phone every 1-2 years?

> I never play MP4s on my phone directly

A good chunk of he video on the internet is mp4, so how would you know if you were playing an mp4 or not?

Re: Essential Phone, available now

#676
post #338

You want fixable and well designed, long software updates, and a good price? Buy an (old) iPhone. I've got a 5S -- still perfectly fast for what I use it for (email, youtube, brokerage account, general internet, some small games), and is getting OS updates and security patches until IOS11. It's $120 on eBay; a new screen can be had for $13, a new battery for $11. it's solidly designed and there's a gigantic field of…

Those screens are so cheap, its really amazing. I fixed an old iPhone 4 and the screen cost me about €15 with shipping. I couldn't believe it. One caveat to this though: If you do buy an old iPhone, make it at least a 5. The iPhone 4 was cut off at iOS7 and can't run most of the apps in the store as they require iOS8 or higher.

Better make it a 5s for 64bit support. The 5 won’t be getting iOS 11 next month.

Re: Essential Phone, available now

#677
post #658

Earlier quoted context omitted.

* Sound of groaning * Thanks. But ugh. That is both absolutely amazing and... well, what did I expect. Of course there are going to be process attacks :) Hmmm. I guess the only defenses against this are - trying to design the layout to get good "route coverage" via test routines (sounds hard) - aiming for super-simple designs that make it difficult to constructively alter the design (pathological simplicity is one pa…

It's much easier to just trust the fab. TSMC do not care about backdooring your hobby project. If you really want to carry on down this route, I would say the most effective approach would be to regard fab interference as a strange form of "single event upset", and borrow high-availability techniques such as lock-step mode across duplicated processors or subsystems.

Interesting. I'm curious, what sort of cost level would someone need to be looking at to mount an attack like the BECKER-CHES one? It would be really cool to be able to say "this would be secure until an attacker starts spending $(X?)XXX,XXX." Everything's vulnerable, step 1 is to have a good idea of how vulnerable.

Lock-step sounds interesting but really really hard - the basis of my idea is security through simplicity, and packing everything onto the one chip so only signed encrypted data comes out. Breaking the design down so that lock-stepped processors would reveal tampering would probably violate integrity and likely have blind spots too.

Re: Essential Phone, available now

#678
post #449

Earlier quoted context omitted.

There is no way I'm going to be continually looking for new incoming CVE that affect my old phone and making sure I have solid workarounds. The risk is too high that I'd miss one, mess up a fix, and then be vulnerable. And even if the risk wasn't that high, we're talking about a lot of time sunk into looking through security postings and verifying my own fixes/workarounds. It doesn't have to take too many minutes per…

That's a total straw man. You don't need to keep up with CVE. You really think I learned about e.g. StageFright through reading CVE or expected you to do that? If there's a serious vulnerability that actually needs your attention, you will read about it in the news (certainly on HN, most likely also the general news if it affects a sizable population). You will become aware of it somehow, most likely before a patch i…

>If there's a serious vulnerability that actually needs your attention, you will read about it in the news

No, this is fucking stupid. Most security related bugs get zero visibility, Linux for example still has a policy to quietly patch them.

Re: Essential Phone, available now

#679

Earlier quoted context omitted.

That's a total straw man. You don't need to keep up with CVE. You really think I learned about e.g. StageFright through reading CVE or expected you to do that? If there's a serious vulnerability that actually needs your attention, you will read about it in the news (certainly on HN, most likely also the general news if it affects a sizable population). You will become aware of it somehow, most likely before a patch i…

>If there's a serious vulnerability that actually needs your attention, you will read about it in the news No, this is fucking stupid. Most security related bugs get zero visibility, Linux for example still has a policy to quietly patch them.

> No, this is fucking stupid.

Well, now I'm definitely convinced...

> Most security related bugs get zero visibility, Linux for example still has a policy to quietly patch them.

Most security bugs don't need your attention either, because they don't have widespread exploits.

Read the prior comments; don't just curse in reply to a single sentence while ignoring all the prior context.

Re: Essential Phone, available now

#680

Earlier quoted context omitted.

> If there's a serious vulnerability that actually needs your attention, you will read about it in the news The ol' security through tech press approach. Seriously though, you can't have the security of your devices dependent on whether or not someone has come up with a catchy name for their exploit. The exploits with names like broadpwn and stagefright are the exceptions, not the rules, there are plenty of critical…

You seem to think that a security hole being "critical" implies you need to care about it. You do not. You only need to care about actual threats , not mere security holes. A "critical" CVE that nobody exploits is pretty darn pointless to worry about, just like how the fact that cellular communication is plaintext isn't really tickling too many people because the average criminal isn't using a Stingray. And an expoit…

>And an expoit that becomes widespread will get the press attention, precisely because people will want to know about it.

As you're clearly entirely clueless about security, how do you know this?

If you primarily get your security news via the press, how do you know that they aren't simply missing most things?

Post reply on HN