Live data from Hacker News

Nobody’s Cellphone Is Really That Secure

theatlantic.com

71–76 of 76 posts

Re: Nobody’s Cellphone Is Really That Secure

#71
post #37

Earlier quoted context omitted.

We know from the Snowden leaks that there were direct data links between Google and the NSA. Despite their vehement denials and public outrage, I still find it hard to believe that it was possible for the NSA to install such massive surveillance without some complicity from Google. Technically this might have been possible without any Google involvement, I agree with that, but given past involvement of other companie…

Nothing in Snowden's leaked documents contradicted Google's statements. The New York Times reported the setup correctly from the start, and the rest of the news media picked up on it shortly thereafter. https://www.cnet.com/news/no-evidence-of-nsas-direct-access-... Your understanding of PRISM matches Greenwald's incorrect reporting, which was based on a high school dropout's misreading of some slides he found on the…

Then again, Google's public statements might not be the best information source to check whether Google did something nefarious or not.

Re: Nobody’s Cellphone Is Really That Secure

#72

Nokia 6.1 (2018 model) costs $270 USD with Android One (at least 2 years of monthly security updates), metal body, fingerprint sensor (no notch), headphone jack and hardware-based remote attestation for tamper detection. https://www.theverge.com/platform/amp/circuitbreaker/2018/5/...

The Xiaomi Mi A1[1] is much cheaper with similar specs. Even this year's update is cheaper[2]. [1]: https://www.amazon.com/Xiaomi-32GB-Factory-Unlocked-Compatib... [2]: https://www.amazon.com/Xiaomi-64GB-Camera-AndroidOne-Smartph...

World has truly moved on from < 5" phones and my palms stopped growing a decade ago.

Re: Nobody’s Cellphone Is Really That Secure

#73
post #49
post #34

Nobody’s phone is really that secure... but an iPhone vulnerability costs more than an average Bay Area house, while an Android vulnerability is more like the cost of cleaning that house once. Edit: turns out the figure for an Android vulnerability is off by several orders of magnitude. What a garbage article!

Consider deleting your false statement, now that aaronharnly has posted a correction.

You can’t delete comments once there’s a reply

Re: Nobody’s Cellphone Is Really That Secure

#74
post #70

Earlier quoted context omitted.

You can get the latest Android on the Nexus 5. https://wiki.lineageos.org/devices/hammerhead Updated 2 days ago: https://download.lineageos.org/hammerhead/changes/

Lineage is great, but that's 14.1 (Android 7, not "the latest" 9) and Lineage can't patch vulnerabilities in binary driver blobs. Still - much better than being left in the cold by your OEM

Fair enough, other models have 15.1 (I'm using one).

You can't force the OEM to patch, but you can get Android security patches without the OEM having to bother supporting it.

The only way forward is postmarketOS, running a mainline kernel.

Re: Nobody’s Cellphone Is Really That Secure

#75
post #56

Earlier quoted context omitted.

three years of frequent updates is pretty much the best support you're going to get with any android phone. i personally love my pixel 2, but they sold about half as many pixels in 2017 as samsung sold phones in a week. [0][1] samsung does give monthly security updates to its flagship products, but it won't support anything for more than two years. i think it's clear that consumers don't actually give a shit about up…

> i think it's clear that consumers don't actually give a shit about updates when they choose their next phone, The people that do give a shit pick ios. Security and updates was the #1 reason I moved from Android to iOS.

That's some intense gatekeeping... At least I can root my Android phone.

iOS security, from a targeted hacking perspective, is easier than ever to circumvent for full control: https://blog.elcomsoft.com/2017/11/ios-11-horror-story-the-r...

Apple also has a nasty habit of coercing users into upgrade to new models, reducing the need for supporting older devices and artificially limiting the amount of older phones in circulation: https://www.wsj.com/articles/apple-faces-multiple-lawsuits-o...

Re: Nobody’s Cellphone Is Really That Secure

#76
post #21

Earlier quoted context omitted.

The problem was hardware manufacturers ie processor etc would not support newer versions of the OS and kernals. Thats why they have come up with project treble with that you would be able to install newer versions of android long after they themselves stop giving updates.

That is what business contracts are for. Treble doesn't help anything because OEMs are the ones still pushing updates, and only devices released with Oreo are oblieged to be compliant with Treble. Which is why even in 2018 most new devices have been released with 7, upgradable to 8. But I am glad OEMs keep ignoring Google, as they finally added update clasues on their licensing contracts. After one year, Oero has ach…

Is 21.5% really so meager considering the amount of older Android phones in circulation?
Post reply on HN