Live data from Hacker News

Blackphone

blackphone.ch

71–80 of 210 posts

Re: Blackphone

#71
Please not another long scrolling page without any real info... shame, I might have wanted one if they had provided any specs or technical details at all...

Re: Blackphone

#72
post #57

The privacy issue in smartphones isn't the freaking application processor running Android. Sure, that ones terrible enough. But the actual problem is the baseband processor running completely non-free software, with an enormous attack surface and access to all the interesting periphery (GPS, microphone). There is not just opportunity to compromise your privacy, Qualcomm and others actively implement such features at…

The solution is for your phone to not be a phone. Strip out the baseband entirely, use usb or wifi to a 4G LTE dongle, do VoIP. Extra benefit that you can explicitly know when you're radiating (and thus being location-tracked). Blackphone is pretty lame, IMO. There's something better coming from a trusted source in weeks, and plenty of work being done on the "there is no phone" phone concept.

"Strip out the baseband" of a dongle and you won't have a device that can connect to the network, authenticate, shift cells or anything else. It's like stripping the firmware off your disk drive.

Fully support the initiative for an open baseband. One reason it's not open is the (fairly legit) fear that intentional and unintentional DoS attacks would occur, affecting everyone in the area. It's really really simple to be an obnoxious cellular network citizen and it's pretty damn hard to police.

Baseband bugs that impact networks are common too due to the complexity. I saw a function point analysis of GSM vs 3G once, seem to remember 1-2 orders of magnitudes difference. Ahh Function Points, you flawed devil of a management metric.

Re: Blackphone

#74
post #72
post #57

Earlier quoted context omitted.

The solution is for your phone to not be a phone. Strip out the baseband entirely, use usb or wifi to a 4G LTE dongle, do VoIP. Extra benefit that you can explicitly know when you're radiating (and thus being location-tracked). Blackphone is pretty lame, IMO. There's something better coming from a trusted source in weeks, and plenty of work being done on the "there is no phone" phone concept.

"Strip out the baseband" of a dongle and you won't have a device that can connect to the network, authenticate, shift cells or anything else. It's like stripping the firmware off your disk drive. Fully support the initiative for an open baseband. One reason it's not open is the (fairly legit) fear that intentional and unintentional DoS attacks would occur, affecting everyone in the area. It's really really simple to…

The idea is that your "high side" device is a phone, with all your apps, etc. It communicates over a well defined interface (USB seems like the best, but bt or wifi could be adequate given certain considerations) to a fully-functional mifi dongle or whatever which does normal cell/public-wifi/etc. functionality. No compromise of the external cell modem can get at high side data. The current "baseband can DMA your main device" is absurd; security processors (only on iOS and BB and maybe WP, really) help a little, but not enough.

Yes, it is two small boxes right now, but there's no reason you couldn't build a "baseband firewall" which puts baseband in one area, a firewall in between, and the regular phone, with only a well defined open interface in between.

Re: Blackphone

#76

The privacy issue in smartphones isn't the freaking application processor running Android. Sure, that ones terrible enough. But the actual problem is the baseband processor running completely non-free software, with an enormous attack surface and access to all the interesting periphery (GPS, microphone). There is not just opportunity to compromise your privacy, Qualcomm and others actively implement such features at…

Hmm, I'd say the real privacy issue is the user who installs and runs all those Facebook, Twitter, LinkedIn, etc. apps and freely shares his private information with everyone. You can't really prevent that with technology unless you start to educate kids/users better. But who am I kidding? People will forfeit their private data for shiny stuff as long as there will be shiny stuff and private data.

No. The problem is not the common user who just follows common hardware and software. The problem is common hardware and software, which put security last.

Re: Blackphone

#78
post #39

Android having the most granular permission system ever seen on any operating system is already the most secure operating system. The biggest security hole next to the baseband processor and the SIM is the user who installs every app in seconds without checking permissions.

Not even remotely granular. Install XPrivacy[1] (which is still not granular enough for me, as it lacks filtering over function arguments) and see that categories are very broad.

[1]: https://github.com/M66B/XPrivacy#xprivacy

Re: Blackphone

#79
https://www.blackphone.ch/hello-world/

I'm sure there's logic there - powering a very basic non-informative landing site with a WP installation that you took the time to customize, but not delete the default post and comment from...

But it certainly doesn't give me warm fuzzy feelings about the people behind this.

Re: Blackphone

#80
Personally, if I were really worried about privacy I would use burners or get a lineman's handset. It seems like a smart device that you use all the time is going to have the same problems.

So, yeah you can encrypt the voice channel. That's great. You can send encrypted text messages. The people involved are serious cryptographers. All of it sounds good.

You have to ask your self though, what is it you are trying to do? Who is your adversary? Other people here have mentioned it, but what about apps on the phone? Facebook is still Facebook.

Post reply on HN