Live data from Hacker News

Blackphone

blackphone.ch

81–90 of 210 posts

Re: Blackphone

#81

The privacy issue in smartphones isn't the freaking application processor running Android. Sure, that ones terrible enough. But the actual problem is the baseband processor running completely non-free software, with an enormous attack surface and access to all the interesting periphery (GPS, microphone). There is not just opportunity to compromise your privacy, Qualcomm and others actively implement such features at…

by looking at the video I know some of the people in Spain who are involved. They are in Bilbao. We did a consulting project with them in 2009. They are more in the creative educational industry.

I am not sure about the technology, however from look of the video I can say it is mostly aim at non-technology experts, with nice fancy design.

Can I ask what kind of people do we need to design all the chips hardware such as baseband processor, using open source design?

And what are HN opinion on Silent Circle?

Re: Blackphone

#82
As others have pointed out, the baseband is not your friend. Was thinking about this recently, and saw no reason why existing POCSAG (pager) networks couldn't be reused to provide a completely passive receiver. Imagine a phone where the baseband was off by default, unless attempting to make a call. Voicemail/e-mail summaries were broadcast encrypted via POCSAG, and generate notifications just like a new mail summary coming in via GPRS/3G would.

Obviously usability would suffer a little bit (mostly in huge latency when you actually wanted to make a call), but seems like very cheap phone could be built that integrated a pager, allowing complete disconnection from the 'active' radio network, avoiding location tracking by your cell provider, or similar evil tricks by third parties.

Re: Blackphone

#83
post #56

Completely useless web page. All wooly 'feel-good' words and no hard, concrete information. So I guess we just have to take it on trust then? Also, their privacy policy is laughable: We turn the logging level on our systems to log only protocol-related errors - great! the pages on our main web site pull in javascript files from a third party. This allows our web developers and salespeople to know which pages are bein…

"Blackphone is re-shaping the landscape of personal communications. Pre-ordering begins..." How is it re-shaping anything before it's started shipping?

Come on, this can't be the first time you've encountered shitty marketing lingo.

Re: Blackphone

#84
post #82

As others have pointed out, the baseband is not your friend. Was thinking about this recently, and saw no reason why existing POCSAG (pager) networks couldn't be reused to provide a completely passive receiver. Imagine a phone where the baseband was off by default, unless attempting to make a call. Voicemail/e-mail summaries were broadcast encrypted via POCSAG, and generate notifications just like a new mail summary…

> " Imagine a phone where the baseband was off by default, unless attempting to make a call."

Except if everyone started using a phone like that, you wouldn't be able to call anyone.

Re: Blackphone

#85
They should probably work on the mixed-content SSL warnings on their own website. It's obviously not related to the security of the phones, but it doesn't instill much confidence.

Re: Blackphone

#86
post #56

Completely useless web page. All wooly 'feel-good' words and no hard, concrete information. So I guess we just have to take it on trust then? Also, their privacy policy is laughable: We turn the logging level on our systems to log only protocol-related errors - great! the pages on our main web site pull in javascript files from a third party. This allows our web developers and salespeople to know which pages are bein…

"Blackphone is re-shaping the landscape of personal communications. Pre-ordering begins..." How is it re-shaping anything before it's started shipping?

"Pre-ordering begins..." is letting folks their idea validating strategy. I wonder what the threshold is going to be, 100, 500, 1000 or more pre-ordered phones.

Re: Blackphone

#87

"and anonymize your activity through a VPN." iOS and Android support VPN but it needs to be manually activated each time, making it rather useless unless you're using some public wifi. If I understand correctly there is a possibility for large companies to integrate VPN but for the average guy it's rather useless if you have to activate it. If this phone has VPN really integrated that'd be great.

I understood that this had been fixed in Android a while back so it would start up automatically? Personally, I'm still on 2.3 which requires a manual startup...

If you could tell me how to do it that would be great. I'm still stuck turning it on all the time. Auto-on would be awesome.

Re: Blackphone

#88
I would hate to say this, but people here and there, are cashing in NSA fiasco. I would have loved it more, if this was more focused on 'features' than playing with people's emotions. this is valid for everything currently cashing-in NSA issue.

As for, NSA spying how exactly can this phone ensure 100% secrecy. Given a user would have to use the same apps, and above all, the carrier that other smartphone users use.

Point is, US Govt is hellbent on spying on you. And they will no matter what. Either change the US Govt, or suck it up. Nothing else is gonna work.

Re: Blackphone

#89
post #63
post #57

Earlier quoted context omitted.

The solution is for your phone to not be a phone. Strip out the baseband entirely, use usb or wifi to a 4G LTE dongle, do VoIP. Extra benefit that you can explicitly know when you're radiating (and thus being location-tracked). Blackphone is pretty lame, IMO. There's something better coming from a trusted source in weeks, and plenty of work being done on the "there is no phone" phone concept.

>There's something better Is this IndiePhone by Aral Balkan?

I've never heard of this project or person, but it looks interesting too.

Re: Blackphone

#90
post #74
post #72

Earlier quoted context omitted.

"Strip out the baseband" of a dongle and you won't have a device that can connect to the network, authenticate, shift cells or anything else. It's like stripping the firmware off your disk drive. Fully support the initiative for an open baseband. One reason it's not open is the (fairly legit) fear that intentional and unintentional DoS attacks would occur, affecting everyone in the area. It's really really simple to…

The idea is that your "high side" device is a phone, with all your apps, etc. It communicates over a well defined interface (USB seems like the best, but bt or wifi could be adequate given certain considerations) to a fully-functional mifi dongle or whatever which does normal cell/public-wifi/etc. functionality. No compromise of the external cell modem can get at high side data. The current "baseband can DMA your mai…

Snapdragon and every other baseband coming out has them on an 'all in one' chip which is application CPU and baseband sharing direct memory. Unless you have a microscope you can't build a hw firewall.

Cryptophone uses an older Samsung to do this but has no SIM protection. The firewall isn't foolproof either it only detects extended use of the baseband cpu without the application cpu being busy then shuts down the device, which makes it a brick open to denial of service.

A hardened Android build is fine for most shady activity and avoiding dragnet surveillance. If you are a drug lord or foreign spy use a laptop or tablet with ostel or silent circle, internal mic removed and running hardened free software, your dongle should have TurboSIM or similar wrapper that can be coded to reject OTA updates and not reply to silent tracking SMS. Marlinespike is also working on a new Whispercore, I have a forensics resistant project, and there is of course Cryptophone GSMK. Is the project you're talking about the build that runs Xen then boots Android in phony isolation because the snapdragon chip can still access memory.

Another problem is simply walking around with 2 phones which is an opsec indicator for feds that you are up to something and req targeted surveillance. They have full automated access to every cell tower db to look for this as per snowden docs dumped on cell meta data

Post reply on HN