Live data from Hacker News

Blackphone

blackphone.ch

91–100 of 210 posts

Re: Blackphone

#91
post #88

I would hate to say this, but people here and there, are cashing in NSA fiasco. I would have loved it more, if this was more focused on 'features' than playing with people's emotions. this is valid for everything currently cashing-in NSA issue. As for, NSA spying how exactly can this phone ensure 100% secrecy. Given a user would have to use the same apps, and above all, the carrier that other smartphone users use. Po…

So hows that "change the US govt" (or any other world gov) going so far since the leaks?

I called bullshit from the beginning that anything will change politically, and now six months later I'm more certain nothing is going to change at the political level. They've dug in their heels for the long ride.

The only positive developments has been private companies like Google encrypting their data centers and privacy software finally finding an audience. But at the same time, not even the most die-hard cypherpunks think you can achieve 100% secrecy from a dedicated adversary. But that's not the primary goal. Countering mass-surveillance is.

Re: Blackphone

#92
post #88

I would hate to say this, but people here and there, are cashing in NSA fiasco. I would have loved it more, if this was more focused on 'features' than playing with people's emotions. this is valid for everything currently cashing-in NSA issue. As for, NSA spying how exactly can this phone ensure 100% secrecy. Given a user would have to use the same apps, and above all, the carrier that other smartphone users use. Po…

The NSA is only one fear - there are other actors you'd expect to be doing similar things. e.g. Chinese, mafia.

Using things like Blackphone can potentially increase the cost of anyone doing this kind of spying, to vastly reduce who will do it for what reasons.

This talk by Dymaxion is good on economics and usability of this stuff: http://dymaxion.org/talks/EaPitLW.html

Re: Blackphone

#93
post #88

I would hate to say this, but people here and there, are cashing in NSA fiasco. I would have loved it more, if this was more focused on 'features' than playing with people's emotions. this is valid for everything currently cashing-in NSA issue. As for, NSA spying how exactly can this phone ensure 100% secrecy. Given a user would have to use the same apps, and above all, the carrier that other smartphone users use. Po…

It's true that you can't have privacy or security in the mass-market apps or in voice or sms over big commercial carriers. However, if a device solved the problems indicated by (username) revelation and following posts on this page, you could then run secure applications - e.g. something with public-key encryption and PFS for the data, and a p2p or tor-style network to obscure the metadata.

It still wouldn't be perfect, but would succeed in many scenarios and would greatly increase adversary costs.

Re: Blackphone

#94
post #74

Earlier quoted context omitted.

The idea is that your "high side" device is a phone, with all your apps, etc. It communicates over a well defined interface (USB seems like the best, but bt or wifi could be adequate given certain considerations) to a fully-functional mifi dongle or whatever which does normal cell/public-wifi/etc. functionality. No compromise of the external cell modem can get at high side data. The current "baseband can DMA your mai…

Snapdragon and every other baseband coming out has them on an 'all in one' chip which is application CPU and baseband sharing direct memory. Unless you have a microscope you can't build a hw firewall. Cryptophone uses an older Samsung to do this but has no SIM protection. The firewall isn't foolproof either it only detects extended use of the baseband cpu without the application cpu being busy then shuts down the dev…

The idea is you don't use baseband functionality at all in the main high-side device. It can be a PDA, connected over USB to a separate radio. There's no way the radio can do anything particularly evil except if there are implementation bugs over USB (API problems with whatever interface you build between them, most likely), but at least that can be inspected by end users and problems found/fixed.

These highly-integrated devices are basically inimical to decent security.

No (that project was an earlier version of blackphone/geekphone, actually! from what I've heard)

Re: Blackphone

#96
post #44

Earlier quoted context omitted.

> iOS permissions are more granular sometimes Not true, http://developer.android.com/reference/android/Manifest.perm...

Android permissions are all or none at install time. iOS allows permissions to be individually toggled at any time. Some people define flexibility differently.

I can revoke permissions on any Android app with App Settings[1].

[1] https://mediacru.sh/DRUrAHvxdlfS

Re: Blackphone

#97
With all the respect what they have done so far, I can't see any reason why this is securer than the other mobile phones..

With the latest NSA stuff, I came to conclusion that a true secure system can only be built under these conditions and just to put it out there, this is just my opinion;

- A computer company that manufactures their own hardware such as hard drive, ram, cables, network cards.

- An OS that is newly written and not based on any other existing operating systems.

- Building the whole system with INDEPENDENT hardware and software mentioned above.

- Keeping the mobile device's source code offline from Internet as much as possible

These are just the first steps on developing a secure system, then comes the mobile network architecture and encryption etc.

I admit, it is not an easy job but, trying to develop a secure system with "not secure" development tools is not the right way to go :)

Re: Blackphone

#98
post #44

Earlier quoted context omitted.

> iOS permissions are more granular sometimes Not true, http://developer.android.com/reference/android/Manifest.perm...

Android permissions are all or none at install time. iOS allows permissions to be individually toggled at any time. Some people define flexibility differently.

[deleted]

Re: Blackphone

#100
post #12

Well, this is just a splash page and says very little. It's in partnerships with http://www.geeksphone.com/ which is FirefoxOS based. But yet the Blackphone splash has an image of a phone with Android buttons. They claim no hooks to vendors, so if it's Android I can't imagine this is going to carry the Play store. I'd be interested in knowing how they will secure and make private the core functionality of being a pho…

Text- in a similar way TextSecure did it, would be my guess. They have something called Silent Text, and they're using the ideas here I believe:

http://eprint.iacr.org/2014/036.pdf

Email? They've announced the DarkMail protocol last year, and should be coming soon:

http://darkmail.info/

https://www.youtube.com/watch?v=IgV_Z6V_llk

Post reply on HN