Live data from Hacker News

Blackphone

store.blackphone.ch

91–100 of 102 posts

Re: Blackphone

#91
post #30
post #5

I hate to break it to you, but this is not going to keep you safe from a state-level adversary. I could drone on about this for pages and pages, but the sad fact is that if you are a target, it doesn't matter that you are using a "secure phone", "secure OS", or "encryption". Time and time again, these systems have been broken or breached with simple tradecraft and subtle sabotage. The Pentagon has a concerted (and ex…

> I hate to break it to you, but this is not going to keep you safe from a state-level adversary. I don't really like this kind of anti-crypto argument. At this point I think making normal communications between normal people less embarrassingly mass-snoopable is a very worthy goal. For the time being, people who really, really have something to hide need to be extra careful (as has always been the case). Which is no…

Ditto.

At the end of the day, state actors all have finite resources. If we continuously tell people to not bother with crypto at all, then we are being self-defeating.

Right now targeting those that use crypto is like shooting fish in a barrel. So few people are using crypto regularly, that they are incredibly easy to single out. If everyone used crypto, the amount it would cost state actors to find and further investigate individuals would quickly overwhelm the current resources of those state actors.

Obviously people using these devices need to know they aren't foolproof and only use them for casual secrets that at most implicate, but not provide solid proof of activities considered subversive by a state actor.

Making the cost of dragnet mass surveillance phishing expeditions prohibitively expensive should be goal number one right now in the crypto community. State actors commit the crime of violating everyone's privacy because it is so incredibly easy and cheap to do so.

I don't know how much it currently costs for state intelligence agencies to investigate an individual, but whatever it is now, I would hope the the price were one to two orders of magnitude more expensive than it currently is and be at least in the 7 figure range. If someone really is a terrorist bent on causing lots of damage and killing civilians, it is trivial to justify spending 7 figures on surveilling that individual. The benefit of making it super expensive to surveil everyone, is that these state agencies can no longer casually surveil those it shouldn't be, such as American lawyers doing work protected by attorney client privilege [0].

At the end of the day, although state actors have deep pockets, they are bounded to some degree by market factors like what activities they can legitimately justify given the cost of surveillance and the the amount of talent they have available.

[0] http://www.nytimes.com/2014/02/16/us/eavesdropping-ensnared-...

Re: Blackphone

#92
post #5

I hate to break it to you, but this is not going to keep you safe from a state-level adversary. I could drone on about this for pages and pages, but the sad fact is that if you are a target, it doesn't matter that you are using a "secure phone", "secure OS", or "encryption". Time and time again, these systems have been broken or breached with simple tradecraft and subtle sabotage. The Pentagon has a concerted (and ex…

Then again, the clock on the wall in the pub might have a hidden microphone, or camera. This site is rather ingenious in where they put microphones/cameras (wall charger?) - supercurcuits.com

Re: Blackphone

#93
post #14

Earlier quoted context omitted.

The irony is that bad crypto like this is worse than no crypto. It is probably more valuable to specifically target users of this phone because they "have something to hide".

I don't know, Phil Zimmermann, Jon Callas et al are hardly known for bad crypto. Full disclosure: I work for Silent Circle and it's pretty damn secure. It's also open-source: https://github.com/SilentCircle

Are all of the silent circle applications free software? Do any of these applications depend on proprietary software to run?

Re: Blackphone

#95

Earlier quoted context omitted.

I don't know, Phil Zimmermann, Jon Callas et al are hardly known for bad crypto. Full disclosure: I work for Silent Circle and it's pretty damn secure. It's also open-source: https://github.com/SilentCircle

Are all of the silent circle applications free software? Do any of these applications depend on proprietary software to run?

They aren't developed in the open (they're opened up in certain releases), but the protocols themselves are open. The server software is proprietary, but the servers don't see any plain-text data.

Re: Blackphone

#96

Earlier quoted context omitted.

Are all of the silent circle applications free software? Do any of these applications depend on proprietary software to run?

They aren't developed in the open (they're opened up in certain releases), but the protocols themselves are open. The server software is proprietary, but the servers don't see any plain-text data.

Ah. Proprietary servers are a dealbreaker for me.

Re: Blackphone

#97
post #62

Earlier quoted context omitted.

EXACTLY. By providing ready access to a stream of digital data and metadata about yourself, you're making their job easier. Even if you use crypto, the mere fact that you use crypto is interesting enough to draw attention. The point is to blend into the background. Do you think that crossing a border using the Blackphone isn't going to raise eyebrows? In denied areas the idea is to use equipment that looks ordinary a…

It seems like you're saying "we should all use encryption as much as possible so it becomes the background". It also seems like you don't think you're saying that.

What I'm saying is that this technology is a small piece of a solution set to a big, hard problem.

Technology and crypto are the easy parts. Infrastructure, legislation, and user behavior are the bigger pieces and a much harder problem.

We have had secure email systems for better than two decades. They are VERY poorly deployed. Why? We have had secure voice systems for even longer. Why is the encryption on these systems so poorly designed?

I don't trust machines to keep my secrets for these very reasons. I have little faith that more crypto will fix anything. That's what I'm saying.

Re: Blackphone

#98
post #97

Earlier quoted context omitted.

It seems like you're saying "we should all use encryption as much as possible so it becomes the background". It also seems like you don't think you're saying that.

What I'm saying is that this technology is a small piece of a solution set to a big, hard problem. Technology and crypto are the easy parts. Infrastructure, legislation, and user behavior are the bigger pieces and a much harder problem. We have had secure email systems for better than two decades. They are VERY poorly deployed. Why? We have had secure voice systems for even longer. Why is the encryption on these syst…

A nit: Email encryption is very hard to get right, but voice encryption is a solved problem (Silent Phone, RedPhone, etc do it very well).

Re: Blackphone

#99
post #97

Earlier quoted context omitted.

What I'm saying is that this technology is a small piece of a solution set to a big, hard problem. Technology and crypto are the easy parts. Infrastructure, legislation, and user behavior are the bigger pieces and a much harder problem. We have had secure email systems for better than two decades. They are VERY poorly deployed. Why? We have had secure voice systems for even longer. Why is the encryption on these syst…

A nit: Email encryption is very hard to get right, but voice encryption is a solved problem (Silent Phone, RedPhone, etc do it very well).

Voice encryption was available with the STU-III for a long long time.

When was the last time you saw a STU-III in an office? Ever? It's because the security capability isn't worth the trade off and friction it creates for business.

The dirty little secret is that the whole process of doing key exchange and verifying that you have a solid connection between two trusted parties is NOT a widely solved problem.

TRUST between two parties that have never met is NOT a solved problem at scale unless you consider SSL a solution and there are a lot of people who think that SSL is broken in many regards.

Think of all the features that a modern enterprise phone system has:

Call waiting Three way calling Conference bridges Voicemail CallerID Call Parking Assistant Mode ...et al. Regulatory archiving

You don't get ANY of those with ANY commercially available secure phone system. The same problems you have with using secure email at scale you have with secure voice.

Re: Blackphone

#100
post #37
post #25

Earlier quoted context omitted.

No. It's UNDERSTAND YOUR ADVERSARY. If I'm trying to protect myself from hackers, I choose one route. From my ISP, another. From FB/Google, another. And from my government or your government, yet another. What's missing here is honest dialogue about the limits of the technology. The best technology has yet to save people from their own foolishness.

We really need to rewrite the entire stack, carefully and with the intent of security, from open-source-DIY hardware up, to have any trust in technology.

You have fun. Get back to me that and see how it goes.
Post reply on HN