Blackphone 2 Review
arstechnica.com
arstechnica.com
I imagine if you had enough realtime keystroke data, you could even identify a user using nothing more than how they type on a keyboard. That's some scary stuff.
Privacy advocates would better serve the public if they instead educated people on how to communicate securely instead of producing yet another black box that users can blindly put their trust in. I suppose this is better than nothing when dealing with less capable actors, but for those who plan their future years ahead, doing something on this phone, only to have it bulk collected and stuck in a database for decryption and analysis later when it serves the political will of those in power is counter productive.
And what they typed - acoustic snooping.
https://freedom-to-tinker.com/blog/felten/acoustic-snooping-...
This was on HN a while ago! https://news.ycombinator.com/item?id=9973329
http://arstechnica.com/tech-policy/2014/05/photos-of-an-nsa-...
The problem is that who orders a Blackphone is not completely private and it is a sign that those people have something they want to hide and there isn't that many of them.
You almost need a private way of sending Blackphones so that the NSA doesn't know who is getting which phone and then if there is a enough volume of Blackphones you should be okay.
Should I be worried?
It might be safer to go to Walmart and buy a pay & go phone and gift cards with cash. Or just stay on Tor sending encrypted messages using PGP.
Plus does the Blackphone address one of the biggest security concerns with modern cellphones: The cell modem? We already know the NSA has implants that target the underlying cellular operating system, turning your phone into a bug, or injecting things into the consumer OS (Android, iOS, etc). Baseband is a legitimate security nightmare.
1) This phone's security features tend to rely on other people having the same phone, which is definitely not a guarantee I can make.
2) This phone (perhaps only this article) doesn't go into detail about how it was secured only that it "was deeply secured" which is too vague for a technical audience.
3) It relies on central services provided by the manufacturer; (why not use Telegram? at least telegram is cross platform).
4) By ordering this phone, it's telling people that I value privacy, which could make me a higher priority target for those that are breaching privacy on a massive scale.
This device does not enhance my privacy, but it gives me all the inconvenience. Now I'd have /another/ user account to worry about and /another/ program to get people to share their details with.
when I think of security I think of PGP (yes, I'm aware the CEO was a producer of PGP) and things like SILC- where it's controlled by users and verified by people you'd like to confer with.
2) Fair point.
3) Telegram is also a central service, so in that respect it's no better than Silent Circle. WhisperSystems is better in that they make some server source code public. But to be fair to Silent Circle, their offer is much more complete: Voice, Messaging, Encrypted contact storage, and outbound PSTN access.
4) By using SILC, Tor, or GPG broadcasts the fact that you value privacy, which could make you a higher priority. What are you going to do, just send everything in cleartext and hope nobody looks?
3) my point was that telegram was "no better" but has better market penetration, while being essentially the same thing.. why have more standards.
4) this is also true, but it's less real world advertising of that fact, you don't order tor, you don't order GPG, and you don't have a physical device which proudly announces that you do. If you're doing security online right, nobody can tell you're doing it at a glance.
4) You order a privacy tool from Amazon, and you're put on a list. You emit the kind of encrypted traffic that 99% of internet users don't, you also get put on a list. In most cases, there's no difference. I suppose if your threat model requires you physically appear not to care about privacy then it matters. Like maybe you work in a sensitive position and you don't want anyone to think you might exfiltrate data, so you only carry the work provisioned device which logs everything you do.
It seems to me like setting up your own disk encryption and secure SIP calling on a phone with an AOSP ROM without any Google apps installed (and just using f-droid as your app store) would be far superior to using this device as far as privacy goes.
Excellent point. A secure phone should either have a GSM module that can be removed or a hard switch to disable it.
All I really want is a fully open source phone that I have control over, is that really too much to ask?
An open baseband is the missing piece and that appears to be rocket science.
If only someone would leak the specs of a modern baseband the same way calypso was leaked ... anyone ? Anyone ?
Unfortunately high spec firefoxos-pre-installed phones aren't really available in the US right now, but you can also convert an existing phone to run FFOS.
https://copperhead.co/android/
We already have a working alpha build on github which includes PaX hardening and various other security patches.
BBM is only secure in combination with a self-hosted BES server (and on which you have installed your own CA certs).