Black market Blackphones get sent a kill message that bricks them
arstechnica.com
arstechnica.com
In my book, a remote kill switch is OK if you can also trigger it. For privacy, DOS is pretty harmless -- you don't lose privacy, you just lose access to some data/service. If, in exchange of a risk of DOS, I can get better privacy some other way, I'll take it. As for SC fighting counterfeiters, I don't blame them. They're not making much $$ these days, and this is a way to keep alive without hurting their actual customers.
There is Replicant ( http://www.replicant.us/ ), a version of Android that aims to get rid of all binary blobs. There is also CopperheadOS ( https://copperhead.co/android/ ).
Related reading: https://blog.torproject.org/blog/mission-improbable-hardenin...
Shameless plug: we sell preinstalled Replicant phones at https://tehnoetic.com/
Even if such an audit was done perfectly (a very serious and difficult undertaking), it would be a point in time assessment, so would become less relevant as new code was committed.
Basically you have to trust some group of people to run a modern computing device/environment, it's just a question of who and how much...
The advantage of FOSS is that the set of who can audit the code is open. It starts small, but grows with popularity and remains agile - eg doesn't necessitate transitively trusting whatever nation-states a single company is vulnerable to.
To take one example with a propietary solution with code from a single company, it is possible for a level of background checking to be done on all contributors. With a FOSS solution, that's just not possible, so you get risks like what if one of the contributors is being paid by a nation state who would like to place a specific bug/vulnerability into a codebase.
Of course in practice the world is much muddier than that as pretty much all propietary software vendors make ample use of code they did not write, and in many cases on open source code that they don't really controle the provenance of.
Personally I'd say the idea of having a high level of trust in any larg'ish software stack is very dubious these days given the likely incentives of various groups to compromise them.
The first systems that were trustworthy were done by proprietary companies with independent evaluation of the product, signatures on source/binaries, and/or optional generation from source on-site. This became standard practice in security- and safety-critical development. You can scale it to as many people available for review often under NDA for the source itself but not signatures or binaries.
A company can do things that are similar to Free software (eg allow customers to build from source), but in the context of modern discussion I'd say that's just taking on aspects of Free software.
"Proprietary software starts off with a high level of trust - trusting just one company. But it can never progress past this."
It's totally false. The evaluation side has been done more times than I can count. It doesn't even have to start with a single source. Many products started as a collaboration of multiple organizations checking each others work that share the result. Another model is CompSci inventing something with details open at the start, patented, and then turned into closed source product. Finally, there's Shared Source models where you can have, fix, or extend the source so long as you're paying. Burroughs B5000 (1961), first system resilient to 0-days, was distributed in source form to customers.
You were oversimplifying proprietary systems then attacking that simplification.
I'd love to find a commercial model that could work for consumer-oriented Free software [0], and I think it could sound quite similar to something you describe. It's just that those type of multi-party collaborations have been pulled into the attractor of free-as-in-beer, at least as far as the code itself is concerned.
[0] I say Free instead of Open, because I can envision software lacking just FSF freedoms 1b and 3 could get stuck in a bad state as well. Like say everyone knows there is a bug and how to fix it, but is legally prevented from doing so.
You were. You made a blanket statement about the whole, proprietary model. In recent comments, you've changed your statement to talk about how the model is applied in the general case. As in, popular implementations vs all implementations. I'll reply to the new comment anyway.
"For example, something like a mass-NDA for every user is going to fail for consumer-oriented software, whereas a company contracting a discrete number of external auditing decomposes into trust through branding."
That's basically what happened. It could go further where lots of users get the NDA with cross-checks but not mass on high-volume scale. It helps if the software is designed in such a way where it can be shown it doesn't manipulate the system. I once proposed memory safety, safe API use, and sandboxing as a start on that. Automated tools could assess those. One could go further with information-flow labels tracking confidentiality or integrity enforced by compiler, runtime, or hardware. A few CompSci projects do it but not mainstream.
"I'd love to find a commercial model that could work for consumer-oriented Free software"
They pay for it. Then they get it. The source is in a FTP server or something somewhere. Things like branding, enterprise features, and tie-ins keep them buying from original supplier. Been done in a few ways although always a risk of clones.
"[0] I say Free instead of Open, because I can envision software lacking just FSF freedoms 1b and 3 could get stuck in a bad state as well. Like say everyone knows there is a bug and how to fix it, but is legally prevented from doing s"
Dual-licensed (proprietary + GPL) covers this. A few, quick proposals follow on non-free trying to approximate free. One could do a shared-source license that allows bug fixes. One could allow redistribution of software to other paying customers. One could cap what's to be paid or for how long before what's purchased becomes perpetual. One can make it go FOSS if it's EOL'd or gets under certain amount of developer time/contributions (tricky measure). Recent proposal was time limit on how long a version or individual product would be paid with it going FOSS after that time limit.
So, quite a few options here. One thing that's important to remember is that FOSS will always have a disadvantage over benign, paid model. The disadvantage is you can contractually ensure those being paid are doing support, bug-fixes, enhancements, pen testing, etc. They can also cover the pro's to do it right. They have lawyer money for patent trolling that will come their way. Combined with shared source like above, they might also get most or all benefits of FOSS with benefits of paid. It's why I'm highly interested to see companies experiment with hybrid models. A few have showed up here but nowhere near enough.
Windows NT
OpenBSD
At least, this is the market I perceive the Blackphone to be addressing.
This seems really scummy and would drive me away from their products forever.
If I were to buy a Blackphone, I would do it because I wanted security, and because I trusted the manufacturer to provide it. The problem with security is that just because my phone appears to be "working perfectly" doesn't mean that somebody isn't eavesdropping on everything I say.
A counterfeit Blackphone, in other words, is completely defective and untrustworthy, no matter how well it appears to work, because my trust in the manufacturer is broken.
I don't exactly see how it bumps up the profit though. You have a bunch of obviously interested customers, who want your product, and then the company has come out with "Actually, we expect you to buy the phone twice, because of a mistake that may or may not of been your fault"
Remember the hassle WhatsApp got for failing open?
The Blackphone+SilentOS is an actual crypto device for people who believe they need crypto. It needs to fail closed. This may cost some people $100, but save their lives.
This also gives the customers the ability to sue the sellers, or at least push for refunds via the sales platforms.
If the user is informed they have a non genuine device that is not safe or secure (e.g. like Windows' nag notification), then they can't expect it to work like a secure device, but more like an ordinary phone.
Then both normal consumers (who will continue to use the phone since they didn't really care too much in the first place about safety) and security conscious consumers (who will re-buy asap) would be more inclined to use the same brand in the future
If my smoke/heat/etc detector starts to fails I don't want it silently dropping back to a smoke-only detector. I want it to start beeping loudly and refuse to stop.
> If the user is informed they have a non genuine device that is not safe or secure
Having to flash a new OS onto it is an appropriately sized clickthrough for a warning of that magnitude. Like being woken in the night to change a smoke-detector battery.
Or something like a Moto G?
Also - they're protecting their own image here - can you image the PR s*itstorm that would unfold if somebody bought a counterfeit Blackphone, got hacked or had their details siphoned off to China, then wrote a blogpost about it? We on HN are often quite quick to judge - so I can certainly see why Silent Circle are taking the careful approach here.
Why should a vendor be able to stop you from using a thing you bought because it looks like one of theirs? No support, sure. Disavow the item, sure. Post warnings on the device as an inbuilt part of the system, sure. But destroy your item? No.
If someone is fraudulently selling cars badged as Fords, Ford itself should not be able to repossess those vehicles. And if Ford thinks that you have stolen their car, they themselves should still not be the ones who repossess it - that's what the police are for. Vigilantism is a bad thing and has all kinds of unexpected failure modes.
Actually, there's a very analogous thing for cars - LoJack. Is that wrong too?
It happens with copy protection on software. I've heard of games that become impossible to win if they detect they're pirated. Others that just fail entirely. Is that not OK either?
It wouldn't be OK if the developers intentionally affected copies that most users would explicitly believe were not counterfeit (for example, if all Steam copies did this because the game developer had an exclusive agreement with EA/Origin).
The users of the counterfeit phones had no way of knowing they were counterfeit. They were advertised as brand new and came in a shrinkwrapped box.
Crypto devices should brick themselves if they discover they've been tampered with.
It's a clear case of seller fraud and if you use a good marketplace (ie not the one starting with E) you can get a refund through the platform. And maybe get information to use in suing the seller.
So if I scramble the firmware on your phone and brick it, you don't consider that damaged?
> LoJack
... works in tandem with police, hardly 'very analagous'.
> It happens with copy protection on software.
The user should have been warned that applying the update would brick the detected non-original phone. It shouldn't have just silently fucked the user over. It's bad ethics and also bad PR. Fucking over a user acting in good faith is poor form ethically.
A closer analogy - and still not exactly, since the owner would still have actually lost the car - would be if the police came and burned it down just so that you couldn't use it.
They're enforcing their copyright. Why not? The police can also confiscate computers with pirated software on them. They even do that sometimes. It doesn't return the money to the IP owners but it's still a way to deter theft.
It sounds like a good idea to me. Even if it doesn't recover their lost sales, it should prevent future black market copies since customers will know to avoid unofficial sellers.
It'd be like if you bought a brand new car from a dealership, then two weeks later the police came to your house, told you it was stolen and burnt it down.
Plus extra points for following through by not actually ever remotely bricking the phones before the anticipated useful lifetime of the real thing. Nagging may or may not be very bearable depending on consumer goodwill.
I know people click through warnings. If that warning could keep them alive, as a dev I'd better do something that'll get their attention.
Also, if they only softly bricked these phones the counterfeiters would just click-through the warnings and sell the phones that way. They have to essentially burn them, for the safety of people who need to be their customers.
If you want a regular phone running whatsapp, use that.
If you didn't want that, there were cheaper phones - even counterfeit.
Oh well, more reason to never consider purchase of one of their devices. Shame because they actually are doing some decent software development.
The factory they contracted to assemble their phones is running extra shifts off the books and selling the extra phones for extra cash on the side. This happens all the time in China.
Does anybody know who made the phones?
[Just bricking Blackphones is a terrible move; letting the users know their phones were counterfeit and leaving them on would have been a far better move, IMHO]
That's the point of the GPL. If the users took care of only buying products including only GPL'ed software, then they would have the freedoms: 1- to use the software, 2- to copy it for their friends, 3- to get the source to audit it and modify it (so they would be free to remove any backdoor that wouldn't exist in the first place for this very reason), 4- to compile the source to binaries and use them to replace the provided binaries (so their may increase their level of trust of the software they run on their hardware).
Do not buy products that come with freedom-restricted software!
Even if there were an alternative OS, I'd say it's still pretty well bricked, since installing alternative OSes is outside the skill level and/or comfort zone of most consumers.
I mean, I recall discussions of whether something was really bricked if you could rescue it by hooking up to a JTAG header.
Practically every device i've ran into that has been bricked has been put into that state via software. It may be impossible to fix such state without a JTAG bus and code from the manufacturer, or by desoldering chips, but I can't remember recently when something bricked was truly destroyed and every recovery method was rendered impossible.
(bearing in mind I wouldn't consider something like a ran-over laptop to be 'bricked', but rather just destroyed)
I'm sure some folks use the term when they are referring to destroyed equipment (a 'bricked' gpu from overheating) but I haven't really encountered it personally.
Whenever I get an update on iOS you get the lovely huge Apple T&Cs, which you have to accept to install the update.
So if SilentCircle does the equivalent and put in there "in the event that this is running on a non-approved device, we'll disable the software" then I click "I agree" it would seem fair enough for them to so.
If I were them I think playing it a little cooler would've been to pop-up "Hey this is a knock-off device, we're not letting you use all the cloud service and you're getting no updates from us" and leave it at that...
From the screenshot, it's not entirely clear to me that the baseband is actually bricked. The updated OS refusing to run on some phones isn't the same as damaging the phone.
Thank you for the laughs!
The genuine phones sell for 662€ with a one-year subscription.
http://www.legislation.gov.uk/ukpga/2002/31/section/1
I'm a bit surprised that isn't the case in the US.
This also affects Bluetooth and WiFi MAC addresses, even of laptop computers (!), if going by the letter of the law. Trivially changed by userspace tools, and IIRC Apple randomizes the MAC addresses to prevent people tracking other people's devices.
Edit: It gets even worse, in theory anyone distributing software capable of changing MACs or writing tutorials on how to do this commits an offence. Just look at http://www.legislation.gov.uk/ukpga/2002/31/section/2, it's madness.
Sounds like two critical flaws to me.
> In conclusion: the firm has no control over its supply chain and embeds remote control into its devices.
Dirty secret: Nobody has control of their supply chain anymore.
There have been Samsung and Apple phones being sold on the black market before the real ones.
If you assemble in China, you can be cloned tomorrow.
They build a secure phone. It gets ripped off by the manufacturer and resold by anonymous eBay people who can install whatever backdoors on the phone. Then the people using them are being snooped on - exactly what they don't want in the first place.
Bricking the phones is the right thing to do.
(It's also not Silent Circle's fault if the counterfeit devices were sold with a locked bootloader, precluding the installation of another Android distro.)
If someone was selling laptops with a pirated copy of Windows on it and a Windows update recognized the unlicensed install, causing the laptop to be non-functional, would that be any different?
Remember, the maker of these dodgy laptops has locked the bios so that you can't reinstall a genuine operating system...
To complete your laptop analogy, this "new" laptop from Best Buy turned out to be goods ripped off the assembly line at the Dell factory before the unit had its Windows OEM license assigned or paid for. The software is unlicensed and therefore not genuine. It is not for Microsoft to offer sympathy and a blind eye, they are well within their rights to identify counterfeit installations of Windows and disable them. The remedy is for Best Buy to offer the customer a full refund.
Silent Circle doesn't owe these consumers anything and are well within their rights to have all of their software completely self-destruct. They don't owe these consumers a robust mechanism to install an AOSP distro. They don't owe these consumers a bootable device. They don't owe these consumers a discount on a genuine device.
The only correct resolution is for the scam victims to receive a refund from the seller.
I could see stopping service on those apps, but bricking the baseband is a step too far, as you lose 911 access and Silent Circle almost certainly had no part in the baseband firmware development and is not a rightsholder to it.
I should also point out the claim that the baseband was intentionally bricked is unsubstantiated. We don't know if that's actually happening. Or if it's happening, we don't know if it's intentional.
The percentage of proprietary software on the phone — be it five percent or fifty — is orthogonal to the point.
This type of attack is just a test case that any truly secure device has to defend against. I'm not advocating a specific mechanism of avoiding this behavior, because there's obviously work to be done here to come up with a better mechanism than "every user audits every line of source before installing". It's just that this design work has to be done - "security" based on trusting a company is easy, and doesn't differ appreciably from what say Apple already provides.
^ with the debatable exception of software distributed in source code form in a language you're able to audit and compile yourself, though you'd still be vulnerable to cleverly concealed exploits
So, I don't think it is accurate to say that it 'allows remote control by its masters,' as it appears that they just added some sort of check in the latest version of their OS that can tell if the hardware is legit. There isn't any evidence, at least not in the article, that indicates they have some sort of remote control/phone home service running on the phone that allows them to control it arbitrarily.
What's fair to say is that you're implicitly trusting Silent Circle to be both competent and benign. But then running pretty much any modern computing device requires you to trust various groups of people in that regard, so this isn't that different really.
The only alternative would be coding the thing 100% yourself.
The only question is of who you choose to trust and how informed your decision is.