The clueful people who argue in favor of Android start not by saying "you can't trust anything that isn't open source" (that would be especially silly if you're arguing for Google's Android phones, which are the only trustworthy phones), but by acknowledging the consensus that iOS is more secure and then challenging it.
On this thread alone, you've:
* Suggested that reverse engineering is a kind of arms race between the NSA and the "good guys", which it is not.
* Suggested that Tor is inextricable from Tor Browser.
* Complained about the suggestion that you might learn how reverse engineering works, because you're just a software developer.
I'm sorry, but comments the one upthread I'm replying to are indistinguishable from trolling to me. I know that's a bit of an aggro thing to say. But: do you honestly believe that the people who write advice like Matt Green in the story we're commenting on, or in the brief we're commenting on here, don't understand what open source is?
EDIT > "I'm sorry, but comments the one upthread I'm replying to are indistinguishable from trolling to me. I know that's a bit of an aggro thing to say."
If that not a personal attack I don't know what it is.
Oh and would you have time to address any of my questions? (In terms other than ios vs. android?)
2) The other choice is a device made by a Chinese or Korean company with a semi-open operating system made by a US company.
3) Either device will have a totally closed baseband chip.
4) Deploying and maintaining secure Linux environment on a Laptop is a full time job that requires expertise journalists don't have.
5) Open versus closed source is a red herring. Everyone is using pre-compiled binaries.
All iPhones are made in China by a Chinese company.
From my somewhat-naive perspective, it seems like the alternative is an Android phone made in China by a Chinese company, which seems not obviously superior.
> 1) Apple has shown substantial backbone in fighting against the US government when pressed to exploit a phone.
And the phone was exploited anyway. The only thing that was established is that Apple must not be forced to help.
> 2) The other choice is a device made by a Chinese or Korean company with a semi-open operating system made by a US company.
That makes both alike.
> 3) Either device will have a totally closed baseband chip.
This is the one the iPhone got right. On the iPhones, it is insulated by a closed interface.
> 4) Deploying and maintaining secure Linux environment on a Laptop is a full time job that requires expertise journalists don't have.
Ditto for Android, iOS, Windows, OS/2, AIX, GNU/Hurd... And anything else you may think about.
> 5) Open versus closed source is a red herring. Everyone is using pre-compiled binaries.
Open source is a necessary condition for securing against any targeted attack. It's just far from sufficient. Also, pre-compiled binaries can help you.
Anyway, both platforms are pretty much closed.
With a very salutary trend toward reproducible builds, which will help prove a connection between the source and binaries. (Though it's taking years to get there.)
Let's be honest, if your adversary is the US government, I suspect that there is no electronic equipment you can use.
Most journalists, however, are more in fear of their lives or communications when outside the US. For that, an iPhone is provably a much better choice.
I've upvoted you because of the first sentence but the second one leaves me a bit puzzled. There are plenty of places where the threat level against journalists is equivalent to the US and quite a few where it is actually less.
In fact, the current 'head-of-state' of the United States is on the record for saying the press is the enemy of his administration.
While your point is well taken, I haven't seen any US administration execute a journalist for quite a while.
Russia and China don't have quite so much restraint. And most of the petty dictatorships and theocracies make Russia and China look perfectly reasonable.
The fact that the US is not a bastion of moral rectitude does not automatically grant moral equivalence to bad or worse actors.
I am perfectly capable of condemning the actions of the US government and working to make it better even while acknowledging that it is better than most and worse than some.
"But he does it, too!" is not a valid argument for justification. But neither is it a valid reason to refrain from reasoned comparison.
Where can I get some citations for this?
This is increasingly important as it's now really obvious that the different agencies have different politics and may end up investigating each other to see who's been compromised to the Russians.
(also, you have to pick something: telling a journalist not to use a phone is a total non-starter)
Not saying it's happening here. Just reminding you they do this.
You nust have missed the whole Snowden leaks where they were all lying to Congress, courts, and so on. Far as the FBI, here's what they say: "That pertains to highly classified matters of national security. Im afraid I can't discuss that here." (Keep repeating.)
They've also been lying about their counterterrorism cases. That one expose showed they're paying undercovers $100,000 or so to convince harmless people to try something. Even financing, equiping, and training them. They sell it in court as them stopping what was already going on. Despite one informant recording them, nobody leading the FBI is fired or doing time. Deception is business as usual.
So, in courts, FBI said that targets using encryption by U.S. companies was impossible to do anything about. They needed expanded powers under things such as All Writs Act to get at the information in such devices. In secret, they were backdooring U.S. companies' products with NSA. They and the DEA were getting actionable information from those programs that they had to hide from courts under a process called parallel construction. They had to create a second trail of evidence that made it look like they found the person another way. Then, get the conviction through that second trail of evidence. The FBI was also willing to dismiss cases any time its claims were tested in court presumably because the claims were lies and methods unconstitutional.
So, the Snowden leaks, the San Bernardino case, and activity around things such as Stingrays shows the FBI will lie to courts to achieve political or legal ends. They'll even sacrifice their own court cases to protect their illegal methods. So, your claim that they won't lie in court or that court has some power over their corrupt activities is false. They consistently mislead everyone they can about both encryption and backdoors. They even exit courts when caught without any criminal penalties whatsoever. James Comey is in fact still free and directing the FBI despite caught in tons of lies from Congress to courts to media.
FBI will lie about these topics in court. They've done it consistently for over a decade now and nobody there has been imprisoned for it. QED.
The FBI does also have a significant counter-intelligence function where the endgame is often "foreign diplomat declared persona non grata".
Typical advice applies, too. Keep batteries out. Drive away from normal location to somewhere with plenty of people in cell radius but off camera. Batteries in, make call. Prearranged times or periods.
Please don't respond with the strawman you keep using of Iphone vs. Android. I am not arguing that Android is more secure. I am saying that taking either to meet an at risk source is bad. Your advice on this forum will contribute to journalists feeling comfortable doing this.
Things you probably don't know (whether based on account age or admissions within this thread):
* tptacek has been an exceedingly active member of this forum for many, many years
* tptacek has been giving us all free security advice for as long as I can recall
* tptacek has founded at least two successful companies primarily dealing with security
* tptacek has, in the past, given much advice that I've considered questionable at the time, but which has proven to be right to me after I've learned enough to realize my errors
And because that all sounds very much like an appeal to authority, I apologize again, but here's the thing -- the comments he made that you object to, and consider to be trolling? They're spot on. I'm not saying that you should believe him because he has a history of making believable claims. What I am saying is that you should believe him because he's far more versed on the subject at hand than you are, and that's by your own admissions within this thread.
It's worth taking a step back here and asking yourself how well you actually know the things you think you know in regards to this thread. I am honestly not savvy enough on mobile security anywhere near capably enough to suggest that he's right and that you're wrong, so please don't assume that's what I'm doing here -- but many of the people you're arguing with in this thread are people who have the requisite bona fides to make their claims with confidence, and while you are boldly asserting the opposite, you acknowledge that this is not your field of expertise, and that you haven't bothered to learn reverse engineering.
Again, if this seems harsh, please know that it isn't intended to. Language is clumsy, and I'm not its best handler on the best of days, but while you might be 100% correct in every one of the claims you've made, the consensus seems to be otherwise, and you haven't done a good job of convincing me that you should be believed over someone who literally pays their bills through the dispensation of their subject matter expertise on this type of material.
Because of the fantastic community, it's obvious that HN is a great place to teach and to learn. Knowing which to do, and when isn't always so obvious. Most of us have made that mistake in the time. Consider whether or not you may be making it now, or figure out how to better support your claims so as to teach more effectively, but cat-pawing at each other throughout the entire thread isn't doing anyone any favors.
Reverse engineering isn't zero sum. The benefit you get from reverse-engineering a closed platform doesn't vanish when someone else reverse-engineers the platform, just like your ability to read open source code isn't damaged by NSA's ability to read it faster.
As I said, I don't know who's right and who's wrong, but the argument seemed to involve a lot of effort for being so unproductive.
I am very familiar with the OPs posts. I do not want this to become personal. If you re-read this thread (and others in this discussion you might notice that.)
To avoid confusion for any readers, you should clarify what this means: Apple has an automated process for serving data in response to any approved FISA court orders from the FBI.
And to make this clear: U.S. companies must comply with valid court orders. Being a "PRISM member" is not optional.
http://www.latimes.com/business/la-fi-tn-apple-fbi-call-2016...