Verizon announces plans to install a download-tracking app on its Android phones
eff.org
eff.org
And please don't say iOS. It's closed source, which means we really don't know what's going on under the hood. We may trust it today, but one secret court order + an overnight update is all we need to lose everything with iOS. Apple execs may not even be made aware of such an update if the order was delivered to the engineers directly.
What are my options such that I'll actually feel comfortable when I sleep at night? My phone knows everything. All my emails (which can typically be used to get into everything else), all my contacts, all my calendar events, where I go every day, and I'm even paranoid that it records all of my conversations. This isn't schizophrenia, we know that devices record people's conversations without their knowledge. A phone doing the same is just one step away.
So what can I do? How can I get some sanity and security around my mobile life?
Would be a great step to have a phone that:
+ Fully open source. (Sorry Android you don't count) + Hardware switch for mic + Hardware switch for location services
Or at least a phone that is beginning to move in that direction? Should I just stop using my phone?
There are no alternatives until we have an open baseband.
Every objection you state in your comment about android (and iOS) is dwarfed by the objections you would have if you truly understood the two other general purpose computers inside your phone that you have no control over - namely, your baseband processor and your SIM card.
Your carrier owns you. Your carrier owns you more deeply than any spyware author ever dreamed of owning you.
Your carrier can upload and run arbitrary java applets onto your SIM card without you ever knowing. Your carrier, depending on which SOC you have and how it is implemented, can access your CPU and memory directly. As in, read the passphrase of your cutesy encrypted chat app as you key it in.
We cannot begin to speak of a secure mobile platform or any kind of open source mobile platform until we have an open baseband and control our own SIM cards. We are very, very far away from this.
In the meantime, you have two choices:
1. treat your mobile device as fully compromised and behave accordingly. This is what I do.
2. Buy a non-cellular mobile device (for instance, the old "samsung galaxy player" devices that have no mobile chipset or SIM card) and insert a cellular modem into the USB port and segregate that function there, and use VOIP software. This actually sounds sort-of workable except for one interesting problem - in addition to handling cellular communications, the baseband also handles voice quality like noise cancellation and so on that also needs to be done in real-time and not interrupted by userland events ... and so your actual voice quality will drop as a result of using VOIP on a handset.
Like how many people with legitimate concerns about baseband tampering can safely carry a dumb phone?
For Qualcomm at least, they share a lot of code with Android, and nearly all the code is fully closed source, even to Apple engineers building the phone above.
Note that code does everything from camera autofocus to doing NAT for tethering, to audio decoding while the CPU is sleeping, to setting up the GPU, to handling supercomplex GSM protocols, to determining USB charging current and serial debug interfaces. It is probably more complex than the whole of the rest of the OS.
Looking at the quality of open source code from Qualcomm, I have nearly zero confidence in the security of that baseband. I'm confident you could find an "accidentally" open debug interface within a few days of looking.
So Android is "open source" even though most of what makes Android Android to most users -- Google Play Services and all of the Google apps and third party OEM apps are closed.
But iOS is closed source even though parts of it are also open source?
Android will run ( and performs all the expected smartphone functions ) using only open-source.
iOS won't boot using only open-source.
I'm not a fan of Android in general but reluctantly continue using it with that distinction as consolation.
iOS has the high ground between the two, but neither are anywhere close to acceptable.
If CopperheadOS is installed the only attack vector Verizon could use is the SIM Card, but CopperheadOS implements a lot of security features that could help mitigate the risk:
* Full verified boot, covering all firmware and OS partitions.
* Baseline app isolation via unique uid/gid pairs for each app.
* App permission model including the ability to revoke permissions and supply fake data.
Carriers can not install software on phones connected to the network. Assuming they installed a Carrier configuration application or anything else using the SIM Card you could revoke its permissions or supply fake data, or even create firewall rules to disallow the traffic manually.
More security features:
I don't think we will ever solve that problem without more support for projects like CopperheadOS and ReplicantOS. They are struggling to even maintain and improve just a couple devices.
374 points, 441 days ago, 118 comments. Note the discussion about baseband.
https://www.silentcircle.com/products-and-solutions/devices/
Take something like that - but use a RasPi Zero W - add on a better touchscreen (plenty of options there).
The Arduino version used a 3G module - but if you are willing to fork out the money, you can find 4G modules out there (they aren't cheap, though).
Then all you have to do as the code magic, a 3d printed case, etc...
You'll still need a cell service provider, of course - no real way to get around that, unless you wanted to set up some kind of wifi auto-hacking system to scrounge off of insecure (and other free) wifi nodes (coverage would be spotty, of course).
Two problems remaining why this won't happen:
a) Baseband (which in some cases has direct access to the microphone, or worse, DMA link to the CPU, or even worse, integrated into the SoC) firmware
b) Linux kernel. So many manufacturers either blatantly ignore the GPL by not releasing kernel source code, and nearly all of them, instead of cooperating with upstream, fork the kernels and add literal crap on their trees. The horrors I have seen, especially in leaked Mediatek source trees... unimaginable. I can certainly understand why Mediatek does not want to release kernel sources.
Also this is the biggest threat to the Android ecosystem. Either some kernel contributor sues Mediatek and other shoddy OEM/ODMs for enough money that they go down (unlikely), or the kernel forks by manufacturers will go so hard out of sync that new userlands of Android will simply not work with fossilized kernels. Same as in the embedded-Linux world...
I believe a lot of manufacturers operate by "lets either not release code at all or code so shoddy no one else wants to release anything based on it", and thus holding privacy, security and competition hostage. Especially as competition is stuff like cyanogenmod which removes all the nasty tracking/adware whose data sales the OEMs intend to monetize...
Have there been other carriers pushing such spyware out to Android phones in in addition to Verizon?
Verizon has made several attempts at unlocking the carrier data including the short-lived header injection [1]. Phone data is the holy grail of data (location, voice conversations, web browsing, apps, address, and potentially purchase history in the future) etc. Lets see if they have a winner this time
We need to get developers to stop supporting ad tech. The stigma of working in ad tech needs to result in enough stink on one's employment history that it's not worth the hassle.
I understand that the logic goes that people will avoid going into advertising in the first place if it limits their employment choices, but that assumes there isn't enough work to stay in advertising. If advertising is already a profitable career path, switching industries later is not a significant consideration now, and your proposal actually makes it easier for advertisers to hold onto talent.
We should be encouraging people to get out of advertising, not stigmatizing it.
Ad tech really needs to go.
I recently had my first "positive" customer service with experience with Verizon switching to their unlimited plan. My bill dropped significantly. ($120 base -> $80 but really $200 -> $80 because I always go over on data)
I just noticed that I have a "phone upgrade" waiting as well. I am an Android dev and typically just buy unlocked phones when I need them and switch SIM cards. This sort of shit is why. Even as it is, Verizon branded phones are filled with crapware you can't delete. It sucks knowing that thru my monthly bill that I am subsidizing a "phone upgrade" program that I am never going to take advantage of due to the way Verizon molests Android before giving you the phone.
If Verizon did all this stuff on an opt-in basis, I'd have no problem with it. If it were opt-out, I'd be grumpy, but would probably deal with it. When it's required, I'm going to be looking for alternatives.
This is what my wife & I did for a while (but with AT&T, since we wanted GSM). Although now we're both happy Republic Wireless customers.
One of the reasons that your phone bill likely dropped is that Verizon no longer couples the cost of your phone with your contract.
This sort of shit is why I only get phones I can root (except for my current iPhone, which was Buy One, Get One).
Root gives you access to tools that can disable/backup/uninstall stuff you otherwise couldn't - as well as access to more powerful adblockers and other goodies.
You have to be careful to try and get "trusted" apps (I don't download "cracked" ZOMG!FREE! games... anymore cough) but it's not like you control what's on your phone 100% anyways...
Guess they gotta make sure Mr. McAdam can earn his $18,000,000 check.
Verizon can't poison Apple's phones, because Apple profits by not selling out their customers.
Google benefits from surveilling their customers, so their OS is surveillance-friendly. By piggybacking on Google's purpose-built surveillance-friendly OS, Verizon's commonality of interest with Google benefits them.
I use Android and iOS so I don't have a horse in the race, but it's disengenous to claim that Apple's business model makes it any more your device than Apple's.
http://iphone.appleinsider.com/articles/17/02/01/see-how-app...
Apple has the power here. Verizon needs the iPhone on their network more than Apple needs to support Verizon as a carrier.
If you can't, bluntly, you're blowing smoke.
Which is it?
I am honestly unsure of the limits on this feature.
Ting, a MVNO and ISP, views customer privacy as an important value.
While Ting may not be able to prevent their upstream mobile providers from bundling such an app, everything I've seen from the company would lead me to believe that Ting would fight it as best it can on principle.
https://ting.com/blog/congress-votes-repeal-broadband-privac...
Also, Ting voice and SMS roam on the Verizon network. Less expensive, too.
No one should spy on you. Period.
Google is a company that relies on trust. If I can't trust them with my data their business will seriously suffer. Verizon in no way cares about users trusting them, it's not in their business model.
It needs to be a choice what companies I trust with my data
Verizon could do this and "offer" faster internet, claiming this tracking is what enables everyone to have faster internet for "free." There's a cost to everything -- including giving away your information. If there was no cost, then Google and company wouldn't want it. The fact that they're able to make money from it implies there's value, and if you're giving away value, it must be costing you. It's just not dollars.
I still think you shouldn't let anyone spy on you, free or not. What Verizon is doing is just the same as them raising the price of their service, except worse, because once they have your data the returns on it will only compound.
[1] http://www.verizon.com/about/news/dispelling-the-myth-of-a-t...
Edit: This may be an unpopular conclusion but it based on facts.
https://www.cnet.com/news/people-trust-nsa-more-than-google-...
Verizon's ethics aside, I have no real trust in their competence to keep data to themselves. I've dealt with their website, I've read the stories of people getting their accounts hijacked because Verizon can't handle verification right, and all the rest. I don't want a side channel to track my downloads, location, and god knows what else because I expect it'll be compromised far faster.
Google seems to do a better job protecting their network and defending user security.
This is key because companies are going to make decisions based on what keeps them in business. Apple would place it's hardware sales over it's ad business in a heartbeat, whereas Google would abandon Android before it would give up on ads, because that's it's entire business.
My hope is that companies that don't place advertising as a core part of their business can be convinced that there is a market in privacy-oriented products, and that competing on advertising isn't worth it.
convince yourself all you want of your fantasy, in the end each business unit has their own rules. and jobs is not the anymore.
good luck with that.
Only "desirable" phones can set rules about what the carrier can and cannot do. Today, thats the iPhone only.
Unless customers will leave the network if it does not stock a particular model of phone, then the network can insist the phone manufacturer install crapware, and until the manufacturer agrees, that model won't be sold.
It's hard to say whether Google would sell everyone's Android's data anyway, if it had 100% control over Android, but I imagine it wouldn't let carriers or OEMs add whatever tracking apps they wanted on the devices.
At first the lady was perturbed that I called, but after calmly explaining to her what was at stake, she actually seemed to agree with me it was a problem. I pray she gets to keep her job, considering she agreed with me on a recorded line.
The takeaway from her is that Verizon does not plan on soiling Google Pixel devices due to their deal with Google to keep the ecosystem clean and allow Google alone to push software updates to the Pixel line. I'm praying this is the real story and I won't come to learn my phone has been infected with spyware.
>Surely they are going to be loading it using Carrier Configuration tied to the sim card... As soon as you put a verizon sim card into your unlocked non verizon phone it installed a bunch of helper apps.
>https://source.android.com/devices/tech/config/carrier.html