Since the Encrochat scare I would imagine no dealer in their right mind would ever use a crimephone again.
Since the Encrochat scare I would imagine no dealer in their right mind would ever use a crimephone again.
Anything you can point me to read about that?
There is no way to know whether either of those services were compromised simply due to their express purpose of forwarding everything to government agent’s computers
They’re just simply not capable of providing users any of the assurances they claim in a way the user can ever have the assurance of
There may be some level of encryption, it acts like a company set up by the government or made to be tapped into.
This wasnt conspiracy theory fiction even before Anom, as there are other examples of governments especially the US government doing this already. Just let Anom be another more clear cut reminder that it doesn't matter who you trust that uses a software, if it doesn't pass some key criteria then don’t use it. There is no “I’m sure this large group of people thought of that” just assume they are stupid, negligent, thought the same as you did and nobody attempted any scrutiny, or are all informants themselves.
https://www.reuters.com/article/us-mexico-telecoms-cartels-s...
Plus, managing DIY security is more complicated than just running Signal on an encrypted phone. Same concerns regarding supply chain interdiction, remote code execution, and other security vulnerabilities on the operating system running Signal.
Yes, but specifically to supply chain security, as this attack shows, the most affordable option to secure your supply chain is to ensure your devices and downloads cannot be uniquely targeted.
Buying a stock iPhone in cash and downloading Signal from the App Store is a far better approach than buying a "drug dealer phone."
I do think this attack, as you imply, simply highlights how hard it is for even motivated consumers in the market to make actually secure choices, which in turn is why the market underemphasizes real security improvements.
That said, one huge caveat: any stock, internet-connected phone is always one law away from being rendered completely transparent to law enforcement with legal jurisdiction over the place of sale.
In the US, for example, Congress could write a law that forces a back door.
The back door doesn’t even have to be to the encryption keys or algorithm, but could be a simple screen capture interface that can be remotely triggered with a warrant.
At least there’s this:
> The Assistance and Access Act contains an express prohibition against building or implementing any weakness or vulnerability in software or physical devices that would jeopardise the security of innocent users. This is found in section 317ZG of the Act which also makes clear that any assistance that makes a system's encryption or authentication less effective for general users is strictly prohibited. This same section prohibits the construction of new decryption capabilities and rules out any requirements that would prevent a company from patching existing security flaws in their systems.
https://www.zdnet.com/article/whats-actually-in-australias-e...
people make this mistaken assumption constsntly.
also, if a criminal had enough intelligent, they tend not to be criminals. very rarely do you find full blown intelligent criminal syndicates.
mostly youll find that basic human heuristics, like security through obscurity is the height of security.
They made it invite only
They also made it a 6 monthly subscription fee
I know I'll get told off again for finding this very very funny, but honestly these guys got duped and deserved it.