Linux Phones (2022)
madaidans-insecurities.github.io
madaidans-insecurities.github.io
> The switch is useless in either of these threat models:
> To prevent cell tower triangulation, you can simply enable airplane mode and it is just as effective.
The threat model for linux phones is completly different, since they use free software und hardware wherever possible.
My Linux laptop runs all open source software, from "trusted" sources. My pinephone runs all open source software from "trusted" sources. If I don't trust Fedora or Alpine, I can download the source rpms and build them myself.
My devices still give _me_ control over them, and allow _me_ access to inspect what my applications are doing. If I am paranoid, I can run `lsof` or `strace` and see every file touched by an application. I can monitor my network and see ever egress host.
It is a completely different threat model than you would have with an Android or iOS device, where you have no trust in your applications or ability to inspect what is happening on your device.
I wouldn't mind a bit of isolation between apps on my Linux desktop (and phone). I would mind the cost of bringing one or several additional copies of a Linux system and degraded performance though, so I'm not a fan of Flatpak for this reason.
I end up not installing a lot of Flatpak apps because of disk space usage anyway. Each package choose a different base system so they end up sharing nothing and taking hundreds of megs each, it's quite annoying.
On the PinePhone I only have OSM Scout Server and Pure Maps installed like this, and that's really because there are no Debian packages for them.
Skimming through the recent comments, there might be a way to optimize some of it.
It is nicer to be open. But it is not paradise.
This isnt some iMessage that is pre-installed that is full of 0 click exploits. This is FOSS that has been tried and tested for a few decades. Sure there might be some cases where someone didn't update software for an exploit, but you'd still need to have that specific software, and I imagine that you'd need to chain a few to make it useful.
I can't see how a Linux phone is more dangerous than an iPhone. (aside from social engineering scams)
I would have expected users to be running software specific to mobile devices, which is very niche and much less tried than it’s closed source competition.
You can’t text or make phone calls from VIM
And you can definitely text with VIM, by using scripts like https://man.sr.ht/~anjan/sxmo-docs/ or something custom ;)
I can see the appeal of having a fully libre phone, but since that isn't possible, it's hard for most people to justify going full Linux.
Arent they running tried and true FOSS when they use chrome? Android?
I think I'm not understanding your point.
Linux phones might be good as a hackable/tinkering-friendly gadget, but they are definitely not secure.
I'm not sure of ANY linux 0 clicks found in the wild.
Some sizable fraction of that is because there is not as big of an audience, so there's less money and attention on developing exploits targeting that OS.
But also FOSS doesn't rely on security by obscurity. We'd see way way more linux based server hacking. Right now, it seems like these are almost exclusively social engineering attacks.
There is still no real Linux (or any kind of FOSS) mobile-oriented userapplication scene. As long as a mobile Linux distro is a hacked together desktop distro, I think this should be improved.
At this time it's a pain to use these phones. Hacking them (in the sense of evil hackers with baklava over their head) is even bigger pain (unusual things usually panic the kernel often) - and the reward is very small (as due to the pain very few people use them in a serious manner)
The happier security blogs are those that then go on contributing/demonstrating solutions to security problems. Why not start from what can I, as a security professional do to fix some of these problems?
Informing companies about the flaws in their products is one of the major things a security professional van do to fix some of these problems.
Alternatively, they could get hired by Purism, convince the CEO to put major investments into an OS overhaul and work closely with several teams of programmers to secure the software. Should be doable with minor mind control powers and a couple years of runtime.
The hardware is out there and can't be altered. The software is out there and is the result of decades of hard work. Many of the fixes are out there already, but the company writing the software hasn't looked for them or didn't care to include them.
What exactly do you expect one single security-aware customer to do about this? Best you can do with a blog is warn about the security risks of practically any Linux phone so that people who care about security know the risks and snakeoil involved, and probably just buy an iPhone or Samsung if they really care about not getting hacked.
Yes, but it is a common misconception that "informing others" is at the core of their contribution. I think is mostly rooted in what earlier generations of security professionals were doing, ie. researching and reporting.
There are merits to knowing the unknowns, but if this happens in a vacuum, it merely causes FUD and stasis, not solutions. (Warranted FUD, but nevertheless fear, uncertainty and doubt.)
In many cases (especially with more modern security professionals) the ones finding the problems have the skills, means, time and resolve to do something about it as well. I therefore invite those to get into the trenches and do the tough work of contributing fixes and improvements, balancing their pet peeves against other aspects, features, etc.
You don't need to convince the Purism CEO of anything, it's all open source. If you feel an overhaul is needed, give it a go. I'm sure they'll consider it if it's an improvement, and if not, have their customers decide.
> What exactly do you expect one single security-aware customer to do about this?
We're talking about a hobbyist device. Battery issues. Tinkering. Enthusiasts. Not some mass market bling trusted upon by millions.
A single security-aware customer of Pine/Purism hardware is likely to be a tinkerer too. On her/his own, she/he can't fix everything — you need a community. But single customer can't expect their Linux phone vendor to fix everything either. This isn't Apple or Google.
If a single customer writes a critique on software design, people shrug. But for some reason, it the critique is not about esthetics, performance or ease of use but about securitah, there is often this kind of entitlement that their critique should be taken seriously, instantly.
Sometimes, the "security expert" wouldn't know how to fix the problem they found. But often they do have the skills, but somehow are afraid to get their hands dirty. I think that's sad.
Balaclava is the headgear, though must admit imagining a bad actor with delicious pastry on their head was amusing.
> Linux phones lack any significant security model [...]. They do not have modern security features, such as full system MAC policies, verified boot, strong app sandboxing, modern exploit mitigations and so on, which modern Android phones already deploy.
Fair enough, not untrue. But same goes for most modern Linux server/desktop distros.
The point being the threat model, where Linux users are generally expected to understand what they are doing. Whereas with Android and iOS there is a (mildly curated) ecosystem of millions of apps pushed onto users. The apps are an obvious attack vector for all kinds of privacy invasion and worse mischief, that need to be mitigated by sandboxes, privilege management, signed images, etc.
Not saying a Linux phone doesn't need those protections in depth, but come on; Librem / Pine are in their infancy, give them a break. If I get a Linux phone to call people, make photos and run Firefox — I'm happy! Much rather have developers invest time in hardware support, battery life, etc. upstreaming contributions into the kernel, than waste their time going re-doing Android.
Disagree. openrepos.net has existed for (more than?) 10 years. It's not huge, but it does exist, it is active, and they make cool stuff.
- the firmware is full of holes and receive no patch after a short period of time.
- the phone itself come with a spyware included (the google apps).
You mix that with the recent news of an AI being able to determine what you're typing from keystroke sounds, and a hacker having access to the backdoor can't only hack your phone but also steal your pc credentials
Problem is that Cellular is most surveilled domain in the world.