Free Your Android
roussos.cc
roussos.cc
So if you really want to be 'free', get rid of the cellphone.
It's good for people to know exactly how much security they get by following particular advice :).
The official reason is that open source radio firmware would be too easy to alter to violate FCC regulations on power, frequency band, and such. It's the same reason that non-proprietary antenna connectors are mostly prohibited.
The usual conclusion is that the manufacturer claims that they cannot allow open access to their radio because of licensing restrictions, but that no restriction actually exists. It's a lazy way for them not to bother.
You can buy a board from Ettus Research and write your own baseband software. The trick is that you need a license to operate a radio at those frequencies, if you buy a phone you get to tag along on the phone company's license because they have made sure that you can't do anything that they didn't show the FCC they could do. If you have an Ettus board and you want to run a base station or an edge device you need to get a license from the FCC to use it.
Strictly speaking, the phone company could have an "open source"[0] baseband stack and they would need to provide some way for the phone to know that it is running the approved version. And that is where it gets tricky, how do you do that? You could provide some sort of EFI type signature on the baseband bits that proved they were the right bits, and you could provide instructions on how to compile to exactly those bits, and while that would help folks understand what could and could not be done with the firmware it wouldn't help them fix problems. And of course people would scour it for vulnerabilities. So we're left with the current situation.
If you're interested in playing around with radio stuff though it is pretty straight forward to get an amateur operators license and a Gnu radio kit and start exploring.
[0] -- Not 'freely licensed' so much as 'you can read the source code, and it is compilable from source'.
[1]http://www1.informatik.uni-erlangen.de/filepool/projects/arm...
All of it can be rather nefarious. Get rid of the PC? (or simply use phones which connect their modems as a peripherals and implement monitoring, like Neo900, not as a master with DMA as most phones today do)
What? Firmware is definitively executable, it just doesn't run on the CPU.
And besides, if you look at the list of proprietary files being copied, there are plenty of normal libraries: https://github.com/CyanogenMod/android_device_semc_iyokan/bl...
This might not matter for most users, but it can decide about live and death for some, like journalists in crisis zones.
Your mainboards almost always have proprietary firmware. Coreboot is woefully underutilized and underfunded in this regard.
All hard drives have proprietary firmware, and often have proprietary processors on board. They are for all intents and purposes isolated computers in and of themselves, and nobody talks about how closed they are.
Graphics hardware is predominantly proprietary, even the most open discrete cards (AMD's) which have technical documentation have proprietary firmware blobs. I can only barely trust myself using these on the pretense that others have already decompiled the blobs and found nothing particularly malignant on a few older model cards. Every other manufacturer except Intel and very recently Broadcom with a single model of GPU are whole stack proprietary.
Network radios, as mentioned in this article, are almost always either wholly proprietary or have a firmware blob like GPUs.
CD drives also have proprietary firmwares like hard drives.
All TVs are running proprietary whole stack firmware on internal computers.
Dumbphones also are computers, just whole stack proprietary.
Your fridge, toaster, many ovens, and microwaves, if digital, are also whole stack proprietary computers.
This stuff is everywhere. There is literally no way to liberate yourself. Even Richard Stallman is driving a car with a proprietary on board computer, and probably cooks food in a proprietary Microwave.
If you care about this, buy a Chromebook. The new ones have Coreboot. Of course, Google blah blah evil, but you can put your own OS in so the stack goes Coreboot->Uboot->(preferred Linux distro)
AMD is pretty much the only company doing anything in this regard. Many of their recent chipsets are supported, like fm1 and fm2.
(They even removed the CPU microcode updates, which IMHO is going a bit too far; there's already microcode in the CPU, and Intel issues those updates to fix various errata in the hardware. Maybe it was done more as an ideological thing.)
http://shop.gluglug.org.uk/product/ibm-lenovo-thinkpad-x60-c...
https://www.fsf.org/news/gluglug-x60-laptop-now-certified-to...
If the FSF likes it, I think you can be pretty sure it's as free as it gets...
[1] http://gizmodo.com/sd-cards-are-tiny-hackable-computers-for-...
EDIT: Just to clarify, firmware blobs are not executed "on their own", they are normally executed on a micro-controller that is embedded in the baseband / power management / gpu / any other chip.
The baseband, particularly, is of concern because it's connected to the outside world, and is powerful and complex. And almost always closed, and provided by an American company (Qualcomm).
The camera executes its firmware, and it has direct access to the memory, flash, network, etc.
I tried to free my Android. I did, I really, really did. I overcame the "your version is not supported by Cyanogenmod" message with a custom build that took forever to find. I overcame the "download the Windows and Windows only installer". I managed to find the Windows-only instructions for unlocking the Bootloader. I managed to install custom drivers for the phone, despite the fact that Windows doesn't really want you to do that anymore.
And then I got stuck, because my phone and Windows 7 are not in speaking terms, so the fastboot tool does nothing.
I spent a couple hours on the task, and yet I haven't even managed to complete step 1. The dead links, the contradicting instructions, the forums full of unanswered questions, it just proved to be too much to me. I'm down to the magic advice now - advice in the lines of "try a different USB port", "change your USB cable" or "restart your computer" (of course). Should I succeed in my task, I may or may not have access to Bluetooth, video and/or tethering - there are contradictory accounts, so I won't really know until I'm done.
"Very detailed instructions"? Yeah, right. How about useful instructions instead?
Their installation instructions are pretty worthless as well, as they're clearly built from a template with the device name swapped in.
Shambles.
For the Motorola X you could have a look at the relevant XDA forum (http://forum.xda-developers.com/moto-x), there might be something worth your while there. Not having one of those devices I can't tell.
1) Your phone must be in developer mode. This is achieved by going to Settings >> About Phone >> and tapping the Build Number item 5 or 10 times (you will see a notification that developer mode is active).
2) You must go into developer mode and check the "Enable USB Debugging" menu. After that, you can plug in your phone (while powered on) and after a few seconds you should see a notification on your phone asking for confirmation to allow debugging from the computer.
3)The "fastboot" command only works from the bootloader screen. "adb" is the tool you can use when the phone is on with debugging enabled. You can run "adb reboot-bootloader" and should be able to use fastboot from there.
The forums (especially xda) are full of voodoo (wipe cache three times!!!11!) and ridiculous claims (so fast! much battery life! very scheduler!). It's really hard to get at the useful information.
Let me outline the general steps to installing Cyanogen.
1. Unlock bootloader (this involves downloading at least one piece of software) 2. Flash custom bootloader 3. Flash custom ROM 4. Wipe and start over
Once you have managed to install Cyanogenmod, it's a really nice experience.
Using Cyanogen with only free software is a pain for die hard RMS fans and other masochists. It makes your phone a lot less useful and a lot more high maintenance. Central app installation and automatic updating? Not really.
If you want a fully Open Source or Google free phone there two several alternatives: Jolla, Firefox OS. If you don't need the latest and greatest check out the N800, N900 and N9 Nokia phones.
If you manage to get it working in some modified state, it's entirely possible that some random thing will cause it to go completely off the rails at some random moment, whether or not you need it then, or have access to alternate hardware, troubleshooting tools, or anybody who could help.
If you really want to have a modified phone, it's probably best to check out the community first and choose a phone model based on what is best supported. Even then, you probably shouldn't mess with it much if you aren't in a position to troubleshoot any problems that come up.
Speaking from years of experience (and as someone whose day job is Android app development) for every Android phone that has high quality developer support for 3rd party OS builds in the custom build "scene" there are dozens with really crappy half-ass amateur hour "support", and this tends to happen more on the phones that most non-hacker-types want to mod (because their carrier/vendor has stuck them on an old version of the OS for no good technical reason, etc).
If you aren't on the latest flagship phone from a big vendor or on a Nexus device, you probably shouldn't bother with custom builds unless you are prepared to deal with a lot of random issues.
The phone that you use to organize your real-life events, keep in touch with the people in your life, get important alerts, etc. is more towards the production server level of importance than the toy gadget. I recommend thinking twice before putting some hacked-up barely-supported ROM on it.
Hacking means making it work to your needs, despite all the limitations some clever suits have decided on your behalf.
For example my phone carries some immigrant files and I need them stored as files, therefore I am not able to use non hacked Apple devices.
All that said i'm itching to do it again because my HTC One is on 4.3 and I can't get the latest lens blur camera onto it!
I can say that it's definitively doable, but it really depends on what one need. If what you need is a browser (Firefox), an email client (K9 & the standard KitKat client) and a Terminal (ConnectBot, Hacker's keyboard), then you won't miss the Play store at all. There are also some good clients for social/media consummation (Tinfoil for Facebook, Twidere, TT-RSS...).
If you need something more, then it's an hit or miss. For maps, OsmAnd+ is nice, but not nearly as good/user friendy as Google Maps. Forget about the latest/cool apps. Forget games, unless you want to emulate some console (and also, running closed games on top of an open emulator is "ethically right"?).
It gets better if you're a little more lenient. For example, I have some Humble Bundle games installed. Those come drm-free, and (usually) don't depend on the Google services. One can also get applications from the Play Store, and install just the .apk for it (I can't remember if one can buy applications with the web interface, or has to do it from the mobile store). In the end, the choice is "I want to avoid Google" or "I don't want proprietary applications on my phone". In the first case, there are many alternative stores (SlideMe, AndroidPit, Amazon...).
Another problem is that F-Droid is small, and doesn't even have all the (F)OSS applications available for Android. For many, the only way to get them is either the Play Store or compile the source. I'm not blaming the F-Droid project, they're doing a terrific work for their size, but it seems that there's little interest in a completely open store, even from the developers.
That said, I'm still running this setup, but I'm considering just giving up and installing the Play Store/Google services because after a while seeing new cool applications but not being able to try them is kinda painful.
On a side note, I haven't noticed any increase in battery life/speed of my device. So it seems that Google's applications aren't an huge battery/resource hog.
Tried Google+? Just opening it by mistake (and immediately closing it) is enough to start glgps and kill my battery in a couple of hours, until I reboot.
But then I would find out my phone's battery died overnight, while it was almost full before I went to sleep, like what the hell? After few weeks of keeping an eye, I found out it was Google+. Hunderds of complaints on Android emailing list, 0 comments from developers.
Google+ is a single Google's project driving me away from being their slave for life.
Anyway, I'd install one of those "minimal" packages that contains only the Play services and the Play store, and eventually install the various Google apps (Maps, maybe Keep) from the Play Store.
This is misleading. Google's DNS privacy policy is very reasonable. The only permanent logs are at the city/metro level. I trust their servers far more than I trust Comcast's or Verizon's. https://developers.google.com/speed/public-dns/privacy
In addition, DNS doesn't send my GPS co-ordinates along with the request, so it will just be IP geolocation data which Google will collate for their own stats on their DNS servers (So they can see/log what regions people access from, etc.).
Just because it mentions storing location doesn't mean they are trying to monitor every step you take when using their DNS.
However, this is not how things is commonly done. Most client machines simply sends this work over to their ISP (or google), and wait for the third-party to do it for them. The third-party then datamine this traffic in order to get revenue.
In general, what you willingly give to a third-party can never be seen as inherently private. Additionally, An intruder that want this information would have to hack, tap or steal the information rather than just leaning on the ISP/Google.
I agree with you, but if Comcast of Verizon are your ISP, they can already see/log which sites you browse (Unless you use Tor or a VPN, that's it) without the need to log your dns requests.
So, as funny as it sounds, I use my ISP dns server for "privacy" (the right term would be "for not telling even more third parties which sites I browse").
On HN: https://news.ycombinator.com/item?id=7715041
Original: https://blog.torproject.org/blog/mission-impossible-hardenin...
It's interesting because the site has gone to some length to host jQuery, Bootstrap and other stuff you could see referenced in HTML source, but CSS file requires stuff from Google servers. So maybe they simply missed that one.
FOR PEOPLE WHO AREN'T OF INTEREST TO THE NSA (THIS IS MOST PEOPLE): You're putting massive amounts of effort into keeping the NSA from getting your data, which, let's be honest, is just chaff they're collecting so they can pick through it for wheat. You really want to do something against the NSA? Start sending your data directly to them so they have to waste time sifting through the logs of what cat photos your friends want you to look at.
IF YOU ACTUALLY ARE A TARGET OF INTEREST TO THE NSA: Everything in here is completely inadequate to secure you against the NSA. In fact, you are probably increasing your own inconvenience more than you are theirs.
> Stop CyanogenMod from reporting tethering usage to your provider
I get why they are using Analytics, but why is a ROM like CyanogenMod reporting tethering usage to the carriers?
> Change DNS settings so that CyanogenMod stops using Google's DNS servers
This is probably something "nice" they thought to do for their users, but I'd rather not have that enabled by default in CM. If they're still trying to be a "privacy ROM" and whatnot, they should be using an OpenNIC DNS or set up their own encrypted DNSChain (https://github.com/okTurtles/dnschain).
* The software that you give access to your phone (be it drivers or the recovery images themselves) isn't signed by anyone. Some of the software isn't even available via HTTPS. I think it's a bad idea to trust some HTTP and unsigned executable more than Google, who are making all they can to ensure the integrity of anything that runs on your phone.
* Unlocking your bootloader is a bad idea. Google erases all your data whenever you unlock your phone[1]. They don't hate you, they've just realized the security issues that come from having an unlocked phone. Take this for example: You're at the airport and ready to leave. However, TSA stops you for a "random" check. They have your phone for about 5 minutes and there's nothing you can do about it. Now, they could ask you for your passcode but then you'd know something's wrong. Now, your bootloader is unlocked, which means they can see your device at firmware level and alter it to their liking it. Nothing can stop them from plating a backdoor in there or just making a copy of all your files and you wouldn't know. That's why Google does [1].
[1]: http://wiki.cyanogenmod.org/w/Install_CM_for_maguro#Unlockin...
* There is a way to lock your bootloader again.
* There is a way, however it's common practice to leave it unlocked and I'm not sure you mention that in your article.
I guess you have to ask yourself - who are you competing with? Do you just not want to be used as an advertising product? Or are you hiding from the NSA?
While producing free radio chip is practically impossible due to both economical and legal reasons (the closest you can get to it is OsmocomBB running on old 2G TI Calypso modem, and the only reason it exists is that TI Calypso has mysteriously disabled checking of firmware signature even thought the functionality for it is present...), there are devices that mitigate the risks by connecting the modem as a "slave" (for instance via USB - this might impact the performance and battery life, as CPU is busy copying data from/to the modem, but it's way more safe than DMA access) or even implement "modem firewalls" that monitor any modem activity and alarm if it does something when it wasn't supposed to do it. Neo900 (http://neo900.org/) is such project and soon there should be a longer article about this modem firewall solution published.
Otherwise if you have a Nexus phone/tablet, you can install MultiROM (http://forum.xda-developers.com/showthread.php?t=2011403) and have both Android and something else installed.
If privacy is required, I leave the handset at home and get on my bike. There is no hiding unless you turn it all off.
What you want is an illusion of privacy. The two are vastly different.
I control the software I run on my phone, so I have a better privacy. It's not perfect I know. But doing nothing because it's not perfect is the biggest illusion of all.
1) You do not control the software you run on your phone. You control almost none of the firmware, which if malicious could easily steal all of your data with impunity.
2) Simply controlling the software is not enough. Cell towers are programmed to track your every move and accessing this information is easy for the government.
3) Even if you did control the software you run on your phone, it implies nothing. The trivial example would be that clearly even when you bought the phone you controlled the software you ran on your phone.
3) Detecting usage of tethering is trivial. The stopping the reporting of the use of tethering just makes it easier for them.
4) DNS settings do not matter. Google's DNS logging policy is fine - and in any case they get no information since your phone provider will be using NAT so they'll have no way of differentiating between your phone and any other. There's no large benefit to privacy by not using Google DNS, but there is a performance cost.
5) You say that you feel safer - this is exactly the problem. All of these apps you've specified could easily have security problems in. They're not widely used, and likely are not widely reviewed. Following this guide gives a brilliant false sense of privacy, but likely little real additional privacy.
What you do on your bike may be inferred from what you do without your bike. So, your sense of privacy when you are not carrying a phone is an illusion too.
- Remove Google analytics from CyanogenMod by flashing freecygn.
- Stop CyanogenMod from reporting tethering usage to your
provider, by changing the "tether dun required" setting.
How is that not default in Cyanogenmod ?2) To pass the tests required to be carrier/google certified you must must report tethering
One thing that was worth being mentioned is one of the very best features of CyanogenMod: Privacy Guard.
It basically allows grained control over what permissions can an application have (read/write contacts, phone logs, location, etc). It's of course possible to allow an access all the time, or just when needs it.
Thanks to privacy guard, one can use applications that might compromise privacy, without compromising privacy.
When using the "ask every time", I've been surprised how many applications try to access my info for no obvious reason, sometimes even when your phone's idle.
Also, the best reference for all these issues is http://prism-break.org/
Chances are that you can connect with most people over Google or Facebook, but it's not perfect. If you are still using their servers, then it might defeat the purpose of avoiding their clients. You can use Off The Record (OTR) to avoid the privacy implications of using the servers with both of them, but none of the official clients support it, so they would have to use an alternative client as well, which defeats the purpose of using existing networks.
Also, there is literally no good foss voip and conferencing options. Jitsi videobridge is the closest thing I've found, and that isn't an XMPP standard and isn't supported by my preferred IM tools. Also, Jitsi is an ugly as sin Java app....
I'm definitely going to try putting aside a week this summer to see how hard it would be to implement videobridge in telepathy. If we could get that and group OTR encryption in it, there would finally be a FOSS communication alternative...
I'm either misunderstanding what is being said, or the author has no idea what they are talking about if they think firmware does not execute...
Android is open and free and all, but most of the devices out there don't give the user this freedom at all. Firefox OS has exactly the same problem - Mozilla does not enforce by any way that the officially branded FxOS implementation should be open. Most of FxOS phones to date, maybe except Geeksphone, are simply closed and need some ridiculous rooting or unlocking in order to just reflash them with newer version of FxOS.
Just look at GTA04/Neo900 (and possibly Freerunner too, but it would probably be massively underpowered) - you could run both Android (Replicant) and Firefox OS there without using any single line of closed source line - but that doesn't represent the usual customer experience for Android and FxOS branded phones. So where's the difference?
Closed-source code on a lower abstraction level could read the plaintext I type on the keyboard before it reaches your app. That code can apparently also "phone home" on its own term.
Thoughts?
I used it last week for testing purposes.
When is this meme going to stop? When are people going to realize that there's no point in glorifying and seeking privacy?
This article is a perfect example of everything you lose when you get into this craze. Why would anyone actively limit their opportunities and disconnect themselves from others? For an imaginary reward?
Privacy is not a trade-off. It's plain loss.
I don't think you understand the meaning of freedom. Some people choose to do what you question because they want to. The nature of freedom is that people can do what they believe (so long as it hurts no one else), even if you think it's stupid.
Second, the whole quest for privacy ultimately hurts the freedom of everybody. How you ask? By leading to the creation of arbitrary laws that limit non-coercive access to information.
A right to privacy give people an exclusive right over anything that's a product of their existence. "That photon bounces off of me and gets into your camera lenses? Well, I guess you'll have to hand over that tape if you don't want to get into troubles."
No information should ever be made private by legal means. Only physical privacy must be allowed.
Or hell, just live in the US. There is plenty of prosecution of ideologies people don't agree with - have a pedophile who doesn't practice it express their physical attraction to children and see how people like that. Or maybe you like polygamy. Or hell, in many towns it is as bad as the Middle Eastern countries - profess your agnosticism or atheism and you get denied service at establishments and mugged.
Privacy is an essential guard when people with power don't like what you think. The ability to hide information you don't want them to know can keep you alive.
When people talk about privacy, they don't think about it as a tool. They don't talk about it like people in China talk about an air-pollution mask. Do you often hear about how air-pollution masks should be a right and why we need them to preserve a freer future?