A review of the Blackphone, the Android for the paranoid
arstechnica.com
arstechnica.com
* the microphone
* the GPS chip (or if not possible, the GPS antenna)
* the GSM chip (or if not possible, the GSM antennae)
* the camera(s)
I have talked to the Silent Circle people at MWC in barcelona and they acknowledged the current security issue with the closed source, black box baseband. This first blackphone is of course just a first step.
However, physical switches could help against certain attack scenarios.
Raising the bar (e.g. open-source software stacks) against smaller attackers helps everyone.
Being very clear about what they can do, as well as what they can't do, would be a very good thing.
Mobile telephones are a difficult item to make secure. Getting telcos to cooperate with law enforcement doesn't seem to have posed many problems so far.
If I could be reasonably certain that the baseband only communicated with the rest of the phone via a limited modem(/similar) protocol at the hardware level - which should be possible - then I'd be happy provided that 100% of software running on the main CPU was Free Software, with sources available.
That means the bootloader, the kernel, all drivers - including video drivers, zero binary blobs - the display manager, and all provided apps, need to be Free Software. Unfortunately, as far as I can tell, the Blackphone doesn't even do that. (But I'm not 100% sure. I can't find that much info about the core OS software/drivers anywhere.)
For example, I created a 'Samsung account' to try out the heart rate monitor on S5. I didn't know that if I create an account like that, the phone instantly uploads (syncs) my pictures, contacts etc. to a server somewhere. Sure, maybe that was mentioned in the long EULAs, but it's not practical to read through all the EULAs everytime I crete an account.
In addition, the 'Samsung account sync' app was installed on default, so I didn't even get to accept the app (or even read what access rights it had).
I was shocked and horrified. It might have been fixed since then - I've become much more paranoid and turn that crap off.
did I miss something in the writeup? OSS modem firmware, OS wifi chipset, anything hardware or firmware related?
The OS might have some neat UI for privacy stuff, but fundamentally if it's closed source and has a closed baseband (afaik, there's no phone with an open baseband), then there's no real security.
Is there no middle ground? Doesn't a device that changes your threat model from 'passive dragnet' to 'active compromise by a nation state' have some value?
Beyond that, it provides literally nothing that you can't install for free on any Android device. I could make you an equally "secure" or "private" device for $300 and an hour's time.
Yeah, this was my takeaway from the article. They even link to the Google Play store entries for the software that comes packaged on the phone. Missed opportunity, I think.
"What sells this phone is the software and services it is bundled with, which separately would sell for $879"
The software bundled with the phone makes the phone worth buying.
In all fairness I wouldn't say Ars Technica, good though some of their coverage is, are really the people to determine this.
Especially in an article in which at no point do they ask "where's the source?".
If find the trustworthy value of a phone is about equal to the privacy leak bounty. If each customer trusts the phone with, say $300 worth of information, then that should be a hell of a big bounty.
So Ars Technica should have talked about "where's the source" and "how much is the bounty".
CM11 hardening: https://blog.torproject.org/blog/mission-impossible-hardenin...
For those who understand why that's important, what do you think about CM11 on a Samsung Galaxy Player (no GSM), using wifi VPN to a cheap phone/hotspot which does have GSM baseband, e.g. Firefox phone? Or two Firefox phones, if Android apps aren't important?
Some protection against malicious firmware/hardware can come from ARM's IOMMU with an open-source Type-1 hypervisor, but these are not mainstream yet.
Whatever the technical merits of Blackphone, their marketing is increasing awareness of mobile security. If they can prove demand for this category of solution, it will increase security audits of all mobile hardware & software stacks.
That I agree and I really hope that it works. But on that note, I don't like the name Blackphone. When I hear "black" I associate it with nefarious activities; and that meaning suggests that only those with criminal purposes need privacy.
This scenario is true of plenty of smartphones shipping today, but of course it's not something that manufacturers advertise and it's potentially difficult to verify.
One should probably also be concerned about wifi firmware, though smartphone wifi is almost exclusively connected via sdio and not able to directly affect main memory.
The biggest concern in systems where baseband and wifi radios are not-too-deeply integrated is driver bugs where input from those subsystems is overly-trusted or not adequately validated -- of course solid drivers should never trust the hardware, even if not actively malicious, it can be horribly buggy.
I suspect most Tegra-based devices do -- though they introduced a combo apps/model Tegra 4i last year, which likely shares resources.
Generally if it has a standalone apps processor that's provided by a different vendor than the modem it probably does.
Even with unified apps/modem designs, some newer SoCs are designed to provide isolation between the cores, but from a tinfoil hat perspective that requires you to trust the SoC vendor (and perhaps the fab), so if you're paranoid you'd probably avoid any combo designs.
[1] http://www.ishoppstore.com/en/quad-core/4707-oneplus-one-55-...
[2] http://www.gsmarena.com/oneplus_one_in_stock_at_one_retailer...
(I posted a sort of question below along these lines but not yet had a response)
"Baseband firewall: Based upon three years of cutting-edge research in baseband processor security, the new patent-pending GSMK CryptoPhone Baseband Firewall™ offers unique protection against over-the-air attacks with constant monitoring of baseband processor activity, baseband attack detection, and automated initiation of countermeasures. A global first, the CryptoPhone 500’s Baseband Firewall provides a revolutionary line of defence against over-the-air attacks not available on any other product."
Even in jest, it's insulting and increasingly out of touch in our post-Snowden world to keep calling privacy-minded people paranoid and I wish people would knock it off.