Blackphone BP1 Now Available
store.blackphone.ch
store.blackphone.ch
There is no secure phone until then.
Oh, and that neat little micro SIM you put into it? It runs fucking Java and has carrier push support for new "applications" builtin, in the meantime it stores and generates the crypto keys used by the baseband.
This is the state of mobile security. Unless you are running osmocomBB on a crusty old Motorola brick with a logger between the phone and SIM to check for anomalous activity, don't touch it with a 3m pole.
Because it seems to me that, sometimes, not leaving your doors and windows wide open, even though "they can always be broken into", is a good idea.
Is there no value to a phone that reduces your NSA dragnet footprint substantially, while at the same time building the capital necessary to develop an open baseband (as I'm sure you're aware, that is not a cheap proposition)?
Easy to make your own burner phone with customized AOSP for temporary use while in China or CIS/Russia if worried about industrial espionage or legions of criminal blackhats hanging around hotel wireless APs. After going through the source removing stuff like debuggered and GPS binaries, and writing custom init scripts can drop in TextSecure, Redphone and many other open source apps, thegrugq's Darkmatter app, platform sign them and enforce with middleware install-time mac to prevent anything else not signed being installed and use dm-verity to check system.img on boot for tampering. Lot's of business travelers need something reasonably secure to bring that they just end up throwing away when they return. Boot a Mobiflauge patched kernel temporarily with fastboot and wipe/encrypt the device when you get back for safe disposal, then flash Paranoid Android or CyanogenMod to it and sell it on CL to get some of your money back.
There's also Nexus 7 devices that can be bought without a baseband to do this. Essential reading is the Android Hacker's Handbook by @pof. Of course using any phone for something illegal is a guaranteed way to get arrested no matter what has been done to it. The hardware will always be a bundle of proprietary blackboxes, likely with a law enforcement door to brick it, record meetings with the mic or track the owner.
For some definition of 'easy' I suppose... (not any definition that the average person would use).
You can't get out of your location being trivially tracked by your carrier until you can pay for network access with anonymous bearer tokens, or at least significantly supplement with free wifi networks or friends' MiFis.
So my point is that we have the ability to assemble secure systems out of off-the-shelf components. It just takes software work to integrate and set up easy to use on-the-go telephony under bona fide GNU/Linux, and carrying around a bit more weight until critical mass is reached and the form factor can be made more convenient.
Except they won't ever be made available, since this company is full of crap. They're selling snake-oil, and shouldn't be trusted.
1. SilentCircle's encrypted messaging and VOIP solution + licenses for close collaborators.
2. Disconnect.Me's VPN
3. Spideroaks encrypted cloud storage
4. Kashmir's wifi finger printing services.
Everything is licensed for 2 years.
The primary market Silent Circle is going after at the moment is journalists, NGO workers, private military contractors etc who need smart phones at an organizational level but want enhanced resistance to surveillance.
2. One of a ton of services that cost like $3-4 or so a month and will probably fall. And sure, it prevents the local WiFi from running sslstrip at the cost of putting all your traffic at an easy-to-monitor place (the VPN provider).
3. A closed source program running access to all your data doesn't sound particularly impressive. But sure, it's better than using Dropbox.
4. Kismet Wifi manager is $2.99 on Google Play.
It might be better than nothing, but the product sounds seriously over-hyped, and some of their claims seem like outright lies or at best misleading/useless.
I also don't get, if such a combo of services was so valuable, why someone just doesn't sell it separately.
You don't need to trust anyone. There are (admittedly slightly out dated) buildable sources for the Android clients on GitHub. The whole point of ZRTP is that the server can be considered untrusted.
The ZRTP part is fine if you can bring your own client. And I guess $12 a month isn't much to pay for SC to run FreeSWITCH as a NAT traversal/endpoint discovery platform.
There's still no real details on how we're supposed to trust Silent Circle from being actively attacked and backdooring clients. If memory serves me correctly Mr. Zimmerman said they're relying on the government not being able to compel them to cooperate. AKA, Lavabit-style. (Sure, ZRTP is solid, but a compromised client isn't detectable to end-users, plus SC talks a lot about calling the PSTN.)
For a comparison to a company that takes security seriously, look at tarsnap. Then go read the PR from Mike Janke the other day.
On another note, what does "100% dedicated network – no sharing or leasing" even mean? Did SC run fibre from Toronto to Switzerland? How is SC's network any different from any other VoIP company that builds a datacenter?
Ephemeral DH for PFS, of course.
(Actually I hope you do talk about blackphone because it's a worthy political product, and probably even a worthy product product.)
It would be a shame if someone were to place a backdoor in it...
If you want true freedom and security, run Replicant. http://redmine.replicant.us/projects/replicant/wiki