5 ms·
That doesn't mean developing secure asynchronous messaging apps for smart device platforms is a bad idea (although adopting PGP over libaxolotl seems a tad fool
by blorgle 11y ago
That doesn't mean developing secure asynchronous messaging apps for smart device platforms is a bad idea (although adopting PGP over libaxolotl seems a tad foolish these days), it only means people should understand their threat model. If your threat model includes an adversary capable of taking over a cell tower or using IMSI catcher, then use a device with no baseband, like a simple tablet.
- zanny 11y agoThis is an important conversation people should have when discussing security. The dream is perfect security and trust - something that no singular person could ever have completely, because it basically requires a ton of things to happen: * You need to audit the blueprints for all hardware. * You need to verify, physically, the products of manufacturing - the physical hardware you will use - often requiring you to know the design and likewise guarantee the implementation of the fab process. * You need to audit and verify all firmware and software running on the system - from your flash controller to your chipset to your CPU to your GPU. This is on top of already having trust in the hardware. * You need to then use software that is secure. Perfect security - mathematically proven security - is probably the most expensive thing you could try in software. It is already impossible for any one individual to have audited all the hardware parts and the underlying OS and firmware, but then they need to also personally verify or write themselves the software implementations of security they will use. We all, by using computers, are yielding an immense amount of security in the form of trust. One of the cornerstones of the free software and open hardware movements are how untrustworthy a singular set of eyes upon hardware or software truly are - that having the ability to independently have someone else inspect the code, or most importantly your own ability to do so, is what gives us reasonable expectations of security. So nothing you ever use you can truly claim to be perfectly secure - you are always trusting that someone else is telling the truth when they say it is secure. In the best case scenario, a lot of unaffiliated people claim it is secure (ie, free software / free hardware). But we are well beyond the point anyone using an Internet based messaging app can presume perfect security, ever. The question is always who you are willing to trust when they claim to offer security - and to recognize when vendors are not promising (legitimate) security at all, as is the case with cell phones.
- daveloyall 11y agoZanny, I disagree with your use of the "nothing is completely secure" truism as an argument against "storing private keys inside cellphones is not a good idea". The local police department has ISMI catchers. I estimate they won't have the ability to extract a file via the baseband until something like eZing becomes ubiquitous. At that point, automated private key extraction will just become another feature of the ISMI catchers. All of this is tangential to the real problem: basebands. Both in cell phones and cable modems. Time to take 'em back. You wouldn't allow OTA updates of your router or PC... Now would you? I'll anticipate one response: "But, giving consumers control of their PHYs would be hell for the cellular/cable operators!" Well, after a few years, their/our networks (and devices) will be more secure.
- bigiain 11y ago> You wouldn't allow OTA updates of your router or PC... Now would you? Have you booted an internet-connected Windows 7/8 machine recently? "Here, have Windows 10, with all the privacy features built in to it switched off! (In fact we're already downloading ot for ypu even before you agree to install it, so it'll be ready as soon as you agree, isn't that _convenient?_)"
- daveloyall 11y agoNo, I have not. :) Well, the Windows 7 machine under my desk at work is managed by the IT dept.
- cyphar 11y ago> > You wouldn't allow OTA updates of your router or PC... Now would you? > Have you booted an internet-connected Windows 7/8 machine recently? No, because I use GNU/Linux.