5 ms·
With Google's Android, this issue will never arise because Android is open source. Any attempt to plant a backdoor will be outright monitored by the community.
by rms_returns 11y ago
With Google's Android, this issue will never arise because Android is open source. Any attempt to plant a backdoor will be outright monitored by the community.
- firloop 11y agoNot too sure about this. Keep in mind that in most commercially sold Android phones, closed source, self updating, Google Play Services is installed by the manufacturer with system level privileges. That alone is enough to create a non insignificant back door.
- rms_returns 11y agoBut you can always root your phone and install Cyanogenmod from scratch, right? Agreed that this is not too trivial right now because of standardization issues, but it could be done if you really care about privacy.
- cyphar 11y agoNot all of CyanogenMod is free software (you still have a bunch of binary blobs, and everyone has to use Google Play Services anyway because every app seems to implicitly require it). Replicant would be a much better alternative if it actually supported anything newer than 2G.
- ionised 11y ago> and everyone has to use Google Play Services anyway This isn't true. You can stick to app repositories like F-Droid and use Raccoon to download Play Store apps via your desktop without using a Google account on your phone.
- noarchy 11y agoIt is true that you can get Play Store apps without a Google Account, but the Place Services framework does a lot more than this. Many apps rely upon the framework for certain pieces of functionality from Google's libraries.
- ionised 11y agoYou mean Google Apps specifically? I don't use them personally but I imagine Goole Now, GMail and Google Maps would need Play Services. The apps I do use (non-google) tend to function well enough without Play Services though.
- thelibrarian 11y agoMany Android apps include the Google Play Services framework in themselves, as they provide extra functionality that is not in the baseline Android API, e.g. a JSON parser.
- 5ilv3r 11y agoFdroid is wonderful. They even strip ads from otherwise foss projects since the licenses are usually not compatible.
- chei0aiV 11y agoReplicant supports 3G devices: https://www.replicant.us/supported-devices.php https://www.replicant.us/supported-devices.php
- tomaskafka 11y agoOr, said differently, Play Services are already a backdoor. They can (and do) install updates or other software pushed by server automatically, without you being able to do anything about it. And they have access to anything on the phone.
- em3rgent0rdr 11y agoF-DROID
- curt15 11y agoAnd it can reportedly grant itself new permissions without the user's knowledge, bypassing a fundamental security mechanism of Android (any Android devs know how this is done?). http://arstechnica.com/gadgets/2013/09/balky-carriers-and-slow-oems-step-aside-google-is-defragging-android/ http://arstechnica.com/gadgets/2013/09/balky-carriers-and-sl...
- kennydude 11y agoGoogle Play Store manages the permission dialog for apps installed via Play Store (Play Services is one). It just doesn't show it for Play Services and just auto-accepts installation.
- deleted 11y ago[deleted]
- noja 11y agoNobody builds their Android from source. Nobody uses Cyanogenmod. And nobody runs Android on a phone where the entire stack is open source and blob free. Anyone who does is a rounding error.
- chimeracoder 11y ago> And nobody runs Android on a phone where the entire stack is open source and blob free. > Anyone who does is a rounding error. I'm actually curious if there is literally anyone who uses no proprietary software, including the radios and the SoC, on their Android device. My bet is that there's not even a single device out there for which this is possible. (If there is, I'd love to see it.)
- jumpwah 11y agoIt's not possible because pretty much all baseband processors (radios) run nonfree software.
- evanosaurus 11y agoThat's the current state of affairs. I know of no baseband manufacturer who has ever offered (nor seemed open to the idea of releasing) source for their chips. Basebands aside, the rest of the device is somewhat feasible to see being open.
- maccard 11y agoWhat's the closest one can reasonably get?
- spacelizard 11y agoNot quite, but you can come close. I have Cyanogen installed on all my Android devices and I try to use as little proprietary software as possible. However I am patiently waiting for the Neo900, which is a free (libre) hardware design based on the Nokia N900: https://neo900.org/ https://neo900.org/ According to them, there are unfortunately no baseband modems on the market that can legally have their firmware distributed as free software. Their workaround is to keep the modem as isolated from the CPU/RAM as possible.
- evanosaurus 11y agoNot necessarily. Despite the openness of Android/AOSP, there are still, unfortunately, things like binary blobs for certain graphics chips and closed-source firmware for things like Wi-Fi chipsets. Given what we've seen agencies like NSA are capable of (intercepting hardware in transit to apply backdoors, paying off RSA to make Dual EC the default pRNG in their crypto libraries, etc.), them compelling a manufacturer of a component to include a backdoor in their closed-source blobs is no stretch of the imagination. Apple even has this problem: basebands in cellular modems are notorious for being the source of exploits in otherwise-secure phones.
- deleted 11y ago[deleted]