6 ms·
Are there any open source alternatives to the iPhone that might take off because of these happenings?
by bmay 11y ago
Are there any open source alternatives to the iPhone that might take off because of these happenings?
- blisterpeanuts 11y agoI was wondering that as well, but on the other hand, by its nature an open source device would be much easier to hack, would it not?
- abrichr 11y agoNo. This is called security through obscurity, and is not effective. See: https://en.wikipedia.org/wiki/Security_through_obscurity?wprov=sfla1 https://en.wikipedia.org/wiki/Security_through_obscurity?wpr...
- xaduha 11y agoDon't keep stuff on your smartphone, that's my solution. At most it should be a thin client.
- MCRed 11y agoYou don't see them going after servers, because the servers are far more vulnerable.
- xaduha 11y ago> You don't see them going after servers, because the servers are far more vulnerable. Really? Every kind of server? I'm sorry, but that's some ridiculous statement. A device running proprietary software that governments have physical access to (after it was confiscated) is less vulnerable than (possibly) your own device running open source software that nobody except you has physical access?
- onion2k 11y agoThe statement "servers are more vulnerable [than phones]" doesn't mean "every server is more vulnerable than every phone". It's a more general point; trusting any given server is a greater risk than trusting any given phone. The fact that you can harden a server against attacks doesn't mean that your data being stored in the cloud is safer because, on the whole, people don't do much more than the minimum. Phone manufacturers do do more than the minimum.
- xaduha 11y agoWho said anything about "the cloud"? I've edited previous comment.
- onion2k 11y ago"the cloud" and "on a server" are the same thing.
- xaduha 11y agoNope. And in any case that's one area in which "security through obscurity" can be useful. Presumably you have your phone on your person, but the fact that you have a server somewhere has to be determined. And if we are being completely paranoid, then you can have some form of Dead man's switch or "self-destruct" option. You have a right to make a phone call, right?
- ChristianBundy 11y agoYou have to be trolling, especially given your Hacker News bio: > Currently working on a server in Chrome that you can connect to using node.js to make a web page do stuff (and no, that isn't back to front). ?!?! I have no words.
- onion2k 11y agoNot at all. That particular project uses https://github.com/GoogleChrome/chrome-app-samples/tree/master/samples/websocket-server https://github.com/GoogleChrome/chrome-app-samples/tree/mast... in Chome. It is a server, and it runs in Chrome. I've made an extension that works as an API so that external clients can connect to it to access the DOM and change parts of a webpage. It'd be stupid, but there's no reason why you couldn't use a system like that, running in Chrome, listening on an IP address, to do pretty much anything a "real" server does. The user wouldn't know. It's just a server, or "the cloud".
- newman314 11y agoSo keep data In the cloud say at a Google DC?
- xaduha 11y agoIt depends on what kind of data it is, but sure, Google DC is fine, as long as you use software/crypto that is considered to be secure and encryption keys are truly yours. But I'd say to look at how people hiding their money from their governments are doing it. Or look at Snowden. Let the law help you, even if it is the law of another country.
- rbanffy 11y agoThat's not enough if the machine can be tampered with and your data or keys copied while in transit or use. You can hide as long as the government doesn't know who you are. When they do, it's game over for you.
- deleted 11y ago[deleted]
- xaduha 11y agoAgain, I'm only talking about relative security compared to a phone. In any case you can create an encrypted container locally and then upload it to a remote server, doesn't really matter that it was intercepted.
- venomsnake 11y agoNo need. The only thing apple must do is change the ios key management. 1. Once you buy the phone you (via itunes) create a RSA key pair. Put one of those in the phone. That key is set and bootloader uses it to verify loaded updates. 2. ios updates come to you signed by apple, you must resign them with your itunes and then they could be loaded. So you obtain the ability to sign your own software on your own device. In that case no amount of Apple assistance can help FBI until they obtain your private key.
- zdkl 11y agoassuming you trust the updates in the first place
- btreecat 11y agoWhich for most users will end up stored in "My Documents/Downloads/my_apple_key.pem" and with out a password.
- shimon 11y agoSure but at least the security of the system is proportional to the strength of your password.
- pquerna 11y agoAassuming this was real, Apple would store the private key in Keychain[1]. Keychain is encrypted with your login password generally, and can have an ACL to only allow iTunes.app as an allowed application without further user prompting. [1] - https://developer.apple.com/library/mac/documentation/Security/Conceptual/keychainServConcepts/02concepts/concepts.html#//apple_ref/doc/uid/TP30000897-CH204-TP9 https://developer.apple.com/library/mac/documentation/Securi...
- ikeboy 11y agoYou lose your key, now you can't upgrade the phone. Nobody can, so the phone goes down in value. Perhaps the ability to completely restore shouldn't require your own signature.
- ska 11y agoYou aren't likely to ever get an open source baseband, so first off you're going to have to have a platform with very clean separation and little or no DMA. Then it's going to need a hardware key separation something like what apple is doing with the enclave approach. Are there any projects like this?
- TaylorAlexander 11y agoMy hope has been that we could pressure the government to open up more radio bands for public use, then create an open source baseband that communicates on those channels. This would have the side benefit of eliminating our reliance on the large carriers for our communications. There is some spectrum in the 600MHz range the government have been talking about re-purposing, but frustratingly they seem more interested in giving that to corporations than letting the public use it. Then you can engineer the over the air protocol to be anonymous. Tower operators could be paid by bitcoin. A truly secure cell phone network is possible. The problem is that certain people don't want us to have secure systems, and we're somewhat reliant on the government to afford us that opportunity. I would imagine that if you focused on how it would help out poor Americans by offering them something cheaper, you'd get more traction than if you focused on privacy.
- ska 11y agoThe problem with an open source baseband isn't so much the availability of bandwidth (although that is an issue) but maintaining control of TX and RX power and shape. You'll never get regulatory approval for a device that is both user modifiable and capable of incorrect signalling (at least, not without some other controls, see e.g. HAM licensing)