8 ms·
Why would someone who's threat model includes the US government possibly want to trust a totally closed OS made by a US company?? Do you still not see the US go
by jhlgkhkhil 10y ago
Why would someone who's threat model includes the US government possibly want to trust a totally closed OS made by a US company?? Do you still not see the US government as a threat to journalists? If not how do you justify this position?
- nickpsecurity 10y agoSmartphones shouldnt be trusted in such a scenario. Many journalists will use them anyway. In that scenario, Apple is probably better since they're not a surveillance company and it's harder to load malware.
- jhlgkhkhil 10y agoBut the OP doesn't go around saying one branch of smart phones are the best of a bad bunch - he goes around saying that they are good. How does he know? Is he better as reverse engineering than everyone as the NSA put together? (And that's not even taking into account all the potential wrench attack targets at a large US company?)
- tedunangst 10y agoWhich phone do you use that's too secure for the NSA to hack?
- deleted 10y ago[deleted]
- nickpsecurity 10y agoA strong, domestic TLA should be assumed to hack or intercept all of them if companies are local. Then game changes to the caller hiding their identity. Text-to-speech and burner phones can do that. However, messaging and email over WiFi's on devices bought with cash hides voice, has better clarity, allows file transfers, and can still do voice as an attachment.
- tedunangst 10y agoIf uber can figure out which burner phones are used by cops, global adversaries aren't going to have trouble with it.
- nickpsecurity 10y agoGood for people I told to keep their burners off unless transmitting from semi-anonymous locations. That's their best privacy technique if they're non-technical.
- tedunangst 10y agoAnd how well did they follow this advice? Would you know if they didn't turn their burner off, or even bother with a burner? "They didn't die in a prison camp, so they must have done things right"? Lay people who value privacy can fuck up their opsec pretty bad without noticing consequences. This is getting in to tiger repelling rocks territory, where it's no measure of one's stealth skills by hiding when nobody's looking.
- nickpsecurity 10y agoIt boils down to two areas of trust: a computer that's potentially malicious against a nation-state with stuff like QUANTUM; their ability to go somewhere remote/crowded and make calls. Im thinking lay people can do the latter because they have for ages. The latter also takes HUMINT to counter which is a precious resource they can't throw at all the reporters simultaneously like electronic attacks.
- tptacek 10y agoThis doesn't even make sense. "Better reverse engineer than the NSA"? What would that mean here?
- jhlgkhkhil 10y agoIt means on what basis can you stand and say to people who's lives may be at risk that you trust apple's press releases? Please don't respond with the strawman you keep using of Iphone vs. Android. I am not arguing that Android is more secure. I am saying that taking either to meet an at risk source is bad. Your advice on this forum will contribute to journalists feeling comfortable doing this.
- tptacek 10y agoNon sequitur.
- jhlgkhkhil 10y agoSo we should just trust you?
- bmelton 10y agoI want to preface this with an apology, because I don't think there's a way to say this without sounding cliquish. For that, I apologize in advance, but because your account appears to be relatively new, I feel like this is somewhat necessary. If this account is a re-roll of a previous one, then I doubly apologize. Things you probably don't know (whether based on account age or admissions within this thread): * tptacek has been an exceedingly active member of this forum for many, many years * tptacek has been giving us all free security advice for as long as I can recall * tptacek has founded at least two successful companies primarily dealing with security * tptacek has, in the past, given much advice that I've considered questionable at the time, but which has proven to be right to me after I've learned enough to realize my errors And because that all sounds very much like an appeal to authority, I apologize again, but here's the thing -- the comments he made that you object to, and consider to be trolling? They're spot on. I'm not saying that you should believe him because he has a history of making believable claims. What I am saying is that you should believe him because he's far more versed on the subject at hand than you are, and that's by your own admissions within this thread. It's worth taking a step back here and asking yourself how well you actually know the things you think you know in regards to this thread. I am honestly not savvy enough on mobile security anywhere near capably enough to suggest that he's right and that you're wrong, so please don't assume that's what I'm doing here -- but many of the people you're arguing with in this thread are people who have the requisite bona fides to make their claims with confidence, and while you are boldly asserting the opposite, you acknowledge that this is not your field of expertise, and that you haven't bothered to learn reverse engineering. Again, if this seems harsh, please know that it isn't intended to. Language is clumsy, and I'm not its best handler on the best of days, but while you might be 100% correct in every one of the claims you've made, the consensus seems to be otherwise, and you haven't done a good job of convincing me that you should be believed over someone who literally pays their bills through the dispensation of their subject matter expertise on this type of material. Because of the fantastic community, it's obvious that HN is a great place to teach and to learn. Knowing which to do, and when isn't always so obvious. Most of us have made that mistake in the time. Consider whether or not you may be making it now, or figure out how to better support your claims so as to teach more effectively, but cat-pawing at each other throughout the entire thread isn't doing anyone any favors.
- clubm8 10y agoSo a journalist should use a dumbphone, where every text and call is transmitted in the clear, and the contents of the address book is stored unencrypted, rather than buy an iPhone and leave it at home when attending sensitive meetings?
- nickpsecurity 10y agoThe policy of most domestic TLA's is to watch for encrypted calls. Those targeting journalists will likely have the journalist's main number in their system. Disposable, dumb phones on both sides are safer. Although the NSA can detect that, I havent heard that many others do or easily. Typical advice applies, too. Keep batteries out. Drive away from normal location to somewhere with plenty of people in cell radius but off camera. Batteries in, make call. Prearranged times or periods.
- Canada 10y agoWho could possibly do their job like that?
- nickpsecurity 10y agoLots of executives and lay people that value privacy. I've met many. In this scenario, the journalist really just needs to be able to receive the call. The need for the OPSEC is mostly on the person leaking stories. They can do less if they don't mind consequences, though.
- jhlgkhkhil 10y agoThe difference is that the dumb phone can be thrown away and replaced - not many people can afford to use iphones as burners..
- chimeracoder 10y agoIf your threat model includes an adversarial nation-state that is known to engage in passive mass surveillance, using burner phones while transmitting all communication unencrypted is a terrible idea.
- zabuni 10y ago1) Apple has shown substantial backbone in fighting against the US government when pressed to exploit a phone. 2) The other choice is a device made by a Chinese or Korean company with a semi-open operating system made by a US company. 3) Either device will have a totally closed baseband chip. 4) Deploying and maintaining secure Linux environment on a Laptop is a full time job that requires expertise journalists don't have. 5) Open versus closed source is a red herring. Everyone is using pre-compiled binaries.
- alasdair_ 10y ago>2) The other choice is a device made by a Chinese or Korean company with a semi-open operating system made by a US company. All iPhones are made in China by a Chinese company.
- zer0tonin 10y agoThey are made by Foxconn, which is a Taiwanese company.
- na85 10y agoDoes that make it meaningfully better?
- md_ 10y agoWhat are the options for someone who wants a fully trusted supply chain? Is there a modern smartphone made with provably secure hardware (and which I can verify is actually running that hardware and not some behave-alike SOC)? From my somewhat-naive perspective, it seems like the alternative is an Android phone made in China by a Chinese company, which seems not obviously superior.
- schoen 10y ago> 5) Open versus closed source is a red herring. Everyone is using pre-compiled binaries. With a very salutary trend toward reproducible builds, which will help prove a connection between the source and binaries. (Though it's taking years to get there.)
- kevinmchugh 10y agoGiven that Apple spent a lot of money last year resisting USG efforts to decrypt their smartphones, it would seem they're an especially trustworthy steward.
- boomboomsubban 10y agoExcept the part where they immediately agreed to help the US Government, only to find that incompetence had made the problem much harder than it should have been. They then resisted having to do a large amount of unpaid labor to continue to help. Plus, a PRISM member.
- boomboomsubban 10y agoAs people seem to think I am wrong, here's a source http://www.latimes.com/business/la-fi-tn-apple-fbi-call-20160219-story.html http://www.latimes.com/business/la-fi-tn-apple-fbi-call-2016...
- willstrafach 10y ago> a PRISM member To avoid confusion for any readers, you should clarify what this means: Apple has an automated process for serving data in response to any approved FISA court orders from the FBI.
- snowwrestler 10y agoIt's not even clear that PRISM implies an automated process. It appears to just be the NSA's internal name for the process of using the FBI to request stored data from service providers. And to make this clear: U.S. companies must comply with valid court orders. Being a "PRISM member" is not optional.
- pjc50 10y agoThe FBI / iPhone controversy shows that US government access to those devices is clearly limited to certain agencies. This is increasingly important as it's now really obvious that the different agencies have different politics and may end up investigating each other to see who's been compromised to the Russians. (also, you have to pick something: telling a journalist not to use a phone is a total non-starter)
- solotronics 10y agoI wonder if the FBI/iPhone event was a psychological operation to make everyone think the Fed couldn't get into an iPhone.
- kswahl1 10y agoIf I were to bet, it was the other way around. They said they got into it when they actually couldn't.
- alasdair_ 10y agoUnlikely. First, we know what they paid for the hack, and secondly, the iphone involved was an old model without a secure enclave - multiple researchers suggested different attacks.
- pvg 10y agoAt the end of the day, the FBI has to win cases in court. What are they going to do with this elaborately orchestrated secret? "Your honour, everyone thought we could not extract evidence from an iPhone but... Psych! We totally can!"
- nickpsecurity 10y agoWhat you described is Standard Operating Procedure for FBI, DEA, and intelligence services if the method is too good to give up. What they do in those situations is try to come up with alternative methods tgat can justify how they obtained the information. That process is called parallel construction. FBI and local departments have even been intentionally losing cases to avoid light being shed on some of their tools, esp stingrays. Not saying it's happening here. Just reminding you they do this.
- tptacek 10y agoThere are clueful people who disagree about Android vs. iOS for security (they're a minority, to be sure). But at this point: people who express shock, surprise, or outrage that security people are recommending iOS are demonstrating cluelessness. The clueful people who argue in favor of Android start not by saying "you can't trust anything that isn't open source" (that would be especially silly if you're arguing for Google's Android phones, which are the only trustworthy phones), but by acknowledging the consensus that iOS is more secure and then challenging it. On this thread alone, you've: * Suggested that reverse engineering is a kind of arms race between the NSA and the "good guys", which it is not. * Suggested that Tor is inextricable from Tor Browser. * Complained about the suggestion that you might learn how reverse engineering works, because you're just a software developer. I'm sorry, but comments the one upthread I'm replying to are indistinguishable from trolling to me. I know that's a bit of an aggro thing to say. But: do you honestly believe that the people who write advice like Matt Green in the story we're commenting on, or in the brief we're commenting on here, don't understand what open source is?
- jhlgkhkhil 10y agoPlease keep the personal attacks away from this forum. There is no place for them here. EDIT > "I'm sorry, but comments the one upthread I'm replying to are indistinguishable from trolling to me. I know that's a bit of an aggro thing to say." If that not a personal attack I don't know what it is. Oh and would you have time to address any of my questions? (In terms other than ios vs. android?)
- jhlgkhkhil 10y agoWow just wow.
- bsder 10y ago> Why would someone who's threat model includes the US government possibly want to trust a totally closed OS made by a US company?? Do you still not see the US government as a threat to journalists? If not how do you justify this position? Let's be honest, if your adversary is the US government, I suspect that there is no electronic equipment you can use. Most journalists, however, are more in fear of their lives or communications when outside the US. For that, an iPhone is provably a much better choice.
- jacquesm 10y ago> Most journalists, however, are more in fear of their lives or communications when outside the US. I've upvoted you because of the first sentence but the second one leaves me a bit puzzled. There are plenty of places where the threat level against journalists is equivalent to the US and quite a few where it is actually less. In fact, the current 'head-of-state' of the United States is on the record for saying the press is the enemy of his administration.
- bsder 10y ago> There are plenty of places where the threat level against journalists is equivalent to the US and quite a few where it is actually less. While your point is well taken, I haven't seen any US administration execute a journalist for quite a while. Russia and China don't have quite so much restraint. And most of the petty dictatorships and theocracies make Russia and China look perfectly reasonable. The fact that the US is not a bastion of moral rectitude does not automatically grant moral equivalence to bad or worse actors. I am perfectly capable of condemning the actions of the US government and working to make it better even while acknowledging that it is better than most and worse than some. "But he does it, too!" is not a valid argument for justification. But neither is it a valid reason to refrain from reasoned comparison.
- JupiterMoon 10y ago> For that, an iPhone is provably a much better choice. Where can I get some citations for this?