3 ms·
Been watching CopperheadOS for a while, the best option as far as I know. I will be getting my next phone directly from them to support development. https://co
by Datenstrom 10y ago
Been watching CopperheadOS for a while, the best option as far as I know. I will be getting my next phone directly from them to support development.
https://copperhead.co/android/ https://copperhead.co/android/
- pgrote 10y agoI am ignorant of how this connects to a carrier. Will it work on Verizon's network? Can Verizon install something once it is connected?
- Datenstrom 10y agoIt will work, right now it only supports a few phones (Nexus 9 WiFi, Nexus 5X, Nexus 6P) with the Pixel and Pixel XL on the way. I don't have a supported phone currently so I haven't been able to test it out but any phone that is capable of connecting to Verizon's network hardware wise should be able to connect using any OS that implements the necessary protocols. The Pixel and Pixel XL use nano SIM cards to connect to a carrier. If CopperheadOS is installed the only attack vector Verizon could use is the SIM Card, but CopperheadOS implements a lot of security features that could help mitigate the risk: * Full verified boot, covering all firmware and OS partitions. * Baseline app isolation via unique uid/gid pairs for each app. * App permission model including the ability to revoke permissions and supply fake data. Carriers can not install software on phones connected to the network. Assuming they installed a Carrier configuration application or anything else using the SIM Card you could revoke its permissions or supply fake data, or even create firewall rules to disallow the traffic manually. More security features: https://copperhead.co/android/docs/technical_overview https://copperhead.co/android/docs/technical_overview
- mahyarm 10y agoThat document doesnt have the word baseband on it. I'm guessing they dont do anything about it?
- Datenstrom 10y agoI am not sure but I don't think so, I am sure they would be bragging about it if they did. There may be some attempt to lessen the risks but I haven't taken a deep look into what they have done in hardening the OS. I don't think we will ever solve that problem without more support for projects like CopperheadOS and ReplicantOS. They are struggling to even maintain and improve just a couple devices.