8 ms·
If the underlying hardware is compromised(it is) then it doesn't matter what the os does.\ EDIT: If you are downvoting me - state why.
by wpdev_63 8y ago
If the underlying hardware is compromised(it is) then it doesn't matter what the os does.\
EDIT: If you are downvoting me - state why.
- craftyguy 8y agoDepends on your threat model. Sure, it's impossible to keep out certain nation states, but a number of OS changes can keep malicious applications developed by less-skilled nation states or highly skilled individuals under control. It's not perfect, but it's better than nothing. Unless you are suggesting that we should just give up on security entirely because it's impossible to have a system that is 100% secure?
- wpdev_63 8y agoDo people really need to worry about other than national states with android and ios? Exploits/Viruses in these OSes are extremely rare in comparison to the desktop OSes and they're just getting harder to exploit. It's gettting to the point where you need the resources of one of the cyber superpowers to exploit these OSes. Their permissions based security model is great and hopefully will make their way to desktop. My theory is that there is a backdoor into these OSes. It's the path of least resistance and there's precedence of this. Obviously Apple/Google are going to vehemently deny this as this and these backdoors would be able to provide the most precise form of surveillance ever created.
- busterarm 8y agoThere are relatively easy tutorials out there, some on freaking YouTube ffs, about how to connect to the JTAG pins on most Android phones and pull data right out of memory. These are barely above trivial attacks that don't require a nation state to pull off, just a talented engineer.
- wpdev_63 8y agoI don't think most people care about physical access exploits. If you did you would have some specialized software which would remotely wipe it upon being tampering with. Common sense. What really matters security wise is who is this security for? If it's for state actors(vault7) then it's useless. It's known that copperheados doesn't do much to defend against them as the phones are exploited on a hardware level. All this extra security is pointless as the people you are most worried about, has access.
- busterarm 8y ago> If you did you would have some specialized software which would remotely wipe it upon being tampering with. Common sense. If somebody physically attaching to your device isn't doing so in an environment that doesn't also block radio signals, they've already failed... and you can't be wiping your phone every time it loses signal. The threat model of a personal computer and the threat model of something that literally follows you everywhere and knows everything you do are very different. Physical access is much easier to obtain exposes you to way, way more. Getting a divorce? Your phone is probably something you want to guard extremely closely. You can get someone to pin your android phone for low-double digit thousands of dollars -- or even free if it's the right kind of person with the wrong kind of morals. IMO, if you have any meaningful assets to protect, whether they're yours or your company's, buying an Android phone with JTAG pins is _insane_ (or simply poor risk analysis). But what do I know? I've only JTAG'd a phone before, scraped the RAM, obtained the unlock code and all of the user data. Random thought: how many people do you know whose phone unlock code is also their ATM pin number?
- pvg 8y agoThe first rule of vote club is you do not talk about vote club. Also, people who vote on your comments either up or down don't owe you explanations. Both of these are standard HN practice.
- craftyguy 8y agoNot GP, but I don't consider it harmful or whatever to ask why folks disagree with you if you don't understand why folks would disagree with you. Sure, none of us owe them an explanation for voting a certain way, but maybe someone will come along and explain it, and they'll learn something new. I don't think the system is strictly "you're right" or "your're wrong" and providing any supporting explanation is discouraged.
- pvg 8y agoI don't consider it harmful It pretty much always devolves into pointless meta. If someone wanted to tell you how right or wrong you are, they'd reply to your comment. Sometimes, perfectly reasonable comments get downvoted. Sometimes, truly awful comments get upvoted. Sometimes people fatfinger the wrong button on their phones. Every poster and every thread is better off just living with it, not worrying about it too much and sticking to the quality of the conversation itself.
- staticautomatic 8y agoWe are the quality of the conversation itself.
- deleted 8y ago[deleted]