13 ms·
Our Cellphones Aren't Safe
- colordrops 8y agoPrivacy and hacking, but also mental and social health, road safety, and potentially radiation danger. Mobile devices are sort of a Faustian bargain.
- malcolmgreaves 8y agoCell phones release non-ionizing radiation. (1) Your internal risk model should put this at the same level as being outside in the sun. (1) https://www.cancer.gov/about-cancer/causes-prevention/risk/radiation/cell-phones-fact-sheet https://www.cancer.gov/about-cancer/causes-prevention/risk/r...
- KMag 8y agoIf you're walking down the street talking on a cell phone on a Summer day without sun protection, there's no debate as to the relative danger of the UV and radio waves you're absorbing. The UV is vastly more dangerous.
- ams6110 8y agoYou need some amount of sunlight to help your body make vitamin D.
- colordrops 8y ago> non-ionizing radiation This is a tired response that everyone memorizes but fails to back with facts. 1. There are studies showing some effects besides DNA mutation, such as heating, due to non-ionizing radiation, which could cause a number of health effects. 2. The World Health Organization classified cell phone radiation as a potential carcinogen. The CDC has stated that there is no conclusive evidence one way or the other on whether cell phones cause cancer. 3. I said "potentially" above.
- gizmo686 8y agoThe sun is a known carcinogen. The fact that we do not have evidence that cellphones are a carcinogen is evidence that the effect size would be small if it exists.
- yongjik 8y agoAh yes, the good old "Group 2B carcinogens" that are "possibly carcinogenic to humans". It includes lead, DDT, dry cleaning (as a job), firefighting (as a job), aloe vera extract, ginkgo extract, and pickled vegetables. A more dangerous Group 2A includes red meat, "Shift work that involves circadian disruption", and "Very hot beverages (more than 65°C)", according to Wikipedia. Group 1 contains UV light. So, walking outside in a sunny day sipping coffee after eating BBQ with kimchi is probably more dangerous than cell phones. Doubly so if you're a firefighter.
- judge2020 8y agoI think the point is that you likely won't do all of those things all day every day; rarely do you spend all day and night in the sun, drinking coffee every hour, and eating red meat 3 times a day. Your phone is with you at all times of the day, always within 5 feet of your person, which means that if it leads to cancer (which we will likely find out within the next 30 years since American children are now surrounded by phones and tablets from age 5) then it's much more likely that you end up with cancer because of your phone rather than the fact that you were out in the sun for an hour every day.
- yongjik 8y agoThe first iPhone was released in 2007. Radars have been used since WW2. Of course it's theoretically possible that cell phone radiation causes cancer to everyone but only after being largely ineffectual for 12 years of continuous use, but that's somewhat reaching, IMHO.
- marcosdumay 8y agoI really don't get how the WHO gets to keep those lists without a severe backslash to their image. Since positive proof that something does not cause cancer is nearly impossible, both state basically that "a lot of people think those could cause cancer, none got to see any, be wary". But walking outside in a sunny day is in a completely different category. Your comparison at the end is severely unbalanced, the Sun alone overwhelms everything else on both sides by a huge margin.
- icelancer 8y agoYou are being extremely charitable with the comparison to the sun. It's probably what, at least 4 orders of magnitude more dangerous to be exposed to the sun than to use a cell phone?
- iscrewyou 8y agoThis is tangential. Faustian Bargain. I just went through the Baader-Meinhof Phenomenon with that phrase. I saw this thread. Read your comment and just went on about my time. Went to Reddit and started reading some comments there. Saw the same phrase just 2 minutes later! Weird stuf.
- newman8r 8y agoI recently launched https://www.tamarin.us https://www.tamarin.us (fake websites + canary credentials) hoping I could capitalize on some of this - but IMO it's a hard sell (and a lot of the salespeople I spoke with kept confirming how hard enterprise security sales are). It will probably be a while before I try to work on another privacy-related product. Fortunately I'm having a little bit more luck on my current project in the health space.
- throwawaylalala 8y agoI like this idea, but I think there are probably two things that are an issue with this: 1 - You remove control of the company from being able to plausibly deny that something happened; you become a second subpeonable party that would disclose something if forced to. 2 - You're not pricing it high enough for a big reseller (like CDW, etc) to want to try to sell it. Not sure how to fix #1 besides selling/licensing the tech (if the patent issues) to a larger company that can roll this into a larger offering (and out to their exiting customers). Background; I've worked in Enterprise Software Sales and as part of a SaaS Operations Team.
- newman8r 8y agoI think you're exactly right on both points, and licensing is probably the best bet. The value prop I tried to push for MSP resellers was that it would result in more incident response work for them. Basically offering to white-label the thing.
- Spooky23 8y agoYou should sell it to consultants. The problem with honeypots in enterprise is that the enterprise leadership wants to avoid knowing things.
- newman8r 8y agoYeah that's one of the interesting aspects of intrusion detection. Intrusion prevention is probably an easier sell.
- 8y ago
- lwansbrough 8y agoImagine a service where you type in a phone number, and it used the GPS location data sold by cellular providers to obtain the physical location of the phone number. It would then autonomously fly a drone near the GPS location of that device and use an onboard cell-site spoofer to intercept data from that device. That’s all possible today.
- koala_man 8y agoAnd also easily defeated with commonly available end to end encrypted messaging
- ehnto 8y agoRecent Australian laws make it possible to force Australian companies and individuals to compromise software to defeat encryption. Which could be as simple as getting a boutique update delivered to a device that includes a screen recorder or keylogger, and it doesn't necessarily have to be the messaging app that gets compromised. That isn't really a problem unique to Australia or state level actors. I think apple and Android have some protections against screen recording.
- saagarjha 8y agoAny “boutique update” you’re talking about would require compromising the OS development process, which means that any protections against scene recording would be easy to remove or work around.
- ehnto 8y agoThat is the hope. But who to trust? Not to mention, some apps already have the permissions for their legitimate use cases, so why not just pick one of those? It may not even require a client update, just requisition of the data from the company. The underlying idea is that smartphones are safer, but they are still software, and your trust points are spread very thin over literally hundreds of people and companies. All of this, blasting across the internet and into dozens of other peoples servers daily. It's hard to consider it secure.
- tptacek 8y agoCounterpoint: In the history of the industry no mass-market computing platform has been safer than the flagship hardware/software platforms from Apple and Google --- on no platform does an exploitable vulnerability cost more to obtain, and no platforms have ever been more capable of establishing secure channels between themselves. SS7 is insecure. But operational practices at both the carriers and inside governments rely on those insecurities to get jobs done, and some of those jobs are important and enjoy wide support. Anything we do to shore up the security of SS7 will, almost necessarily, include compromises most of us here will find hateful, and we'll be stuck with those compromises for another generation. Rather than "fixing the potholes" in GSM and SS7, we could instead accept that the cell signaling layer is insecure, and route around those weaknesses with application code that can establish end-to-end secure channels accountable only to their users. That's pretty close to what Apple has already done with SMS text messaging, which opportunistically upgrades to Apple's secure iMessage protocol. We can do even better than that! That's what we've done with the Internet, where this approach is called "the end to end argument in system design". It worked there and will work just as well for telephony.
- stefan_ 8y agoWho needs to break crypto when you have a baseband processor relay back location, audio and video? The problem with the potholes such as silent SMS are not that they exist, it's that baseband manufacturers have demonstrated unwillingness to address them. Alongside other readily addressable things such as IMSI catchers. It's cool we made the application processor secure, but it's pretty pointless when the 5G chip is in fact a hostile implant.
- bvinc 8y agoI've always wondered this. When encryption algorithms are broken, we phase them out for new ones. When cell tower protocols have weak encryption we don't seem to do anything about it. I hear that edge and 2g protocols are completely unsafe but there's not even an option in my phone to disable them. What gives?
- JumpCrisscross 8y ago> When cell tower protocols have weak encryption we don't seem to do anything about it Consumers are more likely to switch because of coverage than security.
- inetknght 8y ago> Consumers are more likely to switch because of coverage than security. This is, perhaps, because they aren't informed that their communications aren't secure and that coverage is extended despite being insecure.
- bogomipz 8y ago>"When cell tower protocols have weak encryption we don't seem to do anything about it." SS7 is not a "cell tower protocol", its an entire protocol stack that allows a Telco central office switch to talk to any other central office switch on any other Telco anywhere in the world, for both copper and cellular subscribers. It run's the entirety of global phone. Class 5 Telco switches are often old Many of these switches have been in service since mid 1970s. Do an image search for "Nortel DMS 500" and you will get an idea of how old and stodgy a lot of this gear is. And it all needs to interoperate seamlessly as governments, emergency services etc all rely on it. In fact with they add IP capability to SS7 - SIGTRAN, they basically forklifted it as is, warts and all. Presumably to err on the side of caution. A handset only implements a small subset of the SS7 protocol stack the Mobile Application Part(MAP.)
- gnopgnip 8y agoYou can disable edge and 2g on most modern phones.
- interfixus 8y ago> Nobody could have envisioned how deeply ingrained cellular technology would become in our society Am I the only one often peeved by this kind of slop in thought and expression? Of course somebody could. Some visionaries even did, and not than just Arthur C. Clarke. So rightly: 'Few envisioned how deeply ...'
- bitxbitxbitcoin 8y agoI guess this is supposed to be the part where the masses decide whether the added safety is worth the inconvenience of not having cellphones? Or have we already.
- userbinator 8y agoI am relieved to see that this is not another article about EM radiation from mobile phones. However, the title is a bit clickbaity in that manner.
- chakalakasp 8y agoDon’t make phone calls on the teleco layer. Make them on the application later, such as FaceTime voice or Signal. If phone companies won’t secure their networks, lay a secure layer on top of the phone company network.
- matt-attack 8y agoThat’s all fine except SMS is the defacto method that most use for password resets, dual-factor, etc. This was mentioned in TFA. What does one do about that? I think it would be amazing if banks and financial institutions used iMessage but I can’t see it happen.
- hackerman12345 8y agoIME most SMS verification is bundled with some additional information submitted by the user (e.g. secret information, ID information).
- SahAssar 8y agoAll of which is pretty easily phished.
- CorvusCrypto 8y agoHmm interesting read. In Sweden there is a thing called BankID and basically you can use your mobile device as a universal authenticator. Of course, you need to have the device and enter a 6-digit pin, but I often wondered how dangerous it was to use this so much. And on top of that I know people that used it in local cafes on public WiFi. I would love to do an examination of communication via BankIDs app to the internet to see what kind of security exists to protect the user. If you can get the person's social number (personnummer) and their 6-digit code, then spoof their device (probably the easier part) you can basically take over their life in Sweden.
- vlovich123 8y agoU2F & authenticator apps are way better than cellular. Cellular provider companies suck at infosec in massive ways.
- CorvusCrypto 8y agoPretty much my hope. If it's so easy to snoop on cell traffic my hope then is that the app communication is encrypted using modern standards and airtight. Though I'm sure you're right since these apps are more under the microscope. It's probably fine.
- vlovich123 8y agoI had my Uber account hacked even though it had SMS 2FA enabled (from Russia as best I could tell). Now maybe there was some flaw in Uber's implementation but I don't trust SMS 2FA. Talk to any competent security researcher - SMS 2FA is only mildly better than no 2FA. The fact that cellular traffic to this day isn't encrypted properly[1] even though LTE was supposed to should indicate just how horrible cellular providers are at infosec & what happens when they drive security requirements. [1] https://arstechnica.com/information-technology/2018/06/lte-wireless-connections-used-by-billions-arent-as-secure-as-we-thought/ https://arstechnica.com/information-technology/2018/06/lte-w...
- ahje 8y ago
- aplummer 8y ago> Large companies such as AT&T, Verizon, Google and Apple have not been public about their efforts, if any exist. Isn’t this one of the major selling points of iMessage etc?
- deytempo 8y agoNew York Times is broken for IOS mobile
- hardwaresofton 8y agoThe first fully open source phone (RISC-V?[0]) that ditches the 3G chip and goes wifi only using either software defined radio or open source wifi chipset (RISCV again?[1]) will be the only thing to fix this IMO. We have the means to have secure communication over insecure channels with asymmetric crypto signing+encryption (which doesn't seem broken at least for now), the problem is semi-solved at the software layer -- we now need to solve the privacy/security issue at the layers below software. [0]: https://riscv.org/ https://riscv.org/ [1]: https://riscv.org/2018/10/hackaday-article-new-part-day-the-risc-v-chip-with-built-in-neural-networks/ https://riscv.org/2018/10/hackaday-article-new-part-day-the-...
- rapsey 8y agoWifis are often absolutely terrible for low latency applications such as voip (buffer bloat). Also that means your phone only works at home and in the office
- acct1771 8y agoAs discussed elsewhere: https://www.gl-inet.com/products/gl-mifi/ https://www.gl-inet.com/products/gl-mifi/
- hardwaresofton 8y agoYes, but this is only if you subscribe to wifi as it exists today, or near you. It's becoming increasingly common to rent portable wifi devices from 3G carriers, and if long distance wifi mesh networks ever take off things will be even better. The idea is to not have your primary mobile computing platform be compromised, if you can prevent it. Also, see the sibling post to this -- https://www.gl-inet.com/products/gl-mifi/ https://www.gl-inet.com/products/gl-mifi/
- jsjsoaofnfn 8y agoActually 5G provides this overhaul, more than it provides speed benefits for customers. The 4G backend still has a web of trust between operators and their e.g. IP exchange providers. As far as I know, this will change with 5G. Roaming data confidentiality can then be routed and encrypted until the home operator network, while the associated metadata is accessible for the IP X to provide their services. The home operator can verify the smartphone is actually in the visited network. These are all bits and pieces that break up the operator's web of trust.
- hsivonen 8y agoNo mention of why GSM 2G was made less secure than it could be and what current policy makers could learn from that. https://www.aftenposten.no/verden/i/Olkl/Sources-We-were-pressured-to-weaken-the-mobile-security-in-the-80s https://www.aftenposten.no/verden/i/Olkl/Sources-We-were-pre...
- xte 8y agoNo one want safe widespread solutions: we want to being able to spy both for bad and good reasons. The good part is simply justice: telecommunications are vital to anyone, criminals included, to a point that we do not want to limit them. But to catch criminals we still need a bit of surveillance power. Unfortunately the very same power is interest for criminal itself to spy on their targets, any kind of criminal from the home thief that may like follow you to know when you go on holidays, what kind of safety you have at home (because yes, you post new shiny photos of your new home surveillance system, together with it's plan, photos of you and few technicians during the mounting phase etc), what you have in your house (because you post tons of photos/selfie with relevant "background") to your insurance company that buy with discretion your data from Amazon/Google/Microsoft/Apple, data recorded by voice assistant, smart devices with cameras everywhere, speaker mic of your phone etc (curiously in the past such kind of spying devices were buy, and they are very expensive, by people who want to spy on you. Today you buy them from the people willing to spying on you and also you pay connectivity and electricity form them) to your government that likes to know your political opinion and influence network like ancient est-German STASI or modern NSA/FBI/CIA/* do. The real "safety" point is not safety itself but balance of power. A knife good to cut a succulent steak is also good to kill someone and perhaps to open a package. A car the same. A phone the same. etc. They are instruments with more or less effectiveness, comfort and power. If they are balanced so anyone have more or less the same power we have no real safety problem. If too few have too much power we have a problem, bigger as fewer and powerful counterparts are. Unfortunately to proper balance power as a society we need also a certain level of awareness and civic sense distributed among us, because yes knowledge is power. At any level. Today's and not from today's we evolve in a more and more ignorant society with a more and more reduced élite that rules against tons of sheep.
- xwat 8y agoThere are no secure smartphones (2016) https://news.ycombinator.com/item?id=10905643 https://news.ycombinator.com/item?id=10905643
- libdjml 8y agoThe twice-linked brief article states that basebands have full OS memory access, which is not true in 2018. And the article is completely uncited.
- charliebrownau 8y agoAnyone managed to find an Open Source Phone similar to the PI Phone , but with 4G that is Open source and DIY and the parts are sold GLOBALLY, not just EU/CA/UK or USA only.