5 ms·
Can you describe a system that is effective when your phone has malware? I have a little experience with this, designing systems that use TPMs and remote attes
by brians 5y ago
Can you describe a system that is effective when your phone has malware?
I have a little experience with this, designing systems that use TPMs and remote attestation to shut down communication rather than allow forgery or leaks. It’s very delicate to begin with, even if one entity owns all the devices, and unsolved for the general case.
But iOS and ChromeOS seem pretty good.
- ______- 5y ago> Can you describe a system that is effective when your phone has malware? I'm referring to people casually saying: `Download Signal and you'll be fine` and not pointing out other OPSEC practices we all need to follow, regardless of threat model. (Not clicking on malicious links sent via SMS etc).
- pvg 5y agoother OPSEC practices we all need to follow, regardless of threat model. That doesn't really add up - a goals of things like more secure phones and secure general purpose messengers is explicitly to provide a high level of security without following a bunch of OPSEC practices. You aren't going to get mass adoption of more secure systems by insisting everyone take up OPSEC practices 'regardless of threat model'. The aim is to reach that adoption through systems that offer a lot of security without a lot of security-related ceremony. It's sort of inherent in the notion of mass adoption.
- fsflover 5y ago> Can you describe a system that is effective when your phone has malware? There is no such system. However, there are phones based on FLOSS, which you can trust and verify: GNU/Linux phones.
- ysnp 5y agoDo you know of some interesting research in this area besides maqp's https://github.com/maqp/tfc https://github.com/maqp/tfc?