4 ms·
Similar sentiments, I'm already seeing this with Android and custom roms. Right now you get away with spoofing basic integrity checks, but custom roms cannot p
by DistractionRect 3y ago
Similar sentiments, I'm already seeing this with Android and custom roms.
Right now you get away with spoofing basic integrity checks, but custom roms cannot pass hardware attestation. It's not a hard requirement right now in order to maintain backwards compatibility required to target 90%+ of android devices, but give it a few generations and it will be. At that piont I expect a majority of apps will simply be unusable on custom roms, and we'll have no choice but to embrace planned obsolescence.
- JohnFen 3y agoThat issue with Android is what made me decide to give up smartphones. I cannot adequately secure a phone without installing a custom ROM (and even then, it's iffier than ever), and the integrity/attestation checks make custom ROMs very problematic. So, once my smartphone dies, I'll be switching to a dumbphone.
- mrd3v0 3y agoYou should take a look at GNU/Linux mobile operating systems every once in a while. They're making great strides and both popular GUIs KDE and GNOME have been working on making mobile a target in their ecosystems. Fairphone comes with a five-year guarantee for repairs and parts, so none of that early planned obsolescence, and it works with all the Linux mobile distributions I have had my eyes on.
- toastal 3y agoNo planned obsolescence but they removed the headphone jack & started selling the earbuds which are one of the kings of e-waste compared to getting a nice pair of headphones or IEMs that will last a decade or more.
- fsflover 3y agoTry GNU/Linux phones, Librem 5 or Pinephone. They're repairable, with the headphone jack and lifetime updates.
- toastal 3y agoSorry boo, but the telephony is generally pretty garbage on all the Linux options & a phone still needs to be a phone. A lot of those important apps won’t be supported as well as they only cater to the Android/iOS duopoly.
- fsflover 3y agoCalls work fine for me on Librem 5. There are many posts on their forum with similar experiences, e.g., https://forums.puri.sm/t/librem-5-phone-review/21085 https://forums.puri.sm/t/librem-5-phone-review/21085
- toastal 3y agoThat’s one phone with overpriced features unfortunately. I understand you’re paying for a small batch, niche device (that some users have had a lot of issues getting the thing shipped) to get a slow CPU, measly RAM/storage, meh camera, & an IPS panel. I’d rather go the route of postmarketOS with BYOD that with better specs (even a 4–5 year old phone can easily outcompete) & an OLED panel, but much of the effort is not in telephony (I understand it’s all volunteer hackers, but it’s an unfortunate effect). The PinePhones have the same spec issues even with a better sticker price. It’s just too hard to justify. I flashed postmarketOS & Ubuntu Touch on an old OnePlus 1 which has similar specs & it’s gruelingly slow. Phones in the last 3 years are now all ‘good enough’ (hence sales across the board plummeting as upgrades have meant a lot less finally), so until the specs can get there, it’s gonna be a pass.
- euniceee3 3y agoEven then you are yellow booting and that is another security issue. What dumbphones you looking at? Everything retail I am seeing is a stripped down version of Android.
- lll-o-lll 3y agohttps://skysedge.com/unsmartphones/RUSP/ https://skysedge.com/unsmartphones/RUSP/ Some assembly required.
- qingcharles 3y agoI don't know of any dumbphones on the market. I help people out who are on parole and they are not allowed to own smartphones. The best we can do is try to trick the parole agents by buying them flip phones, but even the most basic stupid flip-phones for Grandma still have Alexa built in and have some form of Internet access.
- mindslight 3y agoBut remote attestation doesn't completely prevent you from running custom ROMs. Rather the problem is if you want to use various proprietary crapps/websites that insist on performing attestation. So there doesn't seem to be a point into choosing a "dumb phone" besides as some sort of protest. Rather for each of your devices you'll choose having a libre user-representing (ie secure) OS, or a locked down web TV equivalent. I'd personally choose my pocket device to be running secure libre software, and then use any proprietary crapps on a tablet that stays at home. If remote attestation gets so bad that I can't even do things like access store apps on a libre/secure device, then I'll carry two, with the libre/secure device supplying wifi AP to the other. (this comment is most certainly not meant as any sort of defense of remote attestation)
- xg15 3y agoThe problem is, that's where the network effect bites you in the butt. With functioning remote attestation, platforms can lock down their APIs, so there often will not be a libre alternative. I.e. if your friends are on signal or whatsapp or twitter or whatever, you'll have to use a second phone to contact them, which will probably soon become your primary phone.
- mindslight 3y agoSure, if things get really bad and I couldn't convince friends to use libre-supporting services and/or texting no longer works, then I'd have to choose my main pocket device to be locked down. I'd probably still try to carry the libre device as a secondary one to have access to trustable apps while out, but I can see that being too inconvenient and giving up on it. But my point was that still doesn't indicate moving to a "dumb" phone. A dumb phone is just a locked down device with even fewer capabilities.
- jeroenhd 3y agoA device that can't watch Netflix in HD isn't "unusable". If your bank complains about custom ROMs for wireless payments, the exact same feature can work perfectly fine with your bank card (better even, in some cases). I'm quite annoyed that I can't watch HD movies on my phone but it's not as if I should toss it into the bin now.
- DistractionRect 3y agoThe issue is that it likely won't stop at Netflix and banking. McDonald's won't let you use their app with an unlocked bootloader [0]. My comment was suggesting that the majority of apps, not just banking/Netflix will likely adopt and require hardware attestation when 90%+ of Androids in use support it. Things like Uber/Lyft, Metro, food ordering, email, social media, etc are just as likely to pick it up and that's my point. No, it won't be a brick, but you'll likely lose quite a few apps. [0] https://forum.xda-developers.com/t/mcdonalds-app.4067887/ https://forum.xda-developers.com/t/mcdonalds-app.4067887/
- AnthonyMouse 3y ago> custom roms cannot pass hardware attestation. So this is going to be the interesting question, because obviously they can, they just have to extract the keys from something first. Devices are made by all kinds of vendors and it only takes one vulnerability before you have a market for keys. There are <$200 phones, those cheap phones are more likely to have a vulnerability, and when one of them gets a cracked screen the market value drops to near-zero which makes it cheap to buy one to extract the key. Which is also why remote attestation is totally worthless. An attacker can do the same thing, so relying on the attestation is completely insecure because in practice anyone with a couple bucks will be able to spoof it. But if extracting a key is mildly inconvenient or legally questionable, it will be enough to deter honest casual users but not profit-motivated attackers, and you get the worst of both worlds. So we need to do everything to make sure that doesn't happen. One way is to make extracting keys as easy as possible, of course. Another is to make sure that everybody understands the perversity of this nonsense. It's snake oil the likes of export-grade encryption or EV certificates. Anyone caught using it should be mocked mercilessly and added to a list of disfavored vendors with uninformed security staff. Anything in a position to do so should warn if anything attempts to use it, or disable it to make it more difficult for anything else to rely on its availability. Warnings should emphasize that using it is a security risk that can enable hard to detect malware and is an indication of malice or incompetence. It needs to go away.
- lostmsu 3y agoThe keys would just be revoked and the cheap phones you got the keys from would no longer pass attestation either.
- AnthonyMouse 3y agoYou don't tell them which keys you extracted. If they have to revoke every phone of that model then lots of normal users have them and vendors can't rely on people having phones that support it anymore, so good. And the attacker doesn't care if the key gets revoked after they've stolen your money.
- blibble 3y ago
- matheusmoreira 3y agoYeah. We used to have complete control over our android devices and the apps that ran on them. This hardware attestation business is gonna destroy all that. Right now I can't even launch my bank's app if I have developer mode enabled. They say it's only gonna be for the apps that "really need it" but that's just Google boiling the frog slowly. Might as well buy an iPhone if that's how it's going to be.
- toastal 3y agoThat’s a sad jump. I’d say support/embrace Linux mobile, but we know the app makers won’t support it (and shitty apps like Signal require a primary device running one of the mobile duopoly OSs) & we we know Google with its Web Integrity wants to lock down our web browsing sanctuary that runs on any platform. Yeah, we might be forced into it… or be prepared to go low-tech like going to the bank & calling. For me this will be really bad if I’m traveling abroad since the website requires 2FA & SMS is the only option which will be roaming & even the annual number swap I do when I get a new SIM requires paperwork & waiting a week for processing. But maybe owning a phone is more of a burden due to lack of device control & privacy concerns.