5 ms·
If you can install stuff on the device, how could you protect against it?
by RandomLensman 1y ago
If you can install stuff on the device, how could you protect against it?
- JoshTriplett 1y agoDepending on the level of security you need, there are any number of steps people could take or the industry as a whole could take: - Don't allow remotely installing things on a device, only doing so with physical presence on the device. - Have "binary transparency" mechanisms to make sure that you're seeing the same binary everyone else is, and you're not getting served a special backdoored version nobody else sees. (This doesn't prevent global backdoors, of course, but those are more likely to get caught.) - Relatedly, have multiple independent app stores in different jurisdictions, and make sure they are serving identical binaries. That ensures no one jurisdiction can surreptitiously demand and enforce a backdoor. - Have signatures from the original app author that can be verified, and ensure that intermediaries (e.g. "app stores") can add signatures but can't add anything to the package that's not covered by the original signature. That reduces the number of parties you have to trust. - In an ideal world, only install Open Source software that's reviewed and subject to multiple independent reproducible builds.
- RandomLensman 1y agoIn high security settings, just don't allow devices in. Also, democratically authorized state actors have a valid role to play in liberal democracies.
- JoshTriplett 1y ago> In high security settings, just don't allow devices in. That's appropriate for a SCIF, not for someone's day-to-day life. > Also, democratically authorized state actors have a valid role to play in liberal democracies. They still don't get to have backdoors into everyone's device. Also, many many events throughout history should demonstrate that "democratically authorized" is in fact laughably bad at curtailing abuses of power, and not a substitute for a sacrosanct right to privacy that's systematically enforced through both legal and technical means. Make devices secure. When people tell you to make them insecure, refuse.
- RandomLensman 1y agoNot sure why why we are talking about everyone's device now or even a backdoor as such if it might even need access to the device to interfere with it? (My initial post wasn't about mass surveillance.) If you look at history, not sure why technical measures would offer much protection against violence based approaches against privacy, though.
- JoshTriplett 1y ago> My initial post wasn't about mass surveillance. When you said "If you can install stuff on the device, how could you protect against it?", that sounded like it was talking about how a device that can have new software installed onto it can have a backdoor for later use installed onto it, and that led into a discussion about how to protect against that. Were you instead saying "on a device you have control over, how can you protect yourself against that?". Or something else? > If you look at history, not sure why technical measures would offer much protection against violence based approaches against privacy, though. They can at a minimal level (e.g. steganography, duress passwords), but yes, ultimately there is little you can do against someone threatening you personally with harm.
- RandomLensman 1y agoSorry, I meant it as in someone else installing surveillance on a device/bugging it, not as in installing something with a backdoor for some possible later use, i.e., targeted surveillance of a specific device under a warrant etc. So something which can have a lot more effort per device involved, potentially access to it, and not some broad-based thing. And, yes, there can be a debate if such warrants are desirable etc., but I think it's quite different from broad-based backdoors for potential mass surveillance etc. and liberal democracies can decide to have such tools available.
- JoshTriplett 1y agoAh, got it! Sorry for us talking past each other there, then. I think part of what I was suggesting still applies there: if you can't install things remotely, and you have oversight to ensure that any backdoor applied to you has to have been sent to everyone (which provides a measure of security), then what's left is physical control of the device. For instance, keeping the device in your possession, locking it down against peripherals... That can't prevent you from being physically coerced, but it provides a lot of security in every other case. And if things have devolved to the point of you being physically coerced then you have much worse problems.