4 ms·
Also, how can you claim to have a secure app when it runs on a closed-source operating system? (Even more, we know about Microsoft handing over security holes t
by nexttimer 13y ago
Also, how can you claim to have a secure app when it runs on a closed-source operating system? (Even more, we know about Microsoft handing over security holes to the NSA - why would Apple or Google not do the same?).
It's like saying "this heat is really cold". In other words: a contradiction in itself.
Only open-source apps on open-source operating systems can start making claims about security and trustworthiness.
- ge0rg 13y agoOnly open-source apps on open-source operating systems [..] ...running on Open Source hardware. Many modern smartphones employ a baseband processor and an application processor with shared memory. While the app processor might be running an open-source compiled Android, the baseband processor is usually on a closed, not externally verified (and very buggy) RTOS provided by the manufacturer (Qualcomm, MediaTek, TI, ...)[0]. Owning the baseband is sufficient to gain access to the raw RAM of the application processor, to read any IM messages and keys, to manipulate data, code and whatever else you like. And all this is completely undetectable by any "antivirus" software running on the app processor. [0] http://www.youtube.com/watch?v=fQqv0v14KKY http://www.youtube.com/watch?v=fQqv0v14KKY
- hrjet 13y ago> running on self-manufactured hardware FTFY. Open sourced hardware by itself is of no practical use because the guy who manufactured it for you might have altered it in production.
- polarix 13y agoAnd let's not forget to consider a "trusting trust" attack on the hardware you use to manufacture the processor.