13 ms·
Blackphone
- n008 13y agoJust get an old Nokia feature phone
- GrinningFool 13y agohttps://www.blackphone.ch/hello-world/ https://www.blackphone.ch/hello-world/ I'm sure there's logic there - powering a very basic non-informative landing site with a WP installation that you took the time to customize, but not delete the default post and comment from... But it certainly doesn't give me warm fuzzy feelings about the people behind this.
- linux_devil 13y agoOne should be concerned about privacy and digital footprints , but more or less it depends on how many people are looking forward to adapt this concept. People still use Gmail and facebook .
- joncp 13y agoSecure? They're rewriting the baseband, then? Color me skeptical.
- TeMPOraL 13y ago+1, the phone won't really be private if they won't deploy a new baseband chip that allows for this privacy (and is open-source, so that we could check it).
- tombrossman 13y agoRelated story here http://www.osnews.com/story/27416/The_second_operating_system_hiding_in_every_mobile_phone http://www.osnews.com/story/27416/The_second_operating_syste...
- hekker 13y agoIt would be nice to order Chinese food anonymously with this phone. Looking forward to the release!
- epaga 13y agoNo mention of the thing being completely open sourced - or did I overlook something? If not, seems like something they should mention (I am assuming it IS open source?)...
- elwell 13y agoGood point.
- huhtenberg 13y agoFor a project concerned with privacy and anonymity the news subscription form is asking way too much. Also, why is domain on .ch ?
- troels 13y agoI believe the company is Swiss.
- huhtenberg 13y agoDoesn't seem to be. Domain name: blackphone.ch Holder of domain name: Geeksphone S.L. Geeksphone Rodrigo S calle Manuel Silvela 1 ES-28010 Madrid Spain It's just very curious that they feel like they need to pass for a Swiss company.
- robin_reala 13y agoIt’s not that curious: Switzerland through their history and neutrality policy have a reputation for being secure and unlikely to bow to foreign influence.
- huhtenberg 13y agoNo, I realize that. I just don't understand what they are trying to gain by using .ch domain name. That people who are interested in privacy and security wouldn't notice that they are a Spanish company and proceed to think of them of a Swiss project? Seems pointless at best and misleading at worst.
- jey 13y agoI think it's just a (clever) part of their branding; Switzerland has long had an explicit policy of neutrality. Not a super-reputable source, but succinct: http://www.wisegeek.org/why-is-switzerland-regarded-as-a-neutral-country.htm http://www.wisegeek.org/why-is-switzerland-regarded-as-a-neu... Official Swiss propaganda, but has more info: http://www.vbs.admin.ch/internet/vbs/en/home/documentation/publication.parsys.0008.downloadList.9934.DownloadFile.tmp/neuteebook.pdf http://www.vbs.admin.ch/internet/vbs/en/home/documentation/p...
- c1sc0 13y agoHow does this protect me from my carrier? No matter which phone I use they still need to record who I call for "billing purposes" and know which cell is closest to route my calls.
- msh 13y agoYou could use p2p VoIP.
- sdoering 13y agoNot in Germany, where opening your WIFI makes you liable for all the things that might happen with this. But only if you are a private person (or a small cafe/venue). If you are an ISP, you can operate hotspots wherever you want and charge whatever anyone is willing to pay. And you do not need to fear being held liable for your users actions. [Edit] Meant to say, that since this change of law we do not have a lot of open WIFI-Spots anymore.
- noselasd 13y agoThey could still track you though. You'll need a sim card, and you'll need to attach to the network - which means the carrier can track your location.
- deno 13y ago1) Buy prepaid card with data plan. 2) Access Internet (and VOIP) only via VPN or better yet TOR. 3) Only give out your VOIP number. No one must know your direct number, it’s only for emergencies. This severs all the important connections to make any use of that data, assuming you don’t have any leaks.
- thrwwyusr543 13y agoTo expand on this, does anyone know of a reliable service provider (accepting bitcoins is a bonus) for SIP Trunking[0]? Or any VoIP workflow that can perform calls to PSTN[1] (the regular landline/mobile telephone network). Or even any VoIP provider that offers a basic answering service, where the voice mail box can be checked over the internet a la google voice/skype voicemail? [0] https://en.wikipedia.org/wiki/SIP_Trunking https://en.wikipedia.org/wiki/SIP_Trunking [1] https://en.wikipedia.org/wiki/Pstn https://en.wikipedia.org/wiki/Pstn Edit: A quick search gave me this[2] by Plivo. Does any one know of any other options? [2] http://plivo.com/blog/sip-trunking-to-replace-my-landline-phone-using-plivo/ http://plivo.com/blog/sip-trunking-to-replace-my-landline-ph...
- r0h1n 13y ago>> "Enabling revolutionary communications"? Eh? Wouldn't "Enabling secure/private communications" be a better, albeit less grand, descriptor?
- derefr 13y agoPresumably they mean that literally: enabling the type of communications you need during a political revolution.
- sdfjkl 13y agoTo even have the theoretical possibility of "privacy & security", both software and hardware must be fully open. And then there must be some way to check that the hardware and software you got in that box is actually the hardware from the spec, without extra chips. Those are pretty hard to accomplish.
- buro9 13y agoWell, this is just a splash page and says very little. It's in partnerships with http://www.geeksphone.com/ http://www.geeksphone.com/ which is FirefoxOS based. But yet the Blackphone splash has an image of a phone with Android buttons. They claim no hooks to vendors, so if it's Android I can't imagine this is going to carry the Play store. I'd be interested in knowing how they will secure and make private the core functionality of being a phone and sending email and text, all of which are insecure. On that, I'd speculate that this is just pre-loaded with Silent Circle apps, and maybe will be announced as having DarkMail and a choice of RedPhone. But... there's no info at all really, so who knows what this is. The only problem they really have to solve is the eternal question of: Is it possible to provide real security and privacy whilst providing convenience?
- infinite_snoop 13y agoFrom the video: "PrivatOS is the Android you are familiar with"
- girvo 13y agoGeeksphone actually made Android phones originally.
- higherpurpose 13y agoText- in a similar way TextSecure did it, would be my guess. They have something called Silent Text, and they're using the ideas here I believe: http://eprint.iacr.org/2014/036.pdf http://eprint.iacr.org/2014/036.pdf Email? They've announced the DarkMail protocol last year, and should be coming soon: http://darkmail.info/ http://darkmail.info/ https://www.youtube.com/watch?v=IgV_Z6V_llk https://www.youtube.com/watch?v=IgV_Z6V_llk
- deleted 13y ago[deleted]
- junto 13y ago> Use the apps you know and love. Ok, so how do they stop Facebook et al from abusing our contact lists and location data as they do on existing smart phones?
- joosters 13y agoCompletely useless web page. All wooly 'feel-good' words and no hard, concrete information. So I guess we just have to take it on trust then? Also, their privacy policy is laughable: We turn the logging level on our systems to log only protocol-related errors - great! the pages on our main web site pull in javascript files from a third party. This allows our web developers and salespeople to know which pages are being looked at - so instead of keeping your own logs, you are outsourcing this to a 3rd party with worse privacy policies, and who can now aggregate your website usage with other sites. Why didn't they just keep logging on and get rid of the 3rd party bugs?
- Torn 13y agoExpecting people to write their own metrics stack for a promo site is a bit OTT - there are a lot of good analytics stacks out there which let you get up and running very quickly, complete with dashboards, metrics, etc.
- icebraining 13y agoYou don't need to write your own, just self-host it: http://piwik.org/ http://piwik.org/
- tomp 13y agoWell, Silent Circle is based in Washington DC, so even if they were keeping logs themselves, it wouldn't be much of a privacy reassurance...
- daliusd 13y agoThis web page is clearly marketing page not technology information page. They simply try to gather information if there is interest/demand for something like this. LEAN startup :-)
- panacea 13y ago"Blackphone is re-shaping the landscape of personal communications. Pre-ordering begins..." How is it re-shaping anything before it's started shipping?
- darklajid 13y agoI'm weird enough to be interested in these kind of things, but the whole site is really .. just fluff. Ignoring that and focusing on the sparse details of the actual thing: - High-End Android device - Privacy features in the (custom) Android version - "Secure communication builtin" Again, I like the idea. But so far the details match CyanogenMod (with TextSecure for SMS, maybe XPrivacy on top)?
- soci 13y agoYes, looks like an Android powered device. So, at the end is just another OS right? One of the big drawbacks when I first started my nexus5 was that I was being spyed. Why the hell do I need a gmail account to get started?! I wonder if it would be possible to install this Android flavour in a Nexus device ?
- redacted 13y agoYou don't actually need a gmail account for what its worth - Google just makes it difficult. On the screen where it requests a login you (seriously) need to tap each corner of the screen in clockwise order starting from the top left. That should skip the step.
- ianlevesque 13y agoThat's useful, and user-hostile. On iOS you can just tap "Skip this step" if you don't want to use an Apple account with it.
- Mikeb85 13y agoYet you need an Apple account to download anything from the App Store or iTunes... An iPhone without apps is barely useful.
- higherpurpose 13y agoUnless someone forks it, and builds support for your phone's drivers in it - then it's not possible.
- fmax30 13y agoThis maybe a bit off topic but, why did Switzerland get the .ch domain instead of china. China seems to have a lousy CN domain ,( which reminds me of cartoon network for reasons that are irrelevant here).
- skrause 13y agoIt has been like that before internet domains: http://en.wikipedia.org/wiki/ISO_3166-1_alpha-2 http://en.wikipedia.org/wiki/ISO_3166-1_alpha-2
- dan1234 13y agoCH is Switzerland's ISO-3166 code. The full country name is Swiss Confederation (which is Confoederatio Helvetica in latin).
- chevreuil 13y agoI think it stands for "Confederatio Helvetica", and is the official abbreviations (eg : on licence plates)
- na85 13y agoSame reason the abbreviation for the Swiss Franc is CHF.
- tn13 13y agoHow difficult is it really to make a truly open source phone ? All it takes is one dedicated hardware company and a software company coming together. Hackers have built some amazing hardware in past and we all know about how open source communities have built some of worlds best software. Google, Apple etc. are building devices where they act as gatekeepers and charge us for all nonsensical stuff. If you make a website there are a gazillion ways to promote it but there is only one way to promote and app. Pay some advertiser and you are totally at mercy of Google or Apple. Firefox has been doing the right thing so far but they seem to take too much time.
- zphds 13y agoOpenmoko did that before Android. Sadly, it had a very lukewarm response owing to a not-so-good hardware.
- digitalengineer 13y agoThe baseband or "The secret second operating system that could make every mobile phone insecure". It's used by all phones and it's unsecure. Do they rely on the same baseband? Source: http://www.extremetech.com/computing/170874-the-secret-second-operating-system-that-could-make-every-mobile-phone-insecure http://www.extremetech.com/computing/170874-the-secret-secon...
- yetfeo 13y agoMozilla could take great strides towards this type of phone if they cared. Integrate tor, Whisper Systems RedPhone and SercureText, HTML tracking disabled, etc. I'm surprised their Firefox OS looks and works so much like every other phone out there.
- andor 13y agoMozilla would have an awful lot of security work to do. If you check the CVEs for Firefox, there was, on average, a remote code execution vulnerability each week in the last 3 months. http://web.nvd.nist.gov/view/vuln/search-results?query=firefox&search_type=last3months&cves=on http://web.nvd.nist.gov/view/vuln/search-results?query=firef...
- yetfeo 13y agoThey have to do that work anyway due to Firefox OS.
- revelation 13y agoThe privacy issue in smartphones isn't the freaking application processor running Android. Sure, that ones terrible enough. But the actual problem is the baseband processor running completely non-free software, with an enormous attack surface and access to all the interesting periphery (GPS, microphone). There is not just opportunity to compromise your privacy, Qualcomm and others actively implement such features at the behest of governments and carriers. Oh, and if you plug that enormous hole, you get to the SIM card, yet another processor that you have zero control over, but which has access to enough juicy data to compromise your privacy. I highly recommend everyone to watch a talk from 30C3 by Karsten Nohl, where he shows a live attack on an improperly configured SIM card that remotely implants a Java app on the SIM card which continuously sends your cell ID (your approximate location) to the attacker by short message (without notification to the application processor, e.g. Android or iOS): http://www.youtube.com/watch?v=5B7XyVWgoxg http://www.youtube.com/watch?v=5B7XyVWgoxg Carriers can do this today. (edit: that's a bit nonsensical, because carriers of course already know your cell id. Anyone with the ability to run a fake basestation momentarily (think IMSI catcher) can do this.)
- na85 13y agoCame here to say this exactly. The world needs an open-source baseband processor/firmware.
- deleted 13y ago[deleted]
- dobbsbob 13y agoOsmocom baseband tried this. Works on older motorola phones, then just buy a turbosim with encrypted voice, sms and code your own OTA blocking. Or use a small tablet with no sim using wifi
- f_salmon 13y ago> But the actual problem is the baseband processor running completely non-free software True, and once that one will be made open-source too, there's still the NSA tracking mobile phones worldwide and generating all kinds of privacy-invading data based on it: http://www.washingtonpost.com/world/national-security/nsa-tracking-cellphone-locations-worldwide-snowden-documents-show/2013/12/04/5492873a-5cf2-11e3-bc56-c6ca94801fac_story.html http://www.washingtonpost.com/world/national-security/nsa-tr... (And until that is resolved, my mobile phone will stay in flight mode only.) So once again, while tech may help in the short term, long-term solutions will have to be structural/systemic ones regarding government in general.
- apunic 13y agoAndroid having the most granular permission system ever seen on any operating system is already the most secure operating system. The biggest security hole next to the baseband processor and the SIM is the user who installs every app in seconds without checking permissions.
- drdaeman 13y agoNot even remotely granular. Install XPrivacy[1] (which is still not granular enough for me, as it lacks filtering over function arguments) and see that categories are very broad. [1]: https://github.com/M66B/XPrivacy#xprivacy https://github.com/M66B/XPrivacy#xprivacy
- magic_haze 13y agoArgument-level filtering would be awesome, but I don't know, the existing app+function level filtering seems to be working fine for me so far. The only real complaint I have with xprivacy now is the atrocious UI, and I'd really like some way for it to automatically fetch filters from somewhere so I don't have to bother with the permissions every time an app updates.
- tomp 13y agoNot really, iOS permissions are more granular sometimes - iOS will ask you before an app accesses your phonebook, and you can deny the access. You can't do that with Android.
- apunic 13y ago> iOS permissions are more granular sometimes Not true, http://developer.android.com/reference/android/Manifest.permission.html http://developer.android.com/reference/android/Manifest.perm...
- eddieroger 13y agoAndroid permissions are all or none at install time. iOS allows permissions to be individually toggled at any time. Some people define flexibility differently.
- pieter_mj 13y agoTrue privacy on a smartphone can only be expected when software and hardware are 100% open sourced. This of course includes the source code for the 3 Os's that typically run on a smartphone. Anything that's running server-side cannot be trusted either. So we need client-side encryption/decryption as well.
- digitalengineer 13y ago"and anonymize your activity through a VPN." iOS and Android support VPN but it needs to be manually activated each time, making it rather useless unless you're using some public wifi. If I understand correctly there is a possibility for large companies to integrate VPN but for the average guy it's rather useless if you have to activate it. If this phone has VPN really integrated that'd be great.
- mike-cardwell 13y agoI understood that this had been fixed in Android a while back so it would start up automatically? Personally, I'm still on 2.3 which requires a manual startup...
- ToastyMallows 13y agoIf you could tell me how to do it that would be great. I'm still stuck turning it on all the time. Auto-on would be awesome.
- andyjohnson0 13y agoI know they are pre-launch and this is just a landing page, but it doesn't tell us much. Questions: 1. Is this just a stock phone with some privacy-orientated applications built-in, or is the OS and hardware contributing anything? 2. They seem to be using Android. AOSP or Cyanogenmod? Have they any work themselves to harden the OS? Are they using virtualisation? 3. Any closed binary blobs in there? What about the baseband firmware? (Does open source baseband firmware even exist?) 4. Whats the hardware like? Is it hardened in any way?
- arj 13y agoUnless they have some really special hardware in this, I don't see how its that much different than running cyanogenmod + secure applications on top, such as textsecure.
- avighnay 13y agoGeeksphone is doing pretty impressive for a startup that they were launch partners for Firefox OS and now have roped in PGP founders for this project. Were they successful in delivering on the Firefox phones?, Their website always says 'out of stock'. Blackphone seems to be ambitious too. Is it possible for a startup to sail these two boats? Also I find it odd that the PR is always just before the Mobile World Congress (MWC) which happens in Spain, last year with Firefox OS and this year with Blackphone
- dandare 13y agoI am not getting it, how do you prevent the carrier from knowing where you are if you sign up to it with your number?
- pattle 13y agoThe website doesn't really tell me anything about the phone.
- sidcool 13y agoIs it an Android phone?
- heldrida 13y agoThe phone image is missing. Check "images/teaser_site/img03.jpg", css #phone style.css line 396 Thanks
- Duhck 13y agoI don't really feel like a slave, maybe I am under reacting here. I am pissed the NSA is collecting data, I am upset at all the recent revelations we have had about data privacy in the last 6-8 months, but I certainly don't feel like a slave. These products should be advertised on theblaze and infowares. Sure there is a need for better privacy, but I don't really care for the fearmongering...
- Trufa 13y agoI agree with the fact that the website is still a little bit unspecific but this project is backed by Phil Zimmermann, he was the creator of PGP, it doesn't guarantee anything but it definitely means some smart people who are worried about privacy are behind it.
- EthanHeilman 13y agoI'd really like a phone that had the following features: * physical switches for GPS, WIFI, Radio, Camera, Mic, write/read access to disk (go diskless), * a secondary low power eInk display that is wired directly into the hardware that shows when the last time GPS, mic, camera were turned on (and for how long) and how much data has been sent over the radio and read from disk, * a FS which encrypts certain files with a key that is stored remotely. If your phone is stolen you can delete this remote key. The key is changed on every decrypt. You also get a remote log of all times this remote key was accessed. * hardware support for read-only, write-only files, * hardware support for real secure delete on the SSD, * the ability to change all my HW identifiers at will (IMEI, SIM, etc), * a log, stored on a separate SD card, of all data sent and received using a HW tap on the radio/WIFI. The log should be encrypted such that only someone with the private key can read it (public key used to encrypt an AES session key which is rotated out every 5 minutes). If you think someone has compromised your phone you can audit this log for both exploitation and data exfiltration. Since the log is implemented in HW, no rootkit can alter it.
- blueskin_ 13y agoPlease not another long scrolling page without any real info... shame, I might have wanted one if they had provided any specs or technical details at all...
- naithemilkman 13y agoIsn't this kinda moot if you're using any services that is domiciled in the States?
- pekk 13y agoremember: as long as you are outside the US, you are safe from espionage
- unicornporn 13y agoNo Play store in this I hope. I'm currently running Cyanogenmod without Gapps and I'm wondering what this will offer me.
- blahbl4hblahtoo 13y agoPersonally, if I were really worried about privacy I would use burners or get a lineman's handset. It seems like a smart device that you use all the time is going to have the same problems. So, yeah you can encrypt the voice channel. That's great. You can send encrypted text messages. The people involved are serious cryptographers. All of it sounds good. You have to ask your self though, what is it you are trying to do? Who is your adversary? Other people here have mentioned it, but what about apps on the phone? Facebook is still Facebook.
- _wmd 13y agoAs others have pointed out, the baseband is not your friend. Was thinking about this recently, and saw no reason why existing POCSAG (pager) networks couldn't be reused to provide a completely passive receiver. Imagine a phone where the baseband was off by default, unless attempting to make a call. Voicemail/e-mail summaries were broadcast encrypted via POCSAG, and generate notifications just like a new mail summary coming in via GPRS/3G would. Obviously usability would suffer a little bit (mostly in huge latency when you actually wanted to make a call), but seems like very cheap phone could be built that integrated a pager, allowing complete disconnection from the 'active' radio network, avoiding location tracking by your cell provider, or similar evil tricks by third parties.
- this_user 13y ago> " Imagine a phone where the baseband was off by default, unless attempting to make a call." Except if everyone started using a phone like that, you wouldn't be able to call anyone.
- pyre 13y agoYou'd page them first!
- noselasd 13y agoI'd imagine the POCSAG network would be quite overloaded, quite quickly. It doesn't have a lot of bandwidth, and unless the network knows where you are, messages destined to you would have to be broadcast everywhere.
- sgarrity 13y agoThey should probably work on the mixed-content SSL warnings on their own website. It's obviously not related to the security of the phones, but it doesn't instill much confidence.
- sifarat 13y agoI would hate to say this, but people here and there, are cashing in NSA fiasco. I would have loved it more, if this was more focused on 'features' than playing with people's emotions. this is valid for everything currently cashing-in NSA issue. As for, NSA spying how exactly can this phone ensure 100% secrecy. Given a user would have to use the same apps, and above all, the carrier that other smartphone users use. Point is, US Govt is hellbent on spying on you. And they will no matter what. Either change the US Govt, or suck it up. Nothing else is gonna work.
- dmix 13y agoSo hows that "change the US govt" (or any other world gov) going so far since the leaks? I called bullshit from the beginning that anything will change politically, and now six months later I'm more certain nothing is going to change at the political level. They've dug in their heels for the long ride. The only positive developments has been private companies like Google encrypting their data centers and privacy software finally finding an audience. But at the same time, not even the most die-hard cypherpunks think you can achieve 100% secrecy from a dedicated adversary. But that's not the primary goal. Countering mass-surveillance is.
- frabcus 13y agoThe NSA is only one fear - there are other actors you'd expect to be doing similar things. e.g. Chinese, mafia. Using things like Blackphone can potentially increase the cost of anyone doing this kind of spying, to vastly reduce who will do it for what reasons. This talk by Dymaxion is good on economics and usability of this stuff: http://dymaxion.org/talks/EaPitLW.html http://dymaxion.org/talks/EaPitLW.html
- ds9 13y agoIt's true that you can't have privacy or security in the mass-market apps or in voice or sms over big commercial carriers. However, if a device solved the problems indicated by (username) revelation and following posts on this page, you could then run secure applications - e.g. something with public-key encryption and PFS for the data, and a p2p or tor-style network to obscure the metadata. It still wouldn't be perfect, but would succeed in many scenarios and would greatly increase adversary costs.
- andyjohnson0 13y agoRenowned cryptographer believes his 'Blackphone' can stop the NSA http://www.theverge.com/2014/1/15/5310710/phil-zimmermann-silent-circle-geeksphone-blackphone-launch http://www.theverge.com/2014/1/15/5310710/phil-zimmermann-si...
- rbanffy 13y agoUnless it's possible to power down the communications processor, install fully open source software on it (from the boot and up), and disconnect it from any antennas, I don't trust it at all.
- whizzkid 13y agoWith all the respect what they have done so far, I can't see any reason why this is securer than the other mobile phones.. With the latest NSA stuff, I came to conclusion that a true secure system can only be built under these conditions and just to put it out there, this is just my opinion; - A computer company that manufactures their own hardware such as hard drive, ram, cables, network cards. - An OS that is newly written and not based on any other existing operating systems. - Building the whole system with INDEPENDENT hardware and software mentioned above. - Keeping the mobile device's source code offline from Internet as much as possible These are just the first steps on developing a secure system, then comes the mobile network architecture and encryption etc. I admit, it is not an easy job but, trying to develop a secure system with "not secure" development tools is not the right way to go :)
- giergirey 13y agoYou're probably right about what's involved in building a truly secure smartphone from scratch that we can trust. It's an interesting thought experiment, but I wonder if we can satisfy many use cases without having to build a truly secure smartphone. For example, if I just want to have voice calls to a handful of people with the content of the calls encrypted, then perhaps I can just plug in a "scrambler box" between my untrusted off-the-shelf phone and my audio headset? So rather than designing a secure phone where we trust the wifi stack, the baseband stack, the bluetooth stack, the graphics stack, the USB stack, the flash storage stack because we've designed them from scratch, all we have to design is a little scrambler box that just has audio in, audio out, some mechanism for key generation and exchange, and only needs a laughably modest CPU to do the encryption. Don't really need an OS at all - single process and static memory allocation should suffice. The audio encoding/decoding and encryption/decryption don't sound too hard to implement from scratch. It's the interoperability with the rest of the world and the UI that makes implementing a whole smartphone so hard. [I do wonder though how well our scrambled audio will make it through the phone network which is applying lots of clever compression designed for speech.] If we assume we can mostly trust hardware designs that are at least 30 years old then we can probably avoid designing all the hardware from scratch - e.g. there's probably some sort of Z80 clone CPU we can copy. The mechanism for key generation and management sounds a bit tricky though. The user would need some way to add his contacts' keys to his scrambler box. A keyboard and LCD display to type keys in by hand would be secure but impractical for long keys. The level of tech needed to read a key file from a FAT filing system on a USB stick might be too high to be easily implemented securely. Any ideas? I'm aware of the famous "trusting trust" paper, but I'm not sure we need to worry too much about the compiler used to build the software running on our scrambler box. All we need to do is choose a compiler released before we started out project and never upgrade it. It is hard to imagine a compiler backdoor that would automatically recognize that the intent of our code is to encrypt data and undetectably comprise it (though it would be wise I guess to avoid any existing implementations of cryptographic primitives). Sounds like a hardware kickstarter project :)
- muyuu 13y agoI loved it when they asked for my full name to keep me informed.
- higherpurpose 13y agoSince NSA/FBI can reroute shipping boxes and install malware in them - do they have any plans against that?
- psykovsky 13y agoTamper evident holograms above each and every screw?
- jlebrech 13y agonowhere near as secure as a burner phone purchased in cash.
- bybjorn 13y agoLooks like there will be several players in this market - an alternative is Indie Phone; http://indiephone.eu http://indiephone.eu .. If it ever ships it should be a better alternative privacy-wise as they are building everything from the ground up (their own OS instead of relying on Android, etc.)
- andyl 13y agoI think the Blackphone is a fantastic reaction to the problem of corporate and government spying. It will build awareness of privacy issues, and pave the way for other more secure offerings. A great first step.
- runjake 13y agoI like Mike Janke and all, he's a nice guy. But, he has backed out of RSAC '14 yet [1]? I find it a tough sell to call yourself a privacy advocate and legitimize and fund RSA by speaking at their conference. It also doesn't help Blackphone's cause. 1. http://www.rsaconference.com/speakers/mike-janke http://www.rsaconference.com/speakers/mike-janke
- caiob 13y agoFunny how there's a twitter link at the bottom. Jokes aside, I think it's a great initiative, looking forward to see what comes out of it.
- rch 13y agoThis is not the 'first' phone to do these things. I had an idea along these lines in 2003, and some searching turned up a German company that was already doing it. Somebody bought them a couple of years later, and I don't know what happened to the phone. This sure isn't the 'first' though.
- josefresco 13y agoIf I desire privacy would I buy a Blackphone, or would I buy another more common smartphone which I would then secure? If you're "picked up" or detained and you have a Blackphone, or someone observes you using your Blackphone I doubt very much it would help your pricacy concerns. If however you have a seemingly normal phone it might be overlooked and simply using it wouldn't raise suspicion. My point is that this type of phone is more for the "regular" person who simply doesn't want to be monitored (as much) and not covert agents looking for a secure phone/platform for communication.
- thecoffman 13y agoA site peddling a product that is supposedly about user control and privacy that won't even load without javascript... The irony is almost too much.
- Mikeb85 13y agoWhy? Check out the page source, everything is un-obfuscated, there for you to see.
- wavesounds 13y agoAnyone thinking of making a video to sell a privacy product to mass consumers should probably stay away from creepy music and women walking around in all black hoods. Instead go for soccer moms buying stuff with her credit card or librarians doing research for a school kid. Let's not make secure/private communications something weird and creepy but something normal that everyone does.
- aagha 13y agoIt's interesting that all the work being done on this "secure" phone is being done on non-secure hardware and networks. Presumably if interested parties think this is a threat, they can access all comms/data about this new phone, inject themselves where they see fit and compromise the final product. Oh, and never mind compromising the people involved.
- viseztrance 13y agoI would personally be interested if they would provide security updates over a long period of time.
- blackphace 13y agoTheir trailer seems a little too "inspired" by this First ELSE promo video from 2009: https://www.youtube.com/watch?v=ZHghZnOH8dA https://www.youtube.com/watch?v=ZHghZnOH8dA
- a_rahmanshah 13y agoExactly! I thought this whole black thing was some kind of spoof.
- BuildTheRobots 13y agoLove the idea of a GSM handset that believes in protecting my privacy, however all their features seem to revolve around a secured Android OS. Does anyone know if the actual baseband/wireless side has been designed with security in mind? -for example I'd love to be warned when I'm connected to an A5/0 "encrypted" GSM network, but I haven't been able to find a handset build in the last decade that's willing to warn me.
- ilovecookies 13y agoIsn't the problem more connected to the hardware and the fact that most people are already willingly using tons of applications who are giving information about you to companies like google (maps) twitter, facebook etc. If you install the apps with consent on your phone, and those apps have access to the linux or ios kernel runtime and syslogs then you're basically fucked from start.
- MWil 13y agoI thought it was funny, considering the top comments, that if I cntrl+F for "zimmerman" it takes me all the way to halfway down the page
- dblotsky 13y ago"You can make and receive secure phone calls; exchange secure texts; exchange and store secure files; have secure video chat; browse privately; and anonymize your activity through a VPN." People. It's really secure, private, and anonymous, ok?
- djyaz1200 13y agoWill someone please tell them to remove the clips in their video of testing a white phone in the interest of brand consistency? Also this idea seems like a solid game plan for Blackberry? They could rename their company "Black" ala P-Diddy v just Diddy. :)
- tinalumfoil 13y agoDoes anyone else see this as ridiculous attempt to profit off the NSA leaks. The video is about scaring people into believing their being "enslaved" and are coming out with a device that has "never before before created" that is aimed at "for privacy-minded, security-minded people". It's filled with unrelated words like "neutrality", "all walks of life", "innovative thinkers" to make it seem legit. There is no mention of the methods used by the phone to ensure privacy.
- lispm 13y agoI stopped watching the video at 'Android'.
- skuunk1 13y agoToo bad they couldn't get the url blackphone.sh ;)
- pessimizer 13y agoHow usable is Android without a continual involvement with Google? If you have to be involved with Google, there's no point.
- JoelJacobson 13y agoWould it be possible to do the encryption outside of a normal phone, via some AD/DA converted plugged into the standard 3.5mm-headphone minijack? I started a thread to discuss this idea: https://news.ycombinator.com/item?id=7066792 https://news.ycombinator.com/item?id=7066792
- oh_sigh 13y agoI get the feeling this phone was designed by a marketing group, and not competent engineers. Unless they completely design every chip in the phone, including the SIM and wireless chipsets, the device will never achieve their stated goals.
- bosch 13y agoDoes any one else find it odd a privacy centric phone's website won't load without scripts, cookies, etc? I would think they would have a text only version if items failed to load properly...
- T3RMINATED 13y agoThe Spying can happen through Software too, this phone is garbage.
- cyphunk 13y agoWill the browser be OSS? Will the mail app? Message app? Maps app? If the essential apps that constitute a "smart phone" are not open source, at least the defaults, it's really irrelevant. Not to mention that none of the providers have the code to the baseband. I could imagine a phone that treats the baseband as an untrusted entity and encapsulates everything running over it. This would require forcing SSL for all HTTP traffic, and using some standard for SMS and Voice encryption that is on by default when the recipient on the other end also has a supported device. For those that do not you're unencrypted SMS would be exposed at many hops even if they smartphone were full OSS and trusted, even to the baseband level. So silo'ing everything where possible is a valid solution with closed basebands.
- elwell 13y agoWhile I see the reasoning, the name "Blackphone" just has too much of a racist connotation in America.
- drjacobs 13y agoOuch, don't try this one on a slow connection.
- xmus 13y agoi MUST be dreaming - Android WITH Privacy - am going to pinch myself!