4 ms·
Mission Impossible: Hardening Android for Security and Privacy
- joelanders 12y agoIf you like this, you'll also like Peter Stuge's 30c3 talk: Hardening hardware and choosing a #goodBIOS "A commodity laptop is analyzed to identify exposed attack surfaces and is then secured on both the hardware and the firmware level against permanent modifications by malicious software as well as quick drive-by hardware attacks by evil maids, ensuring that the machine always powers up to a known good state and significantly raising the bar for an attacker who wants to use the machine against its owner." http://media.ccc.de/browse/congress/2013/30C3_-_5529_-_en_-_saal_2_-_201312271830_-_hardening_hardware_and_choosing_a_goodbios_-_peter_stuge.html http://media.ccc.de/browse/congress/2013/30C3_-_5529_-_en_-_... And this is the best blog post I know of on the above: https://blog.patternsinthevoid.net/replacing-a-thinkpad-x60-bootflash-chip.html https://blog.patternsinthevoid.net/replacing-a-thinkpad-x60-...
- synctext 12y ago100+ steps are needed to add some privacy to Android. Impressive work and I'm eager to try this out on a rainy day. Hopefully this will become easier and realistic for many more people soon to have.
- rsync 12y agoUnless there is an open baseband chipset, there is nothing that tor, or anyone else, can do to secure an android phone[1]. Depending on the implementation of the SOC, etc., the baseband chipset, which can be controlled over the air by your carrier (independently of the computer you're holding in your hand) can have full DMA access to the phone. Read that again: the carrier, through special over the air interfaces that you cannot be a part of, can control your entire phones memory - reading and writing bit by bit any piece they want. There's no software, or OS, that will save you on a device like that. Note that not all baseband chipsets are quite as dangerous, but they're all a closed source, third-party controlled device-within-a-device that is run over an out of band interface that you can't control. [1] ... or any other phone ...
- wzdd 12y agoThe very first part of the article, "Hardware Selection", covers this point and recommends that the secure device not have a baseband. They use a wifi-only Nexus 7.
- rsync 12y agoI really wish you could get wifi only phones. The Samsung galaxy player was a good candidate a few years ago, but that's quite old now and doesn't appear to be a trend that continued. A wifi only phone with a full size USB and a very small GSM thumb drive ... that would be workable. Also: fantasy. OR: a normal phone with a GSM sim module that you could add/remove quickly, like a SD card - without opening the device.
- saraid216 12y ago> OR: a normal phone with a GSM sim module that you could add/remove quickly, like a SD card - without opening the device. I've got a Motorola Razr Mini and, if I didn't have a case, the SIM card is removed by stabbing a fingernail into the volume control and pulling. First time I did it, I was so surprised at the ease that I dropped everything.
- ctb_mg 12y agoAren't things like the iPod touch and many tablets basically "wifi only" phones? What if we had a killer phone-over-wifi app, to allow this segment of the market to take off?
- AnthonyMouse 12y ago> What if we had a killer phone-over-wifi app, to allow this segment of the market to take off? It's called VoIP. The carriers do everything they can to kill it (to keep you buying cellular service for voice), but it's not like the technology doesn't exist.
- 12y ago