Re: Privacy Concerns with UbuntuPhone

Danyl Strype <[email protected]>
Newsgroups gmane.org.user-groups.linux.dunedin.general
Message-ID <CAHE=x=kUe=rPGcLkHWF-sbHAy-+B0NM7YV137YjQbui7+17UaA@mail.gmail.com>
Kia ora koutou

Thanks to everybody who shed light on the deeper issues with the cell
phone network technology (btw I was specifically *not* picking on
Ubuntu here, which I why I said I presumed it was a hardware
imposition on the UbuntuPhone developers).

It sounds like a handheld with a 100% free code stack could only ever
be used with wifi and some kind of VoIP, instead of using the cell
phone network? All the more reason to support the work of groups like
the Free Network Foundation (http://thefnf.org/), and the Open
Wireless Movement (https://openwireless.org/) and get a project set up
to implement a free wireless network in Aotearoa. In fact I think the
political party which set up a publicly-owned, country-wide wireless
network, accessible to anyone, would be as revolutionary and
forward-looking as the party that set up the first free-to-air
television broadcast network.

On 10 April 2014 07:42, Thomi Richards <[email protected]> wrote:
>> Yes, a mobile phone with a full open source stack would be really nice. <<

For a desktop computer, it's really nice. For a laptop, which you tend
to carry around with you sometimes and connect to random networks,
it's quite important. For a handheld with a built -in mic and camera
which you carry everywhere with you, and is always on, it's not just
"nice" it's critical to not implementing an updated version of 1984
which would have Orwell rolling in his grave. I agree with Stallman
that the current "mobile phone" technology would have been Stalin's
dream.

>> It's also worth noting that this is not specific to Ubuntu Touch - *all* open source phones, including phones that run Firefox OS, Tizen, and MeeGo run proprietary baseband code <<

Good to know, thanks. I was considering getting one of these phones,
but for now I will stick with the old Nokia dumbphone. Yes, it's
proprietary, and yes it allows me to be tracked whenever it's turned
on, but it's the devil I know, and I'm confident it hasn't got the
processing power to do anything worse. What about the Neo Freerunner
running OpenMoko, did that also have a proprietary baseband?

Paul:
>>  it's likely that cell companies would not allow phones with easily hackable baseband stacks on their networks (they wouldn't let you have a SIM). the problem is that cell services use protocols that depend on all phones playing  nicely with each other <<

This is a horrific situation, comparable to being forced to run a
proprietary network driver in order to be allowed access to an
internet connection, and it sounds like security by obscurity. If the
baseband hardware and software are proprietary, how can the cell
companies know whether it's going to play nicely or not until the
first phone with that baseband joins the network? If the hardware had
publicly documented specs, and the software were free code, the cell
companies would be able to run tests and audit the code.

Correct me if I'm wrong, but we're talking about firmware here. Not
just something a user can muck around with from a GUI. Even in a 100%
free phone, to change the firmware you'd have to flash the chip, the
same way you jailbreak an iPhone, right? So yes, a hacked phone could
cause problems, but I can't see why a 100% free baseband is any more
likely to be a problem in that respect than a proprietary one.

Paul:
>> one hacked phone could easily bring down a cell tower or two <<

Sound like yet another good reason to replace the cell phone network
with a modern, more resilient network, running ethernet over wifi?

Paul:
>> I think the real solution to this problem is hardware architecture that isolates the baseband part of the phone and treats it as potentially hostile (rather than giving it free range through memory) <<

This would certainly be an improvement, and the ArduPhone Jim mentions
would prevent many of the potential unintended consequences where
proprietary modules have access to personal data like address books,
call logs, saved texts/emails etc. Has this approach been considered
for the UbunutPhone, Thomi?

>> There's probably no need to compromise the baseband, as by design and desired operation is is a spy unit, and the telco already has all your data (aka 'metadata', which just means 'data' in this context). <<

I'm sorry, I just don't accept this. I can have an end-to-end
encrypted voice conversation across the internet with an AspireOne and
Trisquel, where no part of the software or hardware stack is a "spy
unit" (that I know of). I see no good reason this shouldn't be
possible with a handheld PC, instead of a desktop or laptop, and no
reason to accept the presence of modules designed to be spy units in
any computer I use.

Hei kōnā
S

-- 
Daniel Strypey Bruce
Community Developer
Disintermedia.net.nz/strype

"Geeks are those who partake in our culture."
- .ISOcrates

"Voting... is the next to last refuge of the politically impotent. The
last refuge is, of course, giving your opinion to a pollster, who will
get a version of it through a dessicated question, and then will
submerge it in a Niagra of similar opinions, and convert them into -
what else? - another piece of news. Thus, we have here a great loop of
impotence: The news elicits from you a variety of opinions about which
you can do nothing except to offer them as more news, about which you
can do nothing."
- Neil Postman, 'Amusing Ourselves To Death'

_______________________________________________
DunLUG mailing list
[email protected]
http://lists.ethernal.org/listinfo/dunlug
DunLUG Wiki - http://dunlug.kallisti.net.nz/
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.