Re: Privacy Concerns with UbuntuPhone

Thomi Richards <[email protected]>
Newsgroups gmane.org.user-groups.linux.dunedin.general
Message-ID <CAN2KdQ9p3Osd_SCt5rHtE-98=HPMAtbB3ZFsqP6_QskHvAAJ2g@mail.gmail.com>
Hi,


On 22 April 2014 15:24, Danyl Strype <[email protected]> wrote:

>
> On 10 April 2014 07:42, Thomi Richards <[email protected]> wrote:
> >> Yes, a mobile phone with a full open source stack would be really nice.
> <<
>
> For a desktop computer, it's really nice. For a laptop, which you tend
> to carry around with you sometimes and connect to random networks,
> it's quite important. For a handheld with a built -in mic and camera
> which you carry everywhere with you, and is always on, it's not just
> "nice" it's critical to not implementing an updated version of 1984
> which would have Orwell rolling in his grave. I agree with Stallman
> that the current "mobile phone" technology would have been Stalin's
> dream.
>
>
Welllllll..... I'm still not convinced that a totally open source software
stack would give us any more real security or privacy than we already have,
for two main reasons.

First, while you *might* be able to reduce the number of "nasty surprises"
in your device when you're running an open source stack (and I personally
doubt this), you won't be able to avoid them totally. Look at the recent
well-published security vulnerabilities and then tell me with a straight
face that open source software is totally secure. All code has bugs, even
the good code.

Second, the software on your personal device is just one small part of the
equation. If the NSA (or whoever) *really* want to know where I am, they
can lean on my telco, or my ISP, or any number of other companies who carry
information about my whereabouts. The best I might be able to achieve is to
make it a bit harder for them... maybe. Then again, I'd need to stop using
my debit and credit cards, not use my bus cards, avoid any areas with
security cameras, never use the Internet, not carry a personal phone, or
any device with a wireless chipset and leave my passport at home, and so
never travel abroad... I'm sure I've forgotten a few things as well. If you
start down this route, you end up having to make one of these:

http://i.imgur.com/B4YkAmV.jpg



> >> It's also worth noting that this is not specific to Ubuntu Touch -
> *all* open source phones, including phones that run Firefox OS, Tizen, and
> MeeGo run proprietary baseband code <<
>
> Good to know, thanks. I was considering getting one of these phones,
> but for now I will stick with the old Nokia dumbphone. Yes, it's
> proprietary, and yes it allows me to be tracked whenever it's turned
> on,


only when it's turned on eh? It must be old :)


> but it's the devil I know, and I'm confident it hasn't got the
> processing power to do anything worse. What about the Neo Freerunner
> running OpenMoko, did that also have a proprietary baseband?
>


Probably not:

http://wiki.openmoko.org/wiki/Neo_FreeRunner_Hardware#CALYPSO_ASIC_digital_baseband

Paul:
> >> I think the real solution to this problem is hardware architecture that
> isolates the baseband part of the phone and treats it as potentially
> hostile (rather than giving it free range through memory) <<
>
> This would certainly be an improvement, and the ArduPhone Jim mentions
> would prevent many of the potential unintended consequences where
> proprietary modules have access to personal data like address books,
> call logs, saved texts/emails etc. Has this approach been considered
> for the UbunutPhone, Thomi?
>

I'm not privy to those sorts of conversations at work, so take this with a
spoon of salt, but my understanding is that that's not how the relationship
between OS provider, carrier, and hardware manufacturer works - especially
when "OS provider" is a small company trying to break into the market. I'm
assuming that we'd all rather have a third player in the mobile market
(whether it be Canonical or someone else) than keep the existing two
players in power? (Add one to all those numbers if you think Microsoft are,
and will continue to be a player in the mobile space).


>
> >> There's probably no need to compromise the baseband, as by design and
> desired operation is is a spy unit, and the telco already has all your data
> (aka 'metadata', which just means 'data' in this context). <<
>
> I'm sorry, I just don't accept this. I can have an end-to-end
> encrypted voice conversation across the internet with an AspireOne and
> Trisquel, where no part of the software or hardware stack is a "spy
> unit" (that I know of).


<tinfoil_hat>
Well, it wouldn't be a spy unit if you knew about it, would it?
</tinfoil_hat>

Seriously though - you really cannot. You can have the illusion of
security, and you can prevent casual snooping. You cannot prevent the
sustained interest of a powerful organisation once they make you a target.

If all you care about is prevention of casual snooping, then I think we
have larger problems to hand than a closed baseband OS.



> I see no good reason this shouldn't be
> possible with a handheld PC, instead of a desktop or laptop, and no
> reason to accept the presence of modules designed to be spy units in
> any computer I use.
>
>
As I mentioned above, I think your premise is faulty. You can't have total
security & privacy with any device once you start broadcasting over the
Internet, no matter what the form factor is.


Regarding closed device drivers, this isn't a new situation for Linux
either - 15 years ago it was very hard to buy a desktop computer that
didn't rely on proprietary drivers; heck - the laptop I'm writing this on
uses the proprietary nvidia kernel driver (it's about 2 years old at this
point). It seems that it's getting easier to avoid this though.

I find myself in an unusual position. I'm a keen advocate for open source
software, I think it has many stunning advantages that we should all be
free to take advantage of. I don't, however, think that adopting open
source software for our personal devices reduces the risk of us being
targeted by a surveillance state - not at the moment anyway.

If you want to make any real positive changes here, I can see two
approaches. One is to improve the software we already have, particularly
the crypto stack. The other is to lobby government for fairer and clearer
legislation around when, where, and how surveillance is permitted. Maybe,
once those things are sorted, the next task will be to tackle device
firmware.

Of course, there's nothing to stop dedicated individuals such as yourselves
tackling all of the above at once :)


Cheers,
-- 
Thomi Richards

_______________________________________________
DunLUG mailing list
[email protected]
http://lists.ethernal.org/listinfo/dunlug
DunLUG Wiki - http://dunlug.kallisti.net.nz/
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.