Re: Privacy Concerns with UbuntuPhone

Thomi Richards <[email protected]>
Newsgroups gmane.org.user-groups.linux.dunedin.general
Message-ID <CAN2KdQ_grfcCq0VGmz6u=h99Yovia5=TF22W1pe=U1xVYk-x=Q@mail.gmail.com>
Hi,


On 23 April 2014 11:28, Worik Stanton <[email protected]> wrote:

> On 22/04/14 17:48, Thomi Richards wrote:
> > Seriously though - you really cannot. You can have the illusion of
> > security, and you can prevent casual snooping. You cannot prevent the
> > sustained interest of a powerful organisation once they make you a
> target.
>
> That is an invalid argument.
>
>
No it's not...


> I can illustrate with an analogy" I cannot be *totally* safe driving my
> car.  Does not mean that wearing my seatbelt is an illusion of safety.
>
>
The original post sounded (to me, at least) like it was couched in absolute
terms. My point is that absolutes don't exist here, just like in your car
analogy. You can make yourself more safe - probably - but don't kid
yourself into thinking that wearing your seatbelt makes you totally
safe.... that's obviously stupid.



> Security is a process and it has a cost.  The real question is "what
> security can I afford" and is that sufficient?
>


Right - I agree.


>
> > If all you care about is prevention of casual snooping, then I think we
> > have larger problems to hand than a closed baseband OS.
>
> Not wanting to put words in Strypy's mouth but I think he is concerned
> with more than that.  The question is can two people establish a covert
> channel of communication that is not accessible to outside observers.
> Either the content nor the fact of the channel being opened.
>
> Clearly if some one follows you around with a high definition long
> distance observation kit, bugs your house etcetera etcetera you cannot.
>
>
I don't think it'd take anything like that much effort. Why would they need
to bug my house when I have a plethora of electronic devices, most of which
connect to the Internet, and can be hijacked remotely?


> Also it would seem it is not possible using the cellular network.  That
> would be the conclusion of this thread?
>
>
I agree that's one conclusion, but I think there's more...


> But it is possible in the general case (the TOR project is doing very
> interesting work), and technology for doing it is very interesting and
> very important right now.
>
>
This is where we disagree. I don't think it's possible in the "general
case" (although I'm not sure exactly what the "general case" is these days,
since mobile devices are pretty damn similar to laptops & desktops these
days). Tor (for example) is still vulnerable at the edges of it's network,
and there have been several interesting studies that show that traffic from
exit nodes are already being silently monitored. This makes interesting
reading, from January this year:

http://securityaffairs.co/wordpress/21535/cyber-crime/russia-spying-tor-network-exit-nodes.html

On top of that, several Tor exit nodes were vulnerable to the heartbleed
bug, so that's another attack vector.

http://threatpost.com/tor-begins-blacklisting-exit-nodes-vulnerable-to-heartbleed/105519

So... using tor, you make yourself more safe, probably. Just like with your
car analogy, these things are all relative. Understanding the risks
involved with any particular piece of technology is probably more important
than trying to achieve absolute security.


Cheers,
-- 
Thomi Richards

_______________________________________________
DunLUG mailing list
[email protected]
http://lists.ethernal.org/listinfo/dunlug
DunLUG Wiki - http://dunlug.kallisti.net.nz/
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.