Re: Privacy Concerns with UbuntuPhone
Thomi Richards <[email protected]>
| Newsgroups | gmane.org.user-groups.linux.dunedin.general |
|---|---|
| Message-ID | <CAN2KdQ_grfcCq0VGmz6u=h99Yovia5=TF22W1pe=U1xVYk-x=Q@mail.gmail.com> |
Hi, On 23 April 2014 11:28, Worik Stanton <[email protected]> wrote: > On 22/04/14 17:48, Thomi Richards wrote: > > Seriously though - you really cannot. You can have the illusion of > > security, and you can prevent casual snooping. You cannot prevent the > > sustained interest of a powerful organisation once they make you a > target. > > That is an invalid argument. > > No it's not... > I can illustrate with an analogy" I cannot be *totally* safe driving my > car. Does not mean that wearing my seatbelt is an illusion of safety. > > The original post sounded (to me, at least) like it was couched in absolute terms. My point is that absolutes don't exist here, just like in your car analogy. You can make yourself more safe - probably - but don't kid yourself into thinking that wearing your seatbelt makes you totally safe.... that's obviously stupid. > Security is a process and it has a cost. The real question is "what > security can I afford" and is that sufficient? > Right - I agree. > > > If all you care about is prevention of casual snooping, then I think we > > have larger problems to hand than a closed baseband OS. > > Not wanting to put words in Strypy's mouth but I think he is concerned > with more than that. The question is can two people establish a covert > channel of communication that is not accessible to outside observers. > Either the content nor the fact of the channel being opened. > > Clearly if some one follows you around with a high definition long > distance observation kit, bugs your house etcetera etcetera you cannot. > > I don't think it'd take anything like that much effort. Why would they need to bug my house when I have a plethora of electronic devices, most of which connect to the Internet, and can be hijacked remotely? > Also it would seem it is not possible using the cellular network. That > would be the conclusion of this thread? > > I agree that's one conclusion, but I think there's more... > But it is possible in the general case (the TOR project is doing very > interesting work), and technology for doing it is very interesting and > very important right now. > > This is where we disagree. I don't think it's possible in the "general case" (although I'm not sure exactly what the "general case" is these days, since mobile devices are pretty damn similar to laptops & desktops these days). Tor (for example) is still vulnerable at the edges of it's network, and there have been several interesting studies that show that traffic from exit nodes are already being silently monitored. This makes interesting reading, from January this year: http://securityaffairs.co/wordpress/21535/cyber-crime/russia-spying-tor-network-exit-nodes.html On top of that, several Tor exit nodes were vulnerable to the heartbleed bug, so that's another attack vector. http://threatpost.com/tor-begins-blacklisting-exit-nodes-vulnerable-to-heartbleed/105519 So... using tor, you make yourself more safe, probably. Just like with your car analogy, these things are all relative. Understanding the risks involved with any particular piece of technology is probably more important than trying to achieve absolute security. Cheers, -- Thomi Richards _______________________________________________ DunLUG mailing list [email protected] http://lists.ethernal.org/listinfo/dunlug DunLUG Wiki - http://dunlug.kallisti.net.nz/