It is a common strategy of manufacturers in China. You, as the designer, get ripped of by the very people that you pay to produce your product. The quality can match the original because they use the same factory, same tools, same processes that are used to produce the original product. The manufacturers simply work another shift, e.g. night shift, or do a few more runs. In some cases, manufacturers clone the whole factory that is used to produce the original product so they can increase output of counterfeit goods.
How could one prevent this? Would it be possible to only program a microcontroller after taking delivery, without which the circuit wouldn't be useful? Or could different components be sourced from different manufacturers, and then assembled in yet another factory? How much collusion between manufacturers should we expect?
This is why devices like game consoles and at least a few models of cell phones have a "geneology" database maintained by the official manufacturer, with originating key material in the hardware, and additional activating key material provided to the device at certain well-controlled manufacturing stations. You simply can't make a working device without going through that process.
[Just bricking Blackphones is a terrible move; letting the users know their phones were counterfeit and leaving them on would have been a far better move, IMHO]
So if this is a known problem with known solutions, then the fact that Blackphone didn't do any of this makes them look like amateurs. Maybe one shouldn't rely on them for security...
I'm pretty sure that an android wear watch I bought on Ebay was grey market. I bought it for ~65% of the suggested retail price. When it died ~9 months later, its SN was not recognized by Motorola, so there was no warranty.
So does this achieve anything other than fuck the people over who (probably unknowingly) wound up buying such a Blackphone? I can just imagine waking up, looking at my phone which has been working perfectly well up until that point, and being told it now has been bricked for some licensing issue.
This seems really scummy and would drive me away from their products forever.
I'm saying it doesn't matter if they avoid a brand if the alternative is that they will buy a knock-off. Neither option represents any value to the actual manufacturer- avoiding negative PR from people with knock-offs might actually be preferable.
This isn't a gameboy. If you want toy security I can sell you a phone painted black. But if you want to stay alive when the Syrian police are hunting your people you might want to rethink that.
I know people click through warnings. If that warning could keep them alive, as a dev I'd better do something that'll get their attention.
Also, if they only softly bricked these phones the counterfeiters would just click-through the warnings and sell the phones that way. They have to essentially burn them, for the safety of people who need to be their customers.
No, I'd just want an unbricked, functional, phone. The point is if you buy a $100 phone from wherever and it works, then it suddenly gets bricked due to some company pushing an update, that company is being a dick.
Because most of the users did not realize that they were buying the phone from them, they just bought the cheapest one they could find (from what seemed like an authorized retailer). Had the user known the phone was counterfeit, they may have bought the legitimate one.
> I can just imagine waking up, looking at my phone which has been working perfectly well up until that point, and being told it now has been bricked for some licensing issue.
If I were to buy a Blackphone, I would do it because I wanted security, and because I trusted the manufacturer to provide it. The problem with security is that just because my phone appears to be "working perfectly" doesn't mean that somebody isn't eavesdropping on everything I say.
A counterfeit Blackphone, in other words, is completely defective and untrustworthy, no matter how well it appears to work, because my trust in the manufacturer is broken.
If you don't turn the counterfeit phones into trash, there is no incentive for people to buy the real thing. This hurts the sales of Blackphones and the revenues and profits of the company which invested cash into developing the product - and harming their ability to provide security for genuine customers.
So, protect the profit first, protect the customers second?
I don't exactly see how it bumps up the profit though. You have a bunch of obviously interested customers, who want your product, and then the company has come out with "Actually, we expect you to buy the phone twice, because of a mistake that may or may not of been your fault"
The customers didn't buy a first blackphone, they bought something vaguely similar, but counterfeit. They literally bought a backdoor.
Remember the hassle WhatsApp got for failing open?
The Blackphone+SilentOS is an actual crypto device for people who believe they need crypto. It needs to fail closed. This may cost some people $100, but save their lives.
This also gives the customers the ability to sue the sellers, or at least push for refunds via the sales platforms.
WhatsApp got that hassle because it failed open and didn't clearly inform the user that it was doing so.
If the user is informed they have a non genuine device that is not safe or secure (e.g. like Windows' nag notification), then they can't expect it to work like a secure device, but more like an ordinary phone.
Then both normal consumers (who will continue to use the phone since they didn't really care too much in the first place about safety) and security conscious consumers (who will re-buy asap) would be more inclined to use the same brand in the future
I can't imagine that anyone worldwide was going to buy their first and only smartphone, but decided to spend more to get a special high-security black phone, and is then without a phone because of this. And even if they were, I'd rate the safety of even one user who'd accidentally click through the warnings and make a call that should have been secure but wasn't, as paramount.
If my smoke/heat/etc detector starts to fails I don't want it silently dropping back to a smoke-only detector. I want it to start beeping loudly and refuse to stop.
> If the user is informed they have a non genuine device that is not safe or secure
Having to flash a new OS onto it is an appropriately sized clickthrough for a warning of that magnitude. Like being woken in the night to change a smoke-detector battery.
It's still no worse than any other China manufactured off-brand phone. Which might be exactly what the owner wants, what they bought, and what just got turned into a brick.
They why would you go to the trouble of getting a counterfeit Blackphone...as opposed to other cheap Chinese devices?
Or something like a Moto G?
Also - they're protecting their own image here - can you image the PR s*itstorm that would unfold if somebody bought a counterfeit Blackphone, got hacked or had their details siphoned off to China, then wrote a blogpost about it? We on HN are often quite quick to judge - so I can certainly see why Silent Circle are taking the careful approach here.
A highly consumer-oriented company would at least offer a discount in trade for a real one, with a grace period.
Plus extra points for following through by not actually ever remotely bricking the phones before the anticipated useful lifetime of the real thing.
Nagging may or may not be very bearable depending on consumer goodwill.
If you bought a car that turned out to be stolen, you might wake up one day to find it's gone because the police recovered it for the owner. It's similar here - buyers looking for a bargain that might be illegal are part of the problem of IP theft. They can seek recourse through the seller they got it from, and if that doesn't work, they shouldn't have trusted a dodgy overseas black market seller with their money.
The analogy would work if IP "theft" was anything like actual theft, ie, if the company actually lost anything that could be recovered by "repossessing" the software.
A closer analogy - and still not exactly, since the owner would still have actually lost the car - would be if the police came and burned it down just so that you couldn't use it.
They company surely did lose something. Customers who wanted to buy their product ended up buying an illegal competitor's product instead. There might even be some customers who go back and buy a genuine phone now that they can't use their fake one.
They're enforcing their copyright. Why not? The police can also confiscate computers with pirated software on them. They even do that sometimes. It doesn't return the money to the IP owners but it's still a way to deter theft.
It sounds like a good idea to me. Even if it doesn't recover their lost sales, it should prevent future black market copies since customers will know to avoid unofficial sellers.
You can't assume that someone who bought a $200 phone would buy the exact same phone for $300 if the $200 option was unavailable (I don't know the exact prices but the Ars article said that there were price differences of up to $100).
Going even further, the analogy is still a little bit flawed, because the people buying the phones have reason to believe the phone was NOT stolen (it came brand new, sealed in a box).
It'd be like if you bought a brand new car from a dealership, then two weeks later the police came to your house, told you it was stolen and burnt it down.
However, you're talking about an independent third party with authority doing this - the police. About theft of a physical object.
Why should a vendor be able to stop you from using a thing you bought because it looks like one of theirs? No support, sure. Disavow the item, sure. Post warnings on the device as an inbuilt part of the system, sure. But destroy your item? No.
If someone is fraudulently selling cars badged as Fords, Ford itself should not be able to repossess those vehicles. And if Ford thinks that you have stolen their car, they themselves should still not be the ones who repossess it - that's what the police are for. Vigilantism is a bad thing and has all kinds of unexpected failure modes.
Stealing back your car can certainly cause problems if done privately by the owner. But here it's the product itself that already came with a bricking mechanism built in and activated it itself. The buyer trusted the seller not to provide a self-bricking phone, and got ripped off. It's never going to affect an innocent phone. It's also no physical items being taken or damaged. No baby is going to be trapped in it, etc.
Actually, there's a very analogous thing for cars - LoJack. Is that wrong too?
It happens with copy protection on software. I've heard of games that become impossible to win if they detect they're pirated. Others that just fail entirely. Is that not OK either?
>It happens with copy protection on software. I've heard of games that become impossible to win if they detect they're pirated. Others that just fail entirely. Is that not OK either?
It wouldn't be OK if the developers intentionally affected copies that most users would explicitly believe were not counterfeit (for example, if all Steam copies did this because the game developer had an exclusive agreement with EA/Origin).
The users of the counterfeit phones had no way of knowing they were counterfeit. They were advertised as brand new and came in a shrinkwrapped box.
The users of the counterfeit phones had no way of knowing the phone was fake and probably contained physical and software backdoors.
Crypto devices should brick themselves if they discover they've been tampered with.
It's a clear case of seller fraud and if you use a good marketplace (ie not the one starting with E) you can get a refund through the platform. And maybe get information to use in suing the seller.
> It's also no physical items being taken or damaged
So if I scramble the firmware on your phone and brick it, you don't consider that damaged?
> LoJack
... works in tandem with police, hardly 'very analagous'.
> It happens with copy protection on software.
The user should have been warned that applying the update would brick the detected non-original phone. It shouldn't have just silently fucked the user over. It's bad ethics and also bad PR. Fucking over a user acting in good faith is poor form ethically.
They build a secure phone. It gets ripped off by the manufacturer and resold by anonymous eBay people who can install whatever backdoors on the phone. Then the people using them are being snooped on - exactly what they don't want in the first place.
And allow the user ongoing use of a pirated copy of their Silent OS software? That's generous.
(It's also not Silent Circle's fault if the counterfeit devices were sold with a locked bootloader, precluding the installation of another Android distro.)
Receiving downvotes. Would be interested in an actual response.
If someone was selling laptops with a pirated copy of Windows on it and a Windows update recognized the unlicensed install, causing the laptop to be non-functional, would that be any different?
Remember, the maker of these dodgy laptops has locked the bios so that you can't reinstall a genuine operating system...
It isn't like you're buying a used laptop from someone on Craigslist, the people buying these phones were intentionally mislead to believe that they were buying a brand new (in a shrinkwrapped box) phone from an authorized retailer. If bestbuy sold windows laptops, advertised that it came with a valid Windows licence and they turned out to be lying, should Microsoft brick their laptops?
Buying a counterfeit product on Ebay is exactly like buying a used laptop from someone on Craigslist, save for the buyer's perception of the seller. I don't see how the appearance of the counterfeit product, or the ignorance of the buyer, or the mainstream-ness of the seller is at all relevant here.
To complete your laptop analogy, this "new" laptop from Best Buy turned out to be goods ripped off the assembly line at the Dell factory before the unit had its Windows OEM license assigned or paid for. The software is unlicensed and therefore not genuine. It is not for Microsoft to offer sympathy and a blind eye, they are well within their rights to identify counterfeit installations of Windows and disable them. The remedy is for Best Buy to offer the customer a full refund.
Let me put it another way. Forget hardware for a moment. The purchaser of these counterfeit Blackphones thought they were buying a software license for Silent OS. In reality it is pirated software. And not just garden variety downloaded-with-bittorrent-for-free piracy but rather software piracy as a profitable business model.
Silent Circle doesn't owe these consumers anything and are well within their rights to have all of their software completely self-destruct. They don't owe these consumers a robust mechanism to install an AOSP distro. They don't owe these consumers a bootable device. They don't owe these consumers a discount on a genuine device.
The only correct resolution is for the scam victims to receive a refund from the seller.
Whoa whoa whoa, Silent OS is based on Android, incorporating many GPLv2 and other FLOSS software. They may have done some minor hardening & UI changes, but beyond that the value of Silent OS is the apps they have built for calling & texting securely.
I could see stopping service on those apps, but bricking the baseband is a step too far, as you lose 911 access and Silent Circle almost certainly had no part in the baseband firmware development and is not a rightsholder to it.
Let's suppose one of the proprietary software components is a special secure bootloader. If Silent Circle disabled that one component, as they would be rightfully allowed to do, the phone is a brick.
I should also point out the claim that the baseband was intentionally bricked is unsubstantiated. We don't know if that's actually happening. Or if it's happening, we don't know if it's intentional.
The percentage of proprietary software on the phone — be it five percent or fifty — is orthogonal to the point.
This is a worry - a disgruntled-but-trusted employee decides might use this fine tool you built for a reasonable purpose from using it to brick every phone you've ever made on his-or-her way out your door.
The vendor shouldn't be able to push an update, no. And to the extent that this update was pulled by users without a diff/sanity check/etc, then that constitutes a de facto push. In any case, any update should be completely revertible (which doesn't prevent against data leaks from hostile code, but does prevent against denial of service).
This type of attack is just a test case that any truly secure device has to defend against. I'm not advocating a specific mechanism of avoiding this behavior, because there's obviously work to be done here to come up with a better mechanism than "every user audits every line of source before installing". It's just that this design work has to be done - "security" based on trusting a company is easy, and doesn't differ appreciably from what say Apple already provides.
Your demand is impossible. Any software update mechanism relies upon trusting the software vendor.^ The only thing you can ever hope for is that the update mechanism is capable of trusting that the update has not been tampered with in transit.
^ with the debatable exception of software distributed in source code form in a language you're able to audit and compile yourself, though you'd still be vulnerable to cleverly concealed exploits
Based on the article, it looks like the bricking/disabling occurred after an update to the latest version of the OS.
So, I don't think it is accurate to say that it 'allows remote control by its masters,' as it appears that they just added some sort of check in the latest version of their OS that can tell if the hardware is legit. There isn't any evidence, at least not in the article, that indicates they have some sort of remote control/phone home service running on the phone that allows them to control it arbitrarily.
From the screenshot, it's not entirely clear to me that the baseband is actually bricked. The updated OS refusing to run on some phones isn't the same as damaging the phone.
Yep. That guy at least had a phone and could flash it with another OS and use it. He has nothing now. Not nice from Blackphone. They should have disabled only their sw.
This happens on military and intel bases regularly. Security is not always simple and clean. Common sense and observing warnings will suffice for most, but things happen.
If they install SilentOS on their unlicensed devices, SilentOS can refuse to run.
The question is: Is there an alternative OS that can be used with these devices? If not then they are unusable without the OS. Is that the same as bricked?
In all but the most pedantic of senses, yes, it is bricked.
Even if there were an alternative OS, I'd say it's still pretty well bricked, since installing alternative OSes is outside the skill level and/or comfort zone of most consumers.
Bricked never meant impossible around here. It has always meant (around these parts, SoCal) that the ceiling for recovery was sufficiently high as to warrant concluding that recovery is impractical.
Practically every device i've ran into that has been bricked has been put into that state via software. It may be impossible to fix such state without a JTAG bus and code from the manufacturer, or by desoldering chips, but I can't remember recently when something bricked was truly destroyed and every recovery method was rendered impossible.
(bearing in mind I wouldn't consider something like a ran-over laptop to be 'bricked', but rather just destroyed)
I'm sure some folks use the term when they are referring to destroyed equipment (a 'bricked' gpu from overheating) but I haven't really encountered it personally.
It is legal because they don't license their software with a license ensuring freedoms of the user. The user is not free to use their software.
That's the point of the GPL. If the users took care of only buying products including only GPL'ed software, then they would have the freedoms:
1- to use the software,
2- to copy it for their friends,
3- to get the source to audit it and modify it (so they would be free to remove any backdoor that wouldn't exist in the first place for this very reason),
4- to compile the source to binaries and use them to replace the provided binaries (so their may increase their level of trust of the software they run on their hardware).
Do not buy products that come with freedom-restricted software!
After all that the GPL still doesn't help these users unless they are also able to spin up and maintain the various servers & services the software also relies on.
It's legal for them to disable the software but not for them to prevent the user from using the hardware. It depends on how literal the "bricking" really is but if they made it impossible to load up (say) cyanogenmod then they could be up for a big destruction of property lawsuit.
I'm guessing it would depend on what T&C's the user clicked "I accept" on when setting the phone up or getting the update.
Whenever I get an update on iOS you get the lovely huge Apple T&Cs, which you have to accept to install the update.
So if SilentCircle does the equivalent and put in there "in the event that this is running on a non-approved device, we'll disable the software" then I click "I agree" it would seem fair enough for them to so.
If I were them I think playing it a little cooler would've been to pop-up "Hey this is a knock-off device, we're not letting you use all the cloud service and you're getting no updates from us" and leave it at that...
If the user does not have a valid licence for the software (since the counterfeit manufacturer essentially gave them a pirated copy) it would be legal for it to stop working.
Slightly off topic but related to the product: how can a device using Android be considered safe and trustworthy privacy wise? The maker can surely choose FOSS only Android and encrypt communications, but the moment they add a binary only device driver it can do whatever it wants since it runs with kernel privileges (ie, sniff virtual keyboard, listen to conversations, access messages, contacts, photos, documents etc).
If I'm not mistaken (please correct me in case I am) there's still no phone out there with open device drivers, which IMO translates into giving only a false sense of security to the user.
Moreover, if I buy a security oriented device and it has a remote kill switch, I would expect at least to be the one and only entity in control of it.
Replicant got rid of all the binary blobs (for the main OS, that is), is not just aiming. The effects are of course that you can't use wifi, unless you're using a USB dongle. Not only that, but Replicant is only ported to devices where the GSM chip can be securely turned off (in other words, it's a separate chip, under the control of the main proccesor); Also, the GSM and GPS chips should be separate. The baseband OS if ofcourse still proprietary, but it can be considered an acceptable tradeof, given that it's only connected to the main processor via a USB-like connection (HSIC).
Having a FOSS phone would only be considered trustworthy if it had been reviewed by an entity you trust. I'm not aware of any mainstream OS that has been fully reviewed for security, so realistically the concept of a "trustworthy" device in that sense doesn't exist.
Even if such an audit was done perfectly (a very serious and difficult undertaking), it would be a point in time assessment, so would become less relevant as new code was committed.
Basically you have to trust some group of people to run a modern computing device/environment, it's just a question of who and how much...
Proprietary software starts off with a high level of trust - trusting just one company. But it can never progress past this.
The advantage of FOSS is that the set of who can audit the code is open. It starts small, but grows with popularity and remains agile - eg doesn't necessitate transitively trusting whatever nation-states a single company is vulnerable to.
Unfortunately can audit and do audit are very different things. I'd agree absolutely FOSS has a higher possible level of trust than a proprietary solution, however in practice I don't think it's necessarily the case.
To take one example with a propietary solution with code from a single company, it is possible for a level of background checking to be done on all contributors. With a FOSS solution, that's just not possible, so you get risks like what if one of the contributors is being paid by a nation state who would like to place a specific bug/vulnerability into a codebase.
Of course in practice the world is much muddier than that as pretty much all propietary software vendors make ample use of code they did not write, and in many cases on open source code that they don't really controle the provenance of.
Personally I'd say the idea of having a high level of trust in any larg'ish software stack is very dubious these days given the likely incentives of various groups to compromise them.
"Proprietary software starts off with a high level of trust - trusting just one company. But it can never progress past this."
The first systems that were trustworthy were done by proprietary companies with independent evaluation of the product, signatures on source/binaries, and/or optional generation from source on-site. This became standard practice in security- and safety-critical development. You can scale it to as many people available for review often under NDA for the source itself but not signatures or binaries.
Sure the company can improve their process, but you're trusting the company to do that and do it properly - a user's relationship is still effectively rooted with one company. It's generous to call this "high", but forgive me for trying to make the point palatable to people who believe an autocratic company makes for something trustable.
A company can do things that are similar to Free software (eg allow customers to build from source), but in the context of modern discussion I'd say that's just taking on aspects of Free software.
"Proprietary software starts off with a high level of trust - trusting just one company. But it can never progress past this."
It's totally false. The evaluation side has been done more times than I can count. It doesn't even have to start with a single source. Many products started as a collaboration of multiple organizations checking each others work that share the result. Another model is CompSci inventing something with details open at the start, patented, and then turned into closed source product. Finally, there's Shared Source models where you can have, fix, or extend the source so long as you're paying. Burroughs B5000 (1961), first system resilient to 0-days, was distributed in source form to customers.
You were oversimplifying proprietary systems then attacking that simplification.
I appreciate your historic perspectives, but it feels like we're merely quibbling over terms/framework on this one. I don't think I'm oversimplifying, more like it's current mass-oriented software that essentially falls into two basic camps, Free and proprietary, with various small tweaks to each model. For example, something like a mass-NDA for every user is going to fail for consumer-oriented software, whereas a company contracting a discrete number of external auditing decomposes into trust through branding.
I'd love to find a commercial model that could work for consumer-oriented Free software [0], and I think it could sound quite similar to something you describe. It's just that those type of multi-party collaborations have been pulled into the attractor of free-as-in-beer, at least as far as the code itself is concerned.
[0] I say Free instead of Open, because I can envision software lacking just FSF freedoms 1b and 3 could get stuck in a bad state as well. Like say everyone knows there is a bug and how to fix it, but is legally prevented from doing so.
"but it feels like we're merely quibbling over terms/framework on this one. I don't think I'm oversimplifying"
You were. You made a blanket statement about the whole, proprietary model. In recent comments, you've changed your statement to talk about how the model is applied in the general case. As in, popular implementations vs all implementations. I'll reply to the new comment anyway.
"For example, something like a mass-NDA for every user is going to fail for consumer-oriented software, whereas a company contracting a discrete number of external auditing decomposes into trust through branding."
That's basically what happened. It could go further where lots of users get the NDA with cross-checks but not mass on high-volume scale. It helps if the software is designed in such a way where it can be shown it doesn't manipulate the system. I once proposed memory safety, safe API use, and sandboxing as a start on that. Automated tools could assess those. One could go further with information-flow labels tracking confidentiality or integrity enforced by compiler, runtime, or hardware. A few CompSci projects do it but not mainstream.
"I'd love to find a commercial model that could work for consumer-oriented Free software"
They pay for it. Then they get it. The source is in a FTP server or something somewhere. Things like branding, enterprise features, and tie-ins keep them buying from original supplier. Been done in a few ways although always a risk of clones.
"[0] I say Free instead of Open, because I can envision software lacking just FSF freedoms 1b and 3 could get stuck in a bad state as well. Like say everyone knows there is a bug and how to fix it, but is legally prevented from doing s"
Dual-licensed (proprietary + GPL) covers this. A few, quick proposals follow on non-free trying to approximate free. One could do a shared-source license that allows bug fixes. One could allow redistribution of software to other paying customers. One could cap what's to be paid or for how long before what's purchased becomes perpetual. One can make it go FOSS if it's EOL'd or gets under certain amount of developer time/contributions (tricky measure). Recent proposal was time limit on how long a version or individual product would be paid with it going FOSS after that time limit.
So, quite a few options here. One thing that's important to remember is that FOSS will always have a disadvantage over benign, paid model. The disadvantage is you can contractually ensure those being paid are doing support, bug-fixes, enhancements, pen testing, etc. They can also cover the pro's to do it right. They have lawyer money for patent trolling that will come their way. Combined with shared source like above, they might also get most or all benefits of FOSS with benefits of paid. It's why I'm highly interested to see companies experiment with hybrid models. A few have showed up here but nowhere near enough.
Most practical security measures are about striking a (better) balance between practicality and security. You're probably right that there is no viable device without binary blobs, but if the (corporate security policy) conclusion from this is that you can't use smartphones at all, practical experience shows that people will be using their private (vastly less secure) phones. In that case, it's way better to provide a much more, if not perfectly, secure phone (and sensible policies for using it).
At least, this is the market I perceive the Blackphone to be addressing.
Safe and trustworthy aren't binary values. They're probabilities that the system won't release private information to undesired actors. To calculate those, you have to do your own risk assessment. Remember that a risk assessment for privacy has to put the value of the privacy against the cost of security -- on your side. On the attacker's side, it's the value of whatever they can learn about you vs their costs in getting past whatever defenses you have. Generally that results in going one of two ways: you trust a 3rd party vendor for some of it, or you build the damn thing yourself from small parts. And unless you've got a silicon fab at home, or are buying a shitload of transistors off of digikey, you're going to be trusting some 3rd parties.
In my book, a remote kill switch is OK if you can also trigger it. For privacy, DOS is pretty harmless -- you don't lose privacy, you just lose access to some data/service. If, in exchange of a risk of DOS, I can get better privacy some other way, I'll take it. As for SC fighting counterfeiters, I don't blame them. They're not making much $$ these days, and this is a way to keep alive without hurting their actual customers.
Your text messages, voice calls and browsing history are analyzed by Google using automated software so there is nothing to worry about... (it is used only for targeted ad purposes) /s
Do all sellers of security devices manufacture them in house? Now that you mentioned this it really does sound like a serious problem for providing any kind of guarantee..
I don't think it's fair to call Blackphone "Scam and snake-oil" just because it uses cloud features and has remote control.
What's fair to say is that you're implicitly trusting Silent Circle to be both competent and benign. But then running pretty much any modern computing device requires you to trust various groups of people in that regard, so this isn't that different really.
It's a bit easier for a cloud provider to look at your data surreptitiously, but you apply that very same "I swear that I won't look at your data" trust upon every software and hardware vendor from your USB keyboard to your internet router.
While that is a good point, it's easier to break open your keyboard and ensure it's not emitting RF than it is to audit a site that may be under an entirely different state.
I stopped buying high-priced electronics on eBay or through Amazon resellers. Number of counterfeit products is staggering and superficial quality is high (exterior is usually close to perfect)
seems like this is a perfect case to use ebays/paypal's refund policy that (apparently) always favors the buyer. The policy that people were using to steal from sellers by pocketing the product and mailing back junk.
It sounds like they have a problem with ghost shifts.
The factory they contracted to assemble their phones is running extra shifts off the books and selling the extra phones for extra cash on the side. This happens all the time in China.
This also affects Bluetooth and WiFi MAC addresses, even of laptop computers (!), if going by the letter of the law. Trivially changed by userspace tools, and IIRC Apple randomizes the MAC addresses to prevent people tracking other people's devices.
Edit: It gets even worse, in theory anyone distributing software capable of changing MACs or writing tutorials on how to do this commits an offence. Just look at http://www.legislation.gov.uk/ukpga/2002/31/section/2, it's madness.
It's poorly drafted, but it's only ever used for people who change IMEI. I think it's only used if they change the IMEI on stolen phones. But yes, it's yet another bad English law passed as a kneejerk response to something or other.
So there is this company that markets an "enhanced privacy" device and the marketing material shows a home screen with Chrome, Play Store and Google App.
124 comments
[ 4.2 ms ] story [ 243 ms ] threadDoes anybody know who made the phones?
[Just bricking Blackphones is a terrible move; letting the users know their phones were counterfeit and leaving them on would have been a far better move, IMHO]
This seems really scummy and would drive me away from their products forever.
I know people click through warnings. If that warning could keep them alive, as a dev I'd better do something that'll get their attention.
Also, if they only softly bricked these phones the counterfeiters would just click-through the warnings and sell the phones that way. They have to essentially burn them, for the safety of people who need to be their customers.
If you want a regular phone running whatsapp, use that.
If you didn't want that, there were cheaper phones - even counterfeit.
If I were to buy a Blackphone, I would do it because I wanted security, and because I trusted the manufacturer to provide it. The problem with security is that just because my phone appears to be "working perfectly" doesn't mean that somebody isn't eavesdropping on everything I say.
A counterfeit Blackphone, in other words, is completely defective and untrustworthy, no matter how well it appears to work, because my trust in the manufacturer is broken.
I don't exactly see how it bumps up the profit though. You have a bunch of obviously interested customers, who want your product, and then the company has come out with "Actually, we expect you to buy the phone twice, because of a mistake that may or may not of been your fault"
Remember the hassle WhatsApp got for failing open?
The Blackphone+SilentOS is an actual crypto device for people who believe they need crypto. It needs to fail closed. This may cost some people $100, but save their lives.
This also gives the customers the ability to sue the sellers, or at least push for refunds via the sales platforms.
If the user is informed they have a non genuine device that is not safe or secure (e.g. like Windows' nag notification), then they can't expect it to work like a secure device, but more like an ordinary phone.
Then both normal consumers (who will continue to use the phone since they didn't really care too much in the first place about safety) and security conscious consumers (who will re-buy asap) would be more inclined to use the same brand in the future
If my smoke/heat/etc detector starts to fails I don't want it silently dropping back to a smoke-only detector. I want it to start beeping loudly and refuse to stop.
> If the user is informed they have a non genuine device that is not safe or secure
Having to flash a new OS onto it is an appropriately sized clickthrough for a warning of that magnitude. Like being woken in the night to change a smoke-detector battery.
Or something like a Moto G?
Also - they're protecting their own image here - can you image the PR s*itstorm that would unfold if somebody bought a counterfeit Blackphone, got hacked or had their details siphoned off to China, then wrote a blogpost about it? We on HN are often quite quick to judge - so I can certainly see why Silent Circle are taking the careful approach here.
Plus extra points for following through by not actually ever remotely bricking the phones before the anticipated useful lifetime of the real thing. Nagging may or may not be very bearable depending on consumer goodwill.
A closer analogy - and still not exactly, since the owner would still have actually lost the car - would be if the police came and burned it down just so that you couldn't use it.
They're enforcing their copyright. Why not? The police can also confiscate computers with pirated software on them. They even do that sometimes. It doesn't return the money to the IP owners but it's still a way to deter theft.
It sounds like a good idea to me. Even if it doesn't recover their lost sales, it should prevent future black market copies since customers will know to avoid unofficial sellers.
It'd be like if you bought a brand new car from a dealership, then two weeks later the police came to your house, told you it was stolen and burnt it down.
Why should a vendor be able to stop you from using a thing you bought because it looks like one of theirs? No support, sure. Disavow the item, sure. Post warnings on the device as an inbuilt part of the system, sure. But destroy your item? No.
If someone is fraudulently selling cars badged as Fords, Ford itself should not be able to repossess those vehicles. And if Ford thinks that you have stolen their car, they themselves should still not be the ones who repossess it - that's what the police are for. Vigilantism is a bad thing and has all kinds of unexpected failure modes.
Actually, there's a very analogous thing for cars - LoJack. Is that wrong too?
It happens with copy protection on software. I've heard of games that become impossible to win if they detect they're pirated. Others that just fail entirely. Is that not OK either?
It wouldn't be OK if the developers intentionally affected copies that most users would explicitly believe were not counterfeit (for example, if all Steam copies did this because the game developer had an exclusive agreement with EA/Origin).
The users of the counterfeit phones had no way of knowing they were counterfeit. They were advertised as brand new and came in a shrinkwrapped box.
Crypto devices should brick themselves if they discover they've been tampered with.
It's a clear case of seller fraud and if you use a good marketplace (ie not the one starting with E) you can get a refund through the platform. And maybe get information to use in suing the seller.
So if I scramble the firmware on your phone and brick it, you don't consider that damaged?
> LoJack
... works in tandem with police, hardly 'very analagous'.
> It happens with copy protection on software.
The user should have been warned that applying the update would brick the detected non-original phone. It shouldn't have just silently fucked the user over. It's bad ethics and also bad PR. Fucking over a user acting in good faith is poor form ethically.
Sounds like two critical flaws to me.
> In conclusion: the firm has no control over its supply chain and embeds remote control into its devices.
Dirty secret: Nobody has control of their supply chain anymore.
There have been Samsung and Apple phones being sold on the black market before the real ones.
If you assemble in China, you can be cloned tomorrow.
They build a secure phone. It gets ripped off by the manufacturer and resold by anonymous eBay people who can install whatever backdoors on the phone. Then the people using them are being snooped on - exactly what they don't want in the first place.
Bricking the phones is the right thing to do.
(It's also not Silent Circle's fault if the counterfeit devices were sold with a locked bootloader, precluding the installation of another Android distro.)
If someone was selling laptops with a pirated copy of Windows on it and a Windows update recognized the unlicensed install, causing the laptop to be non-functional, would that be any different?
Remember, the maker of these dodgy laptops has locked the bios so that you can't reinstall a genuine operating system...
To complete your laptop analogy, this "new" laptop from Best Buy turned out to be goods ripped off the assembly line at the Dell factory before the unit had its Windows OEM license assigned or paid for. The software is unlicensed and therefore not genuine. It is not for Microsoft to offer sympathy and a blind eye, they are well within their rights to identify counterfeit installations of Windows and disable them. The remedy is for Best Buy to offer the customer a full refund.
Silent Circle doesn't owe these consumers anything and are well within their rights to have all of their software completely self-destruct. They don't owe these consumers a robust mechanism to install an AOSP distro. They don't owe these consumers a bootable device. They don't owe these consumers a discount on a genuine device.
The only correct resolution is for the scam victims to receive a refund from the seller.
I could see stopping service on those apps, but bricking the baseband is a step too far, as you lose 911 access and Silent Circle almost certainly had no part in the baseband firmware development and is not a rightsholder to it.
I should also point out the claim that the baseband was intentionally bricked is unsubstantiated. We don't know if that's actually happening. Or if it's happening, we don't know if it's intentional.
The percentage of proprietary software on the phone — be it five percent or fifty — is orthogonal to the point.
This type of attack is just a test case that any truly secure device has to defend against. I'm not advocating a specific mechanism of avoiding this behavior, because there's obviously work to be done here to come up with a better mechanism than "every user audits every line of source before installing". It's just that this design work has to be done - "security" based on trusting a company is easy, and doesn't differ appreciably from what say Apple already provides.
^ with the debatable exception of software distributed in source code form in a language you're able to audit and compile yourself, though you'd still be vulnerable to cleverly concealed exploits
So, I don't think it is accurate to say that it 'allows remote control by its masters,' as it appears that they just added some sort of check in the latest version of their OS that can tell if the hardware is legit. There isn't any evidence, at least not in the article, that indicates they have some sort of remote control/phone home service running on the phone that allows them to control it arbitrarily.
From the screenshot, it's not entirely clear to me that the baseband is actually bricked. The updated OS refusing to run on some phones isn't the same as damaging the phone.
Even if there were an alternative OS, I'd say it's still pretty well bricked, since installing alternative OSes is outside the skill level and/or comfort zone of most consumers.
I mean, I recall discussions of whether something was really bricked if you could rescue it by hooking up to a JTAG header.
Practically every device i've ran into that has been bricked has been put into that state via software. It may be impossible to fix such state without a JTAG bus and code from the manufacturer, or by desoldering chips, but I can't remember recently when something bricked was truly destroyed and every recovery method was rendered impossible.
(bearing in mind I wouldn't consider something like a ran-over laptop to be 'bricked', but rather just destroyed)
I'm sure some folks use the term when they are referring to destroyed equipment (a 'bricked' gpu from overheating) but I haven't really encountered it personally.
That's the point of the GPL. If the users took care of only buying products including only GPL'ed software, then they would have the freedoms: 1- to use the software, 2- to copy it for their friends, 3- to get the source to audit it and modify it (so they would be free to remove any backdoor that wouldn't exist in the first place for this very reason), 4- to compile the source to binaries and use them to replace the provided binaries (so their may increase their level of trust of the software they run on their hardware).
Do not buy products that come with freedom-restricted software!
Whenever I get an update on iOS you get the lovely huge Apple T&Cs, which you have to accept to install the update.
So if SilentCircle does the equivalent and put in there "in the event that this is running on a non-approved device, we'll disable the software" then I click "I agree" it would seem fair enough for them to so.
If I were them I think playing it a little cooler would've been to pop-up "Hey this is a knock-off device, we're not letting you use all the cloud service and you're getting no updates from us" and leave it at that...
There is Replicant ( http://www.replicant.us/ ), a version of Android that aims to get rid of all binary blobs. There is also CopperheadOS ( https://copperhead.co/android/ ).
Related reading: https://blog.torproject.org/blog/mission-improbable-hardenin...
Shameless plug: we sell preinstalled Replicant phones at https://tehnoetic.com/
Even if such an audit was done perfectly (a very serious and difficult undertaking), it would be a point in time assessment, so would become less relevant as new code was committed.
Basically you have to trust some group of people to run a modern computing device/environment, it's just a question of who and how much...
The advantage of FOSS is that the set of who can audit the code is open. It starts small, but grows with popularity and remains agile - eg doesn't necessitate transitively trusting whatever nation-states a single company is vulnerable to.
To take one example with a propietary solution with code from a single company, it is possible for a level of background checking to be done on all contributors. With a FOSS solution, that's just not possible, so you get risks like what if one of the contributors is being paid by a nation state who would like to place a specific bug/vulnerability into a codebase.
Of course in practice the world is much muddier than that as pretty much all propietary software vendors make ample use of code they did not write, and in many cases on open source code that they don't really controle the provenance of.
Personally I'd say the idea of having a high level of trust in any larg'ish software stack is very dubious these days given the likely incentives of various groups to compromise them.
The first systems that were trustworthy were done by proprietary companies with independent evaluation of the product, signatures on source/binaries, and/or optional generation from source on-site. This became standard practice in security- and safety-critical development. You can scale it to as many people available for review often under NDA for the source itself but not signatures or binaries.
A company can do things that are similar to Free software (eg allow customers to build from source), but in the context of modern discussion I'd say that's just taking on aspects of Free software.
"Proprietary software starts off with a high level of trust - trusting just one company. But it can never progress past this."
It's totally false. The evaluation side has been done more times than I can count. It doesn't even have to start with a single source. Many products started as a collaboration of multiple organizations checking each others work that share the result. Another model is CompSci inventing something with details open at the start, patented, and then turned into closed source product. Finally, there's Shared Source models where you can have, fix, or extend the source so long as you're paying. Burroughs B5000 (1961), first system resilient to 0-days, was distributed in source form to customers.
You were oversimplifying proprietary systems then attacking that simplification.
I'd love to find a commercial model that could work for consumer-oriented Free software [0], and I think it could sound quite similar to something you describe. It's just that those type of multi-party collaborations have been pulled into the attractor of free-as-in-beer, at least as far as the code itself is concerned.
[0] I say Free instead of Open, because I can envision software lacking just FSF freedoms 1b and 3 could get stuck in a bad state as well. Like say everyone knows there is a bug and how to fix it, but is legally prevented from doing so.
You were. You made a blanket statement about the whole, proprietary model. In recent comments, you've changed your statement to talk about how the model is applied in the general case. As in, popular implementations vs all implementations. I'll reply to the new comment anyway.
"For example, something like a mass-NDA for every user is going to fail for consumer-oriented software, whereas a company contracting a discrete number of external auditing decomposes into trust through branding."
That's basically what happened. It could go further where lots of users get the NDA with cross-checks but not mass on high-volume scale. It helps if the software is designed in such a way where it can be shown it doesn't manipulate the system. I once proposed memory safety, safe API use, and sandboxing as a start on that. Automated tools could assess those. One could go further with information-flow labels tracking confidentiality or integrity enforced by compiler, runtime, or hardware. A few CompSci projects do it but not mainstream.
"I'd love to find a commercial model that could work for consumer-oriented Free software"
They pay for it. Then they get it. The source is in a FTP server or something somewhere. Things like branding, enterprise features, and tie-ins keep them buying from original supplier. Been done in a few ways although always a risk of clones.
"[0] I say Free instead of Open, because I can envision software lacking just FSF freedoms 1b and 3 could get stuck in a bad state as well. Like say everyone knows there is a bug and how to fix it, but is legally prevented from doing s"
Dual-licensed (proprietary + GPL) covers this. A few, quick proposals follow on non-free trying to approximate free. One could do a shared-source license that allows bug fixes. One could allow redistribution of software to other paying customers. One could cap what's to be paid or for how long before what's purchased becomes perpetual. One can make it go FOSS if it's EOL'd or gets under certain amount of developer time/contributions (tricky measure). Recent proposal was time limit on how long a version or individual product would be paid with it going FOSS after that time limit.
So, quite a few options here. One thing that's important to remember is that FOSS will always have a disadvantage over benign, paid model. The disadvantage is you can contractually ensure those being paid are doing support, bug-fixes, enhancements, pen testing, etc. They can also cover the pro's to do it right. They have lawyer money for patent trolling that will come their way. Combined with shared source like above, they might also get most or all benefits of FOSS with benefits of paid. It's why I'm highly interested to see companies experiment with hybrid models. A few have showed up here but nowhere near enough.
Windows NT
OpenBSD
At least, this is the market I perceive the Blackphone to be addressing.
In my book, a remote kill switch is OK if you can also trigger it. For privacy, DOS is pretty harmless -- you don't lose privacy, you just lose access to some data/service. If, in exchange of a risk of DOS, I can get better privacy some other way, I'll take it. As for SC fighting counterfeiters, I don't blame them. They're not making much $$ these days, and this is a way to keep alive without hurting their actual customers.
The genuine phones sell for 662€ with a one-year subscription.
What's fair to say is that you're implicitly trusting Silent Circle to be both competent and benign. But then running pretty much any modern computing device requires you to trust various groups of people in that regard, so this isn't that different really.
The only alternative would be coding the thing 100% yourself.
The only question is of who you choose to trust and how informed your decision is.
Oh well, more reason to never consider purchase of one of their devices. Shame because they actually are doing some decent software development.
The factory they contracted to assemble their phones is running extra shifts off the books and selling the extra phones for extra cash on the side. This happens all the time in China.
http://www.legislation.gov.uk/ukpga/2002/31/section/1
I'm a bit surprised that isn't the case in the US.
This also affects Bluetooth and WiFi MAC addresses, even of laptop computers (!), if going by the letter of the law. Trivially changed by userspace tools, and IIRC Apple randomizes the MAC addresses to prevent people tracking other people's devices.
Edit: It gets even worse, in theory anyone distributing software capable of changing MACs or writing tutorials on how to do this commits an offence. Just look at http://www.legislation.gov.uk/ukpga/2002/31/section/2, it's madness.
Thank you for the laughs!