Remix.run Logo
Flagship mobile phone with hardware kill switches for privacy(news.itsfoss.com)
33 points by ForHackernews 7 hours ago | 31 comments
fcpk 6 hours ago | parent | next [-]

Wonderful except that soon that phone won't work for anything official in europe because it won't pass play integrity attestation that brussels wants to be the only gateway to certification of devices.

matheusmoreira 6 hours ago | parent | next [-]

Yeah. Remote attestation, "certification" of devices in general, should be illegal. Anything short of that and computer freedom is lost, everything the word "hacker" stands for will be destroyed.

pogue 3 hours ago | parent | prev | next [-]

Is it possible to spoof/emulate play pass integrity somehow?

ulrikrasmussen 2 hours ago | parent [-]

No, not strong integrity, since that depends on hardware secure modules which attest that the software on the phone is signed by Google.

M95D 6 hours ago | parent | prev [-]

Is it so difficult to have a separate phone for gov & bank apps only?

zb3 6 hours ago | parent | next [-]

We can't let Google get away with bundling their spyware in the name of security into a phone we must now have..

It's NOT ok that a government app (often practically mandatory) requires the user to accept some invasive ToS of a foreign corporation maintaining an illegal monopoly.

Requiring attestation doesn't mean Google spyware should be unremovable without breaking it, Google's business model should not be mandated by the law.

izacus 4 hours ago | parent | next [-]

So is there anyone else out there attesting device firmware and ensuring they're secure?

charcircuit 5 hours ago | parent | prev [-]

It's not a law to only trust Google's attestations.

lomase 6 hours ago | parent | prev | next [-]

Difficult? Not at all, but it annoying at least.

like_any_other 6 hours ago | parent | prev | next [-]

The problem is not that it's difficult, the problem is that it makes phones that are not locked against their users commercially dead - a money losing venture for any manufacturer. Because most people simply won't bother with two phones.

rolph 5 hours ago | parent [-]

but what if,the two phones could be packed into one?

it would be a little thicker, you would need 2 of some components.

switch between phones like switching workspace?

netsharc 3 hours ago | parent [-]

Ha, a phone with a KVM (1) although without the K or M: https://en.wikipedia.org/wiki/KVM_switch

Or this 90's hardware oddity that combined Mac and PC: https://www.youtube.com/watch?v=a6b4lYOI0GQ (skip to 8:00 to see it in action).

I wonder if dual-booting is possible, with the boot-loader loading the bootloader that's been "blessed" by Google's certification priests to boot the "certified virginal" phone.

xboxnolifes 5 hours ago | parent | prev [-]

yes

euroderf 6 hours ago | parent | prev | next [-]

> One is a hardware switch that cuts circuit power to the cameras and microphones

How great might be the threat of using its speakers as microphones ?

Anonbrit 5 hours ago | parent [-]

That would practically certainly require electrical changes, at which point all bets are off anyway

Imustaskforhelp 5 hours ago | parent [-]

Can you please elaborate as maybe I couldn't understand what you were trying to convey.

Thanks in advance!

taneliv 6 hours ago | parent | prev | next [-]

Hey, I learned something. I knew of Fairphone, but I didn't know they had kill switches. The device might be out of my budget, but it seems promising.

joecool1029 5 hours ago | parent | prev | next [-]

The mediatek dimensity means it's sure to barely work on US carriers. They're not written band support anywhere on their 'detailed specs'

craftkiller 3 hours ago | parent | prev | next [-]

nit: Title inaccurate. There is a single hardware kill switch, not plural. Separately, there is also a software kill switch.

kogasa240p 6 hours ago | parent | prev | next [-]

Is there a headphone jack?

pogue 3 hours ago | parent [-]

Bring back headphone jacks & SD card slots!

zb3 6 hours ago | parent | prev | next [-]

If GrapheneOS won't plan on supporting that it means it's not as secure as advertised.

NooneAtAll3 5 hours ago | parent | next [-]

GrapheneOS devs state requirements based on Pixels, not choose Pixels based on requirements

so I won't trust judgement based on that

anonym29 13 minutes ago | parent | next [-]

GrapheneOS publishes a list of the requirements: https://grapheneos.org/faq#future-devices

GrapheneOS devs have announced "We're currently working with a major OEM towards future generations of their devices meeting our requirements and providing official GrapheneOS support. GrapheneOS on both Pixels and these future non-Pixels will be fine." (https://grapheneos.social/@GrapheneOS/115102564799343519)

You're welcome to assert otherwise, of course, but your assertions are contradictory with direct statements from the GrapheneOS team.

lawn 4 hours ago | parent | prev [-]

Not at all and ignorant of you to think so.

joemazerino 6 hours ago | parent | prev [-]

No, it means the phone isn't suitable for security maximalists. GrapheneOS doesn't support any hardware except the Pixels.

Bender 6 hours ago | parent [-]

And that's even assuming one cares about the secure enclave. I am not convinced that any phones exist that one can not unlock the enclave via JTAG debugging.

SoftTalker 5 hours ago | parent [-]

For most devices, if you have that kind of physical access, and enough technical resources, all bets are off. Most people's threat model doesn't include three-letter-agencies reading their secure enclave. If yours does, you're probably better off not carrying a phone at all.

bumseltagbaerbi 6 hours ago | parent | prev | next [-]

Blala, 1k electronics shit that won't potentially do calls reliably or BT with cars etc.

yjftsjthsd-h 2 hours ago | parent [-]

> shit that won't potentially do calls reliably or BT with cars etc.

Based on what? If it's not yet available, how would you be able to tell how well it does calls or BT-pairs with cars?

OutOfHere 4 hours ago | parent | prev [-]

It's a run-of-the-mill pre-sale scam. Post when it's actually available for sale.