Hacker Newsnew | past | comments | ask | show | jobs | submit | drnick1's commentslogin

> Just allow monero payments or something.

This is the right solution. A one-time payment in crypto, say $5, ought to be enough to prevent spam. That being said, Signal has demonstrated (when presented a warrant) that they do not store phone numbers. If I remember correctly all they stored was an account ID and a UNIX timestamp such as the last login.


> If I remember correctly all they stored was an account ID and a UNIX timestamp such as the last login.

How do they perform address book matching without an phone number? It just being accessible by SGX does not really count as not storing it.

Problem with phone numbers is they are to short to store as a hash, since you can brute force the sha256 of an phone number in a trivial amount of time on a single consumer device


Wouldn't a payment of about $0.05 do the trick? My understanding of most kinds of spam is that it relies on being able to deploy hundreds of thousands of bot accounts just to get a few hits.

This is for registering an account that can then send many many messages.

> turn off remote access services, dig through the infotainment to turn off what I could

This is never enough. You can't trust a software switch. You need to remove the hardware capability if you want to make sure the car isn't spying on you. In the best case, the telematics box has it's own fuse, and that may be enough. In other cases, you need to find the box and unplug it. The service manual will have it's location. In some cars it's easily accessible, in others less so and you need to remove the glove box or part of the dash. Dealers will probably refuse to do it, my advice would be to DIY or find an independent mechanic who will do it.


Find the telematic's antenna, and put a 50ohm resistor across it. It can scream into it's own private void.

It seems like this is not enough:

https://www.tacomaworld.com/threads/simpler-solution-for-dis...

The most reliable way to permanently silence the cellular modem is to pull the relevant fuse. In the above case, this also disables the microphone, which I think is a positive. Unplugging the DCM entirely, however, seems to disable to right speaker, which is wired through the DCM for some reason.


>right speaker, which is wired through the DCM for some reason

This is to provide cell phone audio during calls – if you're already inside your dashboard to remove the DCM (modem), there is an easy pin-out to restore the right speaker's music audio (which varies across Toyota models, but usually is as simple as placing a jumper across two pins of the unplugged wiring harness.


>Unplugging the DCM entirely, however, seems to disable to right speaker, which is wired through the DCM for some reason.

I'm cynical, but unnecessarily coupling the ability to send telemetry with some feature people definitely want seems like exactly the sort of thing that would be done intentionally.


Would be darkly hilarious if they were using the speaker or rear defroster as a cellular antenna.

(Yeah, technically horrible but I’m sure someone will find a way)


Funny enough i was just recently thinking about how most defrosters would probably make a great antenna with minor modifications


They get off the frequency when heated, might not pass FCC testing.

I Have No Antenna, and I Must Transmit.

I am stealing this for the name of my first album.


> You can do stuff like like turn it on to heat or cool the cabin, live track it's location, lock/unlock doors, open/close trunk, and updates are mostly for the infotainment systemn and driving assists.

Are any of those things more important than your security (e.g., against hackers) and privacy?


If you want true, verifiable privacy and control, it's not an Apple TV that you need. Any old laptop or desktop computer can be used to stream content from the Internet using a Web browser or other "apps."

E.g. Netflix doesn't let you to stream 4k video in browser afaik. So no, it's not a good option.

Desktop OS also don't support Dolby Vision or fancy spatial audio formats.

Trifecta: Piracy + Local media server + Streaming device, either Apple TV/Android TV (without internet access).

No loss of quality, devices that could spy on you, don't, and those that would spy on you, can't. The only trade-off is some convenience.


> I think it depends on the device. If I buy an iPhone, I have the expectation of installing apps on it after purchase, and that necessarily involves a relationship with the app store provider (ie. Apple)

I bought my Pixel from Google and don't want any relationship with Google whatsover. In fact, I wiped the stock OS and installed Graphene for this reason. My apps come from various sources, none of which is Google.


> But what scares me is when every device comes with their own esim and cellular radio.

Cars already do, and the solution is well-known: find the bug, and squash it. Yes, your car will still work, and you cannot be denied warranty because of this. The cellular modem is more or less accessible depending on the make and model.


Then they'll lobby for the eSIM to become a legally mandated component and outlaw use of a product without one. And lawmakers will be happy to oblige as long as they get to use the eSIM for their own purposes.

Linux generally presumes that you run trusted software, not some proprietary program that is approximately malware. If you want a "sandbox" run that program as a separate unprivileged user or use bubblewrap.

> Linux generally presumes that you run trusted software, not some proprietary program that is approximately malware.

But this statement basically says: "Linux has no good permission controls for running software". The assumption is flawed. Trusting software is not a true/false thing.

Yes, you can use sandboxing tools, but how many people use them properly? How many usability bugs do they still have?


Unix systems were initially designed to be multi-user systems (as in multiple meatbags accessing a mainframe across terminals), in an era before it was common to indiscriminately download and run applications from the internet. Files required explicit opt-in to become executable. There were always attempts at mischief, but it was deemed sufficient to separate user account from each other and denying direct access to the hardware so an account compromise wouldn't escalate to the rest of the system.

Because of this heritage Android uses user accounts instead of namespaces a.k.a. containers (a much newer and less mature concept) to isolate apps from each other.


If you have one of those TVs, disassemble it and unplug or remove the microphone, camera and the wireless adapter. Use it as a (rather nice) 4K monitor for a Linux box with Plasma in Bigscreen mode. Pair that with an airmouse remote and you get the most private and user-centric streaming/gaming platform that you can build. Put a decent GPU in the box, add an Xbox controller and Steam and you also built the world's best console.

Has someone qualified that removing the wireless hardware leaves the device functional?

This would be a nice public service for gamers nexus that happened to buy a lot of these devices. :P

I can say from experience in several devices (but not an LG TV) that removing dedicated bluetooth chipsets so far has left devices functional. ... but some things implement their bluetooth as part of the ESP32 that is the whole kit and kaboodle, so you can't remove it.

As to why someone would remove these components -- in addition to the explicit spying LG is doing, there are companies dragnet collecting BTLE device identifiers <> gps collecting, including collecting them via phone apps. This means that if you have any BTLE devices that are frequently with you or otherwise connected to your identity it may be possible for a threat actor to determine your location(s) from largely unregulated commercial databases.

I don't use BTLE at all, so this 'functionality' is a pure risk to me.


I know this isn't the solution you are looking for, but there is a fairly simple workaround and IMO it is superior: set up a Samba server or a Nextcloud instance, either at home or in the cloud, place it with behind a Wireguard tunnel, and don't store anything on the phone itself other than apps and things like maps for OsmAnd that can be redownloaded if lost. The Nextcloud app can automatically sync photos or other files too.

If my phone were lost, stolen or destroyed, I would simply revoke its Wireguard key, buy a new Pixel, flash Graphene, and provision a new Wireguard key. Essentially no data of value would be lost, and restoring my apps and settings manually would take an hour tops. Admittedly, I don't use many apps, so YMMV.


You're right, this is not a solution.

And I'm syncing some of the app data already, but that is not a replacement for the OS apps.

Most of the data cannot be synced like this.


> Most of the data cannot be synced like this.

Isn't it because of lack of the root access?


You could say that.

The lack of root is only significant because unlike in other vendors the built-in backup doesn't work reliably, and you can't use third party software.

But I'm very hopeful, recently they released this Messages update, they're working on introducing native RCS somehow (no idea how but I wish them well), and they recently made a first-class automated call recording.


To be honest the specs of the Fairphone are middling and the device is rather expensive for what you get. The Pixels are a much better value, especially with a series. If you want something truly high end, wait for the Motorola with official GOS support.

Isn't the whole idea behind Fairphone that they are more expensive because the parts are responsibly sourced? That they pay a fair price for labour and materials? And that the phones are highly repairable?

Why would that mean it could compete with a Pixel which generally has none of those goals?


There's nearly no information available on the working conditions, pay or environmental impact of Fairphones. T2Mobile is the company designing and making Fairphones since the Fairphone 4 and little information is available on them. Fairphone provides a long list of companies involved in the supply chain without more details than their location and website.

Pixels have long term availability of official parts for repairs and also official repairs.

Unlike Fairphones, Pixels have very good updates over the long term. Fairphones do not provide anything close to decent updates and it greatly degrades over the lifetime of the device. Fairphone 5 and earlier have an end-of-life kernel without security support. The devices start out lagging months behind on partial security backports and a year or more behind on full security updates which gets worse over time.


Without support of alternative OS Fairphone is basically a landfill. Why would anyone buy this apart from novelty factor.

Supporting an alternative OS wouldn’t change the fate of Fairphone, imo. Most people don’t care to move away from the stock version of Android that comes with their phone or iOS.

This isn't a hypothetical, Fairphone supports alternative OSes. Heck, you can even buy it with /e/OS in their store:

https://www.fairphone.com/the-fairphone-gen-6-plus-e-operati...


tbf that was just more so me insulting fairphone and kinda unnecessary from me

Can I flash my own?


I mean, aside from /e/OS as a first-party option, there are also official Lineage builds[1]. And they're at least a target for PostmarketOS[2], even if that wiki doesn't actually describe something daily-driveable yet.

[1] https://forum.fairphone.com/t/official-lineageos-23-for-the-...

[2] https://wiki.postmarketos.org/wiki/Fairphone_(Gen._6)_(fairp...


Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: