Hacker News new | ask | show | jobs
by 1vuio0pswjnm7 15 days ago
"Phones have great potential to be the most private and secure computers."

How would that be achieved

We could assume that a user could make their own computer "private and secure"

But if a third party, e.g., Apple, Inc., Google, LLC, GrapheneOS Foundation, etc., has RCE, e.g., "auto-updates", then how can the computer be "private and secure" against that third party and any party that they "work with", voluntarily or not, e.g., a business partner, a government, but also others that might target these third parties, such as an attacker who isn't interested in their bug bounty programs, etc.

To achieve "private and secure", would the user need to remove the RCE capability of the third party (parties)

What about data collection and surveillance by the third party (the user would have to review the source code and compile the OS themselves to be sure about data collection and surveillance)

If there is data collection and surveillance, then how could the user be sure that the data collected and surveillance capability held by the third party is "private and secure" from that third party (e.g., Apple, Google, etc.), any third parties that work with them, and others who might target these third parties

Assuming the user even knows the identities of all these third parties, what if their operations are secretive and non-transparent

What if they have a history of dishonesty

What if they make no promises to the user that could be enforced and instead they just assume "trust"

Perhaps each user might have a different concept of "private and secure"

1 comments