RE: MokSec - The Security Framework

Previous message: [thread] [date] [author]
Next message: [thread] [date] [author]
To: List for Openmoko community discussion <community@...>
Date: Tuesday, August 19, 2008 - 2:58 pm

Apologies for the tardiness of this post.

On Mon, 2008-07-14 at 10:57 -0400, Crane, Matthew wrote:

You're forgetting a large attack vector: social engineering. It doesn't
require someone being able to maliciously install something for it to
get on your system, especially once Moko repositories start to flourish
and organizations setup their own for specific apps/purposes.

Additionally, having used several mobile phones (Smart and otherwise)
often it is helpful to be able to decide what abilities a piece of
downloaded software will have (e.g. a game doesn't need to look at my
address book).

You're also assuming that it's a "secure device" and that the owner will
know how to keep it that way. From experience, I can tell you that as
soon as non-geeks get a hold of this phone (Presumably sometime this
fall) device security will go out the window.

> I've been picturing running an encrypted rootfs image off an SD card.

Not a bad idea. I had to do something similar with my Zaurus 5500
several years ago because 14M of storage is not enough. However with the
FreeRunner, I do actually want to keep my rootfs on the rootfs and use
the card(s) for different data sets.

> Once the system boots it's up to the user to unlock the keys to the

Then what happens if you leave the system in sleep mode and accidentally
leave it somewhere and it "wanders off"? You've unlocked the rootfs
already, so as long as the attacker doesn't reboot the phone, they've
got access.

-KW

_______________________________________________
Openmoko community mailing list
community@lists.openmoko.org
http://lists.openmoko.org/mailman/listinfo/community

Previous message: [thread] [date] [author]
Next message: [thread] [date] [author]

Messages in current thread:
MokSec - The Security Framework, Yorick Moko, (Sun Jul 13, 8:07 am)
Re: MokSec - The Security Framework, Kalle Happonen, (Mon Jul 14, 3:20 am)
Re: MokSec - The Security Framework, Jay Vaughan, (Mon Jul 14, 10:16 am)
Re: MokSec - The Security Framework, thomasg, (Mon Jul 14, 4:03 am)
Re: MokSec - The Security Framework, Kalle Happonen, (Mon Jul 14, 9:35 am)
Re: MokSec - The Security Framework, thomasg, (Mon Jul 14, 11:16 am)
Re: MokSec - The Security Framework, Kalle Happonen, (Mon Jul 14, 12:19 pm)
Re: MokSec - The Security Framework, Tilman Baumann, (Mon Jul 14, 10:38 am)
Re: MokSec - The Security Framework, arne anka, (Mon Jul 14, 11:08 am)
Re: MokSec - The Security Framework, thomasg, (Mon Jul 14, 11:19 am)
Re: MokSec - The Security Framework, arne anka, (Mon Jul 14, 11:22 am)
Re: MokSec - The Security Framework, thomasg, (Mon Jul 14, 11:27 am)
Re: MokSec - The Security Framework, Kalle Happonen, (Mon Jul 14, 12:13 pm)
Re: MokSec - The Security Framework, thomasg, (Mon Jul 14, 12:18 pm)
RE: MokSec - The Security Framework, Crane, Matthew, (Mon Jul 14, 12:46 pm)
RE: MokSec - The Security Framework, Crane, Matthew, (Mon Jul 14, 10:57 am)
RE: MokSec - The Security Framework, Knight Walker, (Tue Aug 19, 2:58 pm)
Re: MokSec - The Security Framework, Robert Schuster, (Sun Jul 13, 9:00 am)
Re: MokSec - The Security Framework, Bumbl, (Sun Jul 13, 8:38 am)