back
user profile
ashitlerferad
12,192karma·2,558submissions·September 13, 2015
recent activity (2,558 total)
comment
https://news.ycombinator.com/item?id=11439568
comment
re Debian: your best bet is one of the chroot on Android apps. With some more skills you can get closer to just Debian on a phone that shipped with Android. Unfortunately with the way mobile devices a…
comment
What about getting someone's key? What about distributing your key? What about backing up your secret keys on paper? What about binding your primary secure key that is usually stored in a safe on…
comment
Expiring and revoking keys is a core part of how OpenPGP is meant to work. Export just the valid self-sigs: --export-options parameters
export-minimal
Export the smallest key possible.…
comment
What about signing and verification?
comment
moxie's stuff is, but it is designed for the always-online mobile world: https://whispersystems.org/
comment
I thought the GP comment was talking about reviewing the code changes rather than verifying the hash chain.
comment
Also, please don't display keyids, always fingerprints: https://help.riseup.net/en/security/message-security/openpgp... …
comment
Can you implement OpenPGP-signed pushes?
comment
Hmm, actually it isn't as good as I thought. I guess I was remembering IRC discussions. IIRC, the Replicant folks found Qualcomm based devices pretty commonly have this issue.
comment
The Replicant wiki is a good place for devices that have evaluated, click the links on here: https://redmine.replicant.us/projects/replicant/wiki/Replica... …
comment
Another response to this issue: https://mjg59.dreamwidth.org/41085.html
comment
https://twitter.com/mathewi/status/716771686482202625
comment
Don't forget turning on both of the cameras and streaming the video to 911.
comment
What about capacitors?
comment
Could this apply to software like iOS as well?
comment
serial attached basebands are much rarer than basebands with full or partial control of the CPU or RAM.
comment
In practice, TrustZone is for DRM.
comment
Security issues in ROM are still security issues. Even if it is in ROM, it still needs to be auditable.