Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

Already on GitHub? Sign in to your account

Update mobile environment score #669

Closed
wants to merge 1 commit into
from

Conversation

Projects
None yet
2 participants
Contributor

saivann commented Dec 6, 2014

As suggested in #644, mobile platforms are not perfectly secure platform.

This pull request renames "Secure environment" to "Passable environment" for mobiles to avoid making too broad promises and to incentivize user to read the new text that contains a few advices.

Hardware wallet score is renamed from "Very secure environment" to "Secure environment"

capture du 2014-12-05 15 11 29

Contributor

schildbach commented Dec 6, 2014

What value does this commit actually add? To me it sounds like a general devaluation of the security of Bitcoin. Do we already have wallets/devices on the horizon who deserve the then vacant "very secure" level? Based on the number of incidents I'd say Android is still a secure environment.

Also: the string "passable environment" is missing what the score is actually about. I think it should read "Security: Passable environment" or maybe "Moderately/fairly secure".

The explaination of passable environment is missing why its actually just passable. The negative point about mobiles being stolen or lost applies to current "secure wallets" (previously "very secure") too. User backups are important for any level of security (except perhaps web wallets).

Contributor

saivann commented Dec 6, 2014

@schildbach Do you have any knowledge of any sizeable malware problems on outdated Android OS out there? Is there a lot (or any) security flaws that let apps get around app isolation? If there's no measurable issue on this side, I think I'd go with keeping what we already have.

I do have concerns over the systemic risk that represents automatic updates, but again, it's a double-edged sword and I could not find a way to express that that I felt would not only be confusing.

Contributor

schildbach commented Dec 7, 2014

I'm far from being a malware expert. My understanding is that if you can gain root on your device just by downloading an APK and clicking a button your app private data is at risk. (Rooting via unlocking the bootloader doesn't count.)

One popular rooting app is framaroot. A device compatibility list is here. If your device is on that this, I would not use it, at least not for Bitcoin.

Android AOSP has made it progressively harder to break out of the sandbox.

I guess with Android it's like with any OS: You need to stay up to date. Unfortunately this currently means clever buying decisions (Nexus, "Google Play editions" and recent Motorola devices have a good reputation for not messing up with AOSP and for timely OS updates) and willingness to buy a new phone once your old is EOLed.

Contributor

saivann commented Dec 15, 2014

I'm closing this pull request as I also couldn't find any strong indication of malware issues, and these changes appear to be hardly any better than what we have now.

@saivann saivann closed this Dec 15, 2014

@saivann saivann deleted the mobilescore branch Dec 17, 2014

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment