Slashdot Mirror


Apple, Google Diss the DoD Over Mobile Security

Julie188 writes "The Defense Information Systems Agency (DISA) has long supported the use of BlackBerry smartphones for soldiers. It built a system called Go Mobile to provide secure communications, training, and collaboration applications to mobile soldiers. DISA recently decided to add Android and iPhone to the list of approved devices because of high demand from users. Unfortunately, this choice has become a giant pain in the flank. Why? Because both Apple and Google refuse to give DISA access to their security APIs."

150 comments

  1. Unpatriotic? by fey000 · · Score: 4, Funny

    Queue the Palin. Might be time for Apple and Google to be hunted down like Al-Qaeda. Is there any room left in the Assange bunker?

    1. Re:Unpatriotic? by Myrimos · · Score: 2

      Queue the Palin.

      I saw this a few days ago. Is this a meme? Pedantically speaking, Palin is is a queue of one (at least!) wherever she is. Cue the responses. Might be time for Grammar Nazis and pendants to be hunted down like Apple and Google. Is there any room left in the Assange bunker?

      --
      Internet scofflaw
    2. Re:Unpatriotic? by Anonymous Coward · · Score: 1, Insightful

      It's not possible for big $$$ corporation to be unpatriotic.

    3. Re:Unpatriotic? by mr100percent · · Score: 1

      Well according to Senator Joe Lieberman, Amazon was being a "good corporate citizen" when it kicked WikiLeaks out of its cloud

    4. Re:Unpatriotic? by netsharc · · Score: 2, Informative

      It'll be convenient of Palin to forget that RIM is a Canadian company. Or are they the obedient little Labradors anyway (since the UK is the poodle).

      Also, Sergey Brin is Russian! Aaaaaa, he's a red commie!!!! But then again, Palin is neighbors with him, with she being able to see his childhood home front her front porch and what not.

      For my more serious contribution to this discussion, iPhone security is "trust that the app reviewer catches anything malicious that the developer is trying to do.". Android security is "You are going to install $APP. This app wants access to these features: [read/write SD card, see call status, read/write address book, read/send SMSes, use GPS location]. Do you want to allow all and install?", while BlackBerry security is, "This application wants these features. Choose which of them you want to allow, and which you want to deny."

      Or to be more detailed about it, for corporate BlackBerrys the admin can even do the allowing/denying, globally as well as individually for all apps, including denying the permission to the end-users to install all sorts of random apps.

      So which do you think offers more security?

      --
      What time is it/will be over there? Check with my iPhone app!
    5. Re:Unpatriotic? by Anonymous Coward · · Score: 0

      Palin is is a queue of one (at least!) wherever she is.

      Cue the responses. Might be time for Grammar Nazis and pendants to be hunted down like Apple and Google.

      Is is there a meme for the Nazi-grammar-pedants that screw up their own temper tantrums? Yes ... I see what I did there.

    6. Re:Unpatriotic? by Anonymous Coward · · Score: 1

      It's not possible for big $$$ corporation to be unpatriotic.

      Not true. A big $$$ corporation is unpatriotic if it refuses to invest enough money in purchasing lawmakers.

    7. Re:Unpatriotic? by Anonymous Coward · · Score: 0

      Palin must be doing something right.....she's pissing off all the Eurotrash wannabees.

    8. Re:Unpatriotic? by Anonymous Coward · · Score: 1

      So checkboxes == more security?

      Or more ways for there to be back doors...

    9. Re:Unpatriotic? by Anonymous Coward · · Score: 2, Insightful

      For my more serious contribution to this discussion...

      So which do you think offers more security?

      Oh dear.

      As well as the app review process the iPhone does prompt when an app wants to first use location services, notification, push services, etc. and then allows you to manage and subsequently revoke those permissions. The apps are also sandboxed.
      I am not in a position to comment on any of the Android flavours or BlackBerry security, so I won't.

    10. Re:Unpatriotic? by Anonymous Coward · · Score: 0

      who screw up his or her own temper tantrums

    11. Re:Unpatriotic? by Anonymous Coward · · Score: 0

      So which do you think offers more security?

      None? What does that have to do with security. More informative? Perhaps, but secure? Both users and reviewers are humans and prone to mistakes, I don't see your point.

    12. Re:Unpatriotic? by Anonymous Coward · · Score: 0

      The who is right, but "pedants" is plural, so it should be "their", not "his or her". Even though this will probably get modded off-topic, I just can't let a bad grammar correction like that go because other people might start believing it.

      A bigger problem, though, is that more than forty minutes after my last logged-in post, this *^&@!$ board still won't let me post anonymously without completely logging out first. They've cranked up the post timers to something like five minutes for logged in users and half an hour for anonymous posts. That's very uncool.

      It has gotten so bad that on more than one occasion, I've actually given up and not posted USEFUL posts because I just don't have that long to wait. These ridiculous new delays are a net loss for slashdot, not a win. Trolls are still trolls, but it's starting to have a negative impact on real users who are regular posters. And the thirty minute timer has basically made it so that those of us who want to occasionally express unpopular (but valuable) views can no longer do so unless we go find a separate machine with a separate IP to post from anonymously. The net effect of that is actual censorship, a stifling of the free flow of ideas and opinions that Slashdot is known for.

      Slashdot users' time is valuable. I'm rapidly approaching the point where I'm considering stopping posting on Slashdot simply because the penalty for participation has gotten too high, and I've been posting on Slashdot for over a decade. Taco and friends, TEAR DOWN THAT TIMER.

    13. Re:Unpatriotic? by Anonymous Coward · · Score: 0

      Palin is is a queue of one (at least!) wherever she is

      Being a bit pedantic here, but doesn't she have to be all there to count as one?

      Of course pregnancy would help. As would multiple personalities.

      - -
      Bringing out the vote in 2016! - Me, Myself, and I

    14. Re:Unpatriotic? by Anonymous Coward · · Score: 0

      Well the thing about the iPhone is that it's been shown to have bad/low security. Issues ranging from ease to add a malicious app to the market, to the iPhones security being easy to bypass, to even the fact that the iPhone's encryption is easy to crack.

      It does sadden me that with these problems that were easy to find on google were ignored when the DoD thought about allowing the iPhone to be an approved device (demand should have been one of the lowest factors in allowing it). While certain Android's might not be a good idea to allow, the whole concept of a custom ROM I feel would be a safe answer that would have been great middle ground.

    15. Re:Unpatriotic? by Anonymous Coward · · Score: 0

      Yeah it was...

      Apparently you are an idiot, but it's pretty much against their TOS and the law to host classified documents.

      Go figure?

    16. Re:Unpatriotic? by netsharc · · Score: 1

      How about reading the address book, calendar, or making internet connections?

      Oh, none of those? Hey, some guy in some country just got your contact list!

      --
      What time is it/will be over there? Check with my iPhone app!
    17. Re:Unpatriotic? by RockDoctor · · Score: 1

      Queue the Palin.

      I saw this a few days ago. Is this a meme? Pedantically speaking, Palin is is a queue of one (at least!) wherever she is. Cue the responses. Might be time for Grammar Nazis and pendants to be hunted down like Apple and Google. Is there any room left in the Assange bunker?

      Errr, "woosh". I think.

      Though why people are picking on the Cantab-educated globe-trotter as if he were a retarded backwoods fuckwit, I don't claim to understand.

      --
      Birds are not dinosaur descendants;birds are dinosaurs, for all useful meanings of "birds", "are" and "dinosaurs"
    18. Re:Unpatriotic? by Anonymous Coward · · Score: 0

      It's ironic that listening to Senators is unpatriotic in the U.S.

  2. Umm something is fishy by JonySuede · · Score: 4, Interesting

    Android is open source, how hard could it be to download the code and look into it to find those elusives security apis ?
    I have rolled custom firmware onto an android device using the instruction on some forums, and it worked great, if a dude with is budgies can do it, why can't they ?

    --
    Jehovah be praised, Oracle was not selected
    1. Re:Umm something is fishy by l0ungeb0y · · Score: 1

      As much as I am afraid to ask...
      WTF is a budgie? /please don't be a rule 34

    2. Re:Umm something is fishy by JonySuede · · Score: 3, Informative
      --
      Jehovah be praised, Oracle was not selected
    3. Re:Umm something is fishy by Anonymous Coward · · Score: 0

      As much as I am afraid to ask...
      WTF is a budgie? /please don't be a rule 34

      Aint it some bird?

    4. Re:Umm something is fishy by davester666 · · Score: 1

      And you can get one free if you visit Tex and Edna Boil's Organ Emporium.

      --
      Sleep your way to a whiter smile...date a dentist!
    5. Re:Umm something is fishy by perlchild · · Score: 1

      If they phone home, where they phone home doesn't have to be open source, next question.

    6. Re:Umm something is fishy by Anonymous Coward · · Score: 0

      I don't understand what you meant, you reply does not even attempt to answer the rhetorical questions that the parent asked and yet you seems to believe that you are in fact doing so.

    7. Re:Umm something is fishy by Anonymous Coward · · Score: 0

      Thats a funny joke

  3. Use the souce. by VortexCortex · · Score: 2, Insightful

    Want to access the "security" APIs? Use the Source.

    Why not just offer a custom DoD firmware for Android phones?

    Seriously, there's no way for an application to be "secure" if the platform the application runs on is itself untrusted.

    IMO, My device is not "secure" unless I can control the device's OS & inspect the device's hardware. My phone, my router, my PCs, my GPS, all have firmware I've compiled myself. If an average coder like myself can do this, the DoD shouldn't have any problems either.

    Note: Android works on iPhones too, it's still buggy, but the DoD could help with that if they desired, or just use phones that support custom, open source firmware.

    1. Re:Use the souce. by Anonymous Coward · · Score: 0

      This article smells of shenanigans.

    2. Re:Use the souce. by Myrimos · · Score: 1

      Note: Android works on iPhones too, it's still buggy, but the DoD could help with that if they desired.

      A smooth Android install on an iPhone? It seems like you've found something Apple would like even less than the DoD having access to the iPhone security stack.

      --
      Internet scofflaw
    3. Re:Use the souce. by mercury83 · · Score: 5, Interesting
      I know this is Slashdot and all, but still:

      IMO, My device is not "secure" unless I can control the device's OS & inspect the device's hardware. My phone, my router, my PCs, my GPS, all have firmware I've compiled myself.

      This doesn't make it secure. It just means that if someone's made a mistake, or inserted a backdoor, you've missed it. Control != Security -- sometimes it just creates a poor illusion of security. If you don't have control, you have to trust someone to provide security. Depending on who it is and what their experience is, I often prefer to trust.

      Regardless, one of the big issues that I've seen in this area is that although yes, you CAN jailbreak iPhone or install custom firmware on whatever device you want, you want the ability to deploy commercial-off-the-shelf stuff to users in the field with a 10 second install from the app store. They want to leverage the existing distribution network for the product and application distribution for software packages. They want to piggyback off the commercial world with minimal development effort and cost. What you're proposing a better model from a secure perspective, but is massively more expensive.

    4. Re:Use the souce. by aliquis · · Score: 1

      Why? Apples margins of the iPhone4 is probably huge.

    5. Re:Use the souce. by Myrimos · · Score: 1

      A different OS "duplicates functionality."

      --
      Internet scofflaw
    6. Re:Use the souce. by VortexCortex · · Score: 5, Informative

      I know this is Slashdot and all, but still:

      IMO, My device is not "secure" unless I can control the device's OS & inspect the device's hardware. My phone, my router, my PCs, my GPS, all have firmware I've compiled myself.

      This doesn't make it secure. It just means that if someone's made a mistake, or inserted a backdoor, you've missed it. Control != Security -- sometimes it just creates a poor illusion of security. If you don't have control, you have to trust someone to provide security.

      I write code. I read code. Yes someone can make a mistake, I can miss the mistake, but I can also fix said mistakes as soon as the mistake is discovered. You can't do that unless you can compile your own OS / Firmware. Faster Fixes == Less Vulnerability Window == More Secure. I'm not arguing that open source makes something secure, but using the source can give you more security than otherwise.

      If you argue that control != security, I will put it to you that the inability to Control = No Provable Security. Thus, Control = infinitely times more secure than uncontrollable. How secure is a device that can auto-update it's firmware without your consent?

      Depending on who it is and what their experience is, I often prefer to trust.

      Let us not forget that I am compiling the same sources that those you "often prefer to trust" are compiling; Except that I am also sure that no additional closed source code has been included in my build.

      Binary_Blob == !Trust;

    7. Re:Use the souce. by Anonymous Coward · · Score: 0

      My phone, my router, my PCs, my GPS, all have firmware I've compiled myself.

      But do you trust your compiler?

    8. Re:Use the souce. by Timmmm · · Score: 2, Insightful

      My phone, my router, my PCs, my GPS, all have firmware I've compiled myself.

      Who modded this insightful?

      Do you even have the source code for your GPS firmware, the baseband in your phone, your PC's BIOS and so on? No. Even if you did, are you seriously saying that you've perfectly audited hundreds of thousands of lines of code?

      Where's the "-1 this is really stupid" option?

    9. Re:Use the souce. by tapehands · · Score: 1

      Wait...are you advocating that the Government do something (semi)competent with their money?! Although, I guess it would just get contracted out to someone, and still run the chance of being insecure/buggy/overbudget/not on time...

      Regardless, a third party company rolling their own DoD-approved secure ROMs for common Android phones sounds like a pretty good business plan (though I'm not sure how the licensing would play out)...

      ....brb, off to become a patent troll.

    10. Re:Use the souce. by Anonymous Coward · · Score: 1

      It is not possible to prove security in a modern computer system for any plausible level of control.

      What if your compiler has a "backdoor" that introduces vulnerabilities when certain code is produced, and propogates it to new versions of the compiler? You going to write your own compiler in machine code?

      What if your processor intentionally misinterprets certain sequences in order to introduce a vulnerability?

    11. Re:Use the souce. by Anonymous Coward · · Score: 0

      This doesn't make it secure. This doesn't make it secure.

      That's not what he said. If the code is open, then it can still be insecure. But, if the code is proprietary, then it is ALWAYS insecure.

    12. Re:Use the souce. by Anonymous Coward · · Score: 3, Insightful

      Sometimes control isn't security, but lack of control is always insecurity. Any solution that results in security will necessarily require control.

      you want the ability to deploy commercial-off-the-shelf stuff to users in the field with a 10 second install from the app store.

      If you need security, then this simply isn't going to be one of your goals. Instead, you're going to want 10 second install from your repository, which consists solely of software that you have audited. As a compromise, it might be software that someone else that you trust has audited, but that'll be someone like Theo deRaadt or maybe (stretching a little, but there are degrees of security) the Debian team. But it sure as hell won't be Apple or Google, because while those parties might be competent, their goals are at cross purposes with yours.

      And it's those cross purposes that this story is really about. Apple doesn't have a "Security API"; they have a "Apple Security API" which is intended to protect Apple's interests, not the interests of the users or the owners.

    13. Re:Use the souce. by Anonymous Coward · · Score: 0

      From dealing with carriers at my day-to-day, it's been quite clear that if the DoD can do anything they can't deny, the phone makers would be in the doo-doo. TFA quoted the phone makers giving out the right approach, bring all those (nice, flag-carrying, American) carriers and threaten them, and fix the problem.

    14. Re:Use the souce. by Anonymous Coward · · Score: 0

      So you can read and write code but you can't fix anyone else's code? How does this work?

    15. Re:Use the souce. by VortexCortex · · Score: 0

      My phone, my router, my PCs, my GPS, all have firmware I've compiled myself.

      Who modded this insightful?

      Do you even have the source code for your GPS firmware, the baseband in your phone, your PC's BIOS and so on?

      ::Sigh:: Yes, yes I do. You may not, but I do. Modding your GPS hardware, your phone, etc may not be your thing, but you can get started with modding your PC's BIOS, and/or Router pretty easily.

      It also helps if you research the mod-ability of your device before purchasing them.

      Even if you did, are you seriously saying that you've perfectly audited hundreds of thousands of lines of code?

      No, I haven't audited it all, perfectly, but really, no one has with any large project -- perfect is a goal, and as I've previously stated, the goal is to provide more security via quickly patching my own hardware's firmware if any issues are discovered (smaller vulnerability window = more secure).

      Where's the "-1 this is really stupid" option?

      Are you seriously saying that educating myself about my own hardware/software that is essential to my security is stupid?

      I'd offer even more info, but I'm not going to waste any more time since you were such a dick. Perhaps just try asking, "How can I compile my own firmware for my devices," next time instead of being so caustic. Good luck with Google.

    16. Re:Use the souce. by isilrion · · Score: 1

      If you don't have control, you have to trust someone to provide security. Depending on who it is and what their experience is, I often prefer to trust.

      Exactly. I also prefer to trust. But not blindly: I must be reasonably certain that I can control who I am trusting, and that person/entity has the capacity review the item under consideration.

      That rules out non-free software, as only the author has the capacity to review, and the Apple model, as even with open source apps, I have no control. Quoting an Anon comment in this thread,

      It is not possible to prove security in a modern computer system for any plausible level of control.

      it is obvious that no one person or entity can guarantee the security, so the only sensible option is to not trust any single entity, and instead, distribute that trust among as many people you can, for as much of the toolchain as you can, and be ready to replace the offending part when a problem is detected.

    17. Re:Use the souce. by aristotle-dude · · Score: 1

      This doesn't make it secure. This doesn't make it secure.

      That's not what he said. If the code is open, then it can still be insecure. But, if the code is proprietary, then it is ALWAYS insecure.

      What utter nonsense. How secure code is depends on the quality of the code and whether it has been analyzed by tools and/or other people to uncover flaws. You do not have to have outsiders looking at the code. Code review by peers can improve code quality by finding mistakes the original author may have missed.

      Outsiders do not have some magical quality in finding bugs in code.

      --
      Jesus was a compassionate social conservative who called individuals to sin no more.
    18. Re:Use the souce. by Anonymous Coward · · Score: 0

      A smooth Android install on an iPhone?

      Here's a how-to that doesn't mention problems:

      http://www.redmondpie.com/install-android-2.2.1-froyo-on-iphone-3g-2g-using-bootlace-in-cydia-no-computer-required/

      Some other articles say it is a work in progress with issues, but perhaps those are out of date?

      http://www.pcworld.com/article/196595/how_to_install_android_on_your_iphone.html

      Perhaps you're braver than I would be. Have fun!

    19. Re:Use the souce. by mercury83 · · Score: 1

      I think we're mostly agreed... I prefer open-source for the reasons you outlined. I feel that closed-source, proprietary releases can be a little scary and I wish that more commonly used software was truly open. You say "Inability to Control = No Provable Security". I agree completely. Trust isn't about proof, you're simply BELIEVING that the controller of the source knows what they're doing, has your security in mind, and is on your side. If you a trust a source completely, you don't need provable security. If you've been burned before and are unlikely to trust, you'll want more control because you he no confidence in the "security" that they say it has. Sometimes you can't afford to control, and you're willing to trust someone, even if it's only a little bit of trust. By the way, I definitely used to trust Apple more than I do now -- I now trust them with few things.

    20. Re:Use the souce. by Reaperducer · · Score: 1

      I envy the amount of free time you have to accomplish all of this. Sometimes I wish I didn't have friends, family, a job, or a life, too.

      --
      -- I'm old enough to have lived through six different meanings of the word "hacker."
    21. Re:Use the souce. by sumdumass · · Score: 1

      If this is a bunch of users saying "I want an Iphone issued by the government instead of a blackberry" then the obvious answer is "no, sit down and shut up, we waste enough tax payer monies on you already".

      If this is as I suspect like in the corporate world, where someone sees a commercial of a phone doing all sorts of "cool things", then without any interaction with IT or even coworkers to see if they had problems doing work related tasks with them, buys one, then complains because their 5-10 year old messaging system or their 10 year old productivity/time management sweet cannot communicate with the brand new technology properly and the apps that worked on the old stuff no longer work with the new, and that the company isn't willing to invest $25k top fix this every time they change their personal phones in some attempt to continually remain compliant on the whim of an employee, or purchase some account on someone else' server in order to relay all the information to you through a third party first, the answer is a "personal phones expected to be used for work related activities must be approved by IT before they are purchased or they will not be allowed access to company data".

      The later simply makes sure the end user knows that they have to ask if it will work first. If it doesn't, there is no expectation that it ever will. I think the DOD is attempting to branch out a little and not put all their eggs in one basket, but the obvious answer to this is not ban all Android and Iphone phones (or all unapproved phones that the gov can't install it's own security software on) from government campus by employees if this doesn't happen and you will probably be able to watch Google and Apple trip over each other to give the government what they want. This is because the DOD employees not only use government phones, but also use their own phones and leaving their Iphone or Android at home (if they take public transportation) or in the car in the parking lot would likely translate into the hundreds of thousands if not millions of employees simply buying something that is allowed on campus instead. I think the government has more leverage here then google or Apple realizes.

    22. Re:Use the souce. by Obsi · · Score: 1
    23. Re:Use the souce. by LordLimecat · · Score: 1

      Wheres the -1 clueless? Installing tomato and coreboot isnt remotely close to "compiling firmware" for them, any more than sticking an ubuntu install disk in your PC is rolling your own operating system.

    24. Re:Use the souce. by LordLimecat · · Score: 1

      Installing Tomato firmware takes all of 10 minutes.

    25. Re:Use the souce. by PCM2 · · Score: 1

      Wheres the -1 clueless? Installing tomato and coreboot isnt remotely close to "compiling firmware" for them, any more than sticking an ubuntu install disk in your PC is rolling your own operating system.

      Unless, of course, you compile the firmware.

      --
      Breakfast served all day!
    26. Re:Use the souce. by Anonymous Coward · · Score: 0

      Could you please list to the devices you have and link to the corresponding source code (if the firmware is open source)? I want to move in this direction myself, but I'm unaware of open source firmware for phones, GPS devices and low-level stuff on PCs like CPU microcode, ethernet card firmware and the like.

    27. Re:Use the souce. by aliquis · · Score: 1

      Less functionality is good because it's only supposed to be the functionality Apple wants/can profit from anyway? =P

      Oh well, plenty of used N900 ads around :)

    28. Re:Use the souce. by Anonymous Coward · · Score: 0

      i suppose the "security" a company will use in their employees computers and cellphones is rather to install some kind of commercial rootkit which monitors and reports data transfers.

    29. Re:Use the souce. by Anonymous Coward · · Score: 0

      Apple's interest is to keep customers happy so they keep on buying their products. Which also includes trust. And customers want to be happy using a computer or whatever. So I think both groups essentially do have the same interests? Please specify what you mean with "Apple's interests".

    30. Re:Use the souce. by Anonymous Coward · · Score: 1

      Except that I am also sure that no additional closed source code has been included in my build.

      no you aren't. did you compile your compiler? did you compile the compiler that compiled your compiler?

    31. Re:Use the souce. by Anonymous Coward · · Score: 0

      Wheres the -1 clueless? Installing tomato and coreboot isnt remotely close to "compiling firmware" for them, any more than sticking an ubuntu install disk in your PC is rolling your own operating system.

      This.

      I wish I wasn't AC and had mod points to give. You make me want to register. :)

      Slashdot is going downhill if we don't call each other on bullshit. And vortexcortex is stretching the truth here.

    32. Re:Use the souce. by Anonymous Coward · · Score: 0

      How long did it take you to do these code reviews? Did you do them by hand or use a tool?

    33. Re:Use the souce. by Anonymous Coward · · Score: 0

      Installing someone else's software via a fully documented process isn't exactly what I'd call an accomplishment.

    34. Re:Use the souce. by vijayiyer · · Score: 1

      it is obvious that no one person or entity can guarantee the security, so the only sensible option is to not trust any single entity, and instead, distribute that trust among as many people you can, for as much of the toolchain as you can, and be ready to replace the offending part when a problem is detected.

      That toolchain is only as secure as its weakest link.
      I don't disagree that open source software can be very secure, but your argument for open source software being more secure is uncompelling. Once a problem is detected, it's too late - a backdoor could be inserted that is effectively itself undetectable.

    35. Re:Use the souce. by isilrion · · Score: 1

      it is obvious that no one person or entity can guarantee the security, so the only sensible option is to not trust any single entity, and instead, distribute that trust among as many people you can, for as much of the toolchain as you can, and be ready to replace the offending part when a problem is detected.

      That toolchain is only as secure as its weakest link.
      I don't disagree that open source software can be very secure, but your argument for open source software being more secure is uncompelling. Once a problem is detected, it's too late - a backdoor could be inserted that is effectively itself undetectable.

      As opposed to what? Reducing the chances of even detecting the compromise? I didn't just state that it was more secure (did I say that at all?). The more people who can cry foul, the lower the chances of a single entity to silence them all. After the problem is detected, you have the chance of replacing everything on top of the compromised element of the toolchain and prevent future damage. You can't prevent past damage, obviously, with either approach. But with "closed", you may not be able to prevent the future damage either (closed source: hard to detect, can't recompile, must wait until someone else does it for me. Apple model: I can't install the update by myself, I must wait until Apple publishes one, even if the app is opensource)

      (confession - I don't think I understood your post correctly. My lack of english skills may have played a part on that. I suppose you were thinking along the lines of, if I learn that my gcc is compromised, I'll replace only gcc and not everything compiled with it, which would be a pretty nonsensical position on my part)

  4. DoD should not support the Foxconn iPhone by Animats · · Score: 3, Insightful

    The iPhone is made by the Foxconn division of Hon Hai Precision Industry Company Ltd, in Shenzen, China. Apple is just the design and sales firm. That's not a reliable source for secure DoD communications.

    There are still some non-China cell phone manufacturing facilities. DoD needs to look hard at sourcing.

    1. Re:DoD should not support the Foxconn iPhone by Anonymous Coward · · Score: 0

      Considering the freakout that the DoD has had with fake/malware-injected CPUs, I'm surprised anything non-domesticly built is considered. Even then, building it within the USA's borders doesn't mean a lot without tight cradle-to-grave security.

    2. Re:DoD should not support the Foxconn iPhone by Anonymous Coward · · Score: 0

      And to your children, you're just the sperm donor I suppose.

    3. Re:DoD should not support the Foxconn iPhone by arogier · · Score: 2, Informative

      I don't see why the DoD can't contract Texas Instruments to make them a custom Android phone entirely in the US.

    4. Re:DoD should not support the Foxconn iPhone by Locutus · · Score: 0

      yes but you're talking about the US DoD and aren't they not the same ones who have no way to secure data being removed from their secure computers via USB or CD/DVD? I thought I read recently that they are now going back to eliminating those interfaces on some of their systems but not all and still have no way to secure using those devices on their secure network. So I would not look for logic here.

      LoB

      --
      "Anyone who stands out in the middle of a road looks like roadkill to me." --Linus
    5. Re:DoD should not support the Foxconn iPhone by Anonymous Coward · · Score: 1

      Except that Foxconn is actually headquartered in the Republic of China on Taiwan, a US ally.

    6. Re:DoD should not support the Foxconn iPhone by Suki+I · · Score: 1

      As soon as they give one of these things to Bradley Manning it won't matter any more anyway.

    7. Re:DoD should not support the Foxconn iPhone by hedwards · · Score: 2

      Because it's not like our allies spy on us.

    8. Re:DoD should not support the Foxconn iPhone by aristotle-dude · · Score: 1

      The iPhone is made by the Foxconn division of Hon Hai Precision Industry Company Ltd, in Shenzen, China. Apple is just the design and sales firm. That's not a reliable source for secure DoD communications.

      There are still some non-China cell phone manufacturing facilities. DoD needs to look hard at sourcing.

      Right, because American citizens never, ever are criminals or terrorists? Didn't the 9/11 terrorists live in the US for a long time?

      --
      Jesus was a compassionate social conservative who called individuals to sin no more.
    9. Re:DoD should not support the Foxconn iPhone by Anonymous Coward · · Score: 0

      I don't see why the DoD can't contract Texas Instruments to make them a custom Android phone entirely in the US.

      Because even the DoD can't afford a seventy-thousand-dollar-each cellular phone with every component made in the USA.

      Heck, considering that you'd have to open new fabs for some of the parts, it'd probably run more like $170,000 each.

    10. Re:DoD should not support the Foxconn iPhone by xnpu · · Score: 0

      Ah yes.. and then complain that the DoD-special-phone is hopelessly delayed, incredibly be over budget and not as secure as it was supposed to be. Doing everything from scratch is a lot more work than you may think. You can't simply trust a non-China manufacturer because it's not in China. It's not like US companies don't employ immigrants or that local citizens can't be bribed. No matter what, the DoD will have to do it's due diligence.

    11. Re:DoD should not support the Foxconn iPhone by arogier · · Score: 1

      But if you consider what they pay for missile parts... and the fact that missiles only get used once...

    12. Re:DoD should not support the Foxconn iPhone by frosty_tsm · · Score: 1, Insightful

      I don't see why the DoD can't contract Texas Instruments to make them a custom Android phone entirely in the US.

      Because even the DoD can't afford a seventy-thousand-dollar-each cellular phone with every component made in the USA.

      Heck, considering that you'd have to open new fabs for some of the parts, it'd probably run more like $170,000 each.

      Even with the defense contractor mark-up, 170k is not how much it would cost to make an iPhone or Android in the US. Well, unless the plants were run like a unionized auto-plant...

    13. Re:DoD should not support the Foxconn iPhone by Requia · · Score: 1

      If you factor in that they could easily use up a million phones before they became obsolete (depending on how serious they are about them being used by everybody) economy of scale would drive that price way way way down.

      --
      By all means mod me troll. I'm always happy to see my enemies are afraid to debate me.
    14. Re:DoD should not support the Foxconn iPhone by gtall · · Score: 1

      Yes, and how many of them missiles are actually fired off every year? I'm guessing not a lot.

    15. Re:DoD should not support the Foxconn iPhone by gtall · · Score: 1

      It only takes one mole to compromise your security. At that point, it isn't strictly a technological issue, although technology can ameliorate it.

    16. Re:DoD should not support the Foxconn iPhone by sumdumass · · Score: 1

      The strategic value of a missile is quite a bit more/different then that of a phone that can already be replaced by another phone already on the market.

      comparing a missile's value to a phone is much like comparing the value a working car presents to you with the value of a toy matchbox car. You can justify spending a larger sum of money on one of those 1967 mustangs, but not the other.

    17. Re:DoD should not support the Foxconn iPhone by mTor · · Score: 1

      At least a large portion of the iPhone's cost comes back to Apple as a revenue and supports American programmers.

      Since Android is completely free and Google does not license it, NO PORTION of most of the Andorid's phones comes back to US. It goes almost completely back to Taiwan and China.

      RIM's a Canadian company and all of their revenue goes to Canada.

      PS: Be careful when you try to throw stones in a glass house.

    18. Re:DoD should not support the Foxconn iPhone by Anonymous Coward · · Score: 1

      And it's not like you spy on your allies.

    19. Re:DoD should not support the Foxconn iPhone by vijayiyer · · Score: 1

      Qty 1M != economies of scale for a consumer electronics device. The iPhone sold more in 1 day.

  5. Security APIs? by Anonymous Coward · · Score: 0

    lol wut?
    This article goes so far as to call the two companies unpatriotic for not supporting the DoD.
    Rubbish.

  6. I would do the same by Anonymous Coward · · Score: 0

    It sounds as if the government is effectively asking for a backdoor. With lack of oversight already, why should Google or Apple expect them to do right by their customers?

    Besides, there's a reasonable amount of IP in any security stack. Why should any for-profit organization just hand it over?

    1. Re:I would do the same by Anonymous Coward · · Score: 0

      On Mac OS X , the security stack is Open Source - Google CDSA - its on Sourceforge.

  7. Access to what? by beakerMeep · · Score: 5, Insightful

    TFA is very light on technical details. What security API are they looking to access? To do what? They have access to AOSP/Linux, and could even cook up custom ROMs if they needed. Is there some cryptographic hardware driver they need or something?

    Also, From the 'article'

    It seems to me that Apple and Google are making self-centered bad decisions here that won't play well with the American public. Clearly, Apple and Google should re-think these myopic and selfish policies

    WTF? Maybe this journalist should re-think his self-centered trite opinion fluff pieces. Oh wait, it's NetworkWorld. Not much chance of that happening I guess.

    --
    meep
    1. Re:Access to what? by UnknowingFool · · Score: 4, Insightful

      One person I spoke with from DOD said that Apple flat out refused to play ball, telling DOD to "talk to our integrators and carriers."

      I don't have any more details than the author but he seems to be making assumptions based on conversations that he wasn't involved with. Maybe the simple fact of the matter is that Apple doesn't have any security APIs that would meet the DoD standards. Frankly Apple has designed their phone for the consumer space; Blackberries are more designed for security. Also it may be that Apple simply doesn't want to share any source code with the government. If they did, someone here on slashdot would espouse some conspiracy theory that Apple was helping the federal government track and mind-control you through your iPhone.

      As for Android, it is open source so the DoD can make their own modifications like the NSA did with SELinux.

      --
      Well, there's spam egg sausage and spam, that's not got much spam in it.
    2. Re:Access to what? by russotto · · Score: 3, Insightful

      Apple doesn't have any integrators either, so that conversation makes no sense.

    3. Re:Access to what? by Anonymous Coward · · Score: 0

      Umm, Unisys, CSC, Fujitsu, Lockheed Martin, among others ...

  8. Dont Be Fooled by Anonymous Coward · · Score: 0

    Look, it's all fine and dandy. iPhone is great, android is great. It's all setup by microsoft. While they sit back and watch apple and google run into the wildy arrogant ways of thier past, they're quitely selling tons of software to enterprises AND home users. When apple and google get the DOJ hammer, it'll even out the market share ofmobile, therefore, provide an enormous boost to microsoft and probably palm too. Look at this way, Balmer is Dooku and google is clone army.

    1. Re:Dont Be Fooled by ScrewMaster · · Score: 1

      Look at this way, Balmer is Dooku and google is clone army.

      Yes, but Count Dooku got his hands chopped off and died.

      --
      The higher the technology, the sharper that two-edged sword.
  9. I don't think this is the full picture... by EnglishTim · · Score: 5, Interesting

    Shenanigans! There's got to be more to it than this.

    The entire source for Android is available; what could Google be holding back? It's not as if they manufacture the phones.

    What are these 'Security APIs'? It doesn't make any sense.

    I think it's more likely that the DoD asked for some of Google / Apple's signing keys and the companies rightly refused.

    1. Re:I don't think this is the full picture... by digitaltraveller · · Score: 2

      Last time I looked (~2.0 era) there was still a ton of closed source stuff in android, usually labelled 'prebuilt' in the source directory.

      Even if all the prebuilt stuff is gone now, there is still a ton of closed source firmware that's not distributed, but required for a working handset.

      Cyanogen would be the man to ask get all the nitty gritty.

    2. Re:I don't think this is the full picture... by EnglishTim · · Score: 1

      Isn't that the prebuilt toolchain stuff?

      I'm sure there may be some closed-source stuff lower down than the OS in some of the phones, but that'd all be parts written by the handset manufacturers, and will vary between phones.

  10. Patriotism? by SuperSlacker64 · · Score: 5, Insightful

    According to the article, practically the only reason given as for why Google and Apple should give access to these APIs is to be patriotic. But as a few other people have pointed out, Google and Apple, though based in the US, are no longer solely US companies. What would this article's opinion have been had Russia or China or some other countries equivalent Department of Defense had asked for access to these APIs I wonder?

  11. Apple, Google Diss the DoD by multipartmixed · · Score: 0

    Dissing the DoD - or, as the article says, "thumbing their noses at" the DoD is not a wise move.

    The Denizens of Doom are a group of hacker-biker crossbreeds. A true Ubermensch, if you will. Piss them off sufficiently, and they will kick your digital ass!

    --

    Do daemons dream of electric sleep()?
  12. security, the ultimate pretext by bzipitidoo · · Score: 3, Interesting

    The military's security evaluations are heavily biased. Any technology the military does not want to use can be declared insecure, whether or not it is, and vice versa. One can always find a reason something is not secure.

    For example, they wanted to use Windows, and not any flavor of UNIX. The fact that Windows is produced by an American company was trotted out as a reason it was more secure. Code written by foreigners might have back doors, etc. Also, open source software development was shot down as fundamentally less secure than proprietary ways. Anyone might slip malware into open source. So, no Linux or FreeBSD. But then, why not a proprietary UNIX? They also prefer dealing with big companies, which informally disqualifies many UNIX vendors. They just have to come up with good sounding excuses, and security ones are great.

    For the other side of the issue, they'll lean on their evaluators to rubber stamp tech that they like. Often it seems that what they really want out of their evaluators is creative reasoning that gives them the cover they need to use what they want, not impartial evaluations. Or they'll bypass them. They can get approval on an interim basis when there is nothing secure enough, and they have to have something. They're accustomed to Windows, and they like it, so they found ways to get it on board.

    However, they can't do absolutely anything. Often there are ways that though extremely inconvenient, do increase apparent security, and which cannot be worked around. A big one is the "air gap". Need a separate computer for each network, to prevent information leakage across the boundaries.

    --
    Intellectual Property is a monopolistic, selfish, and defective concept. It is "tyranny over the mind of man"
    1. Re:security, the ultimate pretext by AF_Cheddar_Head · · Score: 2

      WTF are you talking about. Unix and Linux are used extensively on mission systems with in the DoD. You think they use Windows to manage the Missile systems you need to think again.

      You are correct in thinking that if a general wants something then he can probably get it secure on not but you are an idiot to think that Open Source is not used in the DoD. The politics can overrule the evaluators. Many times I have seen the evaluators say something is not a good idea and get overruled by the bosses.

    2. Re:security, the ultimate pretext by Anonymous Coward · · Score: 1

      The military's security evaluations are heavily biased. Any technology the military does not want to use can be declared insecure, whether or not it is, and vice versa. One can always find a reason something is not secure.

      BS. There may be some grey areas, but there are all sorts of actual, real documented standards. The blackberry platform has been audited & certified from end-to-end:

      http://us.blackberry.com/ataglance/security/certifications.jsp

      Blackberry has been approved by the governments of Canada, United Kingdom, Austria, Australia, New Zealand, United States, Turkey, and NATO.

      Blackberry has gone through the Cryptographic Module Validation Program (CMVP) that governs the conformance testing of cryptographic modules to Federal Information Processing Standard (FIPS) 140-2, "Security Requirements for Cryptographic Modules."

      The Common Criteria is an international evaluation scheme of IT security products and systems. Common Criteria evaluation results are recognized by 26 countries. Many Blackberry products have been certified for Common Criteria EAL 2+ or EAL 4+ certification.

      Apple and Android have been tested, audited & certified by... nobody.

    3. Re:security, the ultimate pretext by OzPeter · · Score: 0

      WTF are you talking about. Unix and Linux are used extensively on mission systems with in the DoD. You think they use Windows to manage the Missile systems you need to think again.

      of course a rebuttal of this is simply to point you at the USS Yorktown. True that the "missile"systems were not controlled by NT, but being dead in the water would not have helped firing any weapon at all.

      --
      I am Slashdot. Are you Slashdot as well?
    4. Re:security, the ultimate pretext by gandhi_2 · · Score: 2

      FBCB2 runs on Solaris and can be found in almost every Stryker since 2001.

      It can be found almost every US platoon of wheeled vehicles in Iraq or Afghanistan. Probably in all the Brads and Abrams too.

    5. Re:security, the ultimate pretext by Registered+Coward+v2 · · Score: 1

      WTF are you talking about. Unix and Linux are used extensively on mission systems with in the DoD. You think they use Windows to manage the Missile systems you need to think again.

      of course a rebuttal of this is simply to point you at the USS Yorktown. True that the "missile"systems were not controlled by NT, but being dead in the water would not have helped firing any weapon at all.

      The failure appears not to be an OS issue but an application issue; something that can happen with any OS.

      --
      I'm a consultant - I convert gibberish into cash-flow.
    6. Re:security, the ultimate pretext by Anonymous Coward · · Score: 0

      Yep Cheddar is correct. The parent is doesn't know what he is talking about.
      One example , most classified systems are UNIX boxes , not windows. The lower level folks your talking about is for systems that are not classified systems. When you got higher up the classification level you don't see many windows boxes at all. And I was in the military and also now I work for defense contractor. No windows boxes are only the primary choice for none classified systems. As a contractor it is much easier to STIG(http://iase.disa.mil/stigs/index.html) a Linux or UNIX box, my god windows boxes are a complete pain in the ass. Anything windows just causes pain when you try to go classified.
      Also final shot, I can see why google and apple refused, the people I have worked with at DISA about 20. Only one would I consider technically competent, and I am pretty sure he left DISA for another job.

    7. Re:security, the ultimate pretext by xnpu · · Score: 1

      What a non argument. It's not like Microsoft doesn't employ foreigners.

    8. Re:security, the ultimate pretext by OzPeter · · Score: 1

      The failure appears not to be an OS issue but an application issue; something that can happen with any OS.

      The point was that the DOD is/was using Windows technology in critical applications.

      --
      I am Slashdot. Are you Slashdot as well?
    9. Re:security, the ultimate pretext by gtall · · Score: 1

      yes, and you are full of shit, DoD is filthy with Unix, Linux, Mac OS, and other assorted systems. Go back under your rock.

    10. Re:security, the ultimate pretext by Registered+Coward+v2 · · Score: 1

      The failure appears not to be an OS issue but an application issue; something that can happen with any OS.

      The point was that the DOD is/was using Windows technology in critical applications.

      No one said they weren't - just that *Nix was also used; and that Windows was not the cause of the Yorktown's failure.

      --
      I'm a consultant - I convert gibberish into cash-flow.
    11. Re:security, the ultimate pretext by ToasterMonkey · · Score: 1

      For example, they wanted to use Windows, and not any flavor of UNIX.

      Except they do use UNIX.
      and Linux

      what the hell are you rambling on about?

    12. Re:security, the ultimate pretext by bzipitidoo · · Score: 1

      EAL 4 is not really that good, but it is used a lot because that's the highest level that is easy to obtain. EAL 5 through EAL 7 is where the real security begins.

      A big problem is that there's almost nothing rated EAL 5+. Only stuff I have heard of are devices simple enough that formal proofs are possible, software that is so locked down as to be nearly useless, and stuff such as GEMSOS that is obsolete because the evaluation process took longer than the lifetime of the technology. Undoubtedly, Apple and Android aren't rated not because they are fundamentally less secure, but because evaluation and fixing of problems is a long and expensive process. I have heard times ranging from 6 months to 10 years. SELinux, which btw is only EAL 4, is such a pain to administer and use that no one wants to. Rather funny the time a Red Hat rep came to a users group meeting to brag about SELinux, and then admitted he wasn't using it himself. Didn't have it enabled on the laptop he was using to run his slide show, and didn't have any demo.

      Most exasperating is the military's knee jerk handling of requests for information. They're big on false positives. They'd rather not tell anyone anything, for fear of leaking a secret. It's understandable, because the punishments are harsh, but it's not productive. Their own people are routinely denied innocuous information that they really do need. Existence of and means to contact labs that can test for EAL 5 to 7? Secret. Information on the requirements to qualify as EAL 5 to 7, so perhaps you can set up your own lab? Secret. Lists of devices and software that have met the standards? Tests and results, which could be embarrassing? Oh, definitely secret. Why is it secret? Secret. Except that it isn't-- often the persons making such claims aren't sure, or feel they have something to hide, and are just trying to stay out of trouble. Takes a lot of digging and prying to shake that sort of info loose, to say nothing of the effort to actually do formal verifications.

      Yes there are standards, many of them. Too bad it's such a bear to use them.

      --
      Intellectual Property is a monopolistic, selfish, and defective concept. It is "tyranny over the mind of man"
  13. You know what annoys me? by Anonymous Coward · · Score: 0

    I'll tell you what annoys me. Are you ready? Summaries that ask a question, and then answer it. Why is that annoying? I believe this post answers that.

  14. Bad summary by zigfreed · · Score: 2

    Google and Apple just told the DISA to talk to the integrators. They aren't getting special treatment which makes sense: as big as the DoD is, they are still smaller and more specialized than the general public which the devices were meant to serve.

    This is a job for a small, tight-knit development company developing under NDA, i.e. integrator.

  15. Cryptograms by xsxixmx · · Score: 1

    They ought just make an app with some serious cryptography. It should be easy enough to just text instead, idk the security level differences, whatever works better though. For test they can change the letter codes (binary/ascii) with random cycling syncable layouts (keys). And I saw something in the book: "Blink" regards just going back to 'word of mouth'... And regards the API, it should already be in there pocket if you ask me. "many hands make the work load light"

    --
    GOT ZEN?
  16. Poor Article by dcollins · · Score: 1

    FTA: "Providing API access to DOD is the patriotic and morale thing to do, especially since DOD is opening the door to lots of sales opportunities for both companies. "

    Yeah, that's a well-written article. I'm convinced.

    --
    We know where leadership by an anti-intellectual "strongman" who scapegoats minorities and likes boisterous rallies goes
  17. Google and Apple know all too well by gilesjuk · · Score: 1

    If you give access or information about APIs that this information can leak out and be used for the wrong purposes.

    The military should buy something that does what they want, not buy a consumer product then try to get the manufacturer to change it for them.

  18. seems fair enough by cenobyte40k · · Score: 1

    The DOD can take it multi-million dollar contract and go somewhere else. It's not up to the DOD to force companies to make smart business transactions, but if I was a stock holder at Google or Apple I might be a little pissed.

    1. Re:seems fair enough by Anonymous Coward · · Score: 0

      Google knows that dealing with governments costs a lot of time and is only worth the effort (and bad publicity) if they get payed very well for it.
      Both Google and Apple should know exactly how profitable it was for RIM, so if they reply with "just get a BlackBerry" it just isn't worth it.

    2. Re:seems fair enough by Anonymous Coward · · Score: 0

      So a couple of things :

      The mobile device fleet in the DoD , whilst large, is likely only a couple of days (or less) worth of sales for either Apple or the Open Handset Alliance ( both are in the 200,000-300,000 activations per day range ).

      All those organisations are involved in a highly competitive, emergent market, and they do not have infinite resources. Apple has maybe 2000 Software Engineers, and Google would likely be similar (you can quibble by a few thousand either way) - most of their organisation headcount is operations, sales , marketing and in Apple's case support and retail. They need to make hard decisions about where to spend their time and resources. It is likely that most of what DoD would want (see later in comment), have zero to negligible impact in the consumer or business markets, and therefore, doing those things would take away effort from new features that may have large net sales impact across all markets.

      So what is DoD likely to want, at least as a wishlist :

      - Certified Hardware Cryptography ( Apple actually has this now to a point, and whilst not common on Android, there are a handful of specialised, very expensive Andriod devices do such as from General Dynamics )
      - Backdoor master key and key escrow for all cryptography , including customising CA roots
      - Integration with their Common Access Card for unlocking the device and authentication to Apps ( App authentication is possible by third party effort, but unlocking the device would be a more major undertaking )
      - More device restrictions and controls ( eg fail-closed trusted network detection, VPN always on, prevention of creating personal email accounts, disable cut and paste, App whitelist )
      - S/MIME Email (available as 3rd Party Apps for both platforms )
      - Intranet App store , including site licencing
      - Formal Security Certifications
          - Common Criteria Certification to EAL4 for SIPRNET ( this is a 6+ month, multi-million dollar undertaking, tying up many R&D staff in the process - note also there are no CCC Protection Profiles defined for Mobile Devices, so the vendor gets to make them up !
          - FIPS-140-2 Level 2 (Cryptography has been validated, and the device has anti-tamper provisions on the cryptographic module - Apple only has applied for FIPS-140-2 Level 1)

      Add all that up, and its person-years and millions of dollars in effort, for maybe a days worth of current sales. Maybe half of it has broader applicability to a wider range of customers , and is probably in their respective pipelines somewhere.

      In Apple's case they can at least partially do a bunch of that list right now, using custom Apps and external accessories, but that is something they'd live up to an integrator like Unisys or similar to put together. Android is probably a bit behind this on average, but specialist vendors can certainly put custom devices together with that feature set for a price, given enough time and effort ( although they'd likely leave the "with Google" features out of any such device ).

      DoD can't have it both ways - COTS pricing, a feature set that 99.9% of the market doesn't care about, ease of use : pick any 2.

      Interestingly Wikileaks recent time in the sun has shown that an awful lot of data is overclassified, and that human factor weaknesses far exceed the capacity of any technical protection measure to address.

  19. Apple's iPad needs a CAC reader... (or a USB slot) by (H)elix1 · · Score: 1

    This is going to get even worse for Apple's iPad and other USB free devices. Without a smart card reader, or at least a USB slot to add one, these devices are going to have very limited usability in the DoD as things move forward.

  20. Re:I altered ANDROID recently (was easy) by Anonymous Coward · · Score: 0

    hey, it's Hosts File Guy! I wondered when you would show up.

  21. Re:Apple's iPad needs a CAC reader... (or a USB sl by gandhi_2 · · Score: 1, Troll

    They gay ban hasn't been overturned yet.

  22. Re:Apple's iPad needs a CAC reader... (or a USB sl by Anonymous Coward · · Score: 0

    Actually, iPad 2 may very well have a USB port.

  23. Re:Umm something is hurting my eyes! by alienzed · · Score: 1

    Giant colored font batman!

    --
    Never say never. Ah!! I did it again!
  24. Sorry I don't see government as the gate keeper by Ruler4You · · Score: 1

    I just can't see the justification for the government to have and hold proprietary information it has no rights to. If it should some day be determined that some corporate irresponsibility or collaboration in a criminal or treasonous context fell on the shoulders of corporate officers, I'd favor prosecution. But not release of the proprietary information itself. As it is government information and citizen information in the governments cognizance is considerably compromised by their "security". Only in the context of socialist nationalization (even then it's hard to justify) does this make the slightest bit of sense.

  25. Why I'm getting a Blackberry by Logic+Worshipper · · Score: 0

    iPhone and Android make money by spying on you. DOD wants to reprogram their OS to make that impossible, and they said no. They won't even let the DOD have a secure version of their OS, because their OS are inherently insecure.

    1. Re:Why I'm getting a Blackberry by Reaperducer · · Score: 1

      iPhone and Android make money by spying on you [citation needed]. DOD wants to reprogram their OS [citation needed] to make that impossible [citation needed], and they said no [citation needed]. They won't even let the DOD have a secure version of their OS [citation needed], because their OS are inherently insecure [citation needed].

      FTFY.

      --
      -- I'm old enough to have lived through six different meanings of the word "hacker."
  26. Re:Apple's iPad needs a CAC reader... (or a USB sl by WiseWeasel · · Score: 1

    Seriously, how is a disgruntled private supposed to suck down the contents of the DoD document store without a USB port?

    --
    "I like systems, their application excepted", George Sand (French)
  27. Exactly by Evets · · Score: 1

    This is exactly the reason that platforms like OSX and Windows are so secure, and linux is so riddled with viruses. Can you imagine the problems we would be facing if people actually had access to review and update those operating systems?

  28. Re:Apple's iPad needs a CAC reader... (or a USB sl by Anonymous Coward · · Score: 0

    Nope. Just bluetooth. They make bluetooth CAC readers.

  29. Something more... by Anonymous Coward · · Score: 0

    Perhaps it is politically motivated. Something about two wars comes into mind.

  30. The "Lord of HOSTS" will do nicely by Anonymous Coward · · Score: 0

    "hey, it's Hosts File Guy! I wondered when you would show up." - by Anonymous Coward on Saturday December 11, @01:47PM (#34524460)

    See subject-line... & someone is modding my post on how to use HOSTS files on ANDROID even (very easy to do with ADB).

    APK

    P.S.=> "Gee, I wonder WHY?" (not): With ISP/BSP's talking about "pay as you use" internet (how much bandwidth you consume in other words) -> http://yro.slashdot.org/story/10/12/08/2012243/FCC-Approving-Pay-As-You-Go-Internet-Plans so they can not only TRACK YOU via cookies & such in adbanners but also charge you more because you are downloading + processing adbanner content, which means YOU CONSUME MORE BANDWIDTH BY DOWNLOADING & RUNNING AD BANNER CONTENT!

    (Adbanner content, which mind you, has been shown to bear malware malicious code before no less -> http://apcmag.com/microsoft_apologises_for_serving_malware.htm in the past (& that's not a first either))

    Yes - I can pretty much guess it's NOT Google's people down modding me here, but rather ISP/BSP reps + advertisers (or even malware makers), because they are the ones that HATE HOSTS FILES more than anyone does... apk

  31. Apple is ignoring Corporate and DoD's requests by Anonymous Coward · · Score: 0

    Apple is flat out ignoring demands such as this and is 100% concentrating on the consumer. They are missing the boat on security requirements of larger corporations and apparently the DoD as well. I think they are missing a huge and somewhat captive market, if they would just do as required the would sell a huge # of phones and iPad's. I think they are too focused on selling apps to teenagers. Don't get me wrong I love my iPhone and iPad but I must admit I have had to jump thought hoops to get them to work for me as office tools.

  32. Re:Effete moddowns w/ no justification, again? by Anonymous Coward · · Score: 0

    Maybe the mods love watching you rant? It is fairly entertaining.

  33. Re:Effete moddowns w/ no justification, again? by Kalriath · · Score: 1

    You do realise, apk, that Slashdot's moderation system actually prevents providing justification, as any successive post nullifies all moderation to a conversion, right?

    Personally, I'd suspect that you were downmodded for being completely off-topic - you're going on about hosts files in a discussion on the DISA not getting access to the Android and iPhone OS security APIs.

    --
    For a site about things like basic rights, Slashdot users sure do like to censor "dissent".
  34. Re:Effete moddowns w/ no justification, again? by metrix007 · · Score: 1

    The justification on technical grounds is you have no idea and what you try to pass of as technical insight is demented ignorant rambling.

    --
    If you ignore ACs because they are anonymous - you're an idiot.
  35. metrix007 got played, He played himself. by Anonymous Coward · · Score: 0

    metrix007 is pissed about this http://yro.slashdot.org/comments.pl?sid=1888084&cid=34462614 [slashdot.org] where he blundered on hosts files against the person he's trolling now. metrix007 got played, He played himself.

  36. Google and Apple CAN'T DO IT! by rdebath · · Score: 1

    Linux and BSD the OS's under Android and iPhone both have solid security tools. Linux's version was written by the NSA FFS. But once the machine leaves the hands of G&A the 'integrators' have full control over what goes in and what stays out. For Linux the major security enhancements can be turned off with a single switch & kernel recompile.

    The only way either company could force the issue is to use legal means and renegotiate their agreements with these 'integrators' AKA 'Phone companies'.

    Good luck with that!

  37. Do not feed the troll by Anonymous Coward · · Score: 0

    See my subject above? It's about you.

  38. fair is fair... by hesaigo999ca · · Score: 1

    If blackberry did just that, then they should too, although I do not understand what the big deal is, if the military is reviewing the code in order to see what is going on as to ensure no one is logging the communication flow, but anyways, this is not news, happens all the time when dealing with military, they need to follow protocal, and the rest of us civis don't....no big deal, so they stay with BB and just keep ensuring their platform survives even longer...

  39. Re:Kalriath, on HOSTS files, last time you RAN! by Kalriath · · Score: 1

    apk, really. Let it go, you're not doing yourself any favours. This is exactly the sort of behaviour that gets you downmodded, you know. It's a bit like that twitter fellow.

    Stop. Just... stop.

    --
    For a site about things like basic rights, Slashdot users sure do like to censor "dissent".
  40. Kalriath & MS have to admit "APK IS RIGHT"? by Anonymous Coward · · Score: 0

    Kalriath didn't like the beating he took @ my hands regarding HOSTS files before on /. here, as it's where I got Kalriath to run away from disproving the numerous points I listed in favor of HOSTS files, and where I got Kalriath to ADMIT THE SAME AS MICROSOFT'S OWN MGT. HAD TO VS. MYSELF ON THE SAME POINTS

    (Microsoft's own senior mgt. of their "Windows Client Performance Division" in FOREDECKER to admit the same -> That using a smaller file (by using smaller blocking addresses in HOSTS files) will result in BETTER HOSTS FILE PERFORMANCE):

    Here http://it.slashdot.org/comments.pl?sid=1687452&cid=32694426 [slashdot.org]

    and

    Here http://it.slashdot.org/comments.pl?sid=1687452&cid=32632240

    (That's what this reaction in my P.S. of his is about, since he's now caught in the fact he likes to "troll" my posts on HOSTS files)

    APK

    P.S.=>

    "apk, really. Let it go, you're not doing yourself any favours." - by Kalriath (849904) on Monday December 13, @03:21PM (#34538324)

    You followed me into another HOSTS file post, and you have to "eat it" because you're shown not only trolling me here before on HOSTS files posts I do, but also that you royally "MESSED UP LARGE" on them, having to admit my points are right!

    (You, & right along with Microsoft's own people too, also having to admit my points on HOSTS files are indeed, correct!)

    ---

    "Stop. Just... stop." - by Kalriath (849904) on Monday December 13, @03:21PM (#34538324)

    Why don't you take your own advice, you're the one that gives yourself this beating by following around my posts on HOSTS and you get disproven on every so called "point" you make and you run in the end (until you do it again that is, like today)...

    See the 2 urls above, to anyone else reading, this isn't a "1st" for Kalriath on my posts on HOSTS files, & he did just as poorly here as per his usual! apk

  41. Good for them by bryan1945 · · Score: 1

    Give the gov their code and expect it spread on the internet the next day. (Yeah, I have a lot of faith in the gov'ment)

    --
    Vote monkeys into Congress. They are cheaper and more trustworthy.