Guardian Rom - Secure Android OS

Discussion in 'privacy technology' started by x942, Jun 9, 2013.

  1. happyyarou666

    happyyarou666 Registered Member

    Joined:
    Jan 29, 2012
    Posts:
    803

    oh my ! ill keep an eye on you guys now more than ever this is starting to get interesting , still out on wich android phone to buy thou this looked promising until ive heard no nexus version aka full aosp support ...crap! love the design much more than the htc one even so here

    http://www.androidcentral.com/huawei-ascend-p6-review , as said the design is great not so much the negatives about it thou -.-...xD

    still running an ~ Snipped as per TOS ~ 8 year old phone :argh: , when will someone release a proper ~ Snipped as per TOS ~ android phone with full aosp support and one that doenst look like a fn plastic toy brick damn it
     
    Last edited by a moderator: Oct 21, 2013
  2. x942

    x942 Guest

    I will look into this and if needed we can fix the default ciphersuite.

    What's coming:


    Screen mockup for the settings app here
     
  3. Grassman20

    Grassman20 Registered Member

    Joined:
    Jul 14, 2013
    Posts:
    28
    Location:
    USA
    I'm pretty excited about this project. My smartphone is critical to daily life and I hate that it's basically just an NSA tracking device right now. I know that you can't make it perfectly secure and private, but there are massive improvements that can be made over the current Android options.

    I'll be watching with much anticipation.
     
  4. PaulyDefran

    PaulyDefran Registered Member

    Joined:
    Dec 1, 2011
    Posts:
    1,163
    I hope you get a Nexus 5 :D

    PD
     
  5. TheCatMan

    TheCatMan Registered Member

    Joined:
    Aug 16, 2013
    Posts:
    327
    Location:
    sweden
    Been doing the same, I like this project its nice to see decent people spreading the wilderness around here, thanks goes out to x942 am sure many other lurkers out there hidden !
     
  6. Gitmo East

    Gitmo East Registered Member

    Joined:
    Jul 28, 2013
    Posts:
    106
    This is starting to look awesome :thumb:
    I'm running a HTC One with ViperOne Rom, I have been toying with the idea of "opting out" and ditching my phone/NSA beacon altogether but not sure I could do it though :(
    Guardian Rom could be the solution, thanks
     
  7. x942

    x942 Guest

    Just waiting for launch day and it's mine! :D

    (I hope it's okay to post this if not sorry and mods please remove it)


    Guardian Rom has launched a funding campaign on our site: -www.guardianrom.com-

    All the proceeds go to making Guardian Rom better and speeding up development. There are some good gifts too for donations.
     
  8. PaulyDefran

    PaulyDefran Registered Member

    Joined:
    Dec 1, 2011
    Posts:
    1,163
    I think when you get the 5 supported, I'm switching. Are you going to incorporate MAC spoofing? There is FINALLY a working MAC spoofer in the Play Store - MAC spfr (root). Works on GNex and N7. There is working Host Name Spoofing as well, with another app, and also an app for specifying what DNS servers you want to use. Just some things to look at for GuardianROM.

    It would really be great if you could develop the kernel for better battery/performance as well...like franco, faux, trinity, etc... But I don't know how that would effect security.

    PD
     
  9. x942

    x942 Guest


    Nexus 5 will be supported as soon as I get one (hopefully quickly at launch). It's going to be my new secure phone ( I use a Note 3 as a daily driver - need Gapps for somethings sadly).

    We have mac spoofing working on certain devices. The app will be released opensource on the Play Store as well. We have now started working on making a lot of our apps installable on any device, this way users aren't forced to use our Rom. This will be released as a flashable zip sooner or later.

    Right now it's a stock kernel with only security enhancements (mainly XTS mode is supported). Battery life improvements should be noticeable out of the gate since GApps aren't present. GApps (especially maps and hangouts) kill battery like nothing.
     
  10. 1337

    1337 Registered Member

    Joined:
    Mar 16, 2013
    Posts:
    8
    Great project! I'm not able to test the ROM (I'm using SGSII) but like what I'm reading so far.
    The irony: The website you mention(www.guardianrom.com) is not able to load with my secure/privacy browser setup(FF + ABE + NoScript).
     
  11. x942

    x942 Guest

    Sorry about that. We are using Squarespace as our host as it is much easier then dedicating the time to actually hosting our own site. We have a developer work on our own site however and it should be up shortly :)

    We also will be setting up a TOR hidden service for downloads as well. :thumb:
     
  12. cb474

    cb474 Registered Member

    Joined:
    May 15, 2012
    Posts:
    351
    Does the secure replacement app for callling only work as VOIP and fully disable placing regular calls over one's cellular network? Or is it possible to also place regular calls?
     
  13. x942

    x942 Guest


    You can use both. The Secure Calling app (Ostel) does integrate with the dialer so it's easier to use but you don't have to enable this and normal calls still work fine. Only calls going over the Ostel network or your own ZRTP server are encrypted. :thumb:
     
    Last edited by a moderator: Oct 28, 2013
  14. cb474

    cb474 Registered Member

    Joined:
    May 15, 2012
    Posts:
    351
    Thanks for the explanation.
     
  15. PaulyDefran

    PaulyDefran Registered Member

    Joined:
    Dec 1, 2011
    Posts:
    1,163
    OSTel is nice, great inclusion. For those that want to try it now, head to the website (VPN/Tor) and create an account. Then install CSIPSimple and configure. Only using while connected to a VPN would increase anonymity.

    x942, how would you compare Moxie's RedPhone to OSTel/CSIP? Pretty much the same, no?

    PD
     
  16. MagnificentSpam

    MagnificentSpam Registered Member

    Joined:
    Nov 1, 2013
    Posts:
    3
    Location:
    Germany
    I'd like to know this, too. Is there any way to download apks directly from google play without having gapps installed? And if not, would it be very insecure to install the google play app in this rom and deny all permissions exept the google account with openpdroid?
     
  17. kareldjag

    kareldjag Registered Member

    Joined:
    Nov 13, 2004
    Posts:
    622
    Location:
    PARIS AND ITS SUBURBS
    Last edited: Nov 1, 2013
  18. x942

    x942 Guest


    Security wise: Pretty much the same. Ease of use: Redphone wins hands down (uses your phone number so no sign up needed). Privacy: Ostel wins hands down (doesn't use your phone number so no tie back to you, also you can setup your own server).


    Yes, I have an old spare phone I use to pull apks down. I then use titanium to back them up and flash them to my Guardian Phone. I don't do this anymore though for security reasons. Not much you can do. If you install playstore it can do what ever it wants basically. I have tried with openpdroid and it just breaks the playstore completely.

    I am looking into have the ability to have GApps in the "outer OS" and not in the hidden OS.


    Thanks!! :D
     
  19. 1337

    1337 Registered Member

    Joined:
    Mar 16, 2013
    Posts:
    8
    What are the security concerns here?
    What can an app with no permissions do? Or average google play app that receive fake data(thanks to OpenPDroid) and without Internet, Bluetooth, NFC permissions?
     
  20. MagnificentSpam

    MagnificentSpam Registered Member

    Joined:
    Nov 1, 2013
    Posts:
    3
    Location:
    Germany
    I'm using cyanogenmod 10.2 at the moment, will try this rom when I'm home next week.
    I configured openpdroid to deny all permissions exept account credentials and accounnts to the apps Google Account Manager, Google Play Store, Google Play-Dienste (german language) and some other apps with google in their name.
    The Play Store still works, but there are notifications popping up every few seconds telling me something was denied to an google app, so I guess this might effect battery life.
    I'd like to be able to download apps when not at home and I don't have a second phone with me.
    I also guess downloading proprietary apps via other repositories like Aptoide or Blackmart isnt a good Idea concerning the safety, or am I wrong here?
     
  21. pharmakos

    pharmakos Registered Member

    Joined:
    Oct 26, 2013
    Posts:
    3
    Location:
    midwest
    Hi,
    I just received my Nexus 5. Yay. Am I right in that the Guardian Rom that you have for the Nexus 4 will not work and I have to wait until you create a version?
     
  22. x942

    x942 Guest

    You are introducing closed-source and proprietary apps into secure (open-source) system. Personal I refuse to do this as much as possible. To each their own though.

    Permissions aren't the only issue here. What if the app requires internet access to run? Revoking it crashes it. Then one day the developer pushes a malicious update that turns it into spyware (or worse malware thanks to a root exploit). Only install from sources you trust. In my case that's FOSS software ONLY. In your case that may be different.


    The issue isn't block permissions, the issue is that the Google Framework has system permissions. It can basically do what it wants. We have a work around for this though:

    (NOTE: This is dependent on Google Approval and numerous other things. )

    We are looking into having a "Professional" and "Community" edition. The latter would be fully open-source as mentioned, the first would be exactly the same but include the proprietary Google Apps while in the normal OS. Hidden OS would NOT have GApps as this would leak the presence of the Hidden OS.

    Of course this is just thoughts on paper. We have to get the stable build out before anything is done along these lines. It should work in theory though. This would give users the best of both worlds. Play OS and Secure OS on one device.

    Personal I would not use ANY proprietary apps at all, regardless of what store they came from.
     
  23. PaulyDefran

    PaulyDefran Registered Member

    Joined:
    Dec 1, 2011
    Posts:
    1,163
    My Nexus 5 is on the delivery truck - Get To Work! :D

    PD
     
  24. x942

    x942 Guest

    I have a build in the works. Sadly UPS is useless and once again delayed my package. I can't start till Tuesday now. I wish companies would use more reliable services for delivery. UPS has never delivered a package to me on time yet.
     
  25. InconspicuosName

    InconspicuosName Registered Member

    Joined:
    Nov 9, 2013
    Posts:
    8
    Location:
    EU
    Hi Kyle,

    Any update on the Guardian project for the Nexus 5? (We are talking about the LG Nexus 5, right?) I'm in the market for either a new smartphone or no phone at all, so this ROM is sort of a deal breaker for me :)

    Thanks!
     
  1. This site uses cookies to help personalise content, tailor your experience and to keep you logged in if you register.
    By continuing to use this site, you are consenting to our use of cookies.