• XSS.stack #1 – первый литературный журнал от юзеров форума

Новое! Введение в разработку Secrypt Phone

Seichs

floppy-диск
Пользователь
Регистрация
23.12.2024
Сообщения
8
Реакции
1
Hello xss.pro community!

Dark-Logo-standard-resolution.png


My name is Seichs, and I am happy to introduce my new project - Secrypt Phone . We are developing a modified Google Pixel 8 with a specially customized operating system.

Key features of Secrypt Phone:

  • Security First : We remove cameras, microphones and several other sensors from the device to ensure maximum protection of your privacy.
  • Strong encryption and Titan M2 security chip : Protects your device and data from sophisticated physical attacks, keeping your information safe.
  • Verified Boot : Ensures that the operating system has not been modified, maintaining the integrity of your device.
  • P2P functionality : The phone works on a peer-to-peer (P2P) principle and uses servers only to establish a handshake, ensuring direct and secure communication.
  • Connect via Tor network : Your phone connects to the Internet via the Tor network, providing anonymity and additional protection when browsing the web and communicating.
  • Automatic Power Off Switch : The phone automatically turns off after a set period of inactivity, preventing unauthorized access.
  • Duress PIN : An emergency PIN that automatically erases your entire phone and data if you are forced to provide access under duress.
  • Obfuscated PIN layout and privacy screen : Allows you to enter your PIN in public without anyone peeking. Alternatively, an integrated fingerprint sensor for added convenience and security.
  • Open Source and Certification :
    • Open Source : Open source code allows you to check for back doors and other security risks.
    • Attestation : Hardware verification of the authenticity and integrity of the phone's software, providing full control over the device.
  • Exclusive device : Secrypt Phone with pre-installed Secrypt OS is sold directly from us. The phone comes with pre-installed Secrypt Chat messenger - a secure and convenient communication application.
  • No Data Storage : No user data is stored. Users are not required to create an account to use the phone and the app.
  • Safe activation process :
    • The application comes with a physical activation code generated by us.
    • After activating the application, you can enter your username and password.
    • You will then receive 8 words that you need to save. These words are needed to reset your password.
    • Without these 8 words, you will never be able to change your password, and we cannot do it for you either.
  • Sealed Packaging : Secrypt Phone comes in a sealed box to ensure the integrity and safety of the device upon delivery.
Our commitment:

Our team is working hard to bring this project to life, aiming to create a secure and private device for users who value their security and privacy. With P2P functionality, minimal server usage, Tor network connection, and advanced security measures, we ensure that your communication and data remain as direct and secure as possible.

Looking for feedback:

We are constantly looking for things that we may have missed and should implement. Your feedback, suggestions and ideas are very welcome to make Secrypt Phone and Secrypt OS even better!

We welcome your feedback, suggestions and cooperation!

Sorry for possible errors in Russian, as this text was translated automatically.

Thank you for your attention and support!

Sincerely,
Seichs
 
очередной ханипот от ФБР?
 
Open Source : Open source code allows you to check for back doors and other security risks.
As Dread Pirate Roberts mentioned, how can we be sure this project isn’t a honeypot? Has the source code been independently audited by trusted third parties? And what guarantees do we have that the hardware is free from any tampering or backdoors? Providing clarity on these points could go a long way in building trust.
 
As Dread Pirate Roberts mentioned, how can we be sure this project isn’t a honeypot? Has the source code been independently audited by trusted third parties? And what guarantees do we have that the hardware is free from any tampering or backdoors? Providing clarity on these points could go a long way in building trust.
the main problem is not with the software, but with the hardware. FBI will know the financial information, names and addresses of all people who have purchased that "secure phone".
 
names and addresses of all people who have purchased that "secure phone"
Yeah, exactly, that’s the main issue. Even if the software is super secure, if personal or financial info is collected during the purchase, it totally undermines privacy. The only way is to have anonymous purchases, like using crypto (e.g., XMR) with no buyer information recorded. Without that, a 'secure phone' is just a fancy name))), not truly secure. Privacy starts the moment you buy it.
 
Ребята просто решили наварить бабок с GrapheneOS + InviZible Pro


> Security First : We remove cameras, microphones and several other sensors from the device to ensure maximum protection of your privacy.
show full list

> Secrypt OS + Open Source and Certification :
show your git repo

> Secrypt Chat messenger
show source code + audit from any company

>No Data Storage : No user data is stored. Users are not required to create an account to use the phone and the app
>After activating the application, you can enter your username and password.

Bсе остальное это дефотные фичи GOS.
 
the main problem is not with the software, but with the hardware. FBI will know the financial information, names and addresses of all people who have purchased that "secure phone".
Thank you for your concerns regarding the Secrypt Phone . We understand that privacy and security are crucial, and we would like to clarify how we address these aspects.

Development Phase

We have just started the development of both the software and hardware for the Secrypt Phone . Our goal is to create a secure and reliable device that meets the highest privacy standards.

Open Source Plans

Although we are not open source at the moment, it is our intention to make Secrypt OS/Secrypt Chat fully open source before the phone becomes available for purchase.
This will allow external companies and independent researchers to audit our code and verify the system's security. We will only begin selling the phone once we have successfully passed these audits, ensuring the highest level of security and trust for our customers.

Anonymous and Secure Purchasing Processes

  • No Personal Data: During the purchasing process, we do not store any personal information.
  • No Account Required: Customers do not need to create an account to make a payment.
  • Cryptocurrency Payments: We exclusively accept payments in privacy-focused cryptocurrencies such as Monero and Zcash
  • Discreet Shipping: We offer shipping to post points and PO Boxes to protect your physical address.

Public Demonstrations and Proof of Concept

To strengthen trust in our hardware and software, we will organize public demonstrations and proof of concept presentations.
These events will showcase that no unwanted modifications have been made and that our security measures are effective.

Based in Switzerland and Compliance with Privacy Laws

We are based in Switzerland, a country renowned for its strict privacy laws and strong data protection regulations. This location offers several advantages for our privacy-focused product:
  • Robust Privacy Legislation: Swiss privacy laws are among the most stringent in the world, providing comprehensive protection for personal data. This ensures that all customer information is handled with the utmost care and in compliance with the highest legal standards.
  • Data Sovereignty: Being based in Switzerland means that all data processing and storage occur under Swiss jurisdiction. This offers an added layer of security, as Swiss laws prohibit unauthorized access and ensure that your data remains private and protected against external pressures.
  • Reputation for Neutrality and Security: Switzerland is globally recognized for its neutrality and commitment to security. This reputation reinforces the trustworthiness of our operations and ensures customers that their privacy is a top priority.
  • Access to Expertise: Switzerland is home to leading experts in data privacy and cybersecurity. By operating from this hub, we can collaborate with top professionals to continuously enhance our security measures and ensure that our product remains at the forefront of privacy technology.

Earning Your Trust

We understand that we need to earn your trust, and we are committed to doing our best to achieve this. Transparency, rigorous security measures, and continuous improvement are at the core of our mission to provide you with a trustworthy and private device
Please leave some feedback for me and my team. If you have any other questions we would love to hear them and give you an awnser.

Kind Regards,
Seichs

 
The phone comes with pre-installed Secrypt Chat messenger - a secure and convenient communication application.
lol, I haven't noticed this at the first glance, now I'm even more confident that this is a honeypot by FBI.
 
lol, I haven't noticed this at the first glance, now I'm even more confident that this is a honeypot by FBI.
Completely understand the skepticism. We're here to build something genuinely secure and trustworthy, and we hope to prove you wrong by exactly delivering that! We will make all software completely opensource even the chat app,
 
Completely understand the skepticism. We're here to build something genuinely secure and trustworthy, and we hope to prove you wrong by exactly delivering that! We will make all software completely opensource even the chat app,
Answer to my message, please :)

> We are based in Switzerland
And share company details, who is CEO, etc
 
Пожалуйста, обратите внимание, что пользователь заблокирован
1735943604487.png
 
  • "Security First : We remove cameras, microphones and several other sensors from the device to ensure maximum protection of your privacy."
The only value in your sales proposition right here. I can just take my phone to a phone repair specialist and request these parts to be seperated?
  • Strong encryption and Titan M2 security chip : Protects your device and data from sophisticated physical attacks, keeping your information safe.
This is not your feature. This is done by Google.
  • Verified Boot : Ensures that the operating system has not been modified, maintaining the integrity of your device.
This is not your feature. This is done by Google.
  • P2P functionality : The phone works on a peer-to-peer (P2P) principle and uses servers only to establish a handshake, ensuring direct and secure communication.
What?
  • Connect via Tor network : Your phone connects to the Internet via the Tor network, providing anonymity and additional protection when browsing the web and communicating.
Orbot on the Google Play Store
  • Automatic Power Off Switch : The phone automatically turns off after a set period of inactivity, preventing unauthorized access.
Can be done through other simpler means.
  • Duress PIN : An emergency PIN that automatically erases your entire phone and data if you are forced to provide access under duress.
Forensics will clone your phone in any serious case.
  • Obfuscated PIN layout and privacy screen : Allows you to enter your PIN in public without anyone peeking. Alternatively, an integrated fingerprint sensor for added convenience and security.
GrapheneOS feature
  • Open Source and Certification:
    • Open Source : Open source code allows you to check for back doors and other security risks.

      Because you are using GrapheneOS

    • Attestation : Hardware verification of the authenticity and integrity of the phone's software, providing full control over the device.

      Because you are using Google Pixel
  • Exclusive device : Secrypt Phone with pre-installed Secrypt OS is sold directly from us. The phone comes with pre-installed Secrypt Chat messenger - a secure and convenient communication application.

    ANOM wiretapping technique

  • No Data Storage : No user data is stored. Users are not required to create an account to use the phone and the app.

    This is useless. Why would anybody buy your phone when they would gain all of what you just described by buying a Pixel 8 and flashing GrapheneOS, and afterwards installing Tox/Session?

  • Safe activation process:
    • The application comes with a physical activation code generated by us.
    • After activating the application, you can enter your username and password.
    • You will then receive 8 words that you need to save. These words are needed to reset your password.
    • Without these 8 words, you will never be able to change your password, and we cannot do it for you either.

      Security illusions, that hold little to no value because of the previous points.
  • Sealed Packaging : Secrypt Phone comes in a sealed box to ensure the integrity and safety of the device upon delivery.

    Great! I will buy this suspicious phone for everyone and as other people noted be put on a watchlist for doing that. I don't need to worry about tampering if i purchase from the electronics store with cash.


    Overall honeypot rating: -9999999/10
 
Answer my message, please:)

> We are based in Switzerland
And share company details, who is CEO, etc
We're two Cyber Security students—Seichs from the Netherlands and Spice from Switzerland—working on this as a learning project. For now, we're keeping our real identities private for security reasons. Inspired by companies like Nitrokey, our goal is to create a product that prioritizes privacy for journalists, aid workers, and those who need it most—not for illicit purposes. We're strong advocates for privacy and see this as an opportunity to learn and contribute to the field. And again we hope to prove you wrong.
 
We're two Cyber Security students—Seichs from the Netherlands and Spice from Switzerland—working on this as a learning project. For now, we're keeping our real identities private for security reasons. Inspired by companies like Nitrokey, our goal is to create a product that prioritizes privacy for journalists, aid workers, and those who need it most—not for illicit purposes. We're strong advocates for privacy and see this as an opportunity to learn and contribute to the field. And again we hope to prove you wrong.
> Nitrokey
is pure shit. selling overpriced items is shit.

U told u have company in CH - now no company and students.
Where is open-source repo?
Where is an audit?

U're not a like Nitrokey, u're like Krebs bastard.
 


Напишите ответ...
  • Вставить:
Прикрепить файлы
Верх