Showing posts with label mobile. Show all posts
Showing posts with label mobile. Show all posts

Monday, 20 June 2016

Phones Show Chat 347 Notes on Smartphone, Mobile and IT Security

I recently had the pleasure of being a guest on Steve Litchfield and Ted Salmon's Phones Show Chat podcast for episode 347, which was published on 19th June 2016. I've been a regular guest on the podcast over the years, and I've worked in the IT information security industry for 13 years (you can find me here and here for more details) which is probably why Steve and Ted asked me to discuss the topic in detail during the show.

We covered a lot of ground around mobile and IT security, with a lot of terminology and acronyms, so this blog post is designed to be a companion or reference to the podcast episode.

Let's start with some terminology:
  • Vulnerability. The bug, hole or weakness in the software or operating system, usual unintentional, sometimes maliciously inserted (aka the backdoor). This can lead to the ability to, for example, execute code or escalate privileges (obtain root or administrator rights) either locally on the device, or even more scary, remotely from afar. When there is a way to use the vulnerability to do such a thing, we have an...
  • Exploit. This is taking advantage of the vulnerability to mount a successful attack. A vulnerability can be known, and there may not necessarily be an exploit in the wild. Once there is a working exploit, we get even more concerned about a vulnerability, as before that point, threat is only theoretical.
  • Patching. This is basically updating software or operating systems, and should be done regularly. It will ensure that you receive fixes developed for known vulnerabilities. In the mobile world, this will come through your OEM/carrier for the phone OS itself, and the app store should be the mechanism for keeping apps up-to-date.
  • Zero Day. This refers to the scenario where a vulnerability exists but has not been publicly disclosed to the vendor. This is dangerous because the vulnerability could be abused and exploited by attackers, but if the developers don't know about it, they can't write and distribute a patch or update to close the hole. Zero day vulnerabilities with working exploits, especially for highly used systems like Windows, Android and iOS, can trade hands for hundreds of thousands of dollars on the 'dark web'. This ties in with...
  • Responsible disclosure. Where if you find a vulnerability, you should inform the developers privately, so they can fix the hole or weakness in the system. Not sell it on the dark web. Also, should you choose to publicise the vulnerability first, you give attackers a window of opportunity to exploit the vulnerability before the developers have had chance to fix and update the software. Publicise your great work finding the vulnerability after the fix has been available for some time.
  • Bug bounties. Companies will give money to people who find vulnerabilities in their products, systems and services and disclose them responsibly. This even includes The Pentagon! In the last year, Google paid out more than $500,000 in these types of rewards. This type of scheme hopes to make hackers disclose responsibly rather than trade on the 'dark web'.
  • CVE (Common Vulnerabilities and Exposures). This is the industry standard library of vulnerabilities, and gives us a uniform and standardised way to refer to vulnerabilities in precise language, rather than using common language which can get mangled, abbreviated, or otherwise abused or confused. Some vulnerabilities are so serious that the industry also gives them nicknames, like Heartbleed, Shellshock, and most recently Badlock. Sometimes these are justified to get publicity so we all make sure we patch our systems. Other times it is research organisation trying to publicise themselves.
  • CVSS (Common Vulnerability Scoring System). This it the industry standard way of rating the severity of a vulnerability. It uses factors like the vector used (is it local and I have to get on the system first, or can I perform an attack remotely), complexity of the potential exploit, authentication required, and impact to the CIA of data (confidentiality, integrity, availability).


At the end of day, security is about minimising risk to an acceptable level, and this is no different with our smartphones. Risk is classically defined as "impact x probability". The impact of the thing happening could be anything from an app crashing, to your whole phone and digital identity being stolen or abused. The probability of the thing happening depends on how easy it is for the attacker. Many attacks require users to be in one of 3 scenarios: installing apps from 3rd party app stores, to have rooted or jailbroken your device, or they require the attacker to be between your phone and the Internet, to have somehow got inside the flow of the network traffic (called "man in the middle", or MiTM). Classic MiTM is achieved with the public wifi scenario, where you think you are connecting to a safe wifi provided by a venue, but you are actually connecting to a wifi network created someone with a wifi pineapple or similar, and they're going to snoop into your data and try to attack you. Seriously, don't use public wifi unless you really need to, you just can't trust it.

These three scenarios (3rd party app stores, root/jailbreak, MiTM) are for most normal users, and even you technically savvy PSC listeners, quite unlikely. This is why my main conclusion on the podcast was that yes, it is shame that many Android phones are behind on OS updates and security updates/patches; it would be better if they weren't, but the risk to users is low. This is because whilst the impact or an attack could be very high, the probability is low, so referring the impact x probability calculation, the inference is that the risk is low.


It gets more interesting when we have vulnerabilities with higher probability...
  • Stagefright (a collection of at least 8 individual vulnerabilities, each with their own CVE number) made lots of news, partly because one exploit involved simply sending an MMS to an Android device, which by default will retrieve the multimedia content referred to in the message, and then execute code and escalate privileges. You don't need to use 3rd party app stores, be rooted, or have a MiTM.
  • XcodeGhost also made lots of news, based on the potential risk. A modified version of Xcode, the development kit for Apple apps, had been distributed in the Far East, and developers were using that version instead of downloading it from Apple, because it was quicker to download from the Internet than from Apple's servers in USA, so the theory went. This modified Xcode was then inserting malware into apps constructed with the development kit. Again, no 3rd party app store required, no jailbreak required, no MiTM required.
These two issues show examples where the probability is higher, principally because the user does not need to do something silly or out of their way to make the device more vulnerable. If impact is high and probability is high, suddenly that's a big risk. However, these are the exception when you look through all the mobile-related headlines about security issues or potential for attacks.


It might be easier for me to see through the headlines because I work in IT security, but if you read some of the following headlines, they sound very serious! I've listed each one along with the source of the headlines (generally IT security companies publishing things they've found, to flex their muscles publicly or show they have great threat research capability in order to help win business from enterprise organisations) and the methodology needed, to show that there's little here to be massively worried about for 99.9% of users...
  • "87% of Android devices insecure" (link)
    • Press release for research org, most need 3rd party app stores
  • "New type of auto-rooting Android adware is nearly impossible to remove" (link)
    • Security company research, 3rd party app store
  • "Devastating Vulnerability Affects 66 Percent of Android Phones" (link)
    • Security company research, 3rd party app store
  • "Critical Vulnerability Plagues 60% of Android Devices" (link)
    • Security company research, requires root
  • "More than a Billion Snapdragon-based Android Phones Vulnerable to Hacking" (link/link)
    • Security company research, 3rd party app store
  • “Android Installer Hijacking estimated to impact 49.5 percent of all current Android users" (link)
    • Security company research, 3rd party app store
Some 'news stories' are worse than others. Take this analysis of one such news story: “Our Symantec pals wax poetic for a whopping 750 words before mentioning a teensy, weensy asterisk to all of this: The malicious app is not found on Google Play and may be downloaded from third-party app stores, forums, or torrent sites. Users who have Google Play installed are protected from this app by Verify Apps even when downloading it outside of Google Play."

Here's a tongue in cheek summary from a well-known blogger in the IT security industry, he's worth subscribing to on YouTube as his videos are very entertaining... https://www.youtube.com/watch?v=W5gdAxAGRyo


Here's a summary and some closing thoughts and recommendations for mobile and IT security:
  • Software will always have vulnerabilities, software engineering is not 100% science (unlike some other engineering disciplines)
  • Remember, enterprises (£Ms of budget) are getting successfuly attacked, the attackers are very clever. However, mobile phones have a much smaller "attack surface" than enterprises with 1000s of Windows desktop PCs, so the odds or more in our faviour when considering smartphones alone
  • Best practices: never re-use passwords, use a password manager if it makes it easier; never open attachments unless you need to or were 100% expecting the attachment form someone; only use 1st party app stores; always accept updates for the OS and apps; avoid public wifi where possible.
  • Don’t confuse vulnerability with exploit. This might help you wade through the nonsense and sensationalist headlines.
  • Be annoyed that Android has a big problem with getting updates to users (through OEMs, carriers and many other obstacles) but also realise that you are far more likely to be exploited through your PC or laptop through things like malvertising via Flash, ransomware via attachments
  • You're also more likely to have digital accounts compromised through the services themselves getting hacked, like LinkedIn for example. By the way, did I mention...
  • Don't re-use passwords!
  • And please uninstall Flash on all your PCs and laptops as soon as possible, thank you!

Saturday, 14 November 2015

DIY Sony Xperia Z1 Compact Refurbishment

Somehow, on 29th and 30th of October 2015, I managed to crack the screens of two phones in two successive days.

  • First, my primary device at the time, the Sony Z3 Compact. Not only did the screen crack, but the digitiser failed too, I couldn't even unlock the device. I moved to an old backup device, the Sony Z1 Compact.
  • A day later, I cracked the screen on the Z1 Compact! I was clearing out some dirt from the earpiece with the pointed end of a safety pin. Innocuous! Same result, cracked screen and the digitiser failed so I was unable to unlock the device.

Unlucky? Careless? Either way, the devices had not been subject to any unusual conditions, heat or cold. It's not really surprising that they failed in the same way given they were made by the same manufacturer, but plenty of phone screens crack and leave the digitiser operational, giving you a 'grace period' to get a replacement sorted! I must also add that these phones between them have had around 3 years of daily use, but the digitisers still seem fragile in my opinion.

This all happened 4 days after I was a guest on the Phones Show Chat podcast, where I was complementing the Sony Compact range in general, and confirming I was really looking forward to the Z5 Compact! Timing...

Following a successful Nexus 4 screen replacement last year, and yet-to-be-blogged iPhone 5 screen replacement a few months later, I confidently ordered replacement parts to fix both phones. Here's the Z1 Compact screen replacement.

WARNING: This is not a "how to", should not be mistaken for step-by-step guide, and contains very mediocre photography...

A broken screen and knackered digitiser too:

The screen and digitiser came as a single unit, but did not include the adhesive, so I ended up ordering this separately which set me back a few days:

Removal of the old broken screen is as simple as applying heat (YouTube videos will say use a heat gun, I find a hair dryer works fine), then lifting the screen with plastic tools. The one supplied here looks suspiciously like a guitar plectrum:

Here you can see Sony's factory-fitted screen protector getting in the way; peel this off then get on with removing the actual screen:

Here you can see the adhesive clinging on as the screen is lifted from the chassis:

Having disconnected it, the old screen lies next to the chassis. It's best to remove and clean up as much of the old adhesive as possible, to ensure maximum effectiveness of the new assembly:

Attaching the new screen and doing a power-on and touch test before is always a good idea before fully sealing it to the phone...success:

Having peeled away the film on one side of the adhesive, you can see where it will line-up inside the chassis, around the front-facing camera and earpiece:

Adhesive applied to the chassis, now peel off the blue film, then connect and place the new screen into the chassis:

All done! There is one more step advised, which is to either place the device in a clamp, or between heavy books, to ensure the adhesive gets to work properly. I did the latter, overnight, and it has worked perfectly:


From a stint being lent to a less-then-careful family member, the back of the Z1 Compact was pretty knackered as well, so I'd also ordered a new back cover. You'll find straight replacements made of glass, but also polycarbonate plastic back options too, which I opted for due to cost and durability.

Here's the old beaten-up back cover:

Same as the front of the device, heat up and pry the back cover from the chassis, then remove all the old adhesive and clean up the surfaces:

Then place the adhesive and the back cover onto the chassis. As with the front screen, some pressure from a clamp or heavy books for a few hours helps the adhesive get to work properly:

The total cost was £32, and 50 minutes of my own time to do the whole job, including the screen and the back cover. It was nowhere near as complex at the Nexus 4 or iPhone screen replacements; no screws, no removing components to gain access to remove the screen or back cover, just heating up to loosen old adhesive, and put new adhesive and new parts onto the chassis!


Photos taken with Nokia Lumia 930, a long-term loan courtesy of Steve Litchfield.

Thursday, 30 July 2015

Android Updates with New Permissions

Permissions, the system by which apps declare which hardware or special functions they wish to use, are getting a huge overhaul in the next version of Android, codenamed 'M'. Full details can be found here, with a slightly more palatable version here. This may or may not make developers more aware of the impact of the APIs they use, declare, and how users view, care or don't care about how apps use the hardware and special functions of their Android devices. Certainly a recent published vulnerability within Stagefright (an Android component) has given Android security the unwanted spotlight yet again, so both enterprise and home users alike may be getting more wary, we can only hope. I wrote about the need for a better security patching system for Android 15 months ago, and nothing has changed, it is still a problem given the Stagefright vulnerability.

However, with the current system of permissions declaration in play for a number of months yet before 'M' is released, and perhaps even longer given the slow roll-out of new versions of Android across manufacture and carrier variants, here's some examples of how permissions should and shouldn't be dealt with! Android users will know that in some app updates, developers add features which require them to use extra permissions, and these are displayed to the user at update time.


Case 1

Here's an example from a voicemail app, which for some reason now wants extra permissions from no less than 9 different categories:



When developers publish app updates, they are encouraged to give proper release notes, explaining what has changed in the new version. Here is the accompanying text:




They seem like mainly fixes, improvements to existing features, and that's about it. So why all the new permissions? Why should I be happy, as a user, to suddenly allow this app to get much more of the content and functionality within my device? I contacted the developer, and the response below seems to suggest they were forced into declaring all these permissions just to add badge support for the app's icon in the various launchers.

"Unfortunately we had to add them in order to set the badge counters but they are ALL related to that and are specific to different launchers from various manufacturers and third parties."

This may or may not seem appropriate to you. most apps asking for further permissions are usually legitimate, and sometimes Android will put developers in a corner with certain APIs and permission. However, it would have been far better to include reference to this in the release notes.

Case 2

Here is an altogether better example. This is a password management app, which itself was in the news for a breach last month, but takes a different approach. Here's the app update, and the new permissions it wants to declare:


Not as many as the voicemail app, granted, but still permissions I might be interested in if the privacy of my location is very important to me. Let's see what the release notes say:


A full list of new features, with new permissions called out where they are needed. Much better, more transparent, and the users understands why they are required. Furthermore, for extra credit there is a link at the bottom which follows through to their website, where every single permission used by the app is described in detail, not just the new ones.

 

Now, if I didn't want the app to use the new permissions, I only have one choice; don't install the update. This becomes tricky if I want other new features of fixes, as a user I can't be granular. However, as previously described, the new version of Android, 'M', is due to make significant improvements to the granular control and to the user experience of being notified that apps are using certain hardware or software functions.

And finally...

Whilst we're on the topic of app updates, a special mention has to go to Shifty Jelly for their Pocket Casts release notes. They do the job of describing new features and permissions required, but also include some great humour at the same time, always amusing!

Tuesday, 12 August 2014

DIY Nexus 4 Refurbishment

At the time of writing my full-time device, for work and play combined, is a Moto G. There's nothing much to tempt me away at present, given my usual caveats about "phone-sized phones" and wanting decent value for money. My better half dropped her old Nexus 4, several times, until the digitiser finally gave up and she inherited my unloved Z1 Compact. Whilst I wait for my next phone to be announced (Moto X2? Moto G2?) I decided to refurbish the Nexus 4 myself, and here's how it went...

WARNING: This is not a "how to", should not be mistaken for step-by-step guide, and contains very mediocre photography...

I had nothing to loose. The back had been cracked and smashed for a while before the final accident which took out the screen glass and digitiser, leaving the touch screen completely dead. The phone was as good as useless, so I couldn't really make it less functional with my average DIY skills!



For less than £40 I was able to source a replacement screen/digitiser unit and a back glass panel from eBay. I opted for just the glass panel for fixing the back of the Nexus 4, although you can get the whole back case unit including (or excluding if you wish) the coils for wireless charging and NFC.



The screen/digitiser unit included a set of "handy tools". The Torx screwdriver was actually too small, so I ended up using my own.


The back cover is mostly cosmetic on the Nexus 4, so I opted to start with the more important screen/digitiser. A couple of Torx screws and some levering with the plastic tools and the back cover popped off. A further 11 or 12 small Philips screws later and the battery and plastic motherboard covers were free and removed. The battery in particular was held in place with strong adhesive, this took some encouragement to release from the case!



The links between the motherboard, daughter-board and other components like the rear-facing camera and 3.5mm jack were next to be disconnected, then each of those parts were removed from the device. Knowing I had to put this bunch of parts back together once the screen was replaced, I scored geek points by numbering the components as I pulled them out, making re-assembly much easier.



At this point "the device" was was just a screen/digitiser and some side buttons! This matched (almost) the state of the screen/digitiser unit I had been supplied. The compare and contrast was interesting, as the numbers of the parts didn't totally match from the original. I wasn't surprised, this would most likely be the evolution of the manufacturing process during the time the Nexus 4 was being manufactured, leading to different part numbers along the way.




One genuine omission on the new screen/digitiser unit was a diffuser which should sit in front of the notification LED. On the left the original clearly has a white diffusing layer, which is actually secured between the screen and the casing. On the right, there is no diffusing layer, you can see straight through to the black outer casing, which is almost transparent when any amount of light is present. I added my own diffusing layer, made crudely from printer paper, but it seems to have done the job!



Re-assembly then began, starting with the side buttons, the camera, the 3.5mm jack, the daughter-board, the main motherboard, the plastic motherboard covers and the battery. I had a scary moment when the device didn't power up after re-assembly, but a few minutes on charge from a wall socket subsequently revealed the battery was flat. In hindsight this makes sense; with touch input not working, I was unable to actually turn off the Nexus 4 in its broken state, so I most likely left it in a corner somewhere where it would have drained entirely!



With the screen/digitiser replaced, I started work on the back cover. Having gone for the cheaper option of purchasing just the glass panel and not the entire casing unit, I had to remove the old glass panel fro the plastic outer case. The glass was already shattered in one corner, so starting there I began to pull apart and pick out the shards of glass. The NFC/wireless charging coils made this job trickier; they are on effectively a gold sticker, pressed onto the inside of the back cover. I had to peel this off the old back cover with some force due to the strong adhesive, but not so much force as to break or tear the coils!



The plastic table cloth was very useful, as at the end of this glass work I was able to round up and dispose of the large amount of small pieces of glass, not the kind of stuff you want to be on your kitchen floor when you're walking in barefoot to get your breakfast in the morning!



Having picked out all the glass pieces, the back cover was free of its original panel. Almost. There were still many bits and pieces of glass and other dust and grime, which would need to be removed to ensure a good adhesion with the new panel. Some rubbing/cleaning alcohol and cotton buds did the trick to clean up the plastic case ready for the new panel.



Before assembly, a compare and contrast was again interesting. The new glass panel did not include the speaker grill, or a small square rubber spacer around the rear-facing camera. They were relatively easy to transplant to the new glass panel however.



The last steps were the placement of the glass panel on the back cover case, and attaching the back cover to the device again. One more boot up confirmed that the back cover work had not broken anything, and the refurbishment was complete.


Whilst I've flashed more ROMs and rooted/jailbroken more phones than I'd care to mention, I've never attempted any hardware work on any smartphones, so I was chuffed that this one worked out well. Given this was a popular device, there were lots of helpful articles and videos on the Internet for reference, so I didn't have to do much brain work myself! I just has to ensure I wasn't too clumsy with the small components and delicate electronics! Having brought it back to life, I'm looking forward to using the Nexus 4 with its beefier specs compared to my Moto G, and hopefully it will tide me over until my next phone is announced and released!


Tuesday, 15 July 2014

Feels Like a New Moto G

I factory reset my Moto G last night and set everything up from scratch. I'd not done this since I bought the phone 7 months ago. It took until past midnight, and I was short on sleep anyway!

However, battery life in the 48 hours since the reset has been much better, and the feel around the operating system is much quicker, along with only one app crashing where previously there would have been several. This is with the same set of apps and data as before the reset. To be complete in the detail here, that 7 months usage did include the update from Jelly Bean to KitKat. The conclusions are therefore:
  • Android now behaves like Windows, in that users who consume lots of software/apps/services will accumulate crud, which over time slow the device down and make random things (crashes, force closes) happen, and only a fresh install gets you back to the speed and stability you know the hardware is capable of.
  • Major version updates of the operating system should always be followed by a factory reset where possible.
  • Android's native backup and restore of apps and app data is still pathetic, and very rarely restores a complete set of apps or app data, if it starts at all. There’s very little control of how it happens, and no web portal to see the apps Google has linked to your account, such that you know the apps it will restore, and have a choice to prune the list. Android is far, far behind iOS in this area, which has had flawless back and restore for years.
  • The Moto G really is a brilliant device, especially given the context that this (albeit non-4G variant) 16GB model cost me £81 brand new from Tesco with ClubCard vouchers plus £3 for a SIM unlock.
None of this is news par se, but as one of those annoying folks who wants his phones to be "phone sized" (that's around 130mm x 65mm for me) it does justify my feeling that there isn't a better phone out there for me right now, over 7 months after the Moto G originally 

I've been tempted by a Moto X, the natural migration path in some ways from the Moto G, but as it is now a year old, a successor is likely around the corner. Given the Samsung Galaxy S5 Mini and HTC One Mini 2 were both disappointing and overpriced, my hopes for a new phone-sized phone to purchase seem to rest on rumoured devices such as:
  • Sony Z2 Compact, where they'll hopefully have fixed the Z1 Compact's problems like the under-performing camera, the nasty factory-fitted screen protectors, and the chassis design that makes it feel larger than it is.
  • Moto X2, where they'll have a much better camera in than that on the Moto X, and release it in the UK promptly (versus 6-7 months delay on the Moto X after it launched in the US)
  • Some other thing that's a bit off piste and will surprise me into a purchase (a small Xiaomi device, a OnePlus One Mini, etc)
That list doesn't include anything too concrete, or even anything likely to be released in the near future. It's just as well this feels like new Moto G since the factory reset, as I seemingly won't be buying anything actually new any time soon...

Friday, 13 December 2013

The Moto G, And Updating Without New Firmware

It's widely recognised that Motorola, now owned by Google, have created the best value-for-money phone this year in the Moto G. I managed to get hold of the 16GB model from Tesco in the UK for £81! It retails for £129 normally, but Clubcard vouchers brought that down, and with a £2 SIM unlock from eBay, it is comfortably amazing value for £83 all-in. However, in the week since I've had the device, it's something less obvious which has surprised and impressed me.

The first was on 9th December 2013, when the list of apps with updates in the Play Store included "Motorola Boot Services". Whilst the update description merely said "Enhancements to the power-up experience", the update actually changed the initial boot-up animation to a Winter-themed one. I've meddled with boot-up audio and animations before on other devices, but that required you to have root, as it would mean replacing protected system files. Motorola have however built the Moto G firmware such that a Play Store app is able to modify these system files. A new boot animation capability isn't going to change the world, but it's something I've not seen any other Android manufacturers put into their devices, and is a nice touch and something different from Motorola, as well as a pretty clever idea. I also love that the boot animation app package is called moodles! (com.motorola.moodles)



The second was yesterday, 12th December 2013, when another Play Store update caught my eye, "Motorola Camera". The LG Nexus 5 launched with Android 4.4, and was updated recently with new firmware images to 4.4.1 and 4.4.2. Whilst the 4.4.2 update's change log was slightly shrouded in mystery, the 4.4.1 update definitely contained camera app improvements. This is great for the Nexus 5 owners, however, the clever thing Motorola have done by siphoning off the camera app into a Play Store updatable package, is to allow updates to the camera app without touching the entire phone's firmware. That means much less hassle getting the firmware updates tested, regression tested against existing functionality, and then getting it approved and tested by networks/carriers around the world.



A look at Motorola's entries in the Play Store (below) shows there are quite a few apps which can update via the Play Store, including the FM Radio, the Migrate app, the Assist app, the SMARTACTIONS app... All of these can be updated without the need for the lengthy process of building, testing and network/carrier approving a new firmware. Google Play Services was updated at Google I/O this year which allows core APIs, services and apps to be updated by Google without manufacturers releasing new firmware as well. Google have also started to release other apps into the Play Store such as Calendar and more recently Keyboard, and the likes of GMail, Maps and YouTube were already updatable through the Play Store, so all your core Google apps are updatable without firmware updates too.



The sum of all of this is that whilst the Android version problem is not getting any better, the version problem itself is in fact becoming less and less of an issue. Getting those version updates for your non-Nexus phone, give or take the highly popular devices like the Samsung Galaxy S4 or HTC One, is slow due to development time and network/carrier approval process. Or for many other devices updates never happen at all! Now however there is an argument that you're not missing out on a huge amount if you're not running the latest point release of Android, given all the other software components can be updated outside of firmware updates, and especially if you have a Moto G of course!

Monday, 23 September 2013

iPhone 5c Lust!

Unfortunately, I believed the rumours leading up to the Apple launch event on 10th September 2013 which were suggesting that the new colourful iPhone would be a "cheap" device, maybe even so cheap that it would be within reach of the those in developing countries.

As a mobile enthusiast, if you want to be able to comment on the industry, be able to genuinely make comparative commentary between devices and ecosystems, you simply have to have an iPhone. That or have very convenient access to one, and with my better half moving from iPhone to Android, that's left me needing one of my own. Whilst not the biggest by market share any more, the iPhone is still arguably the single most important device, if not the most important ecosystem, and every product announcement, price change or hardware glitch becomes mainstream news.

Apple's service of keeping older handsets eligible for newer operating systems is very commendable, something which is much easier to maintain when you don't have the disconnect between one company writing the operating system source code, and another company making the hardware and customising the operating system almost to their heart's content. Android phones in particular can find themselves stranded on very old versions where a manufacturer has seemingly lost interest. Yet it is only this year that the iPhone 3GS, released in 2009, has fallen off the support train being the newest device not to have iOS 7. This however means that the old 3GS I can see in the corner of the room, next to a bunch of charging cables and a couple of old Android phones, is no longer good enough for that job of being a relevant comparison device.

So with the rumours of the 5c being such a cheap device, I was quite excited at the thought of being able to buy an iPhone again. It's not feasible to buy full-priced, or even second-hand iPhones of the latest generation or two when you are using them as comparison devices, they're simply too expensive (although they do hold value very well of course). I reckon anything up to £350 at a push and I was in, and the fact that they were coloured only made me lust more. 

I'd already been eyeing up the HTC One Mini in blue, and I'm glad that manufacturers have started building colourful devices again. The multi-colour approach has in recent years been most utilised by Nokia in the Lumia range, and I really hope they've sparked all the manufacturers to think again about colour, and take us away from the land of black rectangles!

Needless to say I was of course then disappointed when Apple announced that the iPhone 5c would start at £479, completely out of the price range for a device used mainly for comparison purposes. Not only that but as I buy all my devices SIM free, it is probably too expensive even to buy as a main device, and I'm not even sure I could live with iOS on my main device even if I thought I could justify the cost.

We now know that the iPhone 5c was never going to be a budget device, and actually sits nicely between the 4S and 5s (yes, one is upper case and the other lower...) in the Apple range, allowing Apple to drop the iPhone 5, and presumably make a lot more margin on each 5c they sell, boosting profitability, whilst adding new marketability and product differentiation in the 5c with its coloured casing. Very smart move as ever from Apple, but a shame for me and anyone else who were excited to pick up a shiny new colourful budget iPhone!

Tuesday, 23 July 2013

BlackBerry Q10 Mini-Review


Thanks to Steve and Tim from Phones Show Chat, I've been lucky enough to get a short loan of a BlackBerry Q10, and I've been testing it out as my almost day-to-day work phone*. All email and Internet access plus outbound calls have been on the Q10, leaving only inbound calls on my previous handset. I was concerned that in going after the consumer market, BlackBerry's version 10 operating system would lose some of the efficiencies of its predecessors as a raw efficient phone call and email machine, instead going after flashy graphics and fancy gesture controls. Well, they have indeed gone after those features, but the physical qwerty keyboard is happily alive and well! This is only a mini-review due to the short time period I had with the handset, and that I was unable to get enough time to test out some major features with a busy workload!

*The almost is because there was simply too much hassle in 1) cutting up my current mini SIM into a micro SIM, plus 2) getting the IT department to remove the BES service on my account, then have it put back on a week or two later!


The Q10 is BlackBerry's latest incarnation of their most traditional form factor; the wide candybar with a physical qwerty keyboard. It's where they made their name many years ago, and is still what most people think of when they hear the word BlackBerry. It's also a favourite form factor of mine for work and getting things done, having already tried touch-based keyboards for the that purpose. When typing acronyms, technical terms, names and lots of punctuation into emails whilst on the move, which my job regularly requires, I still find there is nothing better and more efficient than a physical keyboard. Unfortunately for me, there can't be much other demand in the market for this, as this form factor is now an endangered species.



BlackBerry OS 10

The Q10 launched with BlackBerry OS 10, which is a big departure from the recent BlackBerry OS 5, BlackBerry OS 6 and BlackBerry OS 7 versions seen on the last few years' worth of Bold, Curve and Torch devices. Out go a lot of the old style menu driven functions, and in come swipe gestures. Out goes the entire concept of a traditional home screen used by iOS, Android and Windows Phone. Out goes the nasty low resolution displays and slow CPUs and in comes a lovely screen, lots of RAM, and with it some very nice transition animations. Fortunately this all runs very smoothly, which is probably no surprise given that BlackBerry OS 10 is built on QNX, a real-time operating system built to be dependable and lag-free in multi-tasking environments. Seriously  the animations around the OS are buttery smooth, to borrow a phrase from Google! At the time of writing the Q10 was running version 10.1, with version 10.2 allegedly being around the corner based on leaks into the wild earlier this month.

The new gesture controls take a while to get used to, as does the lack of a genuine "home" screen. The "main" screen is arguably the multitasking view, which gives a vertically scrollable 4x4 list view of running apps, which works really well. Swiping to the screen on the right gives you a horizontally scrollable app drawer, where apps can be re-ordered and put into folders like iOS and many Android-based devices. Swiping to the left from the multitasking view takes you to BlackBerry hub, a unified messaging area for all your email accounts, SMS, BBM, notifications, and calls. Swiping down from the top of the screen in any of these views brings up quick settings for WiFi, Bluetooth, Alarm and a link to the main settings area for the whole device. Within some individual apps this top down swipe gesture gives you the app's menu area, and commonly the app's settings and shortcuts. Swiping from the bottom of the screen upwards at any time takes you back to the multitasking view, which as previously mentioned makes this view (arguably) the home or default screen if you were forced to pick one. Check the bold sections there, that's a lot of gestures to remember! As a full-time geek I found I got my head around this eventually, but I'm not so sure the average user would find this easy at all, especially compared to simpler user experiences and paradigms found in iOS and Android.


Multitasking App Drawer

It should be noted that BlackBerry no longer requires BES or BIS connectivity with OS 10, where OS 7 and previous did. For the average user this is great, as BlackBerry bolt-ons for BIS were only ever confusing, and forced traffic through BlackBerry's own servers which weren't known for their stability, particularly during 2012. For business use, a server-side upgrade to BES 10 is required for the handset to use BES to sync email and PIM data. With my employers not forking out for this paid-for BES 10 licence and upgrade, I opted instead to use ActiveSync. In practice this worked just fine, although during my test period I found it to be 10-20 seconds slower updating email and calendar entries. The standard Microsoft Exchange-based remote wipe functionality wiped the entire device, as opposed to removing the ActiveSync account and its related data.



Apps

My primary use case during this brief period was for work purposes, which only really needs call, SMS and email functionality, and these all pass with flying colours. I use Evernote a lot, and was excited to find it was integrated into the OS. Until I found it was very basic, not even bringing in tags for example. There is no standalone Evernote app, as there isn't for many other marquee services and apps found on iOS and Android, and even Windows Phone in a lot of cases (probably because Microsoft are paying for them). This was one of the areas I didn't have time to fully explore though, as I was using the Q10 only for work purposes, but anecdotally there do seem to be many big-name apps missing from the BlackBerry World app store, and quality games also seemed hard to find. If I were to have the handset for personal use, I would also have tested Google services integration, and was unsurprised when I found very little in the way of first-party Google apps in BlackBerry World, instead finding third-party paid apps for access to Drive and Maps for example. Note that anyone using Google 2-step authentication will have to use an application-specific password to add your Google account for email, calendar and contact sync.

One very interesting feature I ran out of time to test was being able to run Android apps within BlackBerry OS 10. At present this is limited to Gingerbread (v2.3) compatible apps only, but version 10.2 is rumoured to bring support for Jelly Bean (v4.1) apps.

Hardware

This is the best hardware qwerty keyboard device I've used. Unfortunately that's not a great accolade, as all the other efforts in this area, particularly the Android-based ones, were so incredibly poor. We haven't seen an Android phone with physical qwerty keyboard in the UK since the Motorola Pro+ in December 2011, which is 18 months ago, and that too was poor, under-powered and underwhelming in almost every way! There is no such thing as an iPhone with a physical keyboard, and next to none for Windows Phone. The last big stand on physical keyboards outside of BlackBerry was by Palm (subsequently bought out by HP) with the Pre range of handsets, and that didn't end well! So it seems this is a dying breed, which is a real shame for those who love the form factor.



The keyboard buttons have slightly softer click than previous BlackBerry models, but still retain the per-button curved raised edge, making each button easy and quick to locate under your thumbs. I found I was equally fast on this keyboard as I have been on all the previous generation of BlackBerry handsets. The overall build quality is great, very sturdy, and has a great feel in the hand. I didn't have much chance to properly try out the camera or speakers in any meaningful way, but quick tests showed them to be no cause for concern.

Conclusion

Again, I must stress this is mini-review only, and I lacked enough time to properly test things like the camera, using Android apps, and many other consumer-facing apps, features and integrations. However, as a business tool and a natural successor to the Bold and Curve ranges, I was pleased to see that the new BlackBerry OS 10 direction had not detracted too much from the origins of being a very efficient business tool, and whilst it is a little larger than previous models to accommodate a bigger screen, I could definitely use it day-to-day at work. It's great to see a manufacturer put some decent specs behind a handset with physical qwerty keyboard, but I'd still prefer it with Android or even iOS if I were to have the handset for personal use as opposed to work use.