Skip to main content

Bought a Blackphone off eBay? An update could brick your device

blackphone update bricks devices 2 official 02a
Owners of Silent Circle’s security-minded Blackphone who purchased the device from vendors other than the company itself or one of its approved sellers are finding themselves with a security-minded paperweight after a recent update. Thing is, the update is functioning precisely as Silent Circle intended.

In an effort to crackdown on gray-market devices that have been manufactured without the company’s consent or are straight-up counterfeits, the 3.0.8 release of Silent OS, which was pushed to the Blackphone 2 last week, deliberately disables phones that Silent Circle identifies as fraudulent. The company warned potential buyers against buying from unauthorized resellers on January 16 before issuing the update.

Recommended Videos

A user in Germany shared his experience of a bricked device with Ars Technica on Friday. The owner purchased the phone off eBay and reports that, after upgrading to 3.0.8, he was hit with the following message:

“This smartphone has been identified as an unlicensed device. Only Blackphones sold through accredited vendors are authorized to operate SilentOS. SilentOS has been disabled on this device.”

The message invites users to contact customer support if they believe their device is legitimate.

When the individual reached out to Silent Circle, a representative responded that the IMEI number provided was not that of an official Blackphone, and the company could not provide any further assistance.

“Silent Circle is aware that unauthorized devices have been manufactured as Blackphones and we’re working aggressively to stop the sale of those,” said Blair Young, Silent Circle’s VP of Product Management, in a statement. “As we’ve counseled, it’s imperative for consumers and companies to work directly with authorized sales partners when purchasing the Blackphone 2. We invite people to check with us prior to purchasing, so we can help them be sure they’re securing an authorized phone to ensure they get the software and services that come with it.”

Of course, purchasing a phone designed primarily to be secure from a potentially disreputable eBay seller is certainly counter-intuitive and Silent Circle cannot guarantee the protection of such devices. However, the company’s decision to brick illegitimate Blackphones is controversial, as buying from resellers is fairly common practice with smartphone buyers.

Adam Ismail
Former Digital Trends Contributor
Adam’s obsession with tech began at a young age, with a Sega Dreamcast – and he’s been hooked ever since. Previously…
How to control which apps access your location on iOS and Android

Do you feel comfortable knowing that an invisible force follows you, shadowing your every move all day every day? It sees specific places you go and the duration of your stay. It follows your route around town and then your return back home. How, you ask? Through your smartphone and apps.

The idea that unknown companies can and do constantly track your whereabouts can be unnerving. But you can put a stop to it right now. You can determine what apps are collecting location information and then learn how to use your phone's built-in controls to limit sharing your life with these strangers.

Read more
Update your Twitter app right now if you’re on Android
Hand holding a Twitter phone

Twitter says it has patched a vulnerability inside its Android app that could have potentially let malicious actors view information of private accounts and take over profiles through an intricate back-end process. If a hacker managed to exploit the loophole, they could send direct messages and tweets on the target account’s behalf.

The social network claims so far it hasn’t discovered any affected user, nor found evidence of whether a third-party service has taken advantage of the bug. However, Twitter is reaching out to the people whose details may have been exposed. It’s unclear how long the vulnerability was left out in the open. The issue is not present on Twitter’s iOS app.

Read more
Update your Google Chrome browser now: New exploit could leave you open to hacks
Google Chrome Stock Photo

If you’re a Google Chrome user, you should update the browser immediately. Google released a software update to the browser late yesterday evening that patches two zero-day vulnerabilities to the browser that could potentially allow the browser to be hijacked by hackers.
One of the vulnerabilities affects Chrome’s audio component (CVE-2019-13720) while the other resides in the PDFium (CVE-2019-13721) library.
Hackers can corrupt or modify the data in Chrome’s memory using the exploit, which will eventually give them access to the computer as a whole.
One of the exploits, CVE-2019-13720 has been discovered in the wild by researchers at Kaspersky.
Google says that the update to the browser will be rolling out to users automatically over the coming days and weeks.
That said, if you’re a Chrome user it would be more prudent for you to go ahead and do that update manually right now instead.
To make it happen you’ll want to launch Chrome on your computer and then click on “Chrome” in the menu bar followed by “About Chrome.” That will launch the Settings menu. From there,  click “About Chrome” at the bottom of the menu on the left. That will likely trigger an automatic update if yours hasn’t already happened. If it doesn’t, you’ll see a button to manually update the browser as well.
Once you update the browser you should be good to go without fear of the security threat becoming an issue. Last month many Mac users ran into issues with Google Chrome when it seemed to send computers into an endless reboot cycle.
An investigation by Mac enterprise and IT blog Mr. Macintosh found that the issue was actually a bug that deletes the symlink at the/var path on the Mac it’s running on, which essentially deletes a key in the MacOS system file.
That issue only impacted Macs where the System Integrity Protection (SIP) had been disabled. The issue particularly impacted older Macs that were made before SIP was introduced with OS X El Capitan in 2015.
All this comes as Google is gearing up to launch some major updates to Chrome, including one update that will change how you manage tabs using the browser. That update is expected to roll out later this year.

Read more