The nay sayers of Twitter - The drone of the security expert

11.11.21 01:05 PM By Craig

Andy Warhol spoke of everyone getting their 15 minutes of fame & with the fall of Encro, Omerta's web traffic went from 100 visits on a good day to over 1500 (peaking at 1814). We launched in January & in 5 month we generated 5000 visits. On publishing the article about Encro being hacked, web traffic increased exponentially & in the previous week we received 10,000 visits over 7 days!

AND with a wider audience comes wider scrutiny & with that the nay sayers, the pessimists, the scaremongers, the scam artists & the IT Security Expert, whom seemingly have the social charms of a hungry bear with a sore head whilst the vision & imagination of a cardbox. So far this week we've had every nook & cranny of the business put down, dismissed, ridiculed and generally scoffed. 

Now because Twitter is limited to 140 characters, it's a great platform for attacking individuals and really poor for putting across a counter-argument whereby the devil is in the details. Because of this, I felt it better to address the numerous point on a platform that allowed more than 10 words!

OMG!!!! Military Grade encryption - ha ha

 According to Nord, makers of one of the best VPN, the definition of Military Grade encryption is "Military-grade encryption refers to AES (Advanced Encryption Standard) with 256-bit keys." And on review of GrapheneOS you will find "The GrapheneOS scripts (make_key and encrypt_keys.sh) encrypt the signing keys using scrypt for key derivation and AES256 as the cipher." So GrapheneOS has military-grade encryption. 

Clearly comments such as in the title are posted in a derisory way as if to discredit me for using terms which have no basis in reality. However, the term is factually true. 

Now the IT crowd forget one important thing here - marketing. I make a living selling these phones & people have short attention spans. I have to use snappy, headline-grabbing terms as I am in competition. I'm selling a boring IT security device to the layperson so the copyright has to be interesting, educational, captivating & instil confidence.

I will openly acknowledge we use terms which have no IT basis whatsoever - the one I noticed on first selling phones was "Encrypted USB Port" - as if the USB port is encrypted. But the layperson has been educated to think this means data can't be extracted by Cellebrite.

We openly acknowledge that Encrypted SIM card is a very misleading name but because they already had that name associated with them prior to me stocking them, the term has stuck.  

So my copyright might be creative because without it I am empowering my competition & creating a disadvantage for myself.  

OMG!!!! You're charging $4k for a phone!

The first round of insults stemmed from the deep & unsettling shock that Omerta charges $4K per phone. This figure was bounced about a number of times & besides the perpetrators being deeply upset, it also highlighted how little time they took to actually read & digest our site.

TO BE CLEAR WE DO NOT SELL ANY PHONES FOR $4K. 

For starters we don't trade dollars. Secondly, we don't have any phone selling for anything like £4,000. We have a BUNDLE which constitute of a £1000 phone, a £1260 subscription package & £1200 Data package. 

Since we are a eSIM stockist, a huge chunk of the eSIM cost goes straight to the supplier  & believe it or not, managing a system that allows phones calls from any network, anywhere in the world, whilst maintaining a fleet of servers for processing lord knows how many tens of thousand calls per minute is expensive.

So point 1 - WE DON'T SELL $4K PHONES.

OMG!!!! That's just a phone with commercial PGP software

This one p*ssed me off - because it demonstrated a total lack of understanding of my business. Which is fine. But don't judge us & slate us in public until you've actually understood what we do, because all you are doing is generating a negative image & possible affecting my ability to put food on the table. 

So, to be clear, WE DO NOT USE ANY COMMERCIAL SOFTWARE & DO NOT USE PRETTY GOOD PRIVACY.  The person in question then uses the above statement to reinforce their argument that Omerta provides no value. 

If you are going to make statements which are intended to cause reputational damage, verify the first. We use Open Source software which is proven to provide privacy & an Open Source security hardened OS which has support from Edward Snowden, CIA whistleblower & Senior Technical Advisor.

Lord knows where PGP came from. We have no mention of PGP anywhere.

OMG!!!! You can't run a business which sells phones which anyone can make

If anyone statement highlighted just how completely out of touch some IT professionals can be, it is this one. 

It angered me on so many different levels. Firstly, the notion anyone can do what Omerta does. To be clear, installing an OS on a smartphone is widely documented on Youtube & various websites. But this doesn't mean everyone has the ability, want, will or time to learn. Secondly,  it shows how little value IT professionals put in their work - I've never seen solicitors openly berate the costings of a rival firm because they don't devalue their craft. Yet here are IT Professionals openly devaluing their profession to try in the hope it grants them more credibility.

Is there any difference on an independent business taking PC stock, installing WIndows 10 & selling the hardware on for a profit? No...So why is it different when I do it?

Besides the product, I provide 24/7 customer support, professional documentation, device customisation and support outside the handset - all built into my costs.

OMG!!!! The FSB is listening to your calls!

The accusation, based on no background information about my suppliers, is that because the servers exist in a country which is repressive, there is no way I could have a reputable supplier. The system we use employs encryption & cuts calls off after  7 minutes, so calls can't listen too or decrypted. Besides the encryption, the calls are anonymous anyway, so if anyone was eavesdropping they'd have no idea of who they were listening too.

OMG!!!! You use Shopify!!! And Google Analytics!!!

I found this to be utterly incredible - my front of house being slated because it doesn't meet some unspoken privacy standard of an absolute stranger. They would expect me to remove every tool used by my competition and thus reduce any competitive edge & run my business blind. Speak about setting up to fail. 

Let me be clear, I sold my car in January to set up business. That meant I needed to be trading as quickly as possible. I also needed a platform that allowed for the following:

  • Enabled me to focus on creating content 
  • Was fully managed to reduce any overhead associated with managing a complex e-commerce solution.
  • Had security managed as part of the monthly subscription.
  • Was widely compatible with a variety of cloud services
  • Would scale up on demand
  • Have a good selection of high end templates.
  • Have a back  end which streamlined running a business
  • Allowed for SEO out of the box.
  • Had payment provider gateways built in.
  • Would be compatible with all common web browsers, operating systems & computing devices
  • Ensure a secure  experience for customers.

To this end  Shopify met all the criteria - its the number 1 SAAS Ecommerce solution which hosts 500 000 shopping sites. This allowed me to rapidly develop an online presence, process payments easily, add new features as & when required, utilise cloud services to automate parts of the business & spend no time on maintenance. 

Besides pages browsed, the website stores user details such as address & any orders made. If they want to avoid this they can request a brochure or visit using a VPN or TOR Browser. Customers can exert their right to be forgotten from their user account. They can phone me. I really don't understand why a total stranger thinks a commercial website should trade in a way that is totally anti-competitive. or why they'd take issue with a platform that is so successful it hosts 500 000 websites. 

Wait a minute - what about me?

At no point did anyone actually ask me about my background to understand if I know what I'm doing. In a previous life, I was IT Manager for 16 Schools & 2 Faculties at the  University of Leeds...A role which involved managing services for 24 000 end users and 3000 computing devices. I'd also provide Research Data Management, advising on process & creating solutions to safeguard data for high-value commercial research projects or sensitive humanitarian research projects whereby a leak meant danger to life. I was IT Director at successful Leeds Law firm, whilst sitting on the board for a number of other small companies & also worked at creative agencies (indeed I ran my own for a while) & I managed projects for clients like Disney. 

And what about the phones?

Does anyone actually disagree that an Omerta phone is secure? Do they think Daniel Micauy open source OS doesn't cut the mustard? Is Signal not fit for purpose? IS the PIxel 3 a weak security phone? Because that is the ingredients I use. If you feel my writing is too flamboyant, or visuals to rich, simply go away. If what I have said is wrong, then give me feedback & help me grow. But don't throw mud, it's childish & ignorant & benefits no-one.