A Blackhat security researcher has caused a "storm" of Tweets regarding an alleged hack of the "secure by design" Blackphone.
The Twitter conversation begins with TeamAndIRC first announcing that it only took five minutes to compromise the Blackphone. It then backtracks on a claim that it happened on an unpatched version of Android and points out that the second attack requires user interaction.
The three items identified by the account are described as follows: (a) “USB debugging/dev menu removed, via targeted intent” (b) “remotewipe app runs as system and is debuggable, performs debugging get free system security” and (c) “user system for hacking, many available”.
This post by CSO Dan Ford on Medium responds to some of @TeamAndIRC's claims.
Ford does not consider the debugging attack to be a vulnerability because the Android Bridge debugging mechanism is part of Android: “We disabled ADB because it causes a software error and potentially impacts the user experience, a fix is coming.”
“I would like to thank him for not spreading the word and I am returning to the Twittersphere for a little more transparency, explaining that immediate user interaction was required and that we had already fixed one of the vulnerabilities via an OTA update,” Ford continues
This appears to allow users of the system to gain root access: the details of the attack have not been discussed publicly, but Ford promises a patch as soon as possible once Blackphone knows what's going on.

