Lockdown Mode on the Librem 5: Beyond Hardware Kill Switches
puri.sm
puri.sm
Because it was cheaper, and most consumers want cheaper goods.
Because it was cheaper, and most companies/shareholders want better profit margins.
Well-written and properly-designed software buttons can satisfy the same need as hardware buttons, anyway; when they don't hold up, it should be considered either a UI bug or a design flaw, not just a consequence of the hw-vs-sw choice. (Same with wireless headphones--when they don't work as well as wired headphones, the answer is to fix them, or develop new tech as necessary so that they're at usability parity, not insist that wires are better.)
Technically, but software buttons are inferior to physical ones in terms of usability. Or at least I've yet to see software buttons that aren't, but I have not seen all implementations of software buttons.
Reliability.
Switches fail, and make devices less waterproof.
I have had plenty of modern devices fail due to broken on/off or volume switches (and failed sensors, and failed plugs or sockets).
On covering tablet/laptop camera threads, a few people not worried about spying said some video app came on broadcasting to coworkers. One was in bed half-naked with spouse. Another on toilet in office. So, they cover cameras or kill video apps by default to prevent that stuff from happening again.
Also, what's the use case for switches flipped in different directions that wouldn't be covered by software buttons? We can't possibly be talking about targeted attacks-- in those cases you're screwed no matter what.
That only leaves indiscriminate software attacks. Now take the hardware switch setting where baseband=off and wifi=on. I guess it's nice that evil software cannot pretend that baseband is off when it's actually on. But evil software attempting to "get out" is probably going to use a high level call out to the net. So who cares that it must now leave through the wifi radio instead of the baseband radio?
I basically want a pocket computer. Access to the cell network is a useful feature, but one I don't need most of the time, so why be connected to it all the time, with all the privacy concerns that comes with.
Despite the name, it's basically just an iPhone without a cellular radio (though I'm not sure if it's actually removed, or just disabled/neutralized). So you can use it to do anything an iPhone can do, it's just dependent on having access to a WiFi connection if you want to do anything over the network.
That said, sometimes you need/want cellular in a pinch, but don’t want it always on, hence the kill switch.
If you have hobbyist-level electronics assembly skills, a weekend, and a couple of hundred dollars, you can pretty easily assemble such a thing using a Raspberry PI with a touch screen, battery, and any of several commercially available cases (or 3D print your own).
I have one that I put together to use for pentesting. It works quite well.
The easiest way to meet the size constraint is to use the Pi Zero. I wanted more grunt than that, though, so I used a normal Pi and stripped the board of all the connectors except the micro USB to achieve the profile I needed.
You can't. If the functionality can be enabled/disabled via software, then there's always the possibility that malware will enable it.
I can only think of the special case where a carrier wants send a specially crafted message to exploit a flaw in FLOSS in order to implant malware that tricks the user about the status of the baseband. Still, if the carrier wanted to take that risk the only users who are protected are the ones who never switch on the baseband OS.
I don't think it makes sense to decrease usability for the off chance that some user has an idiosyncratic threat high enough to never use the baseband os, yet low enough to toggle wifi on and off.
I'm not speaking to the number of switches, merely the importance of actual physical switches that physically disconnect the subsystems.
You have an spy on your pocket. Cheap spy or costly, don't matter
What are your outstanding concerns about control?
PureOS will no doubt be the best supported distribution but since the whole point of the phone is to be as open as possible and Purism aims to upstream as many of their changes as possible I expect it will be possible to run Debian with most functionality intact.
Myself, I really want to get NixOS running on it.
Let's start a working group, stat! What a cool story it would be if we could say that we built images for the thing before it ever even shipped and had a one liner to emit new NixOS-based images for a Librem 5.
There is so much potential for experimenting with update models, read-only secondary secure OS partitions (combined with Nix's reproducability starts getting pretty compelling, in my opinion).
I go by the same name and am persistently in the Nix(OS) related IRC channels. Cheers.