If you care about that stuff, you should abandon carrying a phone--switching away from a smartphone is probably useless if not counterproductive.
If you care about that stuff, you should abandon carrying a phone--switching away from a smartphone is probably useless if not counterproductive.
This is true. But I'm not a privacy absolutist. I'm willing to sacrifice privacy for some things, and having a phone is one of those things.
But that I'm willing to put up with that from one company in no way means that I'm willing to put up with that from other companies.
> switching away from a smartphone is probably useless if not counterproductive.
I don't see how -- can you explain? Reducing data leakage seems useful even if I'm not completely eliminating it, and I don't see how it's actively counterproductive at all.
There is a large amount of $$$ that goes into security of iOS and iPhone (sometimes orthogonal to privacy, sometimes not) that does not go into a dumbphone. The iPhone is also much more scrutinized and researched into than a random dumbphone, so it is plausible that you get much more exposure to exploits, etc., using a dumbphone that does not get updates etc.
It seems unlikely they put the same efforts into finding a zero day for a nokia. There might be a super easy to find zero-day though, like you're saying.
There were always obscure pieces of software that would pull your forgotten pin right off the device with the right secret code, in which case you have full access to the device.
I'd also expect them to be vulnerable to much simpler attacks like just reading flash chips directly
What's your threat-model? If your adversary is a nation-state on par with China, you're probably toast unless you have a well-resourced entity supporting you (think large corporate or another nation-state)
The dumb phone has no access to the pocket computer, after all.
edit: In a laboratory environment, it is probably easier to break into a dumbphone vs breaking into an iPhone, yes.
I can't tell you which results in better opsec today for say carrying out government-disapproved commerce. But I can tell you that the privacy benefits of having a bona fide computer that you control in your pocket will continue to grow, while the cell network is stuck being forever subservient to government/commercial surveillance.
I'm always confused by statements like this. What makes you think Google and Apple are any different in willingness than Verizon and AT&T? Or what makes anybody think any of them even have a choice turning over data on their users?
What do people think other people do when some law enforcement agencies show up on their doorsteps with warrants?
Also, empirically, I trust Apple and Google to keep data more secure from hackers than AT&T.
(I was also careful to use “blanket” requests as opposed to warrant in my original post)
Once I've completed the project, it's very likely that I'll write it up on one of my websites. I'll submit the link to HN at that time so everyone can see what I've done.
The short and sweet, it's an ARM-based micro, with WiFi, Bluetooth, a couple of USB ports and an HDMI output (to use with a HUD that I have). It will have an old-school color 4-inch LCD with resistive touch for its screen (not ideal, but the best I can do right now. I'll work on upgrading that to an OLED w/capactive touch in version 2). It will also have 8 physical buttons, because I like physical buttons. It will be in a 3D printed case. The total size will be roughly the same as an average thin smartphone, but will be a mm or two thicker.
It will link up with my watch, which will be the primary way I interact with it on a daily basis. My goal is that 90% of the time I won't need to actually handle the device itself.
Are you using an existing smartwatch or building something yourself there too?
Come to think of it, would an iphone with the cellular network disabled do?
There’s just something about running LineageOS on an old Galaxy Tab 2 (still Android, although apparently the hardware support is phenomenal) that has me trawling eBay for cheap tablets.
Source: it was one of my less-unsuccessful projects :)
Alternatively what RMS does is he shuts off his phone and only turns it on when he needs to use it.
I mentioned radio, because wifi / cell tower triangulation can be used to infer location.
Or at least I know that in one court case there was a nice big 8x10 of the defendant purchasing a burner phone. Apparently a lot of Point of Sale systems, especially where they sell burner phones, are wired to take a nice portrait of you when you purchase. I didn't know that at the time, and apparently, neither did the defendant.
That, combined with the location of his phone matching the location of his license plate around town did him in.
So if you try the burner phone thing, someone else has to buy it, and you should never take it with you to places where there are likely to be security cameras. And you also might want to refrain from driving with it in your vehicle.
However, if state persecution isn't part of your threat model, a burner is one layer of indirection that might make tracking and identification difficult for surveillance companies.
He also only browses the internet by emailing himself text/HTML from a remote server.
We can protest all we want and these entities would be ready with their PR script, about how they value their users, blah, blah, blah. Because, they know, at the end of the day, users are going to come back to them, use their platform to protest.
Unless there is a mass exodus towards p2p & decentralized network, these entities aren't going to budge, not an inch!
Case and point, if you've enabled location history for your Google account you can take a look at your own history and see for yourself just how easy it would be to identify someone given the power to subpoena surveillance footage, vehicle registration records, driver's licenses, etc. For my own data for the month of November right off the bat I walked to a nearby McDonald's and paid with a debit card. Even if they didn't have surveillance footage from all of the cameras in the restaurant they still have financial records of the small number of orders that were placed soon after I walked into the restaurant, that combined with the driver's license addresses and vehicle registration records in close proximity to my house would almost immediately identify me. Even just looking at where someone lives is enough to narrow it down to a tiny list of candidates and for >90% of citizens they are going to be on some record as having that address. In short, tax returns generally indicate where you live, as well as specifically state if any dependents that you claim also live with you. Then there's utilities which are just about impossible to avoid, then there's property records which don't need any subpoena as it's literally public records posted on a searchable website for most (all?) of the country. Voter registration data would also tie an individual to an address. USPS, UPS, and Fedex would be another easy way to come up with candidates, the list goes on and on but unless you're homeless you're going to be on a list somewhere. The next day after the McDonalds I drove to WalMart, where I again made purchases with a debit card and walked around in plain view of a plethora of surveillance cameras and again, just from the time of arrival and the time of departure you can narrow down the list of candidates to a relatively small list and I highly doubt any of my immediate neighbors also went to WalMart at the same time as me and left that WalMart at the same time as me. Also even if WalMart did not cooperate with any subpoena or if I paid in cash, it's not uncommon for private companies to drive around with a license plate reader through parking lots cataloging which license plates are present at a location for the purposes of selling that data to repossession companies looking for cars. I drove to that WalMart in a car registered in my name. After that there's a very obvious pattern indicating where I work and when. The company I work for files payroll taxes, none of my coworkers live anywhere near me, assuming it's just less precise positional estimates that a phone company would have for E911 purposes maybe they'd need to also look at the surrounding businesses as well but still, end of the day I think it's highly unlikely that my neighbors right by my house happen to also work right beside my employer. Right after that I travelled to one of our branch offices which would very strongly imply that I work at my specific employer and not the one in the adjacent unit. After that there's more visiting restaurants and gas stations and paying via a debit card as well as visiting my parents house. That's all in the span of a single week. Even with just a coarse history of the location of my phone it's absolutely trivial to identify me specifically. In fact, just off of the property records alone and some public records to determine employment history and family relationships I'd bet it'd be relatively easy enough to identify me by name even ignoring all of the different areas where police could simply subpoena payment records or surveillance footage.
Location data, even coarse location data, is definitely enough to identify almost everyone if you're in a position to correlate that with additional records. Unless you have your burner phone turned off almost all of the time, it really doesn't matter if the phone provider doesn't have your name, there's so many other sources.