The only secure option is using an external WiFi or cellular data router for Internet connectivity. The router can of course be geolocated. And adversaries may gain some access. But it should be possible to prevent access through it to the phone. That is, it's a firewall.
Then do end-to-end encrypted Internet stuff, messaging and VoIP. And by using some mix of VPNs and Tor, adversaries won't even see most metadata. Except for communication timing, of course.
See https://blog.torproject.org/mission-improbable-hardening-and...
Edit: But this still doesn't protect from some third party with root rights on the phone. For Android, the Copperhead OS might be enough. But I don't know enough to know. And for iOS, I suspect that you're stuck trusting Apple.
The only exception to this is the checkm8 vulnerability, which can be performed on an A11 and older chips (so iPhone XR/XS/XS+ and 11/11 pro/11 pro max aren't vulnerable) from DFU mode, which doesn't need the device passcode.
Is that true?
Could one somehow enable updates through pure TCP/IP?
Maybe same for Android?
Except that you'd arguably want to update it locally with the Copperhead OS.
> If your computer can’t communicate with Apple's software update server, you might see one of these messages.
The carrier setting thing hasn't ever been use for a jailbreak exploit AFAIK so chances are it's not a good attack vector.
From your other comment:
> But it mentions the option of wiping baseband firmware
iOS also has signature verification for its baseband, since trying to load an incompatible one during a downgrade[0] breaks Face ID / Touch ID.
But ya, this is all "trust apple to not do anything". They've made a good stance with refusing the FBI request[1], but the FBI got into the phone anyways[2].
0: https://github.com/tihmstar/futurerestore
1: https://news.ycombinator.com/item?id=11116274
2: https://venturebeat.com/2016/03/28/u-s-government-gains-acce...
And under what circumstances does the phone leave airplane mode, and go back online.
But even if that were solid, you'd still be ~unable to install apps that Apple doesn't provide. Unless you play the developer game, and I gather that's limited in app number, and how long they'll stay functional.
I mean, if Apple says airplane mode turns off the cell radio, that’s a falsifiable claim, so you don’t have to take it entirely on faith. It might be possible to hide it in the UI, but you can’t hide a radio signal.
Say you set airplane mode. And then the phone sleeps. Will it still be in airplane mode after you wake it?
Or say you shut the phone off, and restart it. Is it still in airplane mode?
That's an issue because, as soon as it's not in airplane mode, it knows where it is.
And that reminds me, does airplane mode disable GPS? Because if it doesn't, it's more or less pointless, from a geolocation perspective.
>Or say you shut the phone off, and restart it. Is it still in airplane mode?
Yes.
>And that reminds me, does airplane mode disable GPS? Because if it doesn't, it's more or less pointless, from a geolocation perspective.
Why does that matter? You can turn location services off. Moreover, GPS functions passively. Turning it on doesn't transmit your location to anyone.
> Why does that [GPS] matter?
GPS matters because it's important that the phone doesn't know where it is. I mean, if it doesn't know where it is, there's no need to worry that adversaries will access the information.
> You can turn location services off.
Off entirely? Even for the OS? Or for rogue apps?
> Turning it on doesn't transmit your location to anyone.
No, but it generates location information that could leak. And if the phone uses WiFi to supplement GPS, it necessarily communicates with some remote server.
So your threat model is that you can't trust the device itself? If that's your threat model, you'd probably need a phone with hardware kill switches. Also, if you can't trust the device itself, why would you be carrying the device around? What would you use it for?
>No, but it generates location information that could leak. And if the phone uses WiFi to supplement GPS, it necessarily communicates with some remote server.
On android you can explicitly disable that ("device only" in location settings). There's no such option on ios, although you could still disable wifi/bluetooth and still have working gps.
Yes. I don't trust a phone OS where I lack root privileges. And I entirely don't trust the baseband.
> If that's your threat model, you'd probably need a phone with hardware kill switches.
Yes. Or with disabled GPS, baseband and WiFi. And with Internet connectivity via external WiFi router, or cellular modem/router.
> Also, if you can't trust the device itself, why would you be carrying the device around? What would you use it for?
I'd use it as a phone. Albeit just using VoIP.
And if I had all the iffy stuff in a separate device, connected via USB, I could trust the phone as much as I trust the host machine I'm using now.
I mean, I'm working in a Debian VM that hits the Internet through a nested VPN chain. And the Debian host has no access to GPS or WiFi. So I'd want to replicate that on a phone.
With that in mind, there's not really any kind of reasonable way to hide what devices are connecting to what tower. This is where location information comes from. It's really an inescapable part of how cellular devices work.
Inbound / outbound numbers are something that has to be available for similar reasons. There's also clear legal precedent making those accessible to law enforcement and not requiring a warrant. There's little to be gained by trying to encrypt them, even if it was possible.
Call and text comments are the things here that can be encrypted. It's not something the phone companies are in a rush to do.
The comment from mirimir elsewhere in this thread reminds me that this is kind of an overstatement, or at least that the details are complicated.
You could gain a lot of privacy in this regard by separating mobile data services from telephony and identity. For example, you could imagine paying for mobile data anonymously, either using existing prepaid mobile data services or using a hypothetical future service with blinded payment tokens and only extremely-ephemeral device identifiers. Then you could imagine getting all of your identity and communications services from someone totally independent of your mobile data provider. If the mobile data provider cooperated with your application-layer communications service provider more than you wanted, you could try to create your own service instead, or try to route at least the messaging setup part of the process via Tor or other proxies, so that the mobile data operator and application-layer intermediaries didn't even know about the connection.
I'm not sure anyone other than privacy advocates would consider this progress relative to the current situation; certainly carriers and governments would like it a lot less (it might already be illegal in some jurisdictions in various ways), and most users would probably find that it increased cost while decreasing reliability and usability of some services. It could also make it harder to use the network to investigate or deter device theft, as well as harder to investigate application-layer fraud and account hijacking.
To be clear about what could change, it's true that towers will always know which devices are connecting to them at a particular moment, but this could in principle be separated from billing, identity, and any kind of persistent identifier. So they don't have to know that a particular device is being used by you, or that a particular device is being used by the same person who uses a particular application-layer identity.
The other problem in trying to get there right now without carriers' and governments' cooperation is that, since you can't rotate hardware identifiers on GSM interfaces, a carrier can see your movement patterns for the lifetime of your use of a particular device, and can probably determine that those movement patterns are similar enough to another device's movements that they're probably used by the same person.
Sometime I hope to write a long article on possible non-metadata-collecting mobile communications futures. It's a really interesting topic.
- your location in time and space
- the numbers you contacted
- the duration of contact
If you were spying on someone, what would you rather know: all the above metadata you listed, or a full recording of all their calls?
That depends entirely on the purpose of the spying.
If you're spying with a goal of assassination, the location data from their morning commute might be far more valuable.
You can't trust cell companies to help you against the government.
I don't buy this reasoning. It suggests that cell companies will roll over to any law enforcement demands. If that's the case, why don't law enforcement ask cell companies for their cell tower logs directly? Why spend thousands of dollars on equipment when the same information is an email away?