Encryption of IP traffic happens on the open system, so no problem there.
If you'd like to complain about encryption of voice calls happening on the closed modem, I have some bad news. It wouldn't matter if it was open or closed, since the network it negotiates keys with is also compromised.
The only problem remaining, on this particular device, is direct connection of physical sensors (microphone, GPS, etc) directly to the modem. This is solved by physical switches (or hardware switches controlled from the open system) between the sensor and the modem.
The only exception I see now is the GPS, which is embedded into the modem. If they solve that, I'm buying the phone.
You can't use cellular or WiFi without being geolocated. But as long as the modems are securely isolated from the open system, geolocation information can't pollute your communications. There's obviously the same geolocation issue with broadband.
Also, that isolation prevents compromised modems from compromising the open system, and the accessing data, compromising end-to-end encryption, and so on.
Both are aspects of modems being "treated as compromised/hostile".
is that even the case of the microphone? My understanding was that - independently of the possibility to turn the microphone and modem off with kill switches - all audio data to the modem comes via I2S from the SoC anyways, i.e. that the microphone is NOT directly connected to the modem but to the SoC (possibly via a separate audio codec Chip) and that the SoC serves the modem via I2S whatever audio data the user pleases (whether that be from the microphone or whatever else).
So does make open source modems rare, liability exposure of legal fallouts make for some muddy waters.
In the US, hams are prohibited from employing encryption with the single exception for control coms with amateur space-based radios. With the proliferation of digital modes, the encryption rule is increasingly being challenged and it will be interesting to see where this goes in the future.
The PinePhone appears to use a similar approach here. The modem's only job is to provide a data connection, and ideally everything sent through that connection is encrypted in such a way that even if the modem wanted to snoop, it would be unable to do so. All it sees is encrypted noise, with the OS and application doing everything they can to keep it that way. The additional hardware isolation helps to ensure that even if the modem is compromised in some way by an attacker (difficult, but theoretically not impossible) it has very limited access to the rest of the phone, and would hopefully not be able to do very much damage. This is in stark contrast to most of the rest of the mobile industry today, which happily integrates the modem into the rest of the memory space, and would be at far greater risk should a modem exploit be discovered.
None of this is perfect, of course. In a perfect and ideal world, a FOSS modem would exist at scale, and the PinePhone would use that and all of the firmware would be open source. But the practical reality is that, at scale, a closed blob for the modem is required; no alternative exists that's cost effective enough to bring to market. So, the phone is designed to give that blob just as little trust as possible while still making the connection work. I think that's a perfectly fair trade.
Is that still the case? I though that most phones now isolate modems via some flavor of USB with IOMMU.
And indeed, that phones now isolate modems better than Intel and AMD machines isolate USB devices. There's IOMMU, but only some software actually uses it, such as Qubes.
With the PinePhone (and also the Librem 5) the modem and SoC are physically seperate so the communication between those two components can be inspected and controlled.
But iOS devices don't have the cellular modem in the SoC.
And neither does the latest from Qualcomm with 5G, which I gather will go in at least high-end phones.
We have two devices coming to market that take ideologically different approaches to choose from: the PinePhone (pragmatic compromise) and the Librem 5 (no compromise). So just pick where on the libre spectrum you want to live and enjoy 2020... it should be a fun year!
Basically the post says that the PinePhone mobile phone is, with the exception of the "mobile phone" part, a completely open source mobile phone.
It's just a funny way to write the post. If you remove the mobile phone part it's not a mobile phone. It's like saying a cake is, with the exception of the cake part, completely vegan.
CPU -> LTE Modem || DMZ || Cellphone Provider
We have this for the Pinephone. CPU || DMZ || LTE Modem -> Cellphone Provider
This is fine.Remember that in the first model, and in most typical phones, the LTE Modem have above root access to the CPU through DMA. The exception is some more modern devices like the iPhone, which give the modem a specific sandbox device to DMA into that's not the actual processor.
It'd be nice if the PinePhone supported this.