Bunnie's Precursor Crowdfunding Begins
crowdsupply.com
crowdsupply.com
If one is worried about nation state actors, the ownership of a device that's secure and uncommon enough is likely to attract additional scrutiny or just be seized, legally or not.
It's a pretty cool device, mind you. The fact that they're going out of their way to make sure the device is fully inspectable and trustable is pretty impressive, as you point out. It's just not very usable as a privacy tool in a hostile environment due to it being rather conspicuous.
The distinction between "tamper evidence" and "tamper resistance" seems to provide a good analogy here. Without secure devices, a state can spy on you in a clandestine way. With secure devices, a state can spy on you in a more overt way. You might still care about making the tampering evident!
("can" here probably means "can somewhat easily")
That being said, I'd love to have a reasonably modern device that's auditable and has enough functionality (email, calendar, web browser, GPS, VPN, phone, SMS) to be both useful and respectful of the user (eg. dark patterns to send location data to Google). I love the form factor of the Precursor and the fact that it has a keyboard on it.
If it allowed me to ditch the Android phone with a less distracting alternative, that would be amazing. It's definitely not there yet, since I don't think they have started doing that much work on the software side of things, but definitely something to keep a look at.
And for some people for some causes those risks, including "worse", might be worth it.
Besides, if you're the sort of person who might be the target of "worse" you're probably going to have a hard time regardless of if the oppressive power gets into your device. ... but maybe the security protects some of your friends from befalling the same fate.
As far as seizure goes-- it has an accelerometer in it: "Zeroize on throw" is probably implementable. Alternatively, time-lock where if the device is moved from its hiding spot at the wrong time of day or without the right gestures it get wiped.
The PinePhone seems to be coming along decently these days. Maybe that's a workable alternative?
The most important difference between a jail and a home is who controls the lock on the door. Most smartphone companies want you to believe that the gilded jail they’ve designed for you is the safest place to spend your time. Precursor takes a different approach. By giving you the keys to the lock, it gives you a home.
We are both arguing that you don’t really own a smartphone, so you aren’t buying the building.
It depends on what you'd like to accomplish, but given that powerful FPGAs are now more affordable and plenty of great FPGA friendly libraries are emerging which work with open source tools, the barrier for Soft-CPU implementations has lowered significantly. This sort of project looks great for cases where trusting blackbox chips was questionable.
Could you (or anyone else) elaborate on this? If possible, ELI5 please because I know very little about hardware. :)
> The CPU is, of course, the most problematic piece. I’ve put some thought into methods for the non-destructive inspection of chips. While it may be possible, I estimate it would cost tens of millions of dollars and a couple years to execute a proof of concept system. Unfortunately, funding such an effort would entail chasing venture capital, which would probably lead to a solution that’s closed-source. While this may be an opportunity to get rich selling services and licensing patented technology to governments and corporations, I am concerned that it may not effectively empower everyday people.
> The TL;DR is that the near-term compromise solution is to use an FPGA. We rely on logic placement randomization to mitigate the threat of fixed silicon backdoors, and we rely on bitstream introspection to facilitate trust transfer from designers to user. If you don’t care about the technical details, skip to the next section.
I think it would be pretty interesting to have a Lora radio for participating in networks like meshtastic (https://www.meshtastic.org/).
I get why many people would find cellular interesting, but since it's not possible to use cellular without device level location tracking by the cell network... I think it is less useful.
In either case bridges from other networks (such as LTE cellular) to wifi exist and are readily available, including tiny battery powered ones... So the lack of external cellular shouldn't prevent you from using precursor with cellular.
This does not provide access to native cellular functionality like voice calls or sms/mms messaging. Obviously cellular connected wifi hotspots are an option for data service, I'm not clear why you're presenting that as if it's equivalent.
For SMS/MMS do none of the wifi hotspots offer a similar interface to serial cellular modems?
The isolation technique AIUI is not really any different from what purism does with the librem; hang it off the USB bus, expose power control to the user.
But that still provides convenient first-class software integration as a cellular modem when that's functionality the user wishes to access.
A wifi hotspot your device uses over wifi which just happens to be reaching the internet via a cellular network has absolutely no software-level integration as a cellular modem providing voice/SMS/MMS services.
> For SMS/MMS do none of the wifi hotspots offer a similar interface to serial cellular modems?
Not AFAIK, my experience is limited to a ZTE mobile hotspot on at&t prepay, but it's a bog standard wifi hotspot. Sure I can do the sms-over-email dance through the data link, but i could also use voip or skype or whatever over data, that's besides the point. To be useful as a hardened even basic feature phone substitute, it needs to be able to make/receive calls and sms/mms, at most requiring the flick of a switch toggling the cellular modem.
https://www.crowdsupply.com/sutajio-kosagi/novena/updates/no...