I didn’t even realize apple had the ability to do something like this? Can someone explain how this is even possible for them to do? This wasn’t an update was it? Just a flipped switch?
And your final question "What else are they capable of doing without my permission?" --- the answer is anything they want. Concretely, what are the capabilities installed NOW that they can take advantage of, who knows exactly?
As an example, I do remember a looong time ago Google remotely removed apps from Android phones, pretty sure Apple could or might even have done so as well.
Another solution for apple is to simply revoke the codesigning certificate that is used to sign the app, which will render the application un-runnable.
[0]: https://www.macrumors.com/2008/08/06/apples-ability-to-deact...
Nothing technical prevents them from putting something in ring zero which does silent updates without announcing them, but that's not what's happening here.
This means they can intercept even e2e encrypted messages such as signal, if they wanted.
When you control kernel, you can do anything, to anything running on that system.
For comparison in a Linux distro:
- everything is built from source on distro infrastructure, users can inspect any an all source code of everything running on their machine - software updates are transparent and not enforced, user can read changelog or compare source code of the updates - software updates of individual packages don't usually go directly from upstream open source software developers but via a package maintainer in the distro, for each distro - if an upstream project introduced fishy stuff like Apple is doing would almost certainly be noticed by either one of the package maintainers or users due to changes in the source or in software behavior, alerting others to do source code analysis and stop the attempt from affecting users
Once things like Apple is doing become normalized, the next step becomes making it illegal to distribute or use software that doesn't do it. So running your Linux phone will be illegal, and why would you want to do that anyway, except to look at child pornography?
Similarly, non-sanctionable digital currencies like Bitcoin will be made illegal.
Avoiding modern tech is a workaround, but will be get increasingly hard as the world becomes increasingly reliant on it. (Cash, also, will have to go away.)
I’ve been looking at trying something like a Pixel but with Calyx as a first step while waiting for the PinePhone and the Libre M to mature further.
This can't happen fast enough... though I can't get behind Purism/LibreM it's just too fucking expensive, basic privacy and ownership of your device shouldn't be a privilege.
Basically, is it with interacting with Apple users if you are worried about that problem?
There is librem and pinephones and they don't look bad, but don't expect many apps and interoperability. Some people regard that as a plus.
I’d like something like my 4 inch iPhone SE but I know that is impossible. How about 4.7 inch range like the new iPhone SE?
Edit: If anyone is ever reading this and looking, I went with a Pixel 2, has a 5 inch screen and a good camera. I'll see how it goes. Will be nice to not be locked into Apple anymore.
https://www.phonearena.com/phones/size/Google-Pixel-4a,Googl...
Keep in mind that bezels have gotten much smaller over time.
It costs $50, though.
"Sailfish X is currently available in the countries of the European Union, Norway and Switzerland ("Authorized Countries") and the use of our website and services to purchase Sailfish X outside of the Authorized Countries is prohibited."[0]
In practice only the act of buying the actual Sailfish OS license in https://shop.jolla.com needs to be done from the the EU/supported countries. That can be done via a EU VPN and none of the Jolla provided services (RPM repositories needed for system updates, etc.) are geoblocked. I went to Japan with Sailfish OS phone twice with no issues at all.
For reference:
- getting SFOS from outside of EU:
https://together.jolla.com/question/184861/ask-purchase-sail...
https://forum.sailfishos.org/t/has-jolla-abandoned-sailors-i...
- stats from the community Sailfish OS software repository showing a lot of traffic from countries outside of the officially supported area
I think it is because of the USA's allowance of trivial patents which act like a trade block.
I have recently installed it on the Xperia 10 II you mention as well use a couple Xperia X devices in the family. Use the Jolla 1 & Jolla C before back when Jolla still manufactured their own devices.
Frankly, before some of the PinePhone distro mature, this is the only really usable Linux distro based independent mobile OS. And it has been available for years, yet people don't seem to be aware of it or seem to ignore it for some reason.
And if you have any questions about Sailfish OS, fire away! :)
Did you take PureOS into account ? It is the Linux OS installed on the Librem 5 phone. https://puri.sm/products/librem-5/
And while I agree that the closed source parts are stupid I still think Sailfish OS is a good stepping stone to full open distros and hardware once they reach sufficient maturity.
Also have they resolved the kernel updating issue? All phones which ship with Android 11 or lower are unable to have their kernel updated because each device uses a modified kernel[1]. Phones which ship with Android 12 like the Pixel 6 all use the same Android Common Kernel, so it's enabled Google to guarantee the Pixel 6 will have at least 5 years of kernel and OS updates for the first time in Android's history.
https://jolla.zendesk.com/hc/en-us/articles/201440787-What-A...
You can even install microg or full blown Google apps if you really want & are fine with the implications (still less problematic having Google stuff in the emulator than on a native device IMHO).
There have been actually also some attempts to get Anbox running on Sailfish OS as the community ports dont get the Android emulation layer, only officially supported devices.
As for major version kernel update issues - they did not, but I am not really sure it's that problematic in the end.
So basically they base their port on the best kernel version + blob bundle from the Sony open device program at the time, then stick with it. Apparently the way updates of these low level things work on devices originally shipping with Android are too stupid and fragile to make supportable over the air updates possible for Sailfish OS.
They could port the adaptation to newer bundle from the open device program and either mandate re-flashing or support two versions based on different kernels on a single device. Both not very good options imho.
Still, not updating the major kernel version does not mean the Don support the devices or newer rebuild the kernel. All the Xperia devices in the program are still getting OS updates, including security fixes for the kernel. They actually only recently dropped support for their Jolla 1 handset released in 2013.
It's just when you really need the latest kernel features or the most advanced Android emulation layer you might need to get the most recently supported device.
Thats what kept me there for all those years. :)
No idea about the ToF sensor - I woukd guess it could be used unless it nerds some weird Android blobs to function.
On the positive side, a stand-alone air-gapped TAN generator feels much saver than using a (possibly back-doored) smart-phone to do on-line banking.
They have done all kinds of dark patterns, for example they update the website (which eventually becomes a mandatory update), but that requires relinquishing the hardware token, or they update their mobile app, and if you even try to log-in into the new app they automatically cancel your token, etc.
When my token's battery died, they didn't want to give me a new one. They said they don't offer the service anymore. Only after escalating N times and explaining that I need a hardware token because their SMS-based 2FA didn't work internationally they gave me a new token. Suddenly it wasn't discontinued anymore. Now they moved off SMS-based 2FA to some mobile app, so I suspect next time I need a token I won't be able to get it.
Make no mistake, enjoy your TAN generator while you can, because you will not be able to enjoy it for long.
In the country I live in right now, the only way to get a proof for your COVID-19 vaccination is if you "voluntarily" enroll into some phone-based authentication scheme with your government that requires a modern, non-jailbroken iOS or Android device.
You have to log-in to a government website, and you do it either through a mobile phone registered with the government, or with a smartcard and a proprietary Java application. Pick your poison. (And they don't want to issue new smartcards either.)
I've run into a few that require 2FA - either SMS or email, your choice.
However there are a couple of new "Fintech" banks in the UK that are mobile app only. No website and I assume very difficult to get anyone on the phone. That seems crazy to me. Access to your bank is at the mercy of Google/Apple.
[1]https://www.mediamarkt.de/de/product/_reinersct-tanjack%C2%A...
Deutsche bank uses PhotoTAN, which supports hardware TAN generators [2].
Some banks use different but similar TAN generators (e.g. SecurePlus [3]), and I also witnessed Postbank accounts operated with USB-based TAN generators [4] called "BestSign".
[1] https://www.voelkner.de/products/476429/REINER-SCT-tanJack-o...
[2] https://genostore.de/db/phototan-lesegeraet/92/phototan-lese...
[3] https://cb.kobilshop.com/secureplus-generator/1/secureplus-g... securePlus Generator
[4] https://www.seal-one.com/devices.en#DiVc3100KLink BestSign
Expensive phones triangulate via towers (fast!) and use that to bootstrap the GPS unit. Some GPS units don’t support that bootstrapping and are, thus, slower.
Theoretically it might be possible to combat cell tower triangulation by having the modem only respond to one tower at a time and insert artificial latency to make it harder to work out your distance. But, another convenient fact: cell modems are all closed source, proprietary black boxes. They also have DMA (Direct Memory Access) to your phone.
Perhaps I should be wearing a tinfoil hat but these don't seem like coincidences to me. They seem like intentional measures to weaponise a tool in our everyday lives.
Nope. I have several dev devices. None of which have an iCloud account setup.
Didn’t do anything special; just skipped it at setup.
And how about specially crafted 'normal' pictures sent to individual to trigger the system? Special mind would have a perfect tool to get some one down / put into the troubles.
Here it is: https://puri.sm/products/librem-5 and https://www.pine64.org/pinephone/.
It also supports the Librem 5, but also the Oneplus 6 and 6T
* benchmark results faked by software
* personal data collection
* backdoor
All of these do not appear on the English page so there's a link to the French one : https://fr.wikipedia.org/wiki/OnePlus#Controverses
I'm looking at doing the same and I noticed Nokia has published the source code for the 8110 (I believe kaios runs ontop of Linux)
There's the Pinephone these days, but it's not ready for general consumption.