How do you pay for jmp.chat? Do you trust their code to be bug-free and without possible exploits? Do they do regular security audits and code reviews? Do they have enough users and maintainers to be able to quickly detect and address security issues? Are you sure Airplane Mode turns off the baseband and cuts off all cellular communication? It doesn't, you can still emergency receive alerts in Airplane Mode. Your phone can tell exactly where you are by comparing your wifi search results + RSSIs to known public databases without even having to use GPS. How much do you trust your VPN provider to keep no logs? How do you pay for VPN?
I use the word 'mitigate' not 'solve' since closed source baseband modems are a problem. Cellular traffic is off in airplane mode, but the baseband could be exploited if someone wanted to find me AND knew which IMEI to target. Because the IMEI has never been associated to me, that is a challenge.
I run my own VPN and share it with a few other people.
How confident are you in your VPN server configuration skills? Gaining access through mis-configured self-hosted boxes is the easiest attack vector usually as most people who self-host aren't experts in the software they are using leading to leaks. Besides that, do you keep a list of packages installed on your box, open ports, etc? How about security patches and regular updates as well as auditing access logs to ensure no one gained access to your box?
Squeaky wheels get the grease and squeaky nails get the hammer, but silence in a noisy forest is alarming.
VPNs hide the content of connections, at least from MITM / eavesdroppers, but server-side data scrapes are quite effective at figuring out who you are (or what your phone is ... see below). Nothing really does a good job of hiding the fact that you are connected to a VPN except TOR, and where that connection originates (e.g., your wifi network, which is well Geo-located, remember?). And de-anonymization of VPN connections to identify downstream connections are possible, IIRC. Details about your phone are well recorded (MAC, SID, etc)
And always remember, your phone can be implicated based on location data, which will implicate you once it's discovered you own the phone. And that's as simple as looking up the SIM purchase / use.
When I am at home, I am WIFI only. When I am out, WIFI & bluetooth are off. This takes some discipline at first but then just becomes habit. I know the spot on my commute home where I switch my settings.
In theory it could protect location data from the carrier for locating you with a wild amount of opsec practice but I highly doubt you could pull that off for a daily driver.
Having wifi/bluetooth off in public isn't a terrible idea though as those are generally much easier attack surfaces and are leakier.
Suppose you wanted to find someone that aways turned on their phone on at ~8:15 AM and found someone that always turned their phone off at ~8:10 AM within 15 miles. How difficult would you say it was to make this connection?
All of these privacy focussed phone OSes tread lightly on the fact that there are a grand total of zero modern open source basebands in existence.
The carrier definitely knows where you live if you take your phone to your house at night, even if it is off. The only way to prevent that is to put it in a faraday pouch at your “airplane mode” checkpoint.
Why do you think basically zero phones have trivially removable/changeable batteries? Any phone that clams to be security first and doesn’t at least have a switch (an actual switch) that disconnects the battery altogether is a joke.
What does intelligence have to do with whether someone is a criminal? There are dumb criminals and smart criminals; I'm not sure what the correlation here is.
Treating this just like investments, over your lifetime, its a no brainer on which is the better path to take.
"Why do this risky exciting dangerous thing over there when you could come over here and be a flacid lifeless drone with me at Bezos' personal blowjob-drone company. Marry the first person you meet, have some kids, yay stability!"
Honestly though they might as well just use the average IQ for the population. There's not a person alive who hasn't violated some law at some point. We're all criminals.
That's not how saved networks work, as far as I know. If you have a source saying otherwise, I would like to read it.
[0]: https://www.wi-fi.org/knowledge-center/faq/what-are-passive-... [1]: https://dot11ap.wordpress.com/active-scanning-probes/ [2]: https://stackoverflow.com/questions/36264440/phone-doesnt-se...
You need burner phones to cycle after each usage.
TBH, seems you cranked up the paranoia to 11. The VPN has to terminate somewhere, so if I was a state actor attacking you, I'd figure out where that is. WiFi+BT firmware isn't bullet proof, either, and hypothetically an exploit chain could be found to enter via WiFi and stealthy enable cellular. In practice XKCD #538 applies: https://xkcd.com/538/
For most of us the attacker is someone trying to make some money by scamming, stealing CC or installing a malicious app.
It's the day you miss something that your effort was pointless. Even if your solution is always secure, it only takes one slip up to ruin everything
Any threat as large as youre trying to protect against, if interested in you, can just wait for you to make a mistake.
Anyhow, if one slip-up is enough, you're doing it wrong. Imagine you were a mad scientist testing out a jetpack- you are confident yes? But I imagine you would feel more confident with a bunch of nets, and a trampoline underneath that, and a lightning rod in case of a storm, and a requirement that you hold down multiple buttons at once to play with the controls, etc.
That is, if you are serious you will put in multiple safety nets at every layer of the stack so that "one slip" is not enough.
You like to talk to people, but you know that a long-term pseudonym is the gravest danger of them all.
You like virtualization, but you keep some crucial data and keys(treams) on a un-networked machine.
You like anonymizing networks, but you know the caveats of traffic tunneling and didn't connect from your home router.
You connect to a randomly-chosen wireless AP, but you know that just in case your MAC-spoofing fails or you get pwned or something, you are glad that you bought the device with cash and never tied its characteristics to your identity.
You are glad that the only transceiver connected to the device is an external wireless dongle so that when you are done, you don't accidentally connect with your device from home.
You are glad you waited for an overcast day so that you could thwart spy satellites that use visible/infrared light, and that you connected to the AP from afar to thwart cameras.
The list goes on. The guy whose face you see plastered in the news? Yeah, that guy thought his experimental jetpack was the shit. And it was- until it wasn't.
VPNs cannot break TLS, (unless you're dealing with the intelligence apparatus of a major power, which probably can break TLS) so they cannot introspect most of the content you send and receive anyways.
What they can do, however, is see the domain name of the HTTP requests you send when setting up TLS.
Chaining VPNs doesn't add security by any metric.
It's also possible GP is referencing GGPs arguably paranoid position on phones, relating it to similar paranoias held by Dwight (the character who delivers the monologue).
Do your family and friends do that?
Maybe it's better to blend in with the noise.