"Basically, you’re either dealing with Mossad or not-Mossad. If your adversary is not-Mossad, then you’ll probably be fine if you pick a good password and don’t respond to emails from ChEaPestPAiNPi11s@ virus-basket.biz.ru. If your adversary is the Mossad, YOU’RE GONNA DIE AND THERE’S NOTHING THAT YOU CAN DO ABOUT IT." -- https://www.usenix.org/system/files/1401_08-12_mickens.pdf
There's a lot of humour in that article, but some cold hard truth as well.
While this advice suggests I should just give up, that's not a practical option.
I'm fortunate enough to have never had that knock on my door, but I'm certain I'm on several lists.
You don't need to "give up", you need to work out what stuff you do or talk about that "Mossad" isn't really interested in, and be much more circumspect about where and who you talk with about anything that they might be interested in.
Sadly, for anybody without my kind of middle aged white dude privilege, that's almost certainly a "chilling effect".
What's the most subversive thing you've ever posted, repeatedly, with a large number of people seeing it? Chances are that it's not being "fortunate" that keeps you save but you simply aren't of interest to them.
In Communist China, you're perfectly safe as long as you aren't the "wrong" ethnicity and never prominently criticize the Party. In democratic country X, despite people getting to vote, it's not fundamentally different.
PS: Are there any other articles that he's written that are similarly entertaining?
try here for a great start https://mickens.seas.harvard.edu/wisdom-james-mickens
If your adversary has access to your phone, directly, then encryption will not help (practically speaking - got to keep saying that because heroic efforts can be expended). If that adversary is the phone manufacturer (a) you are screwed and (b) the manufacturer is taking a huge business risk
Point is using Signal your messages and secrets cannot be found on a server over which you have no control. You do have control over your phone. You can switch to a more reputable manufacturer, you can keep it away from your adversary
One way to express it: The phone isn't much use unless you have access to the data. If you can access it, so can adversaries with access to your phone.
Given the amount of spying that has been revealed (a lot of it seeming to be superficially illegal) it seems reasonable to assume that phones are compromised in all manner of ways unless proven otherwise. I'd prefer to be pleasantly surprised.
Anything that makes it more expensive for the government to read someone's communications is a bonus. Ideally panopticon states will remain uneconomic.
* For example, see https://news.ycombinator.com/item?id=10905937
* Mobile-phone baseband chipsets are proprietary and secret a.f. and part of that is down to the carrier's insistence.
* Baseband chipsets run software that the carrier ships OTA to the phone.
* While baseband chipsets are ostensibly part of the wireless modem and meant to simply provide a service to the rest of the phone it looks like they generally have some form of access to the phone's main memory bus (just like any other PCIe device in a PC) and so could read the framebuffer (assuming it's backed in RAM at all) - or at least the back-buffers of the screens of running applications.
* Even 6-7 years ago, there existed definite causes for concern in (at least) the 32-bit version of iOS - but I can't find any hard evidence that the baseband chip in Apple Silicon-era phones wouldn't have at least some access. See https://github.com/userlandkernel/baseband-research
walled-off from the rest of the phone (somehow) from what I can tell it looks like
A useful search term here is IOMMU, the major phone platforms have readily available documentation describing the architecture and its security goals.
The baseband parts here are not, as message board C.W. would have it, top secret unknowable wizard hardware. You can get the part numbers and look them up.
There's a lot of weird mythology about these modem parts. The thread you linked to included someone claiming that basebands were DMA'ing into host memory --- you couldn't even do DMA over the HSIC USB the parts were using. Like, it wasn't even physically possible.
(I have no idea what a 5G Snapdragon Xwhatever can do today, but I assure you that Apple's security team does).
We have way, way, way more than that. Both the GP and you are arguing about the security deficiencies of modern phones as you've imagined them, rather than as they are but that gap is trivial to close with relatively little reading.
I appreciate the strength of your conviction - but I'm not an phone industry insider, and have no access to the kinds of reading-material I assume you're pointing to - for example, Qualcomm put their docs behind a verify-your-employer-wall (which is outrageous): https://www.qualcomm.com/products/technology/modems/snapdrag...
...if Qualcomm's attitude towards openness and transparency is representative of the mobile comms industry in general then they have little hope of correcting any misinformation or misconceptions other technology folk like ourselves might have, let alone the general public.
Likewise, you can highlight text on screenshots.
A GPS transponder with microphone and camera under the control of billionaires seems like a mistake
https://hackaday.com/2020/09/29/bunnies-betrusted-makes-firs...