Is it impossible to use a smart phone with strict privacy, or just very difficult?
Is it impossible to use a smart phone with strict privacy, or just very difficult?
It takes a bit to get it all configured initially, but once done it's sufficiently smooth sailing with occasional tweaks. The only thing that annoys me sometimes is that notifications no longer work properly for many apps, as the majority use Google's notifications service. Accessing OS updates may also become problematic, depending on the device OEM.
For what it's worth, I disagree with a number of the most important conclusions the author makes in the paper.
It's not really about my privacy requirements, but about living in a society where someone can investigate and organize against the powerful, without their own computers/phones/cars immediately ratting them out, and without needing a team of security experts.
Though the line for when lack of privacy starts to hurt us is much lower than people think, like Doordash stealing tips from their workers, that in a privacy-respecting society Doordash wouldn't even know about: https://news.ycombinator.com/item?id=43040984
and you think the Qualcomm RTOS can do what exactly?
> Do we know everything that's running on a Pixel?
did you mean hardware, or software?
Well that's the point, it's a black box so there's no telling what it can and can't do. There's what Qualcomm says it can do, and then there's what it can do.
It also can't cause the phone to levitate. It also can't recharge my battery.
As a rule, I don't worry unlikely hypotheticals, because doing so is a needless denial of service on my brain. Saying it's a blackbox is true, but that doesn't mean you get to invent random things to worry about, without direct evidence it's connected to the specific device we're discussing.
But do think I should at least try to meet you half way, so maybe I can preempt a few things that used to be true or possible. The baseband also can't install software into my android OS. It also can't directly read memory from my phone. It can't directly control my phone's bootup.
These are things poorly designed phones used to be able to do, that aren't possible on the Pixel line of hardware because it was designed to prevent them. That's why GraphineOS targets the pixel line. Because it's hardware is designed in a way to enable a secure device.
True, but the corollary is that you also can't say it's not doing certain things. Just because you currently don't have evidence of something happening does not rule out the possibility, but I must admit I am ignorant about the specifics of how the Pixel's RTOS is implemented.
So I'm genuinely inquiring: Could it be sending your GPS location to some entity without notifying the GPOS?
With very low confidence, I believe for chips that put GPS on the baseband, yes it can because that's required for E911. (I don't know what the pixel line does) Can it then transmit that location using the baseband without you being able to tell? I would assume so, and that's a case where it's safe to assume it can.
Unfortunately, that doesn't matter much. Your location is also trivially known by your ISP by triangulating connection strength. Often this can be more accurate than GPS in many real cases. The threat/risk that's able to compromise the baseband SoC, is more easily able to compromise your ISP. And thus the phone simply existing is a risk to location privacy, given a perfectly secure ideal baseband SoC.
Can that be used to uniquely identify you, and correlate it with your other actions. That's not really a question I'm prepared to answer in a HN comment (because I have to draw that line somewhere for my own limited sanity), so.... specifically yes, but generally, no. That is to say, it is possible given sufficient resources. But it's non-trivial to do in bulk. And there are many many easier and cheaper ways, so https://xkcd.com/538/ applies here too.
The RTOS could be used to leak your location, the fact that you're using a VPN, any nonVPN traffic, and call traffic. FWIW, I was mistaken and Google uses Samsung radios rather than Qualcomm.
Graphine OS runs in the Normal Zone on an ARM SoC while running Trusty OS in the TEE. In order for an App, or Graphine OS to interact with certain hardware it must use the Trusty Lib and Trusty Driver APIs into the TEE. The entire composition and operation of the Trusty OS operates in the "Trust me bro" space and Google's entire business model is built around spying on users.
So forgive me if I'm a little skeptical that Graphine OS.
> The RTOS could be used to leak your location, the fact that you're using a VPN, any nonVPN traffic, and call traffic.
Yes, it could... so can the default software on android, and so can your ISP (DPI is shockingly powerful). But, what's the risk there? How does knowing the ratio of traffic I send and receive being VPN, or TLS encrypted expose me to additional risk?
> So forgive me if I'm a little skeptical that Graphine OS.
I haven't looked in a long time so my memory is completely gone, but does GraphineOS not build their own Trusty OS image? https://android-review.googlesource.com/admin/repos/q/filter... What am I missing from why GraphineOS can't be trusted?
It's less accurate than GPS, but constant.
> The FCC said it found the carriers each sold access to its customers’ location information to ‘aggregators,’ who then resold access to the information to third-party location-based service providers.
https://krebsonsecurity.com/2024/04/fcc-fines-major-u-s-wire...
Companies that have chosen a surveillance capitalism business model have way more personal data, but they claim that they aren't selling that data to anyone willing to cut them a check the way that the carriers and app developers do.
However, data hordes stored by Google/Facebook/etc are still subject to warrants, so how much do you trust that warrants will not be abused?
Disclaimer: I have a Librem 5 but don't use it. I use GrapheneOS on a Pixel.
GrapheneOS isn't supposed to be for privacy though, as they focus on security instead. I don't think it would be too much to ask for a little help on the privacy front, but that might be ignorant of me.
Yes. It is a surveillance device pushed by government for this reason.
But it's a special kind of computer where all the laws are different, I have different rights when I'm near it or using it, and I am in constant battle with the companies that sold the phone to me to 1) try to keep my life as private as I can and 2) not pay them a commission on things I buy.
But what can I say about my phone that I couldn't now say about my TV, or my car?
This will never become less dangerous, this will become increasingly more dangerous.
"I want to send and receive messages from you but you're not allowed to know anything about me" is, at first pass, a tall order. We can sort of get that from the postal system and very little else in terms of communications technologies (and even then, if you screw with the network the postal service in the US is empowered federally to hunt you down).
Sorry for all these questions, but without them answered your claim sounds like a conspiracy theory.
All governments at all levels. Ever see a government service, office, or bureau talk of an app or show a QR code? That is a carrot for those who already use and stick for those who don't. Sometimes there is a paper form you can get and sometimes not. Do you recall all those covid apps?
Why? Because the government desires to know, for a variety of reasons. The US so they can watch your small payments. Europe so they can watch your speech and carbon footprint. Used to be so they could track you if you had a 1% deadly disease.
[EDIT] Evidence? Snowden's leaks and what I mentioned already
"A Manhattan Project for online identity: A look at the White House's National Strategy for Trusted Identities in Cyberspace"
<https://web.archive.org/web/20110506083805/http://radar.orei...>
In part:
The NSTIC proposes the creation of an "identity ecosystem" online, "where individuals and organizations will be able to trust each other because they follow agreed upon standards to obtain and authenticate their digital identities." The strategy puts government in the role of a convener, verifying and certifying identity providers in a trust framework.
I'd learned about this in 2018/19 as Google+ was shutting down, through a Search Engine Journal piece (leveraging Howard's earlier article heavily), similarly only available as an archive, with the original article substituted in place with another at the same URL. This one by Kristine Schachinger:
"In Memoriam: The Rise, Fall & Death of Google Plus"
...Google was only going to be one of many identity service providers for a program run by the Federal Government called the NSTIC, or National Strategy for Trusted Identities in Cyberspace....
<https://web.archive.org/web/20181220165659/https://www.searc...>
I'll note that neither article makes a direct link to mobile phones / smartphones, but clearly as those became widespread and individually identified with a single person for the most part, use of phone numbers as unique identifiers became widespread. Indeed, on Google+, over four billion accounts were eventually compiled, those being automatically granted to every registered Android device through about 2016 (the practice stopped about then). Google increasingly required phone numbers for account registration and recovery, "bribing" G+ members with "vanity" account names if they'd supply same.[1] The use of phone numbers as account validation tokens on numerous other services is now widespread.
________________________________
Notes:
1. I resisted the bait. Ironically, the vanity names couldn't be mapped back to the 20-ish digit UUID that otherwise identified accounts, and those who did make use of the nonnumeric IDs were largely excluded from archival efforts to save G+ content when the service shut down in 2019. I managed to create at least two backups of my own (non-vain) content, for what that's worth.