1) Buy a slim ipod touch 2) Jailbreak (unnecessary) 3) App CryptMe allows transfer of plaintext from your computer through iTunes, password unlock on the device, quick search (nice), and according to Firewall iP (Cydia program) doesn't connect to the internet (or you could just always keep wifi off).
GPG isn't pretty, and support lags with OS X releases but you can do alot with it.
I've been using this methodology for securing cloud backups for several years. Using tools like Duplicity, you can safely encrypt data on potentially untrusted devices or networks using a public key, and keep the private key safely stored somewhere on the smartcard.
The downsides to these sorts of approaches is that encrypting data is easy, key management for decrypting it is a pain.
They might do it out of necessity: to "scratch itches".
Limitation breeds creativity. This is true in general, but certainly in computers. Ever heard of demoscene? By comparison to the constraints we had to work with in the 80's, the power of today's handheld computers (one usage of which is as a "phone") is hardly a limitation. But I guess it would depend on what you are trying to do. I have no idea what you would want to do. Only you know that.
As for what others might do, were they to be able to upload their own software to their phones, well, the only way to answer that question is to let them and see what comes out of it.
Only a fool would believe he could direct, let alone predict, all the uses that might be made of a particular software program, a particular language or a particular computer.
One use of a computer is as a communications device, aka a "phone". Another is a "game console". There are plenty of other uses for handheld computers even if you yourself cannot think of them.
Can I upload software to my SIM card? No.
Most phones accept some type of SIM card, while not all phones have a means of user-controlled offline external storage (microSD, etc.).
Why can't the user access a SIM card? Why can't she look at the software stored on a SIM card?
The SIM card slot is pretty much off-limits to the user. Yet the user owns the phone.
This is like buying a computer that has a special card slot owned by a single company or a consortium of companies that produce special cards only for their own use. The user is effectively denied access to the slot.
"Crapware" is just my opinion. Although I've heard others note the same thing.
The ChromeOS developers are currently porting coreboot to ARM, too.
http://en.wikipedia.org/wiki/Unified_Extensible_Firmware_Int...
Hence firmware to replace BIOS, with the same purpose as BIOS.
So do you re-program your UEFI firmware?
And since when is x86-64 an ARM system, since that was my remark?
FYI: the main Javacard applet on a SIM card is the GSM applet, the one you use to authenticate against your network. Other applets are useful for network operators: IMEI tracking sends them your phone ID to help them configure it correctly -- it is also used to track stolen phones. Another useful one updates your preferred foreign network list when you change countries, connecting you automatically to a cheaper network when available.
Uploading your own software will not do you much good. As mentioned above, CPU and memory are very limited on SIM cards, and Javacard is basically a glorified assembler you do not want to touch. SIM cards are mostly there to perform some simple crypto operations for network authentication and that's it.
As for running a known-secure firmware: in the end a SIM card only authenticate you against a Mobile Operator with a pre-shared key. If you believe your SIM is running a non-secure firmware, how can you trust your Mobile Network Operator not to do fancy stuff on their network behind your back?
Yes, the telecom owns the card they give you. Indeed, that is their property. But they don't need to own the smart card standard and use it to exclude users from using the slot.
Imagine if the motherboard you bought would had certain slots that were off-limits to you and open to use only by certain companies.
As for "glorified assemler", have you considered something more succinct, like FORTH. There's nothing glorious about Java.
Javacard is not Java. No OO, no classes, no GC, no floats, no strings, the only data type you can use is int16. Have fun.
I don't want no stinking Java, whether it's a small subset of the language or the full blown monster. For the task at hand, I'd have more fun with assembly language than anything prefixed with "Java".
The blank smart card possibilities are enticing. If we can use our own crypto.
Doesn't OpenMoko's WikiReader run FORTH?