The Problem with Mobile Phones
ssd.eff.org
ssd.eff.org
To me, current mobile phones seem like a step backwards in many fronts, as highlighted by the EFF or the Neo900 developers [4]:
- It should be possible to install your preferred OS, pretty much like you do on a PC.
- Hardware components should be more open. When not possible, they should be isolated like the Neo900 will do [4].
These two things would lead to much better privacy, and less planned obsolescence. It's atrocious that many cell phones don't get software updates past the 24 months mark.
We should get much more serious about this. The current mobile landscape is depressing.
However, drivers in ARM platforms are very opaque. You rely upon the goodwill of the manufacturer to update them, and most of the time they don't. See how most devices get unsupported in Cyanogenmod after a while.
And in any case, all the privacy concerns remain. It's a hardware issue. Android would be fine.
The <> format has worked before for me here. ???
Blackphone uses Kismet WiFi Manager to prevent MAC broadcasting and other issues https://play.google.com/store/apps/details?id=net.kismetwire...
For such a ubiquitous device that holds so much personal data and is portable in ways laptops will never be, one wonders why we are designing mobiles to be just like tiny laptops with all the same protocols, applications and OS APIs. First, sure, it's easy, but who ever heard of an old-school phone dying from a DDoS attack (which now is the current major mobile threat)? Or, being taken over by malware and every contact, password and account login sent to the Maldives for quick smash-and-grab sessions against bank accounts and so forth?
Maybe the intrinsic issue is really that we are still doing the "make it smaller" thing with tech and calling that innovation instead of "make it different" which out of the box often comes with intrinsic security of its own for actually being different.
Second, OK, we ditch IP and flip to OSI protocols. Now apart from decreased security due to all this new software that'd have to be made, how would that make things more secure, at all? Everyone will still want to use the Internet, so it's not airgapping.
This argument makes no sense.
2) However, while I wasn't making an argument per se, more just thinking out loud about architecture choices, especially when they "mimic" systems that are not for the same purpose, I do believe that is a small part of the problem when it comes to mobile security as pertains to phones. And, maybe I'm also thinking that with that in mind, there might be room for a whole separate set of protocols and methods for interacting with the Internet (or a reasonable facsimile of it) from your phone, which is not a PC :-)
[0] https://www.skycure.com/blog/ios-shield-allows-dos-attacks-o...
I'm still getting my feet wet with this critical thinking exercise, especially where an exchange of ideas is required to hone my own! I'll have to come back to this one...
Security through obscurity is not entirely worthless, but certainly not worth the cost of starting all over from square one.
I can use my laptop without having any cloud identity tied to it - I don't need to give anyone my email address or card number just to log in. I don't have to upload my contact list or communication history to the cloud. I can install software on it that Microsoft or Apple haven't approved, and if I pay for software Microsoft or Apple don't take a cut. I can install different operating system, if I want. I can develop software on my laptop without special license and without paying Apple or Microsoft. When I develop software, I can share it with other people with laptops and they can run it. I can access filesystem in any way I want and directly modify, share or create files without them being transferred to the cloud.
Modern smartphones are very not like laptops.
Android is perhaps more like actual computer, but I'd guess that's mostly legacy - if Google made Android now, I'm sure they would make it more closed, and they are making it more closed with every release.
"Most mobile phones give the user much less control than a personal desktop or laptop computer would"
Why make your peace with it, fight it!
This way I would only need to take my phone out of airplane mode if I happen to be in a location where I can't use another phone to return pages.
The downside of a one way pager is that there is no way to know if the message got through. If you are in an elevator (or wherever) you simply never know of the page.
The only truly "off phone", is one without batteries or in a microwave, sans the power cord.
The important aspect of a modular mobile phone is not what you can add to it (silly little consumer modules) but what you ca subtract from it.
With a modular mobile phone, you could physically isolate the GPS/GSM/LTE/bluetooth components at will.
My prediction is that the google modular phone, whatever it's called, will have the cellular components on the base system and not removable, which is a pity.
> Paraben's StrongHold bags block out wireless signals from cell towers, wireless networks, and other signal sources to protect evidence.
Works both ways :)
The problem isn't so much 'mobile phones' the problem is smart mobile phones and the suppliers of software for them, and for all mobile phones the big black box that is the baseband processor and whatever goes on in there. Little snitches does not cover it.