28
Cape.co, GrapheneOS, Recco in MN madness
(sh.itjust.works)
Privacy has become a very important issue in modern society, with companies and governments constantly abusing their power, more and more people are waking up to the importance of digital privacy.
In this community everyone is welcome to post links and discuss topics related to privacy.
much thanks to @gary_host_laptop for the logo design :)
What this person is describing is a recent ios device with lockdown on, biometrics off, adp on and an understanding that no us carrier can offer cell service with security or privacy from the us government because of the lawful intercept backdoor.
They need to change their behavior to include turning their phone off frequently and incorporate practice using their phones duress inputs. They need to recognize that the phone is always a tracking device and cannot function in the way they want without being a tracking device. Because of that last part, and because the metadata delivered to phones is now used to direct police action, they need to understand that phones can’t come with them to organizing or protest and they can’t communicate about those things using the phone no matter what app or encryption is employed.
It’s also important to recognize that if the people they’re around don’t take these same precautions then it may be best to simply stop associating with those people in that way. Some friends are a lot of fun at parties but can’t be trusted.
Once all that is handled then a nice cherry on top is mullvad. Easy to understand and handle for even the most tech averse.
People will say that they don’t trust iphones because they’re not open source, but every leak from cop and intelligence tech companies like celebrite indicates that they are incapable of compromising an up to date ios device especially in bfu (not unlocked after being powered on) state. These leaks could be dismissed as limited hang outs, but the fact that we also see action based on metadata from the lawful intercept backdoor instead of direct compromise of devices seems to corroborate it.
Tldr: switch to apple and go prodromal
E: another benefit I forgot to mention is looking normal. The context of the request is one where the users fellow citizens may be snitching on them to law enforcement. Being able to blend in is absolutely worthwhile because every nosy neighbor or coworker is gonna be looking for signs of a user being a weirdo. Having a “hardened” ios phone and changing your behavior lets you blend right in.
What does turning the phone off frequently do? Also, by duress, do you mean anti-tamper destructive functionality? Like wipe info if unapproved authentication methods are used or something?
Cell phones have three states: unlocked, locked afu (after first unlock) and locked bfu (before first unlock). When in bfu the phone is much more difficult to attack because it won’t allow access to the pairing or anything really. It becomes even more restrictive with lockdown on.
Turning the phone off frequently accomplishes two things, it keeps the user from messing with it and makes sure if someone grabs you up in your home while you’re reading your newspaper smoking your pipe then they grab your phone while it’s turned off, in bfu lock when it’s powered up.
The duress inputs can do a lot with a little. You can lock the phone, turn it off, dial 911 etc.
iOS devices already have wipe after a number of failed pin attempts. I’m dubious of much more than that for this user. The threat model here is police picking you up and using a far reaching warrant and off the shelf technology to peer into your devices, not someone dead bugging your devices’ security chip. It’s only got to last as long as the cops are allowed to hold your shit, so the four or five years lead that leaks from various cybersecurity companies indicate that devices in bfu have over their opponents in intelligence seems perfect.
It’s common practice for law enforcement to go ahead and do the ten tries or whatever makes the device wipe itself before they give it back to you anyway, so it’s a double edged sword.
There is a meshtastic Lemmy community. I think it has limited functionality. Like text only. IIRC it is low frequency, like 900 MHz or something, and is reliable. You have these walkie talkie looking devices, but they don't do voice that I'm aware of. Also, no issues with needing ham license or any of that. I'd be hard pressed to think there was not a community there that didn't have nodes set up. I don't know about security, but it might be under the radar.
There is a meshtastic map, but smaller networks in your community might not register, which is good.
Again, speaking as a radio operator, for this users needs its tough to recommend a radio solution to the non-technical especially when it’s a mesh based hobbyist one the user will be relying on to communicate securely.
Radio also sticks out like sore thumb and it’s important to be able to look normal.