Conversation

Replying to
Yesterday, the government sued the publisher of #PermanentRecord for—not kidding—printing it without giving the CIA and NSA a change to erase details of their classified crimes from the manuscript. Today, it is the best-selling book in the world:
577
10.4K
Phone security has been something I've struggled with for a long time. I once spoke with 's about how it's possible to physically remove internal microphones and cameras from a phone, but even that only mitigates a portion of the threat.
32
1,837
But as long as your phone is turned on, even with "location permissions" disabled, the radios in the phone that connect it to all the nice things you like are screaming into the air, reporting your presence to nearby cell towers, which then create records that are kept forever.
70
2,282
Software is equally important. The iOS and Android operating systems that run on nearly every smartphone conceal uncountable numbers of programming flaws, known as security vulnerabilities, that mean common apps like iMessage or web browsers become dangerous: you can be hacked.
33
1,633
This Tweet was deleted by the Tweet author. Learn more
It doesn't support the Nexus 6P anymore since that device doesn't meet the security standards and is also end-of-life without full security updates available. It has never supported it while being known as AndroidHardening or GrapheneOS, only during the previous incarnation.
3
This Tweet was deleted by the Tweet author. Learn more
The Librem 5 doesn't meet the basic security expectations of GrapheneOS including having full security updates. It will ship on day one with serious vulnerabilities and no way to fix them. Similarly, it doesn't meet a lot of other standard privacy/security expectations either.
2
2
along with lying about their products. GrapheneOS expects hardware targets to meet basic security standards including having full security updates and basic hardware security features including proper verified boot / attestation, key derivation, the HSM-based keystore a lot more.
1
This Tweet was deleted by the Tweet author. Learn more
Show replies
This Tweet was deleted by the Tweet author. Learn more
An audio recording kill switch has substantial value as a final line of defence after the device has been compromised and all the data on it has already been obtained. They aren't providing one, but rather one disabling only a portion of the hardware able to do audio recording.
1
1
Show replies