Nerd & opinion haver.

  • 0 Posts
  • 5 Comments
Joined 3 years ago
cake
Cake day: June 14th, 2023

help-circle
  • If your threat model includes Google as a trusted party, you’re an untrusted party to me.

    It is sus that they privilege Google software in so many ways over other FOSS implementations. Saying “well Google can be trusted to be reasonably secure” is not an excuse for anyone who considers Google to be one of the primary parties they wish to keep their information away from.

    I have a lot more trust in F-Droid because they take a principled stance against Google. Maybe their software is not as high quality as GOS devs would insist, but I can trust that they will not act against my interests, far more so than the GrapheneOS project.



  • This is why threat modeling is important.

    but what if I get arrested on some false pretenses and they use cellebrite to gain access?

    Chances are they can clone the eMMC and wait for a CVE. Or threaten or hold you until you cave. If a lawsuit is your only recourse, I would expect any constitutional barriers to be ignored in practice. Your best bet is to never end up being an explicit target, which may be more difficult for certain individuals.

    My threat model considers dragnet surveillance as the primary threat, so I’d compromise on surviving dirty maid type attacks in favor of reducing the information my device gives out.

    Obviously if your device is being actively exploited, you cannot be private. But your security requirements increase greatly if your data footprint indicates to them that you warrant targeted scrutiny.