> Until basebands are mandated to be FOSS for security and safety reasons, Google is just moving the chairs around on the deck of a sinking ship.
I agree. I couldn't see much of a point in the techniques discussed when there's a huge elephant in the room, and you can't fix it, so I thought I was missing something obvious.
I wasn't: it's just security theater, doing something for the sake of doing something, while there's a big pink elephant in the room you should not look at:
> the IOMMU refuses to allow the OS to restrict the baseband processor's view into system RAM.
And I can't find any valid technical reason for that elephant to be in the room.
There shouldn't be limitations for accepting IOMMUs: "be liberal in what you accept and conservative in what you send"
> Some phones straight up admit the baseband is actively hostile and only communicates with it via serial
That looks like a fair assumption. You wouldn't have daemons listening as UID 0 on all ports, accepting then running the random binaries they get, so why would you magically assume it's ok to do the exact same but with baseband instead of a daemon?
> (which leads to poor performance, but a secure phone)
Can you recommend some phones?
I wanted to get a better understanding of the stack so I bought an original pinephone, with the grand plan of installing arch on it (for fun!)
Could it be made to work like that?
A simple search only found https://www.reddit.com/r/pinephone/comments/har9aj/pine_phon... which concludes with "I don't think the Pinephone can provide any of the security requirements of Graphene OS ( iommu isolation etc )"
What should I buy to explore the concept of IOMMUs on cellphones?