This looks really cool! I don’t know if this more of a feature phone or a smart phone though. Would like to see pictures of completed builds and what they can do.
MikroPhone: A privacy enhanced, simple and featured RISC-V mobile phone
21–30 of 90 posts
Re: MikroPhone: A privacy enhanced, simple and featured RISC-V mobile phone
#22It's a bit of an annoyance when products talk a lot about "privacy" and "security", but never once mention what sort of threat model they are private/secure against. Then add in something like a bespoke (unvetted?) communication protocol on top and my eyes really start to roll. The people who really want privacy & security enough to be willing to buy something like this will want a lot more detail than what is offere…
> ...but never once mention what sort of threat model they are private/secure against. You know, they're Secure(TM)! Against Threats(TM)! Buy me if you're scared of Threats(TM)! Threat modeling ("Secure from who? Under what conditions?") sort of stuff just doesn't seem to be a thing that's taught these days outside certain weird circles. And certainly something this project hasn't touched on in the slightest. But, ye…
Re: MikroPhone: A privacy enhanced, simple and featured RISC-V mobile phone
#23It's a bit of an annoyance when products talk a lot about "privacy" and "security", but never once mention what sort of threat model they are private/secure against. Then add in something like a bespoke (unvetted?) communication protocol on top and my eyes really start to roll. The people who really want privacy & security enough to be willing to buy something like this will want a lot more detail than what is offere…
> ...but never once mention what sort of threat model they are private/secure against. You know, they're Secure(TM)! Against Threats(TM)! Buy me if you're scared of Threats(TM)! Threat modeling ("Secure from who? Under what conditions?") sort of stuff just doesn't seem to be a thing that's taught these days outside certain weird circles. And certainly something this project hasn't touched on in the slightest. But, ye…
The supply chain is so wide and vast, and even if they did tamper with it, the iPhone is basically the only phone out there that multiple third parties have ran through CT scanners, X-ray machines, and silicon R/E just to show off the tech inside the phone like a bunch of nerds for clicks, meaning you have lots of good reference material to check against for any potential tampering of your own acquisition.
Re: MikroPhone: A privacy enhanced, simple and featured RISC-V mobile phone
#24Ah, another privacy-oriented phone project. As if the Pine-, Libre-, Jolla-, Neo900- etc. etc. endeavours weren't successful enough.
I was wondering - what is the status of those projects? And because they are (mostly?) open source, why not start with one of them?
Re: MikroPhone: A privacy enhanced, simple and featured RISC-V mobile phone
#25Earlier quoted context omitted.
I was wondering - what is the status of those projects? And because they are (mostly?) open source, why not start with one of them?
Neo900 is dead. Unfortunately. It was always on shaky ground (the nature of a hardware project) but what seems to have killed it was PayPal withholding its funds for long enough to take the wind out of key people's sails. PayPal just decided to abruptly lock out the project account one day after accruing a substantial number of down-payments, and refused to give the funds back for around a year. By the time some prog…
Re: MikroPhone: A privacy enhanced, simple and featured RISC-V mobile phone
#26Tbh I would accept anything usable without being bound neither to Google nor Apple. Like a Linux phone but with usable apps which is quite important. For example Samsung gets free MP3 player and more important, background-running voice recorder, which is extremely important for me, but was impossible to find on OnePlus One.
Re: MikroPhone: A privacy enhanced, simple and featured RISC-V mobile phone
#27Earlier quoted context omitted.
> ...but never once mention what sort of threat model they are private/secure against. You know, they're Secure(TM)! Against Threats(TM)! Buy me if you're scared of Threats(TM)! Threat modeling ("Secure from who? Under what conditions?") sort of stuff just doesn't seem to be a thing that's taught these days outside certain weird circles. And certainly something this project hasn't touched on in the slightest. But, ye…
This. And no 2G/3G to protect against SS7 threats. 4G/5G only can be quite limiting but in this threat model you want SS7 attacks out.
Re: MikroPhone: A privacy enhanced, simple and featured RISC-V mobile phone
#28Earlier quoted context omitted.
Neo900 is dead. Unfortunately. It was always on shaky ground (the nature of a hardware project) but what seems to have killed it was PayPal withholding its funds for long enough to take the wind out of key people's sails. PayPal just decided to abruptly lock out the project account one day after accruing a substantial number of down-payments, and refused to give the funds back for around a year. By the time some prog…
Why do people trust PayPal with their futures? It's also Neo900's fault - everyone knows by now what PayPal does.
Re: MikroPhone: A privacy enhanced, simple and featured RISC-V mobile phone
#29Re: MikroPhone: A privacy enhanced, simple and featured RISC-V mobile phone
#30It's a bit of an annoyance when products talk a lot about "privacy" and "security", but never once mention what sort of threat model they are private/secure against. Then add in something like a bespoke (unvetted?) communication protocol on top and my eyes really start to roll. The people who really want privacy & security enough to be willing to buy something like this will want a lot more detail than what is offere…
> ...but never once mention what sort of threat model they are private/secure against. You know, they're Secure(TM)! Against Threats(TM)! Buy me if you're scared of Threats(TM)! Threat modeling ("Secure from who? Under what conditions?") sort of stuff just doesn't seem to be a thing that's taught these days outside certain weird circles. And certainly something this project hasn't touched on in the slightest. But, ye…
There's a multitude of reasons - but here's the biggest one: Apple's Lockdown mode is all or nothing. You can't selectively enable certain features that you may truly depend upon. On the other hand, GrapheneOS allows you to selectively disable individual security features that may be too overbearing. It would be far easier to daily drive a GrapheneOS Pixel than an iPhone in Lockdown, for that reason alone.