Live data from Hacker News

MikroPhone: A privacy enhanced, simple and featured RISC-V mobile phone

mikrophone.net

21–30 of 90 posts

Re: MikroPhone: A privacy enhanced, simple and featured RISC-V mobile phone

#21
post #4

This looks really cool! I don’t know if this more of a feature phone or a smart phone though. Would like to see pictures of completed builds and what they can do.

Current status section mentions "3d printable phone case designed in FreeCAD", but there don't seem to be corresponding file. I think the project is practically in breadboard stage.

Re: MikroPhone: A privacy enhanced, simple and featured RISC-V mobile phone

#22
post #18
post #11

It's a bit of an annoyance when products talk a lot about "privacy" and "security", but never once mention what sort of threat model they are private/secure against. Then add in something like a bespoke (unvetted?) communication protocol on top and my eyes really start to roll. The people who really want privacy & security enough to be willing to buy something like this will want a lot more detail than what is offere…

> ...but never once mention what sort of threat model they are private/secure against. You know, they're Secure(TM)! Against Threats(TM)! Buy me if you're scared of Threats(TM)! Threat modeling ("Secure from who? Under what conditions?") sort of stuff just doesn't seem to be a thing that's taught these days outside certain weird circles. And certainly something this project hasn't touched on in the slightest. But, ye…

This. And no 2G/3G to protect against SS7 threats. 4G/5G only can be quite limiting but in this threat model you want SS7 attacks out.

Re: MikroPhone: A privacy enhanced, simple and featured RISC-V mobile phone

#23
post #18
post #11

It's a bit of an annoyance when products talk a lot about "privacy" and "security", but never once mention what sort of threat model they are private/secure against. Then add in something like a bespoke (unvetted?) communication protocol on top and my eyes really start to roll. The people who really want privacy & security enough to be willing to buy something like this will want a lot more detail than what is offere…

> ...but never once mention what sort of threat model they are private/secure against. You know, they're Secure(TM)! Against Threats(TM)! Buy me if you're scared of Threats(TM)! Threat modeling ("Secure from who? Under what conditions?") sort of stuff just doesn't seem to be a thing that's taught these days outside certain weird circles. And certainly something this project hasn't touched on in the slightest. But, ye…

One of the amusing things I thought about with acquiring a "secure" iPhone was that you should just buy it from a random Walmart in the middle of nowhere in America.

The supply chain is so wide and vast, and even if they did tamper with it, the iPhone is basically the only phone out there that multiple third parties have ran through CT scanners, X-ray machines, and silicon R/E just to show off the tech inside the phone like a bunch of nerds for clicks, meaning you have lots of good reference material to check against for any potential tampering of your own acquisition.

Re: MikroPhone: A privacy enhanced, simple and featured RISC-V mobile phone

#24
post #17

Ah, another privacy-oriented phone project. As if the Pine-, Libre-, Jolla-, Neo900- etc. etc. endeavours weren't successful enough.

I was wondering - what is the status of those projects? And because they are (mostly?) open source, why not start with one of them?

Neo900 is dead. Unfortunately. It was always on shaky ground (the nature of a hardware project) but what seems to have killed it was PayPal withholding its funds for long enough to take the wind out of key people's sails. PayPal just decided to abruptly lock out the project account one day after accruing a substantial number of down-payments, and refused to give the funds back for around a year. By the time some progress started being made again, the funds were no longer enough and the project was at that point based on seriously obsolete hardware (as opposed to the regular kind of obsolete most hardware projects have to work with).

Re: MikroPhone: A privacy enhanced, simple and featured RISC-V mobile phone

#25
post #24
post #17

Earlier quoted context omitted.

I was wondering - what is the status of those projects? And because they are (mostly?) open source, why not start with one of them?

Neo900 is dead. Unfortunately. It was always on shaky ground (the nature of a hardware project) but what seems to have killed it was PayPal withholding its funds for long enough to take the wind out of key people's sails. PayPal just decided to abruptly lock out the project account one day after accruing a substantial number of down-payments, and refused to give the funds back for around a year. By the time some prog…

Why do people trust PayPal with their futures? It's also Neo900's fault - everyone knows by now what PayPal does.

Re: MikroPhone: A privacy enhanced, simple and featured RISC-V mobile phone

#26
post #2

Tbh I would accept anything usable without being bound neither to Google nor Apple. Like a Linux phone but with usable apps which is quite important. For example Samsung gets free MP3 player and more important, background-running voice recorder, which is extremely important for me, but was impossible to find on OnePlus One.

Is Librem 5 not such a device?

Re: MikroPhone: A privacy enhanced, simple and featured RISC-V mobile phone

#27
post #22
post #18

Earlier quoted context omitted.

> ...but never once mention what sort of threat model they are private/secure against. You know, they're Secure(TM)! Against Threats(TM)! Buy me if you're scared of Threats(TM)! Threat modeling ("Secure from who? Under what conditions?") sort of stuff just doesn't seem to be a thing that's taught these days outside certain weird circles. And certainly something this project hasn't touched on in the slightest. But, ye…

This. And no 2G/3G to protect against SS7 threats. 4G/5G only can be quite limiting but in this threat model you want SS7 attacks out.

Depends on your use case but.. just only use WiFi and never put a (e)SIM in it.

Re: MikroPhone: A privacy enhanced, simple and featured RISC-V mobile phone

#28
post #25
post #24

Earlier quoted context omitted.

Neo900 is dead. Unfortunately. It was always on shaky ground (the nature of a hardware project) but what seems to have killed it was PayPal withholding its funds for long enough to take the wind out of key people's sails. PayPal just decided to abruptly lock out the project account one day after accruing a substantial number of down-payments, and refused to give the funds back for around a year. By the time some prog…

Why do people trust PayPal with their futures? It's also Neo900's fault - everyone knows by now what PayPal does.

Why are paypal allowed to do this with impunity? You're not. I' not. Why are they allowed to break both the law and the social contract?

Re: MikroPhone: A privacy enhanced, simple and featured RISC-V mobile phone

#30
post #18
post #11

It's a bit of an annoyance when products talk a lot about "privacy" and "security", but never once mention what sort of threat model they are private/secure against. Then add in something like a bespoke (unvetted?) communication protocol on top and my eyes really start to roll. The people who really want privacy & security enough to be willing to buy something like this will want a lot more detail than what is offere…

> ...but never once mention what sort of threat model they are private/secure against. You know, they're Secure(TM)! Against Threats(TM)! Buy me if you're scared of Threats(TM)! Threat modeling ("Secure from who? Under what conditions?") sort of stuff just doesn't seem to be a thing that's taught these days outside certain weird circles. And certainly something this project hasn't touched on in the slightest. But, ye…

Er, no, that would be locked-down GrapheneOS, on a Pixel.

There's a multitude of reasons - but here's the biggest one: Apple's Lockdown mode is all or nothing. You can't selectively enable certain features that you may truly depend upon. On the other hand, GrapheneOS allows you to selectively disable individual security features that may be too overbearing. It would be far easier to daily drive a GrapheneOS Pixel than an iPhone in Lockdown, for that reason alone.

Post reply on HN