Earlier quoted context omitted.
I remember the creator of CopperheadOS claiming the "Nexus 5" (which is EOL) is not secure because of hardware (baseband?) vulnerabilities that wouldn't be trivial to fix. Citation: https://twitter.com/DanielMicay/status/1058103333414522880
Basebands are generally terrible black boxes. Even for new devices, they're a major security concern.
Does anyone know anything about the GSMK Cryptophone 500? It's appears to be a modified Galaxy S3 with a heavily custom ROM and can double as an IMSI catcher. I wonder. Did they RE the baseband or replace it with their own?
https://www.cryptophone.de/en/products/mobile/cp500/
Interesting.