• NuclearDolphin@lemmy.ml
    link
    fedilink
    English
    arrow-up
    3
    ·
    17 hours ago

    This is why threat modeling is important.

    but what if I get arrested on some false pretenses and they use cellebrite to gain access?

    Chances are they can clone the eMMC and wait for a CVE. Or threaten or hold you until you cave. If a lawsuit is your only recourse, I would expect any constitutional barriers to be ignored in practice. Your best bet is to never end up being an explicit target, which may be more difficult for certain individuals.

    My threat model considers dragnet surveillance as the primary threat, so I’d compromise on surviving dirty maid type attacks in favor of reducing the information my device gives out.

    Obviously if your device is being actively exploited, you cannot be private. But your security requirements increase greatly if your data footprint indicates to them that you warrant targeted scrutiny.

    • NewOldGuard@lemmy.ml
      link
      fedilink
      English
      arrow-up
      1
      ·
      edit-2
      17 hours ago

      100% agree with you, for who I am and what I do I know that I need a device that is as tamper resistant as possible with the smallest attack surface feasible. That goes for remote execution as much as the evil maid scenario. But this is entirely catered to my threat model and risk tolerance. And sure there is the possibility of the rubber hose cryptanalysis but that doesn’t mean we should give up on securing as much as possible on the device side. It’s the swiss cheese model and we’re plugging a hole at a time lol

      I advocate for everybody to use as secure a device as practical, and for these mitigations to be the default, but I’m fundamentally speaking for myself in this thread with my stance on fairphone and /e/OS right now. I want to support repairability and ethical supply chains too without compromising on my more core tech needs