Hacker News new | past | comments | ask | show | jobs | submit login

It's when you turn on flight mode, right? /s

(You have to physically remove the wifi and bluetooth hardware)

Also, one-way diodes are fine, mostly.

But I agree completely. There's a major lack of awareness.

I'm quite angry that firewalls on phones isn't a thing - and that you have to use a VPN workaround. Why is such a basic feature missing? (Oh wait, I know: advertising revenue, and uh, intentional vulnerability)




You can use a firewall on GNU/Linux phones though.


except there's no such phones.

there's no pure linux even on the main cpu, let alone in the entire device with separate computers for radio, camera, lowpower mode, etc.


Sending this message from my Librem 5 used as a daily driver, https://en.wikipedia.org/wiki/Librem_5.


yeah. that's the least worse. but still much worse than even x86, which is already questionable but accepted as ok.

nothing on that SoC is free or open.

btw, misleading everyone by running the blobs in a separate core with the same accesses of the main ones just to brute force certification is even worse than admitting you couldn't get free of the blobs, like the pine phone people correctly did.


That's moving the goalposts; we started at

> You can use a firewall on GNU/Linux phones though.

And that's true. There are phones, that run GNU/Linux distros, that give you a working software firewall. Pointing at blobs doesn't make it not GNU/Linux on a phone with a firewall. At best it points to a place where a firewall could be undermined, but if that's your standard then (nearly?) everything fails, including actual literal firewall hardware appliances (I'd take Linux nftables on a blobbed network card over Cisco any day).


> including literal firewall hardware appliances

Correct, and not getting why that is the worse of the options puts you out of the discussion in this thread. sorry.


> with the same accesses of the main ones

Could you provide any links or details?


Same access to most of the buses. unless you keep all your secrets in one core registers and maybe local caches. anyway, I wouldn't know. nothing from those cores is open besides the ARM abi it is built based on.




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: