4 ms·
Doesn't matter at all. If your adversary is the CIA, you cannot trust your mobile phone OS, firmware and drivers not to read and report your memory contents.
by c00lio 3y ago
Doesn't matter at all. If your adversary is the CIA, you cannot trust your mobile phone OS, firmware and drivers not to read and report your memory contents.
- matheusmoreira 3y agoI used to think that as well but IOMMU is a thing now. Read strcat's posts, they're really informative. He's the developer of GrapheneOS. https://news.ycombinator.com/threads?id=strcat https://news.ycombinator.com/threads?id=strcat
- c00lio 3y agoYour IOMMU needs to be programmed, just like your MMU. Programming is provided by the OS and driver. Early IOMMU configuration is provided by the firmware. Check mate.
- matheusmoreira 3y agohttps://news.ycombinator.com/item?id=20151431 https://news.ycombinator.com/item?id=20151431 > It can't improve the security of firmware directly, but it can certainly improve the isolation of it by auditing and improving IOMMU configuration
- pgeorgi 3y agoThe IOMMU that is subservient to the cell modem, where the latter runs code of unknown provenance with the ability for ad-hoc, targeted updates over the network?
- matheusmoreira 3y agoIsn't the modem one of the things isolated by the IOMMU? How is it subservient to it?
- fsflover 3y agoWhat if they all are FLOSS or isolated from the OS like on Linux phones?
- c00lio 3y agoIf they all were properly isolated there would be less of a problem, but proper isolation is hard. If they all were FLOSS, there would also be the hope of solving this problem, as long as you can prove that you are really running the right FLOSS blobs. But I know of no Linux smartphone that would really satisfy either of those conditions properly.
- fsflover 3y agoAFAIK my Librem 5 runs exclusively free software, except in (not perfectly but still) isolated WiFi and modem cards.