Hacker News new | ask | show | jobs
by Xen9 503 days ago
Absolutely best idea is to make an encrypted PDA & play forensic scientist by recording everything.

1. Get a Google Pixel 9, 9 Pro, or 9 Pro XL smartphone (Cellebrite-proofn at time of writing). 2. Verify images & GOS. 3. Disable biometrics & wireless connections. 4. Memorize with Anki or your own head a new, NIST-compliant passphrase with ≥ 8+ words. 3. Get a cover for the smartphone. 4. Buy EMI tape and electrically insulating waterproof tape. 5. Tape the insides of the cover with EMI, layering it & govering the inner walls as well, no gaps (overlay two adjacent layer always, say ≥ 1 cm, if possible) 6. Add one layer of the other tape to insides of the cover 7. Story inside your underpants 24/7 powered off when you don't use it.

My setup is more secure than not having phone, a Qubes laptop, a 2G burner, or not having phone.

2 comments

How is it more secure than not having a phone?
By capturing evidence of what happens to you that cannot be tampered with.
But that’s not security, it’s usability. Just by virtue of taking your phone to a less safe place you’re lowering its security. Taking a small offline camera would be a lot more secure if your concern is recording the events.
Any honest threat model assumes that any internet-connected device is already compromised…
If you‘re opening the cover, disconnecting antennas might be the way to go instead. Depending on the device, it‘s relatively painless and even reversible.
I believe they mean a cover as in a case that has a folding cover, not as in the external layer of the phone itself. So you effectively turn that otterbox-ish thing into a faraday cage that will enclose your phone.

I am not sure how I follow how that isn't completely negated as soon as you go to actually use the phone, though.

Most antennas require desoldering to disable, but mmWave & possibly NFC can be removed without it. Lining the case thoroughly with EMI tape edge-to-edge and adding another layer over any gaps blocks RF signal emission & reception. The screen side doesn't need shielding since antennas aren't directed through it. If you set & use USB-C for charging only and your installation passed PGP & attestation, then the OS disabling wireless components will also eliminate active remote attack surface & reduce passive remote attack surface at least remarkably.
Or, use a Faraday cage?