Comment by 555244466
7 hours ago
The Librem 5 uses a bottom of the barrel, standard industrial CPU from 2017 with no updates. It is no more open than a Google Pixel or any other mobile device. it lacks proper updates, isolated radios, and any form of hardening. The kill switches are also useless if your device is fully compromised and turned into a spying device, all of your data is already gone. The only thing the switches do as a last resort is block voice recording, which is an improper way of doing it since speakers are essentially just microphones in reverse.
> CPU from 2017 with no updates
This is false. Please stop writing false statements without any links. NXP promises to produce the i.MX 8M Quad until Jan. 2033. The support will be even longer.
> it lacks proper updates
This is FUD.
> isolated radios
They are isolated with USB. This might be slightly weaker than IOMMU, but for me the benefit of freedom is worth it. There is no shared memory.
> it lacks proper updates, isolated radios, and any form of hardening
FUD and false information. Please stop this.
> The kill switches are also useless if your device is fully compromised
This is false again. It doesn't matter how much my device might be compromised. The attacker will not get any access to the shut down sensors, radios or voice/video, if I use the three kill switches.
> since speakers are essentially just microphones in reverse
Librem 5 speakers do not support this.
Not OP, but
> This is false. Please stop writing false statements without any links. NXP promises to produce the i.MX 8M Quad until Jan. 2033. The support will be even longer.
I think they meant that the processor itself is old. It supports ARMv8 and is lacking the enhanced memory protection and execution features of the ARMv9-A processors on newer phones.
> This is false again. It doesn't matter how much my device might be compromised. The attacker will not get any access to the shut down sensors, radios or voice/video, if I use the three kill switches.
The problem is that your device can be compromised quite easily and without you knowing. The kill switches are moot at that point.
The kill switches will work independently on a compromise. Why are they moot? Also, it's possible to completely reflash the device in case of doubt.
"quite easily" strongly depends on what exactly you are doing. For example, if I use Firefox with NoScript, then it is not very easy.
5 replies →