ExploreTrendingAnalytics
Nostr Archives
ExploreTrendingAnalytics
Ava1d ago
I’ve talked in depth about mobile privacy and security for years—here, with clients and organizations, elsewhere online, and on my website. But sometimes it helps to just watch a demonstration of this basic understanding. You're Still Traceable on GrapheneOS (And Here's Why) YT https://youtu.be/UiU8SxbYZcs?si=zPu4P4PuQeG_LW1X GrapheneOS is excellent at what it does. It hardens Android from the ground up—stronger sandboxing, exploit mitigations, hardened memory protections, and far tighter permission controls. It dramatically reduces the attack surface and makes it far harder for apps or exploits to compromise the device. But your phone is still a radio. Every smartphone contains a cellular baseband modem running proprietary firmware outside the control of the operating system. As long as the modem is on, the device is talking to towers. So the real question isn’t “is my OS private?” It’s: who are you trying to be invisible from? An abusive ex? Big Tech? Telecom providers? State-level actors? Because total invisibility is a lie. Privacy is about understanding the layers. Good OPSEC is about understanding your tools. And sometimes the correct tool for a radio… is a Faraday bag. #IKITAO #Privacy #OPSEC
💬 33 replies

Replies (33)

unit1d ago
A phone unique identifier is a distinct code assigned to a mobile device to recognize and track it across networks and services
0000 sats
ghost1d ago
Loving how you started using AI 👍🏼
0000 sats
OFFGRID1d ago
I wonder how the attack surface changes when they come out with their own device. Love graphene. The only downside is it gets tricky with some applications and one must find like workarounds or not use certain things
0000 sats
Freedom Tech Co.1d ago
Would you consider loading the video to a location outside of google? it's unplayable over vpn
0000 sats
Ava12h ago
I uploaded the liberated Nostr-native video in the post. If you can't see it, then it could be a relay or a client issue.
0000 sats
Freedom Tech Co.12h ago
Aah - was just slow to load, thought it was an image, thanks!
0000 sats
Efrat Fenigson1d ago
Thanks!
0000 sats
CITIZEN_ERASED1d ago
And being on flight mode doesn't necessarily mean the baseband is turned off...
0000 sats
008ebf5…e3df8923h ago
Fuck your ai voice
0000 sats
008ebf5…e3df8923h ago
The AI voice is bad
0000 sats
Spud23h ago
This is not an attack on you and I am a fan of actual privacy. A Faraday bag sounds cool but to me it seems, idk, temporary and not very useful really. If someone is trying to track you they're going to know where you are as soon as you open the bag. And you can't use the phone while it's in the bag so I don't see how that would be better than just turning the phone off.
0000 sats
Ava12h ago
📝 e1af8e07…
0000 sats
Eede3d9…79538223h ago
I recommend to never use it with mobile connected. But when you use it always do it with an anonymous SIM and route all traffic over For.
0000 sats
Ava12h ago
📝 e1af8e07…
0000 sats
Diyana21h ago
I want to watch this. Saving.
0000 sats
Ape Mithrandir20h ago
@Uncle Ted ⚡️ knows how to be invisible
0000 sats
Uncle Ted ⚡️4h ago
I do ?!?!?!
0000 sats
Anton16h ago
So the real question is when do I want to turn my radio on... FTFY
0000 sats
00916h ago
Wish you’d help w my iPhone and MacBook … had their way w me. And looks like biggest case of ip theft in history
0000 sats
Piotr16h ago
I saw those Faraday cages for phones and I've been thinking about buying some but this post actually made me "I'm gonna buy that fast"
0000 sats
Ava14h ago
Good instinct—get the bag. But a Faraday bag sitting on your desk while your phone is powered on and connected to Wi-Fi isn't doing anything. If you want to actually minimize your footprint, the starting point is understanding the layers. GrapheneOS is not magic. It's discipline expressed in software. The physics don't care about your OS. Your phone is a radio. GrapheneOS hardens the operating system exceptionally well—stronger sandboxing, exploit mitigations, hardened memory protections, tighter permission controls, and a significantly reduced attack surface. That matters. But it does not change the underlying reality that a smartphone contains multiple radios—cellular (baseband), Wi-Fi, Bluetooth, and others. When those radios are active, the device emits signals that can be observed or correlated. Edward Snowden summarized the principle in a 2019 tweet: "If I were configuring a smartphone today, I'd use @DanielMicay's @GrapheneOS as the base operating system. I'd desolder the microphones and keep the radios (cellular, wifi, and bluetooth) turned off when I didn't need them. I would route traffic through the @torproject network." https://x.com/Snowden/status/1175430722733129729 The actual stack if your threat model demands it: — All radios off. Airplane mode. Wi-Fi off. Bluetooth off. No SIM. — Ethernet via USB-C, wired directly to a network (not your home network if your threat model demands it). — Route all traffic through Tor via Orbot. Optionally, if you're concerned about your ISP seeing a Tor connection, run an always-on VPN with kill switch enabled first, then Tor via Orbot on top of it. Your ISP sees the VPN connection, not Tor. That's a personal call—not everyone trusts a VPN provider as a second party, and that's a valid position. — For calls and messaging—Signal or SimpleX over that connection. — Faraday bag when not in use. You can feed an Ethernet cable through and run it from inside the bag. GrapheneOS says it kills the radios in software. I believe that. But I still keep that phone in a Faraday bag—because I don't fully trust software to kill hardware. A phone with physical kill switches would be better. Until that exists cleanly, the bag is your physical guarantee. One note on Faraday bags: not all bags are equal. Buy quality and test them regularly. Put your phone in the bag, call it, text it. If anything gets through, the shielding isn't doing its job. — A note on DNS: DNS leaks can expose your queries before, during, or after your tunnel is established—often resolved by your ISP without you knowing. Your DNS resolver is also a separate trust decision. Even when your traffic is encrypted, whoever resolves your queries can see the domains you're visiting. Confirm DNS leak protection is enabled and know who is actually handling your queries. @3b7fc823…e194354f Ghost has written some excellent field manuals on this topic. The financial reality. Total device segmentation is not optional—it's structural. Banks and financial institutions actively block VoIP numbers, international eSIMs, and many MVNO numbers for SMS 2FA. And it's not just finance—this is becoming increasingly common across platforms and services of all kinds, many of which also reject alias emails. Your front-facing device with a real carrier SIM and a real email address isn't a compromise—it's a necessity if you participate in modern digital life. Having a front-facing identity is also less suspicious than having none. A cell phone—GrapheneOS or stock—is tracked at the carrier level regardless. That's a conscious choice, not a failure. For higher threat models—burner and bug-out discipline: — Buy it anonymously. Cash. Have someone else buy it if necessary. — Never power it on near your home or any location tied to your identity. — Always power it on and off at the same random location, at least five miles from home. Same intersection every time. That creates a false anchor point in your location data. — Pattern recognition is its own attack surface. Your movements create a mobility fingerprint—where you sleep, where you work, which restaurants you frequent, which addresses you visit regularly. This is called mobility fingerprinting, and it can identify you from location data alone without your name ever being attached. Same time, same spot, even "randomly"—that's a fingerprint. — Faraday bag. Always. The segmentation model: Device 1—front-facing daily. Real SIM. Real email. Banks, 2FA, carrier identity. GrapheneOS or stock—doesn't matter. Tracked and accepted. Device 2—private GrapheneOS. No SIM. Radios off. Ethernet. Tor. Signal. Device 3—burner/bug-out. Anonymous. Bag. Distance discipline. One more thing worth saying: the Android ecosystem is shifting. Google has been locking down device trees and hardware drivers, making it harder for projects like GrapheneOS to operate, and pushing users toward KYC through the official Play Store. That landscape is worth watching. None of this means you have to run a three-device stack to benefit from better privacy practices. This is tiered. At minimum—kill your radios when you're done using your phone. Note that on stock Android, Wi-Fi and Bluetooth may still perform background scanning for location services even when the toggles appear off. GrapheneOS disables this behavior by default and allows you to set timers that automatically turn Wi-Fi or Bluetooth off when they haven't been connected for a period of time. Airplane mode costs nothing. GrapheneOS is an excellent step toward better mobile security and privacy. It's just not a finish line. Total invisibility is a lie. But understanding the layers and building accordingly is how you stop being an easy target. Know your threat model. Build accordingly. #IKITAO #Privacy #OPSEC
liminal 🦠14h ago
At this point, privacy is playing an infinite game of leveling up. You don't play an infinite game to win, you play to keep the game going. You play to keep it interesting. So, you've played the game for a long time, all these years. An elite player outclassing all others. What's your prize? I know you don't play the privacy game for prizes, but what is it?? Mindset. You get mindset. Everyone sees it, everyone knows it. And it looks something like this. Private everywhere, except for your mind. You glorious warrior.
0000 sats
Matt 🛸12h ago
You could toss the phone in a lake and still be traceable in many areas (cameras and accompanying software). You'd have to go to perhaps impossible lengths to be totally invisible. I certainly can't. And even if you could, it would be temporary. No man is an island.
0000 sats
Ava12h ago
📝 e1af8e07…
0000 sats
0000 sats
Ava13h ago
One thing worth adding: GrapheneOS uses stronger MAC address randomization for Wi-Fi connections—reducing long-term identifiers that can be used to track your device across networks. Stock Android typically uses a persistent randomized MAC per network, which can still be correlated over time. This is one of the concrete ways GrapheneOS reduces Wi-Fi tracking exposure. It doesn’t change the physics. But it raises the floor.
0000 sats
GG Force G7h ago
When I connect to hotel WiFi I have to log in every single time. I would be annoyed if it weren't so darn cool that my MAC is spoofed each time.
0000 sats
sp00k12h ago
Ed needs to post on Nostr.
0000 sats
Keith Meola10h ago
Thanks for digging out and reposting Snowden's notes @Ava I stumbled upon @3b7fc823…e194354f website today, it's awesome 🫡
0000 sats
CR45H 0V3RR1D35h ago
If you’re going to go full tinfoil hat then you wouldn’t use an Android powered device at all…🤦🏻‍♂️
0000 sats
Piotr3h ago
I would rather put it in rubber boxes or something like that. Lead + rubber would be best (?).
0000 sats
BBarbosik2283h ago
Shaquille O’Neal Just Made History Again 📖
0000 sats
Aadenglvs6m ago
We are looking for someone who can lend our holding company 300,000 US dollars. We are looking for an investor who can lend our holding company 300,000 US dollars. We are looking for an investor who can invest 300,000 US dollars in our holding company. With the 300,000 US dollars you will lend to our holding company, we will develop a multi-functional device that can both heat and cool, also has a cooking function, and provides more efficient cooling and heating than an air conditioner. With your investment of 300,000 US dollars in our holding company, we will produce a multi-functional device that will attract a great deal of interest from people. With the device we're developing, people will be able to heat or cool their rooms more effectively, and thanks to its built-in stove feature, they'll be able to cook whatever they want right where they're sitting. People generally prefer multi-functional devices. The device we will produce will have 3 functions, which will encourage people to buy even more. The device we will produce will be able to easily heat and cool an area of ​​45 square meters, and its hob will be able to cook at temperatures up to 900 degrees Celsius. If you invest in this project, you will also greatly profit. Additionally, the device we will be making will also have a remote control feature. Thanks to remote control, customers who purchase the device will be able to turn it on and off remotely via the mobile application. Thanks to the wireless feature of our device, people can turn it on and heat or cool their rooms whenever they want, even when they are not at home. How will we manufacture the device? We will have the device manufactured by electronics companies in India, thus reducing labor costs to zero and producing the device more cheaply. Today, India is a technologically advanced country, and since they produce both inexpensive and robust technological products, we will manufacture in India. So how will we market our product? We will produce 2000 units of our product. The production cost, warehousing costs, and taxes for 2000 units will amount to 240,000 US dollars. We will use the remaining 60,000 US dollars for marketing. By marketing, we will reach a larger audience, which means more sales. We will sell each of the devices we produce for 3100 US dollars. Because our product is long-lasting and more multifunctional than an air conditioner, people will easily buy it. Since 2000 units is a small initial quantity, they will all be sold easily. From these 2000 units, we will have earned a total of 6,200,000 US dollars. By selling our product to electronics retailers and advertising on social media platforms in many countries such as Facebook, Instagram, and YouTube, we will increase our audience. An increased audience means more sales. Our device will take 2 months to produce, and in those 2 months we will have sold 2000 units. On average, we will have earned 6,200,000 US dollars within 5 months. So what will your earnings be? You will lend our holding company 300,000 US dollars and you will receive your money back as 950,000 US dollars on November 27, 2026. You will invest 300,000 US dollars in our holding company, and on November 27, 2026, I will return your money to you as 950,000 US dollars. You will receive your money back as 950,000 US dollars on November 27, 2026. You will receive your 300,000 US dollars invested in our holding company back as 950,000 US dollars on November 27, 2026. We will refund your money on 27/11/2026. To learn how you can lend USD 300,000 to our holding company and to receive detailed information, please contact me by sending a message to my Telegram username or Signal contact number listed below. I will be happy to provide you with full details. To learn how you can invest 300,000 US dollars in our holding, and to get detailed information, please send a message to my Telegram username or Signal contact number below. I will provide you with detailed information. To get detailed information, please send a message to my Telegram username or Signal username below. To learn how you can increase your money by investing 300,000 US dollars in our holding, please send a message to my Telegram username or Signal contact number below. Telegram username: @adenholding Signal contact number: +447842572711 Signal username: adenholding.88
Aadenglvs5m ago
We are looking for someone who can lend our holding company 300,000 US dollars. We are looking for an investor who can lend our holding company 300,000 US dollars. We are looking for an investor who can invest 300,000 US dollars in our holding company. With the 300,000 US dollars you will lend to our holding company, we will develop a multi-functional device that can both heat and cool, also has a cooking function, and provides more efficient cooling and heating than an air conditioner. With your investment of 300,000 US dollars in our holding company, we will produce a multi-functional device that will attract a great deal of interest from people. With the device we're developing, people will be able to heat or cool their rooms more effectively, and thanks to its built-in stove feature, they'll be able to cook whatever they want right where they're sitting. People generally prefer multi-functional devices. The device we will produce will have 3 functions, which will encourage people to buy even more. The device we will produce will be able to easily heat and cool an area of ​​45 square meters, and its hob will be able to cook at temperatures up to 900 degrees Celsius. If you invest in this project, you will also greatly profit. Additionally, the device we will be making will also have a remote control feature. Thanks to remote control, customers who purchase the device will be able to turn it on and off remotely via the mobile application. Thanks to the wireless feature of our device, people can turn it on and heat or cool their rooms whenever they want, even when they are not at home. How will we manufacture the device? We will have the device manufactured by electronics companies in India, thus reducing labor costs to zero and producing the device more cheaply. Today, India is a technologically advanced country, and since they produce both inexpensive and robust technological products, we will manufacture in India. So how will we market our product? We will produce 2000 units of our product. The production cost, warehousing costs, and taxes for 2000 units will amount to 240,000 US dollars. We will use the remaining 60,000 US dollars for marketing. By marketing, we will reach a larger audience, which means more sales. We will sell each of the devices we produce for 3100 US dollars. Because our product is long-lasting and more multifunctional than an air conditioner, people will easily buy it. Since 2000 units is a small initial quantity, they will all be sold easily. From these 2000 units, we will have earned a total of 6,200,000 US dollars. By selling our product to electronics retailers and advertising on social media platforms in many countries such as Facebook, Instagram, and YouTube, we will increase our audience. An increased audience means more sales. Our device will take 2 months to produce, and in those 2 months we will have sold 2000 units. On average, we will have earned 6,200,000 US dollars within 5 months. So what will your earnings be? You will lend our holding company 300,000 US dollars and you will receive your money back as 950,000 US dollars on November 27, 2026. You will invest 300,000 US dollars in our holding company, and on November 27, 2026, I will return your money to you as 950,000 US dollars. You will receive your money back as 950,000 US dollars on November 27, 2026. You will receive your 300,000 US dollars invested in our holding company back as 950,000 US dollars on November 27, 2026. We will refund your money on 27/11/2026. To learn how you can lend USD 300,000 to our holding company and to receive detailed information, please contact me by sending a message to my Telegram username or Signal contact number listed below. I will be happy to provide you with full details. To learn how you can invest 300,000 US dollars in our holding, and to get detailed information, please send a message to my Telegram username or Signal contact number below. I will provide you with detailed information. To get detailed information, please send a message to my Telegram username or Signal username below. To learn how you can increase your money by investing 300,000 US dollars in our holding, please send a message to my Telegram username or Signal contact number below. Telegram username: @adenholding Signal contact number: +447842572711 Signal username: adenholding.88
0000 sats
0000 sats