Privacy and the Problem of “Magical Devices”

Dear privacy seekers,

A common question I get as a privacy consultant is “what do you think of this privacy phone?” My initial response is prepared astonishment, my tone that of Buddy from ‘Elf’ when he walks in to a New York coffee shop whose outside sign proclaims, “The Word’s Best Cup of Coffee”. Buddy’s naive response is comical: “You did it! Congratulations! The world’s best cup of coffee.” He yells this to a confused audience that was obviously selling an exaggerated; indeed, a false bill of goods.

There is no such thing as a privacy device; the very idea is counterproductive to privacy. Individualized privacy is a mindset, a holistic series of plans that you train yourself to execute to deal with the surveillance apparatuses that are extreme and sometimes as adaptive as you are. A privacy-minded person educates himself. He practices and prepares dozens of tools to be put to use. He also refuses outright to use certain devices or tools. He minimizes. That’s as much a part of privacy strategizing as anything else.

But I understand. The “magical device” mindset is the same mindset that gets people buying the magical health supplement while claiming to be “holistic” (actual holism means the opposite: taking into account the thousands of decisions daily that affect one’s health). It’s the same person who gets a shot to reduce their obesity: never mind the side effects or the fact that habits have not been changed. It’s the same person who spends weeks researching the best golf club instead of practicing with the one she has. It’s an easy solution in a world where making a purchase is significantly faster and much more psychologically comforting than learning a lesson and putting rubber to road.

But it’s also more than just that. And here we get to some serious problems with “magical devices.”

First, “privacy devices” create a false dichotomy. The question is not whether to use the “regular” device or the “privacy” device. In fact, sometimes no device is the best device. When someone asks me about “phone privacy” my first response is, “Well, how far do you think you can get without a phone?” It’s not an extremist position. I’m prepared to yield quickly enough, but not until the person has gotten the message. And I actually know people who get around without a phone. I myself rarely use one and often travel around without one. Not having a phone is phone privacy. Once you acquire a phone, even anonymously with anonymous phone service, you’re now beaming your location back to a number of cell towers. You can’t be fully private and have a phone.

Using a privacy device is still adding to the data that you put out there. In my purposefully provocative posts on Twitter I sometimes pose the question, “What privacy app have you removed from your phone today to have more privacy?” Counterintuitive, but I hope people get the message: privacy is about having less exposure. It’s about doing less on surveillance systems. It’s not about “more”. It’s not a purchase. Privacy is minimalism. The prideful (and alleged) tech-savvy people on Privacy Reddit are incredibly vulnerable to this kind of thinking because they think that tech can solve any problem; when tech might itself be the problem.

Second and more severe: privacy devices actually encourage bad behavior. This is why I call them magical devices: they present an aura, however strongly in your mind, that what you do on this device is superior in privacy to what you did on your previous device. Indeed, the device might even encourage me to take further risks. It’s like back in the days of installing the latest highest-rated antivirus on Windows and promptly visiting the same shady website as before. Indeed, many of us would go to even shadier websites knowing that we have the highest-rated antivirus on our PC.

The companies selling these devices don’t help. Many of them claim their devices offer “privacy” and help you “go invisible” while failing to explain that this “privacy phone” is still subject to the same old-fashioned tracking as any phone: SIM or eSIM exposure, purchase exposure, triangulation, and all the other inherent problems of phone privacy. Sometimes the only “privacy” that is being advertised for this phone is some dubious offshoot of GrapeheneOS pre-installed on the phone. At worse, some of these snake oil companies sell non-FOSS software that basically amounts to “we give you privacy: trust us, bro.” It’s difficult to imagine how many naive people buying these devices have continued their old bad privacy habits, or worsened them, thinking that things have changed because of the device they’re using. Is using a privacy phone to install Instagram, loading up your profile, and tagging your location a private phone? I think not.

The “Use GrapheneOS bro” commentators are actually part of this problem. Actual phone privacy involves determining whether you need a phone and for what purposes, buying it privately, buying phone service privately (hugely important), and then avoiding as many apps on your phone as possible (no banking apps, no social media, no Uber, no Big Tech GPS, etc) so that you can use it for an emergency communication device while away from home. By saying “Just use GrapheneOS” you’ve removed an entire tapestry of strategy and given the green light for people to not have to think about strategy at all. GrapheneOS users in this scenario become “temporarily immortal.” They have a force field that magically protects them from all privacy exposure. Perhaps the best demonstration of this was the recent person in Atlanta who used the “duress PIN” feature from his GrapheneOS phone to wipe it before it could be searched. This was foolish, and he is now accused essentially of destroying evidence. What sounds good in forums of OPSEC theorycrafting, in a world where your guilty is increasingly a matter of how the judge feels when she wakes up in the morning, is a far cry from actual strategizing about crossing borders. As I’ve said on another occasion: “Magic devices are bad because they present the illusion that the device is offering them something that they themselves are meant to offer the device.”

Third, and in passing, I find privacy-specific devices to be poorly built. I’m typing this article on a Linux laptop company device whose trackpad goes haywire sometimes, randomly moving and even clicking on icons. Crazy, I know. I’ve talked about my struggles with these laptops over the years, and while there are solutions, it’s absolutely the case that these indie companies do not have the chops to produce serious hardware. I’m sorry to say it. We’ve seen with Purism the difficulty of producing affordable products that release on time. And then with System76 laptops stripped of the notorious Intel Management Engine you’re confining yourself to years’ old processors instead of the latest tech. Ironically, due to the way that laptop parts integrate, you’re less likely to have Linux compatibility with a “Linux-based laptop” than with classic Lenovo Thinkpad laptop. This I’ve learned the hard way. You’re much better off sticking to the big companies that have experience with building hardware and hijacking them as best you can with FOSS privacy operating systems.

Finally, privacy devices actually present new privacy and security risks. Privacy devices come from somewhere. From a company and from a warehouse. Centralizing a supply chain is a problem, especially when it sells a sensitive product. Cryptocurrency hardware wallets are especially vulnerable to supply chain attacks: hijack the supply in some way and you could have easy free money. In the case of privacy devices, ordering them from the company increases your odds that the devices have been tampered with. They also add a privacy device to your purchase history: tied to your credit card and to your home address or your post office box. Being on the record as having purchased a privacy device itself poses security and privacy risks. A privacy-focused person would buy a Google Pixel phone and then install GrapheneOS on it (after considering whether she needs it at all, of course). This is a much more innocuous purchase.

Add to this risk the fact that these privacy companies like to put their own stamp on software. Search around privacy device shops online and you’ll find many variants of GrapheneOS and Linux distributions, slightly modified and then with the company’s own branding slapped on it. Is that safer than using the vanilla GrapheneOS or Linux distribution? I think not. And hardly necessary.

So what’s the solution?

Knowledge, as usual. Understanding not just the tech but the systems that the tech taps in to. If you want privacy you have to exercise the mind, not just buy a product. And it’s crucial to pass this along the family members as well: they are the ones most likely to buy in to the “magical device” trope. We much teach ourselves and continue to teach others that privacy is about self-responsibility. It’s about minimalism. Privacy and sovereignty, as I’ve said elsewhere “are mindsets, not devices. They require an investment of understanding technology and systems in order to achieve them. Privacy is knowledge, not software—and definitely not hardware. Magic devices are bad because they present the illusion that the device is offering them something that they themselves are meant to offer the device.” Privacy devices breed incompetent users. And in a quickly-adapting world where the adversary changes quickly, if you’re a person that wants privacy, you must invest in the education and not in the panacea. As for me, I say “nay” to magical devices.

And I say “yes” to education disconnected from corrupting sponsorships.

Yours,

Gabriel Custodiet

To top