At least one phone design I looked at, a Samsung Galaxy S5 has all the peripherals like the interfaces for the cameras and microphones attached to a dedicated core. The radio core. Aka "baseband core". Along with the interfaces for the radio and for wifi/bluetooth.
None of this is exposed, everything is on the Samsung Exynos SOC. The phone runs a firmware AMSS ("Advanced Mobile Subscriber System") and that firmware has among other things all the drivers to operate the cameras and the codecs for the microphones (and speakers). The Cortex-A application cores are connected to the radio core with a serial interface which the Android rild (radio interface layer daemon) uses to send commands to the radio core.
There is nothing that stops them from including extra functionality in that firmware that lets them call into the phone and access the cameras and microphone along with the GPS location. Without any knowledge of the user.
The rild in the stock Samsung S5 firmware contains a FILESERVER with the operations create, delete, read, write on files and directories. It awaits commands from the radio core running AMSS. That means AMSS can do anything it wants to any file in the filesystem, including deleting files you are preferred not to have, maliciously changing information or planting incriminating files.
Another important thing to know is that SIMToolkit functionality can be triggered by a text message containing STK commands. Some phones reply back with a text message that contains their current GPS location. without informing the user.
Also, while the phone authenticates the subscriber identity to the mobile network, the mobile network is unauthenticated. This makes the use of IMSI catchers such as from Rohde & Schwarz ("Stingray") easy. An IMSI catcher pretends to be a base station of a legitimate network and causes phones to switch over to it by broadcasting spoofed Quality of Service information and providing a stronger signal than legitimate base stations.
This allows a man in the middle attack leading to call interception.
I just been using common sense when dealing with organizations number (1) "I don't have data breaches you have data breaches why would I give you more information" (the last one was my insurance company notified me they had a data breach a few months ago) go figure (we all know they are selling the data and claiming its a breach)
(2) what happens if someone steals my phone and it is part of 2 part authentication? the whole thing just seems like a bad idea,
but I am being forced even by the government to use two part ID (I just have a $25 flip phone)
I just want my phone to be a phone
I want my drivers license to be a license to drive a car
Google now censors videos by putting an age-restriction on it and the only way to access the video is by handing over a copy of your passport or some other paper to Google. That is rather dystopic to me, obviously I don't do that. So Google does both censorship and gets sensitive data. I don't know what Google does with this data, I just know that it is
I also have a laptop with no hard drive but 16 gigs of ram.. I load Core plus (Tiny core) linux into ram from USB, then remove the USB. Then everything I do is from Ram only. After a moment of setting up a browser, Im online completely with no trace after I shut down the laptop. I used to work for the Government and saw what tricks they used to "anonymous" people in the field. Although they had a different version of Linux that I have never encountered outside of that facility .. But due to it being classified, I will not say it's name. My job consisted of verifying employees adherence to the rules of holding their clearance levels. And we literally got into peoples lives in every manner described on this site.. And many many more.. Far more advanced than you could imagine.. As an example, We had laser Acoustic listening devices in 1990.. Police are just getting them now. That is how far behind civilian tech is ..Think about that.
Why I always use a burner phone..
Why I always piggyback on the local library wifi.
TOR browser and VPN as well. All of my email is based in Swiss
servers. Data is stored on a bios ,password protected SSD . Bios Password on the drive is extremely difficult to break without sitting at the machine.