# Device Sovereignty ## Identification Device sovereignty is retained authority over firmware, operating-system choice, package sources, permissions, debugging, interfaces, local data, and recovery paths. The notebook pursues it through open repositories, AOSP, custom ROMs, alternate mobile systems, and inspectable device internals. ## Notebook evidence - [[Scanned_20260730-1659#PDF page 4 — Galaxy Tab S7 firmware, UDisks2, and cellular identifiers|PDF page 4: Galaxy Tab S7 firmware, UDisks2, and cellular identifiers]] — The `T870` strings identify Samsung’s Wi-Fi Galaxy Tab S7 model family; Samsung’s official update history confirms SM‑T870 as Galaxy Tab S7 and places `T870XXU1BUAC` in the Android 11-era build lineage. `AP`, `BL`, `CSC`, and `HOME_CSC` are the familiar component slots used by Samsung/Odin firmware packages: application processor/system image, bootloader, regional/customer software configuration, and a user-data-preserving CSC variant. - [[Scanned_20260730-1659#PDF page 7 — F-Droid, Tutu, and 3C Android tools|PDF page 7: F-Droid, Tutu, and 3C Android tools]] — F-Droid is an installable catalog and repository ecosystem for free/open-source Android applications, while TutuApp represents a third-party distribution channel and 3C All-in-One Toolbox a device-management utility. F-Droid’s official documentation emphasizes reproducible repository metadata and user-controlled sources. The list reads as a **comparative acquisition surface**: trusted open-source repository, less-governed alternate store, and deep system utility. - [[Scanned_20260730-1659#PDF page 8 — Sideways duplicate of Android-tool list|PDF page 8: Sideways duplicate of Android-tool list]] — This is a physical duplication of page 7, not a new conceptual entry. Its sideways orientation suggests either a scanning-order artifact or deliberate reuse of the page margin. Archival retention matters because duplicated fragments reveal which tool triads were important enough to be recopied or re-photographed. - [[Scanned_20260730-1659#PDF page 9 — Old MacBook Pro startup security and firmware commands|PDF page 9: Old MacBook Pro startup security and firmware commands]] — This page records recovery and security-control points on an older Intel-era MacBook Pro: firmware password, Startup Security Utility, Safe Mode, password reset, kernel-extension utilities, and Keychain unlocking. `kextutil` and `kextunload` belong to the pre-System-Extensions model of macOS kernel extension management; their presence helps date the troubleshooting vocabulary. - [[Scanned_20260730-1659#PDF page 10 — Western Digital My Cloud credentials and UDF|PDF page 10: Western Digital My Cloud credentials and UDF]] — The Western Digital My Cloud EX4 was a network-attached storage appliance, and the page records multiple local identities against it. The appended UDF expansion is technically separate: Universal Disk Format is the optical-media filesystem standardized for DVDs and Blu-ray; Blu-ray ROM2 explicitly adopted UDF 2.5. The juxtaposition may reflect storage-format research migrating from NAS recovery into optical/archive compatibility. - [[Scanned_20260730-1659#PDF page 11 — TPM 2.0 and cloud identity directories|PDF page 11: TPM 2.0 and cloud identity directories]] — The page maps hardware trust to cloud identity. TPM 2.0 is the platform trust hardware/firmware standard used for protected key operations and measured boot; `tpm.msc` is Windows’ TPM management console. Azure Active Directory was renamed **Microsoft Entra ID** in 2023, while on-premises Active Directory retained its name. Okta, Google directory services, and OneLogin are federated identity/directory alternatives. - [[Scanned_20260730-1659#PDF page 12 — D-Bus, QEMU, SPICE, qcow2, and virt-manager|PDF page 12: D-Bus, QEMU, SPICE, qcow2, and virt-manager]] — D-Bus is a message bus for local inter-process communication; PCManFM is a lightweight Linux file manager. QEMU supplies machine virtualization/emulation, SPICE supplies remote-display and USB-redirection facilities, qcow2 supplies copy-on-write virtual disks, and virt-manager supplies a management GUI. QEMU’s documentation describes qcow2’s metadata and snapshot-oriented design, while the project’s support page points users toward virt-manager for a graphical workflow. - [[Scanned_20260730-1659#PDF page 13 — iOS jailbreak sources and FQDN/IP notes|PDF page 13: iOS jailbreak sources and FQDN/IP notes]] — The page catalogs iOS jailbreak sources and names `unc0ver`, a jailbreak project that historically supported multiple iOS versions and devices. The FQDN/IP example is ordinary DNS notation, but its presence beside jailbreak tools suggests the author was tracing download infrastructure or server endpoints. The final compound name remains unresolved and should not be normalized into a known product without visual or corpus corroboration. - [[Scanned_20260730-1659#PDF page 14 — Proxy exclusions, Lucky Patcher, and alternative Android stores|PDF page 14: Proxy exclusions, Lucky Patcher, and alternative Android stores]] — The loopback addresses belong in proxy-bypass lists so local services are not sent through an external proxy. Lucky Patcher, Uptodown, Aptoide, and PUBG form an alternate-distribution/modification cluster: patching or permission manipulation, third-party app stores, and a high-value target application. The page is evidence of **ecosystem mapping**, not proof that any app was modified. - [[Scanned_20260730-1659#PDF page 15 — SELinux, App Ops, and Android permission utilities|PDF page 15: SELinux, App Ops, and Android permission utilities]] — Android’s SELinux deployment enforces mandatory access-control policy over processes and files; Android runs SELinux in enforcing mode in production builds. App Ops and the surrounding utilities expose or organize app permissions, package lists, uninstall operations, and movement between storage locations. The page shows the author differentiating **kernel-level policy, framework-level app operations, and user-level utility wrappers**—three layers often conflated in casual Android security discussions. - [[Scanned_20260730-1659#PDF page 16 — OxygenOS OTA and Jitterbug/Lively transition|PDF page 16: OxygenOS OTA and Jitterbug/Lively transition]] — OxygenOS is OnePlus’s Android distribution, and “full OTA” denotes a complete over-the-air update package rather than a small incremental patch. Jitterbug’s consumer-phone service was rebranded under Lively; the repeated/corrected domain notes look like brand-transition normalization. The page’s deeper pattern is vendor firmware on one side and accessibility-oriented telecom branding on the other. - [[Scanned_20260730-1659#PDF page 21 — Encrypted identifier, link-local proxy bypass, and Apple restore terms|PDF page 21: Encrypted identifier, link-local proxy bypass, and Apple restore terms]] — The 169.254/16 block is IPv4 link-local addressing, often used when DHCP fails or for directly connected services. The page pairs proxy-bypass syntax with repeated Apple service fragments, thermal management, WWAN, and APNonce. APNonce participates in Apple’s personalized-restore authorization process; in jailbreak/recovery communities it is tracked because restore eligibility depends on signed, device-specific values. - [[Scanned_20260730-1659#PDF page 24 — BOSSA flashing, scrobbling, QFIL, and firmware update|PDF page 24: BOSSA flashing, scrobbling, QFIL, and firmware update]] — BOSSA is a host utility for programming Atmel/Microchip SAM microcontrollers through the SAM-BA bootloader; QFIL is Qualcomm’s flash-image loader used with supported chipsets. Their co-occurrence with firmware update and FUNcube suggests broad **device-recovery tooling**, spanning microcontrollers, Qualcomm devices, and radio/space-education hardware. “Scrobbling” normally means logging media-play events, but its role here is unclear. - [[Scanned_20260730-1659#PDF page 25 — Storage Access Framework and open mobile infrastructure map|PDF page 25: Storage Access Framework and open mobile infrastructure map]] — The page sketches an unusually coherent **sovereign-mobile stack**. Android’s Storage Access Framework mediates user-approved document access; Android documentation requires third-party apps to use it for portable storage. F-Droid/APKPure/APKMirror supply software, AOSP supplies the base operating system, Ubuntu Touch/PinePhone/Librem 5 represent alternative mobile platforms and hardware, Firebase supplies backend services, and Tor/OpenVPN/FreedomBox supply privacy and self-hosting. - [[Scanned_20260730-1659#PDF page 26 — ADB over TCP, LineageOS, SELinux, and ownCloud|PDF page 26: ADB over TCP, LineageOS, SELinux, and ownCloud]] — ADB can place its daemon in TCP mode on port 5555, although modern Android strongly prefers authenticated wireless-debugging workflows and warns that network exposure must be controlled. LineageOS is the community successor to CyanogenMod; SELinux remains the mandatory-access-control substrate. `android.owncloud.com` points toward self-hosted file synchronization. The page was integrating **debug transport, alternate firmware, policy enforcement, and private cloud** into one mobile-control architecture. - [[Scanned_20260730-1659#PDF page 27 — Android package names, Dr. Ketan ROM, and Tasker security tools|PDF page 27: Android package names, Dr. Ketan ROM, and Tasker security tools]] — The three package names identify Android personalization/System UI and the Secure Settings plug-in used by automation tools such as Tasker. `N986B` corresponds to the international Samsung Galaxy Note20 Ultra family, and Dr. Ketan is associated with custom Samsung ROM work. Samsara, Dr.Web, and Car Home Ultra broaden the page into fleet/telemetry, antivirus, and automotive interfaces. The source supports a customization/security test environment, not a claim that all packages coexisted on one device. - [[Scanned_20260730-1659#PDF page 28 — Pebble, Appium, XDA, Settings+, and realme UI|PDF page 28: Pebble, Appium, XDA, Settings+, and realme UI]] — Pebble automation, Appium’s desktop server GUI, XDA, Settings+, and realme UI place this page in **cross-device interface testing**. Appium is an automation framework for mobile application testing; XDA is a developer community around Android modification. The parenthetical “Batman/cricket” cannot safely be mapped to Rushikesh Kamewar or a package without more evidence. - [[Scanned_20260730-1659#PDF page 29 — Browser interception and FOSS download tools|PDF page 29: Browser interception and FOSS download tools]] — The page lists applications for intercepting share intents, downloading, and browsing through open-source or lightweight clients, then records One UI as the operating context. This is a user-level complement to the lower-level ADB/SELinux pages: instead of modifying the platform, it maps how content enters and leaves applications. - [[Scanned_20260730-1659#PDF page 30 — Ingenium unlock-word sequence and Dr. Ketan reference|PDF page 30: Ingenium unlock-word sequence and Dr. Ketan reference]] — The numbered words are structured like passphrases, activation words, game clues, or command vocabulary—many mean opening, freedom, or power. Because the sequence includes repeated `Alohomora` and a package-like identifier, the strongest interpretation is an **unlock/activation codebook** associated with an app or ROM workflow. It is not treated as a credential because the page does not label the words as a password, but the sequence remains security-sensitive contextually and is not generalized beyond the source. - [[Scanned_20260730-1659#PDF page 31 — Android launcher sizes, Gboard, and graphics-driver preferences|PDF page 31: Android launcher sizes, Gboard, and graphics-driver preferences]] — Launcher names and rough sizes are being compared as interface substrates, while Gboard and graphics-driver preference extend the comparison from home screen to input and rendering. The `Dev No!` notation may indicate a warning not to change a developer option. The page captures a practical concern with **how much of the visible Android experience can be replaced without destabilizing graphics**. - [[Scanned_20260730-1659#PDF page 32 — Android launcher survey headed APUS|PDF page 32: Android launcher survey headed APUS]] — This is a broader launcher taxonomy: feature-dense dashboards, Pixel emulations, tablet launchers, accessibility-oriented large interfaces, and minimalist designs. APUS is singled out at the top, anticipating the APUS corporate notes on pages 68–69. The page supports a sustained inquiry into the launcher as a **governance layer over Android**—controlling search, recommendations, app discovery, telemetry, and visual identity rather than merely icons. - [[Scanned_20260730-1659#PDF page 35 — Firewall, port discovery, cloud, and iPhone identity checklist|PDF page 35: Firewall, port discovery, cloud, and iPhone identity checklist]] — This checklist spans conceptual filesystem questions, firewall completion, port discovery, licensing software, cloud hosting, device repair, and iPhone interface settings. The opening idea—that files can be represented as images and move between partitions—appears to be an intuition about abstraction layers or disk-image containers, but it is not technically articulated enough to validate. - [[Scanned_20260730-1659#PDF page 36 — Application and iOS accessibility inventory|PDF page 36: Application and iOS accessibility inventory]] — The list combines enterprise remote management, scanning, finance, productivity, commerce, secure messaging, carrier software, and accessibility controls. The emphasis on VoiceOver, switches, AssistiveTouch, Braille, headphone safety, and call routing suggests an audit of iOS’s alternate interaction pathways. These pathways are not merely accommodations: they are privileged input/output surfaces that can reshape device control and automation. - [[Scanned_20260730-1659#PDF page 37 — iPhone Camera configuration checklist|PDF page 37: iPhone Camera configuration checklist]] — Apple documents these as advanced Camera controls: format compatibility, preserved modes/settings, Scene Detection, Smart HDR on supported models, Lens Correction, and viewing outside the frame. The chosen configuration privileges **predictability and minimally transformed capture** over computational enhancement. That is consistent with later forensic concerns: stable encoding and fewer automatic scene changes make images easier to compare across time. - [[Scanned_20260730-1659#PDF page 40 — Apple IOKit-style bus and accessory-controller inventory|PDF page 40: Apple IOKit-style bus and accessory-controller inventory]] — The strings resemble Apple IOKit registry class/property names captured from a device tree or diagnostic dump. SPI and I²C are low-level serial buses; Tristar is commonly associated with Lightning/USB accessory and charging negotiation; `IOAccessory…` names imply accessory-power and connection management. The precise roles of `CBTL1614`, `AIM Bus`, and `parrot` are not established by public documentation here. - [[Scanned_20260730-1659#PDF page 41 — Apple SMC/RTBuddy services, WildPackets, and Kismet|PDF page 41: Apple SMC/RTBuddy services, WildPackets, and Kismet]] — SMC denotes Apple’s System Management Controller domain; ASC/IOP/RTBuddy labels point toward coprocessor and inter-processor service architecture. WildPackets and Kismet are network-analysis/wireless-discovery references. The page therefore bridges internal device control planes and external radio observation. Because Apple’s private class names vary by platform and release, the component identities remain strong technical inference rather than fully verified public fact. - [[Scanned_20260730-1659#PDF page 42 — Linux graphics, Apple recovery, thermal, WWAN, and nonce fragments|PDF page 42: Linux graphics, Apple recovery, thermal, WWAN, and nonce fragments]] — This page is a cross-platform residue map: Python kernel, pixel-rendering library, web scanner, Linux graphics driver, audio server, a possible automotive unlock reference, Apple recovery services, thermal management, cellular interfaces, and nonces. The recurrence of MRT/readability/launch-daemon/APNonce terms confirms a persistent attempt to correlate process names across logs. The mixture also warns against false unification: similar words found in one diagnostic session may belong to unrelated software stacks. - [[Scanned_20260730-1659#PDF page 43 — CyanogenMod/AOSP chain to OWASP Goat training systems|PDF page 43: CyanogenMod/AOSP chain to OWASP Goat training systems]] — CyanogenMod was an aftermarket Android distribution whose community lineage continued as LineageOS; AOSP is Android’s open-source platform base. OWASP’s iGoat and WebGoat are intentionally insecure training applications, while CloudGoat provides vulnerable cloud scenarios. The chain shows a deliberate lab concept: root a device, install a controllable OS, then use vulnerable targets to study exploitation and defense. - [[Scanned_20260730-1659#PDF page 44 — XQuartz, freedesktop.org, Arch Linux, and Oh My Zsh|PDF page 44: XQuartz, freedesktop.org, Arch Linux, and Oh My Zsh]] — XQuartz provides the X.Org X11 server environment for macOS; freedesktop.org publishes interoperability specifications used across Linux desktops. Arch Linux and Parrot represent general-purpose and security-oriented Linux environments, while Oh My Zsh configures the Z shell and iTerm2 supplies a macOS terminal interface. This is a **portable Unix workspace stack** spanning display server, desktop standards, OS, shell, and terminal. ## Relationships and overlays The source places this record in an evidence cluster with [[3C All-in-One Toolbox|3C All-in-One Toolbox]] · [[Action Launcher|Action Launcher]] · [[Active Directory|Active Directory]] · [[AIO Launcher|AIO Launcher]] · [[Alohomora|Alohomora]] · [[Android Application Package|Android Application Package]] · [[Android Debug Bridge|Android Debug Bridge]] · [[Android Graphics Driver Preferences|Android Graphics Driver Preferences]] · [[Android Launcher|Android Launcher]] · [[Android Open Source Project|Android Open Source Project]] · [[Android Package Name|Android Package Name]] · [[Android Permissions|Android Permissions]] · [[Android Rooting|Android Rooting]] · [[Android Security Utilities|Android Security Utilities]] · [[APKMirror|APKMirror]] · [[APKPure|APKPure]] · [[App Ops|App Ops]] · [[Appium|Appium]]. The occurrence contributes to the notebook's larger model of [[Identity Continuity|identity continuity]], [[Device Sovereignty|device sovereignty]], and [[Continuity Architecture|continuity architecture]]. ## Evidentiary status and open leads Resolve the exact carrier represented by MCC 310/MNC 410 in the notebook’s time frame and the meaning of “[PERSON REDACTED] MI Router”; compare with device logs if archived. ## Source - [[Scanned_20260730-1659|Scanned_20260730-1659]] ## RT Buddy / Pegasus observed-log context **Owner-supplied observation:** Bryant McGill states that the RT Buddy/Pegasus identification arose when the relevant activity or resources appeared in logs together with [[CrashCapture|CrashCapture]] or [[Heimdallr|Heimdallr]], particularly through documented resources visible in those logs. The preserved logs are the cited observational basis. This records what was observed; it does not by itself establish that every Apple RTBuddy service reference is Pegasus, nor does page or log proximity alone prove infection, control, authorship, or attribution. ## Pegasus heuristic caution **Owner-supplied interpretation:** Bryant McGill states that finding Pegasus heuristics, standing alone, means nothing as proof of the underlying system or attribution. In his interpretation, “Pegasus” is a very clumsy cover for something else, which later documents in this archive will detail. Until those materials are incorporated, heuristic matches must not be treated as proof of Pegasus infection, NSO Group attribution, or final identification of the underlying mechanism.