The idea is you don't use baseband functionality
at all in the main high-side device. It can be a PDA, connected over USB to a separate radio. There's no way the radio can do anything particularly evil except if there are implementation bugs over USB (API problems with whatever interface you build between them, most likely), but at least that can be inspected by end users and problems found/fixed.
These highly-integrated devices are basically inimical to decent security.
No (that project was an earlier version of blackphone/geekphone, actually! from what I've heard)