Live data from Hacker News

Pixel Security

security.googleblog.com

1–10 of 152 posts

Re: Pixel Security

#2
Encryption is all well and good but I feel like Google's handling of root causes a lot of issues.

There are a lot of pretty basic things (like ad blocking or monitoring battery usage) that require root, which severely impacts the security of the device.

EDIT: Okay, I stand corrected on ad blocking. Access to detailed battery stats however is locked behind the BATTERY_STATS permission which isn't accessible to anything except for system apps. That aside, there are other basic things like backup that also require root.

Re: Pixel Security

#4
Pixel/Google does not motivate a threat model under which to evaluate or understand their design and marketing promises, but we can take a hint from "protects your data if your phone falls into someone else's hands." - Namely thefts of opportunity.

Unlike other phone manufacturers, Google does not promise potential customers that your data will be protected from Google, it's partners and from law enforcement and mass surveillance programmes.

Therein this product doesn't provide a stronger security posture that competitors - and furthermore it's threat model and security properties do not meet what are in my opinion minimal reasonable requirements.

Re: Pixel Security

#5
Sorry - not post related:

#2 spot on HN, 2 comments, submitted 28 minutes ago.

Is this normal? Never seen that happen on HN before. Just curious

Re: Pixel Security

#6
post #2

Encryption is all well and good but I feel like Google's handling of root causes a lot of issues. There are a lot of pretty basic things (like ad blocking or monitoring battery usage) that require root, which severely impacts the security of the device. EDIT: Okay, I stand corrected on ad blocking. Access to detailed battery stats however is locked behind the BATTERY_STATS permission which isn't accessible to anythin…

Not true for either of them.

Apps can use the VPN API to do ad blocking without root, and there are tons of ways to do more battery monitoring without root, like the built in battery monitoring...

Re: Pixel Security

#7
post #2

Encryption is all well and good but I feel like Google's handling of root causes a lot of issues. There are a lot of pretty basic things (like ad blocking or monitoring battery usage) that require root, which severely impacts the security of the device. EDIT: Okay, I stand corrected on ad blocking. Access to detailed battery stats however is locked behind the BATTERY_STATS permission which isn't accessible to anythin…

I recently discovered that Firefox for Android support uBlock Origin.

Re: Pixel Security

#8

Pixel/Google does not motivate a threat model under which to evaluate or understand their design and marketing promises, but we can take a hint from "protects your data if your phone falls into someone else's hands." - Namely thefts of opportunity. Unlike other phone manufacturers, Google does not promise potential customers that your data will be protected from Google, it's partners and from law enforcement and mass…

>Unlike other phone manufacturers, Google does not promise potential customers that your data will be protected from Google, it's partners and from law enforcement and mass surveillance programmes.

Are you referring to Apple? Because they don't promise that either.

Re: Pixel Security

#9
post #8

Pixel/Google does not motivate a threat model under which to evaluate or understand their design and marketing promises, but we can take a hint from "protects your data if your phone falls into someone else's hands." - Namely thefts of opportunity. Unlike other phone manufacturers, Google does not promise potential customers that your data will be protected from Google, it's partners and from law enforcement and mass…

>Unlike other phone manufacturers, Google does not promise potential customers that your data will be protected from Google, it's partners and from law enforcement and mass surveillance programmes. Are you referring to Apple? Because they don't promise that either.

[deleted]
Post reply on HN