Live data from Hacker News

GrapheneOS and forensic extraction of data (2024)

discuss.grapheneos.org

71–80 of 208 posts

Re: GrapheneOS and forensic extraction of data (2024)

#71
post #24

Earlier quoted context omitted.

No. When the government fails to delivery what people need (not necessarily wants), you have a bad government. When gangs and bandits (or drugs, or diseases, or whatever) takes on the street, it's not about people's view, it's just bad stuff that the government need to address or there's no point on having a government.

Aside from the fact that there's a subjective definition problem here (how do we decide what people "need"?), I think this an unrealistic view. By this definition, every government that has ever existed or ever will exist is a "bad" government because no government can ever tackle every single problem 100% of the time. Many problems are extremely difficult to solve (e.g. global warming), and others simply cannot be s…

Everything is bad if we simply redefine "good" to mean "immaculately perfect and infallible in literally all conceivable scenarios"

Re: GrapheneOS and forensic extraction of data (2024)

#72

I really love Graphene OS but I _wish_ there was a version in which you could get a root shell and extract private data of apps you install when verified as the user. The developers are on record as saying that root blows a hole in their security model (it does!) but if there was _some_ way of doing it safely, so I can modify applications I as the user wish to, it would be my ideal OS. I know I could download and sel…

What is the threat model when enabling root on a phone and why can't it be mitigated? Root is enabled on most servers and desktops and we are surviving fine.

Re: GrapheneOS and forensic extraction of data (2024)

#73
post #4

There is no such thing like "bad government" and "good government". I mean - it really depends on people's views, therefore we must not blissfully put our data into govt hands because "they will protect us from terrorists and child rapists". What they will do, actually, is that for sure they will abuse innocent citizens at some point of time. They will. Even if they don't, they will. Or maybe they are doing it right…

> it really depends on people's views.

No it does not. It depends on peoples morals.

Re: GrapheneOS and forensic extraction of data (2024)

#74
post #4

There is no such thing like "bad government" and "good government". I mean - it really depends on people's views, therefore we must not blissfully put our data into govt hands because "they will protect us from terrorists and child rapists". What they will do, actually, is that for sure they will abuse innocent citizens at some point of time. They will. Even if they don't, they will. Or maybe they are doing it right…

> it really depends on people's views. No it does not. It depends on peoples morals.

> > it really depends on people's views.

> No it does not. It depends on peoples morals.

Morals are a kind of views.

Re: GrapheneOS and forensic extraction of data (2024)

#75
post #51

Earlier quoted context omitted.

That's interesting. Can you share a guide for doing that?

You can just follow the official build instructions with a single change: when specifying the build target, change it from -user to -userdebug: https://grapheneos.org/build#setting-up-the-os-build-environ...

Hhmm that seems like a hassle, TBH.

One of the things I like the most about GOS is the web installer, and how easy it is to use. If I need a custom build, to run my own server, and sacrifice performance for it, it doesn't seem worth it. It would also be good to know what a debug build entails, how exactly it is "less secure", and so on. Since this is unlikely to be documented by the GOS team, a 3rd party guide would still be helpful.

Re: GrapheneOS and forensic extraction of data (2024)

#78
post #13

[flagged]

This is kinda paranoid speech. GrapheneOS and Tor remain two of the best projects out there for privacy. I'd love to hear of other open alternatives, if any. ..."I don't trust google hardware, but I trust hardware from a dictatorial controlling regime" also does not really help your argument, sorry. Besides, they seem to be working with some OEM to get their own phone out. I'd love to receive daily updates on this, b…

Nice try. First you call names, then you complain about phones with dictatorial origins while both of them come from exactly the same origin, that point is moot.

Even worse security practice to use the software and hardware from exactly the same OEM in terms of security. There is a reason why open implementations are important on the cybersec field, precisely to avoid "trust" but move into the side of "verify" since they need to inter-operate.

Re: GrapheneOS and forensic extraction of data (2024)

#79
post #49

Earlier quoted context omitted.

You can't have a cake and eat it. A root access is a big hole, there's no way mainline will support it. As for the possible way, you answered yourself already (custom keys and images) :)

> A root access is a big hole How so? On Linux, I can add an account to the sudoers list, and have the flexibility to configure the level of security appropriate for my use case. I have yet to experience any security issues (that I'm aware of). Why isn't this possible on my mobile device as well? This absolute stance is not right. Security is not binary, but a spectrum. I should be allowed to have full control over m…

Well, anyone with actual root on a secure (locked, verified boot on) Android phone can hard brick it with a single command. Yes, you can yell at the user telling them it's their fault. Still something you usually do not want to support.

I don't think having authorized temporary root is inherently insecure, but on the other hand making sure it is secure could be a huge time sink.

Now, the original request here, modifying user app (I'd assume it's not system app) data, is reasonable. Designing a properly authenticated way to allow doing so would be an interesting challenge.

Re: GrapheneOS and forensic extraction of data (2024)

#80
>...because it is doing far more hardening than iOS against these attacks. iPhones also have security element, but the companies developing attacks, had successfully bypassed secure element throttling from Apple for years (and are doing the same with Samsung and Qualcomm

Is it true that Pixels are more hardened against brute forcing the security module and that iphones (and other phones) are easily bypassesed by these hacking tools?

Post reply on HN