Live data from Hacker News

GrapheneOS and forensic extraction of data (2024)

discuss.grapheneos.org

121–130 of 208 posts

Re: GrapheneOS and forensic extraction of data (2024)

#121
post #4

There is no such thing like "bad government" and "good government". I mean - it really depends on people's views, therefore we must not blissfully put our data into govt hands because "they will protect us from terrorists and child rapists". What they will do, actually, is that for sure they will abuse innocent citizens at some point of time. They will. Even if they don't, they will. Or maybe they are doing it right…

Time for a Bitcoin moment, but for governments.

DAOs?

Re: GrapheneOS and forensic extraction of data (2024)

#122

I've always found it strange that GrapheneOS only runs on Google hardware. Can anyone explain this choice?

I agree with you, it's a dangerous and suspicious choice, https://news.ycombinator.com/item?id=45100831

Okay, I'll bite - what phone GOS should run on?

Remember the context is having a *secure* handset in hand.

Re: GrapheneOS and forensic extraction of data (2024)

#123
post #8
post #4

There is no such thing like "bad government" and "good government". I mean - it really depends on people's views, therefore we must not blissfully put our data into govt hands because "they will protect us from terrorists and child rapists". What they will do, actually, is that for sure they will abuse innocent citizens at some point of time. They will. Even if they don't, they will. Or maybe they are doing it right…

> therefore we must not blissfully put our data into govt hands Extending this reasoning, we should not blissfully put our data into anyone's hands. Government mission at least have a veneer of public servants, as opposed to private hands whose only real motivation is fiduciary obligations towards the shareholders.

it's about the interests of each party.

The interest of a government is to control its citizen, either now or at some point in the future.

The interest of a private company is to make more money.

Between the two, I certainly prefer a private company attempting to monetize my data rather than a government trying to control me either now or in the future. And let's stop the bs about "public servants", even in the EU which is maybe the most democratic bloc in the world, governments are trying to impose a chat control (among other laws restricting freedom). It's just in the nature of governments to control its population

Re: GrapheneOS and forensic extraction of data (2024)

#124

As long as the USB port of your phone is used, you can not stop it. This is the backdoor the governments want without having to be tethered. Vote for privacy. Vote against the police state. Vote for freedom. Libertarian rant aside. Governments fund these kinds of operations in secret so they can "effectively do their jobs". There's a ton of subcontractors working on AWS platforms that do analysis of this UFED "dump".…

> Vote

Sure... Vote "correctly" and then watch the world burn anyway when the politicians start spinning some nonsense about money laundering drug trafficking child molesting terrorists.

Re: GrapheneOS and forensic extraction of data (2024)

#125

Earlier quoted context omitted.

Thanks > These devices meet the stringent privacy and security standards and have substantial upstream and downstream hardening specific to the devices It still seems strange. A big part of GrapheneOS is to provide a safeguard from Googles data hoarding, yet it works primarily on Google phones.

Conspiracy theory time: GrapheneOS is a skunkworks project from Google, to sell more Pixel hardware.

Considering last years development and quite open Google hostility?

No.

GoS have provided a lot of patches upstream, Some of which were even applied. Despite that they wouldn't get early access to A16 just because. Access EVERY vendor promising to preinstall privileged Google services has.

Allegedly Google security team was very happy about that idea, but got vetoed by management.

Re: GrapheneOS and forensic extraction of data (2024)

#126

I really love Graphene OS but I _wish_ there was a version in which you could get a root shell and extract private data of apps you install when verified as the user. The developers are on record as saying that root blows a hole in their security model (it does!) but if there was _some_ way of doing it safely, so I can modify applications I as the user wish to, it would be my ideal OS. I know I could download and sel…

What is the threat model when enabling root on a phone and why can't it be mitigated? Root is enabled on most servers and desktops and we are surviving fine.

This is why most desktops and servers are comparably much less secure.

Check why Qubes OS was developed.

Re: GrapheneOS and forensic extraction of data (2024)

#128

Earlier quoted context omitted.

I agree with you, it's a dangerous and suspicious choice, https://news.ycombinator.com/item?id=45100831

Okay, I'll bite - what phone GOS should run on? Remember the context is having a *secure* handset in hand.

He's not wrong from a computer freedom perspective. GrapheneOS is actively hostile to things like complete root access. It blows a hole in the security model. It's also very much enabled by the exact same sort of user hostile cryptography that corporations use to lock down their devices. Things like hardware attestation which protects apps from us. We can't easily do things like MITM an app to reverse engineer it.

I still it's superior to any stock Android OS but the risks associated with giving up freedom for security must be considered. The ideal is to have security while simultaneously maintaining our power as the owners of the machine.

Re: GrapheneOS and forensic extraction of data (2024)

#129
post #49

Earlier quoted context omitted.

You can't have a cake and eat it. A root access is a big hole, there's no way mainline will support it. As for the possible way, you answered yourself already (custom keys and images) :)

> A root access is a big hole How so? On Linux, I can add an account to the sudoers list, and have the flexibility to configure the level of security appropriate for my use case. I have yet to experience any security issues (that I'm aware of). Why isn't this possible on my mobile device as well? This absolute stance is not right. Security is not binary, but a spectrum. I should be allowed to have full control over m…

How so?

Root can access absolutely everything.

Malware capable of getting root can access / exfiltrate anything, use your network, flash your firmware, can persist permanently, can use you as a vector.

Shellshock, log4j, Heartbleed. Hundreds of the big profile vulnerabilities that can be exploited on the system in an attempt to obtain root. And then you're cooked.

You really think a malware with the root access can't do much?

Why do you think selinux (and similar) even exist?

This isn't absolute stance. This is just stating that having a root access on the proruction/daily system is the opposite of security.

Re: GrapheneOS and forensic extraction of data (2024)

#130
post #79
post #49

Earlier quoted context omitted.

> A root access is a big hole How so? On Linux, I can add an account to the sudoers list, and have the flexibility to configure the level of security appropriate for my use case. I have yet to experience any security issues (that I'm aware of). Why isn't this possible on my mobile device as well? This absolute stance is not right. Security is not binary, but a spectrum. I should be allowed to have full control over m…

Well, anyone with actual root on a secure (locked, verified boot on) Android phone can hard brick it with a single command. Yes, you can yell at the user telling them it's their fault. Still something you usually do not want to support. I don't think having authorized temporary root is inherently insecure, but on the other hand making sure it is secure could be a huge time sink. Now, the original request here, modify…

Oh, I agree that the initial request is more than reasonable. Titanium Backup is something i miss every day.

Especially since Seedvault is.... ekhm, lacking.

Post reply on HN