Live data from Hacker News

Leaker reveals which Pixels are vulnerable to Cellebrite phone hacking

arstechnica.com

21–30 of 372 posts

Re: Leaker reveals which Pixels are vulnerable to Cellebrite phone hacking

#21
post #10

Here's the full document without the blurriness: https://www.documentcloud.org/documents/24833831-cellebrite-... (it's been available since 2024 -- found by searching for "android os access support matrix" on documentcloud)

The point here is that the doc you linked is a year and a half old, this (if real) is much newer. Security is a constant arms race between attackers and defenders, nothing is static so updates of this nature are always welcome.

I'm not disputing that. :)

Re: Leaker reveals which Pixels are vulnerable to Cellebrite phone hacking

#22
post #4

Earlier quoted context omitted.

Short answer: Google is a business that can be compelled by the federal government in ways that nonprofits are resistant to. Ron Wyden identified one of these weaknesses in 2023: https://arstechnica.com/tech-policy/2023/12/apple-admits-to-...

No American company has a choice when the Feds want data stored on a company's server. That doesn't stop Apple or any other company from designing devices that attempt to keep prying eyes out of the data stored on your device.

The government has ways of twisting the arms of uncooperative people/organizations into providing all the backdoors they need. Everything from increased tax and regulatory scrutiny to "discovering" CSAM on executives' computers or phones.

The government does what it wants because it's the government. Mere laws generally don't stand in its way for long.

Re: Leaker reveals which Pixels are vulnerable to Cellebrite phone hacking

#24
post #13

I've set up GrapheneOS on my Pixel with 2FA fingerprint + PIN unlock. No way will anyone be getting into it without my cooperation. My only issue was less compatibility with my local emergency services, since they can't see me on a map for some reason if I call from a GOS phone. My solution to that was a second Pixel as an emergency phone - one with the stock OS, that I'll swap sims with and take with me when hiking,…

First I’m hearing Graphene causes issues with E911 - is this a setting?

[deleted]

Re: Leaker reveals which Pixels are vulnerable to Cellebrite phone hacking

#25
post #12

I've set up GrapheneOS on my Pixel with 2FA fingerprint + PIN unlock. No way will anyone be getting into it without my cooperation. My only issue was less compatibility with my local emergency services, since they can't see me on a map for some reason if I call from a GOS phone. My solution to that was a second Pixel as an emergency phone - one with the stock OS, that I'll swap sims with and take with me when hiking,…

Obligatory https://xkcd.com/538

https://grapheneos.org/features#duress :D

Re: Leaker reveals which Pixels are vulnerable to Cellebrite phone hacking

#26
post #7

Earlier quoted context omitted.

Let's be very clear: this is still Google's choice. Google could build a phone that they can't be compelled to do anything to after the phone is sold to their customer, but Google alone chooses to not invest in the security of the phones they're selling to their customers. Because: what is good for the government is now equally good for Google. Do we not remember how Google immediately enabled TLS everywhere, interna…

> how enshittified Google and Apple have become I don’t know about pop-ups or whatever, but as far as mobile security Apple appears to be running the table. Last cellebrite leak showed they couldn’t do anything in BFU, and you can tell Siri to put it back in BFU without hands while being arrested.

“Siri, whose phone is this” doesn’t work on recent iOS versions. You could ask it to reboot, but that requires confirmation

Re: Leaker reveals which Pixels are vulnerable to Cellebrite phone hacking

#27
post #16
post #7

Earlier quoted context omitted.

> how enshittified Google and Apple have become I don’t know about pop-ups or whatever, but as far as mobile security Apple appears to be running the table. Last cellebrite leak showed they couldn’t do anything in BFU, and you can tell Siri to put it back in BFU without hands while being arrested.

Lots more devices are safe BFU than just Apple's. It's not that complicated on a technical level - it's basically full-disk encryption. Apple sells the illusion of security and privacy, but they're not meaningfully more secure or private except from the device's owner. Remember when they made a big deal of blocking Facebook tracking, while simultaneously adding their own intrusive tracking?

> Lots more devices are safe BFU than just Apple's. It's not that complicated on a technical level - it's basically full-disk encryption.

So we agree: it's puzzling that Google can't manage to do it.

Re: Leaker reveals which Pixels are vulnerable to Cellebrite phone hacking

#28
post #22

Earlier quoted context omitted.

No American company has a choice when the Feds want data stored on a company's server. That doesn't stop Apple or any other company from designing devices that attempt to keep prying eyes out of the data stored on your device.

The government has ways of twisting the arms of uncooperative people/organizations into providing all the backdoors they need. Everything from increased tax and regulatory scrutiny to "discovering" CSAM on executives' computers or phones. The government does what it wants because it's the government. Mere laws generally don't stand in its way for long.

I think this is a very negative idea to promote: that laws should can be subverted. Everyone should believe that laws work and when they don't we should work to fix that, not assume that it can never be fixed.

Re: Leaker reveals which Pixels are vulnerable to Cellebrite phone hacking

#29
post #22

Earlier quoted context omitted.

No American company has a choice when the Feds want data stored on a company's server. That doesn't stop Apple or any other company from designing devices that attempt to keep prying eyes out of the data stored on your device.

The government has ways of twisting the arms of uncooperative people/organizations into providing all the backdoors they need. Everything from increased tax and regulatory scrutiny to "discovering" CSAM on executives' computers or phones. The government does what it wants because it's the government. Mere laws generally don't stand in its way for long.

The government certainly objected when Apple designed an implementation of encrypted cloud backups for iDevices.

That didn't stop Apple from eventually rolling out encrypted cloud backups anyway.

Apple also refused to insert a backdoor into iDevices when James Comey ordered them to do so. They took the FBI to court and forced them to back down.

Google is perfectly capable of fighting too, but their business model puts them at a huge disadvantage.

If you make your money spying on users to make ad sales more profitable, then you have no choice but to hand it over to any Federal, State or local agency that can convince a judge to issue a warrant.

Re: Leaker reveals which Pixels are vulnerable to Cellebrite phone hacking

#30

I've set up GrapheneOS on my Pixel with 2FA fingerprint + PIN unlock. No way will anyone be getting into it without my cooperation. My only issue was less compatibility with my local emergency services, since they can't see me on a map for some reason if I call from a GOS phone. My solution to that was a second Pixel as an emergency phone - one with the stock OS, that I'll swap sims with and take with me when hiking,…

> My solution to that was a second Pixel as an emergency phone

Picking a Pixel specifically as an emergency phone is quite the choice, given years of on and off 911 issues.

Post reply on HN