Earlier quoted context omitted.
The point here is that the doc you linked is a year and a half old, this (if real) is much newer. Security is a constant arms race between attackers and defenders, nothing is static so updates of this nature are always welcome.
I'm not disputing that. :)
Leaker reveals which Pixels are vulnerable to Cellebrite phone hacking
31–40 of 372 posts
Re: Leaker reveals which Pixels are vulnerable to Cellebrite phone hacking
#32Earlier quoted context omitted.
Let's be very clear: this is still Google's choice. Google could build a phone that they can't be compelled to do anything to after the phone is sold to their customer, but Google alone chooses to not invest in the security of the phones they're selling to their customers. Because: what is good for the government is now equally good for Google. Do we not remember how Google immediately enabled TLS everywhere, interna…
> how enshittified Google and Apple have become I don’t know about pop-ups or whatever, but as far as mobile security Apple appears to be running the table. Last cellebrite leak showed they couldn’t do anything in BFU, and you can tell Siri to put it back in BFU without hands while being arrested.
Source? Note that "disables faceid/fingerprint" isn't the same as "BFU".
Re: Leaker reveals which Pixels are vulnerable to Cellebrite phone hacking
#33Earlier quoted context omitted.
> how enshittified Google and Apple have become I don’t know about pop-ups or whatever, but as far as mobile security Apple appears to be running the table. Last cellebrite leak showed they couldn’t do anything in BFU, and you can tell Siri to put it back in BFU without hands while being arrested.
Lots more devices are safe BFU than just Apple's. It's not that complicated on a technical level - it's basically full-disk encryption. Apple sells the illusion of security and privacy, but they're not meaningfully more secure or private except from the device's owner. Remember when they made a big deal of blocking Facebook tracking, while simultaneously adding their own intrusive tracking?
That's not the full story. Using LUKS encryption on your linux laptop might make it "safe BFU", but only if you're using a high entropy password. Most people don't want to enter a 24 character password to unlock their phone, so Apple/Google have to add dedicated security hardware to resist bruteforce attempts, hence the vulnerabilities.
Re: Leaker reveals which Pixels are vulnerable to Cellebrite phone hacking
#34They couldn't answer the question most on my mind: "We’ve reached out to Google to inquire about why a custom ROM created by volunteers is more resistant to industrial phone hacking than the official Pixel OS. We’ll update this article if Google has anything to say."
Re: Leaker reveals which Pixels are vulnerable to Cellebrite phone hacking
#35Re: Leaker reveals which Pixels are vulnerable to Cellebrite phone hacking
#36I've set up GrapheneOS on my Pixel with 2FA fingerprint + PIN unlock. No way will anyone be getting into it without my cooperation. My only issue was less compatibility with my local emergency services, since they can't see me on a map for some reason if I call from a GOS phone. My solution to that was a second Pixel as an emergency phone - one with the stock OS, that I'll swap sims with and take with me when hiking,…
Is there anything actually preventing Samsung or another vendor from adopting GrapheneOS's security innovations?
Re: Leaker reveals which Pixels are vulnerable to Cellebrite phone hacking
#37Re: Leaker reveals which Pixels are vulnerable to Cellebrite phone hacking
#38They couldn't answer the question most on my mind: "We’ve reached out to Google to inquire about why a custom ROM created by volunteers is more resistant to industrial phone hacking than the official Pixel OS. We’ll update this article if Google has anything to say."
Is grapheheOS actually harder to hack or does cellebrite just not put a lot of effort into supporting it because the very low odds of LEs running into one in the wild?
Re: Leaker reveals which Pixels are vulnerable to Cellebrite phone hacking
#39Wow. I was just thinking about jumping ship from iPhone to Pixel.
Re: Leaker reveals which Pixels are vulnerable to Cellebrite phone hacking
#40I've set up GrapheneOS on my Pixel with 2FA fingerprint + PIN unlock. No way will anyone be getting into it without my cooperation. My only issue was less compatibility with my local emergency services, since they can't see me on a map for some reason if I call from a GOS phone. My solution to that was a second Pixel as an emergency phone - one with the stock OS, that I'll swap sims with and take with me when hiking,…
Is there anything actually preventing Samsung or another vendor from adopting GrapheneOS's security innovations?