Live data from Hacker News

Leaker reveals which Pixels are vulnerable to Cellebrite phone hacking

arstechnica.com

51–60 of 372 posts

Re: Leaker reveals which Pixels are vulnerable to Cellebrite phone hacking

#51
post #43

Earlier quoted context omitted.

Let's be very clear: this is still Google's choice. Google could build a phone that they can't be compelled to do anything to after the phone is sold to their customer, but Google alone chooses to not invest in the security of the phones they're selling to their customers. Because: what is good for the government is now equally good for Google. Do we not remember how Google immediately enabled TLS everywhere, interna…

Ah yes, Google could make a unhackable phone secure against state actors, they just do not feel like it. Not at all a problem that is viewed as so impossible that the very notion of it is beyond belief to the overwhelming majority of software developers. Google can just waltz on down to the corner store and get a jug of unhackable phone software. They just do not want to. The fact of the matter is that they are incap…

I’ll be asking Anwar down at the bodega to start carrying jugs of unhackable from now on! I want to try the new razzle dazzle berry and 4D cool ranch if he can get them…

Re: Leaker reveals which Pixels are vulnerable to Cellebrite phone hacking

#52
post #42

Another great thing about GrapheneOS (besides security) is that Google Play Services can be installed without elevated privileges and even in a separate profile which can't run in the background. This makes the phone suitable for both normal usage and for those cases where you need to use some "official" app. It passes Play Integrity "MEETS_BASIC_INTEGRITY" but of course doesn't pass higher levels but not because it'…

https://xkcd.com/1200/

Re: Leaker reveals which Pixels are vulnerable to Cellebrite phone hacking

#53
post #48

> Notably, the Pixel 10 series is moving away from physical SIM cards. Is it? I hadn't followed news of the new Pixels. I don't like the idea of modernizing this and going full eSIM. It will introduce a lot of new friction, somehow I don't doubt it. Just now arrived to Mexico for a quick trip and grabbed a prepaid SIM from a 7-11 in the airport. All quick and simple. I doubt things would be so seamless when not havin…

eSIM can be QR code so if they wanted, Mexican vendor just pay and show QR code for you to scan.

Re: Leaker reveals which Pixels are vulnerable to Cellebrite phone hacking

#54
Oh, that's what you get by being unaware of the cellphone brands. I was all excited thinking "hey, they found a way to hack phones through, I guess, screen firmware by setting a special sequence of pixels? How frakking cool!". How disappointed I was...

Re: Leaker reveals which Pixels are vulnerable to Cellebrite phone hacking

#55

Earlier quoted context omitted.

> the Kmart Blue Light Special Hello fellow old timer. Do kids today even get this reference other than possibly just on context? My other favorite old store was a place called Gibsons where their stores signage had each upper case letter as an individual square. After it went under, more than one location became SBINGOS joints where first/last squares were no longer lit.

Another old-timer here who grew up with Gibsons. It was the only grocery store in town back in the days before WalMart invaded. Ammunition, camping gear, dry goods, garden supplies, farm and ranch supplies, blue jeans, shirts, ties, overalls, etc. They sold everything under one roof in a town of 2500. I thought they had all been swallowed up and shut down until I moved up here to N Texas and was surprised to find a G…

> I moved up here to N Texas and was surprised to find a Gibsons here.

Curiosity kills the cat. What part of NTX? I'm willing to take a trip this weekend just for the lulz. You talking Sherman/Dennison/Paris/Gainesville north, or just Denton/McKinney north? Only thing I'm seeing is one way out west in Weatherford.

Re: Leaker reveals which Pixels are vulnerable to Cellebrite phone hacking

#56
post #21

Earlier quoted context omitted.

I'm not disputing that. :)

Fair, I suppose I've misunderstood. I took "it's been available since 2024" as a dismissal of this new information.

Also fair! I think "leaker" is just bristly to me in this context, when there's a nearly identical version of it just hanging out for folk to find. But also just a hope that some folk might poke around documentcloud for similar documents lying around. Lots of newsworthy gems in there just waiting to be picked up and this's a good example.

Re: Leaker reveals which Pixels are vulnerable to Cellebrite phone hacking

#57
post #9

Earlier quoted context omitted.

Cellebrite is like the Kmart Blue Light Special of Israeli spyware, when you compare it to Greykey and NSO Group offerings. I would not use their capabilities as the be-all end-all.

> the Kmart Blue Light Special Hello fellow old timer. Do kids today even get this reference other than possibly just on context? My other favorite old store was a place called Gibsons where their stores signage had each upper case letter as an individual square. After it went under, more than one location became SBINGOS joints where first/last squares were no longer lit.

You could say that they "hacked the Gibsons".

Re: Leaker reveals which Pixels are vulnerable to Cellebrite phone hacking

#59

Earlier quoted context omitted.

https://grapheneos.org/features#duress :D

Use that and you'll get charged with destruction of evidence

How would they know? Genuine question, I don't run GOS.

Re: Leaker reveals which Pixels are vulnerable to Cellebrite phone hacking

#60
post #44

Earlier quoted context omitted.

Is grapheheOS actually harder to hack or does cellebrite just not put a lot of effort into supporting it because the very low odds of LEs running into one in the wild?

It physically disables USB ports when locked which significantly reduces the attack surface + can be configured to automatically reboot.

Two fixes that would be trivial to backport to mainline Android.
Post reply on HN