Live data from Hacker News

Leaker reveals which Pixels are vulnerable to Cellebrite phone hacking

arstechnica.com

71–80 of 372 posts

Re: Leaker reveals which Pixels are vulnerable to Cellebrite phone hacking

#71
post #60

Earlier quoted context omitted.

Two fixes that would be trivial to backport to mainline Android.

You can configure USB port for charging only in the developer options.

On Lineage this is the default behaviour: charging only until I tap on a notification to change it.

Re: Leaker reveals which Pixels are vulnerable to Cellebrite phone hacking

#72
post #22

Earlier quoted context omitted.

No American company has a choice when the Feds want data stored on a company's server. That doesn't stop Apple or any other company from designing devices that attempt to keep prying eyes out of the data stored on your device.

The government has ways of twisting the arms of uncooperative people/organizations into providing all the backdoors they need. Everything from increased tax and regulatory scrutiny to "discovering" CSAM on executives' computers or phones. The government does what it wants because it's the government. Mere laws generally don't stand in its way for long.

Well then why hasn’t the government “discovered” CSAM on apple executives’ computers? We know that at least last year iOS users who had reasonably modern hardware and kept up with software updates were very difficult to hack on par with Graphene, and last fall Apple introduced automatic reboots in iOS 18.1 which closed a lot of “wait for AFU exploit” paths off.

Re: Leaker reveals which Pixels are vulnerable to Cellebrite phone hacking

#73
post #42

Another great thing about GrapheneOS (besides security) is that Google Play Services can be installed without elevated privileges and even in a separate profile which can't run in the background. This makes the phone suitable for both normal usage and for those cases where you need to use some "official" app. It passes Play Integrity "MEETS_BASIC_INTEGRITY" but of course doesn't pass higher levels but not because it'…

https://xkcd.com/1200/

this is actually not the case on modern android lol

Re: Leaker reveals which Pixels are vulnerable to Cellebrite phone hacking

#74
post #66
post #60

Earlier quoted context omitted.

Two fixes that would be trivial to backport to mainline Android.

iOS already does both of this afaik. At least the automatic reboot part, I think the USB data functionality is disabled in some cases while locked too.

iOS is also compromised according to other cellebrite docs so that makes me think Graphene OS just might not be worth the effort for them.

Re: Leaker reveals which Pixels are vulnerable to Cellebrite phone hacking

#75
post #74
post #66

Earlier quoted context omitted.

iOS already does both of this afaik. At least the automatic reboot part, I think the USB data functionality is disabled in some cases while locked too.

iOS is also compromised according to other cellebrite docs so that makes me think Graphene OS just might not be worth the effort for them.

iOS was hackable in 2024 for certain hardware (in particular the checkm8 era phones) or for iOS versions which had known vulns at that point. Modern hardware with updates was still listed as “in research” which means “we can’t”.

Re: Leaker reveals which Pixels are vulnerable to Cellebrite phone hacking

#77
post #48

> Notably, the Pixel 10 series is moving away from physical SIM cards. Is it? I hadn't followed news of the new Pixels. I don't like the idea of modernizing this and going full eSIM. It will introduce a lot of new friction, somehow I don't doubt it. Just now arrived to Mexico for a quick trip and grabbed a prepaid SIM from a 7-11 in the airport. All quick and simple. I doubt things would be so seamless when not havin…

eSIMs feel like a solution waiting for a problem. Consumers are happy with physical SIMs, you obtain one, you put it in your phone then you forget about it until you swap your phone.

I'm sure eSIMs are a good idea if your aim is to gain even more control over our personal devices.

Re: Leaker reveals which Pixels are vulnerable to Cellebrite phone hacking

#78
post #3

They couldn't answer the question most on my mind: "We’ve reached out to Google to inquire about why a custom ROM created by volunteers is more resistant to industrial phone hacking than the official Pixel OS. We’ll update this article if Google has anything to say."

GrapheneOS makes security trade-off that are inconvenient to the user. This results in a far more secure device, but nonetheless a device that the general public would find far more annoying. Google would lose a proportion of its user base by implementing the same protections.

Example: https://old.reddit.com/r/GooglePixel/comments/ytk1ng/graphen...

Also Google Pay is missing.

Re: Leaker reveals which Pixels are vulnerable to Cellebrite phone hacking

#79
post #3

They couldn't answer the question most on my mind: "We’ve reached out to Google to inquire about why a custom ROM created by volunteers is more resistant to industrial phone hacking than the official Pixel OS. We’ll update this article if Google has anything to say."

I'd almost want to avoid GrapheneOS because it gets so much attention from law enforcement that it's probably a big target for various agencies to find vulnerabilities in.

Re: Leaker reveals which Pixels are vulnerable to Cellebrite phone hacking

#80
post #3

They couldn't answer the question most on my mind: "We’ve reached out to Google to inquire about why a custom ROM created by volunteers is more resistant to industrial phone hacking than the official Pixel OS. We’ll update this article if Google has anything to say."

GrapheneOS makes security trade-off that are inconvenient to the user. This results in a far more secure device, but nonetheless a device that the general public would find far more annoying. Google would lose a proportion of its user base by implementing the same protections. Example: https://old.reddit.com/r/GooglePixel/comments/ytk1ng/graphen... Also Google Pay is missing.

Which particular thing you consider inconvenient or even annoying? You can even install Google Play there.

I see just one minor tradeoff - no face unlock.

Post reply on HN