Live data from Hacker News

Leaker reveals which Pixels are vulnerable to Cellebrite phone hacking

arstechnica.com

81–90 of 372 posts

Re: Leaker reveals which Pixels are vulnerable to Cellebrite phone hacking

#81

Earlier quoted context omitted.

eSIM can be QR code so if they wanted, Mexican vendor just pay and show QR code for you to scan.

The unfortunate problem with eSIM is that you can't swap it between phones.

You absolutely can. But it does need an internet connection for that. Which actually makes eSIM more secure than regular SIM.

Re: Leaker reveals which Pixels are vulnerable to Cellebrite phone hacking

#82

I've set up GrapheneOS on my Pixel with 2FA fingerprint + PIN unlock. No way will anyone be getting into it without my cooperation. My only issue was less compatibility with my local emergency services, since they can't see me on a map for some reason if I call from a GOS phone. My solution to that was a second Pixel as an emergency phone - one with the stock OS, that I'll swap sims with and take with me when hiking,…

Don't know if/how this works in the US, but the EU emergency number can always be called without a simcard/subscription, so no need to swap simcards. (And sometimes even from a locked phone)

Re: Leaker reveals which Pixels are vulnerable to Cellebrite phone hacking

#83
post #48

> Notably, the Pixel 10 series is moving away from physical SIM cards. Is it? I hadn't followed news of the new Pixels. I don't like the idea of modernizing this and going full eSIM. It will introduce a lot of new friction, somehow I don't doubt it. Just now arrived to Mexico for a quick trip and grabbed a prepaid SIM from a 7-11 in the airport. All quick and simple. I doubt things would be so seamless when not havin…

You can actually get a prepaid travel eSIM before you leave on holiday.

Re: Leaker reveals which Pixels are vulnerable to Cellebrite phone hacking

#84
post #28
post #22

Earlier quoted context omitted.

The government has ways of twisting the arms of uncooperative people/organizations into providing all the backdoors they need. Everything from increased tax and regulatory scrutiny to "discovering" CSAM on executives' computers or phones. The government does what it wants because it's the government. Mere laws generally don't stand in its way for long.

I think this is a very negative idea to promote: that laws should can be subverted. Everyone should believe that laws work and when they don't we should work to fix that, not assume that it can never be fixed.

It can be fixed, but not through the same protocols and institutions that have been compromised.

Re: Leaker reveals which Pixels are vulnerable to Cellebrite phone hacking

#85

Earlier quoted context omitted.

Another old-timer here who grew up with Gibsons. It was the only grocery store in town back in the days before WalMart invaded. Ammunition, camping gear, dry goods, garden supplies, farm and ranch supplies, blue jeans, shirts, ties, overalls, etc. They sold everything under one roof in a town of 2500. I thought they had all been swallowed up and shut down until I moved up here to N Texas and was surprised to find a G…

> I moved up here to N Texas and was surprised to find a Gibsons here. Curiosity kills the cat. What part of NTX? I'm willing to take a trip this weekend just for the lulz. You talking Sherman/Dennison/Paris/Gainesville north, or just Denton/McKinney north? Only thing I'm seeing is one way out west in Weatherford.

That's the closest one to me. I'm in that direction though not in that town. There on Main Street on the left heading south from the courthouse.

Re: Leaker reveals which Pixels are vulnerable to Cellebrite phone hacking

#86
post #3

They couldn't answer the question most on my mind: "We’ve reached out to Google to inquire about why a custom ROM created by volunteers is more resistant to industrial phone hacking than the official Pixel OS. We’ll update this article if Google has anything to say."

I'd almost want to avoid GrapheneOS because it gets so much attention from law enforcement that it's probably a big target for various agencies to find vulnerabilities in.

This doesn't make sense. If you're worried about the government targeting you, then what is the alternative... less hardened phones? At least Graphene will protect you better than the stock OS. If you're really that concerned then you shouldn't use anything going through cell tower (or take extreme precautions when doing so).

Re: Leaker reveals which Pixels are vulnerable to Cellebrite phone hacking

#87
post #60

Earlier quoted context omitted.

Two fixes that would be trivial to backport to mainline Android.

You can configure USB port for charging only in the developer options.

I think that's at the OS level. I think there are things that could be done through the firmware level.

Re: Leaker reveals which Pixels are vulnerable to Cellebrite phone hacking

#89

Earlier quoted context omitted.

Is grapheheOS actually harder to hack or does cellebrite just not put a lot of effort into supporting it because the very low odds of LEs running into one in the wild?

I read from an old HN post that three letter agencies hate graphen OS. The author heard it from defcon or some similar conference. I couldn’t find the post anyway :/ I think it is buried under one of the posts that discuss Defcon and Blackhat.

Wouldn't it be a total mindfuck if it turns out that Graphene is less secure[1] than stock Pixel, and this is all part of an ANOM-style honeypot operation that has Feds hyping it up, to trick interesting targets into adopting a less-effective security posture.

1. Such as via slower 0-day responses, for instance. This is a thought experiment, I'm nor alleging that this is what it is.

Re: Leaker reveals which Pixels are vulnerable to Cellebrite phone hacking

#90

Earlier quoted context omitted.

I read from an old HN post that three letter agencies hate graphen OS. The author heard it from defcon or some similar conference. I couldn’t find the post anyway :/ I think it is buried under one of the posts that discuss Defcon and Blackhat.

Wouldn't it be a total mindfuck if it turns out that Graphene is less secure[1] than stock Pixel, and this is all part of an ANOM-style honeypot operation that has Feds hyping it up, to trick interesting targets into adopting a less-effective security posture. 1. Such as via slower 0-day responses, for instance. This is a thought experiment, I'm nor alleging that this is what it is.

Anyone can build GrapheneOS from source code, which I doubt is true of any law-enforcement honeypot.
Post reply on HN