Live data from Hacker News

Leaker reveals which Pixels are vulnerable to Cellebrite phone hacking

arstechnica.com

101–110 of 372 posts

Re: Leaker reveals which Pixels are vulnerable to Cellebrite phone hacking

#101
post #80

Earlier quoted context omitted.

GrapheneOS makes security trade-off that are inconvenient to the user. This results in a far more secure device, but nonetheless a device that the general public would find far more annoying. Google would lose a proportion of its user base by implementing the same protections. Example: https://old.reddit.com/r/GooglePixel/comments/ytk1ng/graphen... Also Google Pay is missing.

Which particular thing you consider inconvenient or even annoying? You can even install Google Play there. I see just one minor tradeoff - no face unlock.

That is a major feature. It prevents coerced unlocking.

Re: Leaker reveals which Pixels are vulnerable to Cellebrite phone hacking

#102
post #76

How come not a single Cellebrite device got "lost" and thoroughly analyzed? Surely quite a few police depts are rather lax.

One did "fall off a truck" and into Moxie Marlinspike's hands back in 2021: https://signal.org/blog/cellebrite-vulnerabilities/

A bunch of their software was also leaked in a hack back in 2023: https://ddosecrets.com/article/cellebrite-and-msab

Re: Leaker reveals which Pixels are vulnerable to Cellebrite phone hacking

#103
post #75
post #74

Earlier quoted context omitted.

iOS is also compromised according to other cellebrite docs so that makes me think Graphene OS just might not be worth the effort for them.

iOS was hackable in 2024 for certain hardware (in particular the checkm8 era phones) or for iOS versions which had known vulns at that point. Modern hardware with updates was still listed as “in research” which means “we can’t”.

The last leak was in 2024. Hopefully somone nabs the latest iOS release information

Edit: last released leak showed they had broken the then most recent iOS release (17.5.1) in AFU state on all but the most recent hardware which was marked "available in CAS"

https://discuss.grapheneos.org/d/14344-cellebrite-premium-ju...

The good news is neither pixel nor iOS seems to show full file system extract under BFU state in the recent tables I can find.

Re: Leaker reveals which Pixels are vulnerable to Cellebrite phone hacking

#104

Wow. I was just thinking about jumping ship from iPhone to Pixel.

All iPhones were vulnerable according to the last available iOS support matrix.

That's not quite correct, but you're not a million miles off: https://www.documentcloud.org/documents/24833832-cellebrite-...

To calibrate your sense of time, the iPhone 15 had been released in September 2023 and that doc is dated April 2024, so ~6 months.

And just for completeness, here was the Android doc that leaked at the same time: https://www.documentcloud.org/documents/24833831-cellebrite-...

Re: Leaker reveals which Pixels are vulnerable to Cellebrite phone hacking

#105

Earlier quoted context omitted.

Anyone can build GrapheneOS from source code, which I doubt is true of any law-enforcement honeypot.

See my footnote in original comment.

GrapheneOS updates really fast, like on a weekly basis. The trouble is that you have to trust the developers in general. Even if you did build it yourself, did you read all the code and scripts used to build it? But I think it's still a net benefit for a certain kind of user to have the code, and it raises the minimum complexity of any potential exploit.

Re: Leaker reveals which Pixels are vulnerable to Cellebrite phone hacking

#106

Earlier quoted context omitted.

Anyone can build GrapheneOS from source code, which I doubt is true of any law-enforcement honeypot.

Exactly what someone who sets up a honeypot targeting nerds would want you to think.

You can actually build it. But who has time to audit all that stuff? Then you know, there could be firmware hacks that make all the system-level backdoors a moot point.

Re: Leaker reveals which Pixels are vulnerable to Cellebrite phone hacking

#107
post #87

Earlier quoted context omitted.

You can configure USB port for charging only in the developer options.

I think that's at the OS level. I think there are things that could be done through the firmware level.

Since no phone on the market has open-source firmware, and the firmware likely has all the capabilities of the base system, I think arguing for a firmware lock on that is kind of pointless. Sure, every little bit of security helps, but ultimately you still need to trust a lot of stuff to use a smartphone or most other modern hardware.

Re: Leaker reveals which Pixels are vulnerable to Cellebrite phone hacking

#108
post #80

Earlier quoted context omitted.

GrapheneOS makes security trade-off that are inconvenient to the user. This results in a far more secure device, but nonetheless a device that the general public would find far more annoying. Google would lose a proportion of its user base by implementing the same protections. Example: https://old.reddit.com/r/GooglePixel/comments/ytk1ng/graphen... Also Google Pay is missing.

Which particular thing you consider inconvenient or even annoying? You can even install Google Play there. I see just one minor tradeoff - no face unlock.

Google OS-level integration is absent, and while Google Play Services can be installed, you're still missing things like Chromecast. Also, there's more manual configuration (although I don't remember exactly what, I've never used GrapheneOS). A lot of stuff you do get for free, but not all of it, and stuff that's been removed as a "feature" isn't always stuff that nobody wants.

Re: Leaker reveals which Pixels are vulnerable to Cellebrite phone hacking

#110
> https://signal.org/blog/cellebrite-vulnerabilities/

There’s always the hope they are hit back: Cellebrite can develop solutions to automate the hacking of target phones, but in doing so their physical devices are exposed to being hacked as well.

Post reply on HN