Live data from Hacker News

Leaker reveals which Pixels are vulnerable to Cellebrite phone hacking

arstechnica.com

111–120 of 372 posts

Re: Leaker reveals which Pixels are vulnerable to Cellebrite phone hacking

#111
post #44

Earlier quoted context omitted.

Is grapheheOS actually harder to hack or does cellebrite just not put a lot of effort into supporting it because the very low odds of LEs running into one in the wild?

It physically disables USB ports when locked which significantly reduces the attack surface + can be configured to automatically reboot.

The auto reboot is configured by default. Its quite a long window, every 18 hours or so from memory. It can be configured to be shorter than this.

I experimented with one hour, but missed an alarm.

Its good security practice to reboot your phone before going to bed, this puts it in the much harder to break in to BFU state.

Re: Leaker reveals which Pixels are vulnerable to Cellebrite phone hacking

#113
If there's one thing I find the most galling about Cellebrite and the larger realm of state-sponsored hacking, it's that it's practically destroyed the ability to jailbreak devices. Pretty much everything on PPL/SPTM has no public jailbreaks to speak of anymore, at least not until way after the feds have thoroughly 0wned you first.

While some of this comes down to "Apple increased their security posture", a lot of it is that these exploits are $$$ now... and also that nation state actors only really care about data exfiltration. It's https://xkcd.com/1200/ all over again. The thing the nerds actually want is, well, not useless to the glowies, but it is definitely overkill.

Re: Leaker reveals which Pixels are vulnerable to Cellebrite phone hacking

#114
post #75

Earlier quoted context omitted.

iOS was hackable in 2024 for certain hardware (in particular the checkm8 era phones) or for iOS versions which had known vulns at that point. Modern hardware with updates was still listed as “in research” which means “we can’t”.

The last leak was in 2024. Hopefully somone nabs the latest iOS release information Edit: last released leak showed they had broken the then most recent iOS release (17.5.1) in AFU state on all but the most recent hardware which was marked "available in CAS" https://discuss.grapheneos.org/d/14344-cellebrite-premium-ju... The good news is neither pixel nor iOS seems to show full file system extract under BFU state in…

Neither have had any known BFU on the latest iOS for years. AFU is occasionally possible but most of the leaks had latest software and hardware as still protected. Powering off the phone is always still a good idea though if you can.

Re: Leaker reveals which Pixels are vulnerable to Cellebrite phone hacking

#115

Earlier quoted context omitted.

https://grapheneos.org/features#duress :D

Use that and you'll get charged with destruction of evidence

If the Duress PIN is an obvious one, it may be one of the first ones your adversaries try. Like 1111 for example. So you may not even have to tell them the Duress PIN for them to attempt it.

Re: Leaker reveals which Pixels are vulnerable to Cellebrite phone hacking

#116
post #48

> Notably, the Pixel 10 series is moving away from physical SIM cards. Is it? I hadn't followed news of the new Pixels. I don't like the idea of modernizing this and going full eSIM. It will introduce a lot of new friction, somehow I don't doubt it. Just now arrived to Mexico for a quick trip and grabbed a prepaid SIM from a 7-11 in the airport. All quick and simple. I doubt things would be so seamless when not havin…

You can actually get a prepaid travel eSIM before you leave on holiday.

Which are absolutely shit because your data exits out on the other side of the world with 150ms extra latency.

Getting an (e?)SIM from a local carrier is always better and often cheaper too.

Re: Leaker reveals which Pixels are vulnerable to Cellebrite phone hacking

#117
post #70
post #27

Earlier quoted context omitted.

> Lots more devices are safe BFU than just Apple's. It's not that complicated on a technical level - it's basically full-disk encryption. So we agree: it's puzzling that Google can't manage to do it.

Google being bad doesn't mean Apple is good.

Aye but it is good Apple is safe out of the box. BFU is a low bar, and the shame is on Google.

>Lots more devices are safe BFU than just Apple's

Really? Secure against the exploits and methods these tools 3 letter agencies employ? I hate to cry source, but base Android isn't secure. What devices have similar hardware-level security, or have their Android flavor shipping with these Graphene-OS-level patches?

Re: Leaker reveals which Pixels are vulnerable to Cellebrite phone hacking

#118
post #28
post #22

Earlier quoted context omitted.

The government has ways of twisting the arms of uncooperative people/organizations into providing all the backdoors they need. Everything from increased tax and regulatory scrutiny to "discovering" CSAM on executives' computers or phones. The government does what it wants because it's the government. Mere laws generally don't stand in its way for long.

I think this is a very negative idea to promote: that laws should can be subverted. Everyone should believe that laws work and when they don't we should work to fix that, not assume that it can never be fixed.

On the other hand, it can be a grave mistake to confuse how things should be with how things are. Activists and whistleblowers should not act with the blind assumption that laws will protect them and that "minor" hurdles to law enforcement (i.e., the 5th amendment in the US) will be sufficient to protect them either.

I'm also unfortunately not convinced that some of these problems are tractible -- one of the core issues is that the legal systems of the world have adopted the third-party doctrine for warrants and so even if there was a legal right to prevent everyone's devices from being backdoored you would also have to depend on Google, Facebook, Twitter, Apple to be willing to go to court at great expense to defend your rights. I don't like to think of myself as being cynical, but I just don't believe that would happen. And if the company is happy to comply, law enforcement doesn't even need a warrant. I honestly don't see how anything other than technological solutions are on the table here.

(I am aware of the high-profile stuff with Apple and Google claiming to fight against backdoors in court. In this respect I must admit that I am a cynic -- Cellebrite/NSO/et al claim they can get into iPhones and Android devices and law enforcement agencies happily buy their products, so someone here is lying.)

Re: Leaker reveals which Pixels are vulnerable to Cellebrite phone hacking

#119
post #80

Earlier quoted context omitted.

Which particular thing you consider inconvenient or even annoying? You can even install Google Play there. I see just one minor tradeoff - no face unlock.

Google OS-level integration is absent, and while Google Play Services can be installed, you're still missing things like Chromecast. Also, there's more manual configuration (although I don't remember exactly what, I've never used GrapheneOS). A lot of stuff you do get for free, but not all of it, and stuff that's been removed as a "feature" isn't always stuff that nobody wants.

> stuff that's been removed as a "feature" isn't always stuff that nobody wants.

Graphene isn't made to cater to what everyone wants. Face ID and fingerprint unlocking so clearly have no place in a hardened OS. "Google OS-level integration is absent" should not be suprising.

This said, you ought to be able to have BFU security with stock Android and it's embarrassing Google ships stock vulnerable.

Re: Leaker reveals which Pixels are vulnerable to Cellebrite phone hacking

#120
post #119

Earlier quoted context omitted.

Google OS-level integration is absent, and while Google Play Services can be installed, you're still missing things like Chromecast. Also, there's more manual configuration (although I don't remember exactly what, I've never used GrapheneOS). A lot of stuff you do get for free, but not all of it, and stuff that's been removed as a "feature" isn't always stuff that nobody wants.

> stuff that's been removed as a "feature" isn't always stuff that nobody wants. Graphene isn't made to cater to what everyone wants. Face ID and fingerprint unlocking so clearly have no place in a hardened OS. "Google OS-level integration is absent" should not be suprising. This said, you ought to be able to have BFU security with stock Android and it's embarrassing Google ships stock vulnerable.

> Graphene isn't made to cater to what everyone wants.

I know! My entire point is Graphene wouldn't be a good choice for the stock OS on a mass-market phone. The Graphene devices will be great, but if Google were to replace their stock OS with Graphene there would be problems.

Post reply on HN