Live data from Hacker News

Leaker reveals which Pixels are vulnerable to Cellebrite phone hacking

arstechnica.com

171–180 of 372 posts

Re: Leaker reveals which Pixels are vulnerable to Cellebrite phone hacking

#171
post #86

Earlier quoted context omitted.

I'd almost want to avoid GrapheneOS because it gets so much attention from law enforcement that it's probably a big target for various agencies to find vulnerabilities in.

This doesn't make sense. If you're worried about the government targeting you, then what is the alternative... less hardened phones? At least Graphene will protect you better than the stock OS. If you're really that concerned then you shouldn't use anything going through cell tower (or take extreme precautions when doing so).

I did say "almost". But as you mention there aren't many alternative. It would be a better world if there were several options besides just Graphene that prioritize security.

Re: Leaker reveals which Pixels are vulnerable to Cellebrite phone hacking

#172
post #142

Earlier quoted context omitted.

eSIMs feel like a solution waiting for a problem. Consumers are happy with physical SIMs, you obtain one, you put it in your phone then you forget about it until you swap your phone. I'm sure eSIMs are a good idea if your aim is to gain even more control over our personal devices.

I've been using an eSim on my iPhone and it's been wonderful because: 1. migrating between iPhones also transfers the eSim 2. if I get a tourist sim card at an airport, I don't have to worry about taking out or losing my main sim 3. the ability to have multiple sims is also ideal: I currently have phone plans in AU and SG, in addition to any tourist sim cards I pick up

It sounds like you’re talking about the benefits of having both? The new iPhones have only eSIM which is currently a hurdle, especially for the ”tourist SIMs”. OTOH, I’m sure Telcos will shape up their support and iron out the major bugs rather quickly precisely because of this.

Re: Leaker reveals which Pixels are vulnerable to Cellebrite phone hacking

#173
post #48

> Notably, the Pixel 10 series is moving away from physical SIM cards. Is it? I hadn't followed news of the new Pixels. I don't like the idea of modernizing this and going full eSIM. It will introduce a lot of new friction, somehow I don't doubt it. Just now arrived to Mexico for a quick trip and grabbed a prepaid SIM from a 7-11 in the airport. All quick and simple. I doubt things would be so seamless when not havin…

eSIMs feel like a solution waiting for a problem. Consumers are happy with physical SIMs, you obtain one, you put it in your phone then you forget about it until you swap your phone. I'm sure eSIMs are a good idea if your aim is to gain even more control over our personal devices.

eSIMs are fantastic for anyone who travels internationally.

Re: Leaker reveals which Pixels are vulnerable to Cellebrite phone hacking

#174

Earlier quoted context omitted.

Wouldn't it be a total mindfuck if it turns out that Graphene is less secure[1] than stock Pixel, and this is all part of an ANOM-style honeypot operation that has Feds hyping it up, to trick interesting targets into adopting a less-effective security posture. 1. Such as via slower 0-day responses, for instance. This is a thought experiment, I'm nor alleging that this is what it is.

Those honeypot phones clearly use marketing aimed at criminals and make all sort of false promises and clearly aren't technical and transparent projects like GrapheneOS. GrapheneOS community doesn't tolerate discussion of crime or implying you are a criminal on their official community chat rooms and forum. Doesn't make sense for it to be a project aimed at luring in criminals. Anyway, GrapheneOS ships security patch…

The biggest difference is that the honeypot phones come with their own custom apps all claiming to have completely secure communications. That's their selling point, the set of apps, or even a single one, which they claim is unbreakable. The criminals buying these phones aren't interested in just GrapheneOS on its own. Clearly they don't consider something like Signal secure enough, even if run on GrapheneOS.

Re: Leaker reveals which Pixels are vulnerable to Cellebrite phone hacking

#175

Earlier quoted context omitted.

I read from an old HN post that three letter agencies hate graphen OS. The author heard it from defcon or some similar conference. I couldn’t find the post anyway :/ I think it is buried under one of the posts that discuss Defcon and Blackhat.

Wouldn't it be a total mindfuck if it turns out that Graphene is less secure[1] than stock Pixel, and this is all part of an ANOM-style honeypot operation that has Feds hyping it up, to trick interesting targets into adopting a less-effective security posture. 1. Such as via slower 0-day responses, for instance. This is a thought experiment, I'm nor alleging that this is what it is.

GrapheneOS releases patches very quickly, often even faster than OEMs do. But patches are only useful for fixing individual known vulnerabilities. GrapheneOS additionally focuses on defending against whole classes of vulnerabilities. [1] For example, in addition to fixing memory corruption bugs in individual system components, GrapheneOS has deployed memory protections for the entire OS in the form of hardened_malloc [2] and by enabling the ARM memory tagging extension for the kernel, most system processes (with very few exceptions) and all user-installed apps.

The honeypot theories don't make sense, since GrapheneOS is fully open source, and very transparent about developers, funding, infrastructure, and other internal stuff.

[1] https://grapheneos.org/features#exploit-protection

[2] https://github.com/GrapheneOS/hardened_malloc

Re: Leaker reveals which Pixels are vulnerable to Cellebrite phone hacking

#176
post #142

Earlier quoted context omitted.

eSIMs feel like a solution waiting for a problem. Consumers are happy with physical SIMs, you obtain one, you put it in your phone then you forget about it until you swap your phone. I'm sure eSIMs are a good idea if your aim is to gain even more control over our personal devices.

I've been using an eSim on my iPhone and it's been wonderful because: 1. migrating between iPhones also transfers the eSim 2. if I get a tourist sim card at an airport, I don't have to worry about taking out or losing my main sim 3. the ability to have multiple sims is also ideal: I currently have phone plans in AU and SG, in addition to any tourist sim cards I pick up

>if I get a tourist sim card at an airport, I don't have to worry about taking out or losing my main sim

bold of you to assume we'll still have a sim card slots

Re: Leaker reveals which Pixels are vulnerable to Cellebrite phone hacking

#177
post #3

They couldn't answer the question most on my mind: "We’ve reached out to Google to inquire about why a custom ROM created by volunteers is more resistant to industrial phone hacking than the official Pixel OS. We’ll update this article if Google has anything to say."

GrapheneOS makes security trade-off that are inconvenient to the user. This results in a far more secure device, but nonetheless a device that the general public would find far more annoying. Google would lose a proportion of its user base by implementing the same protections. Example: https://old.reddit.com/r/GooglePixel/comments/ytk1ng/graphen... Also Google Pay is missing.

[deleted]

Re: Leaker reveals which Pixels are vulnerable to Cellebrite phone hacking

#178
post #142

Earlier quoted context omitted.

eSIMs feel like a solution waiting for a problem. Consumers are happy with physical SIMs, you obtain one, you put it in your phone then you forget about it until you swap your phone. I'm sure eSIMs are a good idea if your aim is to gain even more control over our personal devices.

I've been using an eSim on my iPhone and it's been wonderful because: 1. migrating between iPhones also transfers the eSim 2. if I get a tourist sim card at an airport, I don't have to worry about taking out or losing my main sim 3. the ability to have multiple sims is also ideal: I currently have phone plans in AU and SG, in addition to any tourist sim cards I pick up

Fwiw, I can't remember the last time I bought a physical sim at an airport. Airalo lets me buy an eSim at the departing airport, which means I've got cell data from the instant I arrive. They're not the only company offering this, and I'm sure I could min max and find a more cost optimized service, but it's done me well enough. Depending on the amount of international travel you do, and to where, however, US travellers may have a better time with a carrier like T-Mobile which include international data to a number of countries.

Re: Leaker reveals which Pixels are vulnerable to Cellebrite phone hacking

#179
post #172
post #142

Earlier quoted context omitted.

I've been using an eSim on my iPhone and it's been wonderful because: 1. migrating between iPhones also transfers the eSim 2. if I get a tourist sim card at an airport, I don't have to worry about taking out or losing my main sim 3. the ability to have multiple sims is also ideal: I currently have phone plans in AU and SG, in addition to any tourist sim cards I pick up

It sounds like you’re talking about the benefits of having both? The new iPhones have only eSIM which is currently a hurdle, especially for the ”tourist SIMs”. OTOH, I’m sure Telcos will shape up their support and iron out the major bugs rather quickly precisely because of this.

> It sounds like you’re talking about the benefits of having both?

physical sims make no contribution to any of their points.

Re: Leaker reveals which Pixels are vulnerable to Cellebrite phone hacking

#180
post #48

> Notably, the Pixel 10 series is moving away from physical SIM cards. Is it? I hadn't followed news of the new Pixels. I don't like the idea of modernizing this and going full eSIM. It will introduce a lot of new friction, somehow I don't doubt it. Just now arrived to Mexico for a quick trip and grabbed a prepaid SIM from a 7-11 in the airport. All quick and simple. I doubt things would be so seamless when not havin…

eSIMs feel like a solution waiting for a problem. Consumers are happy with physical SIMs, you obtain one, you put it in your phone then you forget about it until you swap your phone. I'm sure eSIMs are a good idea if your aim is to gain even more control over our personal devices.

> Consumers are happy with physical SIMs, you obtain one, you put it in your phone then you forget about it until you swap your phone.

As a consumer I was much happier with esims: I swapped provider, got the esim in the mail essentially instantly, put it in my phone, and forgot about it util I swapped phone... at which point esim transfer was part of the migration so I essentially didn't have to think about it either.

Post reply on HN