Live data from Hacker News

Leaker reveals which Pixels are vulnerable to Cellebrite phone hacking

arstechnica.com

271–280 of 372 posts

Re: Leaker reveals which Pixels are vulnerable to Cellebrite phone hacking

#271
post #163

Earlier quoted context omitted.

Which are absolutely shit because your data exits out on the other side of the world with 150ms extra latency. Getting an (e?)SIM from a local carrier is always better and often cheaper too.

And you can buy an eSIM from a local carrier, which will then email you a code. It's unheard of for local carriers to mail physical SIMs to the other side of the world.

The typically tier 2 carriers are the main ideal perfect market for eSIMs. If you want to do everything online, you really can't if it relies on a physical something. I would estimate 90% of the market is for mint mobile and consumer cellular. eSIMs are a genius move progression from the old burner phone days, from the perspective of overhead costs and flexibility.

Re: Leaker reveals which Pixels are vulnerable to Cellebrite phone hacking

#272
post #257
post #80

Earlier quoted context omitted.

Which particular thing you consider inconvenient or even annoying? You can even install Google Play there. I see just one minor tradeoff - no face unlock.

They removed pattern lock, which makes me uncomfortable. I don't care for touch/fingerprint (or face) because biometrics aren't protected in the fifth amendment right to be free from self-incrimination. The only screen lock is PIN.

Straight from the horse's mouth: https://discuss.grapheneos.org/d/16393-maybe-re-instate-patt...

> Pattern unlock is a badly designed lock method that's a major downgrade from the security of a PIN for multiple reasons.

> Pattern lock is even more dangerous to people who are as you say more casual users. It is a badly designed and dangerous feature. iPhones not having this is very good for users. We will not add back a major flaw in the OS security design.

If this makes you uncomfortable somehow? OK? Maybe it's not an OS for you :)

Re: Leaker reveals which Pixels are vulnerable to Cellebrite phone hacking

#273
post #242

Earlier quoted context omitted.

Is the battery life better with Graphene?

I would say, similar. In theory it may be slightly worse, because you are not using play services to deliver notifications, but each app does their own fetching (I believe that's how it works), but you will also restrict apps more (due to e.g. being able to restrict network access), so the two sort of cancel out.

Yes unless the app offers Unified Push (like Molly vs Signal).

Re: Leaker reveals which Pixels are vulnerable to Cellebrite phone hacking

#274

Earlier quoted context omitted.

Google OS-level integration is absent, and while Google Play Services can be installed, you're still missing things like Chromecast. Also, there's more manual configuration (although I don't remember exactly what, I've never used GrapheneOS). A lot of stuff you do get for free, but not all of it, and stuff that's been removed as a "feature" isn't always stuff that nobody wants.

Is it really missing Chromecast? I read that it works if you have Play services (but haven't tried)

No, works fine for me from sandboxed (very much unprivileged) YouTube, New Pipe And VLC.

I do have sandboxed Google services installed.

Re: Leaker reveals which Pixels are vulnerable to Cellebrite phone hacking

#275
post #158
post #114

Earlier quoted context omitted.

Neither have had any known BFU on the latest iOS for years. AFU is occasionally possible but most of the leaks had latest software and hardware as still protected. Powering off the phone is always still a good idea though if you can.

That's not true. Cellebrite has working BFU and AFU exploits for recent iOS and usually catches up to the latest iOS versions and hardware in weeks or a couple months. They do not have working brute force support for the Pixel 2 / Pixel 6 or later / iPhone 12 or later due to the secure elements but can still exploit the devices in BFU mode and extract the data available before unlocking. iPhone 17 may work out better…

My mental model of this is “Apple releases new iOS with security patches -> time passes before cellebrite develops an AFU exploit -> Eventually Apple patches the exploit -> go to step 1”. By adding auto reboot Apple ensured that since lots of the time is spent in the stage where the latest iOS has no AFU exploit and AFU becomes BFU before that changes, and thus they are stuck with only extracting whatever is unencrypted at boot time at best. The leaked matrices even for September 2024 had no BFU listed for any remotely recent versions.

Re: Leaker reveals which Pixels are vulnerable to Cellebrite phone hacking

#276

Earlier quoted context omitted.

> It sounds like you’re talking about the benefits of having both? physical sims make no contribution to any of their points.

> 2. if I get a tourist sim card at an airport That sounds like it would be a physical sim, or am I incorrect?

iPhones are eSim only for a few years now.

Re: Leaker reveals which Pixels are vulnerable to Cellebrite phone hacking

#277
post #251

Earlier quoted context omitted.

> In fact, looking at the news this week, the same question applies to Microsoft and Apple as well. Are they too big and distracted to care about security? Yes, of course they are, but its more rational than just being distracted. If not caring does does not lose you a significant amount of revenue why should you care? The same applies to big players in the industry with regard to security and quality in general. In…

> If not caring does does not lose you a significant amount of revenue why should you care? Sounds like it's time for heavy regulation. These corps are not "normal" businesses anymore, I think special (and stricter) rules should apply to them.

They are hard to regulate and I really doubt governments have either the willingness or the competence to do so effectively. The businesses are very heavily motivated to find ways around regulations, or manipulate them to to their advantage.

Regulation is a very poor substitute for competition, and for well informed customers.

Some of what I said in this comment is relevant: https://news.ycombinator.com/item?id=45780529

Re: Leaker reveals which Pixels are vulnerable to Cellebrite phone hacking

#278

Earlier quoted context omitted.

My banking apps run on it, but my concert ticket app doesn't, so I have a separate phone just for that one app.

Can concert tickets not be bought in a web browser?

Nope. This is eplus in Japan, and if you try go through the website it tells you you have to use the app. It's cos a lot of shows these days don't use paper tickets, but smart tickets on your phone. It is what it is.

Re: Leaker reveals which Pixels are vulnerable to Cellebrite phone hacking

#279
post #205

Earlier quoted context omitted.

Are you affiliated with the project? I see all your posts are about Graphene OS. On HN it is customary to state it: you often see "author here" in discussions where the author joins. If you are part of the team I would suggest against using the third person ("they have a team..."). I know strcat is the lead Graphene OS developer, and it seems you and Andromxda are very knowledgeable about the project and very active…

It's literally ONE click away from the GrapheneOS main page, lol, the literacy levels gone through the floor. https://grapheneos.org/history/ > GrapheneOS now has multiple full-time and part-time developers supported by donations and multiple companies collaborating with the project. This is beyond being just shockingly, willingly ignorant and this is out there re on the open, so in the spirit of your own response, I…

I am not debating what tranq_cassowary and the other two users are writing: it seems all correct (from what I can verify) and useful. I am just suggesting that they disclose their affiliation, if there is any, as a good transparency practice.

I myself am not affiliated in any way with their "infamous competition", not even as a user of their software, so I have nothing to disclose. (Actually, I am a Graphene OS user.)

Re: Leaker reveals which Pixels are vulnerable to Cellebrite phone hacking

#280
post #64

Earlier quoted context omitted.

GrapheneOS is seemingly working with an OEM to make a GrapheneOS smartphone. Its probably not samsung, but would still be an established vendor

It better not be Samsung...

It isn't Samsung
Post reply on HN