Live data from Hacker News

GrapheneOS finds Bluetooth memory corruption via ARM MTE

grapheneos.social

131–140 of 228 posts

Re: GrapheneOS finds Bluetooth memory corruption via ARM MTE

#131
post #122

Earlier quoted context omitted.

I'm aware people may downvote the hell out of this, but if they do they're the ones writing the bugs: it's not "bad skilled developers" it's everyone. Memory corruption is basically a language feature of C/C++. It's best to not perpetuate the belief that it's dumb people because very few people think they're dumb and I've seen some absolutely amazing coders write some hilarious memory bugs. It just comes with the ter…

My favourite quote. "A consequence of this principle is that every occurrence of every subscript of every subscripted variable was on every occasion checked at run time against both the upper and the lower declared bounds of the array. Many years later we asked our customers whether they wished us to provide an option to switch off these checks in the interests of efficiency on production runs. Unanimously, they urge…

Great quote. Nice to have memory tagging to help with the debug process these days. Not surprising to see these mistakes being made about 50 years later, as the fundamentals have not changed. Doing the same thing and expecting different results is, well, you know...

Re: GrapheneOS finds Bluetooth memory corruption via ARM MTE

#132
post #60

Earlier quoted context omitted.

[flagged]

I might have not caught that he tried to kill graphene os. Didn't he just say that he decided to not use gOS anymore because he thinks that the developer of gOS might have something against him personally? Anyway, I don't know a single person who stopped using gOS because of the feud between these two Gladly I might add since I have been enjoying gOS so far

Rossman did nothing of the sort. Watch his video for reference.

https://m.youtube.com/watch?v=4To-F6W1NT0&t

What Rossman referred to is easily revealed in this very thread from Daniel's comments.

I refuse to use GrapheneOS because of Daniel's behavior. He has attacked me personally on this site multiple times.

Re: GrapheneOS finds Bluetooth memory corruption via ARM MTE

#133

Hope somebody using Graphene OS could answer: 1. Is it very challenging to install Graphene OS? Need special cables and to know a lot about jailbreaking Android devices, or will I be fine just following instructions? 2. Is it very inconvenient to use as a daily driver? How often phone just crashes and requires a few days of debugging? Will my bank app work on it?

It's easy to install and for 99% of use-cases the OS is just as convenient as any other Android phone. However, recently my wife and I travelled to Orlando Florida to visit Disney World and Universal Studios. While their apps mostly worked with sandboxed Google Play Services, I did have some annoying issues. The My Disney Experience app gave me a lot of glitches related to Location (it was intermittent but I would oc…

Try disabling rerouting for Geolocation requests to GrapheneOS, because I personally found the gps provider integrated in it to be almost unusable, since it doesn't implement Bluetooth/wifi scanning at all.

Yes that means google will get your location, but it's still better than going back to stock which is also better than any other third party skin in terms of privacy/security.

Re: GrapheneOS finds Bluetooth memory corruption via ARM MTE

#134
post #102
post #66

Earlier quoted context omitted.

This is also satire, right?

I’m not the parent commenter, but not really. Daniel Micay himself said that iphones are one of the best choices from a security perspective, GrapheneOS closing the gap. The reason is the close working together of hardware and software, which is very seldom done in case of Android devices - pixels being the sole exception that care about it, that’s why they are the only supported device. Not much point in buying some…

No, that's not correct and what you're stating about my views or what I have said is not correct.

> Daniel Micay himself said that iphones are one of the best choices from a security perspective, GrapheneOS closing the gap.

I haven't said this about current era GrapheneOS. You're referring to outdated comments from 4 years ago. Pixels, AOSP and GrapheneOS have all massively improved since then. Pixels with the stock OS have competitive security with iOS. GrapheneOS is not closing a gap with iOS on security. It is closing a gap on privacy and also surpassing it with features like Contact Scopes.

> The reason is the close working together of hardware and software, which is very seldom done in case of Android devices - pixels being the sole exception that care about it, that’s why they are the only supported device.

AOSP is developed largely with and for Pixels, but that is not why they're the only supported devices for GrapheneOS. They're the only supported devices because they're the only devices meeting the security requirements listed at https://grapheneos.org/faq#future-devices. If you ignore the differences in APIs between iOS and Android while pretending that the iPhone supported alternate operating systems, it does not meet that full requirements list either. The lack of MTE is a simple example.

It's presented as being for the ultra paranoid but what it does is mainly reducing huge amounts of attack surface created by default enabled Apple services. They're basic security measures rather than something super advanced and niche. It's all grouped together into one setting with some aspects impacting usability a lot without being able to get most of the features without that, which was their choice, and is what makes it into way more of a niche feature than it has to be.

These Apple services/features don't exist for GrapheneOS in the first place. People use Signal or the hardened Molly fork on GrapheneOS, not iMessage/Facetime, etc. Android already takes a more cautious approach to media handling in the stock OS. Lockdown mode mainly disables the permissive defaults of Apple services/features and provides attack surface reduction for Safari. GrapheneOS has Vanadium features that are similar such as JIT being disabled by default but beyond that those browser parts of it there isn't a lot that's applicable.

Re: GrapheneOS finds Bluetooth memory corruption via ARM MTE

#135
post #134
post #102

Earlier quoted context omitted.

I’m not the parent commenter, but not really. Daniel Micay himself said that iphones are one of the best choices from a security perspective, GrapheneOS closing the gap. The reason is the close working together of hardware and software, which is very seldom done in case of Android devices - pixels being the sole exception that care about it, that’s why they are the only supported device. Not much point in buying some…

No, that's not correct and what you're stating about my views or what I have said is not correct. > Daniel Micay himself said that iphones are one of the best choices from a security perspective, GrapheneOS closing the gap. I haven't said this about current era GrapheneOS. You're referring to outdated comments from 4 years ago. Pixels, AOSP and GrapheneOS have all massively improved since then. Pixels with the stock…

I didn’t mean to misrepresent your views, was only remembering an old comment of you that said that iphones are quite good for the security-minded.

Of course I could not have known how the state of security, or your opinion of it has changed in the meanwhile.

Re: GrapheneOS finds Bluetooth memory corruption via ARM MTE

#136
post #102

Earlier quoted context omitted.

I’m not the parent commenter, but not really. Daniel Micay himself said that iphones are one of the best choices from a security perspective, GrapheneOS closing the gap. The reason is the close working together of hardware and software, which is very seldom done in case of Android devices - pixels being the sole exception that care about it, that’s why they are the only supported device. Not much point in buying some…

The problem with the iOS ecosystem is that it's not safe from manufacturer spying? This is the much larger issue than 3rd parties. Does lockdown mode prevent this?

Please read https://news.ycombinator.com/item?id=39672701. My actual position is that current Pixels with the stock OS and iOS have comparable security. iOS has overall better privacy including privacy from apps. It's not strictly more private and Pixels with stock OS do have areas where they do better. AOSP on a Pixel doesn't have the heavily integrated Google apps and services which gives it more advantages than the stock OS usually has compared to iOS, so it's hard to say which has better privacy. A major focus for GrapheneOS is addressing the biggest privacy weaknesses such as providing Contact Scopes, Storage Scopes and a per-app Sensors toggle which not only close the gap with iOS in those 3 areas but go significantly beyond what it provides. There are still a few areas where iOS does better on privacy, but GrapheneOS definitely does better overall. Security is a clearer picture where it's clearer more secure overall and there aren't a lot of areas where it's worse since the Pixel stock OS / AOSP starting point has very strong security. Suggest that people look through https://grapheneos.org/features which explains what we provide compared to standard Android 14 QPR2, although it's missing a lot of minor features and some recent major features.

GrapheneOS gets to focus on the weak points in Android and can make a bigger performance and memory usage sacrifice to achieve privacy and security. We can also add more user-facing features and toggles than either Apple or Google is willing to provide. This allows us to do many things they can't do. We care a lot about preserving app compatibility but we're willing to have opt-in features which break some apps, and we're willing to break apps with severe memory corruption bugs by default with an opt-out toggle to get them working. GrapheneOS aims to be nearly as easy to use as the stock Pixel OS once we do more work on the out-of-the-box experience and bundled apps, but we're willing to have more complex privacy and security options available for people who can deal with it. We see the starting point of AOSP as an already very good base relative to other modern operating systems.

Re: GrapheneOS finds Bluetooth memory corruption via ARM MTE

#137
post #84

Stock Pixel may not ship with it on by default for end users, but anyone can enable developer options and enable Memory Tagging Extensions - either until toggled off, or for a single session if you're trying to test a specific app - if you do want the feature on.

That's not the same as what's being used on GrapheneOS. It also excludes a significant portion of Bluetooth. Enabling support for memory tagging in the stock Pixel OS via developer options only makes it available for usage but doesn't actually use it. You also need to enable heap memory tagging via the Android Debug Bridge (ADB) shell via setprop. It provides no value through simply being enabled without using it to…

Some background on Sanitizers (ex: kasan) and ARM Memory Tagging Extension (mte) by the one of its developers, Andrey Konovalov:

https://youtu.be/KmFVPyHyfqQ / https://ghostarchive.org/varchive/KmFVPyHyfqQ

https://youtu.be/9wRT2hNwbkA / https://ghostarchive.org/varchive/9wRT2hNwbkA

Re: GrapheneOS finds Bluetooth memory corruption via ARM MTE

#138

Hope somebody using Graphene OS could answer: 1. Is it very challenging to install Graphene OS? Need special cables and to know a lot about jailbreaking Android devices, or will I be fine just following instructions? 2. Is it very inconvenient to use as a daily driver? How often phone just crashes and requires a few days of debugging? Will my bank app work on it?

> Is it very challenging to install Graphene OS?

It's very easy to install with the web installer.

https://grapheneos.org/install/web

You can buy a device with it, but nearly anyone can use the web installer. It's particularly easy to use from Android, ChromeOS and macOS. Windows is a bit trickier since you need to install a driver. Desktop Linux requires installing udev rules, and some distributions with frozen software versions have a buggy service which interferes.

> Need special cables and to know a lot about jailbreaking Android devices, or will I be fine just following instructions?

Non-technical people can do it. You only need a browser with WebUSB. You don't need any special software.

> Is it very inconvenient to use as a daily driver?

Nearly the same as the stock Pixel OS with nearly as broad app compatibility if you use sandboxed Google Play.

> How often phone just crashes and requires a few days of debugging?

You likely won't experience significantly more crashes. It has user-facing crash reporting not existing in the stock OS so you'll notice crashes you wouldn't have known about it. Buggy apps with memory corruption may crash until you enable the per-app compatibility mode, ESPECIALLY if you opt-in to forcing MTE for all user installed apps.

> Will my bank app work on it?

If your bank allows a non-Google-certified OS, which most still do. Banks are gradually disallowing using a non-Google-certified OS and this essentially needs to be addressing as an anti-competition regulation issue. We're working on convincing banks to use https://grapheneos.org/articles/attestation-compatibility-gu... in the meantime.

Re: GrapheneOS finds Bluetooth memory corruption via ARM MTE

#139

Earlier quoted context omitted.

It's easy to install and for 99% of use-cases the OS is just as convenient as any other Android phone. However, recently my wife and I travelled to Orlando Florida to visit Disney World and Universal Studios. While their apps mostly worked with sandboxed Google Play Services, I did have some annoying issues. The My Disney Experience app gave me a lot of glitches related to Location (it was intermittent but I would oc…

Try disabling rerouting for Geolocation requests to GrapheneOS, because I personally found the gps provider integrated in it to be almost unusable, since it doesn't implement Bluetooth/wifi scanning at all. Yes that means google will get your location, but it's still better than going back to stock which is also better than any other third party skin in terms of privacy/security.

It's possible that there was something I didn't figure out how to configure correctly, but I spent a good chunk of time on our vacation mucking with various settings, including disabling re-routing location to the OS :/

Re: GrapheneOS finds Bluetooth memory corruption via ARM MTE

#140

Hope somebody using Graphene OS could answer: 1. Is it very challenging to install Graphene OS? Need special cables and to know a lot about jailbreaking Android devices, or will I be fine just following instructions? 2. Is it very inconvenient to use as a daily driver? How often phone just crashes and requires a few days of debugging? Will my bank app work on it?

1. No, it was very easy. I used a normal USB cable and adb on the Linux command line, but the recommended method involves using Web USB in Chromium which is meant to be easier for non-technical people but I couldn't get it to work. 2. No, it is very convenient. It has a sandbox for Google Play Services, which IMO is the best of both worlds as it means you can install all the proprietary crapware apps that make modern…

> the recommended method involves using Web USB in Chromium which is meant to be easier for non-technical people but I couldn't get it to work.

There's a bug on many Linux distributions which was fixed in fwupd but is still present because they haven't updated it to a recent version. It interferes with reconnecting to the device when it reboots into fastbootd mode as part of the install. We cover it in our install guides now. fwupd usually loses the race to connect to the device to the CLI install tool but wins the race against Chromium's implementation, which is why it impacts web install more. This is likely what you experienced before we documented this fwupd bug and got them to fix it upstream. The problem is that even though fwupd fixed it a while ago, Debian and even the latest Ubuntu still have the bug.

Post reply on HN