Live data from Hacker News

GrapheneOS finds Bluetooth memory corruption via ARM MTE

grapheneos.social

151–160 of 228 posts

Re: GrapheneOS finds Bluetooth memory corruption via ARM MTE

#151
post #2

GrapheneOS is so far ahead in terms of security than anything else that it makes chosing anything but pixel hardware really questionable. But I REALLY want replaceable batteries. Why does everything have to suck nowadays?

Don't worry, GrapheneOS will drop support for your device before you need a battery replacement. (They support devices for slightly longer than the devices are supported upstream)

Are you telling me my battery is going to last more than seven years?

Re: GrapheneOS finds Bluetooth memory corruption via ARM MTE

#153

Hope somebody using Graphene OS could answer: 1. Is it very challenging to install Graphene OS? Need special cables and to know a lot about jailbreaking Android devices, or will I be fine just following instructions? 2. Is it very inconvenient to use as a daily driver? How often phone just crashes and requires a few days of debugging? Will my bank app work on it?

Very easy and solid as a daily driver. I have a Pixel 6a that I've been running it on from when I got it (≈1.5 years), I've never needed to debug anything. My banking apps have worked without issue. The only issue I've encountered is one dual factor authentication app not working on it.

Re: GrapheneOS finds Bluetooth memory corruption via ARM MTE

#155
post #140

Earlier quoted context omitted.

> the recommended method involves using Web USB in Chromium which is meant to be easier for non-technical people but I couldn't get it to work. There's a bug on many Linux distributions which was fixed in fwupd but is still present because they haven't updated it to a recent version. It interferes with reconnecting to the device when it reboots into fastbootd mode as part of the install. We cover it in our install gu…

Since you seem to be on the Graphene team, may I piggyback on this: I've been wanting to make the switch over from iOS for some time but it bothers me a bit that I have to buy a Google phone. Are there any plans to support non-Google devices? I know this has been discussed and the answer I've seen is that Google devices are the best fit, but at least one more option would be nice.

(not on the team) I believe the project are open to supporting other devices that meet the criteria, or collaborating with hardware partners to that effect.

As I understand, the way it works is that the project first has to scope out a hardware target that meets their security requirements before support can be considered and funded for. Just that right now there are no other phones that meet the requirements specified in https://grapheneos.org/faq#future-devices

If a phone met those requirements and was not made by Google, GrapheneOS would consider supporting it. In the case that Google didn't meet the requirements but a different phone did, GrapheneOS would support that phone and not the Pixels.

Re: GrapheneOS finds Bluetooth memory corruption via ARM MTE

#156
post #60

Earlier quoted context omitted.

I might have not caught that he tried to kill graphene os. Didn't he just say that he decided to not use gOS anymore because he thinks that the developer of gOS might have something against him personally? Anyway, I don't know a single person who stopped using gOS because of the feud between these two Gladly I might add since I have been enjoying gOS so far

Rossman did nothing of the sort. Watch his video for reference. https://m.youtube.com/watch?v=4To-F6W1NT0&t What Rossman referred to is easily revealed in this very thread from Daniel's comments. I refuse to use GrapheneOS because of Daniel's behavior. He has attacked me personally on this site multiple times.

[flagged]

Re: GrapheneOS finds Bluetooth memory corruption via ARM MTE

#157
post #140

Earlier quoted context omitted.

> the recommended method involves using Web USB in Chromium which is meant to be easier for non-technical people but I couldn't get it to work. There's a bug on many Linux distributions which was fixed in fwupd but is still present because they haven't updated it to a recent version. It interferes with reconnecting to the device when it reboots into fastbootd mode as part of the install. We cover it in our install gu…

Since you seem to be on the Graphene team, may I piggyback on this: I've been wanting to make the switch over from iOS for some time but it bothers me a bit that I have to buy a Google phone. Are there any plans to support non-Google devices? I know this has been discussed and the answer I've seen is that Google devices are the best fit, but at least one more option would be nice.

[deleted]

Re: GrapheneOS finds Bluetooth memory corruption via ARM MTE

#158

Hope somebody using Graphene OS could answer: 1. Is it very challenging to install Graphene OS? Need special cables and to know a lot about jailbreaking Android devices, or will I be fine just following instructions? 2. Is it very inconvenient to use as a daily driver? How often phone just crashes and requires a few days of debugging? Will my bank app work on it?

Very easy and solid as a daily driver. I have a Pixel 6a that I've been running it on from when I got it (≈1.5 years), I've never needed to debug anything. My banking apps have worked without issue. The only issue I've encountered is one dual factor authentication app not working on it.

And Netflix can't be installed (at least through the Play store) because of restrictions from Netflix' side (I suppose). But that's okay, I can just stop my subscription through the web interface.

Re: GrapheneOS finds Bluetooth memory corruption via ARM MTE

#159
post #147

Earlier quoted context omitted.

Guess not, the RasPi5 is quad A76 which have v8.2 extensions, MTE is v8.5.

MTE is an optional feature for ARMv8.5 and is only available via ARMv9 in practice. Snapdragon doesn't provide it but they told us they're likely going to add it by 2025/2026. Pixel 8 and Pixel 8 Pro are the main option with it. MediaTek and Exynos have theoretically added support for it but that doesn't mean any device with their latest flagship SoC theoretically supporting it actually has it available and working.

Is Snapdragon hardware present in the current/upcoming lineup of Pixel devices such that MTE support is relevant to GrapheneOS?

Re: GrapheneOS finds Bluetooth memory corruption via ARM MTE

#160
post #36

> Pixels shipped a massive hardware security feature (MTE) they aren't enabling for the OS to save 3.125% memory/cache usage. It's silly. Heap MTE has near 0% perf overhead in async mode and is cheaper than increasingly ineffective legacy mitigations like SSP in asymmetric mode. I really want to see someone from the Pixel team justifying the decision here. I really wonder what the thought process is for someone to di…

TL;DR I would not assume they are not using it, or that this is about 3.125% memory/cache usage. Longer answer: Google folks were responsible for pushing on Hardware MTE in the first place - It originally came from the folks who also did work on ASAN, syzkaller, etc. They are not in Android, but it was done with the help and support of folks in Android. That's the Google side, it was obviously a partnership with ARM/…

Thanks for the insight.

>As an aside - It's also not obvious it's the best choice for run-time mitigation.

What are some of the current contenders/arguments?

Post reply on HN