Earlier quoted context omitted.
Google OS-level integration is absent, and while Google Play Services can be installed, you're still missing things like Chromecast. Also, there's more manual configuration (although I don't remember exactly what, I've never used GrapheneOS). A lot of stuff you do get for free, but not all of it, and stuff that's been removed as a "feature" isn't always stuff that nobody wants.
Is it really missing Chromecast? I read that it works if you have Play services (but haven't tried)
Leaker reveals which Pixels are vulnerable to Cellebrite phone hacking
191–200 of 372 posts
Re: Leaker reveals which Pixels are vulnerable to Cellebrite phone hacking
#192Earlier quoted context omitted.
True. This is an issue in America specifically. Where there is a Google Apple duopoly on tap-to-pay tech. Can be worked around though with smart watches like Garmin watch with Garmin Pay. In many other regions there are alternatives like Curve Pay or tap-to-pay functionalities in banking apps
Google Pay also works with a Pixel watch connected to a GrapheneOS phone, FWIW.
Re: Leaker reveals which Pixels are vulnerable to Cellebrite phone hacking
#193Earlier quoted context omitted.
Wouldn't it be a total mindfuck if it turns out that Graphene is less secure[1] than stock Pixel, and this is all part of an ANOM-style honeypot operation that has Feds hyping it up, to trick interesting targets into adopting a less-effective security posture. 1. Such as via slower 0-day responses, for instance. This is a thought experiment, I'm nor alleging that this is what it is.
GrapheneOS releases patches very quickly, often even faster than OEMs do. But patches are only useful for fixing individual known vulnerabilities. GrapheneOS additionally focuses on defending against whole classes of vulnerabilities. [1] For example, in addition to fixing memory corruption bugs in individual system components, GrapheneOS has deployed memory protections for the entire OS in the form of hardened_malloc…
Re: Leaker reveals which Pixels are vulnerable to Cellebrite phone hacking
#194Earlier quoted context omitted.
Now in grapheneosin the updates settings it allows you to apply Google's upstream security patches, but grapheneos is forbidden from releasing the source code for these until a certain time later. You can read more about it on their blog. I have them enabled. At least I can rest easy knowing the Grapheneos Devs are able to inspect the code on users behalf even if they can't yet release it.
Will Graphene release the patches concurrently with Google? If there's a lag, then then Graphene is a tiny bit less safe in terms of one-day/n-day bugs. Not having the source of the patch adds some friction to all attackers, but reversing vulnerabilities from binary patches has a long history.
Re: Leaker reveals which Pixels are vulnerable to Cellebrite phone hacking
#195Another great thing about GrapheneOS (besides security) is that Google Play Services can be installed without elevated privileges and even in a separate profile which can't run in the background. This makes the phone suitable for both normal usage and for those cases where you need to use some "official" app. It passes Play Integrity "MEETS_BASIC_INTEGRITY" but of course doesn't pass higher levels but not because it'…
Called them up, explained the issue and a couple days later a new build without the issue appeared for install.
Re: Leaker reveals which Pixels are vulnerable to Cellebrite phone hacking
#196Earlier quoted context omitted.
No American company has a choice when the Feds want data stored on a company's server. That doesn't stop Apple or any other company from designing devices that attempt to keep prying eyes out of the data stored on your device.
The government has ways of twisting the arms of uncooperative people/organizations into providing all the backdoors they need. Everything from increased tax and regulatory scrutiny to "discovering" CSAM on executives' computers or phones. The government does what it wants because it's the government. Mere laws generally don't stand in its way for long.
Sounds an awful lot like terrorists.
Re: Leaker reveals which Pixels are vulnerable to Cellebrite phone hacking
#197Earlier quoted context omitted.
Neither have had any known BFU on the latest iOS for years. AFU is occasionally possible but most of the leaks had latest software and hardware as still protected. Powering off the phone is always still a good idea though if you can.
That's not true. Cellebrite has working BFU and AFU exploits for recent iOS and usually catches up to the latest iOS versions and hardware in weeks or a couple months. They do not have working brute force support for the Pixel 2 / Pixel 6 or later / iPhone 12 or later due to the secure elements but can still exploit the devices in BFU mode and extract the data available before unlocking. iPhone 17 may work out better…
Re: Leaker reveals which Pixels are vulnerable to Cellebrite phone hacking
#198Earlier quoted context omitted.
The government has ways of twisting the arms of uncooperative people/organizations into providing all the backdoors they need. Everything from increased tax and regulatory scrutiny to "discovering" CSAM on executives' computers or phones. The government does what it wants because it's the government. Mere laws generally don't stand in its way for long.
The government certainly objected when Apple designed an implementation of encrypted cloud backups for iDevices. That didn't stop Apple from eventually rolling out encrypted cloud backups anyway. Apple also refused to insert a backdoor into iDevices when James Comey ordered them to do so. They took the FBI to court and forced them to back down. Google is perfectly capable of fighting too, but their business model put…
Fortunately, no intelligence officials faced any consequences whatsoever for perjuring themselves to congress, or for engaging in a unconstitutional criminal conspiracy, so we can trust that the system of laws we've developed is working as intended and that this will never happen again.
Re: Leaker reveals which Pixels are vulnerable to Cellebrite phone hacking
#199How come not a single Cellebrite device got "lost" and thoroughly analyzed? Surely quite a few police depts are rather lax.
Re: Leaker reveals which Pixels are vulnerable to Cellebrite phone hacking
#200Wow. I was just thinking about jumping ship from iPhone to Pixel.
All iPhones were vulnerable according to the last available iOS support matrix.