Live data from Hacker News

GrapheneOS finds Bluetooth memory corruption via ARM MTE

grapheneos.social

201–210 of 228 posts

Re: GrapheneOS finds Bluetooth memory corruption via ARM MTE

#201
post #180

Earlier quoted context omitted.

Much lower overhead, currently shipping, able to detect some forms of heap corruption but not nearly as reliably as CHERI. No protection on tags and small (2^4) space for them.

MTE can provide strong deterministic security properties through reserved tags. Anything not tagged has a 0 tag and anything tagged has a non-0 tag by default since it's a default exclusion. You can exclude other tags statically or dynamically via instructions for this, but you can also simply use the 0 tag for internal usage such as freed memory while knowing that any tagged pointer can't access it. In hardened_mall…

None of what you said is wrong but the point I was making largely centered around tags being architecturally visible, which is quite different from how CHERI operates.

Re: GrapheneOS finds Bluetooth memory corruption via ARM MTE

#202

Hope somebody using Graphene OS could answer: 1. Is it very challenging to install Graphene OS? Need special cables and to know a lot about jailbreaking Android devices, or will I be fine just following instructions? 2. Is it very inconvenient to use as a daily driver? How often phone just crashes and requires a few days of debugging? Will my bank app work on it?

1. Not at all, but the install guide is lengthy, and it's worth to read it first, so that you don't end up in pitfalls. Other than that, I plugged it in, clicked buttons on a website, waited between button clicks, and after 10 minutes, the phone was good to go.

2. Not for me, but this highly depends on the use case. Graphene has good, honest documentation regarding this[0]. Banking is a pain point, because to the phone, GrapheneOS is an unverified third party system. Other than this, I have never seen a single crash, and I even use the YouTube apps with the Play store that it lets you install.

https://grapheneos.org/usage#banking-apps

Re: GrapheneOS finds Bluetooth memory corruption via ARM MTE

#203
post #60

Earlier quoted context omitted.

I might have not caught that he tried to kill graphene os. Didn't he just say that he decided to not use gOS anymore because he thinks that the developer of gOS might have something against him personally? Anyway, I don't know a single person who stopped using gOS because of the feud between these two Gladly I might add since I have been enjoying gOS so far

I never installed it because of who the founder is... but maybe I'm wrong and it takes someone like this to start such a project.

I suggest to not care about this stuff so much. Can you imagine what sorts of people take part in your daily life, preparing your food, adjusting legislation, providing services like driving the bus, serving your request as a clerk, ringing up your items in a shop, designing and creating your clothes, and so on? We are surrounded with all sorts, and being very selective with a very few makes no difference. If you're interested in the system, I suggest to give it a whirl, your life will be richer with the experience.

Re: GrapheneOS finds Bluetooth memory corruption via ARM MTE

#204
post #27
post #2

GrapheneOS is so far ahead in terms of security than anything else that it makes chosing anything but pixel hardware really questionable. But I REALLY want replaceable batteries. Why does everything have to suck nowadays?

Not exaxtly grapheneOS but close enough CalyxOs has started supporting Fairphone 5 and it has replaceable batteries AFAIK: https://calyxos.org/news/2024/03/05/fp5/

CalyxOS is a great alternative to GrapheneOS. The way I see it is that CalyxOS is much better for privacy but not as good for security, whereas on GrapheneOS security is always the main priority, whilst privacy and usability are second thoughts.

Re: GrapheneOS finds Bluetooth memory corruption via ARM MTE

#205

Earlier quoted context omitted.

I have a super expensive secret on my phone and... I bend the knee to Google. Def can't trust Apple, can't trust Samsung. Google has managed to be the best. (Go ahead and @ me some cases that basically never hit the wild)

I can't imagine the threat model that leads you to trust Google but not Apple, but you do you: Maybe you're a Google hardware engineer and the expensive secret is blueprints for the next generation of Google Glass.

Buddy, 1000+ people got their iPhones cracked by pegasus, at least 1 person was killed and bezos had his noods leaked.

Yeah google does a better job.

Re: GrapheneOS finds Bluetooth memory corruption via ARM MTE

#206

This is 2024. We need formally-verified operating systems, applications, and tools in the spirit of seL4 but going beyond it in rigor. Cobbling together lightly tested, over-engineered, heaving codebase systems with fragile, dangerous languages in this day and age is asking for users dying when foreign actors hack them, annoying bugs for many, and attack surface for malware and hacking generally. On top of that, clea…

> We need formally-verified operating systems

Compartmentalization is a far stronger security measure according to experience. See: Qubes OS.

Re: GrapheneOS finds Bluetooth memory corruption via ARM MTE

#207
post #155

Earlier quoted context omitted.

Since you seem to be on the Graphene team, may I piggyback on this: I've been wanting to make the switch over from iOS for some time but it bothers me a bit that I have to buy a Google phone. Are there any plans to support non-Google devices? I know this has been discussed and the answer I've seen is that Google devices are the best fit, but at least one more option would be nice.

(not on the team) I believe the project are open to supporting other devices that meet the criteria, or collaborating with hardware partners to that effect. As I understand, the way it works is that the project first has to scope out a hardware target that meets their security requirements before support can be considered and funded for. Just that right now there are no other phones that meet the requirements specifi…

> Just that right now there are no other phones that meet the requirements specified

And that highlights the main goal of GrapheneOS - a security hardened mobile OS. (Note that better 'security' doesn't necessarily also mean better privacy protection).

Re: GrapheneOS finds Bluetooth memory corruption via ARM MTE

#208
post #204
post #27

Earlier quoted context omitted.

Not exaxtly grapheneOS but close enough CalyxOs has started supporting Fairphone 5 and it has replaceable batteries AFAIK: https://calyxos.org/news/2024/03/05/fp5/

CalyxOS is a great alternative to GrapheneOS. The way I see it is that CalyxOS is much better for privacy but not as good for security, whereas on GrapheneOS security is always the main priority, whilst privacy and usability are second thoughts.

How do you have privacy without security? If it's less secure it enables more attacks where your private data could be compromised.

Re: GrapheneOS finds Bluetooth memory corruption via ARM MTE

#209

Earlier quoted context omitted.

I can't imagine the threat model that leads you to trust Google but not Apple, but you do you: Maybe you're a Google hardware engineer and the expensive secret is blueprints for the next generation of Google Glass.

Buddy, 1000+ people got their iPhones cracked by pegasus, at least 1 person was killed and bezos had his noods leaked. Yeah google does a better job.

I'm not worried about being targeted by Pegasus, but I am worried about getting targeted for adshit by Google, or them selling all my info to databrokers, or having them disable all my accounts for arbitrary reasons. I think we have different threat models.

Maybe you're special enough to be worth targeting for bespoke surveillance, I'm worried about avoiding ordinary mass-market adtech surveillance.

Re: GrapheneOS finds Bluetooth memory corruption via ARM MTE

#210
post #204

Earlier quoted context omitted.

CalyxOS is a great alternative to GrapheneOS. The way I see it is that CalyxOS is much better for privacy but not as good for security, whereas on GrapheneOS security is always the main priority, whilst privacy and usability are second thoughts.

How do you have privacy without security? If it's less secure it enables more attacks where your private data could be compromised.

Security isn't something you have or not. There's nuances. CalyxOS makes a few trade-offs which I'm happy to accept in order to be able to use several banking apps, Google pay, wallet etc.
Post reply on HN