Live data from Hacker News

Leaker reveals which Pixels are vulnerable to Cellebrite phone hacking

arstechnica.com

211–220 of 372 posts

Re: Leaker reveals which Pixels are vulnerable to Cellebrite phone hacking

#211

Earlier quoted context omitted.

Is grapheheOS actually harder to hack or does cellebrite just not put a lot of effort into supporting it because the very low odds of LEs running into one in the wild?

All of the listed features significantly raise the bar for exploitation ; https://grapheneos.org/features

So Graphene is actually more secure than most stock ROMs, but e.g. banking apps won't run on it "for security"?

Why can't the stock ROMs use these features and be more secure also?

Re: Leaker reveals which Pixels are vulnerable to Cellebrite phone hacking

#212

Earlier quoted context omitted.

Wouldn't it be a total mindfuck if it turns out that Graphene is less secure[1] than stock Pixel, and this is all part of an ANOM-style honeypot operation that has Feds hyping it up, to trick interesting targets into adopting a less-effective security posture. 1. Such as via slower 0-day responses, for instance. This is a thought experiment, I'm nor alleging that this is what it is.

GrapheneOS releases patches very quickly, often even faster than OEMs do. But patches are only useful for fixing individual known vulnerabilities. GrapheneOS additionally focuses on defending against whole classes of vulnerabilities. [1] For example, in addition to fixing memory corruption bugs in individual system components, GrapheneOS has deployed memory protections for the entire OS in the form of hardened_malloc…

> GrapheneOS is fully open source

Not really. There is a bunch of proprietary firmware running on those phones, which can be exploited with or without the help of the manufacturer.

Re: Leaker reveals which Pixels are vulnerable to Cellebrite phone hacking

#213

Earlier quoted context omitted.

All of the listed features significantly raise the bar for exploitation ; https://grapheneos.org/features

So Graphene is actually more secure than most stock ROMs, but e.g. banking apps won't run on it "for security"? Why can't the stock ROMs use these features and be more secure also?

My banking apps run on it, but my concert ticket app doesn't, so I have a separate phone just for that one app.

Re: Leaker reveals which Pixels are vulnerable to Cellebrite phone hacking

#214
post #205

Earlier quoted context omitted.

GrapheneOS isn't made by volunteers. They have a team of around 10 paid developers. They are a nonprofit foundation that receives donations and uses those to pay developers, infrastructure etc. Ars Technica has update its article to rectify that mistake. It doesn't mention that anymore.

Are you affiliated with the project? I see all your posts are about Graphene OS. On HN it is customary to state it: you often see "author here" in discussions where the author joins. If you are part of the team I would suggest against using the third person ("they have a team..."). I know strcat is the lead Graphene OS developer, and it seems you and Andromxda are very knowledgeable about the project and very active…

it might be that guy who uses different accounts for different topics

Re: Leaker reveals which Pixels are vulnerable to Cellebrite phone hacking

#215
BFU inside the table cells means:

"BFU extraction can only pull the small amount of "Device Encrypted" (DE) data that is accessible. This is mostly system logs, some app settings, and other non-personal data. It does not get messages, photos, or detailed app data." It basically gets them the list of apps, when the phone has been powered on and off and perhaps some cell geo location history.

FFS means Full Filesystem Search.

What this implies in practice:

All locked stock Android Pixels (including 10 I am almost sure) are vulnerable to FFS after the first unlock, even in the locked state. If you want to protect your data (crossing a border, or when you are about to be interrogated by Russian FSB), turn off your stock Android Pixel.

Re: Leaker reveals which Pixels are vulnerable to Cellebrite phone hacking

#216
post #205

Earlier quoted context omitted.

GrapheneOS isn't made by volunteers. They have a team of around 10 paid developers. They are a nonprofit foundation that receives donations and uses those to pay developers, infrastructure etc. Ars Technica has update its article to rectify that mistake. It doesn't mention that anymore.

Are you affiliated with the project? I see all your posts are about Graphene OS. On HN it is customary to state it: you often see "author here" in discussions where the author joins. If you are part of the team I would suggest against using the third person ("they have a team..."). I know strcat is the lead Graphene OS developer, and it seems you and Andromxda are very knowledgeable about the project and very active…

[deleted]

Re: Leaker reveals which Pixels are vulnerable to Cellebrite phone hacking

#217
post #33
post #16

Earlier quoted context omitted.

Lots more devices are safe BFU than just Apple's. It's not that complicated on a technical level - it's basically full-disk encryption. Apple sells the illusion of security and privacy, but they're not meaningfully more secure or private except from the device's owner. Remember when they made a big deal of blocking Facebook tracking, while simultaneously adding their own intrusive tracking?

>Lots more devices are safe BFU than just Apple's. It's not that complicated on a technical level - it's basically full-disk encryption. That's not the full story. Using LUKS encryption on your linux laptop might make it "safe BFU", but only if you're using a high entropy password. Most people don't want to enter a 24 character password to unlock their phone, so Apple/Google have to add dedicated security hardware to…

True but those chips also exist for PCs. Some USB security keys have this feature.

Re: Leaker reveals which Pixels are vulnerable to Cellebrite phone hacking

#218
post #183

Earlier quoted context omitted.

GrapheneOS isn't made by volunteers. They have a team of around 10 paid developers. They are a nonprofit foundation that receives donations and uses those to pay developers, infrastructure etc. Ars Technica has update its article to rectify that mistake. It doesn't mention that anymore.

It’s still a valid question. We have this huge corporation that’s doing so many things, constantly lobbying for policy, obscene revenue all while people are exploiting the apk out of their OS. In fact, looking at the news this week, the same question applies to Microsoft and Apple as well. Are they too big and distracted to care about security?

No, it's just that the user will not put up with a system like GrapheneOS.

Re: Leaker reveals which Pixels are vulnerable to Cellebrite phone hacking

#219
post #181

Earlier quoted context omitted.

Google OS-level integration is absent, and while Google Play Services can be installed, you're still missing things like Chromecast. Also, there's more manual configuration (although I don't remember exactly what, I've never used GrapheneOS). A lot of stuff you do get for free, but not all of it, and stuff that's been removed as a "feature" isn't always stuff that nobody wants.

I have no idea what you're talking about. Graphene is my daily driver. "Manual configuration" does not ring any bells. Google OS-level integration being "absent" is a core feature, not an annoyance. The problem with Graphene is that some app publishers are absolute asshats, they think their app is "more secure" when they require the Google verification spiel, when it is the other way around.

Is the battery life better with Graphene?

Re: Leaker reveals which Pixels are vulnerable to Cellebrite phone hacking

#220

> https://signal.org/blog/cellebrite-vulnerabilities/ There’s always the hope they are hit back: Cellebrite can develop solutions to automate the hacking of target phones, but in doing so their physical devices are exposed to being hacked as well.

“By a truly unbelievable coincidence, I was recently out for a walk when I saw a small package fall off a truck ahead of me” Hahahha. Also is this a common expression “fallen of the back of a truck”?

In France it is indeed a popular expression that means 'stolen' or 'acquired by non-disclosable means'
Post reply on HN