Live data from Hacker News

Leaker reveals which Pixels are vulnerable to Cellebrite phone hacking

arstechnica.com

241–250 of 372 posts

Re: Leaker reveals which Pixels are vulnerable to Cellebrite phone hacking

#242
post #181

Earlier quoted context omitted.

I have no idea what you're talking about. Graphene is my daily driver. "Manual configuration" does not ring any bells. Google OS-level integration being "absent" is a core feature, not an annoyance. The problem with Graphene is that some app publishers are absolute asshats, they think their app is "more secure" when they require the Google verification spiel, when it is the other way around.

Is the battery life better with Graphene?

I would say, similar. In theory it may be slightly worse, because you are not using play services to deliver notifications, but each app does their own fetching (I believe that's how it works), but you will also restrict apps more (due to e.g. being able to restrict network access), so the two sort of cancel out.

Re: Leaker reveals which Pixels are vulnerable to Cellebrite phone hacking

#243

So I'm running Pixel 6a with GrapheneOS beta updates, I'm okay? Tho if law enforcement needs in my phone they just need to hold me until after lunch, I get pretty hungry. And those Doritos and coke they offered me sure looks tasty...

Hell, for another sandwich and a potato salad, I'll go a couple more.

Re: Leaker reveals which Pixels are vulnerable to Cellebrite phone hacking

#245
post #153
post #87

Earlier quoted context omitted.

I think that's at the OS level. I think there are things that could be done through the firmware level.

That standard Android toggle doesn't turn off USB support at the OS level but rather controls the default USB gadget mode. USB gadget functionality is one part of the high level USB functionality. That doesn't block USB peripherals, USB-C alternate modes, etc. and leaves nearly all the kernel attack surface being exploited by Cellebrite intact. See https://news.ycombinator.com/item?id=45779241 which explains this.

Sorry, I had the wrong terminology.

Re: Leaker reveals which Pixels are vulnerable to Cellebrite phone hacking

#246
post #87

Earlier quoted context omitted.

I think that's at the OS level. I think there are things that could be done through the firmware level.

Since no phone on the market has open-source firmware, and the firmware likely has all the capabilities of the base system, I think arguing for a firmware lock on that is kind of pointless. Sure, every little bit of security helps, but ultimately you still need to trust a lot of stuff to use a smartphone or most other modern hardware.

I had the wrong terminology. Your sibling comment explains it better.

Re: Leaker reveals which Pixels are vulnerable to Cellebrite phone hacking

#247

Earlier quoted context omitted.

All of the listed features significantly raise the bar for exploitation ; https://grapheneos.org/features

So Graphene is actually more secure than most stock ROMs, but e.g. banking apps won't run on it "for security"? Why can't the stock ROMs use these features and be more secure also?

For what its worth, all of my local banking and e-government apps work flawlessly on GrapheneOS. The only unsupported feature or app I've found so far is Google Pay. (I'm from Italy)

Re: Leaker reveals which Pixels are vulnerable to Cellebrite phone hacking

#248

Earlier quoted context omitted.

All of the listed features significantly raise the bar for exploitation ; https://grapheneos.org/features

So Graphene is actually more secure than most stock ROMs, but e.g. banking apps won't run on it "for security"? Why can't the stock ROMs use these features and be more secure also?

If apps refuse to run on graphene it's not because of graphene's content it's just a question of whether the attestation is recognised. It's not signed by Google.

I guess one reason you'd want to avoid that is that makes it harder to e.g spoof your location or falsely tell the app that screenshotting is disabled.

Re: Leaker reveals which Pixels are vulnerable to Cellebrite phone hacking

#249
post #183

Earlier quoted context omitted.

GrapheneOS isn't made by volunteers. They have a team of around 10 paid developers. They are a nonprofit foundation that receives donations and uses those to pay developers, infrastructure etc. Ars Technica has update its article to rectify that mistake. It doesn't mention that anymore.

It’s still a valid question. We have this huge corporation that’s doing so many things, constantly lobbying for policy, obscene revenue all while people are exploiting the apk out of their OS. In fact, looking at the news this week, the same question applies to Microsoft and Apple as well. Are they too big and distracted to care about security?

Google has many, many government contracts.

I believe that they would face enormous scrutiny in multiple contexts if they adopted Graphene as the next version of Android.

Google also wants Play and GMS to have complete control of the device for their own selfish reasons. I do not see them willingly sandboxing their own control.

So I can think of a few reasons.

Re: Leaker reveals which Pixels are vulnerable to Cellebrite phone hacking

#250

Earlier quoted context omitted.

All of the listed features significantly raise the bar for exploitation ; https://grapheneos.org/features

So Graphene is actually more secure than most stock ROMs, but e.g. banking apps won't run on it "for security"? Why can't the stock ROMs use these features and be more secure also?

Wells Fargo runs on my Grapheme device.

It also runs on Lineage with Mind The Gapps.

Post reply on HN