Live data from Hacker News

Leaker reveals which Pixels are vulnerable to Cellebrite phone hacking

arstechnica.com

251–260 of 372 posts

Re: Leaker reveals which Pixels are vulnerable to Cellebrite phone hacking

#251
post #183

Earlier quoted context omitted.

It’s still a valid question. We have this huge corporation that’s doing so many things, constantly lobbying for policy, obscene revenue all while people are exploiting the apk out of their OS. In fact, looking at the news this week, the same question applies to Microsoft and Apple as well. Are they too big and distracted to care about security?

> In fact, looking at the news this week, the same question applies to Microsoft and Apple as well. Are they too big and distracted to care about security? Yes, of course they are, but its more rational than just being distracted. If not caring does does not lose you a significant amount of revenue why should you care? The same applies to big players in the industry with regard to security and quality in general. In…

> If not caring does does not lose you a significant amount of revenue why should you care?

Sounds like it's time for heavy regulation. These corps are not "normal" businesses anymore, I think special (and stricter) rules should apply to them.

Re: Leaker reveals which Pixels are vulnerable to Cellebrite phone hacking

#252
post #183

Earlier quoted context omitted.

It’s still a valid question. We have this huge corporation that’s doing so many things, constantly lobbying for policy, obscene revenue all while people are exploiting the apk out of their OS. In fact, looking at the news this week, the same question applies to Microsoft and Apple as well. Are they too big and distracted to care about security?

No, it's just that the user will not put up with a system like GrapheneOS.

How so? Graphene is perfectly useable for a non-technical user. And once you install Play Store, it's almost indistinguishable UX-wise from any other Android phone.

Re: Leaker reveals which Pixels are vulnerable to Cellebrite phone hacking

#253
post #242

Earlier quoted context omitted.

Is the battery life better with Graphene?

I would say, similar. In theory it may be slightly worse, because you are not using play services to deliver notifications, but each app does their own fetching (I believe that's how it works), but you will also restrict apps more (due to e.g. being able to restrict network access), so the two sort of cancel out.

I see. Thanks for the feedback!

Re: Leaker reveals which Pixels are vulnerable to Cellebrite phone hacking

#254
post #183

Earlier quoted context omitted.

It’s still a valid question. We have this huge corporation that’s doing so many things, constantly lobbying for policy, obscene revenue all while people are exploiting the apk out of their OS. In fact, looking at the news this week, the same question applies to Microsoft and Apple as well. Are they too big and distracted to care about security?

> In fact, looking at the news this week, the same question applies to Microsoft and Apple as well. Are they too big and distracted to care about security? Yes, of course they are, but its more rational than just being distracted. If not caring does does not lose you a significant amount of revenue why should you care? The same applies to big players in the industry with regard to security and quality in general. In…

I don't think you can rule out international government pressures to keep these OSes vulnerable.

I agree that not caring happens a lot in the industry. Plenty of places where you'd think security was a high priority shockingly it isn't. Instead, C-levels will dedicate just enough resources to pass security audits clients demand and not a a penny more.

Re: Leaker reveals which Pixels are vulnerable to Cellebrite phone hacking

#255

Earlier quoted context omitted.

So Graphene is actually more secure than most stock ROMs, but e.g. banking apps won't run on it "for security"? Why can't the stock ROMs use these features and be more secure also?

My banking apps run on it, but my concert ticket app doesn't, so I have a separate phone just for that one app.

Can concert tickets not be bought in a web browser?

Re: Leaker reveals which Pixels are vulnerable to Cellebrite phone hacking

#256
post #232
post #212

Earlier quoted context omitted.

> GrapheneOS is fully open source Not really. There is a bunch of proprietary firmware running on those phones, which can be exploited with or without the help of the manufacturer.

Show me any device on earth that can run a browser that has no proprietary code whatsoever (including hardware) on it?

AFAIK older Talos Secure Workstation with Power CPUs was it. Everything open including CPU firmware.

Not sure about smartphones though - they mostly struggle with a fact there are no truly open source baseband.

Re: Leaker reveals which Pixels are vulnerable to Cellebrite phone hacking

#257
post #80

Earlier quoted context omitted.

GrapheneOS makes security trade-off that are inconvenient to the user. This results in a far more secure device, but nonetheless a device that the general public would find far more annoying. Google would lose a proportion of its user base by implementing the same protections. Example: https://old.reddit.com/r/GooglePixel/comments/ytk1ng/graphen... Also Google Pay is missing.

Which particular thing you consider inconvenient or even annoying? You can even install Google Play there. I see just one minor tradeoff - no face unlock.

They removed pattern lock, which makes me uncomfortable.

I don't care for touch/fingerprint (or face) because biometrics aren't protected in the fifth amendment right to be free from self-incrimination.

The only screen lock is PIN.

Re: Leaker reveals which Pixels are vulnerable to Cellebrite phone hacking

#258
post #33

Earlier quoted context omitted.

>Lots more devices are safe BFU than just Apple's. It's not that complicated on a technical level - it's basically full-disk encryption. That's not the full story. Using LUKS encryption on your linux laptop might make it "safe BFU", but only if you're using a high entropy password. Most people don't want to enter a 24 character password to unlock their phone, so Apple/Google have to add dedicated security hardware to…

True but those chips also exist for PCs. Some USB security keys have this feature.

Do they actually implement anti-bruteforce protections though? Or does it just provide a static secret? Moreover how strong are the anti-bruteforce protections? Do they restrict attempts to a few per second, or actually keep track of how many wrong attempts and wipe themselves if that's exceeded?

Re: Leaker reveals which Pixels are vulnerable to Cellebrite phone hacking

#259
post #119

Earlier quoted context omitted.

Google OS-level integration is absent, and while Google Play Services can be installed, you're still missing things like Chromecast. Also, there's more manual configuration (although I don't remember exactly what, I've never used GrapheneOS). A lot of stuff you do get for free, but not all of it, and stuff that's been removed as a "feature" isn't always stuff that nobody wants.

> stuff that's been removed as a "feature" isn't always stuff that nobody wants. Graphene isn't made to cater to what everyone wants. Face ID and fingerprint unlocking so clearly have no place in a hardened OS. "Google OS-level integration is absent" should not be suprising. This said, you ought to be able to have BFU security with stock Android and it's embarrassing Google ships stock vulnerable.

Graphene on my Pixel 6 certainly does support fingerprint unlocking.

I prefer pattern unlock, which it does not support.

Re: Leaker reveals which Pixels are vulnerable to Cellebrite phone hacking

#260
post #3

They couldn't answer the question most on my mind: "We’ve reached out to Google to inquire about why a custom ROM created by volunteers is more resistant to industrial phone hacking than the official Pixel OS. We’ll update this article if Google has anything to say."

GrapheneOS is basically the Android equivalent of iOS Lockdown mode. Considering how the threat landscape has changed, it would be nice if Google offered this itself. Or became a long-term sponsor of GrapheneOS, seeing how great a job they've been doing.

Not really.

iOS in lockdown mode has multiple features disabled (or crippled, depending on how you look at it), while GrapheneOS is just..... secure by design with secure defaults.

https://support.apple.com/en-us/105120

In iPhone also you cannot just turn on/off/adjust these protections one by one, it's all or nothing.

Post reply on HN