Live data from Hacker News

Leaker reveals which Pixels are vulnerable to Cellebrite phone hacking

arstechnica.com

261–270 of 372 posts

Re: Leaker reveals which Pixels are vulnerable to Cellebrite phone hacking

#261
post #3

They couldn't answer the question most on my mind: "We’ve reached out to Google to inquire about why a custom ROM created by volunteers is more resistant to industrial phone hacking than the official Pixel OS. We’ll update this article if Google has anything to say."

So much for all the security posturing by Google lol.

I mean, hardware is great, it's literally the only safe and secure hardware for AOSP. Samsung are mostly security theater, all the other brands are shockingly bad.

Re: Leaker reveals which Pixels are vulnerable to Cellebrite phone hacking

#262
post #205

Earlier quoted context omitted.

GrapheneOS isn't made by volunteers. They have a team of around 10 paid developers. They are a nonprofit foundation that receives donations and uses those to pay developers, infrastructure etc. Ars Technica has update its article to rectify that mistake. It doesn't mention that anymore.

Are you affiliated with the project? I see all your posts are about Graphene OS. On HN it is customary to state it: you often see "author here" in discussions where the author joins. If you are part of the team I would suggest against using the third person ("they have a team..."). I know strcat is the lead Graphene OS developer, and it seems you and Andromxda are very knowledgeable about the project and very active…

It's literally ONE click away from the GrapheneOS main page, lol, the literacy levels gone through the floor.

https://grapheneos.org/history/

> GrapheneOS now has multiple full-time and part-time developers supported by donations and multiple companies collaborating with the project.

This is beyond being just shockingly, willingly ignorant and this is out there re on the open, so in the spirit of your own response, I would suggest you admit your comment is a hit piece from their infamous competition.

Re: Leaker reveals which Pixels are vulnerable to Cellebrite phone hacking

#263
post #205

Earlier quoted context omitted.

Are you affiliated with the project? I see all your posts are about Graphene OS. On HN it is customary to state it: you often see "author here" in discussions where the author joins. If you are part of the team I would suggest against using the third person ("they have a team..."). I know strcat is the lead Graphene OS developer, and it seems you and Andromxda are very knowledgeable about the project and very active…

it might be that guy who uses different accounts for different topics

Of your favourite search engine is broken too, here's the link anyone can read: https://grapheneos.org/history/

Re: Leaker reveals which Pixels are vulnerable to Cellebrite phone hacking

#264
post #86

Earlier quoted context omitted.

This doesn't make sense. If you're worried about the government targeting you, then what is the alternative... less hardened phones? At least Graphene will protect you better than the stock OS. If you're really that concerned then you shouldn't use anything going through cell tower (or take extreme precautions when doing so).

I did say "almost". But as you mention there aren't many alternative. It would be a better world if there were several options besides just Graphene that prioritize security.

What they are doing is difficult and expensive.

The talent pool that is willing to work in a nonprofit is not likely large.

Re: Leaker reveals which Pixels are vulnerable to Cellebrite phone hacking

#265
post #142

Earlier quoted context omitted.

I've been using an eSim on my iPhone and it's been wonderful because: 1. migrating between iPhones also transfers the eSim 2. if I get a tourist sim card at an airport, I don't have to worry about taking out or losing my main sim 3. the ability to have multiple sims is also ideal: I currently have phone plans in AU and SG, in addition to any tourist sim cards I pick up

Fwiw, I can't remember the last time I bought a physical sim at an airport. Airalo lets me buy an eSim at the departing airport, which means I've got cell data from the instant I arrive. They're not the only company offering this, and I'm sure I could min max and find a more cost optimized service, but it's done me well enough. Depending on the amount of international travel you do, and to where, however, US travelle…

It's important to point out that few MVNO operators on T-Moble extend this international access.

Re: Leaker reveals which Pixels are vulnerable to Cellebrite phone hacking

#266
post #86

Earlier quoted context omitted.

This doesn't make sense. If you're worried about the government targeting you, then what is the alternative... less hardened phones? At least Graphene will protect you better than the stock OS. If you're really that concerned then you shouldn't use anything going through cell tower (or take extreme precautions when doing so).

I did say "almost". But as you mention there aren't many alternative. It would be a better world if there were several options besides just Graphene that prioritize security.

In reality you have iPhones (in lockdown mode meaning you mist throw some of the usability away) or GrapheneOS if you prefer android.

No other hardware and software solutions come close. Cellebrite matrix shows it pretty well (and from late 2024 cellebrite cannot even extract entire phone form the unlocked GOS.

Re: Leaker reveals which Pixels are vulnerable to Cellebrite phone hacking

#267

Earlier quoted context omitted.

Google Wallet works but tap-to-pay NFC payments don't because Google enforces strong Play Integrity for that portion. They only allow Google certified OSes to use it. It's a sad choice on their part, not GrapheneOS' fault or choice.

Without Google Pay, Google Wallet is practically a glorified card number vault. Which can still be useful, just not at card terminals.

Close.

To me it's a biggest missing feature to date (and the team brought that up with European Commission already, as there are no technical or security reasons for that). Worth noting it will work on the old, unpatched, rooted, wildly unsafe phones with the right magisk configuration. But not on the safest os.

Anyway, it keeps the passes okay for me, and for the payments I use Garmin Pay.

Re: Leaker reveals which Pixels are vulnerable to Cellebrite phone hacking

#268

Earlier quoted context omitted.

Google Pay also works with a Pixel watch connected to a GrapheneOS phone, FWIW.

Oh is that right? That's cool. That might be enough to give Graphene another go, especially since Android Car is supported now. Thank you.

Also Garmin watches if you'd prefer wearing something with battery lasting weeks, not hours ;)

Re: Leaker reveals which Pixels are vulnerable to Cellebrite phone hacking

#269

Earlier quoted context omitted.

My banking apps run on it, but my concert ticket app doesn't, so I have a separate phone just for that one app.

Can concert tickets not be bought in a web browser?

No they can’t. It’s very frustrating.

I had to get my friend to buy them for me when I was on Graphene

Re: Leaker reveals which Pixels are vulnerable to Cellebrite phone hacking

#270
post #256
post #232

Earlier quoted context omitted.

Show me any device on earth that can run a browser that has no proprietary code whatsoever (including hardware) on it?

AFAIK older Talos Secure Workstation with Power CPUs was it. Everything open including CPU firmware. Not sure about smartphones though - they mostly struggle with a fact there are no truly open source baseband.

There is no smartphone fully powered by open firmware. Also keep in mind that the hardware itself is proprietary too.
Post reply on HN