Live data from Hacker News

Leaker reveals which Pixels are vulnerable to Cellebrite phone hacking

arstechnica.com

281–290 of 372 posts

Re: Leaker reveals which Pixels are vulnerable to Cellebrite phone hacking

#281
post #183

Earlier quoted context omitted.

GrapheneOS isn't made by volunteers. They have a team of around 10 paid developers. They are a nonprofit foundation that receives donations and uses those to pay developers, infrastructure etc. Ars Technica has update its article to rectify that mistake. It doesn't mention that anymore.

It’s still a valid question. We have this huge corporation that’s doing so many things, constantly lobbying for policy, obscene revenue all while people are exploiting the apk out of their OS. In fact, looking at the news this week, the same question applies to Microsoft and Apple as well. Are they too big and distracted to care about security?

Don't you remember when Satya Nadella was called in front of a congressional hearing to explain their numerous security breaches? So yeah..

Apple is a different story, but they are not invulnerable to cellebrite either

Re: Leaker reveals which Pixels are vulnerable to Cellebrite phone hacking

#282

Earlier quoted context omitted.

Wouldn't it be a total mindfuck if it turns out that Graphene is less secure[1] than stock Pixel, and this is all part of an ANOM-style honeypot operation that has Feds hyping it up, to trick interesting targets into adopting a less-effective security posture. 1. Such as via slower 0-day responses, for instance. This is a thought experiment, I'm nor alleging that this is what it is.

I use graphene not for security but because it doesn't come with any Google surveillance stuff. Let's be realistic if some 3 letters agency really want some data about me, there's not much I can do to counter that unless I'm ready to go to extreme lengths.

>Let's be realistic if some 3 letters agency really want some data about me, there's not much I can do to counter that unless I'm ready to go to extreme lengths.

I once thought like you. You do not need to go to extreme lengths to make things difficult and that is what is important. The fact is that the 3 letter agencies are increasingly fucking with normal people in a race to the bottom. Do not be defeatist - that only hurts everyone. The more people protecting themselves the safer everyone is from these people. If people just give up on privacy it puts a spotlight on normal people protecting themselves. The current state of which is so bad I have trouble putting it into words.

Re: Leaker reveals which Pixels are vulnerable to Cellebrite phone hacking

#283

Earlier quoted context omitted.

Reminds me of that one case a few weeks back where Graphene wasn't allowed to release a patch because Google wasn't planning on releasing a patch for it for a few more months.

GrapheneOS has a security preview release channel that is opt-in but includes patches from these embargoed vulns already. Again, it's opt-in but for those with a higher threat model use-case it's nice to have.

Would this not defeat the purpose of responsible disclosure? As a bad actor I could learn of secret vulnerabilities from this channel.

Re: Leaker reveals which Pixels are vulnerable to Cellebrite phone hacking

#284
post #48

> Notably, the Pixel 10 series is moving away from physical SIM cards. Is it? I hadn't followed news of the new Pixels. I don't like the idea of modernizing this and going full eSIM. It will introduce a lot of new friction, somehow I don't doubt it. Just now arrived to Mexico for a quick trip and grabbed a prepaid SIM from a 7-11 in the airport. All quick and simple. I doubt things would be so seamless when not havin…

eSIMs feel like a solution waiting for a problem. Consumers are happy with physical SIMs, you obtain one, you put it in your phone then you forget about it until you swap your phone. I'm sure eSIMs are a good idea if your aim is to gain even more control over our personal devices.

For me, eSIM was the only solution to a very real problem: being able to use virtual carriers without mailing a physical SIM. I can pay anonymously for a regional SIM from my MVNO at an affordable price, without giving a local carrier a copy of my passport to retain indefinitely. Unfortunately, they still only resell incumbent bandwidth--but that's the reality of spectrum licensing.

Re: Leaker reveals which Pixels are vulnerable to Cellebrite phone hacking

#285

Earlier quoted context omitted.

I use graphene not for security but because it doesn't come with any Google surveillance stuff. Let's be realistic if some 3 letters agency really want some data about me, there's not much I can do to counter that unless I'm ready to go to extreme lengths.

>Let's be realistic if some 3 letters agency really want some data about me, there's not much I can do to counter that unless I'm ready to go to extreme lengths. I once thought like you. You do not need to go to extreme lengths to make things difficult and that is what is important. The fact is that the 3 letter agencies are increasingly fucking with normal people in a race to the bottom. Do not be defeatist - that o…

I think their comment is rightly pointing out that if a TLA or other state intelligence actor takes an interest in you specifically, they can do quite a bit of classic spycraft that is considerably more expensive i.e. direct surveillance. No alternative handset OS will protect you from an agent who bugs your house, or someone firing a polonium pellet into your leg from a modified umbrella.

Re: Leaker reveals which Pixels are vulnerable to Cellebrite phone hacking

#286
post #257

Earlier quoted context omitted.

They removed pattern lock, which makes me uncomfortable. I don't care for touch/fingerprint (or face) because biometrics aren't protected in the fifth amendment right to be free from self-incrimination. The only screen lock is PIN.

Straight from the horse's mouth: https://discuss.grapheneos.org/d/16393-maybe-re-instate-patt... > Pattern unlock is a badly designed lock method that's a major downgrade from the security of a PIN for multiple reasons. > Pattern lock is even more dangerous to people who are as you say more casual users. It is a badly designed and dangerous feature. iPhones not having this is very good for users. We will not add back…

That is hardly the only problem.

The browser is astonishingly bad at dark mode.

The launcher forces almost all icons to greyscale black and white and does not accept icon packs.

I feel like I'm downgrading by my compulsion for Brave and Lawnchair, but some attention is lacking in aesthetics. (e/os has this problem to a lesser degree with the Bliss launcher.)

There is no rooted ADB. Even if a giant OS TAINTED notification appears every five minutes if I ever turn it on, I want it.

There are a few other annoyances that regulate Graphene to one of my experimental spares.

Re: Leaker reveals which Pixels are vulnerable to Cellebrite phone hacking

#287
post #258

Earlier quoted context omitted.

True but those chips also exist for PCs. Some USB security keys have this feature.

Do they actually implement anti-bruteforce protections though? Or does it just provide a static secret? Moreover how strong are the anti-bruteforce protections? Do they restrict attempts to a few per second, or actually keep track of how many wrong attempts and wipe themselves if that's exceeded?

There are many different ones.

Re: Leaker reveals which Pixels are vulnerable to Cellebrite phone hacking

#289

Earlier quoted context omitted.

https://grapheneos.org/features#duress :D

Use that and you'll get charged with destruction of evidence

Surely that's better than being charged with whatever crime they're trying to pin on you?

Re: Leaker reveals which Pixels are vulnerable to Cellebrite phone hacking

#290
post #3

They couldn't answer the question most on my mind: "We’ve reached out to Google to inquire about why a custom ROM created by volunteers is more resistant to industrial phone hacking than the official Pixel OS. We’ll update this article if Google has anything to say."

I'd almost want to avoid GrapheneOS because it gets so much attention from law enforcement that it's probably a big target for various agencies to find vulnerabilities in.

More attention than stock android?
Post reply on HN