I've set up GrapheneOS on my Pixel with 2FA fingerprint + PIN unlock. No way will anyone be getting into it without my cooperation. My only issue was less compatibility with my local emergency services, since they can't see me on a map for some reason if I call from a GOS phone. My solution to that was a second Pixel as an emergency phone - one with the stock OS, that I'll swap sims with and take with me when hiking,…
Don't know if/how this works in the US, but the EU emergency number can always be called without a simcard/subscription, so no need to swap simcards. (And sometimes even from a locked phone)
Leaker reveals which Pixels are vulnerable to Cellebrite phone hacking
301–310 of 372 posts
Re: Leaker reveals which Pixels are vulnerable to Cellebrite phone hacking
#302Earlier quoted context omitted.
Oh is that right? That's cool. That might be enough to give Graphene another go, especially since Android Car is supported now. Thank you.
Also Garmin watches if you'd prefer wearing something with battery lasting weeks, not hours ;)
Re: Leaker reveals which Pixels are vulnerable to Cellebrite phone hacking
#303Re: Leaker reveals which Pixels are vulnerable to Cellebrite phone hacking
#304A ~dozen programmers are shipping a demonstrably more secure version of a multi-billion-dollar corporation's own operating system on that company's own hardware. That's incredible.
Or, it was lower priority for discovering exploits due to the number of users.
The reasoning is that the company, being concerned with online advertising and reach,^1 has the incentive to ensure that the software becomes popular with the largest possible number of users, perhaps even achieving monopoly power. According to traditional HN commentary, this makes the company and its software a preferred target for exploits by virtue of its popularity
1. Online surveillance practices to potentially support targeted advertising services, where the companies wantonly collect enormous quantities of data about millions of people, also makes them a target for exploits, e.g., "data breaches"
Consider an alternative status quo where computer owners, i.e., software users, have many options to choose from, including many operating systems, browsers, "app stores", "platforms", and so on
None of the options may be necessarily better choices for "security" for technical reasons^2 but the fact that those who target software from a small number of advertising services juggernauts with millions of users ("lucrative targets") are denied access to such lucrative targets, because the lucrative targets do not exist, is an improvement to "security" overall
2. But some may compete and attempt to distinguish themselves on this basis
In this alternative status quo there would likely be requirements that software be compliant with open standards and interoperable, allowing computer users to write, edit, compile, install and choose whatever software they desire, from any source, including their own brain, i.e., they might choose to write, compile and install their own software on their own computers
Re: Leaker reveals which Pixels are vulnerable to Cellebrite phone hacking
#305Earlier quoted context omitted.
> In fact, looking at the news this week, the same question applies to Microsoft and Apple as well. Are they too big and distracted to care about security? Yes, of course they are, but its more rational than just being distracted. If not caring does does not lose you a significant amount of revenue why should you care? The same applies to big players in the industry with regard to security and quality in general. In…
I don't think you can rule out international government pressures to keep these OSes vulnerable. I agree that not caring happens a lot in the industry. Plenty of places where you'd think security was a high priority shockingly it isn't. Instead, C-levels will dedicate just enough resources to pass security audits clients demand and not a a penny more.
Financial pressures cause this to happen well enough on its own.
The marginal gain from making a really secure phone is outweighed by the engineering cost and degraded user experience. (General public would rather the phone support every streaming video and graphics format under the sun than just a few securely implemented ones).
When was the last time you saw a FIPS mode option on a home WiFi router? Or even just the ability to turn off internal services? Oddly, just a single option to disable all management would often by useful and fairly trivial but never exists…
Re: Leaker reveals which Pixels are vulnerable to Cellebrite phone hacking
#306Earlier quoted context omitted.
> If not caring does does not lose you a significant amount of revenue why should you care? Sounds like it's time for heavy regulation. These corps are not "normal" businesses anymore, I think special (and stricter) rules should apply to them.
They are hard to regulate and I really doubt governments have either the willingness or the competence to do so effectively. The businesses are very heavily motivated to find ways around regulations, or manipulate them to to their advantage. Regulation is a very poor substitute for competition, and for well informed customers. Some of what I said in this comment is relevant: https://news.ycombinator.com/item?id=45780…
I've been following tech for my entire adult life. For more than 30 years now, competition or waiting for customers to become informed has never worked.
The only tools we have against mega corps are the ones the EU is currently applying via DMA and similar. But it will take a global effort in order to permanently shift priorities towards "earning money while doing the right thing" (as opposed to "earning money" state of today).
Corps like Google, Apple and friends are more similar to countries than businesses. The only problem is, international law and political pressure doesn't work on them as they're similar to countries governed by cartels.
Re: Leaker reveals which Pixels are vulnerable to Cellebrite phone hacking
#307Earlier quoted context omitted.
Also Garmin watches if you'd prefer wearing something with battery lasting weeks, not hours ;)
That's what I use. The Garmin O/S UX is a bit ass, but usable and I never need to carry money if I am going on a run.
Re: Leaker reveals which Pixels are vulnerable to Cellebrite phone hacking
#308Earlier quoted context omitted.
Which particular thing you consider inconvenient or even annoying? You can even install Google Play there. I see just one minor tradeoff - no face unlock.
They removed pattern lock, which makes me uncomfortable. I don't care for touch/fingerprint (or face) because biometrics aren't protected in the fifth amendment right to be free from self-incrimination. The only screen lock is PIN.
Re: Leaker reveals which Pixels are vulnerable to Cellebrite phone hacking
#309So I'm running Pixel 6a with GrapheneOS beta updates, I'm okay? Tho if law enforcement needs in my phone they just need to hold me until after lunch, I get pretty hungry. And those Doritos and coke they offered me sure looks tasty...
Re: Leaker reveals which Pixels are vulnerable to Cellebrite phone hacking
#310Earlier quoted context omitted.
Let's be very clear: this is still Google's choice. Google could build a phone that they can't be compelled to do anything to after the phone is sold to their customer, but Google alone chooses to not invest in the security of the phones they're selling to their customers. Because: what is good for the government is now equally good for Google. Do we not remember how Google immediately enabled TLS everywhere, interna…
Google brings to mind the ship of Theseus - many of the core decision makers have changed over the years, to the point where it's arguably a different company. The biggest change was 2015 (two years after your article): the founders and Eric Schmidt stepped back and a couple of other folks retired, leading to a new CEO, CFO and CBO. Their opinions on how to best run the company were quite different to their predecess…