Live data from Hacker News

Leaker reveals which Pixels are vulnerable to Cellebrite phone hacking

arstechnica.com

311–320 of 372 posts

Re: Leaker reveals which Pixels are vulnerable to Cellebrite phone hacking

#311

Earlier quoted context omitted.

Is there anything actually preventing Samsung or another vendor from adopting GrapheneOS's security innovations?

GrapheneOS is seemingly working with an OEM to make a GrapheneOS smartphone. Its probably not samsung, but would still be an established vendor

They are not making a "GrapheneOS smartphone", they are just helping providers make their new devices compatible with the security requirements, so GrapheneOS can be installed on it. But GrapheneOS will not come by default AFAIK.

Re: Leaker reveals which Pixels are vulnerable to Cellebrite phone hacking

#312
post #293

A ~dozen programmers are shipping a demonstrably more secure version of a multi-billion-dollar corporation's own operating system on that company's own hardware. That's incredible.

Or, it was lower priority for discovering exploits due to the number of users.

It's a possibility. Graphene has some traction though and if a potential high-importance target is running the OS, Cellebrite wouldn't want to be doing emergency vulnerability research to respond.

Re: Leaker reveals which Pixels are vulnerable to Cellebrite phone hacking

#313

Earlier quoted context omitted.

Use that and you'll get charged with destruction of evidence

Surely that's better than being charged with whatever crime they're trying to pin on you?

It depends, often the cover up is worse than the crime. See: Enron, Watergate, Trevor Jacob

Re: Leaker reveals which Pixels are vulnerable to Cellebrite phone hacking

#314
One super simple usability v. security tradeoff that Graphene made is that if you plug a new device into the USB while the screen is locked, it just won't work until you unlock the screen. This is kinda annoying the three times a year I want to use wired earbuds, but it's a major impediment for any kind of AFU hacking.

Re: Leaker reveals which Pixels are vulnerable to Cellebrite phone hacking

#315
post #314

One super simple usability v. security tradeoff that Graphene made is that if you plug a new device into the USB while the screen is locked, it just won't work until you unlock the screen. This is kinda annoying the three times a year I want to use wired earbuds, but it's a major impediment for any kind of AFU hacking.

Someone should invent a purely analog port for wired earbuds that's immune to that kind of attack.

Re: Leaker reveals which Pixels are vulnerable to Cellebrite phone hacking

#316
post #252

Earlier quoted context omitted.

No, it's just that the user will not put up with a system like GrapheneOS.

How so? Graphene is perfectly useable for a non-technical user. And once you install Play Store, it's almost indistinguishable UX-wise from any other Android phone.

“Install an OS on your phone” is nonsensical to 99.99% of users. You’re in a tech bubble.

Re: Leaker reveals which Pixels are vulnerable to Cellebrite phone hacking

#317
post #225

Earlier quoted context omitted.

So Graphene is actually more secure than most stock ROMs, but e.g. banking apps won't run on it "for security"? Why can't the stock ROMs use these features and be more secure also?

> Why can't the stock ROMs use these features and be more secure also? Some of the features may hurt user experience in some way and people made different trade-off. For example, GrapheneOS disables USB before unlock so that there's no chance that some driver codes in Linux kernel run in response to a device being plugged in, for attack surface reduction. Then, say, if you have a cracked screen, the touchscreen no lo…

That also sounds like a nonstarter for a lot of kiosk and embedded use cases

Re: Leaker reveals which Pixels are vulnerable to Cellebrite phone hacking

#318

Earlier quoted context omitted.

Oh is that right? That's cool. That might be enough to give Graphene another go, especially since Android Car is supported now. Thank you.

Also Garmin watches if you'd prefer wearing something with battery lasting weeks, not hours ;)

It's not that bad, my battery lasts around 36 hours. I take it off when I go to shower and by the time I remember to put it back on (~30min) it's usually back to 90%+.

Re: Leaker reveals which Pixels are vulnerable to Cellebrite phone hacking

#319

Earlier quoted context omitted.

Can concert tickets not be bought in a web browser?

Nope. This is eplus in Japan, and if you try go through the website it tells you you have to use the app. It's cos a lot of shows these days don't use paper tickets, but smart tickets on your phone. It is what it is.

What about people who do not have a smartphone?

Re: Leaker reveals which Pixels are vulnerable to Cellebrite phone hacking

#320
post #144

Earlier quoted context omitted.

Is grapheheOS actually harder to hack or does cellebrite just not put a lot of effort into supporting it because the very low odds of LEs running into one in the wild?

GrapheneOS provides massive security improvements over Android. You should read https://grapheneos.org/features#exploit-protection for an overview. Cellebrite quite clearly puts substantial effort into targeting GrapheneOS, much more than they do into targeting variants of Google Mobile Services Android across devices. Cellebrite provides much more detailed information and comparisons for GrapheneOS than any other va…

This is great information, thank you! Do you happen to know to what extent MTE is used on Android 16 when both Advanced Protection is enabled and when the newly-released "Device Protection" feature is enabled?
Post reply on HN