Live data from Hacker News

Leaker reveals which Pixels are vulnerable to Cellebrite phone hacking

arstechnica.com

321–330 of 372 posts

Re: Leaker reveals which Pixels are vulnerable to Cellebrite phone hacking

#321
post #160

Earlier quoted context omitted.

The last leak was in 2024. Hopefully somone nabs the latest iOS release information Edit: last released leak showed they had broken the then most recent iOS release (17.5.1) in AFU state on all but the most recent hardware which was marked "available in CAS" https://discuss.grapheneos.org/d/14344-cellebrite-premium-ju... The good news is neither pixel nor iOS seems to show full file system extract under BFU state in…

February 2025 documentation was posted by someone in that thread and a blog post was written by someone about it which was linked there. The initial link posted with the February 2025 documentation died and the blog post only focuses on Android and GrapheneOS rather than iOS too. GrapheneOS has access to the latest Cellebrite Premium documentation since we have a contact able to share it with us. In April 2024 and th…

Any info on recent ban of SafeDot by Android and GOS? Any plans to implement SafeDot as an official GOS app?

Re: Leaker reveals which Pixels are vulnerable to Cellebrite phone hacking

#322
post #315
post #314

One super simple usability v. security tradeoff that Graphene made is that if you plug a new device into the USB while the screen is locked, it just won't work until you unlock the screen. This is kinda annoying the three times a year I want to use wired earbuds, but it's a major impediment for any kind of AFU hacking.

Someone should invent a purely analog port for wired earbuds that's immune to that kind of attack.

Maybe with a standardised size suitable for the thin phones we use nowadays, and to make the wires usable in any orientation they can also have one axis of symmetry, maybe along it's primary axis?

Re: Leaker reveals which Pixels are vulnerable to Cellebrite phone hacking

#323
post #160

Earlier quoted context omitted.

February 2025 documentation was posted by someone in that thread and a blog post was written by someone about it which was linked there. The initial link posted with the February 2025 documentation died and the blog post only focuses on Android and GrapheneOS rather than iOS too. GrapheneOS has access to the latest Cellebrite Premium documentation since we have a contact able to share it with us. In April 2024 and th…

Any info on recent ban of SafeDot by Android and GOS? Any plans to implement SafeDot as an official GOS app?

Isn't that now a native android function?

Re: Leaker reveals which Pixels are vulnerable to Cellebrite phone hacking

#324
post #286

Earlier quoted context omitted.

Straight from the horse's mouth: https://discuss.grapheneos.org/d/16393-maybe-re-instate-patt... > Pattern unlock is a badly designed lock method that's a major downgrade from the security of a PIN for multiple reasons. > Pattern lock is even more dangerous to people who are as you say more casual users. It is a badly designed and dangerous feature. iPhones not having this is very good for users. We will not add back…

That is hardly the only problem. The browser is astonishingly bad at dark mode. The launcher forces almost all icons to greyscale black and white and does not accept icon packs. I feel like I'm downgrading by my compulsion for Brave and Lawnchair, but some attention is lacking in aesthetics. (e/os has this problem to a lesser degree with the Bliss launcher.) There is no rooted ADB. Even if a giant OS TAINTED notifica…

Vanadium is pretty good but I agree there are problems I can circumvent only by using another one (Brave); I presume it's the strict tracking protection that breaks some sites.

Not sure about your launcher problem, but you had to turn it on yourself? I don't experience anything like this on my phones. I miss Nova though; none of the other launchers I tried came near (last tried: uLauncher, Kvaesito, Olauncher, Lawnchar, Niagara. Need to try Square home perhaps).

Lack of rooted adb is a good, conscious choice for the security focused OS. It's not about _you_, it's about the integrity of the OS.

You demand access to adb root. Today Cellebrite cannot extract entire phone with one profile unlocked. I bet they'd be thrilled to hear about the new, beautiful target.

If you really need that, you can build yourself debug image and have access to it. You want it, but that's incompatible with the security model. They give you ways to get it, of course, but without their stamp of OS integrity.

To me safe defaults are a good choice.

Re: Leaker reveals which Pixels are vulnerable to Cellebrite phone hacking

#325
post #252

Earlier quoted context omitted.

How so? Graphene is perfectly useable for a non-technical user. And once you install Play Store, it's almost indistinguishable UX-wise from any other Android phone.

“Install an OS on your phone” is nonsensical to 99.99% of users. You’re in a tech bubble.

I'm not talking about installation. I'm talking about using the OS once it's installed.

Re: Leaker reveals which Pixels are vulnerable to Cellebrite phone hacking

#326

Earlier quoted context omitted.

All of the listed features significantly raise the bar for exploitation ; https://grapheneos.org/features

So Graphene is actually more secure than most stock ROMs, but e.g. banking apps won't run on it "for security"? Why can't the stock ROMs use these features and be more secure also?

Because these apps use google play integrity which only google certified devices pass

Re: Leaker reveals which Pixels are vulnerable to Cellebrite phone hacking

#327

Earlier quoted context omitted.

So Graphene is actually more secure than most stock ROMs, but e.g. banking apps won't run on it "for security"? Why can't the stock ROMs use these features and be more secure also?

If apps refuse to run on graphene it's not because of graphene's content it's just a question of whether the attestation is recognised. It's not signed by Google. I guess one reason you'd want to avoid that is that makes it harder to e.g spoof your location or falsely tell the app that screenshotting is disabled.

It's mostly preventing apps to be botted . As each device has its own certificate and can be banned exclusively, if it's google certified. This certificate( also called keybox/keybox.xml) is stored in the secure enclave in the device.

If you want to dive deeper you can checkout droidguard/play integrity.

Re: Leaker reveals which Pixels are vulnerable to Cellebrite phone hacking

#328
post #119

Earlier quoted context omitted.

> stuff that's been removed as a "feature" isn't always stuff that nobody wants. Graphene isn't made to cater to what everyone wants. Face ID and fingerprint unlocking so clearly have no place in a hardened OS. "Google OS-level integration is absent" should not be suprising. This said, you ought to be able to have BFU security with stock Android and it's embarrassing Google ships stock vulnerable.

> Graphene isn't made to cater to what everyone wants. I know! My entire point is Graphene wouldn't be a good choice for the stock OS on a mass-market phone. The Graphene devices will be great, but if Google were to replace their stock OS with Graphene there would be problems.

Okay, but who cares to be honest? :)

If the general public prefers unsafe phones, they can chose literally any else brand. This is never going to be a mass market phone because of the tradeoffs that are perfectly fine for the intended recipients (eg people who believe a torch/calculator app REALLY doesn't need internet access, or that their Instagram REALLY doesn't need to have access to ALL the photos/videos.

Re: Leaker reveals which Pixels are vulnerable to Cellebrite phone hacking

#329

Earlier quoted context omitted.

So Graphene is actually more secure than most stock ROMs, but e.g. banking apps won't run on it "for security"? Why can't the stock ROMs use these features and be more secure also?

My banking apps run on it, but my concert ticket app doesn't, so I have a separate phone just for that one app.

They do it to prevent botting . They use play integrity ( i think ex safety net ).

Re: Leaker reveals which Pixels are vulnerable to Cellebrite phone hacking

#330
post #225

Earlier quoted context omitted.

> Why can't the stock ROMs use these features and be more secure also? Some of the features may hurt user experience in some way and people made different trade-off. For example, GrapheneOS disables USB before unlock so that there's no chance that some driver codes in Linux kernel run in response to a device being plugged in, for attack surface reduction. Then, say, if you have a cracked screen, the touchscreen no lo…

That also sounds like a nonstarter for a lot of kiosk and embedded use cases

Okay? Then switch that off? :)
Post reply on HN