Earlier quoted context omitted.
> GrapheneOS is fully open source Not really. There is a bunch of proprietary firmware running on those phones, which can be exploited with or without the help of the manufacturer.
Firmware is not OS. Your machine is a distributed system. The firmware is what runs a specific node. Yes they usually have DMA, shared busses, etc. That's an implementation detail.
Leaker reveals which Pixels are vulnerable to Cellebrite phone hacking
341–350 of 372 posts
Re: Leaker reveals which Pixels are vulnerable to Cellebrite phone hacking
#342Earlier quoted context omitted.
Isn't that now a native android function?
A little green dot? No, it's a small fraction of SafeDot functionality. I'm interested in audible notification when camera, mic, or gps is accessed. Currently, I cannot make it work on GOS (maybe, may phone is hacked).
Re: Leaker reveals which Pixels are vulnerable to Cellebrite phone hacking
#343Earlier quoted context omitted.
Is there anything actually preventing Samsung or another vendor from adopting GrapheneOS's security innovations?
GrapheneOS is seemingly working with an OEM to make a GrapheneOS smartphone. Its probably not samsung, but would still be an established vendor
Re: Leaker reveals which Pixels are vulnerable to Cellebrite phone hacking
#344Earlier quoted context omitted.
GrapheneOS provides massive security improvements over Android. You should read https://grapheneos.org/features#exploit-protection for an overview. Cellebrite quite clearly puts substantial effort into targeting GrapheneOS, much more than they do into targeting variants of Google Mobile Services Android across devices. Cellebrite provides much more detailed information and comparisons for GrapheneOS than any other va…
This is great information, thank you! Do you happen to know to what extent MTE is used on Android 16 when both Advanced Protection is enabled and when the newly-released "Device Protection" feature is enabled?
Re: Leaker reveals which Pixels are vulnerable to Cellebrite phone hacking
#345Earlier quoted context omitted.
That's not true. Cellebrite has working BFU and AFU exploits for recent iOS and usually catches up to the latest iOS versions and hardware in weeks or a couple months. They do not have working brute force support for the Pixel 2 / Pixel 6 or later / iPhone 12 or later due to the secure elements but can still exploit the devices in BFU mode and extract the data available before unlocking. iPhone 17 may work out better…
Citation needed.
Re: Leaker reveals which Pixels are vulnerable to Cellebrite phone hacking
#346Earlier quoted context omitted.
That's not true. Cellebrite has working BFU and AFU exploits for recent iOS and usually catches up to the latest iOS versions and hardware in weeks or a couple months. They do not have working brute force support for the Pixel 2 / Pixel 6 or later / iPhone 12 or later due to the secure elements but can still exploit the devices in BFU mode and extract the data available before unlocking. iPhone 17 may work out better…
What data _is_ there to extract BFU, really, if you can't break the secure element? I mean, the main storage isn't decrypted yet, right?
Apps are installed so that their packages are available before first unlock and can explicitly opt-in to supporting a specific subset of their components and data before available before first unlock. An app can implement push notifications before first unlock if the developers want to do it, and they could do that in a way where no message data, etc. is available before first unlock. The OS leaves it up to apps to decide what to do, and nearly all apps stick with the default of all their functionality and data available After First Unlock instead of either making it available Before First Unlock or having it go back at rest while locked again.
Re: Leaker reveals which Pixels are vulnerable to Cellebrite phone hacking
#347Earlier quoted context omitted.
No, it's just that the user will not put up with a system like GrapheneOS.
How so? Graphene is perfectly useable for a non-technical user. And once you install Play Store, it's almost indistinguishable UX-wise from any other Android phone.
Re: Leaker reveals which Pixels are vulnerable to Cellebrite phone hacking
#348Earlier quoted context omitted.
No, it's just that the user will not put up with a system like GrapheneOS.
Put up what exactly? You think privacy and security is readily available to everyone who just desires so? If by "put up", you mean not even putting normal efforts, then sure. That user, along with you, fully deserves to get tracked, profiled and fingerprinted to the maximum extent of mass surveillance
No, I but I would like to make it so. I find your view that people “deserve” privacy to be incredibly depressing and antithetical to the spirit of user empowerment.
Re: Leaker reveals which Pixels are vulnerable to Cellebrite phone hacking
#349Earlier quoted context omitted.
How so? Graphene is perfectly useable for a non-technical user. And once you install Play Store, it's almost indistinguishable UX-wise from any other Android phone.
He's a fucking ignorant normie. He has never even tried to install GOS because if he did, he would know how almost identical the experience is with Android and there are no privileged google processes running on your phone which not only hog the resources but sends every single bit of information about your whole life
Re: Leaker reveals which Pixels are vulnerable to Cellebrite phone hacking
#350Earlier quoted context omitted.
That's not true. Cellebrite has working BFU and AFU exploits for recent iOS and usually catches up to the latest iOS versions and hardware in weeks or a couple months. They do not have working brute force support for the Pixel 2 / Pixel 6 or later / iPhone 12 or later due to the secure elements but can still exploit the devices in BFU mode and extract the data available before unlocking. iPhone 17 may work out better…
My mental model of this is “Apple releases new iOS with security patches -> time passes before cellebrite develops an AFU exploit -> Eventually Apple patches the exploit -> go to step 1”. By adding auto reboot Apple ensured that since lots of the time is spent in the stage where the latest iOS has no AFU exploit and AFU becomes BFU before that changes, and thus they are stuck with only extracting whatever is unencryp…
Apple and Google do not appear to have a regular source for finding out which vulnerabilities are currently being exploited. Both appear to be refraining from actively seeking our these devices to patch all the exploits they use. It's often external researchers including at Citizen Lab and Amnesty International determining which vulnerabilities are being exploited by these tools and reporting it to both Apple and Google. Long periods of time often pass with no loss of capabilities for new Android and iOS versions. The main reason Cellebrite loses access is likely tied to the deployment of new exploit protections requiring working around those and using new vulnerabilities. Code churn also likely impacts them.
You seem to be mixing up what they're referring to as a BFU exploit with a BF exploit. Pixel 2, Pixel 6+ and iPhone 12+ have withstood Cellebrite's efforts to do brute force attacks against a BFU device. BFU exploit means they can extract data such as saved Wi-Fi networks and installed apps, but without a BF exploit they cannot bypass the secure element throttling. It may become impractical for them to have BF exploits anymore, but it doesn't make their BFU exploits worthless.