Live data from Hacker News

Leaker reveals which Pixels are vulnerable to Cellebrite phone hacking

arstechnica.com

61–70 of 372 posts

Re: Leaker reveals which Pixels are vulnerable to Cellebrite phone hacking

#61
post #28
post #22

Earlier quoted context omitted.

The government has ways of twisting the arms of uncooperative people/organizations into providing all the backdoors they need. Everything from increased tax and regulatory scrutiny to "discovering" CSAM on executives' computers or phones. The government does what it wants because it's the government. Mere laws generally don't stand in its way for long.

I think this is a very negative idea to promote: that laws should can be subverted. Everyone should believe that laws work and when they don't we should work to fix that, not assume that it can never be fixed.

I think it's healthy to imagine how authorities might abuse power and under what impetus, in order to head off those abuses. Laws have been subverted in the past, so it's rational to assume that they might be subverted in the future. This is actually a cornerstone of any effort to fix issues.

Re: Leaker reveals which Pixels are vulnerable to Cellebrite phone hacking

#62
post #48

> Notably, the Pixel 10 series is moving away from physical SIM cards. Is it? I hadn't followed news of the new Pixels. I don't like the idea of modernizing this and going full eSIM. It will introduce a lot of new friction, somehow I don't doubt it. Just now arrived to Mexico for a quick trip and grabbed a prepaid SIM from a 7-11 in the airport. All quick and simple. I doubt things would be so seamless when not havin…

eSIM can be QR code so if they wanted, Mexican vendor just pay and show QR code for you to scan.

The unfortunate problem with eSIM is that you can't swap it between phones.

Re: Leaker reveals which Pixels are vulnerable to Cellebrite phone hacking

#63
post #30

I've set up GrapheneOS on my Pixel with 2FA fingerprint + PIN unlock. No way will anyone be getting into it without my cooperation. My only issue was less compatibility with my local emergency services, since they can't see me on a map for some reason if I call from a GOS phone. My solution to that was a second Pixel as an emergency phone - one with the stock OS, that I'll swap sims with and take with me when hiking,…

> My solution to that was a second Pixel as an emergency phone Picking a Pixel specifically as an emergency phone is quite the choice, given years of on and off 911 issues.

...with the Google software.

Re: Leaker reveals which Pixels are vulnerable to Cellebrite phone hacking

#64

Earlier quoted context omitted.

Is there anything actually preventing Samsung or another vendor from adopting GrapheneOS's security innovations?

GrapheneOS is seemingly working with an OEM to make a GrapheneOS smartphone. Its probably not samsung, but would still be an established vendor

It better not be Samsung...

Re: Leaker reveals which Pixels are vulnerable to Cellebrite phone hacking

#65
post #60
post #44

Earlier quoted context omitted.

It physically disables USB ports when locked which significantly reduces the attack surface + can be configured to automatically reboot.

Two fixes that would be trivial to backport to mainline Android.

You can configure USB port for charging only in the developer options.

Re: Leaker reveals which Pixels are vulnerable to Cellebrite phone hacking

#66
post #60
post #44

Earlier quoted context omitted.

It physically disables USB ports when locked which significantly reduces the attack surface + can be configured to automatically reboot.

Two fixes that would be trivial to backport to mainline Android.

iOS already does both of this afaik. At least the automatic reboot part, I think the USB data functionality is disabled in some cases while locked too.

Re: Leaker reveals which Pixels are vulnerable to Cellebrite phone hacking

#67
post #4

Earlier quoted context omitted.

Short answer: Google is a business that can be compelled by the federal government in ways that nonprofits are resistant to. Ron Wyden identified one of these weaknesses in 2023: https://arstechnica.com/tech-policy/2023/12/apple-admits-to-...

Let's be very clear: this is still Google's choice. Google could build a phone that they can't be compelled to do anything to after the phone is sold to their customer, but Google alone chooses to not invest in the security of the phones they're selling to their customers. Because: what is good for the government is now equally good for Google. Do we not remember how Google immediately enabled TLS everywhere, interna…

Google brings to mind the ship of Theseus - many of the core decision makers have changed over the years, to the point where it's arguably a different company.

The biggest change was 2015 (two years after your article): the founders and Eric Schmidt stepped back and a couple of other folks retired, leading to a new CEO, CFO and CBO. Their opinions on how to best run the company were quite different to their predecessors.

I think another major change is the attention Google started to get from government and regulators.

Re: Leaker reveals which Pixels are vulnerable to Cellebrite phone hacking

#68

I've set up GrapheneOS on my Pixel with 2FA fingerprint + PIN unlock. No way will anyone be getting into it without my cooperation. My only issue was less compatibility with my local emergency services, since they can't see me on a map for some reason if I call from a GOS phone. My solution to that was a second Pixel as an emergency phone - one with the stock OS, that I'll swap sims with and take with me when hiking,…

Is there anything actually preventing Samsung or another vendor from adopting GrapheneOS's security innovations?

Willingness to pay great developers and engineers to build secure hardware,

understanding sec,

them observing actual demand for security.

History says don't hold your breath.

We get lucky once in a while, like with Google's hardware (without their software).

Re: Leaker reveals which Pixels are vulnerable to Cellebrite phone hacking

#69
post #9
post #7

Earlier quoted context omitted.

> how enshittified Google and Apple have become I don’t know about pop-ups or whatever, but as far as mobile security Apple appears to be running the table. Last cellebrite leak showed they couldn’t do anything in BFU, and you can tell Siri to put it back in BFU without hands while being arrested.

Cellebrite is like the Kmart Blue Light Special of Israeli spyware, when you compare it to Greykey and NSO Group offerings. I would not use their capabilities as the be-all end-all.

I was pretty much looking for this info. Thank you.

Re: Leaker reveals which Pixels are vulnerable to Cellebrite phone hacking

#70
post #27
post #16

Earlier quoted context omitted.

Lots more devices are safe BFU than just Apple's. It's not that complicated on a technical level - it's basically full-disk encryption. Apple sells the illusion of security and privacy, but they're not meaningfully more secure or private except from the device's owner. Remember when they made a big deal of blocking Facebook tracking, while simultaneously adding their own intrusive tracking?

> Lots more devices are safe BFU than just Apple's. It's not that complicated on a technical level - it's basically full-disk encryption. So we agree: it's puzzling that Google can't manage to do it.

Google being bad doesn't mean Apple is good.
Post reply on HN