Join the discussion

Write your take first — we'll ask for email only when you're ready to publish.

  • Hacker News
  • So I'm running Pixel 6a with GrapheneOS beta updates, I'm okay? Tho if law enforcement needs in my phone they just need to hold me until after lunch, I get pretty hungry. And those Doritos and coke they offered me sure looks tasty...
  • Hell, for another sandwich and a potato salad, I'll go a couple more.
  • Technically, the upgrade to the Pixel 8 (or higher) would be security-wise a lot better, because they offer more memory safety (MTE), but yeah you are probably good.
  • Since nobody else has mentioned it... "vulnerable to hacking" is doing a lot of heavy lifting here. It's "vulnerable" about as much as my LUKS desktop system is vulnerable.

    These charts have been available for years and don't tell us anything particularly scary IMO.

    This "hacking" especially for BFU/turned-off Pixel devices, at best would amount to brute-forcing your password, either on-device or after copying the flash elsewhere.

    Short of using top-secret multi-million dollar 0days or something, there is no inherent Pixel flaw that lets them bypass the device's encryption or anything crazy like people are thinking. They still have to get your password somehow, just like anyone else.

  • How come not a single Cellebrite device got "lost" and thoroughly analyzed? Surely quite a few police depts are rather lax.
  • I wonder why they haven't switched to a more lucrative model of remote unlock/forensic acquisition using something like WebUSB.
  • One did "fall off a truck" and into Moxie Marlinspike's hands back in 2021: https://signal.org/blog/cellebrite-vulnerabilities/

    A bunch of their software was also leaked in a hack back in 2023: https://ddosecrets.com/article/cellebrite-and-msab

  • Another great thing about GrapheneOS (besides security) is that Google Play Services can be installed without elevated privileges and even in a separate profile which can't run in the background. This makes the phone suitable for both normal usage and for those cases where you need to use some "official" app.

    It passes Play Integrity "MEETS_BASIC_INTEGRITY" but of course doesn't pass higher levels but not because it's insecure - it's because it refuses to grant GMS elevated privileges. Good news is that banking apps can whitelist GrapheneOS using standard Android attestation mechanism (and some already did).

    by zb3
  • My bank (largest local in my country) shipped a beta version of their app where my pixel8p with grapheneos was flagged as insecure this summer.

    Called them up, explained the issue and a couple days later a new build without the issue appeared for install.

  • I've set up GrapheneOS on my Pixel with 2FA fingerprint + PIN unlock. No way will anyone be getting into it without my cooperation.

    My only issue was less compatibility with my local emergency services, since they can't see me on a map for some reason if I call from a GOS phone.

    My solution to that was a second Pixel as an emergency phone - one with the stock OS, that I'll swap sims with and take with me when hiking, stand up paddle bording and doing other activities that carry risk. This phone has no sensitive information in it. I also have a PLB for added protection.

  • Is there anything actually preventing Samsung or another vendor from adopting GrapheneOS's security innovations?
  • First I’m hearing Graphene causes issues with E911 - is this a setting?
  • Don't know if/how this works in the US, but the EU emergency number can always be called without a simcard/subscription, so no need to swap simcards. (And sometimes even from a locked phone)
  • > My solution to that was a second Pixel as an emergency phone

    Picking a Pixel specifically as an emergency phone is quite the choice, given years of on and off 911 issues.

  • One super simple usability v. security tradeoff that Graphene made is that if you plug a new device into the USB while the screen is locked, it just won't work until you unlock the screen. This is kinda annoying the three times a year I want to use wired earbuds, but it's a major impediment for any kind of AFU hacking.
  • Someone should invent a purely analog port for wired earbuds that's immune to that kind of attack.
    by Zak
  • Testament to GrapheneOS' competence and commitment to it's purpose that it's called out by name by Cellebrite.
  • A ~dozen programmers are shipping a demonstrably more secure version of a multi-billion-dollar corporation's own operating system on that company's own hardware. That's incredible.
  • Or, it was lower priority for discovering exploits due to the number of users.
  • Here's the full document without the blurriness: https://www.documentcloud.org/documents/24833831-cellebrite-...

    (it's been available since 2024 -- found by searching for "android os access support matrix" on documentcloud)

  • This one doesn't have Pixel 9's so the image in the article has been updated a bit.
  • The point here is that the doc you linked is a year and a half old, this (if real) is much newer. Security is a constant arms race between attackers and defenders, nothing is static so updates of this nature are always welcome.
  • > https://signal.org/blog/cellebrite-vulnerabilities/

    There’s always the hope they are hit back: Cellebrite can develop solutions to automate the hacking of target phones, but in doing so their physical devices are exposed to being hacked as well.

  • “By a truly unbelievable coincidence, I was recently out for a walk when I saw a small package fall off a truck ahead of me”

    Hahahha. Also is this a common expression “fallen of the back of a truck”?

  • ahhh what is this?

    > The completely unrelated

    > In completely unrelated news, upcoming versions of Signal will be periodically fetching files to place in app storage. These files are never used for anything inside Signal and never interact with Signal software or data, but they look nice, and aesthetics are important in software. Files will only be returned for accounts that have been active installs for some time already, and only probabilistically in low percentages based on phone number sharding. We have a few different versions of files that we think are aesthetically pleasing, and will iterate through those slowly over time. There is no other significance to these files.

    by ajr0
  • They couldn't answer the question most on my mind: "We’ve reached out to Google to inquire about why a custom ROM created by volunteers is more resistant to industrial phone hacking than the official Pixel OS. We’ll update this article if Google has anything to say."
  • One idea is that the stock rom by Google may phone home even when locked. Perhaps with a malicious WiFi network, attackers can exploit the phone through a flaw in DNS or HTTP handling.

    If GrapheneOS skips contacting remote servers like that, they would not be vulnerable.

    It would be a story of Google prioritizing tracking over security.