24 ms·
Doesn't GrapheneOS only support Google Phones? Do we know everything that's running on a Pixel? At a minimum there's an unknown Qualcomm RTOS running the base
by cptskippy 2y ago
Doesn't GrapheneOS only support Google Phones? Do we know everything that's running on a Pixel? At a minimum there's an unknown Qualcomm RTOS running the baseband.
- grayhatter 2y agoGraphineOS only target's phones with better than average hardware security, yes and you think the Qualcomm RTOS can do what exactly? > Do we know everything that's running on a Pixel? did you mean hardware, or software?
- nehal3m 2y ago>and you think the Qualcomm RTOS can do what exactly? Well that's the point, it's a black box so there's no telling what it can and can't do. There's what Qualcomm says it can do, and then there's what it can do.
- grayhatter 2y agoThen that's a really weak point. There's a lot of things we know it can't do. It can't break the encryption between software, and remote servers. It also can't cause the phone to levitate. It also can't recharge my battery. As a rule, I don't worry unlikely hypotheticals, because doing so is a needless denial of service on my brain. Saying it's a blackbox is true, but that doesn't mean you get to invent random things to worry about, without direct evidence it's connected to the specific device we're discussing. But do think I should at least try to meet you half way, so maybe I can preempt a few things that used to be true or possible. The baseband also can't install software into my android OS. It also can't directly read memory from my phone. It can't directly control my phone's bootup. These are things poorly designed phones used to be able to do, that aren't possible on the Pixel line of hardware because it was designed to prevent them. That's why GraphineOS targets the pixel line. Because it's hardware is designed in a way to enable a secure device.
- nehal3m 2y ago>Saying it's a blackbox is true, but that doesn't mean you get to invent random things to worry about, without direct evidence it's connected to the specific device we're discussing. True, but the corollary is that you also can't say it's not doing certain things. Just because you currently don't have evidence of something happening does not rule out the possibility, but I must admit I am ignorant about the specifics of how the Pixel's RTOS is implemented. So I'm genuinely inquiring: Could it be sending your GPS location to some entity without notifying the GPOS?
- grayhatter 2y ago> So I'm genuinely inquiring: Could it be sending your GPS location to some entity without notifying the GPOS? With very low confidence, I believe for chips that put GPS on the baseband, yes it can because that's required for E911. (I don't know what the pixel line does) Can it then transmit that location using the baseband without you being able to tell? I would assume so, and that's a case where it's safe to assume it can. Unfortunately, that doesn't matter much. Your location is also trivially known by your ISP by triangulating connection strength. Often this can be more accurate than GPS in many real cases. The threat/risk that's able to compromise the baseband SoC, is more easily able to compromise your ISP. And thus the phone simply existing is a risk to location privacy, given a perfectly secure ideal baseband SoC. Can that be used to uniquely identify you, and correlate it with your other actions. That's not really a question I'm prepared to answer in a HN comment (because I have to draw that line somewhere for my own limited sanity), so.... specifically yes, but generally, no. That is to say, it is possible given sufficient resources. But it's non-trivial to do in bulk. And there are many many easier and cheaper ways, so https://xkcd.com/538/ https://xkcd.com/538/ applies here too.
- cptskippy 2y ago> Qualcomm RTOS can do what exactly? The RTOS could be used to leak your location, the fact that you're using a VPN, any nonVPN traffic, and call traffic. FWIW, I was mistaken and Google uses Samsung radios rather than Qualcomm. Graphine OS runs in the Normal Zone on an ARM SoC while running Trusty OS in the TEE. In order for an App, or Graphine OS to interact with certain hardware it must use the Trusty Lib and Trusty Driver APIs into the TEE. The entire composition and operation of the Trusty OS operates in the "Trust me bro" space and Google's entire business model is built around spying on users. So forgive me if I'm a little skeptical that Graphine OS.
- grayhatter 2y agoGoogle's business model is selling ads, all the data collection is so they can charge more for the ads they sell. The more you trust the platform, the more info you'll willingly give to Google, the more they can charge for ads. The more you trust your phone, the more you'll use your phone, the more chances Google has to collect information. They don't need to directly "spy" on you using means outside the normal data collection where you give them data. Thus, while I agree the "just trust me bro" attitude is borderline incompetence when it comes to security. I'm unconvinced that Google would take the risk of attempting to spy on anyone out of band. > The RTOS could be used to leak your location, the fact that you're using a VPN, any nonVPN traffic, and call traffic. Yes, it could... so can the default software on android, and so can your ISP (DPI is shockingly powerful). But, what's the risk there? How does knowing the ratio of traffic I send and receive being VPN, or TLS encrypted expose me to additional risk? > So forgive me if I'm a little skeptical that Graphine OS. I haven't looked in a long time so my memory is completely gone, but does GraphineOS not build their own Trusty OS image? https://android-review.googlesource.com/admin/repos/q/filter:trusty https://android-review.googlesource.com/admin/repos/q/filter... What am I missing from why GraphineOS can't be trusted?
- cptskippy 2y agoAfaik, Trusty OS is closed source.