3 ms·
GrapheneOS releases patches very quickly, often even faster than OEMs do. But patches are only useful for fixing individual known vulnerabilities. GrapheneOS ad
by Andromxda 11mo ago
GrapheneOS releases patches very quickly, often even faster than OEMs do. But patches are only useful for fixing individual known vulnerabilities. GrapheneOS additionally focuses on defending against whole classes of vulnerabilities. [1] For example, in addition to fixing memory corruption bugs in individual system components, GrapheneOS has deployed memory protections for the entire OS in the form of hardened_malloc [2] and by enabling the ARM memory tagging extension for the kernel, most system processes (with very few exceptions) and all user-installed apps.
The honeypot theories don't make sense, since GrapheneOS is fully open source, and very transparent about developers, funding, infrastructure, and other internal stuff.
[1] https://grapheneos.org/features#exploit-protection https://grapheneos.org/features#exploit-protection
[2] https://github.com/GrapheneOS/hardened_malloc https://github.com/GrapheneOS/hardened_malloc
- Yokolos 11mo agoReminds me of that one case a few weeks back where Graphene wasn't allowed to release a patch because Google wasn't planning on releasing a patch for it for a few more months.
- linux_modder 11mo agoGrapheneOS has a security preview release channel that is opt-in but includes patches from these embargoed vulns already. Again, it's opt-in but for those with a higher threat model use-case it's nice to have.
- largbae 11mo agoWould this not defeat the purpose of responsible disclosure? As a bad actor I could learn of secret vulnerabilities from this channel.
- udev4096 11mo agoYou have google to blame. GrapheneOS tried very hard to make sure they have those security patches as google delays publishing the source tree and it's only available to OEMs
- subscribed 11mo agoThese patches are available to all vendors who chose not to protect their users yet. Releasing binary patches is allowed, this is why GOS have added the security preview channel.
- MYEUHD 11mo ago> GrapheneOS is fully open source Not really. There is a bunch of proprietary firmware running on those phones, which can be exploited with or without the help of the manufacturer.
- rollcat 11mo agoFirmware is not OS. Your machine is a distributed system. The firmware is what runs a specific node. Yes they usually have DMA, shared busses, etc. That's an implementation detail.
- fragmede 11mo agoAn implementation detail where TLAs could theoretically get root remotely? Seems like a bit more than a detail to be glossed over.
- rollcat 11mo agoFree firmware can have a security issue and root your device. A working IOMMU will stop both free- and non-feee firmware from rooting your device. These concepts are orthogonal.
- gf000 11mo agoShow me any device on earth that can run a browser that has no proprietary code whatsoever (including hardware) on it?
- SXX 11mo agoAFAIK older Talos Secure Workstation with Power CPUs was it. Everything open including CPU firmware. Not sure about smartphones though - they mostly struggle with a fact there are no truly open source baseband.
- Andromxda 11mo agoThere is no smartphone fully powered by open firmware. Also keep in mind that the hardware itself is proprietary too.