3 ms·
Hopefully, this will finally lead to a shift in thinking so that security practices like those used in GrapheneOS become more widespread in the future. Most sof
by RandomGerm4n 6mo ago
Hopefully, this will finally lead to a shift in thinking so that security practices like those used in GrapheneOS become more widespread in the future. Most software developers simply patch security vulnerabilities as soon as they become aware of them rather than taking preventive measures where possible. Finding an exploit that works in Vanadium on GrapheneOS is significantly harder than on standard Android running Chrome.
There are now projects in the desktop space such as Secureblue which aim to adopt security practices similar to those of GrapheneOS. They have Trivalent which is inspired by Vanadium and applications use the hardened_malloc familiar from GrapheneOS by default.
- jjav 6mo ago> Hopefully, this will finally lead to a shift in thinking so that security practices like those used in GrapheneOS become more widespread in the future. Most software developers simply patch security vulnerabilities as soon as they become aware of them rather than taking preventive measures where possible. Working in this space, I'm worried the future is even more reactive than today. Today I can get teams to review for security the architecture before implementing, and to review the implementation for security before shipping. As teams move (more specifically, are forced to move) to vibe coding the whole thing, nobody knows what the design is or what the implementation looks like. Vibe all the way because the CEO says so or you're fired. This means the only place to catch vulnerabilities becomes after the fact, which is usually too late.