Y
HN Search
Hacker News Search
new
|
comments
|
top
|
jobs
strcat
searching PlanetScale…
1.
▲
2.
▲
3.
▲
4.
▲
5.
▲
6.
▲
19 ms
·
181.
▲
by
strcat
11mo ago
It's often possible to get through to people who are initially hostile. They were friendlier than a lot of the Free Software community on Mastodon and didn't even link to harassment content. They burned themselves out and stopped
182.
▲
by
strcat
11mo ago
We weren't given a chance to see what was being claimed and properly respond to it. Our response at the end of the article was to this prompt, which was in the first and only email we received, in English: > I am preparing an articl
183.
▲
by
strcat
11mo ago
The article misses the substantial privacy improvements made by GrapheneOS and heavily downplays the importance of security. There are widespread use of exploits, not only in targeted attacks. It also omits the fact that the other operating
184.
▲
by
strcat
11mo ago
> You can't attack Debian like this without providing a few examples. It's not specific to Debian. They're packaging a massive ecosystem of software nearly entirely not developed or significantly changed by Debian and are
185.
▲
by
strcat
11mo ago
Convincing people that the exploit protections are valuable and worth providing as even an opt-in feature let alone an enabled by default one is difficult. Google shipped the Pixel 8 with production quality MTE support at a hardware level i
186.
▲
by
strcat
11mo ago
Cellebrite and other companies can develop exploits using independent sets of bugs. Cellebrite is also not the only company developing exploits. These companies (or governments) don't have to wait until the bugs they use get patched or
187.
▲
by
strcat
11mo ago
Android and iOS both use filesystem-based disk encryption with fine-grained keys, not only a global encryption key. There's a subset of the OS data available before first unlock to have basic functionality available there. Three exampl
188.
▲
by
strcat
11mo ago
It's a statement directly based on the regularly updated Cellebrite Premium documentation from the past 2 years. At a bare minimum, the April 2024, July 2024 and February 2025 documentation was posted publicly and even that subset show
189.
▲
by
strcat
11mo ago
The stock OS doesn't use it for any of the kernel or most of userspace. It only uses it for specific processes where they're explicitly enabling it in that mode and apps explicitly opting into it. Nearly no apps are explicitly opt
190.
▲
by
strcat
11mo ago
No, that's not at all what was said. Pixel 7 is a fully supported device with Android 16 QPR1 available for it via the stock OS. /e/ is on Android 13 on the Pixel 7 without the kernel, driver and firmware updates released for
191.
▲
by
strcat
11mo ago
> I was arguing on the other axis. It's got good coverage of OS options, but the list of features is indistinguishable from someone saying "okay, this is what GOS does; how do others compare to each of its selling points?"
192.
▲
by
strcat
11mo ago
> This is not true for Debian, which is the upstream of PureOS. Lots of the software they provide has privacy invasive behavior and far more than that has poor privacy. > And yet, it has practically negligible number of malicious apps
193.
▲
by
strcat
11mo ago
Alarms work after reboot in the default system Clock app configuration. However, it does not work in all configurations since not everything is properly handled for the Clock app's Direct Boot mode. Google's Clock app works better
194.
▲
by
strcat
11mo ago
February 2025 documentation was posted by someone in that thread and a blog post was written by someone about it which was linked there. The initial link posted with the February 2025 documentation died and the blog post only focuses on And
195.
▲
by
strcat
11mo ago
That's not true. Cellebrite has working BFU and AFU exploits for recent iOS and usually catches up to the latest iOS versions and hardware in weeks or a couple months. They do not have working brute force support for the Pixel 2 /
196.
▲
by
strcat
11mo ago
No, that's wrong. You're basing your claims on outdated leaks of Cellebrite documentation showing they didn't support the most recent iOS version yet, which they did end up support weeks later. You can't simply point to
197.
▲
by
strcat
11mo ago
iOS 18.1 added a variant of the locked device auto-reboot feature used by GrapheneOS, but it has a hard-wired 72 hour timer instead of a default 18 hour timer that's configurable between 10 minutes and 72 hours. iOS doesn't have a
198.
▲
by
strcat
11mo ago
That's the standard Android behavior for the USB gadget mode, not something specific to LineageOS, and it does not mean USB is in a charging-only mode but rather than no USB gadget functionality such as file transfer (MTP) is active. I
199.
▲
by
strcat
11mo ago
That standard Android toggle doesn't turn off USB support at the OS level but rather controls the default USB gadget mode. USB gadget functionality is one part of the high level USB functionality. That doesn't block USB peripheral
200.
▲
by
strcat
11mo ago
That standard Android toggle doesn't turn off USB support at the OS level but rather controls the default USB gadget mode. USB gadget functionality is one part of the high level USB functionality. That doesn't block USB peripheral
201.
▲
by
strcat
11mo ago
No, that only changes the USB gadget mode. It doesn't disable USB peripheral support, USB protocol handling, etc. in the OS and doesn't disable USB at a hardware level. It doesn't protect against the vast majority of Linux ke
202.
▲
by
strcat
11mo ago
That's definitely not trivial and it's a small fraction of the security features GrapheneOS provides. https://news.ycombinator.com/item?id=45779157 explains several of the relevant features. Using hardware memory
203.
▲
by
strcat
11mo ago
GrapheneOS is an open source project which was started in 2014 by people with an existing history working on open source projects. It has existed for over 11 years. It resisted a takeover attempt by a company sponsoring it. It's entire
204.
▲
by
strcat
11mo ago
GrapheneOS provides massive security improvements over Android. You should read https://grapheneos.org/features#exploit-protection for an overview. Cellebrite quite clearly puts substantial effort into targeting GrapheneOS,
205.
▲
by
strcat
11mo ago
Userdebug builds of GrapheneOS with ADB root access are officially supported. We recommend setting ro.adb.secure=1 rather than making a standard userdebug build with always-on unauthenticated ADB if it's not solely for development. Mod
206.
▲
by
strcat
11mo ago
People can modify GrapheneOS however they want including making their own builds with the officially supported userdebug root support enabled. Open and free doesn't mean catering to power users with the official setup at the expense of
207.
▲
by
strcat
11mo ago
People have the freedom to modify GrapheneOS in any way they want and run it on their device instead of the official releases. Freedom doesn't mean GrapheneOS going out of the way to provide all kinds of power user with major downsides
208.
▲
by
strcat
11mo ago
> There are no malicious apps in GNU/Linux repositories. That's definitely not the case. There have been repeated cases of developers shipping malicious code which ended up in distribution package repositories. Defining malicio
209.
▲
by
strcat
11mo ago
APEX modules have their changes released as part of AOSP quarterly and yearly releases. There were also monthly releases with the new features distributed in the monthly mainline updates until recently. GrapheneOS is entirely capable of sig
210.
▲
by
strcat
1y ago
APEX modules are open source components of AOSP. See https://android.googlesource.com/platform/packages/modules/ . Those modules include a lot of other AOSP code beyond what's directly in packages/mo
More ›