GitHub - cawilliamson/treble_graphiteos
github.com
external-link
Contribute to cawilliamson/treble_graphiteos development by creating an account on GitHub.
CorrectAlias
link
fedilink
English
17h

I saw it already, but those hardware security features also secure the features you mention there. The other features were developed with the hardware security features in mind. Again, without secure hardware, it’s possible for your software to be modified and no longer secure. That’s the broken security model I keep mentioning.

While it could definitely be more secure than other ROMs, security was never tested without the hardware features and thus it could also expose you to attacks because of that. Worse, it could make you assume that you’re secure when you’re really not.

An excellent example is Cerberos. GrapheneOS is able to completely block attacks from Cerberos by disabling the USB port data lanes entirely, something that most (if not all non Pixel phones) are unable to do. Cerberos uses many zero day vectors to break in though the data lanes, and in this case you likely would not be able to block the attack. They’d be able to dump your phone contents and then much of the software security features wouldn’t matter.

Arthur Besse
creator
link
fedilink
English
16h

Should the world just throw away the billions of non-Pixel devices in use today?

And/or should everyone just give up on improving security at all for the vast majority of phone users who cannot afford Pixels, since they can’t ever be as secure as a Pixel?

@[email protected]
link
fedilink
English
24h

Should the world just throw away the billions of non-Pixel devices in use today?

Why are you acting like GrapheneOS is the only custom ROM available? There are other GSIs and ROMs that non-Pixel users can use to keep their older phones going.

CorrectAlias
link
fedilink
English
4
edit-2
6h

I didn’t say that they should be thrown away? I’m not sure where that came from.

I said that I would rather use something else that was designed without the hardware security features in mind. It’s all about your personal threat model, and mine does not align with this fork of Graphene. I’m either going to use something like Lineage which has at least been tested from a security standpoint (and does not have possible zero days because of patch working a ROM designed with specific hardware features not available on my device) or I’m going to get a used pixel and run Graphene. Even Calyx would be preferred to this once they start up development again.

What’s with the hostility?

dustycups
link
fedilink
English
14h

I think they are frustrated at repeating themselves, as I’m sure you are.
I tend to agree that, even though the hardware security isn’t there, GrapheneOS has some good features that would make it an alternative for these devices. If your threat model doesn’t include eg: physical access to the device then it still has benefits.

Create a post

DROID DOES

Welcome to the Android community on Lemmy. Here you can participate in amazing discussions and events relating to all things Android.

The rules for posting and commenting, besides the rules defined here for lemmy.world, are as follows:

Rules


1. All posts must be relevant to Android devices/operating system.


2. Posts cannot be illegal or NSFW material.


3. No spam, self promotion, or upvote farming. Sources engaging in these behavior will be added to the Blacklist.


4. Non-whitelisted bots will be banned.


5. Engage respectfully: Harassment, flamebaiting, bad faith engagement, or agenda posting will result in your posts being removed. Excessive violations will result in temporary or permanent ban, depending on severity.


6. Memes are not allowed to be posts, but are allowed in the comments.


7. Posts from clickbait sources are heavily discouraged. Please de-clickbait titles if it needs to be submitted.


8. Submission statements of any length composed of your own thoughts inside the post text field are mandatory for any microblog posts, and are optional but recommended for article/image/video posts.


Community Resources:


  • 1 user online
  • 33 users / day
  • 47 users / week
  • 456 users / month
  • 1.17K users / 6 months
  • 1 subscriber
  • 2.27K Posts
  • 40.2K Comments
  • Modlog