solrize

joined 3 years ago
[–] solrize@lemmy.ml 10 points 2 days ago (1 children)

What are they going to do about upstreams that use it? Like the Linux kernel for example.

[–] solrize@lemmy.ml 1 points 4 days ago (1 children)

Source for this?

This is a start: https://grapheneos.social/@GrapheneOS/117140352254892456

The obsession with security chips is what allows Pixels and iPhones to be the most secure devices on the planet.

I remember the govt trying to muscle Apple into unlocking someone's iphone, til they suddenly stopped because they found Cellebrite could unlock it instead. There have been several new iphone generations since then but I haven't heard about govt muscling anytime recently. So I have to infer they can still unlock iphones. As for Pixels, this is in Dutch but very recent: https://www.omroepbrabant.nl/nieuws/6023856/drievoudige-moord-in-oosterhout-telefoon-van-verdachte-gekraakt

Machine translation of main paragraphs:

The Netherlands Forensic Institute (NFI) has unlocked the Google Pixel phone belonging to 29-year-old Veronica K., according to the prosecutor. "A large number of images of weapons and stacks of cash were found on her phone. There are also a large number of chat messages that can now be read." K. is alleged to have facilitated the murder by supporting the perpetrators.

The prosecutor expects to receive the first results from the NFI on Thursday. During the hearing, the prosecutor also said there is good reason to hope that the NFI will be able to unlock the Google Pixel phones belonging to the other two suspects as well.

So I think you're putting too much faith in this stuff. I will ask my crypto homies if they have any recent info about phone attacks though.

More relevantly, most secure devices AGAINST WHAT? You're talking about a locked phone attack which is the absolute least of most users' worries. The phone is so insecure in everyday use that the border patrol is near irrelevant. Plus users including paranoids like me don't have any opsec to speak of. When was the last time you crossed a border with an Android phone anyway? I don't think I've ever done that. Like most people I don't leave the country that often. Last time I did was before I switched to Android, IIRC. I might have had an analog or 2G flip phone or something. If I travel somewhere again it's not that big a deal to leave my Android phone at home, as I mentioned before.

Even in the border patrol picture, Graphene and TPM won't protect you from what used to be called rubber-hose cryptanalysis (xkcd.com/538). They're defending from the wrong threat.

Look, I understand the advantages of crypto hardware. I've programmed it and written simulators for it. But, the way to really keep cryptography in people's hands is to make it not require special hardware. Thus I'm skeptical that the government hates Graphene, but it really did hate PGP back in the day.

If I get to add new hardware to phones, TPM would be on my list but not at the top. First might be something like POCSAG (plus build out the pager network again) so you can receive text messages without transmitting anything or revealing your location. Second, third, etc. would be in a similar vein.

[–] solrize@lemmy.ml 1 points 4 days ago* (last edited 4 days ago) (3 children)

That's all very nice but not many of us are willing to buy a $1000 phone (or an obsolete Pixel) to get Graphene. They soon won't be able to run it on new Pixels, and also the stuff about AOSP updates stops mattering since AOSP itself is nearly dead. The obsession with security chips (fighting the seized phone attack while comparatively ignoring much more relevant threats) is another misplaced priority. It's the old notion of "fence post security", putting a 100 foot fence post in the middle of the desert expecting the attacker to try to climb over it instead of going around it.^1^ Andd again, I'm amused at the idea of the US and Chinese governments allowing a Motorola (Lenovo) Graphene to be sold if it's really that secure.

We need a de-googled Android fork (maybe Lineage is that) on mass market phones using the hardware that those phones have. Otherwise we're acquiescing to the notion that Elon Musk deserves more privacy than Joe Schmoe when it should be the other way around.

^1^ hpmor.com chapter 115.

[–] solrize@lemmy.ml 2 points 4 days ago (5 children)

You believe GrapheneOS is not able protect against Motorola?

Um yes? How do you protect against someone who literally controls the hardware?

[–] solrize@lemmy.ml 2 points 1 week ago* (last edited 1 week ago) (1 children)

I get the impression that most kindle books are sold (well rented) by subscription, i.e. all you can read for a fixed monthly fee, so a subscriber downloading an AI book or other crap doesn't pay any increment to do so. IDK how the revenues are divided up.

[–] solrize@lemmy.ml 5 points 1 week ago

I'll take The Noisy Decisions RMS and Linus Torvalds Made That Devastated Microsoft for all the marbles, Alex.

[–] solrize@lemmy.ml 33 points 2 weeks ago (1 children)

we assumed that having “visual” cues was further out because AI at the time wasn’t up to the task.

For just terrain recognition, the US has had that since before there was GPS. Since the 1950s even.

https://en.wikipedia.org/wiki/TERCOM

[–] solrize@lemmy.ml 1 points 2 weeks ago

Unfortunately besides chips, another huge input to this AI crap is electric power, which is coming mostly from expanding fossil fuel consumption and thus increasing planetary heating. Economists' intersecting curves are of no help with that.

[–] solrize@lemmy.ml 4 points 2 weeks ago

Some of the shortages have been due to supply interruptions, like the hard drive factory getting flooded, or similarly with a DRAM factory catching on fire. I don't know what happened after the Chia lunacy (Chia was a crypto currency that consumed vast amounts of SSD space and destroyed the SSD's through extreme write wear) but prices did normalize after a while. I know that Chia was the final straw that got Hetzner to ban crypto mining on its hardware outright. Previously, it was forbidden on VPS's but allowed on dedicated servers. Anyway it caused a temporary shortage of both SSD and hard drives.

view more: next ›