• unexposedhazard@discuss.tchncs.de
    link
    fedilink
    English
    arrow-up
    52
    ·
    edit-2
    1 day ago

    I honestly feel like the goal with this delayed release and app signing control is to make custom roms less attractive and more vulnerable to law enforcement zero days.

      • 0_o7@lemmy.dbzer0.com
        link
        fedilink
        English
        arrow-up
        3
        arrow-down
        2
        ·
        1 day ago

        They were always, and I mean always been law-enforcement friendly tho. What are you getting at?

        Didn’t you see the leaked cellebrites slides. Pixels up until 9 were exploitable. Why do you think they hire engineers from places who sell these exploits to law enforcement?

        It’s a circular economy where both have a plausible deniability. Google gets to claims they are unaware of the bugs, Government gets to claim they used an “exploit” from a middleman.

        https://arstechnica.com/gadgets/2025/10/leaker-reveals-which-pixels-are-vulnerable-to-cellebrite-phone-hacking/

        • AmbiguousProps@lemmy.today
          link
          fedilink
          English
          arrow-up
          4
          ·
          edit-2
          22 hours ago

          Well, yes, but that is not exclusive to Pixels, and in fact, most phones (other than the latest iPhones) are more vulnerable. Pixels, especially the latest devices, have the best hardware security features of any Android phone (unfortunately). You’re focused on Pixel, but that’s only because of the recent leaks which specifically focused on Pixel because of their breaching difficulty. Here’s the full matrix from last year (which hasn’t leaked as recently):

          https://discuss.grapheneos.org/d/14344-cellebrite-premium-july-2024-documentation

          GrapheneOS, even now, is not vulnerable for several reasons, most of which tie into the hardware features of the Pixel. There’s a reason Graphene only works on Pixel.

          All I’m saying is that it’s entirely misleading to imply that only Pixels are vulnerable. This is not the case, even for iPhones.

          I’m also not sure why you seem to be trying to say I disagree on the fact that Google is happy to leave vulnerabilities wide open, when that is exactly what I said in my original comment. Their new release schedule allows them to leave these vulnerabilities open for an even longer time, making Cellebrite’s job easier.

  • BeerEnjoyer@lemmy.zip
    link
    fedilink
    English
    arrow-up
    23
    ·
    1 day ago

    This was supposed to happen in “a few weeks” from September 10th, btw. Meanwhile QPR2 is almost there and we just get QPR1. Can’t wait to see QPR2 source code by the summer of 2026!

  • arcterus@piefed.blahaj.zone
    link
    fedilink
    English
    arrow-up
    31
    ·
    1 day ago

    Fucking finally. Also from a linked article about their apparent Android PC project:

    Osterloh touched upon Google’s efforts to bring its AI stack to PCs. “This is another way we can leverage all of the great work we’re doing together on our AI stack, our full stack, bringing Gemini models, bringing the assistant, bringing all of our applications and developer community into the PC domain. And I think this is another way in which Android is gonna be able to serve everyone in every computing category.”

    No one gives a shit about your AI crap, just stop ruining AOSP.