Skip to content
  • Categories
  • Recent
  • Tags
  • Popular
  • World
  • Users
  • Groups
Skins
  • Light
  • Brite
  • Cerulean
  • Cosmo
  • Flatly
  • Journal
  • Litera
  • Lumen
  • Lux
  • Materia
  • Minty
  • Morph
  • Pulse
  • Sandstone
  • Simplex
  • Sketchy
  • Spacelab
  • United
  • Yeti
  • Zephyr
  • Dark
  • Cyborg
  • Darkly
  • Quartz
  • Slate
  • Solar
  • Superhero
  • Vapor

  • Default (Cyborg)
  • No Skin
Collapse
Brand Logo

CIRCLE WITH A DOT

  1. Home
  2. Uncategorized
  3. I still think that #GrapheneOS should not chain themselves to a single vendor but rather release actual proper specs for support.

I still think that #GrapheneOS should not chain themselves to a single vendor but rather release actual proper specs for support.

Scheduled Pinned Locked Moved Uncategorized
grapheneosromandroiddistromotorola
6 Posts 4 Posters 2 Views
  • Oldest to Newest
  • Newest to Oldest
  • Most Votes
Reply
  • Reply as topic
Log in to reply
This topic has been deleted. Only users with topic management privileges can see it.
  • kkarhan@infosec.spaceK This user is from outside of this forum
    kkarhan@infosec.spaceK This user is from outside of this forum
    kkarhan@infosec.space
    wrote last edited by
    #1

    I still think that #GrapheneOS should not chain themselves to a single vendor but rather release actual proper specs for support.

    • Otherwise we'll continue to see lazy ripoffs / rebadgings of their #ROM / #Android - #distro instead.

    I also doubt that #Motorola will release any affordable device with @GrapheneOS support.

    • And I'm not even talking about their ≤€250 retail budget phones they neglect and refuse to update, but rather anything in the ≤ €500 price bracket.
      • Pretty shure only ≥ €1k devices will get any chance of that, making it even more classist.

    And unlike @tails_live / @tails / #Tails dropping #32bit support amidst the fact that there are almost no #32bitOnly machines that can run it, I don't see the benefit of trusting into an unauditable blackbox of a "#SecurityChip".

    • I'm shure @stman could run entire semester-long classes at a university explaining why this blatant violation of #KerckhoffsPrinciple is irredeemably bad, but I digress…
    A kurt@chaos.socialK 2 Replies Last reply
    0
    • kkarhan@infosec.spaceK kkarhan@infosec.space

      I still think that #GrapheneOS should not chain themselves to a single vendor but rather release actual proper specs for support.

      • Otherwise we'll continue to see lazy ripoffs / rebadgings of their #ROM / #Android - #distro instead.

      I also doubt that #Motorola will release any affordable device with @GrapheneOS support.

      • And I'm not even talking about their ≤€250 retail budget phones they neglect and refuse to update, but rather anything in the ≤ €500 price bracket.
        • Pretty shure only ≥ €1k devices will get any chance of that, making it even more classist.

      And unlike @tails_live / @tails / #Tails dropping #32bit support amidst the fact that there are almost no #32bitOnly machines that can run it, I don't see the benefit of trusting into an unauditable blackbox of a "#SecurityChip".

      • I'm shure @stman could run entire semester-long classes at a university explaining why this blatant violation of #KerckhoffsPrinciple is irredeemably bad, but I digress…
      A This user is from outside of this forum
      A This user is from outside of this forum
      a53bdb@mastodon.social
      wrote last edited by
      #2

      @kkarhan @GrapheneOS @tails@fosstodon.org_live@venera.social @tails @stman Security chip is the most important part of Android security model. Without it, verified boot, anti brute force password and many features won’t work. Titan M2 is a variant of OpenTitan like Chrome is a variant of Chromium. It’s much more transparent than other security chips.

      kkarhan@infosec.spaceK stman@mastodon.socialS 2 Replies Last reply
      0
      • A a53bdb@mastodon.social

        @kkarhan @GrapheneOS @tails@fosstodon.org_live@venera.social @tails @stman Security chip is the most important part of Android security model. Without it, verified boot, anti brute force password and many features won’t work. Titan M2 is a variant of OpenTitan like Chrome is a variant of Chromium. It’s much more transparent than other security chips.

        kkarhan@infosec.spaceK This user is from outside of this forum
        kkarhan@infosec.spaceK This user is from outside of this forum
        kkarhan@infosec.space
        wrote last edited by
        #3

        @a53bdb @stman which makes @GrapheneOS's claims that they 'necessitate' it copletely pointless…

        • Also you can't audit the integrity of it down to the last transistor!
        1 Reply Last reply
        0
        • kkarhan@infosec.spaceK kkarhan@infosec.space

          I still think that #GrapheneOS should not chain themselves to a single vendor but rather release actual proper specs for support.

          • Otherwise we'll continue to see lazy ripoffs / rebadgings of their #ROM / #Android - #distro instead.

          I also doubt that #Motorola will release any affordable device with @GrapheneOS support.

          • And I'm not even talking about their ≤€250 retail budget phones they neglect and refuse to update, but rather anything in the ≤ €500 price bracket.
            • Pretty shure only ≥ €1k devices will get any chance of that, making it even more classist.

          And unlike @tails_live / @tails / #Tails dropping #32bit support amidst the fact that there are almost no #32bitOnly machines that can run it, I don't see the benefit of trusting into an unauditable blackbox of a "#SecurityChip".

          • I'm shure @stman could run entire semester-long classes at a university explaining why this blatant violation of #KerckhoffsPrinciple is irredeemably bad, but I digress…
          kurt@chaos.socialK This user is from outside of this forum
          kurt@chaos.socialK This user is from outside of this forum
          kurt@chaos.social
          wrote last edited by
          #4

          @kkarhan I think, the security chip does exactly, what kerkhoff tells us: keep the keys secret

          kkarhan@infosec.spaceK 1 Reply Last reply
          0
          • kurt@chaos.socialK kurt@chaos.social

            @kkarhan I think, the security chip does exactly, what kerkhoff tells us: keep the keys secret

            kkarhan@infosec.spaceK This user is from outside of this forum
            kkarhan@infosec.spaceK This user is from outside of this forum
            kkarhan@infosec.space
            wrote last edited by
            #5

            @Kurt It violates said principöle by being obscure on it's own and not fully opensource'd!

            • Just like #CensorBoot aka. #TPM it is thus not to be trusted!
            1 Reply Last reply
            0
            • A a53bdb@mastodon.social

              @kkarhan @GrapheneOS @tails@fosstodon.org_live@venera.social @tails @stman Security chip is the most important part of Android security model. Without it, verified boot, anti brute force password and many features won’t work. Titan M2 is a variant of OpenTitan like Chrome is a variant of Chromium. It’s much more transparent than other security chips.

              stman@mastodon.socialS This user is from outside of this forum
              stman@mastodon.socialS This user is from outside of this forum
              stman@mastodon.social
              wrote last edited by
              #6

              @a53bdb @kkarhan @GrapheneOS @tails Until we have "End-User verifiable free integrated circuits", all these tremendos efforts of GrapheneOS devs can be annihilated by just a single hardware backdoor in any IC composing those smartphones.

              And here I ask you the question : Will hackers start worrying about empowering end-users with the power to verify their ICs one day ?

              Ok, it's a lot of organizational work.

              But it is existential !

              1 Reply Last reply
              1
              0
              • R relay@relay.infosec.exchange shared this topic
              Reply
              • Reply as topic
              Log in to reply
              • Oldest to Newest
              • Newest to Oldest
              • Most Votes


              • Login

              • Login or register to search.
              • First post
                Last post
              0
              • Categories
              • Recent
              • Tags
              • Popular
              • World
              • Users
              • Groups