599
you are viewing a single comment's thread
view the rest of the comments
view the rest of the comments
this post was submitted on 03 Oct 2026
599 points (99.7% liked)
Technology
88627 readers
2936 users here now
This is a most excellent place for technology news and articles.
Our Rules
- Follow the lemmy.world rules.
- Only tech related news or articles.
- Be excellent to each other!
- Mod approved content bots can post up to 10 articles per day.
- Threads asking for personal tech support may be deleted.
- Politics threads may be removed.
- No memes allowed as posts, OK to post as comments.
- Only approved bots from the list below, this includes using AI responses and summaries. To ask if your bot can be added please contact a mod.
- Check for duplicates before posting, duplicates may be removed
- Accounts 7 days and younger will have their posts automatically removed.
Approved Bots
founded 3 years ago
MODERATORS
The companies who sell these bypass devices spend time on graphene too, don’t worry.
The price of iOS exploits would suggest Apple’s doing a pretty good job in this area.
I'm sure they do spend time on Graphene OS, but that's not the same as being successful in cracking it.
Most of these exploits involve side channel attacks which are much closer to the hardware. Graphene definitely does a lot more to make that difficult, but typically devices are getting pwned within a few months even with graphene.
Having graphene on relatively new hardware is a really good practice, but it obviously isn't a complete security posture on its own. Not having sensitive, compromising or incriminating stuff on your daily carry phone is much more important.
I remember one cybersec company got hit with an internal communications leak that suggested they could get into any GrapheneOS device before the Pixel 9, AFU or BFU. They were still having trouble with BFU Pixel 9. But this was a year or two ago.
Device wipe before capture/seizure seems to be the highest guarantee.
As someone with a Pixel 8 running Graphene OS, I'd love for you to cite the source so I could read it.
https://www.androidauthority.com/cellebrite-leak-google-pixel-grapheneos-security-3611794/
Appears I was partially misremembering, they were able to get into older phones on older security patches.
I wonder if they spend time on Linux mobile devices, considering how niche they are.
But then again, security through obscurity is not real security, and I'm not aware of any reasonable way to run something like QubesOS on a phone in any way that would be usable.
I'm sure they spend time on Linux in general, since it is the most common operating system (and includes Android, so even bigger). I doubt they spend much, if any, effort on the specific subset of systems that make a Linux phone different from another Linux device.
Smartphones had been vulnerable for pretty much it's entire existence, and most of time, while true software do play a role, it's been more about stuff such as bootloader exploits.
Sadly Linux phones on it's state are insecure by design.
They don't have to stay insecure by design. It just requires purpose-built hardware.