Trying to deploy WPA3 on my home network
gist.github.com
gist.github.com
They probably do want to be getting the latest security patches to the kernel and base OS.
Citation: https://twitter.com/DanielMicay/status/1058103333414522880
I assumed Android ROMs carry a fully fledged distribution, including the kernel and firmware. Sure, the latter might be out of date.
When I tried digging into the question "where does this so-called open source come from", I stumbled upon Kernels that basically have one commit adding the whole blob.
Is the ROM merely the application software built for a target kernel (which is persistent on the device)?
I've hacked around with Kernel modules on Android before, but miss the big picture in that regard.
Edit: especially the new update infrastructure (treble?), Does it change anything here?
The device kernel is a fork of https://git.kernel.org/pub/scm/linux/kernel/git/torvalds/lin... or more accurately https://source.android.com/devices/architecture/kernel/andro... at the end of the day. The "whole thing as one commit" is just people not caring enough to maintain source history.
Treble seems to mean that the software can be updated separately from the drivers and the firmware - https://www.androidauthority.com/project-treble-818225/, it could actually make things worse in terms of out of date drivers and firmware.
So it's not just about it not being secure going forwards. It and most other similar age handsets are insecure because a fix has never been released for the older chips.
[1] https://googleprojectzero.blogspot.com/2017/04/over-air-expl...
Does anyone know anything about the GSMK Cryptophone 500? It's appears to be a modified Galaxy S3 with a heavily custom ROM and can double as an IMSI catcher. I wonder. Did they RE the baseband or replace it with their own?
https://www.cryptophone.de/en/products/mobile/cp500/
Interesting.
I am aware of the eMMC issues. Not to mention a phone from those days is slower then current phones, although I don't know much that matters with the custom ROM they use.
Yes, the drivers are ancient, and probably have a ton of security vulnerabilities. Has the general situation improved in recent years? To me it seems that hardware vendors generally don't care about these issues at all. Which phone would you say has secure drivers?
It's a tradeoff - new phones are more secure, but they're also secured against you, e.g. if I OEM unlock my Galaxy Note 9, a bit is set permemnantly that could be used to determine whether the phone gets a warranty repair.
To get back on track, you may want to have a look to see if the "board support package" is still supported. You're well out of vendor support and it looks like the last commit to https://github.com/LineageOS/android_kernel_samsung_smdk4210... was 2013.
The gold standard would be a phone that runs a very-close or actually mainline Linux kernel, but I don't think we're there yet.
Nexus devices were fantastic, but they're gone now. Pixel, I guess, but I was scared off after the 5X and 6P hardware issues.
Don't use SAE (which is, indeed, an instantiation of Dragonfly). I have a strong suspicion that the way it is used, there will be a practical attack.
Basically, take the original password/secret, derive two secrets A and B, run SAE with A as the secret, get a session key K, then use hash(K|B) as the actual session key.
If they don't have anything like that, I wouldn't be surprised if real-world implementations end up being less secure than up-to-date WPA2.
Then another obvious but naive response is "then your security is no better than WPA2 anyway" but hopefully it's clear why that isn't the case in the real world.