154 karma · joined March 26, 2021
Interests: AI/ML, Cybersecurity, Hacking, Hardware, Open Source, Privacy, Programming, Research, Technology, UI/UX Design, Web Development
---
I haven't found a desktop operating system that ticks most of the boxes, especially security and privacy. The only OS that ticks all the boxes is GrapheneOS, but it's not really a desktop OS. That's why I'm so excited about these updates, and why I wish there was either a good keyboard/trackpad case for the Google Pixel Tablet running GrapheneOS, or someone would make a laptop that had the necessary requirements to support GrapheneOS.
I code on my work laptop, and if I really wanted to, I could probably SSH or VNC into a Linux box to code on GrapheneOS. There is also pKVM, which will probably make it easy to run Linux VMs on GrapheneOS at some point in the future.
Once the battery runs out completely, then you can be sure verified boot is helping you out. I'm sure there are now other mechanisms that fixed the example of faking the boot process I wrote about earlier.
For example, this makes malware persistence much more difficult, as verified boot checks for integrity at every boot and reverses any unsigned changes.
Persistence on iOS and Android is very difficult. As an example, at least on iOS, threat actors have sometimes failed to achieve persistence, so they hijack the shutdown process and simply fake shutdown by animating the shutdown flow. The user thinks they've shut down the phone, but in reality the device was never shut down and never went through the verified boot process. However, since Steve Jobs decided iOS never needs a manual reboot, gaining persistence may not even be necessary, because people don't reboot their iPhones.
I used an iPhone a few years ago and when setting it up, I made sure to turn off all iCloud stuff. When it was time to get a new phone, I noticed all my pictures were in iCloud.
I also did not like how hard it was to try and keep Bluetooth and Wifi turned off. Regularly it would nag me to connect to an open Wifi when I was sure I switched Wifi off completely. Turns out iOS re-enables both Wifi and Bluetooth after OS updates and you can't completely switch them off from the quick settings. If users privacy was so important, wouldn't you want to make sure all that stuff would not happen?
Also, it's good practice to reboot your phone one in a while, so why isn't there a reboot option in iOS?
Compared to any other mobile OS, there is no compromise software wise on GOS.
I can't thank you enough Daniel for your work on AOSP and GOS, and all the other work you've done around security and privacy.
[1] https://www.corellium.com/ [2] https://security.apple.com/research-device/
Apple has decided that iOS should only accept downloading OS updates over wifi. In my country, for example, people don't really set up wifi at home anymore because basically everyone has unlimited cellular data. So they don't need to connect to any wifi at all. All the iOS update statistics seem to come from the US, where everyone relies on wifi.
It seems that on some level, iOS suffers from the same update problem as Android, but only because Apple decided to do so for no reason. Not everyone lives in the US.
The linked source has a lot of stuff that is done "in the future" and basically all of those "in the future" suggestions, are inferior to what AOSP has had for years.
The document lists some of the drawbacks of Librem 5, such as the use of memory-unsafe languages, and then blames Android for also relying on the same memory-unsafe languages and even some Android-specific components written in memory-unsafe languages. The fact is that Android has tons of mitigations specifically for this problem, which Librem 5 completely lacks. They're not comparable in that way. Librem 5 basically exposes the entire Linux kernel attack surface, whereas Android has multiple layers of protection between userspace and the Linux kernel. Apps written in memory safe language, proper app sandboxes, hardened memory allocator, extremely strict SELinux policies, CFI, PAC, ShadowCallStack, etc.
The only nice thing Librem 5 has, are the killswitches, but do those really matter at this point?
Proton is fine, but their Charity Fundraiser is awesome: https://proton.me/blog/2022-lifetime-account-charity-fundrai...
One can only wonder what these alternatives do when they claim to be minimal and fast and worse, private. Can there really be privacy without security?