HNHacker News
TopNewBestAskShowJobs

tholdem

154 karma · joined March 26, 2021

meet.hn/city/fi-Helsinki

Interests: AI/ML, Cybersecurity, Hacking, Hardware, Open Source, Privacy, Programming, Research, Technology, UI/UX Design, Web Development

---

submissionscomments
tholdem··on Desktop Windowing on Android Tablets
I am not talking about Google's Android. I am talking about GrapheneOS and in Google's blog post they mention that this is coming to AOSP.
tholdem··on Desktop Windowing on Android Tablets
Probably over 90% of what I use my personal laptop for is browsing the web, watching videos, listening to music, and writing notes. In a general purpose OS, I value security above all else. Privacy is a close second, and of course stability, ease of use, resource lightness, and application support are also important factors.

I haven't found a desktop operating system that ticks most of the boxes, especially security and privacy. The only OS that ticks all the boxes is GrapheneOS, but it's not really a desktop OS. That's why I'm so excited about these updates, and why I wish there was either a good keyboard/trackpad case for the Google Pixel Tablet running GrapheneOS, or someone would make a laptop that had the necessary requirements to support GrapheneOS.

I code on my work laptop, and if I really wanted to, I could probably SSH or VNC into a Linux box to code on GrapheneOS. There is also pKVM, which will probably make it easy to run Linux VMs on GrapheneOS at some point in the future.

tholdem··on A Backstage Pass to the Production of the MoonSwatch and Scuba Fifty Fathoms
Can you post the eink smartwatch you got? I miss my Pebble and haven't found any good alternatives. I just want to see the time and notifications easily.
tholdem··on Canarytokens: Honeypot for critical credentials, get notified when they are used (2015)
All adversaries are just humans and humans do stupid mistakes. Opsec and maintaining it is really hard. Just one mistake is enough. It's astounding to read about the really stupid mistakes adversaries do to get caught. But there is of course also the bias that we only read about the mistakes of ones that do get caught.
tholdem··on Canarytokens: Honeypot for critical credentials, get notified when they are used (2015)
You can check by creating a Word Canary and check what's inside. I renamed it from .docx to .zip and it seems there is an external image referenced in the footer. I'm not sure how modern Word handles external images, but I believe you have to approve the download of remote content when you open it nowadays.
tholdem··on Sandboxing all the things with Flatpak and BubbleBox
One thing that steered me away from QubesOS was that the templates used for all VMs were not hardened at all, instead, the Qubes Fedora template for example were less secure than a normal Fedora install. The template uses passwordless sudo and SELinux is completely removed. Security is about layers and the default templates are lacking in that sense. I want to make initial compromise as hard as possible. For QubesOS reasoning for not needing hardened templates to make sense, I would need to have a completely separate AppVM for each application and I don't think QubesOS was meant to be used like that.
tholdem··on Asus refunds Zenfone buyer for failing to provide bootloader unlock tools
I'll judge a tech project on it's technological merits and developers by their technical skills. GrapheneOS is by far the superior choice.
tholdem··on Show HN: Retriever – Securely share secrets over the internet
I don't see how privnote.com is the same as this. Privnote seems to use a database and the links themselves should be treated as secrets as anyone with the link can read the note.
tholdem··on Tell HN: iCloud Password Sync turns on by itself on iOS 17
I mentioned China because there Apple's e2e encryption does not apply.
tholdem··on Tell HN: iCloud Password Sync turns on by itself on iOS 17
Sorry my reply was poorly written. Like with anything, there will be vulnerabilities and techniques that allow for verified boot bypass, which most are not trivial and which need to be fixed, but that does not mean verified boot isn't valuable and working. It means extra cost and work for threat actors and the example was just how it was once done, by not attacking verified boot, but the process before it. Maybe because true persistence was too hard to achieve at the moment, thanks to properly implemented verified boot.

Once the battery runs out completely, then you can be sure verified boot is helping you out. I'm sure there are now other mechanisms that fixed the example of faking the boot process I wrote about earlier.

tholdem··on Tell HN: iCloud Password Sync turns on by itself on iOS 17
Modern smartphone security relies on verified boot which cryptographically verifies various components in the boot process all the way to the kernel and beyond to make sure they have not been tampered with. This not only protects against physical attack vectors, but also remote as it can detect and prevent malicious modifications to the firmware and OS.

For example, this makes malware persistence much more difficult, as verified boot checks for integrity at every boot and reverses any unsigned changes.

Persistence on iOS and Android is very difficult. As an example, at least on iOS, threat actors have sometimes failed to achieve persistence, so they hijack the shutdown process and simply fake shutdown by animating the shutdown flow. The user thinks they've shut down the phone, but in reality the device was never shut down and never went through the verified boot process. However, since Steve Jobs decided iOS never needs a manual reboot, gaining persistence may not even be necessary, because people don't reboot their iPhones.

tholdem··on Secureblue: Hardened Immutable Fedora Images
This is awesome. Hardened_malloc and JITless Chromium OOTB. It's hard to find hardened desktop linux distro, this might be it.
tholdem··on Tell HN: iCloud Password Sync turns on by itself on iOS 17
Imagine being in China and finding this out after an update.

I used an iPhone a few years ago and when setting it up, I made sure to turn off all iCloud stuff. When it was time to get a new phone, I noticed all my pictures were in iCloud.

I also did not like how hard it was to try and keep Bluetooth and Wifi turned off. Regularly it would nag me to connect to an open Wifi when I was sure I switched Wifi off completely. Turns out iOS re-enables both Wifi and Bluetooth after OS updates and you can't completely switch them off from the quick settings. If users privacy was so important, wouldn't you want to make sure all that stuff would not happen?

Also, it's good practice to reboot your phone one in a while, so why isn't there a reboot option in iOS?

tholdem··on Orion Browser by Kagi
Not sure what you mean with "lighter", but the reason some browsers feel heavier is the security features that introduce a performance penalty or take up more resources, like jitless mode and process isolation for example. Firefox is not a secure web browser.
tholdem··on Escaping Duopoly: Best 5 Linux Smartphones Without Performance Security Excuses
I'd be interested to hear more about the security/privacy overstatements.
tholdem··on Pixel 7 WiFi does not work in certain countries
Lineageos is also less stable than GrapheneOS and of course far less secure than GOS. It’s also less secure than stock Pixel OS or any other Android OS that supports verified boot.
tholdem··on Fairphone 4 with /e/OS by Murena now available at fairphone.com
Is sad how much misinformation there is about GrapheneOS. If you can, just try it. Their sandboxed play services implementation is far superior to any other solution.

Compared to any other mobile OS, there is no compromise software wise on GOS.

tholdem··on 0-days exploited by commercial surveillance vendor in Egypt
Agree. Not long ago, Apple used to sue people reporting vulnerabilities to them. Imagine punishing people doing free work for you. Not a good look.
tholdem··on Go to Chrome://settings/adPrivacy to turn off the spyware that in Chrome
I believe madars meant app/process sandboxing which is different to what I think you mean with Firefox containers. Chrome is safer and has stronger sandboxing and exploit mitigations.
tholdem··on Daniel Micay publicly steps down from GrapheneOS
I strongly believe that GrapheneOS is one of the most important projects at the moment for several reasons. Nowadays it's almost impossible to live without a smartphone, it's one of the most used pieces of hardware that people use all day, and there are simply no other alternatives to GOS.

I can't thank you enough Daniel for your work on AOSP and GOS, and all the other work you've done around security and privacy.

tholdem··on NSO developed 3 new ways to hack iPhones, Citizen Lab says
Apple has been kind of forced into the open source model by tools like Corellium[1] and some source code leaks. This means that the black box advantage that iOS has had is no longer as significant. Apple's move with the Security Research Device Program[2] proves this point. They wouldn't be offering it if they didn't think it was a serious problem for them.

[1] https://www.corellium.com/ [2] https://security.apple.com/research-device/

tholdem··on NSO developed 3 new ways to hack iPhones, Citizen Lab says
I have been wondering what's the actual status of iOS updates outside of the US, or in countries where nobody uses wifi? I just checked that my SO's iOS was on 16.3.1, over 2 months old iOS version.

Apple has decided that iOS should only accept downloading OS updates over wifi. In my country, for example, people don't really set up wifi at home anymore because basically everyone has unlimited cellular data. So they don't need to connect to any wifi at all. All the iOS update statistics seem to come from the US, where everyone relies on wifi.

It seems that on some level, iOS suffers from the same update problem as Android, but only because Apple decided to do so for no reason. Not everyone lives in the US.

tholdem··on Android launches yet another way to spy on users with “Privacy Sandbox” beta
Correct me if I'm wrong, but the way FDE is implemented in Librem 5 means that it is only effective when the phone is turned off? The disk is decrypted when you type in your LUKS passphrase and after that, it stays decrypted until you completely power it off or reboot. That makes it pretty much useless on a phone that you carry around.

The linked source has a lot of stuff that is done "in the future" and basically all of those "in the future" suggestions, are inferior to what AOSP has had for years.

The document lists some of the drawbacks of Librem 5, such as the use of memory-unsafe languages, and then blames Android for also relying on the same memory-unsafe languages and even some Android-specific components written in memory-unsafe languages. The fact is that Android has tons of mitigations specifically for this problem, which Librem 5 completely lacks. They're not comparable in that way. Librem 5 basically exposes the entire Linux kernel attack surface, whereas Android has multiple layers of protection between userspace and the Linux kernel. Apps written in memory safe language, proper app sandboxes, hardened memory allocator, extremely strict SELinux policies, CFI, PAC, ShadowCallStack, etc.

The only nice thing Librem 5 has, are the killswitches, but do those really matter at this point?

tholdem··on Android launches yet another way to spy on users with “Privacy Sandbox” beta
What about AOSP or GrapheneOS? Those also lack all tracking. Not to mention the security, and can you really have privacy without security?
tholdem··on Android launches yet another way to spy on users with “Privacy Sandbox” beta
How does the Librem 5 support verified boot? What about user data encryption? Those are the first, most basic security features I am expecting from a smartphone. How about app sandboxes and strict MAC policies?
tholdem··on Pwning the all Google phone with a non-Google bug
If that is true, why Android 0-days are more expensive than iOS?
tholdem··on Ask HN: FOSS Projects Worth Donating To?
I would participate in the Proton Charity Fundraiser. You can buy tickets which would allow you to win Proton lifetime account and at the same time, you would support really cool FOSS projects, such as: GrapheneOS, Qubes OS, Tor Project.

Proton is fine, but their Charity Fundraiser is awesome: https://proton.me/blog/2022-lifetime-account-charity-fundrai...

tholdem··on Min: A fast, minimal browser that protects your privacy
One reason why mainstream web browsers are slow and "bulky" and use a lot of RAM is that they use all sorts of different exploit mitigation and hardening techniques.

One can only wonder what these alternatives do when they claim to be minimal and fast and worse, private. Can there really be privacy without security?

tholdem··on Ask HN: What is your routine to monitor for viruses and secure boot integrity?
Yeah most definitely because of VM. I'm on Silverblue and on Security Level 1. Level 2 would require IOMMU.
tholdem··on WhatsApp data breach sees nearly 500M user records up for sale
Not a data breach, but scraped and aggregated data that is already availavle by design.
← PreviousPage 2 of 3Next →