• 0 Posts
  • 11 Comments
Joined 2 years ago
cake
Cake day: June 9th, 2024

help-circle



  • (GrapheneOS project member here) We are not aware of any organization or software that can hack into GrapheneOS.

    It would be harder for a few reasons. In this case, it would be harder because the baseband is isolated on supported devices so hacking remotely would be harder. GrapheneOS also ports to new Android versions very quickly, which means security patches are applied that other devices/OSes are always far behind on. We also have security preview releases so even more patches are applied for users who enable that. And, finally, there are lots of other hardening things that have been done protect against unknown vulnerabilities. See the website for info about that, but basically the hardened memory allocator + enabling MTE for 8th generation devices and later will catch the most common classes of bugs.







  • Well, the fact is it is impossible to target someone with a modified update. The update client sends no IDs to the server, it just fetches static files and determines whether it needs to update or not. The server only has static files.

    thet could, in theory, make a single OTA that everybody gets, but checks for a specific IMEI or other device ID and only there enables some malicious payload.

    That would be very obvious in the code. And how would devices be targeted if GrapheneOS project members don’t know the unique IDs because they’re not sent in the first place? There are also community members who build GrapheneOS on their own and check if the builds match because GrapheneOS builds are reproducible. It just isn’t possible. But even if people don’t believe all of that, they can still disable the updater app and sideload updates manually. Instructions are on the website.