• 1.11K Posts
  • 1.7K Comments
Joined 2 years ago
cake
Cake day: July 1st, 2023

help-circle






  • As a GrapheneOS user that’s my take too. The paranoid security-obsessed developer who is focused on making the best software to the point of being rude and isolationist is not the kind of person I’d want to hang out with but kind of is the person I want doing security work for the device I have all my personal info on. Sure it would be nicer if they weren’t so abrasive but I’d rather they channel an angry Linus Torvalds than some slick weasel-wordy Steve Jobs.




  • Ah, I thought I’d seen this story already:

    There is one potential downside to the Risk-Based Update System, as highlighted by the folks behind GrapheneOS, a privacy and security-oriented fork of AOSP. In the past, Google gave OEMs a one-month heads-up. Now, they receive several months of advance notice for the larger quarterly updates. This longer window could be problematic, as it gives bad actors more time to potentially find leaked vulnerability details and develop exploits before patches are widely available. While the private ASB is shared securely, it’s accessible to tens of thousands of engineers across dozens of companies, making it conceivable that details could leak to malicious third parties. This remains a hypothetical risk, though, as it would require bad actors to leverage the right exploit on the right devices before they’re patched.