Settings

Theme

Debunking fake stock Pixel OS vulnerability from an EDR company

discuss.grapheneos.org

35 points by kaspar030 2 years ago · 8 comments

Reader

KingOfCoders 2 years ago

What I found funny about the Wired piece, is that one of the worlds top big brother companies, Palantir (do they see themselves as Saruman or are they on the good side, I earnestly wonder, perhaps someone from the inside could comment on that, highly appreciated), makes the point.

gruez 2 years ago

Where's the debunking? The linked post seems to only say that the various media outlets are "misrepresenting a vulnerability" and "fearmongering", but doesn't really expand on that aside from saying it's disabled and "Stock Pixel OS no longer gives the same level of access to the active carrier". It doesn't expand on why those make the vulnerability a non-issue. I expected far more from a "debunking".

  • kayo_20211030 2 years ago

    > "The most straightforward way to do this would involve having physical access to a victim's phone as well as their system password or another exploitable vulnerability that would allow them to make changes to settings."

    If I have all that, why would I need a second level vulnerability? In fairness, the Wired piece might be technically correct, but it does seem overblown; a nice fluffy PR piece rolled up with clickbait.

    • gruez 2 years ago

      It's a preloaded app with possibly privileged permissions (ie. permissions that apps you install normally can't get), so it's possibly worse than what you can normally achieve via physical access. I checked the iVerify report[1], and it doesn't look like such permissions exist, but I'd appreciate more elaboration about the actual vulnerability from grapheneos's debunking post, rather than spending half the article ranting about how various entities are bad.

      [1] https://40052983.fs1.hubspotusercontent-na1.net/hubfs/400529...

Keyboard Shortcuts

j
Next item
k
Previous item
o / Enter
Open selected item
?
Show this help
Esc
Close modal / clear selection