[HN Gopher] Leaker reveals which Pixels are vulnerable to Celleb...
       ___________________________________________________________________
        
       Leaker reveals which Pixels are vulnerable to Cellebrite phone
       hacking
        
       Author : akyuu
       Score  : 126 points
       Date   : 2025-10-30 23:12 UTC (23 hours ago)
        
 (HTM) web link (arstechnica.com)
 (TXT) w3m dump (arstechnica.com)
        
       | gnabgib wrote:
       | Source: https://news.ycombinator.com/item?id=45765858
        
       | derbOac wrote:
       | They couldn't answer the question most on my mind: "We've reached
       | out to Google to inquire about why a custom ROM created by
       | volunteers is more resistant to industrial phone hacking than the
       | official Pixel OS. We'll update this article if Google has
       | anything to say."
        
         | bigyabai wrote:
         | Short answer: Google is a business that can be compelled by the
         | federal government in ways that nonprofits are resistant to.
         | Ron Wyden identified one of these weaknesses in 2023:
         | https://arstechnica.com/tech-policy/2023/12/apple-admits-to-...
        
           | windexh8er wrote:
           | Let's be very clear: this is still Google's choice. Google
           | _could_ build a phone that they can 't be compelled to do
           | anything to after the phone is sold to their customer, but
           | _Google_ alone chooses to not invest in the security of the
           | phones they 're selling to their customers. Because: what is
           | good for the government is now equally good for Google.
           | 
           | Do we not remember how Google immediately enabled TLS
           | everywhere, internally, post-Snowden [0]? Remember when
           | Google was "outraged"? Where are those people now? They
           | surely don't work at Google anymore. It's amazing how
           | enshittified Google and Apple have become in a decade.
           | 
           | [0] https://www.bbc.com/news/world-us-canada-24751821
        
             | harambae wrote:
             | > how enshittified Google and Apple have become
             | 
             | I don't know about pop-ups or whatever, but as far as
             | mobile security Apple appears to be running the table. Last
             | cellebrite leak showed they couldn't do anything in BFU,
             | and you can tell Siri to put it back in BFU without hands
             | while being arrested.
        
               | bigyabai wrote:
               | Cellebrite is like the Kmart Blue Light Special of
               | Israeli spyware, when you compare it to Greykey and NSO
               | Group offerings. I would not use their capabilities as
               | the be-all end-all.
        
               | dylan604 wrote:
               | > the Kmart Blue Light Special
               | 
               | Hello fellow old timer. Do kids today even get this
               | reference other than possibly just on context? My other
               | favorite old store was a place called Gibsons where their
               | stores signage had each upper case letter as an
               | individual square. After it went under, more than one
               | location became SBINGOS joints where first/last squares
               | were no longer lit.
        
               | doodlebugging wrote:
               | Another old-timer here who grew up with Gibsons. It was
               | the only grocery store in town back in the days before
               | WalMart invaded. Ammunition, camping gear, dry goods,
               | garden supplies, farm and ranch supplies, blue jeans,
               | shirts, ties, overalls, etc. They sold everything under
               | one roof in a town of 2500.
               | 
               | I thought they had all been swallowed up and shut down
               | until I moved up here to N Texas and was surprised to
               | find a Gibsons here. It took me a while before curiosity
               | took hold but several years later I visited the store,
               | approx 2003-2004ish, and found they still used old-school
               | cash registers, had no UPC scanning capability and every
               | item had a price tag stuck to it. I think they have since
               | moved into the more modern world locally but the store is
               | still there and is a good source for items that you used
               | to need to go to the town's original hardware stores to
               | find. Some of the items on the shelves may have been in
               | inventory here since the 1970's or 1980's. It's a bit
               | like a time machine where you can get obsolete stuff in a
               | pinch if it is still in stock.
               | 
               | I worked slapping price tags on items in KMart back in
               | the day so I too understand the reference. Glad I'm done
               | with that.
        
               | dylan604 wrote:
               | > I moved up here to N Texas and was surprised to find a
               | Gibsons here.
               | 
               | Curiosity kills the cat. What part of NTX? I'm willing to
               | take a trip this weekend just for the lulz. You talking
               | Sherman/Dennison/Paris/Gainesville north, or just
               | Denton/McKinney north? Only thing I'm seeing is one way
               | out west in Weatherford.
        
               | baxtr wrote:
               | BFU = Before First Unlock after power on or reboot.
               | 
               |  _In this state, a significant portion of the data on the
               | device remains encrypted and inaccessible, unlike the
               | "After First Unlock" (AFU) state, where the necessary
               | encryption keys are available._
        
               | immibis wrote:
               | Lots more devices are safe BFU than just Apple's. It's
               | not that complicated on a technical level - it's
               | basically full-disk encryption.
               | 
               | Apple sells the illusion of security and privacy, but
               | they're not meaningfully more secure or private except
               | from the device's owner. Remember when they made a big
               | deal of blocking Facebook tracking, while simultaneously
               | adding their own intrusive tracking?
        
               | tredre3 wrote:
               | > Lots more devices are safe BFU than just Apple's. It's
               | not that complicated on a technical level - it's
               | basically full-disk encryption.
               | 
               | So we agree: it's puzzling that Google can't manage to do
               | it.
        
               | gruez wrote:
               | >Lots more devices are safe BFU than just Apple's. It's
               | not that complicated on a technical level - it's
               | basically full-disk encryption.
               | 
               | That's not the full story. Using LUKS encryption on your
               | linux laptop might make it "safe BFU", but only if you're
               | using a high entropy password. Most people don't want to
               | enter a 24 character password to unlock their phone, so
               | Apple/Google have to add dedicated security hardware to
               | resist bruteforce attempts, hence the vulnerabilities.
        
               | 05 wrote:
               | "Siri, whose phone is this" doesn't work on recent iOS
               | versions. You could ask it to reboot, but that requires
               | confirmation
        
               | gruez wrote:
               | >Last cellebrite leak showed they couldn't do anything in
               | BFU, and you can tell Siri to put it back in BFU without
               | hands while being arrested.
               | 
               | Source? Note that "disables faceid/fingerprint" isn't the
               | same as "BFU".
        
             | Veserv wrote:
             | Ah yes, Google _could_ make a unhackable phone secure
             | against state actors, they just do not feel like it.
             | 
             | Not at all a problem that is viewed as so impossible that
             | the very notion of it is beyond belief to the overwhelming
             | majority of software developers. Google can just waltz on
             | down to the corner store and get a jug of unhackable phone
             | software. They just do not want to.
             | 
             | The fact of the matter is that they are incapable of making
             | systems consistently secure against even moderately funded
             | professional cyber demolitions teams. This is true across
             | the entire commercial IT industry with literal decades of
             | evidence and proof time and time again.
             | 
             | Could it also be a conspiracy? Could they also have
             | deliberate backdoors? Sure. But even without them their
             | systems and everyone else are grossly inadequate for the
             | current threat landscape which only continues to pull
             | further and further ahead of their lackluster system
             | security.
        
               | wizardforhire wrote:
               | I'll be asking Anwar down at the bodega to start carrying
               | jugs of unhackable from now on! I want to try the new
               | razzle dazzle berry and 4D cool ranch if he can get
               | them...
        
           | GeekyBear wrote:
           | No American company has a choice when the Feds want data
           | stored on a company's server.
           | 
           | That doesn't stop Apple or any other company from designing
           | devices that attempt to keep prying eyes out of the data
           | stored on your device.
        
             | bitwize wrote:
             | The government has ways of twisting the arms of
             | uncooperative people/organizations into providing all the
             | backdoors they need. Everything from increased tax and
             | regulatory scrutiny to "discovering" CSAM on executives'
             | computers or phones.
             | 
             | The government does what it wants because it's the
             | government. Mere laws generally don't stand in its way for
             | long.
        
               | gleenn wrote:
               | I think this is a very negative idea to promote: that
               | laws should can be subverted. Everyone should believe
               | that laws work and when they don't we should work to fix
               | that, not assume that it can never be fixed.
        
               | GeekyBear wrote:
               | The government certainly objected when Apple designed an
               | implementation of encrypted cloud backups for iDevices.
               | 
               | That didn't stop Apple from eventually rolling out
               | encrypted cloud backups anyway.
               | 
               | Apple also refused to insert a backdoor into iDevices
               | when James Comey ordered them to do so. They took the FBI
               | to court and forced them to back down.
               | 
               | Google is perfectly capable of fighting too, but their
               | business model puts them at a huge disadvantage.
               | 
               | If you make your money spying on users to make ad sales
               | more profitable, then you have no choice but to hand it
               | over to any Federal, State or local agency that can
               | convince a judge to issue a warrant.
        
           | kangs wrote:
           | google even has specially signed fw that let you root the
           | device and unlock anything that doesn't rely on the passcode.
           | secureboot passing and all. i can't imagine that the nsa
           | doesnt have them. after that you just gotta crack the usually
           | very simple passcode. wouldny be surprised if thats what
           | cellrite has lol.
        
         | IncreasePosts wrote:
         | Is grapheheOS actually harder to hack or does cellebrite just
         | not put a lot of effort into supporting it because the very low
         | odds of LEs running into one in the wild?
        
           | markus_zhang wrote:
           | I read from an old HN post that three letter agencies hate
           | graphen OS. The author heard it from defcon or some similar
           | conference. I couldn't find the post anyway :/ I think it is
           | buried under one of the posts that discuss Defcon and
           | Blackhat.
        
           | zb3 wrote:
           | It physically disables USB ports when locked which
           | significantly reduces the attack surface + can be configured
           | to automatically reboot.
        
           | dns_snek wrote:
           | Clearly it's harder but just how much harder is anyone's
           | guess? Surely higher value targets would be more likely to
           | use Graphene, so I would think that would make it just as
           | important to invest resources into.
        
       | aussieguy1234 wrote:
       | I've set up GrapheneOS on my Pixel with 2FA fingerprint + PIN
       | unlock. No way will anyone be getting into it without my
       | cooperation.
       | 
       | My only issue was less compatibility with my local emergency
       | services, since they can't see me on a map for some reason if I
       | call from a GOS phone.
       | 
       | My solution to that was a second Pixel as an emergency phone -
       | one with the stock OS, that I'll swap sims with and take with me
       | when hiking, stand up paddle bording and doing other activities
       | that carry risk. This phone has no sensitive information in it. I
       | also have a PLB for added protection.
        
         | fluidcruft wrote:
         | Is there anything actually preventing Samsung or another vendor
         | from adopting GrapheneOS's security innovations?
        
           | immibis wrote:
           | Probably their legal obligation to comply with secret
           | government orders (FISA, NSL etc - the government probably
           | already said don't make unhackable phones or else) and their
           | informal wish to remain on the regime's good side.
        
           | joemazerino wrote:
           | The hardware Samsung provides is not up to spec.
        
           | russianGuy83829 wrote:
           | GrapheneOS is seemingly working with an OEM to make a
           | GrapheneOS smartphone. Its probably not samsung, but would
           | still be an established vendor
        
         | usdogu wrote:
         | Obligatory https://xkcd.com/538
        
           | Stefan-H wrote:
           | Cooperation under duress is still cooperation.
        
           | throawayonthe wrote:
           | https://grapheneos.org/features#duress :D
        
             | IncreasePosts wrote:
             | Use that and you'll get charged with destruction of
             | evidence
        
               | falleng0d wrote:
               | if you're relying on such feature, you'll probably serve
               | less time being charged with destruction of evidence...
        
         | DANmode wrote:
         | First I'm hearing Graphene causes issues with E911 - is this a
         | setting?
        
         | tredre3 wrote:
         | > My solution to that was a second Pixel as an emergency phone
         | 
         | Picking a Pixel specifically as an emergency phone is quite the
         | choice, given years of on and off 911 issues.
        
       | chaps wrote:
       | Here's the full document without the blurriness:
       | https://www.documentcloud.org/documents/24833831-cellebrite-...
       | 
       | (it's been available since 2024 -- found by searching for
       | "android os access support matrix" on documentcloud)
        
         | Infernal wrote:
         | The point here is that the doc you linked is a year and a half
         | old, this (if real) is much newer. Security is a constant arms
         | race between attackers and defenders, nothing is static so
         | updates of this nature are always welcome.
        
           | chaps wrote:
           | I'm not disputing that. :)
        
             | Infernal wrote:
             | Fair, I suppose I've misunderstood. I took "it's been
             | available since 2024" as a dismissal of this new
             | information.
        
               | chaps wrote:
               | Also fair! I think "leaker" is just bristly to me in this
               | context, when there's a nearly identical version of it
               | just hanging out for folk to find. But also just a hope
               | that some folk might poke around documentcloud for
               | similar documents lying around. Lots of newsworthy gems
               | in there just waiting to be picked up and this's a good
               | example.
        
         | Squealer2642 wrote:
         | This one doesn't have Pixel 9's so the image in the article has
         | been updated a bit.
        
       | c420 wrote:
       | >However, rogueFed also called out the meeting organizer by name
       | (the second screenshot, which we are not reposting).
       | 
       | The FBI?
        
       | gnarlouse wrote:
       | Wow. I was just thinking about jumping ship from iPhone to Pixel.
        
         | dns_snek wrote:
         | All iPhones were vulnerable according to the last available iOS
         | support matrix.
        
       | zb3 wrote:
       | Another great thing about GrapheneOS (besides security) is that
       | Google Play Services can be installed without elevated privileges
       | and even in a separate profile which can't run in the background.
       | This makes the phone suitable for both normal usage and for those
       | cases where you need to use some "official" app.
       | 
       | It passes Play Integrity "MEETS_BASIC_INTEGRITY" but of course
       | doesn't pass higher levels but not because it's insecure - it's
       | because it refuses to grant GMS elevated privileges. Good news is
       | that banking apps can whitelist GrapheneOS using standard Android
       | attestation mechanism (and some already did).
        
         | ForHackernews wrote:
         | https://xkcd.com/1200/
        
       | j1elo wrote:
       | > _Notably, the Pixel 10 series is moving away from physical SIM
       | cards._
       | 
       | Is it? I hadn't followed news of the new Pixels.
       | 
       | I don't like the idea of modernizing this and going full eSIM. It
       | will introduce a lot of new friction, somehow I don't doubt it.
       | Just now arrived to Mexico for a quick trip and grabbed a prepaid
       | SIM from a 7-11 in the airport. All quick and simple. I doubt
       | things would be so seamless when not having a SIM tray in the
       | phone. Having to go through an official process to register a new
       | card, ID oneself, hope to not have any incompatibility with the
       | eSIM slots in your phone (admittedly I don't know how this
       | works)... vs. just paying MXN100 and leave the store with a ready
       | to use number.
        
         | stackskipton wrote:
         | eSIM can be QR code so if they wanted, Mexican vendor just pay
         | and show QR code for you to scan.
        
       | vdupras wrote:
       | Oh, that's what you get by being unaware of the cellphone brands.
       | I was all excited thinking "hey, they found a way to hack phones
       | through, I guess, screen firmware by setting a special sequence
       | of pixels? How frakking cool!". How disappointed I was...
        
       ___________________________________________________________________
       (page generated 2025-10-31 23:00 UTC)