ExploreTrendingAnalytics
Nostr Archives
ExploreTrendingAnalytics
island14d ago
GrapheneOS partnering with Motorola sounds great until you remember Motorola is Lenovo. a Chinese-owned company. the same assholes that shipped Superfish, preinstalled adware with a root CA that broke HTTPS on their own customers' laptops. they didn't fail at privacy. they chose to attack it for profit. cunts now these assholes control the bootloader, the baseband, the entire supply chain for your privacy phone. GrapheneOS can harden the OS all day. doesn't matter if the hardware underneath is compromised. Lenovo got caught, paid a fine, moved on. nothing changed more people getting a privacy-first phone is a win. handing that to a company that already sold out its users makes it smell like a honeypot
💬 16 replies

Replies (16)

Global Sports Central14d ago
They had a change of heart, trust me brou 😆
0000 sats
JordanP14d ago
Dang, didn't know this about Lenovo. Is Lenovo still vulnerable in this way?
0000 sats
JordanP14d ago
Dang, didn't know this about Lenovo. Is Lenovo still vulnerable in this way?
0000 sats
plebiANON13d ago
@Sourcenode
0000 sats
Sourcenode13d ago
Dang it
0000 sats
plebiANON12d ago
🤣😂
0000 sats
rieger_san13d ago
Doesn’t matter! When Motorola delivers all the things to GraphenOS to build a Image for the phone you can simply install a graphenOS version by your own without a branding from motorola same like pixel phones
0000 sats
island13d ago
What the fuck is this comment? When a non tech savvy human buys one of these phones for “privacy”, the last thing on earth they plan on doing is flashing a new GraphineOS on top of what’s previously installed. 🤦🏻‍♂️
0000 sats
Derek Ross13d ago
Everyone cheering forgets that Google bought and kept the good parts of Motorola 🥹
0000 sats
Final12d ago
There's nothing to mitigate in the first place. It has nothing to do with GrapheneOS or smartphones. Every Windows laptop vendor has bundled sketchy bloatware in the past and many still do in the present. Security research targets are encouraged, feel free to find something, anything, in these devices that you think are off. Use a non-Motorola device if you want to choose based on pure vibes or you don't like them for any other reason. If you're an OEM, contact us and work with us. If you really have to get to the details then Superfish is not installed by the firmware but was bundled operating system software and was trivially discovered. Obviously, there's no such thing that will happen here or GrapheneOS, it would be caught by our (very) vigilant users and I know I put the rep on the line saying that. >now these assholes control the bootloader, the baseband The bootloader is a standard littlekernel-based Android bootloader. The baseband is Qualcomm's, part of their SoC. Our device requirements on the site state explicitly radios must be isolated and that sensitive data cannot be accessed at the bootloader (working verified boot, zeroing memory left over from the OS, etc.), we are very conscious about that and received bounties for discovering and patching security deficiencies in bootloaders targeting Pixels that were exploited in the wild. We'll be having involvement in the driver and firmware side of things. Working to improve their security posture and harden their stock OS and firmware is part of the partnership.
0000 sats
Final12d ago
...you can argue that Windows was already full of sketchy bloatware without the OEMs bundling bullshit too. it's really sad to see what has been going on with Windows in recent times.
0000 sats
ReyPelayo12d ago
Yes i think that this is a problem. How can we make sure that our hardware is not compromised?
0000 sats
LightningBTC10d ago
https://www.braxtech.net/
0000 sats
CitizenPleb13d ago
You’re grandma ain’t buying this phone. The majority of people buying this phone are going to be tech savvy enough if they’re privacy oriented.
0000 sats
rieger_san13d ago
You haven’t understood anything 🙄
0000 sats
island13d ago
If you’re tech savvy enough, why would you buy a phone from a company that is untrustworthy yet promises privacy & security that’s already built in - then flash it again yourself?
0000 sats