• prettybunnys@piefed.social
    link
    fedilink
    English
    arrow-up
    0
    arrow-down
    1
    ·
    edit-2
    9 months ago

    I spent quite some time in mobile security and I won’t use an Android device knowing what I know.

    I’d like to caveat that this is not an endorsement of Apple security but rather a “OH MY GOD NO” about Android “security”

    These downvotes brought to you by tech tribalism, read the thread

    People hate that iPhones have locked boot loaders and you can’t boot a custom rom. Defensive security experts love that at least for now a critical threat vector is nearly non-existent.

    • Eheran@lemmy.world
      link
      fedilink
      English
      arrow-up
      1
      ·
      9 months ago

      I don’t downvote you because I like one side or the other, I do it because of what you write: Hefty claims with zero substance behind.

    • TrickDacy@lemmy.world
      link
      fedilink
      English
      arrow-up
      1
      ·
      edit-2
      9 months ago

      I spent some time knowing about business practices and user-hostile design and I’ll never use an apple device. And I’ll definitely never give apple another penny, fucking fake assholes.

      I’d like to caveat that this is not a denial that google is horrible, their os is just the only reliable alternative to a Linux phone atm

      Edit: this dude seems really invested in apple. He went back through the thread and edited in weird stuff in several of his comments. I think their appeal to authority fallacy is pretty glaringly on display. Fair to bring up that you know what you’re saying and why, but beating someone over the head with it just makes you sound wrong and like you’re giving a flimsy excuse as to why you don’t have to prove anything.

      • prettybunnys@piefed.social
        link
        fedilink
        English
        arrow-up
        0
        arrow-down
        1
        ·
        9 months ago

        I think you’re doing the tech tribalism thing here whereas I’m talking about actual device security.

        I get it’s popular to hate Apple. Cool. You’re cool for hating Apple.

        Anyone who is genuinely interested in mobile security ought to read some of the white papers or device analysis’ which are available to the public. Security conferences are your best avenue for finding information available to the public.

        Anyways, cool, hate Apple but for some reason give Google a pass.

    • Possibly linux@lemmy.zip
      link
      fedilink
      English
      arrow-up
      1
      arrow-down
      1
      ·
      9 months ago

      I’m not sure why you think Android has security problems. In general it is very secure since it enforces least privilege everywhere.

      It does have security vulnerabilities but so does iOS and ever other piece of software

      • prettybunnys@piefed.social
        link
        fedilink
        English
        arrow-up
        1
        arrow-down
        1
        ·
        9 months ago

        It does not actually enforce least privilege everywhere, its application of SELinux is … well it’s better than what targeted policy does, but it’s designed to be unobtrusive not protective. The issue isn’t Android itself, as a concept it’s not awful. The issue is the reality of being a security professional and attempting to secure the edge which in this case is the users and their devices.

        From a practical standpoint administering and protecting one device type on a fairly closed OS is significantly easier than one where the hardware landscape is so varied.

        If you look critically at what it appears this action (the article, and what I am responding to) is for it is because the USERS being exploited is the threat vector. Android devices have significantly more documented malware out in the wild AS WELL AS many documented and active boot exploits.

        My comments have nothing to do with what I like. This isn’t fanaticism. It’s practical reality.

        A nation state actor likely doesn’t care what device you use because they can get the data they want elsewhere, your device is just a beacon at that point for where.

      • prettybunnys@piefed.social
        link
        fedilink
        English
        arrow-up
        0
        arrow-down
        1
        ·
        edit-2
        9 months ago

        Rather than speak from my expertise which will be refuted (the thread you’re commenting on has already gone this route), go look at what mobile research says.

        Graphene OS which is held up as the champion makes the same claims I do.

        Watch conference demos, look at cellebrited claims from 2026.

        I’m parroting what is known in the wider security community, it just doesn’t conform with what enthusiasts think.

        The reality of the situation is when it comes to a nation state level actor no device is safe. That’s baked into just about all the infrastructure your device uses.

    • givesomefucks@lemmy.world
      link
      fedilink
      English
      arrow-up
      0
      ·
      9 months ago

      Literally the opposite…

      https://www.timesofisrael.com/israeli-tech-company-says-it-can-break-into-all-iphones-ever-made-some-androids/

      Israel doesn’t want the IDF able to hide/leak anything about the ongoing genocide, so they’re making everyone use the phone that they can spy on.

      Like, Israel says it’s for safety but they’ve been committing an open genocide for two years now, why they fuck is anyone taking their word?

      • favoredponcho@lemmy.zipdeleted by creator
        link
        fedilink
        English
        arrow-up
        0
        arrow-down
        1
        ·
        9 months ago

        Do you have any credentials at all here or are you just gonna keep reposting a six year old article about Cellebrite and a long since patched vulnerability. If you knew anything about this space, you’d at least try to post the latest info on which phones Cellebrite can hack. As for iOS, here is what I can find…they cannot hack phones running the latest version: iPhone Cellebrite Hack.

        For Android phones, Pixels can be easily hacked, unless you’re running GrapheneOS: Pixel Vulnerabilities to Cellebrite Hacks. Non-Pixel Android phones are likely even more vulnerable given that few manufacturers even try as hard as Google to secure their phones and do as much to keep their phones on the latest Android version.

        As someone with a career in tech, I concur with the original commenter. On the whole, Android is not a secure OS unless you run Graphene OS. If you care about security, I would choose Graphene OS, iOS, and then everything else.