Remix.run Logo
notorandit 4 days ago

The only thing that comes to my mind is the so-called blobs, the closed source hardware drivers that are needed to make an Android phone work and that run at high privilege level.

If GrapheneOS is not tightly sandboxing them, then chances there are that a capable operator can use whatever backdoor each driver offers, mainly the wifi adapter, the baseband modem and the Bluetooth adapter.

No matter what GrapheneOS developers have done.

Imagine the wifi driver being able to spoof on pin entry procedure.

matheusmoreira 4 days ago | parent [-]

> If GrapheneOS is not tightly sandboxing them

It is. HN user strcat has posted extremely detailed comments on the matter.

https://news.ycombinator.com/threads?id=strcat