| ▲ | tptacek 6 hours ago | |
One way to resolve the tension here is to note that CNE and lawful-intercept access to phones depends generally on platform vulnerabilities, not application code vulnerabilities. Low-level platform code churns less, absorbs more fixes under AI workloads than it does new features, and works in a constrained space where guardrails are easier to provide (and where those guardrails already have institutional support at Apple and Google). Over the long term this state of play could change, and IC/LEO organizations could start leaning more on application vulnerabilities than on platform RCEs. But the action would probably still coalesce around a couple of app-layer targets that could themselves be hardened. | ||
| ▲ | schoen 41 minutes ago | parent [-] | |
I was hoping that the basebands and firmwares would get formally verified. Maybe they will ... with AI-written proofs! | ||