Hacker Newsnew | past | comments | ask | show | jobs | submit | Distilitron's commentslogin

And yes this nonencrypted shit is totally insecure


While the never fixed 0days on android are completely secure.

And let's not forget the several noclick attacks that can root your iphone with a message :)


How can you compare iOS or Android security with desktop Linux security?

Have you checked what it takes to achieve those 0-click root exploits on iOS or Android compared to a desktop Linux distro?

Not even in the same league.


Have you checked the time it takes apple or any android vendor to fix anything vs the time it takes a linux distribution?

Months vs hours.


Sounds like a vendor issue also present on desktop. Just get a pixel and enjoy first class update support with GrapheneOS.


What makes you think it's not encrypted? https://wiki.postmarketos.org/wiki/Full_disk_encryption seems to indicate that support varies a bit by device but it's perfectly doable.


Note that the initramfs is stored without encryption or signing. So while your data won't be leaked when your phone gets stolen, it should be considered compromised if you get it back.


Sure, lack of secure boot is a tradeoff. Of course, by the same token you can just reflash the boot partition and fix that.


How does flashing work, who controls the writes? I remember reading about hacking the controller of an SD card to override the read/write functionality.

I think if the bootloader is overwritable, it could lie to you about reflashing the boot partition...


It varies by device. Obviously something has to handle writes, but generally it's a lower stage that isn't easily writable itself.


Have read this with one thought: "I don't deseve this shit"


Telefon tel aviv is nice, gfx is crap


It's just a Pooh brainworm


Exactly.


Finaly! Great news!


Tutanota is one of the uglier and at the same time pretentious projects. As far as I'm concerned, this crap can't be called e-mail at all. This is some crookedly made homemade work. They don't support the usual protocols for receiving mail, the search is just terrible, all kinds of freaks use them for their dark business, so these left-handed idiots have even started to be added to ban lists. I recently spent half a month persuading the bank because I stopped receiving notifications. And I would also like to see the "engineer" who invented encrypting letters to other providers using a "password". Well, that is, this whole team of developers, managers - they were not upset by such an idea at all. Implement PGP? Let everyone post public keys and write to each other? No! What nonsense! It's better to go somewhere through a browser and enter some crappy password. And should I trust these bastards with my mail? I would spit in their face. I think this row should be filed for bankruptcy.


They should replace the T with P on the new name, epic lolz


It's sounds like total crap.


Lmao the synthesizer needs a different soundface for sure.


Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: