UBports Robot Logo UBports Forum
    • Categories
    • Recent
    • Tags
    • Popular
    • Users
    • Groups
    • Search
    • Register
    • Login
    1. Home
    2. king_of_ooo@defcon.social
    3. Posts
    Offline
    • Profile
    • Following 0
    • Followers 0
    • Topics 0
    • Posts 2
    • Groups 0

    Posts

    Recent Best Controversial
    • RE: We're happy to announce a long-term partnership with Motorola.

      @GrapheneOS @lumi @alexia The current default software stack for desktop Linux is kind of terrible and the lack of coherent threat model or proper ecosystem of sandboxed applications are major issues with desktop right now. What I am still questioning is whether it is even possible to make a proper competitor to ChromeOS (if we ignore the hardware insecurity of basically all PCs).

      So example software choices:
      systemd -> dinit or s6
      sudo -> s6-sudo (setuidless)
      glibc -> muslc
      glibc malloc or jemalloc -> hardened_malloc, malloc-ng, or mimalloc-secure (which supports more CPU architectures)
      bubblewrap (sandbox used by Flatpak) -> #syd (it's written in Rust, has many important exploit protections, and can even be the user login: https://gitlab.exherbo.org/sydbox/sydbox)
      GNOME or KDE -> XFCE (when their new Rust Wayland native WM is finished)
      gnutils -> *BSD or uutils

      The issue of course with most of these alternatives is that they are separate projects and therefore dont have the same goals, methods, or threat models. Also most of these projects are written in C which does not help at all. Also there is of course the lack of a proper chain of trust from the hardware to loading the kernel and userspace.

      It may just not be reasonably possible to provide a alternative without millions of dollars of funding and a decade of development. It would be nice for there to be an alternative to AOSP/ChromeOS or even MacOS for desktop computing which actually takes security seriously. It doesnt even need to have be completely on par when it comes to security, just do better than current Linux distros (not a very high bar).

      What are your thoughts on what to do in case the day comes that Google kills AOSP?

      posted in World
      king_of_ooo@defcon.socialK
      king_of_ooo@defcon.social
    • RE: We're happy to announce a long-term partnership with Motorola.

      @GrapheneOS I tried doing some searching online and I couldnt determine if Pixels have open source firmware? Idk how realistic to hope that these collab devices will have at least source available firmware.

      Also, do you know what the expected EOL timeframe for these new devices will be? Can we expect something on par to the Pixel 8? With advancements in hardware security (eg. the development of MTE) is it even worth holding onto a phone for a 7 year lifespan?

      posted in World
      king_of_ooo@defcon.socialK
      king_of_ooo@defcon.social