TE
科技回声
首页24小时热榜最新最佳问答展示工作
GitHubTwitter
首页

科技回声

基于 Next.js 构建的科技新闻平台,提供全球科技新闻和讨论内容。

GitHubTwitter

首页

首页最新最佳问答展示工作

资源链接

HackerNews API原版 HackerNewsNext.js

© 2025 科技回声. 版权所有。

Pixel Security

198 点作者 praving5超过 8 年前

18 条评论

jc4p超过 8 年前
Just FYI in case anyone is considering buying a Pixel: I strongly urge you not to. <a href="http:&#x2F;&#x2F;kasrarahjerdi.com&#x2F;2016&#x2F;11&#x2F;dont-buy-anything-made-by-google&#x2F;" rel="nofollow">http:&#x2F;&#x2F;kasrarahjerdi.com&#x2F;2016&#x2F;11&#x2F;dont-buy-anything-made-by-g...</a><p>They have no Google provided support, if you drop the phone and break it your only option (if you didn&#x27;t buy the third-party warranty upsell) is to take it to a repair shop. I called the ones near me, none had seen or touched the device before.<p>Don&#x27;t spend $800 on a phone that you can&#x27;t send back to the manufacturer to repair.<p>Edit: I originally said &quot;they have no warranty&quot; and people seem to have understood that as &quot;they don&#x27;t provide free repairs&quot; -- what I&#x27;m trying to say is that this phone is supposedly a competitor to Apple, but if you break it you can&#x27;t walk to the Apple Store and ask them how much it&#x27;d be for a repair. You can&#x27;t send it in the mail to them either. You have to go to an authorized third-party repair shop. That does not sound like first-class flagship $800 product support to me.
评论 #12982655 未加载
评论 #12982629 未加载
评论 #12983606 未加载
评论 #12982748 未加载
评论 #12982616 未加载
评论 #12982609 未加载
评论 #12991454 未加载
评论 #12987954 未加载
评论 #12982940 未加载
评论 #12982815 未加载
评论 #12984102 未加载
tdkl超过 8 年前
Google security is so strong, they&#x27;ll even lock you out of your own account when changing cities, with no chance to get it reinstated :<p><a href="https:&#x2F;&#x2F;www.reddit.com&#x2F;r&#x2F;Android&#x2F;comments&#x2F;5dif8j&#x2F;psa_google_can_lock_your_account_forcing_you_to&#x2F;" rel="nofollow">https:&#x2F;&#x2F;www.reddit.com&#x2F;r&#x2F;Android&#x2F;comments&#x2F;5dif8j&#x2F;psa_google_...</a>
评论 #12982678 未加载
评论 #12982662 未加载
Sir_Cmpwn超过 8 年前
I would really love to see Google tackle fixing the security problems presented by the radio chip. A closed source esoteric firmware full of vulnerabilities that has DMA on your primary CPU and is remotely exploitable by state and private actors? Not to mention that it&#x27;s an entry point into a device that&#x27;s always on your person, has all of your contacts, emails, text messages, and phone calls, and has a GPS module in it. The radio is a <i>huge</i> problem and dramatically outweighs any other security concerns on a phone imo.
评论 #12985396 未加载
zx2c4超过 8 年前
&quot;We then modified the inline encryption block driver to pass this to the hardware. As with ext4 encryption, keys are managed by the Linux keyring. To see our implementation, take a look at the source code for the Pixel kernel.&quot;<p>It doesn&#x27;t sound like they got these changes into mainline. They link here to their source: <a href="https:&#x2F;&#x2F;android.googlesource.com&#x2F;kernel&#x2F;msm&#x2F;+&#x2F;android-msm-marlin-3.18-nougat-dr1&#x2F;fs&#x2F;ext4&#x2F;crypto_key.c" rel="nofollow">https:&#x2F;&#x2F;android.googlesource.com&#x2F;kernel&#x2F;msm&#x2F;+&#x2F;android-msm-ma...</a><p>From that file:<p><pre><code> &#x2F;* TODO(mhalcrow): Just for proof-of-concept *&#x2F; </code></pre> WHOOPS!
wheelerwj超过 8 年前
Isn&#x27;t the pixel the phone that was just pwned inside 60 seconds by security researchers?<p>And doesn&#x27;t google have a terrible track record of releasing data to federal agencies?<p>So, aside from purchasing a phone that is built by data-mining, internet advertising giant, google can&#x27;t even begin to make the claim that they value user security.
评论 #12983610 未加载
评论 #12983648 未加载
devsquid超过 8 年前
Kinda neat they link directly to some source code in a blog post.
amluto超过 8 年前
I trust this as far as I can throw it. Trustzone is at best as secure as the Trustzone secure world kernel, Qualcomm supplies that code (even in the Pixel AFAIK), and the Qualcomm secure world kernel is notoriously poorly written.
评论 #12986056 未加载
评论 #12986057 未加载
beefsack超过 8 年前
Countries with stronger consumer protection laws should have much less of an issue with warranties. My father dropped his Nexus 5 about 11 months after he bought it and Google provided a replacement really promptly.
x0ner超过 8 年前
While all devices have security issues, not too comforted by this:<p><a href="http:&#x2F;&#x2F;thehackernews.com&#x2F;2016&#x2F;11&#x2F;google-pixel-phone-hacked.html" rel="nofollow">http:&#x2F;&#x2F;thehackernews.com&#x2F;2016&#x2F;11&#x2F;google-pixel-phone-hacked.h...</a>
评论 #12985416 未加载
mianos超过 8 年前
I have not seen so many gotos in many many years. I guess it&#x27;s the programming model in this case. I am sure this bit of code is going to be audited quite closely.
评论 #12982843 未加载
评论 #12982636 未加载
评论 #12985426 未加载
mtgx超过 8 年前
Is this meant to be a sort of <i>generic</i> response to this issue? (which they still don&#x27;t seem to be addressing here)<p><a href="https:&#x2F;&#x2F;plus.google.com&#x2F;u&#x2F;0&#x2F;+DeesTroy&#x2F;posts&#x2F;R7V3knn3f1s" rel="nofollow">https:&#x2F;&#x2F;plus.google.com&#x2F;u&#x2F;0&#x2F;+DeesTroy&#x2F;posts&#x2F;R7V3knn3f1s</a><p>Or perhaps to this?<p><a href="http:&#x2F;&#x2F;www.theregister.co.uk&#x2F;2016&#x2F;11&#x2F;11&#x2F;google_pixel_pwned_in_60_seconds&#x2F;" rel="nofollow">http:&#x2F;&#x2F;www.theregister.co.uk&#x2F;2016&#x2F;11&#x2F;11&#x2F;google_pixel_pwned_i...</a><p>Still waiting on Google to at least match, if not surpass, Apple&#x27;s long-term support in regards to updates (which is about twice as much what Google offers right now, even though the Pixel has identical prices to the iPhones, at every level).
jwtadvice超过 8 年前
Pixel&#x2F;Google does not motivate a threat model under which to evaluate or understand their design and marketing promises, but we can take a hint from &quot;protects your data if your phone falls into someone else&#x27;s hands.&quot; - Namely thefts of opportunity.<p>Unlike other phone manufacturers, Google does not promise potential customers that your data will be protected from Google, it&#x27;s partners and from law enforcement and mass surveillance programmes.<p>Therein this product doesn&#x27;t provide a stronger security posture that competitors - and furthermore it&#x27;s threat model and security properties do not meet what are in my opinion minimal reasonable requirements.
评论 #12982535 未加载
评论 #12982572 未加载
RRRA超过 8 年前
meanwhile we still have to deal with a SIM and the baseband is a whole other clusterfuck entirely...<p>Can the users actually get the keys to their own stuff?
sundvor超过 8 年前
And as a bonus, if you onsell it, we&#x27;ll wipe your Google account without warning.
评论 #12988000 未加载
scotchio超过 8 年前
Sorry - not post related:<p>#2 spot on HN, 2 comments, submitted 28 minutes ago.<p>Is this normal? Never seen that happen on HN before. Just curious
评论 #12983470 未加载
评论 #12982556 未加载
评论 #12982624 未加载
akerro超过 8 年前
Does android still backup WiFi passwords in plaintext?
Veratyr超过 8 年前
Encryption is all well and good but I feel like Google&#x27;s handling of root causes a lot of issues.<p>There are a lot of pretty basic things (like ad blocking or monitoring battery usage) that require root, which severely impacts the security of the device.<p>EDIT: Okay, I stand corrected on ad blocking. Access to detailed battery stats however is locked behind the BATTERY_STATS permission which isn&#x27;t accessible to anything except for system apps. That aside, there are other basic things like backup that also require root.
评论 #12982523 未加载
评论 #12982524 未加载
jwtadvice超过 8 年前
Given recent news about mass surveillance, it&#x27;s important to note that Pixel&#x27;s security model does not and can not seek to protect your data for use for private messaging, conversation with attorneys, for journalists, or to organize for political reasons.<p>If you are interested in a communications device that can be used for any of these things, Pixel&#x27;s security model will not cover you and you will need to look for an alternative product.
评论 #12982669 未加载
评论 #12982966 未加载