Here's How They Built The Most Secure Phone On The Planet

preview_player
Показать описание
The champion of privacy and security is an open source mobile operating system built by a non-profit. This is how GrapheneOS built the most secure phone on the planet.

A secure mobile operating system is built on top of a complicated software stack whose every single building block is isolated to enforce the strict security policy. All system components and processes, third party apps and services are separated from one another in a multi-party consent of developers, users and the platform itself. This is known as an Application Sandbox and it is how Android designed its architecture.

GrapheneOS is a non-profit security research project that focuses on hardening privacy and security features of the operating system while maintaining usability at the same time. GrapheneOS adds to Android’s defense in depth by protecting against exploits abusing unknown vulnerabilities, so called 0day exploits. These exploits are being sold legally by malware brokers for millions of dollars because crafting them requires a high set of skills and experience.

GrapheneOS has made such a vast number of improvements it would be impossible to cover them in one video. Many of GrapheneOS’s enhancements have been adopted by the mainstream Android itself. The research project maintains an extensive documentation on all the important features many of which were missed out by this video.

Sources:

Credits
Music by: White Bat Audio, CO.AG Music, Infraction, Yuzzy

Follow me:

The footage and images featured in the video were for critical analysis, commentary and parody, which are protected under the Fair Use laws of the United States Copyright act of 1976.
Рекомендации по теме
Комментарии
Автор

"...OEM apps, also known as bloatware."
Well played.

crimson
Автор

Great video!

Amazing how many people are seemingly quick to detract from the comments in the video and the project mentioned, yet every single one of them using Android are running code that makes even their standard stock or even non security/privacy focused Android distributions more secure than they otherwise would be by default, that comes from it and it's devs. Just a cursory search for 'their name', 'android' and 'upstream' together will throw out a couple of top page results demonstrating that fact.

ThreeFiver
Автор

I loved the idea of GrapheneOS. I bought a Pixel 6 phone and installed GrapheneOS and I'm loving it. The deeper understanding of the extensive efforts to develop GrapheneOS to be as secure as possible that was provided by this video make me love GrapheneOS even more. It's shameful that all cell phone operating systems weren't developed with this level of user security.

LibertyEver
Автор

My understanding in the San Bernadino case, as I remember it having been reported, was that the phone was accessed by the third party hackers by copying the contents of that phone, which had I believe 8 attempts left before its data would been lost, then by brute forcing combinations onto each virtual copy of the phone. Then after each was copy was destroyed with bad attempts, starting again with the next virtual copy, then repeating the process until eventually, inevitability, the correct code was entered and one of the copies of the phone unlocked.

erich
Автор

Amazing mini docu style! Loved the format of the video, the references in the bottom right hand corner, and the content told a great story + informative. Great job!

TheBenJiles
Автор

This is a great video! People dont know how much big tech and governments are spying on you. I really like how you explain the hardware protections and how pixel protects you!

nathancoats
Автор

It's quite rudimentary returning to the physical key we used at the door, but in this day and age of "hostile" software, hardware keys win! Great video THO, the layers and routing was very interesting. Owe ya another beer

troy
Автор

This video is amazing!!! I can't believe it took a year to find me. The music to the narration are all great. Not only that, but this is a subject that fascinates me, and the graphics laying out security are very informative . I don't have a pixel so I can't experience grapheme yet. But I am using the voltage os android 14 gsi on a samsung galaxy tab A which allows me to use graphenes google play sandbox. I absolutely love it.

Emancipatriot
Автор

I might have to try this on my Pixel 4a.
I haven't flashed a custom ROM since my Galaxy S3 back in the day. I rooted it too. I learned so much about Android OS by playing around with that old phone.

TexasTimelapse
Автор

What’s more profitable, a secure phone, or a phone that claims to be secure, but isn’t?

metoonunyabidness
Автор

Hello THO, what would you think would be next best solution for those of us with an average threat model that can't afford to buy a pixel phone, or can't deal with the inconvenience it is to use a brick phone on a daily basis, but also want to be as secure and private as possible?

Thank you for the dedication and work you put into these videos.

UPDATE: Managed to find an used a3 xl for 100 bucks! Graphene runs smoothly.

tato
Автор

Nice!, thanks for the video, this video answers the questions I had from the interview with Gabe. Amazing work!, thanks!

luispaul
Автор

I'm definitely watching this one.

marcusanark
Автор

Great videos. Thanks for posting links to the sources. It is most helpful when doing research.

InfoSecGSO
Автор

Fantastic depth and beautifully researched 💪🧠

josephs
Автор

That's why apps we don't trust need to be containerrised. Linux is trying it's best. We now have operating system for the desktop with immutable filesystems and containerrised apps like flatpaks. It's far from perfect but it's a step in the right direction. Also things like selinux or apparmor do their part. If i think of s good computer os that's reasonably secure i think of Fedora Silverblue. They really try to redefine the Linux security model in a way that you don't have to verify your Programms anymore. On the flip side i think a operating system not installing any binaries is also a cool thing. If you have a source based package manager you can 100% verify the source code and then you compile it yourself. Sure it's a developers night mare but that's a very good security model.

durschfalltv
Автор

I have one major question: Can graphene protect against Pegasus?

renditionsofthefuture
Автор

Wow. What an amazing piece of technology you put together. Thanks for all the insights and for helping to understand it.
Nevertheless, my family keeps some good old Nokia bricks with pre-paid numbers.

genieur
Автор

What does GrapheneOS do to protect against baseband processor vulnerabilities?

mjmeans
Автор

there is a thing I just don't get though
- we want a secure phone to preserve our privacy
- one of the largest perpetrators of our privacy right now is Google
- Google built a phone specially made for privacy.
Anyone else see something wrong here ?
Like a kidnapper educating people how to avoid being kidnapped by telling us "we shouldn't talk to strangers... unless they have a suspicious van parked close by"

ldandco