GrapheneOS version 2025081300 released:
https://t.co/zEfigDY2C3
See the linked release notes for a summary of the improvements over the previous release.
Forum discussion thread:
https://t.co/L9DtRuauT3
#GrapheneOS#privacy#security
BREAKING: BYBIT $1 BILLION HACK BOUNTY SOLVED BY ZACHXBT
At 19:09 UTC today, @zachxbt submitted definitive proof that this attack on Bybit was performed by the LAZARUS GROUP.
His submission included a detailed analysis of test transactions and connected wallets used ahead of the exploit, as well as multiple forensics graphs and timing analyses.
The submission has been shared with the Bybit team in support of their investigation. We wish them all the best.
February 2025 Android Security Bulletin includes a heap buffer overflow in a Linux kernel USB peripheral driver (CVE-2024-53104) marked exploited in the wild. It's likely one of the USB bugs exploited by forensic data extraction tools. We block them using these.
https://t.co/ONq97W5pcO
By default, GrapheneOS blocks new USB connections when the device is locked in the Linux kernel and at a lower level via the USB-C and pogo pins controllers to defend the firmware and lower-level Linux kernel code too. Data is blocked in hardware once connections end.
https://t.co/7S6iIQIYe7
If a user connected a malicious USB device while unlocked which tried to exploit this, general purpose exploit protections come into play. For the majority of the OS, our hardened_malloc project provides strong protections against heap corruption exploits. Kernel heap hardening is a separate thing.
One of the stronger defenses in hardened_malloc is our own implementation of hardware memory tagging (MTE) which integrated shortly after it shipped in production with the Pixel 8 (https://t.co/vRy5Ue3dcv) and we had it enabled by default in around a month (https://t.co/zGQNmQl7FK).
Linux kernel has a standard disabled by default implementation of hardware memory tagging. We very recently began enabling to defend it from issues like this USB heap corruption vulnerability (https://t.co/Y4PeyUCYlu). It's a major improvement but still not nearly as good as hardened_malloc.
We also already had CVE-2024-53104 patched prior to this month since we ship the https://t.co/gNQDiYNpl1 LTS revisions long before the Android Open Source Project / stock Pixel OS. Our systemic defenses are far more important because they work before vulnerabilities are known, so we didn't lead with that fact.
The path to unifying Ethereum is here 🤝
Developed alongside @AcrossProtocol, ERC-7683 proposes that all cross-chain intents follow the same order structure
Solving liquidity fragmentation through a shared filler network
1. Launch $TRUMP $MELANIA $Barron memecoins
2. Use bag holders as exit liquidity
3. Buy BTC, ETH & Stables
4. Pardon yourself and everyone involved.
You can't make that shit up.
Governments have constantly tried to destroy on-chain privacy, taking any chance they could to ensure that personal user information can directly be linked to their on-chain address.
At the same time projects like $TRUMP and $MELANIA are as nontransparent as they can get.
as some of you have seen, the SEC has decided to sue us and @helium literally as they are walking out of the door. the last gasp of a failed crusade against crypto companies in the US
naturally, none of the claims hold any water at all. the SEC has wasted two years of our time and millions of our dollars pursuing any claim they could think of. first it was that the coverage map was fake, then that the cellular radios weren't really cellular, then that the IOT hotspots didn't really work, literally chasing anything that might stick
eventually they decided that wireless access points must be securities (lol), and that if you share your location data using @helium_mobile and get paid for it that is somehow bad. apparently they would rather let the big telco guys steal your data for free and fine them for it later
the icing on the cake is that we somehow defrauded our Series D investors, despite literally all of them telling the SEC that none of that happened. we've addressed this in the past, and have worked with every company on Helium mentioned in the complaint. apparently written testimonials from the companies themselves are insufficient for Gensler and his goons
I don't get angry very often, but this is a blood boiling sequence of events. there's so much more I could say, but it's probably better if I don't
we'll defend ourselves vigorously and continue the Gensler SEC's track record of miserable losses and outright lies. not just for us, but for all DePIN projects. if Helium hotspots are securities, it puts all DePINs in danger. we won't allow that to happen
I'm not remotely concerned. just pissed off
fight ✊🛡️
@theissler@coinbureau Kinda misleading title, they're planning to implement a exit tax if you plan to exit the country with your capital f.e. to avoid paying taxes in france.