A growing number of apps are using the Play Integrity API to enforce installation from the Play Store. This is clearly highly illegal anti-competitive behavior. It doesn't impact GrapheneOS users installing apps with the sandboxed Play Store but does impact other install sources.
@mbananasynergy1@wanghan1995315@phhusson@MishaalRahman@topjohnwu@DanielMicay So we have to approach this incrementally, to build a better future. In a few years, we want only devices with RKP and recent patchlevels to pass. And I hope we'll have a program for certified third party OSes, too! All of our designs take care to leave that option open.
@mbananasynergy1@wanghan1995315@phhusson@MishaalRahman@topjohnwu@DanielMicay We have had some discussions with makers of high-quality ROMs about getting them to pass CTS, then establishing some kind of relationship we can use to trust them. This is a promising direction, but it will require a lot of work on both sides, including by lawyers.
I can't believe a paid OS needs a tool like this. Here's a GUI tool called OFGB (Oh Frick Go Back) to remove all the ads in Windows 11. It's understandable if a free OS or app needs ad support, but this is just crazy.
We just released lawnchair 14! It's based on lawnchair 12 but includes extra features like:
✅ QuickSwitch for Android 10 - 14
✅ No-root global search
✅ Smartspacer support
✅ Hide Dock
And more! Visit our website for additional details: https://t.co/5PRgZ2W4qA
Gonna keep reposting stuff because it's just so simultaneously fascinating and terrifying for the world we live in.
This can't have been the only op they were working, they had to avoid moving too fast so as not to appear sus, so how many other crucial projects are infiltrated?
The xz backdoor was the final part of a campaign that spanned two years of operations. These operations were predominantly HUMINT style agent operations. There was an approach that lasted months before the Jia Tan persona was well positioned to be given a trusted role.
Lots of analysis of the xz/liblzma vulnerability. Most skip over the first step of the attack:
0. The original maintainer burns out, and only the attacker offers to help (so the attacker inherits the trust of the project built by the maintainer).
Read their words👇🏻 1/
Finally, someone cracked it. The ChatGPT system prompt.
If you were wondering why GPT became so bad in the past 6 months, its because "laziness" is part of the system prompt:
1. "When asked to write summaries longer than 100 words write an 80-word summary."
2. "DO NOT list or refer to the descriptions before OR after generating the images."
3. "Do not create more than 1 image, even if the user requests more."