Google says YOU must wait 24 hours if you download an app onto your OWN DEVICE if it's from an "Unverified developer". What ever happened to user choice and Android freedom?! 😡
Google has started rolling out its new ""Advanced Flow", which requires you to wait a 24-hour waiting period if you want to install apps from unverified developers.
Find out more: https://t.co/c89lutjITS
Sign the petition:
https://t.co/pMT2Xhsxwa
We have a partial port of GrapheneOS to the Pixel 11 series after a week of work on it. We're unable to complete the port due to lack of support for ARM hardware memory tagging in software, firmware and near certainly hardware. It appears Google cut an important security feature to save money.
ARM hardware memory tagging (MTE) is used by GrapheneOS across the entire base OS including the kernel and every standard base OS process. It's only temporarily disabled for a few device-specific processes. It greatly improves protection against nearly all remote exploits and many local exploits.
Pixel 8 launched with hardware MTE support in October 2023. We integrated it into our hardened_malloc project and began using it across the OS later that month. Android and the Pixel OS never started using it by default. Android Advanced Protection Mode in Android 16 enables it for a few processes.
Apple's Memory Integrity Enforcement (MIE) is an always enabled feature on the iPhone 17. It's simply a high quality implementation of MTE using the latest standard extensions. It uses MTE in the most secure mode in the kernel and a large portion of userbase. They did a very good job integrating it.
Apple's MIE and Android 16+ AAPM don't use MTE for user installed apps unless those explicitly opt in. GrapheneOS enables it for more apps automatically and has a toggle for users to opt-in for every user installed app. There's a per-app toggle to opt-out for incompatible apps which is uncommon.
Neither iOS or Android encourage app developers to opt into MTE and other more aggressive security features used in the base OS. Apple's docs warn developers of performance and stability issues. Even Signal doesn't opt-in. Our approach enables forcing using MTE in the standard allocators regardless.
Pixel 11 does have security improvements including moving to post-quantum secure verified boot (ML-DSA) and replacing Samsung Shannon IMS with AOSP IMS. Titan M3 should significantly improve protection against data extraction in Before First Unlock state. It's too bad they ruined it by cutting MTE.
Pixel 11 series is a lot more expensive for an incremental improvement to the CPU, the same underpowered GPU and reduced RAM for the Pro base models. They finally caught up to the last generation of Qualcomm cellular radio. It's overpriced, the upgrades aren't impressive and losing MTE is appalling.
Compared to the Pixel 11, a Snapdragon 8 Elite Gen 5 has ~40% higher single threaded CPU performance, ~80% higher multi threaded performance, over 100% higher GPU performance and a far better cellular radio. It also finally has MTE. The next gen is what will be in the first Motorola with GrapheneOS.
Pixel 9a and earlier (including Nexus devices) were the Android Open Source Project reference devices. Pixel support was removed from AOSP with Android 16. It's now harder to support Pixels than many other devices and massive progress towards open source firmware and driver libraries was discarded.
Compared to the stock Pixel OS, GrapheneOS ships AOSP patches months earlier and Linux kernel patches many months earlier. However, we rely on them for firmware and most driver updates. We also want to move to new kernel branches earlier. These things can be improved with our Motorola partnership.
We strongly recommend against buying Pixel 11 devices. Pixel 8, 9 and 10 have much better overall security for GrapheneOS. Pixel 10 is cheaper with similar hardware and MTE. Pixel 11's Titan M3 should improve BFU security for users without a strong passphrase, but losing MTE craters AFU security.
We haven't determined what to do about this situation. It may be best for us to skip the Pixel 11 series devices. We can shift our focus entirely to the upcoming Motorola devices instead. Pixel 10a was really a 9th gen Pixel, so hopefully the Pixel 11a does the same with 10th gen and includes MTE.
Android 17 is officially the first major mobile OS to enable broad Encrypted Client Hello (ECH) support, giving you greater privacy by obscuring the domain names you connect to.
Android app developers can upgrade to OkHttp 5.5.0 today to enable ECH and adopt these modern networking best practices → https://t.co/VWfKhr4pJM
Huge thanks to @Jigsaw and our industry partners for accelerating this standard.
Nous recherchons des travailleurs qualifiés pour contribuer au renforcement de l’économie canadienne et répondre aux pénuries de main-d’œuvre dans des secteurs clés.
Voici les catégories d’Entrée express pour lesquelles nous recherchons des professionnels expérimentés pour compléter notre main-d’œuvre:
• les médecins, les chercheurs et les cadres supérieurs ayant une expérience de travail au Canada;
• les professionnels des soins de la santé et des services sociaux;
• les gens de métiers;
• les éducateurs;
• les professionnels dans les domaines des sciences, des technologies, de l’ingénierie et des mathématiques (STIM);
• les professionnels dans le domaine des transports;
• les travailleurs maîtrisant le français.
Découvrez comment fonctionne la sélection axée sur les catégories (ensembles) d’Entrée express : https://t.co/oHcuh2QRcX
NSA today released two technical reports addressing threats to application specific integrated circuits (ASICs) during the design and manufacturing process. Learn about the threats and appropriate mitigations to reduce risk: https://t.co/qzVT2ucwuY
@Na2sim__ Non, la Gen Z veut gagner beaucoup dès le départ tout en faisant le moins d'effort possible. Dopée aux photos Instagram et aux vidéos "Tik Tok" où certains "influenceurs" étalent leurs quotidiens "rêvés".
Tous les connards des plateaux TV français qui appellent à toujours plus de guerre, comme leurs cousins fiers d’être des amateurs à 3 neurones, doivent regarder ces images. Qu’elles les hantent, qu’elles hantent leurs enfants et les enfants de leurs enfants pour 1000 générations.
Welcome to team CISA! This morning, Acting Director Nick Andersen swore in our newest group of employees. Our hiring push continues; explore career options with CISA: https://t.co/arFjUkoBF4
A modern-day legend!
27 years ago, Ronald Sakolsky donated $5,000 to Yin Yuzhen, a Chinese woman fighting desertification. Over two decades, she grew over 50,000 trees with the funds.
Now, Ronald Sakolsky has come to China to witness this miracle with his own eyes.
Alibaba's AliExpress was caught using users' audio systems to track them.
AliExpress wasn't recording users but instead playing a silent sound and measuring how users' specific devices processed it in order to fingerprint them.
But don't worry because Brave stops this.
The #FBI and its partners are warning industrial control system owners and operators about an active cyber threat targeting Siemens S7 Series programmable logic controllers (PLCs) and are recommending immediate steps to reduce the risk of compromise.
The threat actors are using scanning services to find internet-exposed PLCs that are running outdated software or are otherwise poorly protected.
The @FBI, @NSAGov, @CISAgov, @ENERGY and @EPA urge owners and operators of critical infrastructure to proactively check their systems and review our new Joint Cybersecurity Advisory for technical details and key mitigations: https://t.co/YTwrGeLCy2
😊 I also just uploaded a new version of the lecture notes. https://t.co/bpIvdgG8KO (it's still, and perhaps will always be work-in-progress, given the field is moving fast. Any mistakes are mine :) and any feedback is more than welcome :).
NSA and others releases guidance on applying prevention tactics to strengthen defense of U.S-based programmable logic controllers being targeted by cyber actors using AI. Learn more:
https://t.co/HO99aak50Y
#cybersecurity#AI
🚨 ALERTE – PIRATAGE MASSIF DE L’ÉDUCATION NATIONALE
Des millions d’élèves, enseignants et personnels seraient concernés. Après la DGFiP, le même hacker revendique 43 Go de données, soit près de 346 millions de lignes couvrant plus de 20 ans.
Noms, prénoms, dates de naissance, adresses, téléphones, e-mails, données scolaires, affectations, grades et informations administratives seraient exposés.