Star-grade privacy. Zero-data AI security, trusted by 8M+. Made on Earth by humans. #ShapingSecurity

Sarasota
Joined October 2009
We miss you, Steve. Thank you for your remarkable vision. (* February 24, 1955 - † October 5 2011) #SteveJobs
17
15
1
81
25,113
"Wir haben alle FBI-Mitarbeiter"Hacker veröffentlichen brisante Datensätze Namen, Telefonnummern, Adressen und Informationen über Angehörige: Eine Hackergruppe namens "ShinyHunters" behauptet, die US-Sicherheitsbehörde FBI infiltriert zu haben und Daten sämtlicher Beschäftigter gestohlen zu haben. t-online.de/nachrichten/ausl…
1
94
PROTECTSTAR ✪ retweeted
Your phone is about to stop being yours: "Starting in 2027, every Android app developer must register centrally with Google before their software can be installed on any device." keepandroidopen.org
31
122
11
417
14,745
PROTECTSTAR ✪ retweeted
GrapheneOS is under constant attack: State-sponsored smear campaigns connecting GrapheneOS directly with organised crime, activists being arrested for using its features, social media campaigns with the aim to spread lies, fabrications from competing projects and its members, Wikipedia edit wars and now the persistent downvoting and flagging of GrapheneOS' posts on Hacker News (HN).. If it wouldn't be the best solution around, they wouldn't get that much heat!
Nearly all of the recent posts we've made on Hacker News are now being flagged which hides them from everyone by default. You can see this if you log into an account and enable "showdead" in your settings. Please vouch for our posts if you can do that. news.ycombinator.com/threads…
14
168
3
962
25,489
‼️ BREAKING: Revolut handed over customers’ passport copies, verification selfies and full transaction histories to a malicious actor. The actor sent lawful government information-demand emails using a genuine government domain that passed domain authentication. Revolut later concluded they were not authentic. Affected customers were notified on Friday. What may have been disclosed ranges from name, date of birth and home address to account statements, withdrawal records and complete Bitcoin transaction history. The company says it has alerted the agency to the unauthorised mailbox on its domain, blocked the address and begun notifying regulators. It has not named the agency, explained how someone obtained a mailbox there, or given a number of affected customers. ZachXBT, who circulated the notices, believes the incident was limited in size and aimed at high-net-worth users.
463
2,440
843
12,002
3,506,398
PROTECTSTAR ✪ retweeted
Near the end of May 2026, Russia began filtering access to DataPacket IP space with an enforced domain allowlist for HTTP and TLS SNI. GrapheneOS services aren't on the allowlist so we had to switch from DataPacket Frankfurt to Cherry Servers Amsterdam for Russia. That's now getting filtered too. We've fixed it again by using Zare London for connections from Russia instead. That's the final of our sponsored servers in Europe we can use so we'll need to fall back to Xenyth Toronto if they filter it. We're using our own IP space in Toronto so it should work unless they specifically block us. We don't think we'll be blocked directly but we're also unlikely to get placed on the allowlist. That means our services are gradually going to become inaccessible in Russia via the IP space of major cloud services. Our own IP space will still work fine and we don't host any VPN services ourselves. Our website, OS updates, app repository, connectivity checks, network time, network-based location, geocoding and other main services should work again in Russia. It's likely they'll expand to filtering Zare's IP space and then we'll have to use Toronto where we have our own non-anycast IPv4 /24. They use a domain blocklist for most of the internet and an allowlist for many VPS and dedicated server hosting providers to block access to VPN services. It's likely they'll expand to enforcing an allowlist for every major server hosting provider. That's far more aggressive than China's filtering. Our authoritative DNS is hosted via 2 anycast networks using our own ASN and IP space so it hasn't been impacted by this. It's likely we can avoid it for the rest of our services by using our own IP space. If they start filtering netcup IP space, we can make a reverse proxy to those from Toronto. If our services are blocked, connectivity checks can also be set to Standard rather than Disabled to use the Google servers. That'll keep automatic selection of networks with internet working along with automatic captive portal handling and JobSceduler not assuming every network has internet access.
27
87
12
1,175
92,470
PROTECTSTAR ✪ retweeted
📱 Google a sorti un Pixel 11 plus cher mais il est moins bien protégé qu’un Pixel 10 🫠 GrapheneOS a commencé à le porter... en une semaine, une bonne partie du système tournait... Puis ça s’est arrêté ! Une protection importante a disparu Depuis le Pixel 8, la puce pouvait étiqueter la mémoire et couper net une grosse partie des attaques qui passent par des failles classiques @GrapheneOS s’en servait vraiment @Google presque pas Sur le 11, ils l’ont enlevée Ils ont rajouté d’autres trucs pour la brochure Un peu mieux tant que le téléphone est encore verrouillé Un modem moins mauvais Mais dès qu’il est ouvert, une vraie couche de défense n’est plus là ! Bref... Si tu veux un Pixel pour GrapheneOS, prends un 8, un 9 ou un 10 (Le 10 est même moins cher, et cette protection est encore là) On te vend le modèle neuf mais le silicium, lui, vient de reculer 😉 #Privacy
We have a partial port of GrapheneOS to the Pixel 11 series after a week of work on it. We're unable to complete the port due to lack of support for ARM hardware memory tagging in software, firmware and near certainly hardware. It appears Google cut an important security feature to save money. ARM hardware memory tagging (MTE) is used by GrapheneOS across the entire base OS including the kernel and every standard base OS process. It's only temporarily disabled for a few device-specific processes. It greatly improves protection against nearly all remote exploits and many local exploits. Pixel 8 launched with hardware MTE support in October 2023. We integrated it into our hardened_malloc project and began using it across the OS later that month. Android and the Pixel OS never started using it by default. Android Advanced Protection Mode in Android 16 enables it for a few processes. Apple's Memory Integrity Enforcement (MIE) is an always enabled feature on the iPhone 17. It's simply a high quality implementation of MTE using the latest standard extensions. It uses MTE in the most secure mode in the kernel and a large portion of userbase. They did a very good job integrating it. Apple's MIE and Android 16+ AAPM don't use MTE for user installed apps unless those explicitly opt in. GrapheneOS enables it for more apps automatically and has a toggle for users to opt-in for every user installed app. There's a per-app toggle to opt-out for incompatible apps which is uncommon. Neither iOS or Android encourage app developers to opt into MTE and other more aggressive security features used in the base OS. Apple's docs warn developers of performance and stability issues. Even Signal doesn't opt-in. Our approach enables forcing using MTE in the standard allocators regardless. Pixel 11 does have security improvements including moving to post-quantum secure verified boot (ML-DSA) and replacing Samsung Shannon IMS with AOSP IMS. Titan M3 should significantly improve protection against data extraction in Before First Unlock state. It's too bad they ruined it by cutting MTE. Pixel 11 series is a lot more expensive for an incremental improvement to the CPU, the same underpowered GPU and reduced RAM for the Pro base models. They finally caught up to the last generation of Qualcomm cellular radio. It's overpriced, the upgrades aren't impressive and losing MTE is appalling. Compared to the Pixel 11, a Snapdragon 8 Elite Gen 5 has ~40% higher single threaded CPU performance, ~80% higher multi threaded performance, over 100% higher GPU performance and a far better cellular radio. It also finally has MTE. The next gen is what will be in the first Motorola with GrapheneOS. Pixel 9a and earlier (including Nexus devices) were the Android Open Source Project reference devices. Pixel support was removed from AOSP with Android 16. It's now harder to support Pixels than many other devices and massive progress towards open source firmware and driver libraries was discarded. Compared to the stock Pixel OS, GrapheneOS ships AOSP patches months earlier and Linux kernel patches many months earlier. However, we rely on them for firmware and most driver updates. We also want to move to new kernel branches earlier. These things can be improved with our Motorola partnership. We strongly recommend against buying Pixel 11 devices. Pixel 8, 9 and 10 have much better overall security for GrapheneOS. Pixel 10 is cheaper with similar hardware and MTE. Pixel 11's Titan M3 should improve BFU security for users without a strong passphrase, but losing MTE craters AFU security. We haven't determined what to do about this situation. It may be best for us to skip the Pixel 11 series devices. We can shift our focus entirely to the upcoming Motorola devices instead. Pixel 10a was really a 9th gen Pixel, so hopefully the Pixel 11a does the same with 10th gen and includes MTE.
16
114
2
638
31,838
PROTECTSTAR ✪ retweeted
Today, the @FBI and @TheJusticeDept announced the disruption of a global botnet used by Chinese state-sponsored group known as QTFY to target U.S. critical infrastructure. Our investigation attributes QTFY to the Nanjing Xinjiuwei Network Technology Company, which sells stolen data and hacking services to Chinese military and intelligence agencies. Their services include a scanning platform that scours the internet for vulnerable smart devices—like home routers and security cameras—infects thousands of them, and feeds them into a botnet, or a network of machines secretly controlled by the adversary. These platforms hide the origin of PRC-linked cyberattacks. Thanks to the work of @FBISanDiego, FBI Cyber Division, and partners at DOJ—we shut those platforms down 🔗justice.gov/opa/pr/justice-d…
154
637
61
2,408
143,797
PROTECTSTAR ✪ retweeted
Neue Autos = Kontrollapparate auf 4 Reifen?
36
251
8
1,249
39,663
PROTECTSTAR ✪ retweeted
178
4,746
153
14,885
122,506
PROTECTSTAR ✪ retweeted
This will happen frequently as AI becomes smarter and more agentic
In a review of our cybersecurity evaluations, we found three incidents in which a Claude model reached the internet from within or while interacting with a third-party evaluation environment, and then gained unauthorized access to the real systems of three different organizations. Our post describes what happened, how it happened, and what we’re changing. We encourage other AI developers to perform similar reviews. We conducted this review together with @Irregular, one of our evaluation partners, and thank them for the joint investigation and their collaboration on this post. This type of collaboration is increasingly critical to safe, rigorous evaluation of models, and we look forward to continuing to work together on security. anthropic.com/news/investiga…
1,490
2,081
196
19,934
8,144,045
‼️ UPDATE: Volkswagen has now confirmed the app block. VW told German outlet heise it cut off custom ROM users, including GrapheneOS, LineageOS, and /e/OS, from its app after tying it to Google's Play Integrity API. The app still works on years-old Android phones with no security patches, but not on a fully updated GrapheneOS.
‼️ BREAKING: Volkswagen has banned GrapheneOS users from using their app. Users are reporting they can't log in or control their car anymore. Users are confused, saying Volkswagen allows their app to be used on End-of-Life Android versions, but not on fully patched GrapheneOS.
73
303
29
2,398
143,757
PROTECTSTAR ✪ retweeted
Once we have completed our review for security vulnerabilities, we will make the entire codebase of 𝕏 open source, with no exceptions. Moreover, we will invite third party reviewers to examine the system that is running to confirm that the open source code is what is running. Trust through total transparency is the only thing that should be believed.
5,808
11,957
2,347
108,913
7,347,382
PROTECTSTAR ✪ retweeted
I created a font called Ghost Font that only humans can read. Tested it in Fable and GPT 5.6 Sol Ultra and neither was able to decipher it correctly.
1,090
1,553
564
24,488
17,832,614
PROTECTSTAR ✪ retweeted
Orwells Dystopie 1984 wird in der EU Realität! Erst die Chatkontrolle, DSA und jetzt: Von der Leyen bestätigt, dass jeder in der EU eine App der EU für die Identitätsverifizierung nutzen muss, bevor er auf soziale Medien zugreifen & dort posten kann.
1,084
3,467
281
13,277
519,367
PROTECTSTAR ✪ retweeted
Hyundai and Kia added official GrapheneOS support to their apps months before Volkswagen banned GrapheneOS: discuss.grapheneos.org/d/316… Pressure from Volkswagen customers on them can achieve the same thing. There's no legitimate reason to ban GrapheneOS so they'll undo it with pressure. Leave a 1 star review for Volkswagen's apps on the Play Store asking them to stop banning GrapheneOS. Explain it's a far more secure operating system and fully possible for them to verify the hardware, OS and their app on it if they insist on doing it. It's far more secure than anything they allow. Google has misled companies about what the Play Integrity API provides. It doesn't genuinely enforce having a secure device or legitimate app, it only pretends to. It leaves huge security holes open. It enforces Google's business interests and bans having a reasonably secure device with GrapheneOS. Most companies are unlikely to stop using the Play Integrity API but most are willing to start permitting GrapheneOS via hardware attestation with enough pressure. In addition to every user of their app on GrapheneOS leaving a 1 star review on the Play Store, multiple other steps can be taken too. Every GrapheneOS user with one of their cars using the app should file a customer support request. Keep answering them and countering the template responses. Escalate the request higher up. Tell them you want money back for the vehicle due to reduced functionality after the fact and insist on it. They can trivially stop enforcing the anti-security and anti-competitive Play Integrity API or easily add hardware-based verification of GrapheneOS. Link to grapheneos.org/articles/atte… in the customer support request, but don't add any links to Play Store reviews to avoid filtering. A bunch of apps have added explicit support for GrapheneOS due to pressure from our users. Our userbase is rapidly growing and we'll gain the ability to apply massive pressure to companies doing this. We plan to ship a feature for our Info app for people to opt-in to getting asked for their help. GrapheneOS is production quality OS from a non-profit paying around 15 people to work on it. It's far more secure than anything supported by the Play Integrity API. We have an official partnership with Motorola and we'll have more. Just counter template responses and insist on compensation or a fix.
40
320
16
2,711
56,402
PROTECTSTAR ✪ retweeted
Google shipped an out-of-band update to droidguard breaking using RCS with sandboxed Google Play. We've already fixed it and it will be included in the OS release we're making later today (2026062300). That will likely be our first Android 17 to reach our Stable channel. github.com/GrapheneOS/platfo… Our 2026062200 release is currently available in our Alpha channel and will likely be available in our Beta channel soon. It may be solid enough to reach our Stable channel but it won't have the opportunity to get there since our 2026062300 release will replace it once it's built, signed and tested.
16
46
2
600
32,025