Comment by skorp01
2 days ago
This is not an apt analogy.
A couple of the tenets of computing security are:
- Defense in depth - Principle of least privilege
It is a foundational reality that software (especially in unsafe languages) will invariably have vulnerabilities. Defense in depth and least privilege have compounding effects by forcing attackers to chain multiple exploits to achieve a compromised device, rather than a single vulnerability.
GrapheneOS shows how much can be accomplished on top of relatively secure platforms to begin with (AOSP, Pixel Stock OS, etc.) without sacrificing nearly any usability to the end user (barring manufactured hurdles like Play Integrity). It makes it more damning that many "privacy" OSes and devices cannot even meet the baseline level of privacy and security that AOSP provides, but degrade it.
Firmware and driver neglect and the lack of secure element utilization is not "reasonble security for the price".
No comments yet
Contribute on Hacker News ↗