the internet loves grapheneOS, the secure AOSP fork that also makes Android nicely usable without the LLM crap
-
the internet loves grapheneOS, the secure AOSP fork that also makes Android nicely usable without the LLM crap
<yelling from out of frame>
…ah. this just in, grapheneOS has decided to start codegooning core apps and security fixes and now they’re exhaustingly defending doing that
> Many valid issues are reported in between the hallucinations and other nonsense.
oh I see, what a relief
> Attackers are heavily using AI models to discover vulnerabilities and develop exploits. For example, Cellebrite is heavily using it including developing frameworks for reverse engineering and vulnerability discovery.
gotta use the wrongness machine, no sorry, “frontier models” because the coptech adversary is using them and also mythic’s great at finding vulnerabilities til you find out you can do the same job without it. great! https://grapheneos.social/@GrapheneOS/117226938743085364
-
the internet loves grapheneOS, the secure AOSP fork that also makes Android nicely usable without the LLM crap
<yelling from out of frame>
…ah. this just in, grapheneOS has decided to start codegooning core apps and security fixes and now they’re exhaustingly defending doing that
> Many valid issues are reported in between the hallucinations and other nonsense.
oh I see, what a relief
> Attackers are heavily using AI models to discover vulnerabilities and develop exploits. For example, Cellebrite is heavily using it including developing frameworks for reverse engineering and vulnerability discovery.
gotta use the wrongness machine, no sorry, “frontier models” because the coptech adversary is using them and also mythic’s great at finding vulnerabilities til you find out you can do the same job without it. great! https://grapheneos.social/@GrapheneOS/117226938743085364
@zzt
Shit. We need good forks pronto -
the internet loves grapheneOS, the secure AOSP fork that also makes Android nicely usable without the LLM crap
<yelling from out of frame>
…ah. this just in, grapheneOS has decided to start codegooning core apps and security fixes and now they’re exhaustingly defending doing that
> Many valid issues are reported in between the hallucinations and other nonsense.
oh I see, what a relief
> Attackers are heavily using AI models to discover vulnerabilities and develop exploits. For example, Cellebrite is heavily using it including developing frameworks for reverse engineering and vulnerability discovery.
gotta use the wrongness machine, no sorry, “frontier models” because the coptech adversary is using them and also mythic’s great at finding vulnerabilities til you find out you can do the same job without it. great! https://grapheneos.social/@GrapheneOS/117226938743085364
> There's a massive increase in the number of vulnerabilities fixed in each Linux kernel release and many are severe issues
I wonder what new development process in the kernel is famous for introducing code with vulnerabilities. HMMMMM
-
> There's a massive increase in the number of vulnerabilities fixed in each Linux kernel release and many are severe issues
I wonder what new development process in the kernel is famous for introducing code with vulnerabilities. HMMMMM
the privacy industrial complex isn’t beating the charges. no thought just assertions that something is true because a vendor’s marketing made it so
-
the internet loves grapheneOS, the secure AOSP fork that also makes Android nicely usable without the LLM crap
<yelling from out of frame>
…ah. this just in, grapheneOS has decided to start codegooning core apps and security fixes and now they’re exhaustingly defending doing that
> Many valid issues are reported in between the hallucinations and other nonsense.
oh I see, what a relief
> Attackers are heavily using AI models to discover vulnerabilities and develop exploits. For example, Cellebrite is heavily using it including developing frameworks for reverse engineering and vulnerability discovery.
gotta use the wrongness machine, no sorry, “frontier models” because the coptech adversary is using them and also mythic’s great at finding vulnerabilities til you find out you can do the same job without it. great! https://grapheneos.social/@GrapheneOS/117226938743085364
@zzt Can't say this is unexpected, given their constant shilling for corporate user-disempowering design. And overall, the obnoxious attitude. Now huffing asbestos in Compose is only par for the course
-
@zzt
Shit. We need good forks pronto@avesbury_rosetta @zzt we need mobile linux, to start with. Android is a non-open, user-adversarial dead end. It takes a special kind of wrong mindset to be as determined to work on, and advocate for it, as GrapheneOS
-
the privacy industrial complex isn’t beating the charges. no thought just assertions that something is true because a vendor’s marketing made it so
graphene getting the motorola deal was… suspiciously sweet, actually
and all it cost them was everything
like, there’s no reason for them to codegoon out their system apps, most people replace those. the idea is supposed to be that the built-in ones are simple so you can trust them.
but nah, that won’t play for motorola. gotta goon up some more featureful built-in apps pronto! here, use our sweet deal on claude code seats!
-
the internet loves grapheneOS, the secure AOSP fork that also makes Android nicely usable without the LLM crap
<yelling from out of frame>
…ah. this just in, grapheneOS has decided to start codegooning core apps and security fixes and now they’re exhaustingly defending doing that
> Many valid issues are reported in between the hallucinations and other nonsense.
oh I see, what a relief
> Attackers are heavily using AI models to discover vulnerabilities and develop exploits. For example, Cellebrite is heavily using it including developing frameworks for reverse engineering and vulnerability discovery.
gotta use the wrongness machine, no sorry, “frontier models” because the coptech adversary is using them and also mythic’s great at finding vulnerabilities til you find out you can do the same job without it. great! https://grapheneos.social/@GrapheneOS/117226938743085364
@zzt
"It's a new developer we hired"Why did they hire them, if not to slop?
-
> There's a massive increase in the number of vulnerabilities fixed in each Linux kernel release and many are severe issues
I wonder what new development process in the kernel is famous for introducing code with vulnerabilities. HMMMMM
@zzt Humans are about as good when it comes to introducing vulns. However LLMs for 0day discovery works so well that it leaves you with really no choice, there's no LLM-free tool or process that can compete, in the mean time, you are just left with vulnerable software, that's a fact. The very nature of it being fast means vulnerability hunting becomes much easier and you can't compete as humans on the fixing side without using LLMs, there just isnt even enough qualified labor available in the world to manually handle the influx while keeping users safe. Android uses Linux and GrapheneOS didnt exactly chose that and for compatibility reasons it's quite difficult to change. A more durable choice for enforcing better theoretical security boundaries would be rewriting Linux in a safe programming language, however that is also an effort that requires enormous amount of labor that is not really practical. That would however be a viable human's response to it. You unfortunately just can't keep users safe on existing systems that arent designed from ground up to extremely minimize possible attack surface. Android is in a sense but also has many complex attackable systems made only to increase usability and versatility, you could have a human-made secure system that can resist LLM automated vulnerability hunting but it would certainly not have many features and be very crude to use. Unusable secure software isnt really that helpful either.
-
graphene getting the motorola deal was… suspiciously sweet, actually
and all it cost them was everything
like, there’s no reason for them to codegoon out their system apps, most people replace those. the idea is supposed to be that the built-in ones are simple so you can trust them.
but nah, that won’t play for motorola. gotta goon up some more featureful built-in apps pronto! here, use our sweet deal on claude code seats!
> That increase is despite adding features slowly down a lot. A massive monolithic kernel written in a memory unsafe language is a bigger liability than ever.
rust in the kernel is in the corner like “am I a joke to you”
it’s uhhh real rich that the AOSP fork suddenly has a problem with a massive monolithic kernel written in a memory unsafe language now that LLMs are on the table
and the solution is just LLMs, only that. not fixing the massive, monolithic, or unsafe language bits at all. making them much worse, in fact. thanks!
-
the internet loves grapheneOS, the secure AOSP fork that also makes Android nicely usable without the LLM crap
<yelling from out of frame>
…ah. this just in, grapheneOS has decided to start codegooning core apps and security fixes and now they’re exhaustingly defending doing that
> Many valid issues are reported in between the hallucinations and other nonsense.
oh I see, what a relief
> Attackers are heavily using AI models to discover vulnerabilities and develop exploits. For example, Cellebrite is heavily using it including developing frameworks for reverse engineering and vulnerability discovery.
gotta use the wrongness machine, no sorry, “frontier models” because the coptech adversary is using them and also mythic’s great at finding vulnerabilities til you find out you can do the same job without it. great! https://grapheneos.social/@GrapheneOS/117226938743085364
@zzt the moment GrapheneOS said you needed a Google phone to “deGoogle” your life it was clear that’s all a psyop
-
@zzt Humans are about as good when it comes to introducing vulns. However LLMs for 0day discovery works so well that it leaves you with really no choice, there's no LLM-free tool or process that can compete, in the mean time, you are just left with vulnerable software, that's a fact. The very nature of it being fast means vulnerability hunting becomes much easier and you can't compete as humans on the fixing side without using LLMs, there just isnt even enough qualified labor available in the world to manually handle the influx while keeping users safe. Android uses Linux and GrapheneOS didnt exactly chose that and for compatibility reasons it's quite difficult to change. A more durable choice for enforcing better theoretical security boundaries would be rewriting Linux in a safe programming language, however that is also an effort that requires enormous amount of labor that is not really practical. That would however be a viable human's response to it. You unfortunately just can't keep users safe on existing systems that arent designed from ground up to extremely minimize possible attack surface. Android is in a sense but also has many complex attackable systems made only to increase usability and versatility, you could have a human-made secure system that can resist LLM automated vulnerability hunting but it would certainly not have many features and be very crude to use. Unusable secure software isnt really that helpful either.
@laura_ge yeah I’m not reading all that, stay out of my replies codegooner
-
@zzt
"It's a new developer we hired"Why did they hire them, if not to slop?
-
@avesbury_rosetta @zzt we need mobile linux, to start with. Android is a non-open, user-adversarial dead end. It takes a special kind of wrong mindset to be as determined to work on, and advocate for it, as GrapheneOS
@ariarhythmic @avesbury_rosetta @zzt the issue is that Graphene is (or was) the most secure OS, at least in the mobile space. The one activists use because not even the police can break its security.
Meanwhile Linux is less secure than even macOS and Windows, I like it, I use it on all of my PCs, but not for *security* reasons.
-
> That increase is despite adding features slowly down a lot. A massive monolithic kernel written in a memory unsafe language is a bigger liability than ever.
rust in the kernel is in the corner like “am I a joke to you”
it’s uhhh real rich that the AOSP fork suddenly has a problem with a massive monolithic kernel written in a memory unsafe language now that LLMs are on the table
and the solution is just LLMs, only that. not fixing the massive, monolithic, or unsafe language bits at all. making them much worse, in fact. thanks!
@zzt FUCK FUCK FUCK FUCK FUCK FUCK FUCK FUCK FUCK FUCK FUCK FUCK
/me inhales
FUCK FUCK FUCK FUCK FUCK FUCK FUCK FUCK FUCK FUCK FUCK FUCK FUCK FUCK FUCK FUCK FUCK FUCK FUCK FUCK
god fucking dammit graphene
-
the internet loves grapheneOS, the secure AOSP fork that also makes Android nicely usable without the LLM crap
<yelling from out of frame>
…ah. this just in, grapheneOS has decided to start codegooning core apps and security fixes and now they’re exhaustingly defending doing that
> Many valid issues are reported in between the hallucinations and other nonsense.
oh I see, what a relief
> Attackers are heavily using AI models to discover vulnerabilities and develop exploits. For example, Cellebrite is heavily using it including developing frameworks for reverse engineering and vulnerability discovery.
gotta use the wrongness machine, no sorry, “frontier models” because the coptech adversary is using them and also mythic’s great at finding vulnerabilities til you find out you can do the same job without it. great! https://grapheneos.social/@GrapheneOS/117226938743085364
if you’re in infosec or pretending to be in infosec and you’re about to start gooning in this thread with the contents of anthropic’s marketing campaign for mythic, a model whose results are shit: reconsider
reconsider a lot of things, really
-
@zzt FUCK FUCK FUCK FUCK FUCK FUCK FUCK FUCK FUCK FUCK FUCK FUCK
/me inhales
FUCK FUCK FUCK FUCK FUCK FUCK FUCK FUCK FUCK FUCK FUCK FUCK FUCK FUCK FUCK FUCK FUCK FUCK FUCK FUCK
god fucking dammit graphene
@aspensmonster that’s my inner monologue too
-
-
@ariarhythmic @avesbury_rosetta @zzt the issue is that Graphene is (or was) the most secure OS, at least in the mobile space. The one activists use because not even the police can break its security.
Meanwhile Linux is less secure than even macOS and Windows, I like it, I use it on all of my PCs, but not for *security* reasons.
@hazelnot @avesbury_rosetta @zzt The Linux ecosystem has the potential for it, though; it just needs to be realized with openness, and empowering users in mind instead of the way Google decided to do it.
-
if you’re in infosec or pretending to be in infosec and you’re about to start gooning in this thread with the contents of anthropic’s marketing campaign for mythic, a model whose results are shit: reconsider
reconsider a lot of things, really
@zzt I have zero idea what you're talking about but I am here for the piss and fire.