Skip to content
  • Hjem
  • Seneste
  • Etiketter
  • Populære
  • Verden
  • Bruger
  • Grupper
Temaer
  • Light
  • Brite
  • Cerulean
  • Cosmo
  • Flatly
  • Journal
  • Litera
  • Lumen
  • Lux
  • Materia
  • Minty
  • Morph
  • Pulse
  • Sandstone
  • Simplex
  • Sketchy
  • Spacelab
  • United
  • Yeti
  • Zephyr
  • Dark
  • Cyborg
  • Darkly
  • Quartz
  • Slate
  • Solar
  • Superhero
  • Vapor

  • Default (No Skin)
  • No Skin
Kollaps
FARVEL BIG TECH
  1. Forside
  2. Ikke-kategoriseret
  3. Android has USB data and a large number of USB drivers available including while locked.

Android has USB data and a large number of USB drivers available including while locked.

Planlagt Fastgjort Låst Flyttet Ikke-kategoriseret
29 Indlæg 12 Posters 0 Visninger
  • Ældste til nyeste
  • Nyeste til ældste
  • Most Votes
Svar
  • Svar som emne
Login for at svare
Denne tråd er blevet slettet. Kun brugere med emne behandlings privilegier kan se den.
  • agowa338@chaos.socialA agowa338@chaos.social

    @GrapheneOS

    Hmm, wonder if you can plug a usb to ethernet adapter in and if the phone will automatically switch over to it while in charging-only mode.

    grapheneos@grapheneos.socialG This user is from outside of this forum
    grapheneos@grapheneos.socialG This user is from outside of this forum
    grapheneos@grapheneos.social
    wrote sidst redigeret af
    #12

    @agowa338 Yes, it has all of the USB peripheral functionality enabled. You can also plug in a display and it will connect to it, although current Android will prompt before mirroring the screen to it.

    Android's main USB menu only controls the USB gadget mode and has nothing to do with the device Android is running on using USB peripherals itself. iOS works similarly.

    Many users misunderstand Android's standard approach.

    See the replies to https://x.com/linuxuser1996/status/2086757738055389637 for why we posted this thread.

    agowa338@chaos.socialA 1 Reply Last reply
    0
    • grapheneos@grapheneos.socialG grapheneos@grapheneos.social

      @agowa338 Yes, it has all of the USB peripheral functionality enabled. You can also plug in a display and it will connect to it, although current Android will prompt before mirroring the screen to it.

      Android's main USB menu only controls the USB gadget mode and has nothing to do with the device Android is running on using USB peripherals itself. iOS works similarly.

      Many users misunderstand Android's standard approach.

      See the replies to https://x.com/linuxuser1996/status/2086757738055389637 for why we posted this thread.

      agowa338@chaos.socialA This user is from outside of this forum
      agowa338@chaos.socialA This user is from outside of this forum
      agowa338@chaos.social
      wrote sidst redigeret af
      #13

      @GrapheneOS

      Also I don't have an X account (anymore) and can't see your reply (nor can I enlarge the picture either).

      Wonder if it switches the data from cellular or wifi over to lan automatically though.

      grapheneos@grapheneos.socialG 1 Reply Last reply
      0
      • grapheneos@grapheneos.socialG grapheneos@grapheneos.social

        @AndyGravesGrimeSoul Yes, wireless charging still works with the USB-C port mode set to Off. Setting it to charging-only provides most of the security value but we decided to offer the ability to fully disable it in case there are ever USB-PD vulnerabilities in the USB controller. USB-PD is a secondary form of limited data which could be used to exploit the USB controller itself, turn on USB data and then reach the remaining attack surface for USB in the kernel despite drivers being off.

        andygravesgrimesoul@mastodon.socialA This user is from outside of this forum
        andygravesgrimesoul@mastodon.socialA This user is from outside of this forum
        andygravesgrimesoul@mastodon.social
        wrote sidst redigeret af
        #14

        @GrapheneOS I have a question that might not have an answer, in terms of offense and defense in this context, do you think one will eventually gain a mostly permanent lead? Or will it always be a game of cat and mouse?

        snosrapkungfu@mastodon.socialS A 2 Replies Last reply
        0
        • uninterestednerd@mastodon.socialU uninterestednerd@mastodon.social

          @AndyGravesGrimeSoul @GrapheneOS yes, wireless charging works independently from USB regardless of settings. On GrapheneOS, there's an "Off" option for the USBC port that even blocks charging, so wireless would really be the only way to charge your phone while it's booted into the os.

          grapheneos@grapheneos.socialG This user is from outside of this forum
          grapheneos@grapheneos.socialG This user is from outside of this forum
          grapheneos@grapheneos.social
          wrote sidst redigeret af
          #15

          @UninterestedNerd @AndyGravesGrimeSoul Setting it to Off disables USB including charging in the regular OS boot mode.

          It will still charge in the special OS boot modes: charging, recovery, fastbootd and rescue. Charging mode is what boots when you plug the device into a charger while it's turned off and shows the battery percentage on the screen.

          It can also still charge while powered off and in the firmware boot modes: fastboot mode and boot ROM recovery mode.

          It can't brick the device.

          uninterestednerd@mastodon.socialU 1 Reply Last reply
          0
          • agowa338@chaos.socialA agowa338@chaos.social

            @GrapheneOS

            Also I don't have an X account (anymore) and can't see your reply (nor can I enlarge the picture either).

            Wonder if it switches the data from cellular or wifi over to lan automatically though.

            grapheneos@grapheneos.socialG This user is from outside of this forum
            grapheneos@grapheneos.socialG This user is from outside of this forum
            grapheneos@grapheneos.social
            wrote sidst redigeret af
            #16

            @agowa338 You can see many of the replies at https://nitter.net/linuxuser1996/status/2086757738055389637. We wrote several responses and copy-pasted those to dozens of the replies. Most of the people who replied said they have the feature on their standard Android device when they don't. They believe the standard Android USB menu is the same thing when it isn't at all. Android Advanced Protection Mode added in Android 16 is similar to the software part of our feature but not as good and it's missing the hardware-level blocking.

            1 Reply Last reply
            0
            • andygravesgrimesoul@mastodon.socialA andygravesgrimesoul@mastodon.social

              @GrapheneOS I have a question that might not have an answer, in terms of offense and defense in this context, do you think one will eventually gain a mostly permanent lead? Or will it always be a game of cat and mouse?

              snosrapkungfu@mastodon.socialS This user is from outside of this forum
              snosrapkungfu@mastodon.socialS This user is from outside of this forum
              snosrapkungfu@mastodon.social
              wrote sidst redigeret af
              #17

              @AndyGravesGrimeSoul @GrapheneOS I think making use of tech like pam duress whereby one can enter a 'trash everything' pin instead of the normal pin, on the lockscreen has mileage. not sure if anyone's tried that with graphene.

              grapheneos@grapheneos.socialG 1 Reply Last reply
              0
              • grapheneos@grapheneos.socialG grapheneos@grapheneos.social

                GrapheneOS blocks new USB connections while locked by default at both a software and hardware level. It can be enabled while unlocked too. It can even be set to fully disable USB while booted including USB-PD and other charging functionality. More info:

                https://grapheneos.org/features#usb-c-port-and-pogo-pins-control

                grapheneos@grapheneos.socialG This user is from outside of this forum
                grapheneos@grapheneos.socialG This user is from outside of this forum
                grapheneos@grapheneos.social
                wrote sidst redigeret af
                #18

                USB vulnerabilities are widely exploited. It's used against journalists, activists, dissidents and others at border crossings, protests and elsewhere. Android 16+ has opt-in protection but it's far weaker than our default and blocks installing apps from outside the Play Store.

                1 Reply Last reply
                0
                • snosrapkungfu@mastodon.socialS snosrapkungfu@mastodon.social

                  @AndyGravesGrimeSoul @GrapheneOS I think making use of tech like pam duress whereby one can enter a 'trash everything' pin instead of the normal pin, on the lockscreen has mileage. not sure if anyone's tried that with graphene.

                  grapheneos@grapheneos.socialG This user is from outside of this forum
                  grapheneos@grapheneos.socialG This user is from outside of this forum
                  grapheneos@grapheneos.social
                  wrote sidst redigeret af
                  #19

                  @snosrapkungfu @AndyGravesGrimeSoul GrapheneOS has a duress PIN/password feature:

                  https://grapheneos.org/features#duress

                  It can be entered anywhere the PIN/password is requested by the OS across every profile on the device. It can also be entered as a 2nd factor fingerprint PIN which is another feature added by GrapheneOS.

                  It near instantly wipes key material needed to derive key encryption keys. It can't be bypassed by imaging and restoring SSD data due to secure element and hardware keystore integration.

                  andygravesgrimesoul@mastodon.socialA 1 Reply Last reply
                  0
                  • grapheneos@grapheneos.socialG grapheneos@grapheneos.social

                    @snosrapkungfu @AndyGravesGrimeSoul GrapheneOS has a duress PIN/password feature:

                    https://grapheneos.org/features#duress

                    It can be entered anywhere the PIN/password is requested by the OS across every profile on the device. It can also be entered as a 2nd factor fingerprint PIN which is another feature added by GrapheneOS.

                    It near instantly wipes key material needed to derive key encryption keys. It can't be bypassed by imaging and restoring SSD data due to secure element and hardware keystore integration.

                    andygravesgrimesoul@mastodon.socialA This user is from outside of this forum
                    andygravesgrimesoul@mastodon.socialA This user is from outside of this forum
                    andygravesgrimesoul@mastodon.social
                    wrote sidst redigeret af
                    #20

                    @GrapheneOS @snosrapkungfu just curious, could GrapheneOS ever get Argon2id for the KDF? I know it's be no small task but it'd be amazing somewhere down the road.

                    1 Reply Last reply
                    0
                    • grapheneos@grapheneos.socialG grapheneos@grapheneos.social

                      @UninterestedNerd @AndyGravesGrimeSoul Setting it to Off disables USB including charging in the regular OS boot mode.

                      It will still charge in the special OS boot modes: charging, recovery, fastbootd and rescue. Charging mode is what boots when you plug the device into a charger while it's turned off and shows the battery percentage on the screen.

                      It can also still charge while powered off and in the firmware boot modes: fastboot mode and boot ROM recovery mode.

                      It can't brick the device.

                      uninterestednerd@mastodon.socialU This user is from outside of this forum
                      uninterestednerd@mastodon.socialU This user is from outside of this forum
                      uninterestednerd@mastodon.social
                      wrote sidst redigeret af
                      #21

                      @GrapheneOS @AndyGravesGrimeSoul thanks for the clarification, I didn't know about all those different modes it could charge in. The off setting has a string that mentions charging the device while powered off, I forgot to mention that.

                      1 Reply Last reply
                      0
                      • andygravesgrimesoul@mastodon.socialA andygravesgrimesoul@mastodon.social

                        @GrapheneOS I have a question that might not have an answer, in terms of offense and defense in this context, do you think one will eventually gain a mostly permanent lead? Or will it always be a game of cat and mouse?

                        A This user is from outside of this forum
                        A This user is from outside of this forum
                        a53bdb@mastodon.social
                        wrote sidst redigeret af
                        #22

                        @AndyGravesGrimeSoul @GrapheneOS

                        When the Cellebrite Premium support matrix is leaked in 2024, they can only exploit a specific version of GrapheneOS that is released in 2022. When it’s leaked again in 2025, they had no progress. And GrapheneOS has internal access to support matrix, it is said that it still has no progress.

                        https://discuss.grapheneos.org/d/27698-new-cellebrite-capability-obtained-in-teams-meeting/

                        https://discuss.grapheneos.org/d/20968-grapheneos-still-not-vulnerable-to-cellebrite-device-exploitation-as-of-feb-2025/

                        https://discuss.grapheneos.org/d/14344-cellebrite-premium-july-2024-documentation/

                        grapheneos@grapheneos.socialG 1 Reply Last reply
                        0
                        • grapheneos@grapheneos.socialG grapheneos@grapheneos.social

                          @AndyGravesGrimeSoul Yes, wireless charging still works with the USB-C port mode set to Off. Setting it to charging-only provides most of the security value but we decided to offer the ability to fully disable it in case there are ever USB-PD vulnerabilities in the USB controller. USB-PD is a secondary form of limited data which could be used to exploit the USB controller itself, turn on USB data and then reach the remaining attack surface for USB in the kernel despite drivers being off.

                          mancube@pnw.zoneM This user is from outside of this forum
                          mancube@pnw.zoneM This user is from outside of this forum
                          mancube@pnw.zone
                          wrote sidst redigeret af
                          #23

                          @GrapheneOS
                          could this become a tile like WiFi, location, hotspot etc? it'd be nice to be able to toggle USB settings more easily than digging for it in menus

                          the couple times a month that I drive and want to use android auto I have to go digging 😥
                          @AndyGravesGrimeSoul

                          xav@fosstodon.orgX 1 Reply Last reply
                          0
                          • A a53bdb@mastodon.social

                            @AndyGravesGrimeSoul @GrapheneOS

                            When the Cellebrite Premium support matrix is leaked in 2024, they can only exploit a specific version of GrapheneOS that is released in 2022. When it’s leaked again in 2025, they had no progress. And GrapheneOS has internal access to support matrix, it is said that it still has no progress.

                            https://discuss.grapheneos.org/d/27698-new-cellebrite-capability-obtained-in-teams-meeting/

                            https://discuss.grapheneos.org/d/20968-grapheneos-still-not-vulnerable-to-cellebrite-device-exploitation-as-of-feb-2025/

                            https://discuss.grapheneos.org/d/14344-cellebrite-premium-july-2024-documentation/

                            grapheneos@grapheneos.socialG This user is from outside of this forum
                            grapheneos@grapheneos.socialG This user is from outside of this forum
                            grapheneos@grapheneos.social
                            wrote sidst redigeret af
                            #24

                            @a53bdb @AndyGravesGrimeSoul Note they lost their ability to extract data from GrapheneOS devices when provided with the PIN/password in late 2024. It took months for the documentation to be updated to clarify the capability had been lost for newer versions. We don't expect that to remain the case since the attack surface for an unlocked device where they can use developer options including Android Debug Bridge is massive.

                            1 Reply Last reply
                            0
                            • grapheneos@grapheneos.socialG grapheneos@grapheneos.social

                              Android has USB data and a large number of USB drivers available including while locked. Plug in a mouse, keyboard, external drive or other USB accessory and you'll see that's the case. When Android says charging-only, it means not allowing file transfer.

                              gael_rostang@mastodon.socialG This user is from outside of this forum
                              gael_rostang@mastodon.socialG This user is from outside of this forum
                              gael_rostang@mastodon.social
                              wrote sidst redigeret af
                              #25

                              @GrapheneOS
                              ❌️ charging only
                              ✅️ charging mostly

                              1 Reply Last reply
                              0
                              • mancube@pnw.zoneM mancube@pnw.zone

                                @GrapheneOS
                                could this become a tile like WiFi, location, hotspot etc? it'd be nice to be able to toggle USB settings more easily than digging for it in menus

                                the couple times a month that I drive and want to use android auto I have to go digging 😥
                                @AndyGravesGrimeSoul

                                xav@fosstodon.orgX This user is from outside of this forum
                                xav@fosstodon.orgX This user is from outside of this forum
                                xav@fosstodon.org
                                wrote sidst redigeret af
                                #26

                                @mancube @GrapheneOS @AndyGravesGrimeSoul yes an USB mode tile is a nice idea

                                1 Reply Last reply
                                0
                                • andromxda@infosec.spaceA This user is from outside of this forum
                                  andromxda@infosec.spaceA This user is from outside of this forum
                                  andromxda@infosec.space
                                  wrote sidst redigeret af
                                  #27

                                  @c_th1 Yes, this disables all data transfer capabilities in the USB controller. Unless you're worried about forensics companies somehow exploiting the firmware of the USB controller itself, which is unlikely, but not impossible, considering that some companies seem to specifically hire people with knowledge and understanding of the USB protocol/hardware, as well as GrapheneOS.

                                  https://grapheneos.social/@GrapheneOS/117005499941456851

                                  If you're really worried about these kinds of things, you can disable USB completely and use wireless charging to charge your device. Or you can at least disable USB completely when you're at an airport, or crossing a border.

                                  polixgen@cyberfurz.socialP 1 Reply Last reply
                                  0
                                  • grapheneos@grapheneos.socialG grapheneos@grapheneos.social

                                    Exploiting Linux kernel USB vulnerabilities is how exploit tools from Cellebrite and other companies extract data from Android devices in practice. They also exploit firmware bugs in other boot modes but we convinced Google to eliminate most of that attack surface for Pixels.

                                    L This user is from outside of this forum
                                    L This user is from outside of this forum
                                    libreovergratis@mastodon.social
                                    wrote sidst redigeret af
                                    #28

                                    @GrapheneOS
                                    "but we convinced Google to eliminate most of that attack surface for Pixels."

                                    Do you mean to say, someone on the GrapheneOS team reached out to someone at Google, and asked them to fix a known backdoor actively exploited by law enforcement, and google just complied?

                                    This seems like a completely out of character move for Google.

                                    Why would they help the GOS foundation in any way?

                                    1 Reply Last reply
                                    0
                                    • andromxda@infosec.spaceA andromxda@infosec.space

                                      @c_th1 Yes, this disables all data transfer capabilities in the USB controller. Unless you're worried about forensics companies somehow exploiting the firmware of the USB controller itself, which is unlikely, but not impossible, considering that some companies seem to specifically hire people with knowledge and understanding of the USB protocol/hardware, as well as GrapheneOS.

                                      https://grapheneos.social/@GrapheneOS/117005499941456851

                                      If you're really worried about these kinds of things, you can disable USB completely and use wireless charging to charge your device. Or you can at least disable USB completely when you're at an airport, or crossing a border.

                                      polixgen@cyberfurz.socialP This user is from outside of this forum
                                      polixgen@cyberfurz.socialP This user is from outside of this forum
                                      polixgen@cyberfurz.social
                                      wrote sidst redigeret af
                                      #29

                                      isn't shutting down or restarting the phone safer option?

                                      1 Reply Last reply
                                      0
                                      • pelle@veganism.socialP pelle@veganism.social shared this topic
                                      Svar
                                      • Svar som emne
                                      Login for at svare
                                      • Ældste til nyeste
                                      • Nyeste til ældste
                                      • Most Votes


                                      • Log ind

                                      • Har du ikke en konto? Tilmeld

                                      • Login or register to search.
                                      Powered by NodeBB Contributors
                                      Graciously hosted by data.coop
                                      • First post
                                        Last post
                                      0
                                      • Hjem
                                      • Seneste
                                      • Etiketter
                                      • Populære
                                      • Verden
                                      • Bruger
                                      • Grupper