Skip to content
  • Hjem
  • Seneste
  • Etiketter
  • Populære
  • Verden
  • Bruger
  • Grupper
Temaer
  • Light
  • Brite
  • Cerulean
  • Cosmo
  • Flatly
  • Journal
  • Litera
  • Lumen
  • Lux
  • Materia
  • Minty
  • Morph
  • Pulse
  • Sandstone
  • Simplex
  • Sketchy
  • Spacelab
  • United
  • Yeti
  • Zephyr
  • Dark
  • Cyborg
  • Darkly
  • Quartz
  • Slate
  • Solar
  • Superhero
  • Vapor

  • Default (No Skin)
  • No Skin
Kollaps
FARVEL BIG TECH
  1. Forside
  2. Ikke-kategoriseret
  3. the internet loves grapheneOS, the secure AOSP fork that also makes Android nicely usable without the LLM crap

the internet loves grapheneOS, the secure AOSP fork that also makes Android nicely usable without the LLM crap

Planlagt Fastgjort Låst Flyttet Ikke-kategoriseret
66 Indlæg 37 Posters 9 Visninger
  • Ældste til nyeste
  • Nyeste til ældste
  • Most Votes
Svar
  • Svar som emne
Login for at svare
Denne tråd er blevet slettet. Kun brugere med emne behandlings privilegier kan se den.
  • zzt@mas.toZ zzt@mas.to

    the internet loves grapheneOS, the secure AOSP fork that also makes Android nicely usable without the LLM crap

    <yelling from out of frame>

    …ah. this just in, grapheneOS has decided to start codegooning core apps and security fixes and now they’re exhaustingly defending doing that

    > Many valid issues are reported in between the hallucinations and other nonsense.

    oh I see, what a relief

    > Attackers are heavily using AI models to discover vulnerabilities and develop exploits. For example, Cellebrite is heavily using it including developing frameworks for reverse engineering and vulnerability discovery.

    gotta use the wrongness machine, no sorry, “frontier models” because the coptech adversary is using them and also mythic’s great at finding vulnerabilities til you find out you can do the same job without it. great! https://grapheneos.social/@GrapheneOS/117226938743085364

    zzt@mas.toZ This user is from outside of this forum
    zzt@mas.toZ This user is from outside of this forum
    zzt@mas.to
    wrote sidst redigeret af
    #3

    > There's a massive increase in the number of vulnerabilities fixed in each Linux kernel release and many are severe issues

    I wonder what new development process in the kernel is famous for introducing code with vulnerabilities. HMMMMM

    zzt@mas.toZ laura_ge@eldritch.cafeL 2 Replies Last reply
    0
    • zzt@mas.toZ zzt@mas.to

      > There's a massive increase in the number of vulnerabilities fixed in each Linux kernel release and many are severe issues

      I wonder what new development process in the kernel is famous for introducing code with vulnerabilities. HMMMMM

      zzt@mas.toZ This user is from outside of this forum
      zzt@mas.toZ This user is from outside of this forum
      zzt@mas.to
      wrote sidst redigeret af
      #4

      the privacy industrial complex isn’t beating the charges. no thought just assertions that something is true because a vendor’s marketing made it so

      zzt@mas.toZ 1 Reply Last reply
      0
      • zzt@mas.toZ zzt@mas.to

        the internet loves grapheneOS, the secure AOSP fork that also makes Android nicely usable without the LLM crap

        <yelling from out of frame>

        …ah. this just in, grapheneOS has decided to start codegooning core apps and security fixes and now they’re exhaustingly defending doing that

        > Many valid issues are reported in between the hallucinations and other nonsense.

        oh I see, what a relief

        > Attackers are heavily using AI models to discover vulnerabilities and develop exploits. For example, Cellebrite is heavily using it including developing frameworks for reverse engineering and vulnerability discovery.

        gotta use the wrongness machine, no sorry, “frontier models” because the coptech adversary is using them and also mythic’s great at finding vulnerabilities til you find out you can do the same job without it. great! https://grapheneos.social/@GrapheneOS/117226938743085364

        ariarhythmic@ohai.socialA This user is from outside of this forum
        ariarhythmic@ohai.socialA This user is from outside of this forum
        ariarhythmic@ohai.social
        wrote sidst redigeret af
        #5

        @zzt Can't say this is unexpected, given their constant shilling for corporate user-disempowering design. And overall, the obnoxious attitude. Now huffing asbestos in Compose is only par for the course

        1 Reply Last reply
        0
        • avesbury_rosetta@wetdry.worldA avesbury_rosetta@wetdry.world

          @zzt
          Shit. We need good forks pronto

          ariarhythmic@ohai.socialA This user is from outside of this forum
          ariarhythmic@ohai.socialA This user is from outside of this forum
          ariarhythmic@ohai.social
          wrote sidst redigeret af
          #6

          @avesbury_rosetta @zzt we need mobile linux, to start with. Android is a non-open, user-adversarial dead end. It takes a special kind of wrong mindset to be as determined to work on, and advocate for it, as GrapheneOS

          hazelnot@sunbeam.cityH lunadragofelis@void.lgbtL 2 Replies Last reply
          0
          • zzt@mas.toZ zzt@mas.to

            the privacy industrial complex isn’t beating the charges. no thought just assertions that something is true because a vendor’s marketing made it so

            zzt@mas.toZ This user is from outside of this forum
            zzt@mas.toZ This user is from outside of this forum
            zzt@mas.to
            wrote sidst redigeret af
            #7

            graphene getting the motorola deal was… suspiciously sweet, actually

            and all it cost them was everything

            like, there’s no reason for them to codegoon out their system apps, most people replace those. the idea is supposed to be that the built-in ones are simple so you can trust them.

            but nah, that won’t play for motorola. gotta goon up some more featureful built-in apps pronto! here, use our sweet deal on claude code seats!

            zzt@mas.toZ 1 Reply Last reply
            0
            • zzt@mas.toZ zzt@mas.to

              the internet loves grapheneOS, the secure AOSP fork that also makes Android nicely usable without the LLM crap

              <yelling from out of frame>

              …ah. this just in, grapheneOS has decided to start codegooning core apps and security fixes and now they’re exhaustingly defending doing that

              > Many valid issues are reported in between the hallucinations and other nonsense.

              oh I see, what a relief

              > Attackers are heavily using AI models to discover vulnerabilities and develop exploits. For example, Cellebrite is heavily using it including developing frameworks for reverse engineering and vulnerability discovery.

              gotta use the wrongness machine, no sorry, “frontier models” because the coptech adversary is using them and also mythic’s great at finding vulnerabilities til you find out you can do the same job without it. great! https://grapheneos.social/@GrapheneOS/117226938743085364

              xinit@mastodon.coffeeX This user is from outside of this forum
              xinit@mastodon.coffeeX This user is from outside of this forum
              xinit@mastodon.coffee
              wrote sidst redigeret af
              #8

              @zzt
              "It's a new developer we hired"

              Why did they hire them, if not to slop?

              pikesley@mastodon.me.ukP dnkboston@apobangpo.spaceD 2 Replies Last reply
              0
              • zzt@mas.toZ zzt@mas.to

                > There's a massive increase in the number of vulnerabilities fixed in each Linux kernel release and many are severe issues

                I wonder what new development process in the kernel is famous for introducing code with vulnerabilities. HMMMMM

                laura_ge@eldritch.cafeL This user is from outside of this forum
                laura_ge@eldritch.cafeL This user is from outside of this forum
                laura_ge@eldritch.cafe
                wrote sidst redigeret af
                #9

                @zzt Humans are about as good when it comes to introducing vulns. However LLMs for 0day discovery works so well that it leaves you with really no choice, there's no LLM-free tool or process that can compete, in the mean time, you are just left with vulnerable software, that's a fact. The very nature of it being fast means vulnerability hunting becomes much easier and you can't compete as humans on the fixing side without using LLMs, there just isnt even enough qualified labor available in the world to manually handle the influx while keeping users safe. Android uses Linux and GrapheneOS didnt exactly chose that and for compatibility reasons it's quite difficult to change. A more durable choice for enforcing better theoretical security boundaries would be rewriting Linux in a safe programming language, however that is also an effort that requires enormous amount of labor that is not really practical. That would however be a viable human's response to it. You unfortunately just can't keep users safe on existing systems that arent designed from ground up to extremely minimize possible attack surface. Android is in a sense but also has many complex attackable systems made only to increase usability and versatility, you could have a human-made secure system that can resist LLM automated vulnerability hunting but it would certainly not have many features and be very crude to use. Unusable secure software isnt really that helpful either.

                zzt@mas.toZ 1 Reply Last reply
                0
                • zzt@mas.toZ zzt@mas.to

                  graphene getting the motorola deal was… suspiciously sweet, actually

                  and all it cost them was everything

                  like, there’s no reason for them to codegoon out their system apps, most people replace those. the idea is supposed to be that the built-in ones are simple so you can trust them.

                  but nah, that won’t play for motorola. gotta goon up some more featureful built-in apps pronto! here, use our sweet deal on claude code seats!

                  zzt@mas.toZ This user is from outside of this forum
                  zzt@mas.toZ This user is from outside of this forum
                  zzt@mas.to
                  wrote sidst redigeret af
                  #10

                  > That increase is despite adding features slowly down a lot. A massive monolithic kernel written in a memory unsafe language is a bigger liability than ever.

                  rust in the kernel is in the corner like “am I a joke to you”

                  it’s uhhh real rich that the AOSP fork suddenly has a problem with a massive monolithic kernel written in a memory unsafe language now that LLMs are on the table

                  and the solution is just LLMs, only that. not fixing the massive, monolithic, or unsafe language bits at all. making them much worse, in fact. thanks!

                  aspensmonster@tenforward.socialA zzt@mas.toZ derivativethoughts@mastodon.socialD 3 Replies Last reply
                  0
                  • zzt@mas.toZ zzt@mas.to

                    the internet loves grapheneOS, the secure AOSP fork that also makes Android nicely usable without the LLM crap

                    <yelling from out of frame>

                    …ah. this just in, grapheneOS has decided to start codegooning core apps and security fixes and now they’re exhaustingly defending doing that

                    > Many valid issues are reported in between the hallucinations and other nonsense.

                    oh I see, what a relief

                    > Attackers are heavily using AI models to discover vulnerabilities and develop exploits. For example, Cellebrite is heavily using it including developing frameworks for reverse engineering and vulnerability discovery.

                    gotta use the wrongness machine, no sorry, “frontier models” because the coptech adversary is using them and also mythic’s great at finding vulnerabilities til you find out you can do the same job without it. great! https://grapheneos.social/@GrapheneOS/117226938743085364

                    dmitrylitosh@mastodon.socialD This user is from outside of this forum
                    dmitrylitosh@mastodon.socialD This user is from outside of this forum
                    dmitrylitosh@mastodon.social
                    wrote sidst redigeret af
                    #11

                    @zzt the moment GrapheneOS said you needed a Google phone to “deGoogle” your life it was clear that’s all a psyop

                    1 Reply Last reply
                    0
                    • laura_ge@eldritch.cafeL laura_ge@eldritch.cafe

                      @zzt Humans are about as good when it comes to introducing vulns. However LLMs for 0day discovery works so well that it leaves you with really no choice, there's no LLM-free tool or process that can compete, in the mean time, you are just left with vulnerable software, that's a fact. The very nature of it being fast means vulnerability hunting becomes much easier and you can't compete as humans on the fixing side without using LLMs, there just isnt even enough qualified labor available in the world to manually handle the influx while keeping users safe. Android uses Linux and GrapheneOS didnt exactly chose that and for compatibility reasons it's quite difficult to change. A more durable choice for enforcing better theoretical security boundaries would be rewriting Linux in a safe programming language, however that is also an effort that requires enormous amount of labor that is not really practical. That would however be a viable human's response to it. You unfortunately just can't keep users safe on existing systems that arent designed from ground up to extremely minimize possible attack surface. Android is in a sense but also has many complex attackable systems made only to increase usability and versatility, you could have a human-made secure system that can resist LLM automated vulnerability hunting but it would certainly not have many features and be very crude to use. Unusable secure software isnt really that helpful either.

                      zzt@mas.toZ This user is from outside of this forum
                      zzt@mas.toZ This user is from outside of this forum
                      zzt@mas.to
                      wrote sidst redigeret af
                      #12

                      @laura_ge yeah I’m not reading all that, stay out of my replies codegooner

                      1 Reply Last reply
                      0
                      • xinit@mastodon.coffeeX xinit@mastodon.coffee

                        @zzt
                        "It's a new developer we hired"

                        Why did they hire them, if not to slop?

                        pikesley@mastodon.me.ukP This user is from outside of this forum
                        pikesley@mastodon.me.ukP This user is from outside of this forum
                        pikesley@mastodon.me.uk
                        wrote sidst redigeret af
                        #13

                        @xinit @zzt

                        "You wouldn't know them, they go to a different school. In Canada."

                        xinit@mastodon.coffeeX onepict@chaos.socialO 2 Replies Last reply
                        0
                        • ariarhythmic@ohai.socialA ariarhythmic@ohai.social

                          @avesbury_rosetta @zzt we need mobile linux, to start with. Android is a non-open, user-adversarial dead end. It takes a special kind of wrong mindset to be as determined to work on, and advocate for it, as GrapheneOS

                          hazelnot@sunbeam.cityH This user is from outside of this forum
                          hazelnot@sunbeam.cityH This user is from outside of this forum
                          hazelnot@sunbeam.city
                          wrote sidst redigeret af
                          #14

                          @ariarhythmic @avesbury_rosetta @zzt the issue is that Graphene is (or was) the most secure OS, at least in the mobile space. The one activists use because not even the police can break its security.

                          Meanwhile Linux is less secure than even macOS and Windows, I like it, I use it on all of my PCs, but not for *security* reasons.

                          ariarhythmic@ohai.socialA 1 Reply Last reply
                          0
                          • zzt@mas.toZ zzt@mas.to

                            > That increase is despite adding features slowly down a lot. A massive monolithic kernel written in a memory unsafe language is a bigger liability than ever.

                            rust in the kernel is in the corner like “am I a joke to you”

                            it’s uhhh real rich that the AOSP fork suddenly has a problem with a massive monolithic kernel written in a memory unsafe language now that LLMs are on the table

                            and the solution is just LLMs, only that. not fixing the massive, monolithic, or unsafe language bits at all. making them much worse, in fact. thanks!

                            aspensmonster@tenforward.socialA This user is from outside of this forum
                            aspensmonster@tenforward.socialA This user is from outside of this forum
                            aspensmonster@tenforward.social
                            wrote sidst redigeret af
                            #15

                            @zzt FUCK FUCK FUCK FUCK FUCK FUCK FUCK FUCK FUCK FUCK FUCK FUCK

                            /me inhales

                            FUCK FUCK FUCK FUCK FUCK FUCK FUCK FUCK FUCK FUCK FUCK FUCK FUCK FUCK FUCK FUCK FUCK FUCK FUCK FUCK

                            god fucking dammit graphene

                            zzt@mas.toZ jmax@mastodon.socialJ dnkboston@apobangpo.spaceD 3 Replies Last reply
                            0
                            • zzt@mas.toZ zzt@mas.to

                              the internet loves grapheneOS, the secure AOSP fork that also makes Android nicely usable without the LLM crap

                              <yelling from out of frame>

                              …ah. this just in, grapheneOS has decided to start codegooning core apps and security fixes and now they’re exhaustingly defending doing that

                              > Many valid issues are reported in between the hallucinations and other nonsense.

                              oh I see, what a relief

                              > Attackers are heavily using AI models to discover vulnerabilities and develop exploits. For example, Cellebrite is heavily using it including developing frameworks for reverse engineering and vulnerability discovery.

                              gotta use the wrongness machine, no sorry, “frontier models” because the coptech adversary is using them and also mythic’s great at finding vulnerabilities til you find out you can do the same job without it. great! https://grapheneos.social/@GrapheneOS/117226938743085364

                              zzt@mas.toZ This user is from outside of this forum
                              zzt@mas.toZ This user is from outside of this forum
                              zzt@mas.to
                              wrote sidst redigeret af
                              #16

                              if you’re in infosec or pretending to be in infosec and you’re about to start gooning in this thread with the contents of anthropic’s marketing campaign for mythic, a model whose results are shit: reconsider

                              reconsider a lot of things, really

                              anarchoninawrites@jorts.horseA hairynevus@infosec.exchangeH 2 Replies Last reply
                              0
                              • aspensmonster@tenforward.socialA aspensmonster@tenforward.social

                                @zzt FUCK FUCK FUCK FUCK FUCK FUCK FUCK FUCK FUCK FUCK FUCK FUCK

                                /me inhales

                                FUCK FUCK FUCK FUCK FUCK FUCK FUCK FUCK FUCK FUCK FUCK FUCK FUCK FUCK FUCK FUCK FUCK FUCK FUCK FUCK

                                god fucking dammit graphene

                                zzt@mas.toZ This user is from outside of this forum
                                zzt@mas.toZ This user is from outside of this forum
                                zzt@mas.to
                                wrote sidst redigeret af
                                #17

                                @aspensmonster that’s my inner monologue too

                                1 Reply Last reply
                                0
                                • pikesley@mastodon.me.ukP pikesley@mastodon.me.uk

                                  @xinit @zzt

                                  "You wouldn't know them, they go to a different school. In Canada."

                                  xinit@mastodon.coffeeX This user is from outside of this forum
                                  xinit@mastodon.coffeeX This user is from outside of this forum
                                  xinit@mastodon.coffee
                                  wrote sidst redigeret af
                                  #18

                                  @pikesley
                                  Oh, yeah? I'm from Canada. Is it Steve? Untrustworthy, that Steve.
                                  @zzt

                                  1 Reply Last reply
                                  0
                                  • hazelnot@sunbeam.cityH hazelnot@sunbeam.city

                                    @ariarhythmic @avesbury_rosetta @zzt the issue is that Graphene is (or was) the most secure OS, at least in the mobile space. The one activists use because not even the police can break its security.

                                    Meanwhile Linux is less secure than even macOS and Windows, I like it, I use it on all of my PCs, but not for *security* reasons.

                                    ariarhythmic@ohai.socialA This user is from outside of this forum
                                    ariarhythmic@ohai.socialA This user is from outside of this forum
                                    ariarhythmic@ohai.social
                                    wrote sidst redigeret af
                                    #19

                                    @hazelnot @avesbury_rosetta @zzt The Linux ecosystem has the potential for it, though; it just needs to be realized with openness, and empowering users in mind instead of the way Google decided to do it.

                                    avesbury_rosetta@wetdry.worldA 1 Reply Last reply
                                    0
                                    • zzt@mas.toZ zzt@mas.to

                                      if you’re in infosec or pretending to be in infosec and you’re about to start gooning in this thread with the contents of anthropic’s marketing campaign for mythic, a model whose results are shit: reconsider

                                      reconsider a lot of things, really

                                      anarchoninawrites@jorts.horseA This user is from outside of this forum
                                      anarchoninawrites@jorts.horseA This user is from outside of this forum
                                      anarchoninawrites@jorts.horse
                                      wrote sidst redigeret af
                                      #20

                                      @zzt I have zero idea what you're talking about but I am here for the piss and fire.

                                      zzt@mas.toZ 1 Reply Last reply
                                      0
                                      • pikesley@mastodon.me.ukP pikesley@mastodon.me.uk

                                        @xinit @zzt

                                        "You wouldn't know them, they go to a different school. In Canada."

                                        onepict@chaos.socialO This user is from outside of this forum
                                        onepict@chaos.socialO This user is from outside of this forum
                                        onepict@chaos.social
                                        wrote sidst redigeret af
                                        #21

                                        @pikesley @xinit @zzt I have the Ariel glasses meme in my head 🤣

                                        And now the glasses are Pervert glasses 😭

                                        1 Reply Last reply
                                        0
                                        • zzt@mas.toZ zzt@mas.to

                                          > That increase is despite adding features slowly down a lot. A massive monolithic kernel written in a memory unsafe language is a bigger liability than ever.

                                          rust in the kernel is in the corner like “am I a joke to you”

                                          it’s uhhh real rich that the AOSP fork suddenly has a problem with a massive monolithic kernel written in a memory unsafe language now that LLMs are on the table

                                          and the solution is just LLMs, only that. not fixing the massive, monolithic, or unsafe language bits at all. making them much worse, in fact. thanks!

                                          zzt@mas.toZ This user is from outside of this forum
                                          zzt@mas.toZ This user is from outside of this forum
                                          zzt@mas.to
                                          wrote sidst redigeret af
                                          #22

                                          also, here’s how much you can trust that they’re only using it strictly for reviews:

                                          https://circumstances.run/@davidgerard/117235031728518322

                                          > The AGENTS.md talks about the bot writing new code. On the available evidence I don't actually believe they're not coding with it.

                                          not that “only doing using it for reviews” gets good results. you end up programming the way the LLM insists you should anyway. reviewing like this is exhausting and quality goes straight into the toilet. most people just cognitively surrender to the bot after a bit. this is an extremely common methodology in professional code, and it’s the reason why half the software you use right now fucking sucks.

                                          distractal@hachyderm.ioD owl@bog.fanO 2 Replies Last reply
                                          0
                                          Svar
                                          • Svar som emne
                                          Login for at svare
                                          • Ældste til nyeste
                                          • Nyeste til ældste
                                          • Most Votes


                                          • Log ind

                                          • Har du ikke en konto? Tilmeld

                                          • Login or register to search.
                                          Powered by NodeBB Contributors
                                          Graciously hosted by data.coop
                                          • First post
                                            Last post
                                          0
                                          • Hjem
                                          • Seneste
                                          • Etiketter
                                          • Populære
                                          • Verden
                                          • Bruger
                                          • Grupper