this post was submitted on 14 Jul 2025
703 points (97.7% liked)

Technology

72784 readers
2859 users here now

This is a most excellent place for technology news and articles.


Our Rules


  1. Follow the lemmy.world rules.
  2. Only tech related news or articles.
  3. Be excellent to each other!
  4. Mod approved content bots can post up to 10 articles per day.
  5. Threads asking for personal tech support may be deleted.
  6. Politics threads may be removed.
  7. No memes allowed as posts, OK to post as comments.
  8. Only approved bots from the list below, this includes using AI responses and summaries. To ask if your bot can be added please contact a mod.
  9. Check for duplicates before posting, duplicates may be removed
  10. Accounts 7 days and younger will have their posts automatically removed.

Approved Bots


founded 2 years ago
MODERATORS
 

TLDR: Drug dealers in Catalonia have started to adopt GrapheneOS en masse leading to Catalan police suspecting anyone with a Google Pixel is a drug dealer

you are viewing a single comment's thread
view the rest of the comments
[–] interdimensionalmeme@lemmy.ml 0 points 6 hours ago (1 children)

Strange that google is the only option for the only "secure" operating system.
Hey, do you know what is Ring Level minus One ?

[–] mikey@sh.itjust.works 4 points 3 hours ago (1 children)

Strange that google is the only option for the only "secure" operating system.

The have their reasons: https://grapheneos.org/faq#future-devices

Hey, do you know what is Ring Level minus One ?

I know you're only trolling here and I'm feeding into it, but you nerd sniped me just right to explain why your question is stupid on multiple fronts.

First of all, "Ring -1" is the hypervisor, at least on virtualization-capable devices (which modern Pixels are), and the hypervisor will be Linux's KVM in this case, which is open source and compiled by the Graphene team as part of the kernel from source.

Secondly, Arm (which is the architecture basically all phone chips use, including Pixels) has a slightly different model of security, where apps are Exception Level 0, the OS is EL1, the hypervisor is EL2, and the "secure monitor" (or management firmware) is EL3 (and is probably what you were trying to refer to).

So yeah, I don't think you know what "Ring -1" is. At least not enough to warrant a snarky comment.

[–] interdimensionalmeme@lemmy.ml 0 points 3 hours ago

"-1" is not just hypervisors, things like Intel Management and AMD Platform Security Processor can peer into system memory. I have no doubt similar system exist on ARM, I suspect the radio transceiver can also read system memory and read secrets out of the security devices.

I don't think modern phones are trustable devices. They are opaque blackboxes, pretending to have high security but this security only really protects the spyware operators from being notices.

I don't think it's coincidence that the most "secure" and "private" operating system only operates on a very narrow model selection of phones from just one manufacturer. Probably because they have the best technology to keep the inherent backdoor invisible and implausible. A backdoor to a system nobody trusts wouldn't be very useful.