Update of the Secure Android Platform GrapheneOS

The release of the secure mobile platform GrapheneOS 2024011300 is now available. This version is a branch from the Android codebase (AOSP, Android Open Source Project), enhanced and modified to boost security and ensure privacy. The project was previously developed under the name AndroidHardening and before that branched off from the CopperheadOS project after a dispute among its founders. Most current Google Pixel devices (Pixel 4/5/6/7/8, Pixel Fold, Pixel Tablet) are officially supported in GrapheneOS. The project's developments are distributed under the MIT license.

GrapheneOS includes many experimental technologies related to enhancing application isolation, detailed access control, blocking typical vulnerabilities, and complicating the operation of exploits. For example, the platform uses a custom malloc implementation and a modified libc variant with memory corruption protection, as well as stricter process address space separation. Instead of JIT, only ahead-of-time (AOT) compilation is used in the Android Runtime. The Linux kernel includes many additional protection mechanisms, such as adding canary labels to slub to block buffer overflows. SELinux and seccomp-bpf are utilized to enhance application isolation.

There is the capability to grant access to network operations, sensors, contacts, and peripheral devices (USB, camera) only to selected applications. Reading from the clipboard is allowed only for applications that currently have input focus. By default, obtaining information about IMEI, MAC address, SIM card serial number, and other hardware identifiers is prohibited. Additional measures have been taken to isolate Wi-Fi and Bluetooth-related processes and prevent leaks due to wireless activity. Many of the security enhancement mechanisms developed in this project have been integrated into the main Android codebase.

GrapheneOS employs cryptographic verification of loaded components and advanced data encryption at the ext4 and f2fs file system levels (data is encrypted using AES-256-XTS, and file names are encrypted using AES-256-CTS with HKDF-SHA512 to generate a separate key for each file), rather than at the block device level. Data in system partitions and in each user profile is encrypted with different keys. Available hardware capabilities are utilized to accelerate encryption operations. The lock screen displays a session termination button, which, when pressed, resets the decryption keys and puts the storage into a deactivated state. There is a setting to prohibit the installation of additional applications for selected user profiles. To protect against password guessing, a delay system is employed that depends on the number of failed attempts (ranging from 30 seconds to 1 day).

GrapheneOS fundamentally does not include Google applications and services, nor alternative implementations of Google services, such as microG. However, it is possible to install Google Play services in a separate isolated environment that does not have special privileges. The project also develops several of its own applications focused on information security and privacy. For example, it offers the Vanadium browser based on Chromium and a modified version of the WebView engine, a secure PDF viewer, a firewall, the Auditor application for device verification and intrusion detection, a privacy-focused camera application, and the Seedvault system for creating encrypted backups.

Among the changes in the new version:

  • The implementation of the automatic reboot mechanism has been completely redesigned to use a timer during the init process rather than the system_server process, enhancing security and preventing the reboot of a device that has never been unlocked. The automatic reboot time has been reduced from 72 hours to 18 hours. The main idea behind the automatic reboot is to reset activated (decrypted) partitions containing user data to their original undecrypted state after a certain period of inactivity.

    User profile data remains encrypted after the device is restarted and is decrypted only after the user enters their login password. If the user does not unlock the activated session for more than 18 hours, the device will automatically restart (the timeout can be changed in Settings > Security > Auto reboot) to prevent the analysis of keys remaining in memory if the device falls into the wrong hands.

    As a demonstration of the necessity of the auto-reboot feature, the developers of GrapheneOS mentioned recently discovered vulnerabilities in Google Pixel and Samsung Galaxy smartphones that allow forensic analysis companies to spy on users and extract data while the device is in an activated state (when the session is active and the data is decrypted).

  • A log viewer has been added (Settings > System > View logs) to help assess issues and simplify the preparation of error reports.
  • The interface for sending crash reports has been redesigned.
  • Support for Pixel Camera Service has been added in adevtool, enabling night mode usage in apps on Pixel 6+ smartphones.
  • Support for devices not compatible with Android 14 has been discontinued in adevtool.
  • Notifications for memory corruption detector activation in malloc have been added.
  • Support for sysrq has been disabled in the Linux kernel.
  • The Linux kernel has been updated to the latest GKI (Generic Kernel Image) 5.10.206 for Pixel 6, Pixel 6 Pro, Pixel 6a, Pixel 7, Pixel 7 Pro, Pixel 7a, Pixel Tablet, Pixel Fold, and to version 5.15.145 for Pixel 8 and Pixel 8 Pro devices. Additionally, builds with kernel 6.1.69 have been prepared.
  • The Vanadium browser has been updated to the Chromium codebase 120.0.6099.210.0.

Source: opennet.ru

Buy reliable website hosting with DDoS protection, VPS VDS servers 🔥 Buy reliable website hosting with DDoS protection, VPS VDS servers | ProHoster