• 3 Posts
  • 142 Comments
Joined 1 year ago
cake
Cake day: June 2nd, 2023

help-circle

  • Victims of trauma dont just forget because time passes. They graduate (or dont) and move on in their lives, but the lingering effects of that traumatic experience shape the way the look at the worlds, whether they can trust, body disphoria, whether they can form long-lasting relationships, and other long last trauma responses. Time does not heal the wounds of trauma, they remain as scars that stay vulnerable forever (unless deliberate action is taken by the victim to dismantle the cognitive structure formed by the trauma event).












  • Related to relockable bootloaders and the security they provide, I was under the impression that if a malicious bit of software were to make use of some privilege escalating vulnerability and modify the kernel, the phone would fail to run in some way (ignore the rest of this if that isn’t the case). I dont think security should be dependent on the user behavior in basically any case.

    For example, a FOSS developer in our communities could suddenly lose it and modify an existing app of theirs to inject malicious code making use of a vulnerability in android and we’d have know what of knowing until the damage is reported. Good user behavior is very important for security, but we can’t all be auditing our apps for each new release, even though its quite unlikely to happen.


  • It still has much of the google proprietary blobs still included and relies on google services, also without significant effort to harden Android. I have also heard that sometimes they fall behind on updates to their apps by weeks at a time (correct me if I’m wrong I am still looking for the source I found this info from). It may be moderately degoogled, but their security just ain’t there. In some cases (like OEM EOSL for older devices) having a 3rd party ROM may improve security with more up to date patches. Unless the bootloader is relockable and secure boot is possible, you will be compromising your device’s security (and privacy along with it) and destroying the Android security model in general.