Conversation

twitter.com/DanielMicay/st Some people think that verbally assaulting makes them good at infosec, in fact they know nothing
Quote Tweet
twitter.com/Ricrdo31523064 en.wikipedia.org/wiki/Dunning%E One day, maybe I'll be able to understand how having security updates for the kernel, drivers and firmware is a 'hardware firewall'. I do think IOMMUs and other hardware-based mitigations are important if that counts... *shrug*
2
Replying to and
I didn't say that. I pointed out that a Nexus 5 has hundreds of serious, unfixed disclosed vulnerabilities regardless of which custom ROM you choose. They don't even come close to addressing the problem of it being end-of-life.
2
Replying to and
You have a serious misunderstanding of what I've been saying. Good: using a robust alternative OS with full security updates on a device with proper support for other OSes. Bad: using an OS substantially reducing security from AOSP and not providing the full security updates.
1
Replying to and
An OS is also only part of the overall picture. It can't make up for lacking support for various OS exploit mitigations at a hardware level, a 32-bit address space, lack of verified boot, insecure firmware, lack of IOMMUs isolating components, etc.
1
Show replies