I've restored more of the changes to the Chromium builds for the new hardened mobile OS releases:
github.com/AndroidHardeni
It's set up to prefer 64-bit processes again so it's using the new hardened allocator. It works very well already and will be faster once arenas are added.
Conversation
Replying to
hey Daniel. I just saw on attestation.app that information: Disallow new USB peripherals when locked: no.
How can I change this? So they are dissalowed when locked on my pixel 3?
1
Replying to
Ah ok. I though I missed something. Thanks for the answer. I have another question. I know you don't have the resources at the moment and it is just a question out of interest. There is an app called snoopsnitch. It is made by a person from CCC in germany. It is the only app that
1
is capable to detect several anomalies in the baseband. By using some sort of debugging in the Qualcomm chip. Unfortunately it needs root. I know rooting is insecure. Is it possible to integrate such an app and only grant it this kind of privileges? Hope I make sense
1
ok after reading this thread:
stackoverflow.com/questions/1621
I answered most of the question myself. But still I would be interested to hear your opinion.
1
Replying to
It's not useful in the real world so it makes no sense to include it. Exposing root to the application layer would be a substantial security loss too. It fails to offer any value to make up for that beyond appearing to be useful to people that don't know any better. It isn't.
2
Replying to
you mean it doesn't provide correct information about the activity in the baseband? Because it is just a tool that analysis some more parameters than already exposed. It doesn't do anything to prevent them. But isn't it good to now that some imsi catcher activity is happening?
1
Replying to
It isn't helpful. The network isn't trusted, and you should use encrypted messaging and calls. Interception between the phone and cell tower is not at all necessary to capture or inject traffic. It's a solution looking for a problem, and it doesn't actually work properly anyway.

