Comment on Is Buying a Google Pixel with GrapheneOS Pre-Installed Dangerous?
Object@sh.itjust.works 1 week ago
Technically, possible, but realistically, not much of a concern. You probably know better than anyone else as to whether you are that much of a person of interest that it warrants an attacker who is motivated enough to:
- Figure out that you are interested in a GrapheneOS phone
- Put up an offer and somehow ensure you buy that
- Rebuild GrapheneOS and load a malicious one into it and hope you don’t reinstall one, or use a really fancy trick that it persists across wipes
If it still bothers you, you can install it yourself. GrapheneOS has a web installer through which you can install GrapheneOS. It’s really weird how your browser can access all that, but yeah, you can install it within a website and a phone plugged into that computer. Once you do it yourself, I really doubt there’s anything malicious left.
FearMeAndDecay@literature.cafe 1 week ago
I figured it’d be that kind of situation, but I don’t know much about phone security so I wasn’t sure if there were added vulnerabilities. Thank you!