Hacker Newsnew | past | comments | ask | show | jobs | submit | b8's commentslogin

Samsung phones still have better cameras. Nothing that special over the Pixel 10.

I wish they would support lossless audio. Like the Sony earbuds do with my Pixel.

$1k for this vuln is laughable. If the researcher wrote an exploit as the nday exploit devs did and sold it in the gray market they would of got significantly more.

Anyone who sells such an exploit should go to prison.

Agreed--if you can catch them of course.

Seeking: Any role that I can use my technical skills in. Security analyst, consultant, technical support etc.

Location: Louisiana

Remote: Yes, and/or on-site. I'm experienced with both.

Willing to relocate: Yes

Technologies: AWS, Java (SRC review), C++/C (SRC Review), C# (Basic), Burp Suite, Binary Ninja etc.

Résumé/CV: Full resume on request.

Email: mcorkern1@tulane.edu

GitHub: https://github.com/qf0

Misc: I have over two years of full-time security consulting and blue team experience at NCC Group and Black Lantern Security. Also, I have two 0days and received CVEs under my name and a company research blog post to go along with it. Done contracting for FAANGs and found 0days in their products. Worked at IBM as a programmer too.

I'm eligible for a security clearance and willing to do government work. Already passed a FSP once, but was denied agency specific suitability.


Taylor Swift's parents spent 1 Mil+ on her career. I wouldn't call that middle class.


I might give it to them still if they were fully leveraged.


I wish they would've added features like LED lighting and other improvements while keeping Solar and Atomic clock syncing. Instead of modern smart watch stuff.


I have the ABL-100WE-1A version, it has LED backlight. all of the ABL-100WE have it. I press 3 seconds on the mode button, the watch syncs to the phone, syncs the clock and doesn't drift for a long time, and it also syncs the steps from pedometer.


These watches have cheap batteries that you can swap in two minutes. Not a big deal. Solar batteries cost a lot more money and will render this watch as e-waste in the future.


The Garmin Tactix with solar is good.


PureOS runs on Librem and is decent.


Pokemon is a good investment IMO. My mom even bought me some as an investment in 2008.


Does it protect it in After First Unlock mode? I often use my device and if I lock it before LE or another bad actor catches it then it's kind of useless if it doesn't protect my data in after first unlock (locked) mode. Especially with LE agencies having tools like Cellebrite at their station for same day analysis. Most people probably won't have time to reboot their device.

Similar to how I use Veracrypt, but I leave my PC running, because I hate spending time booting up again. So LE could decrypt my stuff using RAM extraction stuff.


Yes, it provides strong protection while profiles are in After First Unlock state. It automatically reboots 18 hours after locking by default so there's a time limit on having a working exploit which is highly unlikely. The timer can be set as low as 10 minutes by users.

18 hours was chosen to avoid ever triggering for people who use their phone a couple times a day. For most people, it only needs to be a bit longer than their maximum sleep time to avoid triggering in practice. It's mostly fine if it reboots during the night anyway but people may miss an urgent non-carrier call, etc.

Cellebrite's documentation on Cellebrite Premium capabilities is repeatedly leaked. As of a couple months ago, it still shows they lack exploits for locked GrapheneOS devices updated past a certain 2022 patch level.


Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: