{"generator":"GNU social 2.0.2-dev","title":"Conversation","totalItems":1,"items":[{"actor":{"id":"https:\/\/grapheneos.social\/users\/GrapheneOS","displayName":"GrapheneOS","status_net":{"avatarLinks":[{"url":"https:\/\/gnusocial.jp\/avatar\/99224-original-tmp20240219114301.webp","rel":"avatar","type":"image\/webp","width":400,"height":400},{"url":"https:\/\/gnusocial.jp\/avatar\/99224-96-20240219114657.webp","rel":"avatar","type":"image\/webp","width":96,"height":96},{"url":"https:\/\/gnusocial.jp\/avatar\/99224-48-20240219114657.webp","rel":"avatar","type":"image\/webp","width":48,"height":48},{"url":"https:\/\/gnusocial.jp\/avatar\/99224-24-20240219114657.webp","rel":"avatar","type":"image\/webp","width":24,"height":24}],"profile_info":{"local_id":"99224"}},"image":{"url":"https:\/\/gnusocial.jp\/avatar\/99224-96-20240219114657.webp","rel":"avatar","type":"image\/webp","width":96,"height":96},"objectType":"person","summary":"Open source privacy and security focused mobile OS with Android app compatibility.","url":"https:\/\/grapheneos.social\/@GrapheneOS","portablecontacts_net":{"preferredUsername":"GrapheneOS","displayName":"GrapheneOS","note":"Open source privacy and security focused mobile OS with Android app compatibility."}},"content":"<p><a href=\"https:\/\/tech.lgbt\/@becomethewaifu\" class=\"u-url mention\">@becomethewaifu<\/a> That's why we only mentioned it being the chosen attack vector for exploiting it. It's a common attack surface and attack vector for exploits which is why it was removed from Android. It's the SELinux policy disallowing access to AF_ALG outside of dumpstate which blocks exploiting it along with a standard GKI not having the userspace crypto API enabled. AOSP, stock Pixel OS and GrapheneOS don't have the relevant API enabled at all though, which we didn't realize until today.<\/p>","generator":{"id":"tag:gnusocial.jp,2026-07-30:notice-source:ActivityPub","objectType":"application","status_net":{"source_code":"ActivityPub"}},"id":"https:\/\/grapheneos.social\/users\/GrapheneOS\/statuses\/116495186487008270","object":{"id":"https:\/\/grapheneos.social\/users\/GrapheneOS\/statuses\/116495186487008270","objectType":"note","content":"<p><a href=\"https:\/\/tech.lgbt\/@becomethewaifu\" class=\"u-url mention\">@becomethewaifu<\/a> That's why we only mentioned it being the chosen attack vector for exploiting it. It's a common attack surface and attack vector for exploits which is why it was removed from Android. It's the SELinux policy disallowing access to AF_ALG outside of dumpstate which blocks exploiting it along with a standard GKI not having the userspace crypto API enabled. AOSP, stock Pixel OS and GrapheneOS don't have the relevant API enabled at all though, which we didn't realize until today.<\/p>","url":"https:\/\/grapheneos.social\/@GrapheneOS\/116495186487008270","status_net":{"notice_id":null}},"to":[{"objectType":"http:\/\/activitystrea.ms\/schema\/1.0\/collection","id":"http:\/\/activityschema.org\/collection\/public"}],"status_net":{"conversation":"tag:gnusocial.jp,2026-04-30:objectType=thread:nonce=3fa9009dda3a8f92","notice_info":{"local_id":"12532504","source":"ActivityPub"}},"published":"2026-04-30T19:03:05+00:00","provider":{"objectType":"service","displayName":"GNU social JP","url":"https:\/\/gnusocial.jp\/"},"verb":"post","url":"https:\/\/grapheneos.social\/@GrapheneOS\/116495186487008270"}],"links":[{"url":"https:\/\/gnusocial.jp\/conversation\/6364050","rel":"alternate","type":"text\/html"}]}