TGStat
TGStat
Введите текст для поиска
Расширенный поиск каналов
  • flag Russian
    Язык сайта
    flag Russian flag English flag Uzbek
  • Вход на сайт
  • Каталог
    Каталог каналов и чатов Поиск каналов
    Добавить канал/чат
  • Рейтинги
    Рейтинг каналов Рейтинг чатов Рейтинг публикаций
    Рейтинги брендов и персон
  • Аналитика
  • Поиск по публикациям
  • Мониторинг Telegram
Privacy Not A Crime

18 Aug, 00:12

Открыть в Telegram Поделиться Пожаловаться

💬 A follower asks us the following question in Spanish:

Which operating system is most vulnerable to these attacks: GrapheneOS, iOS, or standard Android? Which one is more secure in preventing real-time remote access by government spyware and zero-click attacks where the user doesn’t have to do anything, but simply by inserting the SIM card and connecting to the network, the phone becomes infected and is accessed remotely?


🙏 First of all, thank you for asking.

🔹The most vulnerable and exploitable operating systems are those that are closed-source, the ones that the community cannot audit and does not know what lies behind them. That is why we always recommend using the latest version of Android with the latest security patches applied. Note: we mean ‘open-source’ Android, without proprietary services such as those from Google.

🔹To prevent remote access to your smartphone, you need to take certain basic security measures; the most important ones are as follows:

▫️ Manually update your operating system to the latest version and ensure it has the latest security patches. By ‘manually’, we mean that you should download the update from the provider’s official website and install it from a PC; never update automatically, as this is a common vector for compromise. Always be wary of automatic updates.

▫️ Never accept automatic updates for any type of app.

▫️ Never click on any links that are sent to you, no matter how harmless they may seem. Even if they're sent by someone you trust. Just don't do it.

▫️ Always keep your web browser and apps updated to the latest version, although there are exceptions depending on each person's situation.

▫️ Do not use proprietary services from companies such as Google, Microsoft, Facebook (Meta), X, YouTube, WhatsApp, etc.

▫️ Of course, don't install apps from unknown sources unless you know what you're doing.

🔹Disable the network operator’s services and uninstall apps such as ‘SIM Toolkit’, as this is a commonly used attack vector.

🔹Always opt for an eSIM rather than a physical SIM card to reduce the attack surface.

🔹Use a good, community-maintained smartphone firewall that is regularly updated, and a good VPN that does not keep logs

🔹Block all private IP addresses on the firewall, but particularly those of the service provider (100.64.0.0/10). The service provider may intercept your traffic and reroute it through that range in order to spy on your communications.

🔹Always prioritise 5G NR over any other mobile network. Do not confuse this with 5G NR NSA, as NR NSA uses 4G LTE for the control channel and 5G NR for the data channel. This offers no additional security benefits and creates attack vectors such as man-in-the-middle attacks.

🔹Uninstall any certificate from the root system unless you fully trust it and know what it is for. If you do not know why it is there, it is best to remove it.

❕ But it’s not all down to the software; the hardware is also very important, and, paradoxically, using a less popular smartphone will help to reduce the attack surface. Most exploits are designed for Samsung and Apple.

🔖 These are just a few tips for reducing your attack surface. However, you’ll also need to learn how to identify indicators of compromise so you know when your device might be compromised. But we’ll cover that in another article if our followers show their support.

👋 If you’ve enjoyed this new section, please let us know.

@PrivacyNotACrime 🗽 ⌨️ Chat

286 0 6 3 17
Каталог
Каталог каналов и чатов Подборки каналов Поиск каналов Добавить канал/чат
Рейтинги
Рейтинг каналов Telegram Рейтинг чатов Telegram Рейтинг публикаций Рейтинги брендов и персон
API
API статистики API поиска публикаций API Callback
Наши каналы
@TGStat @TGStat_Chat @telepulse @TGStatAPI
Почитать
Академия TGStat Исследование Telegram 2019 Исследование Telegram 2021 Исследование Telegram 2023
Контакты
Справочный центр Поддержка Почта Вакансии
Всякая всячина
Пользовательское соглашение Политика конфиденциальности Публичная оферта
Наши боты
@TGStat_Bot @SearcheeBot @TGAlertsBot @tg_analytics_bot @TGStatChatBot