this post was submitted on 11 Dec 2024
16 points (94.4% liked)
Cybersecurity
5885 readers
22 users here now
c/cybersecurity is a community centered on the cybersecurity and information security profession. You can come here to discuss news, post something interesting, or just chat with others.
THE RULES
Instance Rules
- Be respectful. Everyone should feel welcome here.
- No bigotry - including racism, sexism, ableism, homophobia, transphobia, or xenophobia.
- No Ads / Spamming.
- No pornography.
Community Rules
- Idk, keep it semi-professional?
- Nothing illegal. We're all ethical here.
- Rules will be added/redefined as necessary.
If you ask someone to hack your "friends" socials you're just going to get banned so don't do that.
Learn about hacking
Other security-related communities [email protected] [email protected] [email protected] [email protected] [email protected]
Notable mention to [email protected]
founded 2 years ago
MODERATORS
you are viewing a single comment's thread
view the rest of the comments
view the rest of the comments
So... go lookup the CVEs. Go have a look at what the actual threats against the old device are. What's the method of attack and do you care.
If you decide you're happy with the device. Then remember to keep going back and seeing if any new attacks against the device exist.
Whatever happens, we're not protected against 0day attacks (by their very nature).
I guess there is some reason to worry about "unknown" attacks against the device. But like 0day's, there's probably unknown attacks against patched devices as well.
Do you have a way to find them? I did look around at some CVE sites but I couldn't find anything specific to pixel 4a, making me think that maybe I need to look at individual parts within it? Which can be a lot more work and somewhat complicated
Edit: Saw CVE-2024-36971, I guess it's time 🫠
That CVE is in the Linux kernel, which CalyxOS should be fixing for you, via their security updates.