Live data from Hacker News

Viewing profile — grapheneos

grapheneos

HN member
Joined
Thu, Jun 18, 2026, 8:04 AM UTC
HN karma
206
Public activity
92 items

About grapheneos

No profile information was provided.

Recent public activity

  1. comment
    Comment #49092146

    In general, it's a very bad sign if an app isn't targeting a recent API level. It's largely not because apps are abandoned but rather to abuse weaker privacy and security protectio…

  2. comment
    Comment #49092117

    It would be easily detected by widely used forensic software from Cellebrite and other companies. It would also definitely look suspicious. We explained in much more depth in respo…

  3. comment
    Comment #49092109

    It uses hardware with a secure element only permitting 20 attempts. The past 5 unique attempts are rejected early out for usability. We published a technical overview of how Graphe…

  4. comment
    Comment #49091060

    Fairphones have very poor security at a hardware, firmware and software level. They've shown complete disinterest in making devices meeting our requirements. https://discuss.graphe…

  5. comment
    Comment #49091020

    Neither of those is a privacy or security hardened OS. AOSP is much more private and secure than the desktop Linux software stack and GrapheneOS greatly improves upon it. GrapheneO…

  6. comment
    Comment #49075836

    We have a dedicated issue tracker for the Messaging app now. The user interface has been nearly entirely overhauled already but we haven't made a new release yet. That's coming soo…

  7. comment
    Comment #49062084

    Yes, it provides strong protection while profiles are in After First Unlock state. It automatically reboots 18 hours after locking by default so there's a time limit on having a wo…

  8. comment
    Comment #49062051

    Vanadium will add more data to the device-to-device backups but we haven't gotten to it yet. For Signal, you can set up their own backups locally and they'll be included with backe…

  9. comment
    Comment #49062021

    It doesn't wipe after a certain number of failed attempts but rather the secure element only permits a total of 20 attempts and heavily throttles the rate those can be done. That's…

  10. comment
    Comment #49060884

    There are more recent leaks. The last release of GrapheneOS they've been able to exploit on locked device is still from 2022 as of a couple months ago. They take longer to break in…

  11. comment
    Comment #49060863

    That isn't truly hidden and can be detected as a low level from the SSD.

  12. comment
    Comment #49060846

    TTS is also in the process of being massively improved. What we've included is only an initial bare minimum implementation. We also plan to add speech-to-text but we may only suppo…

  13. comment
    Comment #49060780

    > I'm surprised they didn't back up the device first. There's no use in taking an image of the SSD and restoring it after a wipe. Data needed to derive the key encryption keys was …

  14. comment
    Comment #49060716

    Reliable deletion of data depends on wiping keys with hardware support. Android has per-profile keys meaning separate keys for each user and Private Space. It can reliably erase al…

  15. comment
    Comment #49060652

    The secure element rate limiting is integrated in a way that can only add security. It can't reduce the security of key derivation since it's only used to get an extra input for de…

  16. comment
    Comment #49060126

    GrapheneOS largely prevented it for Vanadium before this came to light and fully fixed it long before Chromium did. Android 17 prevents cross-profile loopback connections, which is…

  17. comment
    Comment #49060106

    We say 5 years in the requirements but we want 7 and are starting to expect it. Pixels have provided 7 years since the Pixel 8. Qualcomm provides 8 years of support for new platfor…

  18. comment
    Comment #49060094

    It would need to provide that for around 7 years. It would need to avoid getting increasingly delayed over time. It would also need to provide the hardware-based security features …

  19. comment
    Comment #49060075

    /e/ goes in the opposite direction from AOSP for privacy and security compared to GrapheneOS. It lags far behind on providing standard privacy/security patches and protections. It …

  20. comment
    Comment #49060020

    It's not an open source phone. It's closed source hardware with closed source firmware. The closed source userspace drivers/services could be rewritten but the hardware and firmwar…

  21. comment
    Comment #49060003

    GrapheneOS is a privacy project making major privacy improvements. Privacy depends on security so that's why it improves that too.

  22. comment
    Comment #49059999

    No, you can't obtain almost all of the benefits of GrapheneOS on other hardware. Many of the benefits depend on having current privacy and security patches along with hardware-base…

  23. comment
    Comment #49059971

    No, GrapheneOS is a privacy project. Privacy depends on security which is the only reason we work on security too. /e/ and Fairphone both have much worse privacy than the standard …

  24. comment
    Comment #49059941

    Privacy depends on fixing widely abused privacy weaknesses by patching privacy vulnerabilities and shipping major privacy improvements. /e/ is missing many standard Android privacy…

  25. comment
    Comment #49059933

    We definitely don't see privacy and security as binary. Privacy depends on fixing widely abused privacy weaknesses by patching privacy vulnerabilities and shipping major privacy im…