Viewing profile — grapheneos
grapheneos
HN member- Joined
- Thu, Jun 18, 2026, 8:04 AM UTC
- HN karma
- 206
- Public activity
- 92 items
- HN profile
- View on Hacker News ↗
About grapheneos
No profile information was provided.
Recent public activity
-
comment
Comment #49092146
In general, it's a very bad sign if an app isn't targeting a recent API level. It's largely not because apps are abandoned but rather to abuse weaker privacy and security protectio…
-
comment
Comment #49092117
It would be easily detected by widely used forensic software from Cellebrite and other companies. It would also definitely look suspicious. We explained in much more depth in respo…
-
comment
Comment #49092109
It uses hardware with a secure element only permitting 20 attempts. The past 5 unique attempts are rejected early out for usability. We published a technical overview of how Graphe…
-
comment
Comment #49091060
Fairphones have very poor security at a hardware, firmware and software level. They've shown complete disinterest in making devices meeting our requirements. https://discuss.graphe…
-
comment
Comment #49091020
Neither of those is a privacy or security hardened OS. AOSP is much more private and secure than the desktop Linux software stack and GrapheneOS greatly improves upon it. GrapheneO…
-
comment
Comment #49075836
We have a dedicated issue tracker for the Messaging app now. The user interface has been nearly entirely overhauled already but we haven't made a new release yet. That's coming soo…
-
comment
Comment #49062084
Yes, it provides strong protection while profiles are in After First Unlock state. It automatically reboots 18 hours after locking by default so there's a time limit on having a wo…
-
comment
Comment #49062051
Vanadium will add more data to the device-to-device backups but we haven't gotten to it yet. For Signal, you can set up their own backups locally and they'll be included with backe…
-
comment
Comment #49062021
It doesn't wipe after a certain number of failed attempts but rather the secure element only permits a total of 20 attempts and heavily throttles the rate those can be done. That's…
-
comment
Comment #49060884
There are more recent leaks. The last release of GrapheneOS they've been able to exploit on locked device is still from 2022 as of a couple months ago. They take longer to break in…
-
comment
Comment #49060863
That isn't truly hidden and can be detected as a low level from the SSD.
-
comment
Comment #49060846
TTS is also in the process of being massively improved. What we've included is only an initial bare minimum implementation. We also plan to add speech-to-text but we may only suppo…
-
comment
Comment #49060780
> I'm surprised they didn't back up the device first. There's no use in taking an image of the SSD and restoring it after a wipe. Data needed to derive the key encryption keys was …
-
comment
Comment #49060716
Reliable deletion of data depends on wiping keys with hardware support. Android has per-profile keys meaning separate keys for each user and Private Space. It can reliably erase al…
-
comment
Comment #49060652
The secure element rate limiting is integrated in a way that can only add security. It can't reduce the security of key derivation since it's only used to get an extra input for de…
-
comment
Comment #49060126
GrapheneOS largely prevented it for Vanadium before this came to light and fully fixed it long before Chromium did. Android 17 prevents cross-profile loopback connections, which is…
-
comment
Comment #49060106
We say 5 years in the requirements but we want 7 and are starting to expect it. Pixels have provided 7 years since the Pixel 8. Qualcomm provides 8 years of support for new platfor…
-
comment
Comment #49060094
It would need to provide that for around 7 years. It would need to avoid getting increasingly delayed over time. It would also need to provide the hardware-based security features …
-
comment
Comment #49060075
/e/ goes in the opposite direction from AOSP for privacy and security compared to GrapheneOS. It lags far behind on providing standard privacy/security patches and protections. It …
-
comment
Comment #49060020
It's not an open source phone. It's closed source hardware with closed source firmware. The closed source userspace drivers/services could be rewritten but the hardware and firmwar…
-
comment
Comment #49060003
GrapheneOS is a privacy project making major privacy improvements. Privacy depends on security so that's why it improves that too.
-
comment
Comment #49059999
No, you can't obtain almost all of the benefits of GrapheneOS on other hardware. Many of the benefits depend on having current privacy and security patches along with hardware-base…
-
comment
Comment #49059971
No, GrapheneOS is a privacy project. Privacy depends on security which is the only reason we work on security too. /e/ and Fairphone both have much worse privacy than the standard …
-
comment
Comment #49059941
Privacy depends on fixing widely abused privacy weaknesses by patching privacy vulnerabilities and shipping major privacy improvements. /e/ is missing many standard Android privacy…
-
comment
Comment #49059933
We definitely don't see privacy and security as binary. Privacy depends on fixing widely abused privacy weaknesses by patching privacy vulnerabilities and shipping major privacy im…