Live data from Hacker News

Essential Phone, available now

essential.com

361–370 of 695 posts

Re: Essential Phone, available now

#361

Earlier quoted context omitted.

security ones...

What kind of security updates actually worry you though? Not trying to sound snarky, but do you install sketchy apps regularly? What are examples of actual threats are you trying to protect against? If you install untrusted apps regularly I could see why, but if not then what attack vector are you worried about? Are you worried about a WiFi attack in a coffee shop for example?

E.g. there was a remote code execution vulnerability in dhcpcd that got fixed in April 2016.

And we have QuadRooter, Dirty Cow, Stagefright and all the other fancy named Vulnerabilities.

Re: Essential Phone, available now

#362

Earlier quoted context omitted.

What kind of support do you need for a smartphone? I've literally never even thought "maybe I should contact support" for a phone problem.

Tons of things, like "my phone is two weeks old and the battery life has halved"

I'd complain about the battery in that case, not support.

Re: Essential Phone, available now

#363

A little expensive IMHO. I've dropped the iPhone a little more than a year ago. I got a Y6II for $179. Perfect performance, but didn't like Huawei's tweaks to Android. I just got a Moto G5 Plus with nearly-stock Android and it's the best phone I've ever owned, and I paid only EUR 280 for it.

There's also the Nokia 6 playing in that same space. But let's not pretend that those are in the same "flagship" league as the specs on this phone. Screen is higher resolution, processor and GPU are faster, more storage and memory, dual cameras with more MP, USB-C... I mean, almost every spec point worth caring about is obviously better.

I don't know, I can't imagine needing more than 3GB of RAM,>200dpi and 4K video in a phone.

I'm not saying the phone isn't great, just a personal perspective.

Re: Essential Phone, available now

#364

Earlier quoted context omitted.

security ones...

What kind of security updates actually worry you though? Not trying to sound snarky, but do you install sketchy apps regularly? What are examples of actual threats are you trying to protect against? If you install untrusted apps regularly I could see why, but if not then what attack vector are you worried about? Are you worried about a WiFi attack in a coffee shop for example?

Not the person who you are replying to, but in my case, yes, connecting to a hostile WiFi and someone physically stealing my phone and having access to my entire life is exactly my fear.

Also, being able to fine-tweak app permissions is a huge plus for getting Android 6+ phone.

I've switched to Nexus 5x at the beginning of this month. Current price is around 250€, and I basically gained all the features of flagship models (fast charging, good camera, up to date software, security updates for a year from now etc).

But, up until that point, I refused to install apps that I would be scared of what would happen if they were compromised (so, nothing business-related) and apps that are asking me permissions that I don't want to allow them (as an example, no Facebook app what so ever).

Been that way ever since I became a smartphone user, which, because of my privacy fears and dissatisfaction with current market options didn't happen until like two years ago.

Re: Essential Phone, available now

#365

Earlier quoted context omitted.

But your email app will still get updates right? (I guess I'm using Gmail and assuming you are using something like it that gets updates too, but maybe I'm wrong.) Same with SMS - lots of apps that get updates. What's the exact issue?

"Stagefright" is an Android vulnerability that allows attackers to exploit a device by sending a specially crafted MMS message. No user intervention is required, no dodgy apps need to be installed. You're on Android 4, so your phone is vulnerable. If you use your phone for anything important, I'd suggest getting that new phone ASAP.

Actually I've already mitigated this by disabling automatic MMS download, and from what I read [1] it can be mitigated in other ways as well. It can't be done in every app, but then you can just use an app that lets you do this. So this is a non-issue. Any others you can think of?

[1] https://en.wikipedia.org/wiki/Stagefright_(bug)#Mitigation

Re: Essential Phone, available now

#366

Earlier quoted context omitted.

What kind of support do you need for a smartphone? I've literally never even thought "maybe I should contact support" for a phone problem.

Some of the bloatware (minimal as it may be) is very intrusive, including ads sent as notifications through system apps that can not be blocked or silenced. Their support gaslights you about topics like that.

Huh, what are those apps then? Also, what accessories? There's just a charger right?

Supposedly Lineage runs well on them btw.

Re: Essential Phone, available now

#367
post #25

Why would I spend $700+ on a phone with a dubious fate when I can spend $230 on a Moto G5 Plus and have Lineage OS running on it in no time, for a long time?

What exactly is Lineage OS? Their website is pretty hostile towards anyone trying to answer that question easily. The about page consists solely of two definitions of 'lineage', neither of which is a cutesy reference to the project.

Re: Essential Phone, available now

#368

Earlier quoted context omitted.

Decent specs, niche audience, cheap. Pick two.

That applies for niche audience laptops-- for example the gluglug laptop serves a small free-software fanbase but doesn't have decent specs. But for cellphones, lots of values of "niche audience" end up with, "pick zero." Here are some examples: 1. Hook up a keyboard to ssh into the device. 2. Hardware switch to turn off the baseband OS. 3. Software toggle to turn off the baseband OS. 4. Sandboxed baseband OS that is…

Check out postmarketOS. It's porting mobile linux to a whole host of old smart phones. It's a relatively new (open-source) project, but has already progressed considerably. A lot of people (myself included) are excited about the possibilities of having a fully hackable linux phone.

I am not active in the porting side right now, but am prototyping a mobile computing device that runs pmOS. It's kind of a neuromancer style ono-sendai portable deck: A rectangular box (approx 11x29x3cm) that you can opem up and velcro your linux phone into and have a full-sized, stainless steel, porclean, or plastic mechanical keyboard and foldable mouse with slots for extra memory and battery life. It is designed to be as compact and as durable as possible, while staying true to the postmarket name by sourcing from reused materials whenever possible.

My hypothetical market is mainly highly mobile autonomous individuals residing in developing world megacities, but I'm interested to know what someone from the US or Europe thinks about the idea.

Oh ya, one more thing, the profits go to pmOS, to scale up a re-wilding project, and to getting these hackable linux devices into the hands of children forced to work in the supply/waste chain of electronics manufacturing.

How's that sound?

Re: Essential Phone, available now

#369
Check out postmarketOS. It's porting mobile linux to a whole host of old smart phones. It's a relatively new (open-source) project, but has already progressed considerably. A lot of people (myself included) are excited about the possibilities of having a fully hackable linux phone.

I am not active in the porting side right now, but am prototyping a mobile computing device that runs pmOS. It's kind of a neuromancer style ono-sendai portable deck: A rectangular box (approx 11x29x3cm) that you can opem up and velcro your linux phone into and have a full-sized, stainless steel, porclean, or plastic mechanical keyboard and foldable mouse with slots for extra memory and battery life. It is designed to be as compact and as durable as possible, while staying true to the postmarket name by sourcing from reused materials whenever possible.

My hypothetical market is mainly highly mobile autonomous individuals residing in developing world megacities, but I'm interested to know what someone from the US or Europe thinks about the idea.

Oh ya, one more thing, the profits go to pmOS, to scale up a re-wilding project, and to getting these hackable linux devices into the hands of children forced to work in the supply/waste chain of electronics manufacturing.

Re: Essential Phone, available now

#370
post #348

Earlier quoted context omitted.

But your email app will still get updates right? (I guess I'm using Gmail and assuming you are using something like it that gets updates too, but maybe I'm wrong.) Same with SMS - lots of apps that get updates. What's the exact issue?

Apps do get updates, but they aren't the issue. The system/kernel/system libraries don't get updates and if they are compromised all your apps are compromised too. If someone know a vulnerability only in a normal app he can't do anything but look at only this one app, with system access well he can do way more. (Also Android got some additional security/privacy features after Android 4)

But the thing is, even if 100% of your apps are vulnerable, it doesn't mean anything unless the attacker can reach your phone somehow. That can only happen in 5 different ways: (1) Low-level Wi-Fi bug exploit, (2) SMS exploit, (3) Cellular exploit (like a Stingray), (4) Cellular internet connection (open ports, etc.), (5) App-level exploits.

I don't know of any critical examples of #1 that I would need to protect against where upgrading is my only solution (maybe I'll upgrade if I find one). #2 can be mitigated at the app level (see my reply to the other comment here) and probably faster so than the update you'd receive. #3 can't really be mitigated by phone updates. #4 is impractical since cells are behind carrier-grade NATs and don't have dedicated IP addresses to be reachable via the internet. And #5 just involves updating the app, not the OS or hardware.

If you can give me an example of an actual attack that cannot be prevented without upgrading the hardware or the OS, I would find that far more convincing than a hypothetical.

Post reply on HN