Live data from Hacker News

OnePlus OxygenOS built-in analytics

chrisdcmoore.co.uk

181–188 of 188 posts

Re: OnePlus OxygenOS built-in analytics

#181
post #171

Earlier quoted context omitted.

"expected device maintenance" by whom? Anecdata, but 90% of people I know have never installed Linux (and the few times I've had to try and find recovery discs, going to bet reinstalling Windows is at about the same percentage), and not sure I know anyone who's flashed a new ROM on Android. I'm genuinely curious as to where this expectation that everyone should be au fait with OS tinkering comes from?

I didn't say everyone, the audience on HN is far from 'everyone.'

My everyone could easily encompass the HN audience too - there's this stock assumption (especially if you're a developer or tech inclined) that other techies are always tinkering and optimising. Buying a consumer electronics product and not having to mess around with it should be the standard (with an option to tinker if you so wish), whether you read HN or not.

Re: OnePlus OxygenOS built-in analytics

#182
post #161

Earlier quoted context omitted.

Who will pay for that and how are you going to force manufacturers to participate in such scheme? Most people "have nothing to hide" and don't care about privacy, so they won't be happy as manufacturers pass cost of this to them. More realistic way (though not easy too) is to install a firewall on a proxy all traffic is run through and filter suspicious/unknown connections.

Manufacturers or software developers who're especially privacy-conscious, or collecting data that wouldn't be able to get with otherwise, might use this scheme. Maybe the folks who run the upstream server will also pay for the intermediate server. It shouldn't cost much for an entity that's already operating at scale, whether in users or revenue.

"Manufacturers or software developers who're especially privacy-conscious"

Those are few and far between. I still don't see how you are going to get major players into this. Niche -- maybe, but we already have few of these (other comments in this thread mention them). Also, such server would be a very sweet target for hackers and high security requirement raises upkeep by quite a bit.

Re: OnePlus OxygenOS built-in analytics

#183
post #120

Earlier quoted context omitted.

Flashing a third party ROM is probably your best bet. I'm curious to what phones you're considering to replace your OP3 with, though. For myself, I've been looking for something that has "much better than average" security and, unfortunately for any mobile platform, that looks like it's probably not going to happen. The closest ROM I've found is CopperheadOS, but it is only supported on a few devices.

I'm probably just going to flash Lineage. I have plenty of past experience with CM so it should be fairly familiar and it apparently works extremely well on the OnePlus 3 (I've seen the OP3 labeled the perfect phone for Lineage in the past, so hopefully that is true) In terms of phones, I don't know. The Pixel 2 XL, Galaxy S8, Note 8, and LG V30 are probably the best Android devices available right now. I haven't don…

> I'm feeling fairly jaded right now and half-considering switching to an iPhone and away from a lot of Google services because Apple seems to at least half-care about privacy.

Exactly my stance. I am sure Apple is shady as well but it's my opinion (partially supported by numerous stories here on HN) that Google collects and sells anything they can get their hands on.

I'm buying iPhone X for me and my girlfriend (when it finally comes out). We already have iPad Pros. We'll just go full Apple except the gaming PCs. We will change all passwords from inside one of the iDevices as an additional security measure. Most likely gonna use YubiKey 4 as well -- although I am still not informed enough to make the decision.

Already using DuckDuckGo 95% of the time -- sadly it is not as good as Google but really, most of the time it gives me what I need. Still not sure Firefox is up to the task to replace Chrome, but I'm keeping an eye out and using the beta (Quantum).

End-game is gonna be to replace Gmail with something else.

I feel I can't trust Google with telling me the time these days so I am migrating away from them.

Re: OnePlus OxygenOS built-in analytics

#184
post #182

Earlier quoted context omitted.

Manufacturers or software developers who're especially privacy-conscious, or collecting data that wouldn't be able to get with otherwise, might use this scheme. Maybe the folks who run the upstream server will also pay for the intermediate server. It shouldn't cost much for an entity that's already operating at scale, whether in users or revenue.

"Manufacturers or software developers who're especially privacy-conscious" Those are few and far between. I still don't see how you are going to get major players into this. Niche -- maybe, but we already have few of these (other comments in this thread mention them). Also, such server would be a very sweet target for hackers and high security requirement raises upkeep by quite a bit.

No more a target for hackers than upstream log servers. In fact, it will be easier to audit, since it's open-source and does less (only aggregate and anonymise data and pass it on).

Yes, it will be niche to begin with, but everything starts that way. If minor players adopt this, over time, it can put pressure on the big players to do so as well. It's a long game.

For example, MS opened an Azure datacenter in Germany where MS doesn't have access to user data. So, people are starting to do things to restrict their own access.

Re: OnePlus OxygenOS built-in analytics

#185
post #164

Earlier quoted context omitted.

No. You can relock your bootloader and reflash the stock rom provided by OnePlus if you wish.

Isn't there an eFUSE that gets set on the unlock?

https://oneplus.net/support/answer/will-rooting-or-unlocking...

Re: OnePlus OxygenOS built-in analytics

#188
post #176
post #163

Earlier quoted context omitted.

Evil, herp derp. It was done by malware, to steal user data, hence the change. If you want to log Google data traffic, you have to put a CA cert into the system cert store (needs root access).

If a user installs malware from the Play Store, that's his fault, and it's Google's fault for allowing that malware on the store. If he sideloads malware, that's his fault entirely. Preventing me from controlling my phone is evil. Preventing me from seeing what the apps on my phone are doing is evil. If I wanted a padded room or a walled garden, I'd be using iOS.

Defense in depth.

Google can't catch everything from the Play store, hence the CA cert store change.

Post reply on HN