Live data from Hacker News

Review: Copperhead OS

adventuresinoss.com

111–120 of 162 posts

Re: Review: Copperhead OS

#111
post #21

Reviewer touts "security focused" OS, promptly disables "trusted sources" check for installed software. Turn it back on, sure, until the next time you want an APK that's not listed in F-Droid. Seems like a bad idea. How about writing to your favorite app developers and asking them to list on F-Droid instead of sideloading?

FWIW, the "trusted sources" checkbox has been more of a way to scare away people from using Google's competitors (like the Amazon Appstore or F-Droid) than actually indicating any true trustworthiness, given that tons of malware comes from the Play Store, and Google Play Protect ranks dead last on AVTEST.org benchmarks for malware detection.

I believe Google finally introduced a way to deem other app stores as trusted on your phone, but given this is just a block on the manual installation feature, I would consider the trusted sources checkbox to be more "anticompetition focused" than "security focused".

Re: Review: Copperhead OS

#112

Earlier quoted context omitted.

I use that but it's all Google based. Not sure if you can decouple it from Play Services without breaking everything.

You can with microG, which even provides preconfigured builds with microG instead of Play Services - https://lineage.microg.org/

LineageOS for microG – Access Google services without closed software | https://news.ycombinator.com/item?id=15617615

Supported devices: https://wiki.lineageos.org/devices/

Re: Review: Copperhead OS

#113
post #83
post #26

Sometimes I am wondering what Google employees think when they read headlines like this one. I mean they probably have no problem giving the personal data to Google, but at the same time many of them are probably open source proponents and would support a world where the Google services would be entirely optional to Android. A few days ago I was thinking about a new smartphone and because my main problem with my curr…

> Sometimes I am wondering what Google employees think when they read headlines like this one. Hello Google employee here! I suspect we don't all have the same opinion but I can share my own since you asked. Note that I work in Cloud so I work in an area far far away from this stuff and opinions are obviously my own. Frankly the headline makes me a little bit sad because of course I would like to make things which pe…

> I like to think I'm a proponent of open source as I try to contribute but to be honest I don't actually think it really matters for Android to be independent of Google services because as far as I can tell, most people like Android with Google services?

Yeah but what about people who aren't most people? Are you saying they don't matter? That doesn't sound very open source.

Re: Review: Copperhead OS

#114
post #113
post #83

Earlier quoted context omitted.

> Sometimes I am wondering what Google employees think when they read headlines like this one. Hello Google employee here! I suspect we don't all have the same opinion but I can share my own since you asked. Note that I work in Cloud so I work in an area far far away from this stuff and opinions are obviously my own. Frankly the headline makes me a little bit sad because of course I would like to make things which pe…

> I like to think I'm a proponent of open source as I try to contribute but to be honest I don't actually think it really matters for Android to be independent of Google services because as far as I can tell, most people like Android with Google services? Yeah but what about people who aren't most people? Are you saying they don't matter? That doesn't sound very open source.

Those people by definition aren't Googles customers. And Google is the one developing the OS. Maybe Apple will be more open to developing an OS for people that hate them? :)

Re: Review: Copperhead OS

#115
post #46

I think there are some misconceptions in this thread (due to the title). Personally I use CopperheadOS as my daily driver because it stays continually ahead of Google (and groups like AOKP, LineageOS etc) in terms of Android hardening. It goes well beyond just not having Google Play services. See their details on their approach and design: https://copperhead.co/android/docs/technical_overview They make continued patc…

Your otherwise good comment probably should include two things that are critical to Google's stance on Android security:

1. They're a surveillance company that has more actual and potential earnings the more they know about their customers. They get good margins when their customers lack privacy with devices locked into Google by default.

2. They don't care about users' safety since make billions off Android platform but wont even patch vulnerabilities quickly. They have enough money to design a server UNIX from scratch plus a full-custom CPU plus mitigations from code injection at CPU level with all that leaving them with a few billion in revenue left out of Android alone. They just don't care since they're a public company about squeezing out every ounce of profit.

So, their incentives ensure they will leave the devices insecure. Someone will have to make their own versions that are secure like Copperhead and separation kernels before them (eg OK Labs) did. Alternatively, convince Google to offer a paid, secure option for their own internal use if nothing else with them recovering costs by eating up the cryptophone market's revenues.

Re: Review: Copperhead OS

#116
post #94
post #46

I think there are some misconceptions in this thread (due to the title). Personally I use CopperheadOS as my daily driver because it stays continually ahead of Google (and groups like AOKP, LineageOS etc) in terms of Android hardening. It goes well beyond just not having Google Play services. See their details on their approach and design: https://copperhead.co/android/docs/technical_overview They make continued patc…

Copperhead uses Grsecurity, and I used to use Grsecurity, when it was widely available, now that it's not and the developer has decided to act in hostile ways to the Linux community(1), it's made me rethink using his work and/or supporting him. Plenty of consultants make do fine without resorting to closing off their source code, and decide to act better with the community and/or companies. (1) https://www.theregiste…

Copperhead maintains the -hardened patchset, which is essentially a fork of Grsecurity, largely because of those concerns. (I don't use CopperheadOS on my phone, but I do use their work in the form of linux-hardened on my desktop!)

Re: Review: Copperhead OS

#117
post #46

I think there are some misconceptions in this thread (due to the title). Personally I use CopperheadOS as my daily driver because it stays continually ahead of Google (and groups like AOKP, LineageOS etc) in terms of Android hardening. It goes well beyond just not having Google Play services. See their details on their approach and design: https://copperhead.co/android/docs/technical_overview They make continued patc…

Your otherwise good comment probably should include two things that are critical to Google's stance on Android security: 1. They're a surveillance company that has more actual and potential earnings the more they know about their customers. They get good margins when their customers lack privacy with devices locked into Google by default. 2. They don't care about users' safety since make billions off Android platform…

Can you explain how 2.) follows from 1.) ? Or at least how exactly has Google incentive to keep Android insecure (especially in terms of all the security research/hardening being done by internal teams, both for Android and iOS)?

Re: Review: Copperhead OS

#118
post #46

I think there are some misconceptions in this thread (due to the title). Personally I use CopperheadOS as my daily driver because it stays continually ahead of Google (and groups like AOKP, LineageOS etc) in terms of Android hardening. It goes well beyond just not having Google Play services. See their details on their approach and design: https://copperhead.co/android/docs/technical_overview They make continued patc…

We've reverted the title above to the article title, since that's what the guidelines call for anyhow, unless it's misleading or linkbait. The submitted title was "Copperhead OS – De-Google Your Phone".

https://news.ycombinator.com/newsguidelines.html

Re: Review: Copperhead OS

#119
post #94
post #46

I think there are some misconceptions in this thread (due to the title). Personally I use CopperheadOS as my daily driver because it stays continually ahead of Google (and groups like AOKP, LineageOS etc) in terms of Android hardening. It goes well beyond just not having Google Play services. See their details on their approach and design: https://copperhead.co/android/docs/technical_overview They make continued patc…

Copperhead uses Grsecurity, and I used to use Grsecurity, when it was widely available, now that it's not and the developer has decided to act in hostile ways to the Linux community(1), it's made me rethink using his work and/or supporting him. Plenty of consultants make do fine without resorting to closing off their source code, and decide to act better with the community and/or companies. (1) https://www.theregiste…

CopperheadOS doesn't use grsecurity anymore afaik. https://twitter.com/CopperheadOS/status/933684025624993792

Re: Review: Copperhead OS

#120
post #25

> do think it will happen, however. The use case involves corporations, especially those involved in privacy sensitive fields such as health care. Wouldn’t it be cool to have a locked down “business” VM that is separate from a “personal” VM with your Facebook, games and private stuff on it. This already exists for businesses with Samsung Knox / Android for Business. No it's not a full OS but it fits all of their need…

> Having one OS in a "vm" on a phone sounds horrible UX wise I believe most android people are doing this with users. Since Android is now up to the task of docker (kernel 3.10+), it would be very nice to see apps sandboxed with permissions exposed via networked APIs. Then it is impossible for an app (sans exploit) to access private data, and simple for the OS to route certain apps to certain data sets (ie, fake cont…

How would your solution improve on current one, where apps are sandboxed by the permissions system and communicate via Binder which is also RPC based? You just added bunch of layers to architecture for no reason - none of serious Android exploits in years would be mitigated by your approach.
Post reply on HN