Earlier quoted context omitted.
Did you actually find any examples of GrapheneOS phoning home? GrapheneOS doesn't rely on any third-parties I'm aware of. The only service provided is over-the-air security updates. It doesn't even come with an app store (although you can install F-Droid). For that reason, GrapheneOS alone fits all three categories you mentioned: It is Android, it is GrapheneOS, and it is fully controllable / doesn't ship bloatware.
"The only service provided is over-the-air security updates." Connectivity check / time servers https://grapheneos.org/articles/grapheneos-servers#grapheneo... Amongst others.
Android phones are sending significant amount of user data with no opt-out [pdf]
221–230 of 377 posts
Re: Android phones are sending significant amount of user data with no opt-out [pdf]
#222Earlier quoted context omitted.
The article doesn't mention screenshots at all.
> System apps on several handsets upload details of user interactions with the apps on the handset (what apps are used and when, what app screens are viewed, when and for how long). I am too far away from Android development to make any claim about what "app screens" are. Is that android-lingo? Could someone please clarify?
It allows you to know which screens a user views, but not the data on the screen. A pseudo-example would be like "User opened LoginScreen/LoginActivity at yyyy-mm-dd and stayed on that screen for X seconds"
Not an actual screenshot of said screen
Re: Android phones are sending significant amount of user data with no opt-out [pdf]
#223Earlier quoted context omitted.
Some Android flavors, including /e/[1] and GrapheneOS,[2] don't use Google servers for the internet connectivity check by default. [1] https://gitlab.e.foundation/e/backlog/-/issues/268#note_1809... [2] https://grapheneos.org/faq#default-connections
Looking through the GrapheneOS source, the servers may not be Google servers but the system is still designed to phone home. As such, have they solved the problem or is this just another case of "Dont' trust them, trust us instead." Has anyone succeeded in running multiboot on "smartphone" hardware, i.e., where the user can boot into a choice of kernel/userland. One choice might be Android, another might be GrapheneO…
Re: Android phones are sending significant amount of user data with no opt-out [pdf]
#224Last I checked the default keyboard samsung installs on their phones was collecting what you typed and sharing/selling that data with third parties. I try not to store or access any personal information on my cell phones when i can avoid it, but at a certain point, just having one is enough to seriously compromise your privacy. Strong regulation with real sharp teeth is the only thing that can fix this situation.
Strong regulation by whom? The organization that brought us the CIA, NSA, FBI, and the rest of the alphabet soup of “security” bureaucracies that spy on us arbitrarily? Strong regulation could easily worsen the problem, as it can lead to a ratcheting up of the regulatory burden until only mega corps like Apple and Google could afford to make phones, and upstarts like Purism and Pinephone get squeezed out. How about b…
Which origination do you think that is? you think they all came from the same place? Every one of these agencies came into existence under very different circumstances at different times and they fall under different branches and operate in different areas. Do you mean "government" in general?
Yes, it's a horrible thing that these agencies are being used to spy on all American citizens in violation of our freedoms, but that fact doesn't mean that we shouldn't allow any government agency anywhere enforce regulations. How that does that make any sense at all? You could say the same for literally anything. "Who should regulate the amount of lead in our drinking water? The organization that brought us the CIA, NSA, FBI, and the rest of the alphabet soup of “security” bureaucracies that spy on us arbitrarily?"
> Strong regulation could easily worsen the problem, as it can lead to a ratcheting up of the regulatory burden until only mega corps like Apple and Google could afford to make phones, and upstarts like Purism and Pinephone get squeezed out.
It literally couldn't worsen the problem of our privacy being violated and used against us by cell phone companies. If it's illegal for Google to do it, and we had regular independent verification that they were not violating those laws, than it wouldn't matter if the only cell phones that existed on the whole of Earth were made by Google. Google still wouldn't be doing the bad thing we're trying to stop.
Yes, I'd prefer to have more choices but there's zero requirement that regulations make it prohibitively expensive for any company even an upstart. In fact, because this would be regulation against collecting, securing, maintaining, analyzing, marketing, and selling our personal data it'd actually save companies tons of money since they'd no longer be dong any of those things. Established companies who are currently exploiting consumers won't get to profit off of them as they are currently, but they will still save a lot of time and money not exploiting the public.
> How about before getting so gung ho with pointing the government gun at everyone’s head, we consider the option of rolling back the unjust regulations that already exist which give the mega corps undue government privilege (patents are a good place to start)
This isn't an either/or type of thing. There's a lot of great and important things we should be doing. This is one of them. Let's do them all.
> and encouraging (by voting with our wallets) organic alternatives to emerge, like they already are doing.
If "the market" were going to solve this problem, if it were capable of solving this problem, it would have been solved already. It's not. Until strong regulations are in place there will continue to be a very very strong perverse incentive to not solve this problem. We're coming up on 50 years of mobile phone technology and at present there are no comparable options for cell phones and mobile networks that preserve privacy. None. It's not regulations forcing Google and Apple to collect our personal data. They are choosing to do it. They could stop tomorrow if they wanted to. They don't want to. They won't stop until they are forced to stop.
Re: Android phones are sending significant amount of user data with no opt-out [pdf]
#225Earlier quoted context omitted.
Most banks in EU require phone app based confirmations for transfers and other operations (according to PDS2 directive). Visa and Mastercard also introduced 3DSecrue system which piggybacks on the same system of confirmations. Vendors are incentivised to adopt it by lower rates. In essence when paying with card or making a wire transfer (or using some instant transfer method, for example Blik in Poland), you get noti…
It depends per bank; mine discontinued the paper OTP pad as well as the SMS codes, and gave me a separate 2FA device when I didn't want to use their app. I don't think banks can force you to have a smartphone yet.
Re: Android phones are sending significant amount of user data with no opt-out [pdf]
#226I use GraphineOS and LineageOS without Google Play Services. They are great and are suitable replacements for Apple and Google. - Osmand(FOSS) for maps (supports being fully offline!) - Signal and Discord for messaging (Discord is sandboxed) - Newpipe(FOSS) for Youtube - F-droid(FOSS) for my FOSS appstore - APKmirror for the few non-free apps I need - Libretorrent(FOSS) and VLC(FOSS) for watching movies - Firefox(FOS…
> ...and have a better experience in every category than iOS, hardware and software. Really? I tried GrapheneOS on a Pixel 4A, and without exaggerating or trying to come off sensationalist the experience was really tepid compared to iOS, and even "normal" Android. Stuttering and jerky UI (which often also wanted to take a brief nap), very poor GPU hardware acceleration support, notably worse battery life, loads of th…
Pretty sure GrapheneOS doesn't do anything to change GPU h/w acceleration.
Re: Android phones are sending significant amount of user data with no opt-out [pdf]
#227Earlier quoted context omitted.
> ...and have a better experience in every category than iOS, hardware and software. Really? I tried GrapheneOS on a Pixel 4A, and without exaggerating or trying to come off sensationalist the experience was really tepid compared to iOS, and even "normal" Android. Stuttering and jerky UI (which often also wanted to take a brief nap), very poor GPU hardware acceleration support, notably worse battery life, loads of th…
The mid-level processor on the Pixel 4a may just not be performing to your expectations. A phone with a high-end processor would perform better. For GrapheneOS, the fastest compatible phone available (used/refurbished) right now is the Pixel 4 (or Pixel 4 XL). Also, if you are using a Pixel phone with a non-default flavor of Android, the Google Camera app still works if you download it manually. APKMirror is a trustw…
Re: Android phones are sending significant amount of user data with no opt-out [pdf]
#228A distinction needs to be made clear here with regards to the data being transmitted to Google by LineageOS in this study. In the cited paper ( https://www.scss.tcd.ie/Doug.Leith/Android_privacy_report.pd... ), the device used to test LineageOS was a Google Pixel 2 running LineageOS 17.1 which also included an installation of OpenGapps 10.0 nano . It's not the OS that is transmitting the data over to Google, but rath…
> One can find custom LineageOS builds that include MicroG Why bother? Just use Calyx.
Re: Android phones are sending significant amount of user data with no opt-out [pdf]
#229Earlier quoted context omitted.
Some Android flavors, including /e/[1] and GrapheneOS,[2] don't use Google servers for the internet connectivity check by default. [1] https://gitlab.e.foundation/e/backlog/-/issues/268#note_1809... [2] https://grapheneos.org/faq#default-connections
Looking through the GrapheneOS source, the servers may not be Google servers but the system is still designed to phone home. As such, have they solved the problem or is this just another case of "Dont' trust them, trust us instead." Has anyone succeeded in running multiboot on "smartphone" hardware, i.e., where the user can boot into a choice of kernel/userland. One choice might be Android, another might be GrapheneO…
Re: Android phones are sending significant amount of user data with no opt-out [pdf]
#230Earlier quoted context omitted.
Some will, however I have heard some of these apps have janky hooks into Android's trust system which will break them on non-google distros. Personally I wouldn't suggest having banking apps on a phone. You can always use the web browser if you absolutely must access those accounts.
Most banks in EU require phone app based confirmations for transfers and other operations (according to PDS2 directive). Visa and Mastercard also introduced 3DSecrue system which piggybacks on the same system of confirmations. Vendors are incentivised to adopt it by lower rates. In essence when paying with card or making a wire transfer (or using some instant transfer method, for example Blik in Poland), you get noti…