Earlier quoted context omitted.
Well if you really want a phone that's secure and private, prove it by paying for it. Mass production and the ability to sell your data to advertisers means the stuff that does that will always be cheaper.
How does the Librem 5 support verified boot? What about user data encryption? Those are the first, most basic security features I am expecting from a smartphone. How about app sandboxes and strict MAC policies?
Android launches yet another way to spy on users with “Privacy Sandbox” beta
131–140 of 156 posts
Re: Android launches yet another way to spy on users with “Privacy Sandbox” beta
#132Ron Amadeo is so relentlessly critical of Google I've stopped reading his articles. Overall I find coverage on Ars to be pretty good but he really seems to have an axe to grind.
Where do you see this? This claim was also made earlier in the comments on this article. But looking at Amadeo's history - at least at the headline level - I don't see it: https://arstechnica.com/author/ronamadeo/
Re: Android launches yet another way to spy on users with “Privacy Sandbox” beta
#133Earlier quoted context omitted.
> the Google Play store doesn't work but that's no big loss It's the loss of an entire ecosystem worth of apps. If you want an inexpensive phone that will get five or six years of first party support with security updates after that, go with an iPhone SE. The original $399 version got six years of OS updates and just got another security update last month. That's $67 per year that got both an OS update and security u…
>It's the loss of an entire ecosystem worth of apps. He literally just said that he used the Aurora store as an alternative. If you don't know what that is, it is basically an anonymous version of the Play Store. Highly recommended
Re: Android launches yet another way to spy on users with “Privacy Sandbox” beta
#134Earlier quoted context omitted.
With hardware remote attestation there will no longer be any point in even owning an android phone anyway. Android is obviously inferior to iOS in every way but the whole point was you could have control over the machine and do whatever you wanted. Now apps will be able to verify that you "tampered" with the phone and will refuse to run, and since it's hardware cryptography it cannot be faked without massive effort.…
> Android is obviously inferior to iOS in every way Damn how i hate to write that: At least on Android you can turn off WI-Fi and mobile data, unless iOS which keeps it enabled "for system services".
Re: Android launches yet another way to spy on users with “Privacy Sandbox” beta
#135Earlier quoted context omitted.
Yeah, sure. An "optional security feature". > don't complain when services don't want to serve you or treat you different since you are less secure than the other users Hell no. They should not be allowed to discriminate against me just because I chose to own my system. They should not even be able to figure out what software I'm running, to say nothing of "treating me different". "Don't want to serve us" unless we l…
>They should not be allowed to discriminate against me just because I chose to own my system. App developers don't care if you own your system. They just want a way to prove that the device their app is running on is secure and that the client has not been modified. If there was a way for you to prove that to them they wouldn't mind. >They should not even be able to figure out what software I'm running, to say nothin…
> They just want a way to prove that the device their app is running on is secure and that the client has not been modified.
Contradictory. If I own the system, I can obviously modify it and everything running on it. Including your app. Therefore what they want is proof that I don't own the system.
> They just want to know that the client has not been tampered with
"Tampered with" -- there's that language again. Owning my computer is not "tampering", it is freedom.
> They just want some guarantees about the environment they are operating in.
Who cares what they want? It's my machine, I decide what they get. If they get anything at all. If I want them to believe they are running on a clean environment, that's what they should believe.
> The information that they get from you is the package's name, certificate, version, whether it's from the play store, whether your device passes integrity checks, and whether the app is properly licensed.
"Integrity" checks? Rooting my phone does not violate its "integrity". If anything it restores it.
Certificates? Store? Licensing checks? Look at all this crap that must be installed on "my" system just to give you your "guarantees". My phone's gotta come out of the factory pwned at the hardware level for your "guarantees" to be worth anything. It has to come with a full root of trust from the firmware to the bootloader to the operating system to each individual app just to prevent my "tampering". But you're seriously claiming apps aren't invading our machines.
An app "wanting" anything is invasion enough.
Re: Android launches yet another way to spy on users with “Privacy Sandbox” beta
#136Earlier quoted context omitted.
>They should not be allowed to discriminate against me just because I chose to own my system. App developers don't care if you own your system. They just want a way to prove that the device their app is running on is secure and that the client has not been modified. If there was a way for you to prove that to them they wouldn't mind. >They should not even be able to figure out what software I'm running, to say nothin…
> App developers don't care if you own your system. > They just want a way to prove that the device their app is running on is secure and that the client has not been modified. Contradictory. If I own the system, I can obviously modify it and everything running on it. Including your app. Therefore what they want is proof that I don't own the system. > They just want to know that the client has not been tampered with…
I disagree. You can have control in modifying your system, but the software just needs a way to prove that the security features it assumes are true. There could be a way for it to analyze the changes you made and decide whether or not it should trust your system.
>"Tampered with" -- there's that language again. Owning my computer is not "tampering", it is freedom.
It's someone else's software. You may own your computer, but you don't own the YouTube client. Google owns the YouTube client. Tampering with Google's client is tampering.
>"Integrity" checks? Rooting my phone does not violate its "integrity". If anything it restores it.
No, it does not. One part of Android's security model is that app's have storage that only they can access. Take for example a 2FA app which stores it's private key in this location. This makes it so that you must physically have your phone in order to get a 2FA code. This is the "something you have" part of 2FA. Rooting your phone violates the integrity of the system because now someone can just become root and steal the private key. Now they can generate 2FA codes without physically having the device with them. It then becomes another "something you know."
>My phone's gotta come out of the factory pwned at the hardware level for your "guarantees" to be worth anything.
These are security features. Your phone is less secure without them. It's not pwned.
>An app "wanting" anything is invasion enough.
Everyone wants something. Every business transaction includes both parties wanting something from the other.
Re: Android launches yet another way to spy on users with “Privacy Sandbox” beta
#137Earlier quoted context omitted.
I run Lineage Even without GApps, Lineage still includes links to Google. e/OS had a list of some of these at one time. They remove these links and include MicroG in the default install. Others may disagree but in my opinion, it is a pretty good compromise between security, privacy and usability.
I think the links are very few, the main one being captive portal detection for wifi logins. In exchange for this, Lineage delivers the monthly security patches first, mostly guaranteed to be in place by the 15th of every month (load the first nightly published after that date, and it will be bundled).
Re: Android launches yet another way to spy on users with “Privacy Sandbox” beta
#138Bottom line --- Google is privacy invasion by default. I use e/OS with Brave browser --- privacy by default. Both based on Google source but cleansed and stripped of tracking. Personalized ads are mainly an annoyance and a really dumb idea in my opinion. Context sensitive ads are much easier to implement, more privacy respecting and the only ones that are moderately useful and acceptable.
Basically. This is how they make their money. So, no one should be under any illusions about the culture of Google and all of their adherents. Go wants to introduce tool-chain telemetry as a default (opt-out only).
Re: Android launches yet another way to spy on users with “Privacy Sandbox” beta
#139I have a bunch of issues with the "Privacy Sandbox", but my #1 issue is that it's called "Privacy Sandbox". That term implies that a sandbox is being used to preserve your privacy, when it is, in fact, a system designed for the opposite of that.
After all the crap that Google put in Android, I still don't understand why some other alternative ecosystems like Ubuntu Phone or GrapheneOS or Mankato (PinePhone) aren't attractive for users and developers. What's holding everyone back? I understand that without users there won't be apps, but also without apps there won't be users, since they offer just the basics. Imagine if TikTok or WhatsApp have had an app for…
Re: Android launches yet another way to spy on users with “Privacy Sandbox” beta
#140Earlier quoted context omitted.
It's the loss of an entire ecosystem worth of apps. No, it's not. With very few exceptions, the Aurora store pulls apps from Google Play. About the only thing I have seen missing from Aurora store is a few super strict banking apps but you can usually just use their web site.
No paid apps though, right? That would be somewhat painful for me.
This isn't so bad if you use a privacy focused ROM and create a special, single purpose Google login that is only used for app purchases. I also suggest keeping a Google gift card for the occasional purchase.
Privacy invasion doesn't really kick in until you start re-using your Google login and your phone/apps are reporting back to Google on a regular basis with your location, device IMEI, advertising ID, hardware fingerprint, email address, browsing/search history, banking/purchase details (aka Google Pay), etc..