Live data from Hacker News

Lindroid

twitter.com

61–70 of 94 posts

Re: Lindroid

#61
post #5

> full hw accelerated Linux on your Android as an app At this point, you can just run full GNU/Linux on a phone. Sent from my Librem 5.

Sure, but most people might need their phone to do banking apps or apps like WhatsApp, Spotify or Maps which are not available on your phone. This allows people to run GNU apps on their android phone so they can have both

Banking apps won't work with Lindroid either: https://news.ycombinator.com/item?id=40714796

Re: Lindroid

#62

Earlier quoted context omitted.

Huh, I don't have issues with RCS on my rooted OP7Pro. Is my version just sufficiently out of date not to have those extra checks?

I also have OP7Pro (what an amazing phone btw), and yes, we're pretty much sufficiently out of date that they still work - a wild but true reality we find ourselves in.

I mean my Messages app. I installed it years ago and never updated, because why would I ever updated an SMS app, the only thing that can ever happen is for things to break that used to be working, lol. I don't even know if I run A12.

I do know, though, that the OP7Pro is one of the last Android devices that are whitelisted by Google to pass SafetyNet without hardware-backed attestation. Shame that TWRP wiped my working setup. I've been trying to get them to add any basic protection against that for over three years: https://github.com/TeamWin/Team-Win-Recovery-Project/issues/...

It is an amazing phone. Notchless, relockable bootloader (not just unlockable, but custom AVB key support!!), in-screen fingerprint sensor, 90Hz AMOLED, and great build quality.

Re: Lindroid

#63
post #30

Earlier quoted context omitted.

As it’s Linux could we run android in a vm and simulate a safe device? That’s my hope for the future of mobile devices, safe VMs that we can run on top of the spyware (government enforced stuff too) infested phones.

Unfortunately, most of those misguided "device integrity" checkers detect VMs and the best of them (luckily still not used very often) are essentially unbeatable (unless there's a critical bug) due to hardware-backed attestation.

> essentially unbeatable (unless there's a critical bug) due to hardware-backed attestation.

FWIW Google started enforcing those attestations like one month or two ago, and there are many critical bugs. I haven't kept scores, but some other people did : https://x.com/wanghan1995315/status/1803063996204912873

And please note that they only list big brands leaks. Since you can use any OEM's attestation key, /any/ OEM leak can break those so-called "security protections". Even after all security flaws, there is still social engineering. I guesstimate that you could ask an ODM's engineer for an attestation key for like 1k$ and share it to like 20 persons. (200 would probably still remain under the radar, but you need to be capable of keeping a secret with 200 persons)

Though the conclusion shouldn't be that attestation keys are insecure and we need a secure variant (because a secure variant is indeed coming). The conclusion must be that users own the device they bought. Not Google, not Apple.

Re: Lindroid

#64
post #41
post #28

Earlier quoted context omitted.

Yup. I gave up on trying to get Google wallet / Android pay to work on my lineage device. I got it working sometimes but it broke after update and just wasn't reliable enough to keep trying when paying for stuff. I'm not really sure whom they're protecting with this stuff -- the credit card processing companies, maybe?

As far as I also understand Google Messages now uses this as well to gatekeep access to carrier RCS. https://www.theverge.com/2024/3/1/24087418/google-messages-b...

How do you know it's carrier RCS? To the best of my knowledge they are only gatekeeping access to Google Messages private network, not carrier RCS? (Considering the very little number of carrier RCS that's not very relevant though)

Re: Lindroid

#65
post #20

Neat project, but hate the branding. Android is Linux. I think it's really important to recognize that. Linux is not just not the one traditional POSIX style system, it's a platform to build all sorts of systems, including Android.

Americans, Chinese, and Nigerians are all humans, but it's sometimes useful to subdivide the large group for the sake of reference. This is why we say Android and not just Linux, as it helps us avoid "which Linux is it?"

Re: Lindroid

#66
post #28

Earlier quoted context omitted.

Yup. I gave up on trying to get Google wallet / Android pay to work on my lineage device. I got it working sometimes but it broke after update and just wasn't reliable enough to keep trying when paying for stuff. I'm not really sure whom they're protecting with this stuff -- the credit card processing companies, maybe?

> I'm not really sure whom they're protecting with this stuff -- the credit card processing companies, maybe? (small nit: does "whom" even go there?) They're protecting the TEE because they do not want third parties to be able to automate Google Pay through modified software. This isn't necessarily just about normal end users but more like smartphone farms.

>They're protecting the TEE

Why do Transesophageal Echocardiograms[0] need protecting, and from whom do such diagnostics require protection?

I expect I'm missing something, but a web search for 'TEE' only returns that diagnostic test.[1]

[0] https://www.webmd.com/heart-disease/atrial-fibrillation/tran...

[1] Moral: Don't assume everyone knows what a particular acronym means. Just because it's in your head doesn't mean everyone else knows what you mean.[2] E.g., if I say 'JRE' I mean 'Java Runtime Environment' and not 'Joe Rogan Experience'.

[2] According to Piaget[3], people are able to identify that others don't know what's in their heads sometime between ages two and seven.

[3] https://psychcentral.com/health/piaget-stages-of-development...

Re: Lindroid

#67
post #63

Earlier quoted context omitted.

Unfortunately, most of those misguided "device integrity" checkers detect VMs and the best of them (luckily still not used very often) are essentially unbeatable (unless there's a critical bug) due to hardware-backed attestation.

> essentially unbeatable (unless there's a critical bug) due to hardware-backed attestation. FWIW Google started enforcing those attestations like one month or two ago, and there are many critical bugs. I haven't kept scores, but some other people did : https://x.com/wanghan1995315/status/1803063996204912873 And please note that they only list big brands leaks. Since you can use any OEM's attestation key, /any/ OEM l…

> And please note that they only list big brands leaks. Since you can use any OEM's attestation key, /any/ OEM leak can break those so-called "security protections".

Inevitably though, the price of these will rise, the most capable eyes on the planet will have a few very thorough looks at all the TPM chip firmware they can get their hands on, and eventually platforms will be so secure and the price will be so high the only ones left to have them are three-letter agencies (if even these).

Anti tamper measures have their place - I'd really love to have a device that cannot have a persistent backdoor implanted - but the very second the state of the anti-tamper measure becomes visible to user-level applications, they become an arms race between Big Money (=DRM rightsholders and big game studios) and my freedom.

Re: Lindroid

#68

Earlier quoted context omitted.

> I'm not really sure whom they're protecting with this stuff -- the credit card processing companies, maybe? (small nit: does "whom" even go there?) They're protecting the TEE because they do not want third parties to be able to automate Google Pay through modified software. This isn't necessarily just about normal end users but more like smartphone farms.

>They're protecting the TEE Why do Transesophageal Echocardiograms[0] need protecting, and from whom do such diagnostics require protection? I expect I'm missing something, but a web search for 'TEE' only returns that diagnostic test.[1] [0] https://www.webmd.com/heart-disease/atrial-fibrillation/tran... [1] Moral: Don't assume everyone knows what a particular acronym means. Just because it's in your head doesn't mea…

Sorry, TEE stands for Trusted Execution Environment. It's where stuff like DRM executes with access to secrets that the HLOS (Android) can't tamper with. On ARM SoCs the TEE is usually provided as part of TrustZone. No need to patronize.

Re: Lindroid

#69
post #40

Earlier quoted context omitted.

I’d just like to interject for a moment. What you’re refering to as Linux, is in fact, GNU/LInux, or as I’ve recently taken to calling it, GNU plus Linux. Linux is not an operating system unto itself, but rather another free component of a fully functioning GNU system made useful by the GNU corelibs, shell utilities and vital system components comprising a full OS as defined by POSIX. Many computer users run a modifi…

PS. https://www.gnu.org/gnu/incorrect-quotation.en.html

> It is OK to call it “GNU” when you want to be really short, but it is better to call it “GNU/Linux” so as to give Torvalds some credit.

I love this line

Re: Lindroid

#70
post #63

Earlier quoted context omitted.

> essentially unbeatable (unless there's a critical bug) due to hardware-backed attestation. FWIW Google started enforcing those attestations like one month or two ago, and there are many critical bugs. I haven't kept scores, but some other people did : https://x.com/wanghan1995315/status/1803063996204912873 And please note that they only list big brands leaks. Since you can use any OEM's attestation key, /any/ OEM l…

> And please note that they only list big brands leaks. Since you can use any OEM's attestation key, /any/ OEM leak can break those so-called "security protections". Inevitably though, the price of these will rise, the most capable eyes on the planet will have a few very thorough looks at all the TPM chip firmware they can get their hands on, and eventually platforms will be so secure and the price will be so high th…

> I'd really love to have a device that cannot have a persistent backdoor implanted - but the very second the state of the anti-tamper measure becomes visible to user-level applications, they become an arms race between Big Money (=DRM rightsholders and big game studios) and my freedom.

The two can be reconciled by not having any privileged keys baked in by the manufacturer. It's only the manufacturers keeping records of the baked in attestation/signing key(s) that allows for remote attestation to be scaled up into treacherous computing. Otherwise if device owners could generate/load new attestation/signing keys and have them be indistinguishable from any original ones, then that same process can be emulated. This would likely require legislation to reign in manufacturers' desires to retain backdoors, but the point is that it is possible from a technical perspective.

Post reply on HN