Live data from Hacker News

On privacy and control

toidiu.com

111–120 of 132 posts

Re: On privacy and control

#112

"The problem is that the word "privacy" is dialuted[sic] and mean different things to different people. Instead of "privacy" we really should be talking about "control"." It's arguable that without control there can be no "privacy and security", including relief from data collection, surveillance and ads. The so-called "tech" companies that profit from data collection, surveillance and ad services are going to protec…

In the context of personal computers, is it possible to attain "privacy and security" without control

For example, can a "Big Tech" company attain "privacy and security" if it does not have control over its computers. What if it delegates control to someone else such as an individual home internet subscriber

For another example, can an individual home internet subscriber attain "privacy and security" if he does not have control over his computers. What if the subscriber delegates control to a "Big Tech" company

Re: On privacy and control

#113

Earlier quoted context omitted.

1. It's not possible to root GrapheneOS or any Android-based OS and preserve the Android security model. That would run entirely counter to the goal of the GOS. It can be done but shouldn't. 2. They have implemented kill switches for these on the software level. Afaik there's nothing up dispute these working just as well as hardware switches assuming proper verified install of GOS.

1. I've read that rooting breaks Android's security model, but I have yet to find a detailed explanation of how it actually lowers Android's security, especially compared to desktop OSes that are usually rooted, like Linux or MacOS. 2. Software kill switches are prone to software attacks, aren't they? They can't be as secure as hardware kill switches unless we can prove the software kill switches can't be attacked by…

> how it actually lowers Android's security, especially compared to desktop OSes that are usually rooted, like Linux or MacOS

Mobile OSes are notoriously more secure than desktop ones, precisel because of the security model.

Re: On privacy and control

#114
post #77
post #57

Earlier quoted context omitted.

You're blowing this entirely out of proportion. The vast vast majority of apps work without issue with sandboxed play services. Yes it's less plug and play than a stock os. No it's not a life-ending inconvenience.

Just looked - Microsoft Authenticator doesn't appear to work. I might be able to get off of it but it will take some prep. My banks are supported so that's good.

Microsoft Authenticator works on my GrapheneOS (I have the Play Services, not sure if it matters).

Re: On privacy and control

#115

Earlier quoted context omitted.

I usually ask if they poop with the door closed. We all know what you are doing in there, and we do the same thing. No need to hide. Or, why do you get your mail in an envelope? I can see that it is your financial statements. Why do you have curtains on your home? I can go to Zillow and see the interior of your house from years ago.

I think the better argument is (of course, a wrong one), "I trust that big companies won't share my stuff publicly".

Why is that wrong? In the vast majority of cases (at least in Europe) they don't. Now we have the GDPR it's even more difficult.

Re: On privacy and control

#116

Earlier quoted context omitted.

1. It's not possible to root GrapheneOS or any Android-based OS and preserve the Android security model. That would run entirely counter to the goal of the GOS. It can be done but shouldn't. 2. They have implemented kill switches for these on the software level. Afaik there's nothing up dispute these working just as well as hardware switches assuming proper verified install of GOS.

1. I've read that rooting breaks Android's security model, but I have yet to find a detailed explanation of how it actually lowers Android's security, especially compared to desktop OSes that are usually rooted, like Linux or MacOS. 2. Software kill switches are prone to software attacks, aren't they? They can't be as secure as hardware kill switches unless we can prove the software kill switches can't be attacked by…

Approximately, if the user doesn't have root then there's no way to trick them. They also can't access internal app files which gives app authors tight control over how their software is used.

That's the security model. Giving users root breaks both of those assumptions, hence it breaks the security model.

Notice that it is clearly in the best interests of users to at least have this option. But modern BigTech operating systems are designed around corporate interests, not yours. And security professionals seem to prefer to ignore inconvenient things like user freedom.

Re: On privacy and control

#117

My next low hanging fruit is certainly to make my LLM usage local, my queries contain much more sensitive information than what is mentioned by this post. In the past I dropped off privacy when it was too inconvenient. For example I dropped protonmail because of bad search, left Linux desktop for Windows due to missing software, etc, I still haven't found the sweet spot for LLMs yet. For the rest, I'm currently runni…

The absence of solutions for LLM privacy on that list is telling. We’ve figured out how to have private communications with other humans via end to end encryption but arguably we’re leaking a lot more to chatbots about ourselves in a few sessions than we do to even our closest friends and family over Whatsapp

Re: On privacy and control

#118

Earlier quoted context omitted.

1. I've read that rooting breaks Android's security model, but I have yet to find a detailed explanation of how it actually lowers Android's security, especially compared to desktop OSes that are usually rooted, like Linux or MacOS. 2. Software kill switches are prone to software attacks, aren't they? They can't be as secure as hardware kill switches unless we can prove the software kill switches can't be attacked by…

Approximately, if the user doesn't have root then there's no way to trick them. They also can't access internal app files which gives app authors tight control over how their software is used. That's the security model. Giving users root breaks both of those assumptions, hence it breaks the security model. Notice that it is clearly in the best interests of users to at least have this option. But modern BigTech operat…

> Approximately, if the user doesn't have root then there's no way to trick them.

So not having root (somehow?) prevents phishing and tricking? That doesn't seem useful or relevant for people who know what they're doing. If I'm wrong, please elaborate.

> They also can't access internal app files which gives app authors tight control over how their software is used.

I read that in the security model and I don't care for it. App authors shouldn't have any control over how their software is used. In my opinion, of course, but for my computers my opinion is what matters.

Re: On privacy and control

#119
post #113

Earlier quoted context omitted.

1. I've read that rooting breaks Android's security model, but I have yet to find a detailed explanation of how it actually lowers Android's security, especially compared to desktop OSes that are usually rooted, like Linux or MacOS. 2. Software kill switches are prone to software attacks, aren't they? They can't be as secure as hardware kill switches unless we can prove the software kill switches can't be attacked by…

> how it actually lowers Android's security, especially compared to desktop OSes that are usually rooted, like Linux or MacOS Mobile OSes are notoriously more secure than desktop ones, precisel because of the security model.

Okay, but could you give me some examples? How is Android or iOS more secure than Linux or Qubes?

Re: On privacy and control

#120

Earlier quoted context omitted.

Approximately, if the user doesn't have root then there's no way to trick them. They also can't access internal app files which gives app authors tight control over how their software is used. That's the security model. Giving users root breaks both of those assumptions, hence it breaks the security model. Notice that it is clearly in the best interests of users to at least have this option. But modern BigTech operat…

> Approximately, if the user doesn't have root then there's no way to trick them. So not having root (somehow?) prevents phishing and tricking? That doesn't seem useful or relevant for people who know what they're doing. If I'm wrong, please elaborate. > They also can't access internal app files which gives app authors tight control over how their software is used. I read that in the security model and I don't care f…

I agree with you of course. The thing I find frustrating is the willingness of the GrapheneOS (and to a lesser extent LineageOS) devs to toe the corporate line, accepting anti-user-freedom bullshit in the name of this non-security.

> trick them [ into granting root ]

Apologies for the ambiguity.

Post reply on HN