Live data from Hacker News

GrapheneOS – Break Free from Google and Apple

blog.tomaszdunia.pl

231–240 of 967 posts

Re: GrapheneOS – Break Free from Google and Apple

#231

It's a shame only Pixel phones are supported. I have PWM sensitivity and Pixel phones are notoriously bad for this, my eyes hurt when I look at one for more than 30mn. Due to the lack of good, secure alternative, I have had to give up on privacy in exchange for manufacturer updates.

Seriously. Especially if you're someone who wants to cut ties with Google.

Re: GrapheneOS – Break Free from Google and Apple

#232
post #163
post #142

Earlier quoted context omitted.

> It's mind boggingly stupid that they lock down apps like this, when you can just open the thing in a website anyway. I can use my bank on some linux distro... Not in Spain. I can access my bank's website but I can't do anything without their bank app. Even sometimes they require to confirm my identity using their app in order to access their website. I have several linux phones but I can only do banking with their…

Not in Spain. I can access my bank's website but I can't do anything without their bank app. Even sometimes they require to confirm my identity using their app in order to access their website. I've seen this elsewhere, and it's absolutely ridiculous. Why? Because in almost all cases, the apps may only be installed with Google Play, and require the framework to work correctly. And that means? If you are not in good s…

As far as I remember, last time I needed to use Google play on a shared phone I could just create a random Google address (I mean, completely invented name, etc.) and it allowed me to do anything, just as my normal Android.

I am too lazy to test, but did this change? Can't you just make a "fake" account and continue with your life? The phone company knows where you are, the bank knows what you purchase. Compared to that Google will know far less (ofc, if you don't activate everything)

I find it much more insane that it was possible for so long to do banking WITHOUT strong authentication (however implemented) by just providing those 3 numbers on the back of the card (strong security!)

Re: GrapheneOS – Break Free from Google and Apple

#233
post #142

Been using this for about a year on a p9 pro. It works very well. I hear the google tap to pay does not work, but I've never tried it. However Vipps with their tap to pay works fine. BankID works but not with biometric login, which some things require IIRC. And for some reason DnB private works fine, but you are not allowed in on the corp app. It's mind boggingly stupid that they lock down apps like this, when you ca…

> It's mind boggingly stupid that they lock down apps like this, when you can just open the thing in a website anyway. I can use my bank on some linux distro... Not in Spain. I can access my bank's website but I can't do anything without their bank app. Even sometimes they require to confirm my identity using their app in order to access their website. I have several linux phones but I can only do banking with their…

> Not in Spain. I can access my bank's website but I can't do anything without their bank app. Even sometimes they require to confirm my identity using their app in order to access their website.

https://triodos.es has 2FA via SMS, for what is worth.

Re: GrapheneOS – Break Free from Google and Apple

#234

This is especially interesting in regard to the recent HN dicussion on spyware by for-profit intel firms having access to Whatsapp, Telegram, Signal, etc. ( https://news.ycombinator.com/item?id=47033976 ) through OS-level no-click hijacks. I wonder how secure GrapheneOS is in that regard, and what the other contenders are?

It's quite secure against casual attacks, but a proprietary mobile platform has inherent issues wrt. withstanding even mildly sophisticated attackers, including mercenary spyware services. You still have a huge attack surface from all sorts of proprietary firmware blobs and hardware IP blocks that are running directly on the SoC. It's not clear that it's really worth even trying to secure it as opposed to just treati…

well, a concerted attack could easily subvert the baseband if you have a few million dollars and the correct letterhead or private contacts.

GrapheneOS really wants the software in the phone to not pwn the phone. This is good. Its a different, and much more difficult problem to secure the connection to the telco, and the larger internet, because the transport is attacker controlled.

Think of it this way: Say you use Qubes because security is valued very highly for you. Even if you run Qubes, if your router is controlled by your attacker, what kind of a security guarantee could you really get for yourself?

Re: GrapheneOS – Break Free from Google and Apple

#235
Been running GrapheneOS for a while on a Pixel 9, and extremely happy with it! Apart from the usual perks of the FOSS ecosystem, there are a few things specific to GrapheneOS that are not immediately apparent but have turned out to work very well -

1. The Pixel camera app works, including all modes and settings. A camera that takes good photos was absolutely a requirement for me, and the FOSS camera apps are not quite as good yet.

2. I don't have Google Photos and the pixel camera app tries to launch google photos when you want to review the picture you just took. But there is a FOSS app called GPhotosShim that uses the same namespace as google photos and thus fools the camera into launching that app instead. Once launched, it just launches whatever media management app you actually have configured, so it's seamless.

3. Android Auto works!

4. Android QuickShare works!

5. NFC tags / Yubikey integration works!

6. Screencasting works!

7. Sensor access and internet access can be disabled for apps by default (and I do).

Re: GrapheneOS – Break Free from Google and Apple

#236
post #142

Been using this for about a year on a p9 pro. It works very well. I hear the google tap to pay does not work, but I've never tried it. However Vipps with their tap to pay works fine. BankID works but not with biometric login, which some things require IIRC. And for some reason DnB private works fine, but you are not allowed in on the corp app. It's mind boggingly stupid that they lock down apps like this, when you ca…

> It's mind boggingly stupid that they lock down apps like this, when you can just open the thing in a website anyway. I can use my bank on some linux distro... Not in Spain. I can access my bank's website but I can't do anything without their bank app. Even sometimes they require to confirm my identity using their app in order to access their website. I have several linux phones but I can only do banking with their…

This should be illegal that the government forces people into apps controlled by private, commercial entities. I call such a government corrupt.

Here in central Europe I can still access the bank website fine without smartphone. I need a physical device to yield a TAN though, but I can access and do online transactions fine. So I think something is wrong with the spanish government. People need to protest.

Re: GrapheneOS – Break Free from Google and Apple

#237
post #117
post #98

Earlier quoted context omitted.

I would put the focus on having capable web-banking. I never install the banking app on my phone. I must also be getting old, because I don't get the big fuss about NFC payments. Firstly, I'd never use them if they go through Google/Apple. But even when/if they don't, it's not a big deal to use a card, isn't it (if you hate cash)?

Agreed about NFC, I'm happy to scan a QR code. > But even when/if they don't, it's not a big deal to use a card, isn't it (if you hate cash)? Card is usually linked to the US. Some people would like to not depend on that. But the rational solution IMO is for the banking system to use QR codes instead of NFC. Some countries do that and it just works .

> Card is usually linked to the US. Some people would like to not depend on that.

You have a point, and even though it looks like it will be a very corporate-driven system, and possibly dependent on Google or Apple, there seems to be an EU payment system on the making (if it ends up depending on Google or Apple, that will be the irony of leaving VISA/Mastercard to fall in the fangs of Google / Apple, but... oh well, one step at a time).

I think the name is Wero, it was on HN a few days ago.

Re: GrapheneOS – Break Free from Google and Apple

#238

Earlier quoted context omitted.

YMMV. I run sandboxed Google Play Services on GrapheneOS so almost every app works. My digital payments app works, and the same with most government apps I have tried. My private bank's app doesn't work, but I just use their website for the handful of times a year I need to access it.

Does NFC work with those digital payment apps on Graphene?

In India we use QR codes for payments. NFC in general does work (for example, I use a yubikey for 2FA).

Re: GrapheneOS – Break Free from Google and Apple

#239

Earlier quoted context omitted.

fyi a Cell Site Simulator can masquerade as the legitimate telco operator and push type 0 messages to the handset. What that means is they can push malicious settings and configurations (Definitely) and probably malicious firmware to the handset at will. They don't need to code this, they buy the software packages from the usual suspects. Adversary simply needs to put a drt box or a hailstorm or what-not close enough…

I don’t have the source (I’ll have to try find it), but I read that the cell site simulators can work on 4G and earlier but don’t work on 5G. So one thing folks can do is set ur phone to use 5G networks only (unless ur stuck and then u can make it looser but be aware your less protected at that time). I do this on iOS I’m sure it’s do-able on GrapheneOS and hopefully on Android too.

5G CSS is harder yes, but keep in mind that most 5G is the 5G_NSA variety, and is really just riding on the same cell bands, no mmwave here. You probably notice that your phone often slips out of 5g, or you inhabit different modes here.

Essentially, 5G is sort of a lie. Phones spend a lot of time exchanging information via 4g/lte, and just like 2g/3g and 3g/4g, there are simply downgrades that can be performed in the field, without getting too far into the weeds.

5G matters not for this.

Re: GrapheneOS – Break Free from Google and Apple

#240
How are the cameras on the latest devices running GrapheneOS? My last Android experience was the Oneplus One and the experience left me with the feeling that cameras are just too proprietary to work well once you go tinkering with custom ROMs and camera apps.

I'm not a photographer or anything, I just want to quickly point and shoot and get on with whatever I'm doing without thinking too hard.

Post reply on HN