Live data from Hacker News

GrapheneOS – Break Free from Google and Apple

blog.tomaszdunia.pl

311–320 of 967 posts

Re: GrapheneOS – Break Free from Google and Apple

#311

Been using this for about a year on a p9 pro. It works very well. I hear the google tap to pay does not work, but I've never tried it. However Vipps with their tap to pay works fine. BankID works but not with biometric login, which some things require IIRC. And for some reason DnB private works fine, but you are not allowed in on the corp app. It's mind boggingly stupid that they lock down apps like this, when you ca…

[flagged]

Re: GrapheneOS – Break Free from Google and Apple

#312
post #142

Earlier quoted context omitted.

> It's mind boggingly stupid that they lock down apps like this, when you can just open the thing in a website anyway. I can use my bank on some linux distro... Not in Spain. I can access my bank's website but I can't do anything without their bank app. Even sometimes they require to confirm my identity using their app in order to access their website. I have several linux phones but I can only do banking with their…

This should be illegal that the government forces people into apps controlled by private, commercial entities. I call such a government corrupt. Here in central Europe I can still access the bank website fine without smartphone. I need a physical device to yield a TAN though, but I can access and do online transactions fine. So I think something is wrong with the spanish government. People need to protest.

The DSA European digital wallet spec currently requires Google or Apple attestation, so not for much longer.

And that is mandated by the EU.

Re: GrapheneOS – Break Free from Google and Apple

#313
post #142

Earlier quoted context omitted.

> It's mind boggingly stupid that they lock down apps like this, when you can just open the thing in a website anyway. I can use my bank on some linux distro... Not in Spain. I can access my bank's website but I can't do anything without their bank app. Even sometimes they require to confirm my identity using their app in order to access their website. I have several linux phones but I can only do banking with their…

I don't know which banks you are using but in my case I work with five Spanish banks and I can do everything from their websites, no app required. Yes, they try to push you to use their app, some tried to activate mobile 2fa for me when this psd2 thing became mandatory but I always told them their app doesn't work on my phone (which is true) and they offered me alternate methods like sms.

In my country we have a large religious population who eschew the smartphone. This means that no government, banking, or other services require a smartphone.

Re: GrapheneOS – Break Free from Google and Apple

#314
post #42

It's a shame only Pixel phones are supported. I have PWM sensitivity and Pixel phones are notoriously bad for this, my eyes hurt when I look at one for more than 30mn. Due to the lack of good, secure alternative, I have had to give up on privacy in exchange for manufacturer updates.

The Pixel limitations has been my main concern as well. The good news is that they are actively working on developing their own hardware. The bad news is that it’s been delayed. But I’m watching closely. https://www.galaxus.at/en/page/grapheneos-postpones-pixel-al...

That article speculates the OEM is Samsung but I find that very hard to believe. Samsung is totally beholden to Google. The discontinued their own DeX and Tizen smartwatch OS for Google alternatives and as for their "AI" features most of them actually come from Google.

Google would not allow this and they're way too entangled with Samsung.

Re: GrapheneOS – Break Free from Google and Apple

#317
post #210
post #142

Earlier quoted context omitted.

> It's mind boggingly stupid that they lock down apps like this, when you can just open the thing in a website anyway. I can use my bank on some linux distro... Not in Spain. I can access my bank's website but I can't do anything without their bank app. Even sometimes they require to confirm my identity using their app in order to access their website. I have several linux phones but I can only do banking with their…

> Not in Spain. I can access my bank's website but I can't do anything without their bank app. I don't know about Spain specifically, but as far as I understand it no bank in the European Economic Area + UK should allow banking via just the website alone anymore, because of the "Revised Payment Services Directive" (PSD2) regulation. Essentially, banks are required to implement "strong customer authentication", which…

> And in practise that means a banking app, because most people do not want a separate token they have to buy and can lose.

It can be SMS. As said in another comment, the main banks in Spain offer this authentication method while being PSD2 compliant. Some also offer a card with coordinates. So it's not mandatory in any way to use a banking app.

Re: GrapheneOS – Break Free from Google and Apple

#318
post #163

Earlier quoted context omitted.

Not in Spain. I can access my bank's website but I can't do anything without their bank app. Even sometimes they require to confirm my identity using their app in order to access their website. I've seen this elsewhere, and it's absolutely ridiculous. Why? Because in almost all cases, the apps may only be installed with Google Play, and require the framework to work correctly. And that means? If you are not in good s…

> They do it so they don't have to stand up their own push servers I don't agree with this dependency on being in good standing with Google either. But there is a technical reason that isn't wanting to avoid using their push servers. It is about battery usage and radio bandwidth. Keeping open an idle connection over WebSocket, long-poll HTTP or TCP/IP needs regular pings (typically 30 seconds are used), one ping per…

Why does a banking app that I'm not currently using need to ping a server occasionally?

When I want to do banking I'll open the app, do my business, then close the app. A banking application does not need push notifications.

Re: GrapheneOS – Break Free from Google and Apple

#319

Earlier quoted context omitted.

GrapheneOS requirement of Pixel devices is a dependency on Google too. They are currently working with an OEM to release a non-Pixel GrapheneOS phone in the future.

I hope and pray that is a Samsung S Ultra device. The built-in stylus transforms the whole user experience, I would not go back to a device that I must swipe my dirty fingers across.

I’m just imagining myself pulling out the stylus on the train/plane, dropping it, and watching it roll away forever.

Re: GrapheneOS – Break Free from Google and Apple

#320

This is especially interesting in regard to the recent HN dicussion on spyware by for-profit intel firms having access to Whatsapp, Telegram, Signal, etc. ( https://news.ycombinator.com/item?id=47033976 ) through OS-level no-click hijacks. I wonder how secure GrapheneOS is in that regard, and what the other contenders are?

GrapheneOS themselves dont pretend that their secure from that level of attack, but its about evaluating your own threat level. State sponsered actors aren't burning zero days on the vast majority of people, and you only need to look at how badly several european governments want to ban graphene and similar to see that such exploits aren't even being burned on organised crime. Realistically unless you're a journalist…

Thank you for the insight. Indeed, a concerning state of the world where criminals are less at risk from spyware than journalists and activists.
Post reply on HN