Live data from Hacker News

GrapheneOS – Break Free from Google and Apple

blog.tomaszdunia.pl

341–350 of 967 posts

Re: GrapheneOS – Break Free from Google and Apple

#341
post #306

"Break free from Google" and buy a Pixel phone from them to do so. But unironically Pixels are currently some of the best actually open phones. They do not lock down or require shady practices for unlocking the bootloader (although they do require a network check once that happens automatically, but it will permanently allow unlocking the bootloader if successful once. Pixels are very easy to restore and almost un-br…

Pixels are really great despite being from Google. I hope they will continue to make them unlockable/relockable. As you say they are also surprisingly hard to brick. Here is someone trying to break it intentionally during the GrapheneOS install:

https://www.youtube.com/watch?v=ik0AiO0WtuU

If you don't like giving money to Google, plenty of companies offer refurbished Pixel phones.

Re: GrapheneOS – Break Free from Google and Apple

#342
post #210

Earlier quoted context omitted.

> Not in Spain. I can access my bank's website but I can't do anything without their bank app. I don't know about Spain specifically, but as far as I understand it no bank in the European Economic Area + UK should allow banking via just the website alone anymore, because of the "Revised Payment Services Directive" (PSD2) regulation. Essentially, banks are required to implement "strong customer authentication", which…

TOTP not accepted? (When will people learn that biometrics are not another factor: they're entirely public and irrevocable. It's not just security theater, but Apple & Google know that this forces you into their ecosystem, which should be illegal. Of course, Brussels is full of rubes anyway.)

TOTP not accepted, because the confirmation for payment must include the amount to be paid, which cannot be done under TOTP as far as I know.

Re: GrapheneOS – Break Free from Google and Apple

#343

Earlier quoted context omitted.

> They do it so they don't have to stand up their own push servers I don't agree with this dependency on being in good standing with Google either. But there is a technical reason that isn't wanting to avoid using their push servers. It is about battery usage and radio bandwidth. Keeping open an idle connection over WebSocket, long-poll HTTP or TCP/IP needs regular pings (typically 30 seconds are used), one ping per…

Why does a banking app that I'm not currently using need to ping a server occasionally? When I want to do banking I'll open the app, do my business, then close the app. A banking application does not need push notifications.

Unfortunately it needs push notifications to authorize online payments.

Re: GrapheneOS – Break Free from Google and Apple

#344
post #299
post #192

Earlier quoted context omitted.

> Sorry, but then I take this as the usual Sure, you're free to do what you want. Just sharing my opinion given that I follow those projects from the outside. > You or other readers can check I guess what I am trying to say is that it takes multiple sides to argue. For what it's worth, your link shows the founder of /e/OS engaging there. I have seen both technically wrong and misleading claims from the founder of /e/…

I still haven't seen what you describe, the behaviour of other projects. And I dont believe it without proof (since it was claimed so often by GOS without proof being shown, or in some cases with it obviously not existing). For the security thing: It is wrong to claim that an unlocked bootloader completely breaks the android security model. If anything, it breaks one specific aspect, one that doesn't matter for many…

> It is wrong to claim that an unlocked bootloader completely breaks the android security model.

You seem knowledgeable about this, so I'll take the opportunity to ask: if I install a malicious app and it manages to escape the sandbox and alter the system, my understanding is that it will be detected next time I boot it (because the image hash won't match). Isn't that true?

> Signing keys for bootloaders might just not matter

Again a question, I haven't found it in the official documentation: aren't those keys the "system keys"? As in, if my system is signed with some keys and an app is signed with those same keys, doesn't it allow this app to get privileged permissions?

Re: GrapheneOS – Break Free from Google and Apple

#345

Been using this for about a year on a p9 pro. It works very well. I hear the google tap to pay does not work, but I've never tried it. However Vipps with their tap to pay works fine. BankID works but not with biometric login, which some things require IIRC. And for some reason DnB private works fine, but you are not allowed in on the corp app. It's mind boggingly stupid that they lock down apps like this, when you ca…

A collegue of mine was tech lead at a large online bank. For the mobile app, the first and foremost threat that security auditors would find was "The app runs on a rooted phone!!!". Security theater at its finest, checkboxes gotta be checked. The irony is that the devs were using rooted phones for QA and debugging.

ive seen: -"but ios can be jailbroken and it doesnt have an AV!" while the MDM does not allow jailbroken devices, and they also allowed sudo on linux.

auditors are clueless parasites as far as im concerned. the whole thing is always a charade where the compliance team, who barely knows any better tries to lie to yhe auditor, and the auditor pick random items they dont understand anyway. waste of time, money and humans.

Re: GrapheneOS – Break Free from Google and Apple

#346
post #270

Earlier quoted context omitted.

You can lock the bootloader again with GrapheneOS and many banking apps work.

You won't pass Google Play hardware attestation that way, and you won't find a bank in Europe or the UK that doesn't require that to log on to their website within five years.

My bank works fine after relocking (in NL, Europe). And last time I checked all Dutch banks work. My VISA credit card app (from ICS) also works. Same for the government identification app, the government message app, our insurance app. In fact, I haven't encountered anything outside of Google Pay that didn't work.

(I don't deny that there are apps that won't work. Best to check before switching full-time.)

Re: GrapheneOS – Break Free from Google and Apple

#348

I've been using GrapheneOS for about 3 years now. For the most part, it works very well. I don't have any issues with banking apps, nor any other closed source apps. I'm using two profiles both with sandboxed Google play installed. I'm logged in into my private Google account on the work profile. However, there was one case that lead me to thinking about ditching grapheneos to this day. I installed Uber on my phone a…

Last time I checked you could still book a ride using the website.

Re: GrapheneOS – Break Free from Google and Apple

#349

Earlier quoted context omitted.

Maybe not being able to use Uber isn't the downside you think it is though. UK centric view but call a cab and pay in cash, you haven't comprimised your security and you're not engaging with an unethical business.

Well, you still might engage with an unethical business, but at least the chance goes from 100% to somewhere between 0% and 100%. I've run into my share of scammy taxi drivers.

Right but at least then you are the one being scammed, and can decline to be scammed if you wish. As opposed to willingly partaking in a shitty system.

Re: GrapheneOS – Break Free from Google and Apple

#350
post #205

And once you are on GrapheneOS, break free from your proprietary watch ecosystem and switch to GadgetBridge ( https://gadgetbridge.org/ ) I run a Thinkpad with NixOS and KDE, a Pixel 9 with GrapheneOS, and an Amazfit watch paired with GadgetBridge on my phone. It's a testament to the hard work of the FOSS maintainers of these projects, and the spirit of open source, that everything works flawlessly together without a…

Garmin watches seem quite open even without that. I have all my data syncing to influxdb every 15min for a Grafana dashboard and it works great. In background I also have Withings scale sync the measurements a couple of times a day to Garmin.

How do you sync the data out of Garmin? Something like https://github.com/matin/garth, or syncing directly from the watch?
Post reply on HN