Live data from Hacker News

GrapheneOS – Break Free from Google and Apple

blog.tomaszdunia.pl

351–360 of 967 posts

Re: GrapheneOS – Break Free from Google and Apple

#351
post #210

Earlier quoted context omitted.

> Not in Spain. I can access my bank's website but I can't do anything without their bank app. I don't know about Spain specifically, but as far as I understand it no bank in the European Economic Area + UK should allow banking via just the website alone anymore, because of the "Revised Payment Services Directive" (PSD2) regulation. Essentially, banks are required to implement "strong customer authentication", which…

> And in practise that means a banking app, because most people do not want a separate token they have to buy and can lose. It can be SMS. As said in another comment, the main banks in Spain offer this authentication method while being PSD2 compliant. Some also offer a card with coordinates. So it's not mandatory in any way to use a banking app.

Probably not for much longer though. Several countries, including mine, have already banned SMS 2FA for banking, and it's likely that that will be implemented for all of Europe in the near future, possibly with PSD3. Not that SMS 2FA was ever a good idea in the first place.

But yes banking apps are not mandatory, and likely won't be in the near future either, though the alternatives are treated a bit like second class citizens.

Re: GrapheneOS – Break Free from Google and Apple

#352

This is especially interesting in regard to the recent HN dicussion on spyware by for-profit intel firms having access to Whatsapp, Telegram, Signal, etc. ( https://news.ycombinator.com/item?id=47033976 ) through OS-level no-click hijacks. I wonder how secure GrapheneOS is in that regard, and what the other contenders are?

It's just an Android fork. Almost certainly it's equally affected.

That's too simple. First of all, Pixel (which GrapheneOS requires) is one of the few Android phones with a separate secure enclave. GrapheneOS also applies a lot of hardening that other vendors do not: https://grapheneos.org/features#exploit-protection

This does make a material difference, e.g.: https://x.com/MetroplexGOS/status/1982163802188575178

That said, if a state-level actor is up against you, then it's hard to defend yourself against that.

Re: GrapheneOS – Break Free from Google and Apple

#353
Is there a great phone with high end specs this runs on?

Currently have an iPhone 16 pro, and probably my next phone will be something like this.

I need to be able to share photos easily with my wife, typically I’ve been using airdrop.

Re: GrapheneOS – Break Free from Google and Apple

#354
post #321

Earlier quoted context omitted.

This is only my opinion, but GrapheneOS's approach to privacy seems obtuse to me. They will claim that an unlocked bootloader is a risk, but then turn around and recommend you install proprietary apps GApps in their sandbox. The sandbox doesn't matter if all the private data is in the same sandbox! Reminds me of https://xkcd.com/1200/

Feels like you don't know what "the sandbox" is. It's not "their" sandbox, it's from AOSP. When you run an app on Android, it runs in a sandbox. Meaning that your social media app cannot access the files of your banking app by default . They are "sandboxed". On a normal Android, the Play Services are installed as a system app. It is privileged app that has "system" access. A system app is not sandboxed. GrapheneOS al…

If the Tiktok app passes your data to Play Services (say, to support notifications with GCM) then it doesn't make any difference that Play Services is nominally "sandboxed".

I agree there's some marginal benefit that sandboxed GApps need to prompt the user for permissions (rather than having privileged system level access) but at the end of the day, Google Maps will get GPS perms and Google will know everywhere your phone goes.

Re: GrapheneOS – Break Free from Google and Apple

#355

Been using this for about a year on a p9 pro. It works very well. I hear the google tap to pay does not work, but I've never tried it. However Vipps with their tap to pay works fine. BankID works but not with biometric login, which some things require IIRC. And for some reason DnB private works fine, but you are not allowed in on the corp app. It's mind boggingly stupid that they lock down apps like this, when you ca…

A collegue of mine was tech lead at a large online bank. For the mobile app, the first and foremost threat that security auditors would find was "The app runs on a rooted phone!!!". Security theater at its finest, checkboxes gotta be checked. The irony is that the devs were using rooted phones for QA and debugging.

Oh how I fucking wish "security" wasn't a stupid cargo cult checkbox list 3/4 of the times.

Unfortunately, the rot runs too deep.

Re: GrapheneOS – Break Free from Google and Apple

#356
post #226

Earlier quoted context omitted.

It's regularly unreliable here, because it's reliant on a bank app which in turn is reliant on an internet connection, and banks here are kind of shit. It's pretty common here that people will be told they need to turn off an otherwise working Wifi connection when facing problems because bank apps will often just not work properly on wifi. But as I said, even without that, the convenience level is ridiculously differ…

> It's regularly unreliable here, because it's reliant on a bank app which in turn is reliant on an internet connection Got it, that's a fair point! > But as I said, even without that, the convenience level is ridiculously different. It's arguably quicker to open your wallet and use a debit card with an NFC chip than it is to use QR codes This part sounds like those people who use a different unit system than I do an…

Did you miss the part where I said I use both?

I'm not saying "yours" is less convenient. I'm saying the one you and I both use regularly is less convenient than anything NFC based, which I also use semi-regularly.

Re: GrapheneOS – Break Free from Google and Apple

#359

Earlier quoted context omitted.

GrapheneOS themselves dont pretend that their secure from that level of attack, but its about evaluating your own threat level. State sponsered actors aren't burning zero days on the vast majority of people, and you only need to look at how badly several european governments want to ban graphene and similar to see that such exploits aren't even being burned on organised crime. Realistically unless you're a journalist…

Thank you for the insight. Indeed, a concerning state of the world where criminals are less at risk from spyware than journalists and activists.

Its definitely a scary world, safe to assume all your online activity could be hacked if so wanted. Just gotta hope its not wanted and that it doesnt become possible to do it on a mass scale (UK is currently pushing to ban E2E lol, and I know the EU has contemplated similar. If you do fall into the wanted category, face 2 face is really the only option. I know a lot of politcal/investigative journalists also constantly cycle and maintain burner devices but even thats a risk of just how long is a safe time before a device is considered burned.

Re: GrapheneOS – Break Free from Google and Apple

#360

Been using this for about a year on a p9 pro. It works very well. I hear the google tap to pay does not work, but I've never tried it. However Vipps with their tap to pay works fine. BankID works but not with biometric login, which some things require IIRC. And for some reason DnB private works fine, but you are not allowed in on the corp app. It's mind boggingly stupid that they lock down apps like this, when you ca…

A collegue of mine was tech lead at a large online bank. For the mobile app, the first and foremost threat that security auditors would find was "The app runs on a rooted phone!!!". Security theater at its finest, checkboxes gotta be checked. The irony is that the devs were using rooted phones for QA and debugging.

Yeah that's the first thing a pentest will complain about, had the same problem too. I pushed back enough so that it's trivial to bypass but the bank and pentesters also agreed with me that it's security theater or else I would never had the chance.
Post reply on HN