Live data from Hacker News

GrapheneOS – Break Free from Google and Apple

blog.tomaszdunia.pl

421–430 of 967 posts

Re: GrapheneOS – Break Free from Google and Apple

#421
post #210

Earlier quoted context omitted.

> Not in Spain. I can access my bank's website but I can't do anything without their bank app. I don't know about Spain specifically, but as far as I understand it no bank in the European Economic Area + UK should allow banking via just the website alone anymore, because of the "Revised Payment Services Directive" (PSD2) regulation. Essentially, banks are required to implement "strong customer authentication", which…

> And in practise that means a banking app, because most people do not want a separate token they have to buy and can lose. It can be SMS. As said in another comment, the main banks in Spain offer this authentication method while being PSD2 compliant. Some also offer a card with coordinates. So it's not mandatory in any way to use a banking app.

My bank offered that option but not anymore. The use of their app is mandatory now.

Edit to add this anecdote. My bank told me I need to use their app because SMS is not secure, but you need to activate their app using an SMS code!

Re: GrapheneOS – Break Free from Google and Apple

#422
I use and appreciate GrapheneOS due to it being one of, if not the best, option we currently have.

That said, I do not like how much the project depends on Google.

- GrapheneOS is based on Android, which is solely developed by Google.

- GrapheneOS only supports Google Pixel devices. Thankfully, they are working on partnering with a different manufacturer, but details are still very limited.

- They recommend using the Google Play Store (requires a Google account) to get apps and recommend against using F-Droid.

- Their Vanadium web browser is based on Chromium, which is controlled by Google. It also does not have an ad blocker or support extensions. They recommend against using Firefox. Firefox, and Safari to a more limited extent, are the only web browsers keeping Google from having complete control over web standards and the way we can access the internet.

This is not a criticism of the GrapheneOS project or developers. I understand that security is the biggest priority of GrapheneOS and I understand that Google is often good at security. They are following the goals of the project. It is more directed towards the GrapheneOS community that often blindly recommends GrapheneOS as the only option and treats any alternative as inferior and not to be considered. Most users do not need security at all costs. Especially among the free and open source enthusiast community, freedom and user control are often prioritized. There should be more awareness and discussion about what the user wants and whether that actually aligns with the security-first goals of GrapheneOS.

Re: GrapheneOS – Break Free from Google and Apple

#423
post #379

Earlier quoted context omitted.

In the US, many refurbished Pixel phones are Verizon variants which disallow OEM unlocking. When was in college and had Sprint this was a nightmare since then I wanted root for unlimited hotspot (Sprint made it easy that way), but most refurbished Pixels were Verizon variants. And I couldn't just use OnePlus because they were only designed GSM networks or later Verizon CDMA-less. Then, new Pixels were unaffordable fo…

Is it not possible to buy a phone in the US without any cellular providers involved? I thought that kind of lock-in was a thing of the past.

It is possible, but many people still buy them from their provider with financing or subsidies. That means people shopping for used Pixels who want to unlock the bootloader need to avoid the special Verizon variant which forbids unlocking the bootloader.

This is separate from SIM locking, which forbids use with another carrier. US carriers still do that, but are required to remove the lock after a while if the customer doesn't owe them money.

It's not clear why Verizon insists on permanently locked bootloaders or why Google agrees to it for Verizon when they don't do it on Pixels sold anywhere else.

Re: GrapheneOS – Break Free from Google and Apple

#424
post #379

Earlier quoted context omitted.

Pixels are really great despite being from Google. I hope they will continue to make them unlockable/relockable. As you say they are also surprisingly hard to brick. Here is someone trying to break it intentionally during the GrapheneOS install: https://www.youtube.com/watch?v=ik0AiO0WtuU If you don't like giving money to Google, plenty of companies offer refurbished Pixel phones.

In the US, many refurbished Pixel phones are Verizon variants which disallow OEM unlocking. When was in college and had Sprint this was a nightmare since then I wanted root for unlimited hotspot (Sprint made it easy that way), but most refurbished Pixels were Verizon variants. And I couldn't just use OnePlus because they were only designed GSM networks or later Verizon CDMA-less. Then, new Pixels were unaffordable fo…

Oh man, sorry to hear that! On the other side of the pond, carrier-specific/locked phones haven't been a thing for ages. Haven't seen a carrier-specific phone since 2013 or 2014.

Re: GrapheneOS – Break Free from Google and Apple

#425
post #375
post #120

Earlier quoted context omitted.

It is not. GrapheneOS is AOSP-based. But yeah, same binary blob issues for firmwares, but Linux on Mobile has the same issues.

It's not very important but what are you referring to with "it is not" ? AOSP is Android (it's in the name) so I don't get it. Are you talking about blobs re Pixel devices?

No, I really meant that AOSP is not Android. Android builds on top of AOSP. I elaborated here: https://news.ycombinator.com/item?id=47047167

Re: GrapheneOS – Break Free from Google and Apple

#426

Does anyone have a good grasp of the differences between GOS and /e/OS? I'm buying a Fairphone soon and was wondering what both are like

The main difference is that GrapheneOS prioritizes security hardening first and foremost (above usability or compatibility). /e/OS focuses on privacy (i.e. reducing data leakage to adtech) and usability over security. To put it concretely, GrapheneOS recommends running all the proprietary Google apps in a locked "sandbox" so they can't read data on the phone outside the sandbox -- but obviously Google still gets to s…

> security hardening first and foremost (above usability or compatibility).

Right. Something that GrapheneOS boosters often fail to mention. It's not like those guys at Google are just idiots and don't know how to make a hardened allocator. Android uses a different hardened allocator that is much, much faster and uses less space. GrapheneOS is slower and uses more memory.

Re: GrapheneOS – Break Free from Google and Apple

#427
post #51

While I admire GrapheneOS and its goals, I feel that until we free the proprietary baseband processors and their RTOS from the grips of Qualcomm and friends it's a pyrrhic victory, at best .

To make things worse it needs a google phone, of all things.

Re: GrapheneOS – Break Free from Google and Apple

#428
post #329

Earlier quoted context omitted.

TOTP not accepted? (When will people learn that biometrics are not another factor: they're entirely public and irrevocable. It's not just security theater, but Apple & Google know that this forces you into their ecosystem, which should be illegal. Of course, Brussels is full of rubes anyway.)

The question is what generated that TOTP code. The banks must ensure that they "are independent, in that the breach of one does not compromise the reliability of the others," as article 4(30) states. That text is vague as hell, but published opinion of the European Banking Authority on the matter[0] is: "a device could be used as evidence of possession, provided that there is a ‘reliable means to confirm possession t…

Like most security regimes, it's both overly prescriptive and woefully insufficient. In short, dumb. :(

Re: GrapheneOS – Break Free from Google and Apple

#429
post #38

Does anyone have a good grasp of the differences between GOS and /e/OS? I'm buying a Fairphone soon and was wondering what both are like

GrapheneOS claims to be a lot more secure, having additional hardening. See https://eylenburg.github.io/android_comparison.htm - keep in mind that it is not an independent comparison, the Graphene guys directly feed what this table is supposed to say in the issue tracker, https://github.com/eylenburg/eylenburg.github.io/issues/ . But it gives a good representation of the state of the ROMs according to Graphene. In re…

/claims/
Post reply on HN