Live data from Hacker News

Swappa.com for GrapheneOS compatible devices – Stay Away

discuss.grapheneos.org

81–90 of 90 posts

Re: Swappa.com for GrapheneOS compatible devices – Stay Away

#81
post #77
post #47

Earlier quoted context omitted.

Yup! You can even get Android Auto to work without Google Play: - https://github.com/sn-00-x/aa4mg

Once upon a time I would be happy to put custom ROMs on my phone and do all these patches. These days I just care so much about "things should just work" that I cannot justify doing this. I cannot think about how I could spend time figuring out what to do when the repo is no longer maintained or something breaks for random reasons.

The value I get from either being degoogled or using GOS like I have for the last year and a half is worth the 3-5 hours time investment once a year or two when I get a new phone.

Re: Swappa.com for GrapheneOS compatible devices – Stay Away

#82
post #47
post #25

Earlier quoted context omitted.

FWIW I've tested Android Auto before with sandboxed Google Play, works fine.

Yup! You can even get Android Auto to work without Google Play: - https://github.com/sn-00-x/aa4mg

This is a fantastic find, thank you very much! I ended up switching from Lineage + MicroG to GOS for the android Auto support because I couldn't find something like this. I will be setting this up on my secondary Lineage device.

Re: Swappa.com for GrapheneOS compatible devices – Stay Away

#83

I wonder why almost no one in these GrapheneOS praise topic mentions that you won't be able to pay with your phone, and often even bank apps refuse to install on it - it was a deal breaker for me personally, and now I'm back under Google umbrella :<

Fair point, but how much extra effort is it to put a credit card between your phone? I'm still under the Google umbrella as well, but this would be my first issue solved.

Honestly, it's a half hour of work to pull the chip out of a credit/debit card and put it into your phone case. (Just need to be careful and not cut the antennas)

Re: Swappa.com for GrapheneOS compatible devices – Stay Away

#84
post #65

I wonder why almost no one in these GrapheneOS praise topic mentions that you won't be able to pay with your phone, and often even bank apps refuse to install on it - it was a deal breaker for me personally, and now I'm back under Google umbrella :<

You've got a lot of people contesting the "often" part but I'll also add that there's a project tracking banking apps that do work: https://privsec.dev/posts/android/banking-applications-compa... My tiny local credit union app isn't on there, but it worked fine. I miss wallet a bit and it's a shame that there are important apps which still refuse to act reasonably, but I don't think it's really that bad.

Seconded. My credit union's app works just fine as well

Re: Swappa.com for GrapheneOS compatible devices – Stay Away

#85
post #8

Earlier quoted context omitted.

sometimes the option to unlock the bootloader doesn't work until you connect the device to internet. not sure if the original person who posted tried that. this might be a non issue.

OP here. I did try connecting to the internet on both devices I got my hands on, but the bootloader remained locked.

Luckily my pixel was fully unlocked- phew.

Re: Swappa.com for GrapheneOS compatible devices – Stay Away

#86
post #54

Earlier quoted context omitted.

Pretty sure Jeep was hacked via their infotainment system and remotely driven (by researcher Charlie Miller) So it’s actually kind of a real thing

I'm pretty sure that the infotainment hack was completely orthogonal to whether it was Beethoven, Iron Maiden, or blissful silence. Having said that, a successful car infotainment system attack on android auto or apple carplay could, of course, compromise your phone. So it's up to you whether you decide to cope with that possibility by breaking the law and navigating with a handheld device, or simply declining to do…

> separate the audio system from your car

I was responding to a comment about the security implications of letting the infotainment system interact with the vehicle controls, and I referenced an incident where someone compromised a car via that.

I have no idea how CarPlay would compromise your phone given apples sandbox but whomever finds it is gonna have a multimillion dollar payday since iOS jailbreaks are quite valuable.

Re: Swappa.com for GrapheneOS compatible devices – Stay Away

#87
post #54

Earlier quoted context omitted.

I'm pretty sure that the infotainment hack was completely orthogonal to whether it was Beethoven, Iron Maiden, or blissful silence. Having said that, a successful car infotainment system attack on android auto or apple carplay could, of course, compromise your phone. So it's up to you whether you decide to cope with that possibility by breaking the law and navigating with a handheld device, or simply declining to do…

> separate the audio system from your car I was responding to a comment about the security implications of letting the infotainment system interact with the vehicle controls, and I referenced an incident where someone compromised a car via that. I have no idea how CarPlay would compromise your phone given apples sandbox but whomever finds it is gonna have a multimillion dollar payday since iOS jailbreaks are quite va…

The initial convo went:

> Paying with your phone just seems like one of those separation of concerns problem.

Followed by:

> You could then separate the audio system from your car and drive around with a boombox

The first discusses behaviors of end-users. The second was a lame attempt to take the mickey of that, which is why my response clearly indicated that, to my knowledge there are zero security implications of playing your music through your car's entertainment system.

This remains true.

You are discussing design flaws, not user behavior flaws, which is why I pointed out that the design flaws you bring up, in addition to doing you bodily harm, could conceivably also be part of an exploit chain that validates the original poster's concern about using his phone for banking.

But I still sincerely doubt that the choice of playing Beethoven or Iron Maiden either directly places you at risk*, or makes a difference to the ease of exploiting any design flaws in your vehicle.

IOW, the first behavior given (not using your phone for banking) is easy to construe as prophylactic, given that, yes, in fact, peoples' credentials have been stolen from their phones and bad things have happened, due to using phones for financial transactions.

The second behavior given (use a boombox instead of your car's audio) of course could theoretically alter outcomes, but to my knowledge, there has never been a car exploit that depends on whether you have fiddled with the volume control or station selector.

* Assuming of course, that your volume isn't so loud that you've riled up other people. That's always a risk.

Re: Swappa.com for GrapheneOS compatible devices – Stay Away

#88
post #21
post #17

I just bought an official Pixel 9 to install GrapheneOS, and the process couldn't be simpler. Their webusb installer is extremely polished. You just plug your phone in, click through a few steps, and you're done. There's absolutely no reason to bother looking for a phone with GrapheneOS already preinstalled. As a side note, I've been using it for a few months now, and it works great. All the apps I use run on it just…

As a note, swappa isn't selling phones with grapheneos preinstalled. It is selling used phones, you would still have to install gos.

ah I see

Re: Swappa.com for GrapheneOS compatible devices – Stay Away

#89
post #29
post #19

Earlier quoted context omitted.

Difference is a plastic card that is lighter and smaller than the phone is just as effective as the phone is for payments. When it comes to audio, a car stereo is going to be much more convenient and brtter quality than a boombox or bluetooth. That said, i did know someone with an older car who used a bluetooth speaker instead of their stereo, so they could connect their phone audio.

I don't know about where you live but here contactless card payments have lower limits than phone-based ones. Also the phone allows me to switch between multiple cards, including transit-specific cards.

In the US IME there are not restrictions on card spending that are a barrier. In UK I had to sign for a purchase over £100. Extra 10 seconds.

In UK, my credit card was my transit card. I find it easier to navigate my physical wallet than a phone for such things. Personal opinion.

In any case, banking apps that don't function on graphene should be embarrassed by their stupidity. Amex forces sms/email 2fa to login on my graphene phone, when chase, fidelity and several other bank apps do not.

Re: Swappa.com for GrapheneOS compatible devices – Stay Away

#90
post #66
post #52

Earlier quoted context omitted.

I wonder if the person you talked to actually knew what they were talking about. Swappa explains what an unlocked device means in their FAQ and a bootloader is not mentioned. https://swappa.com/faq/answer/unlocked-device

That's sad, because one of Swappa's main selling points (and the reason they got popular) is that they started out as a marketplace for Android phones, and should specifically know about rooted / bootloader unlocked / etc. phones. Enthusiast stuff. Their About page says: > The inspiration for Swappa sparked when Ben had trouble finding a good source for test devices for Android development projects.

I guarantee you that most people buying used phones are more concerned if the phone will work with their existing phone plan than if they can use it as a development testbench.
Post reply on HN