Live data from Hacker News

GrapheneOS user reported to authorities for using GrapheneOS

discuss.grapheneos.org

181–190 of 535 posts

Re: GrapheneOS user reported to authorities for using GrapheneOS

#181
post #20

Someone in the comments of that post linked to a long FAQ section for GrapheneOS about how apps can identify it and so forth [1]. I don't understand why it doesn't just attempt to spoof that's it's stock Android/Google everywhere it possibly can? [1] https://grapheneos.org/faq#:~:text=Apps%20can%20detect%20tha...

Superficial spoofing is pointless - any app that cares would just use the Play Integrity API (which can't be spoofed by GrapheneOS). 0: https://developer.android.com/google/play/integrity/overview

And lets not forget how pointless Play Integrity is for what it is being touted to be for, when there is millions of "Certified" devices ready for us by shady people via clickfarms.

Re: GrapheneOS user reported to authorities for using GrapheneOS

#182

Earlier quoted context omitted.

Yep, police can simply ask anyone for their passwords and if you don't give it up they can put you in jail. I won't be visiting. Despite many flaws, the US has some damn good rights for its citizens compared to the rest of the world.

Is this satire?

No, just the UK.

I actually think it might be worse.

You need to be able to hand over encryption keys too.

Claiming to not know them is also not allowed, whether you actually know them or not.

I am reasonably convinced that if you wipe the key slots on an encrypted drive but leave encrypted blocks around, they might be able to argue that you are obligates to store all the block keys for such an occasion. So using any kind of multi-tier encryption in the UK might be a massive liability unless you permanently store all the material required to derive any key that is used to encrypt anything.

This also probably has impact on TLS now that I think about it.

Now, real world criminal cases are likely to proceed differently than how they proceed in the mind of a programmer interpreting the law as a program. But, I am not too convinced such a farcical thing wouldn't happen, the UK government and police have engaged in much dumber things.

Now that I think about it, storing randomness on a disk could probably be used to incriminate you in case that disk was seized. Since the police wouldn't be able to tell if it wasn't encrypted data.

Re: GrapheneOS user reported to authorities for using GrapheneOS

#183

Might as well report all users of internet to authorities for using internet because internet can also be used to commit fraud.

Actually, that makes me think, what will happen, if suddenly there is a flood of reports, too many for them to deal with? Let's say all GrapheneOS users installed that app to get reported and then some more bots/fakes are set up to do that too.

For start you can strong arm or mandate bank to not make their app run on GrapheneOS device.

Bank is highly regulated service and vital so there's strong incentive and ramp up here

Re: GrapheneOS user reported to authorities for using GrapheneOS

#184

Earlier quoted context omitted.

Fun fact: Americans pay more tax money towards healthcare than countries with universal tax-funded healthcare. How much healthcare does that spending get them? Zero. After overpaying tax for healthcare they also have to buy healthcare separately.

Yea cause we throw more money at it. Our facilities are far superior. In California where I live though folks with little money get very subsidized healthcare that is cheaper than NHS taxes.

Outcomes are worse in the US, perhaps you should reevaluate your assumptions.

Re: GrapheneOS user reported to authorities for using GrapheneOS

#185
post #126

This is totally unacceptable. But going to the hassle of running GrapheneOS and then using it to try and submit facial scans to combine your identity with your PSN account just seems so pointless.

> But going to the hassle of running GrapheneOS and then using it to try and submit facial scans to combine your identity with your PSN account just seems so pointless. reply Totally disagree. Everyone has a different threat model. Some people may solely be interested in the exploit protections and not care about their privacy. Some people might just like that it's completely open source or that there's no AI or it's…

The thing is though that this kind of verification is going to be rife if we keep accepting it, and inconveniences like it not working (plus some banking apps) is almost the entire downside of GrapheneOS.

If you don't use it for things like this you don't really see any disadvantage. Occasionally I get cloudflare or vercel blocked when trying to read a blog but that's all.

So they're at a very strange intersection of using graphene but wanting to do exactly the kind of that is difficult on graphene. And just to be able to chat on PSN.

You're right though, different threat model.

Re: GrapheneOS user reported to authorities for using GrapheneOS

#186
post #115

Earlier quoted context omitted.

Geographically, that's quite the zinger. Legally, no. Different laws.

Europe has many many different jurisdictions. Even if you take the European Union alone and ignore all the other European countries, the EU only legislates over a subset of things for member countries.

Much less the UK.

Re: GrapheneOS user reported to authorities for using GrapheneOS

#187

Earlier quoted context omitted.

This actually is how authorities work. If you do anything unusual at all, you are flagged as suspicious. You will find yourself being denied services without explanation. There is no appeal process.

Not where I live. If it's happening where you live then it's a sign you need to start protesting/organizing/get involved in politics/using whatever skills you have to improve matters before they get worse. This happened in the UK, specifically, and from what we've all seen it's definitely sliding in a bad direction over the past decade. But it's also not in any way so far gone that you can't take action. If you're si…

Have you seen how bank work with Anti Money Laundering?

Re: GrapheneOS user reported to authorities for using GrapheneOS

#188

Earlier quoted context omitted.

Yep, police can simply ask anyone for their passwords and if you don't give it up they can put you in jail. I won't be visiting. Despite many flaws, the US has some damn good rights for its citizens compared to the rest of the world.

> Yep, police can simply ask anyone for their passwords and if you don't give it up they can put you in jail. This is precisely the reason why I don't want to visit the US at the moment. The USA immigration officers can ask me to forfeit my phone's password and look at all my photos, documents, messages, call logs etc, WITHOUT SUSPICION. Some of that data can even stay on their servers for decades, and who knows if i…

I haven't written up an article about it yet, but from a cursory look of the legal stuff this only affects private citizens and could be circumvented by setting up a shell company that owns your devices.

Legally, you can't surrender these devices, access to them or their passwords, as they are company property.

Re: GrapheneOS user reported to authorities for using GrapheneOS

#189
post #112

Earlier quoted context omitted.

What good is a piece of paper? I have nice toilet paper. It doesn't make me safer when visiting the US.

The entire point of a constitution is that, unlike toilet paper, it can be enforced by the courts.

And which one are the courts enforcing at the moment in the US? Pretti? Good?

Re: GrapheneOS user reported to authorities for using GrapheneOS

#190
post #101

It's so surprising that despute so many screams "China" in western media in the last 15 years, it happens in the west, but in China it's free to use any OS without any negative consequences. Why? What's going on?

Not true the part about China, but yes Western countries do like to pretend they have a lot more freedom than they do. If you can't criticize or protest Xi in China, try criticize or protesting the laws in rest of the world. Especially the things they do in the name of privacy, I remember UK jailing folks for FB posts, that's stuff that happens in third world countries. Not that UK ever had much of a leg to stand on,…

> I remember UK jailing folks for FB posts, that's stuff that happens in third world countries.

The only cases this has happened has been over people actively calling for racial violence over an imagined scare - bunch of morons thought a muslim migrant killed someone, so they went on to riot, burn mosques, assault foreign looking people, etc; on day 2 it was revealed the perpetrator was a Britain born Christian son of foreign origins, but the morons didn't care, they had their excuse.

I struggle to think of many countries where calling for immediate violence, on Facebook or in public with placards, is acceptable. Or any reason why it should be.

Post reply on HN