Live data from Hacker News

GrapheneOS has been ported to Android 17

discuss.grapheneos.org

301–310 of 653 posts

Re: GrapheneOS has been ported to Android 17

#301

Earlier quoted context omitted.

> Commercially, this makes sense. Does it though? The people in this thread are like "just use a card". Well I've done that for years and had my card skimmed, lost, and stolen over the years. The cost wasn't trivial either. The credit card company knocked it off my balance but also lost on sales when I didn't have my card while they issued me a new one. It cost the credit card company actual money in both lost sales…

whether a device is rooted kinda does matter from this pov as it undoes a lot of the security assumptions on android... however grapheneos isn't rooted anyway

We're talking about just in time tokens that disappear after use. There's nothing you can do to defeat that on a rooted device. That's the whole point of the entire tech. That's why yubikeys are even a thing.

Re: GrapheneOS has been ported to Android 17

#302

Earlier quoted context omitted.

Any issues with banking insurance or healthcare applications?

Why would you use app for actual insuranceb or even healthcare?

This is not really about me, but understanding if these apps have issues running under the OS. These type of apps typically have extra "security" features.

Re: GrapheneOS has been ported to Android 17

#303
post #244

Earlier quoted context omitted.

It's infuriating that they won't do this for non Google Android. It's in the best interest of both the bank and the card owner. Credential theft risk goes down to basically zero when backed by a fingerprint authenticated virtual card.

What do you mean by credential theft? Stealing the numbers on the card or a malicious person triggering the contactless payment?

Stealing the numbers. Could've been someone taking a photo of the card out of sight. I honestly don't track my card that well when I'm out cause it's easy to have a transaction voided if it's legit not me. Then again cameras are everywhere now.

Re: GrapheneOS has been ported to Android 17

#304
post #240

Earlier quoted context omitted.

Not only obtaining but if you ever need warranty you're done. Just last week I went to a Samsung center and had my fold 6 fixed in 30 minutes, and these centers are everywhere around the world. Same thing with Apple, yet a 4.5 trillion dollar company can't ship and maintain a phone globally. It's so unserious.

Out of curiosity, what was wrong with your Fold 6?

The inner screen built-in protector was peeling in the middle. It was out of warranty, but Samsung charged me 15$ which is very reasonable. The inner screen looks brand-new now, and I guess that's the benefit of these soft foldable screens - you can refresh the entire thing very easily.

Re: GrapheneOS has been ported to Android 17

#305
post #121

Earlier quoted context omitted.

> I'm not looking to fully de-Google but I want Google as apps and not my OS. This is entirely possible as other posters have explained. But I think it kind of defeats the point of Graphene, at least somewhat. Google is already profiling every aspect of your life by reading your emails, files, calendar, location, etc? In that case, OS access becomes moot. I think that GrapheneOS makes most sense as part of a broader…

I agree and have moved mostly away from everything Google. But it's hard to replace maps. I know open street maps exists but it's hard to beat Google's data gathering.

Different scopes and purposes. Google Maps is made to find commercial activities and addresses, OSM is there to map the territory around.

Re: GrapheneOS has been ported to Android 17

#308

Earlier quoted context omitted.

No, if you install the Google camera there is no difference in quality and by revoking network you don't lose privacy.

> by revoking network you don't lose privacy Be careful, apps can still communicate with other apps, e.g. revoking the network permission doesn't stop apps from fetching and displaying ads over the network. I don't know enough about Android internals to understand the mechanisms behind it, but clearly there are ways for apps to exfiltrate data. > Trying to use Network as a complete data exfiltration toggle isn't the…

Eye opener. Thanks for the warning! GrapheneOS sandboxes all apps including GSF as far as I understand. It would be nice if full capabilities could be exposed or at least shown in the app settings. There is the "All permissions" view which has a "have full network access" item with the following details: `Allows the app to create network sockets and use custom network protocols. The browser and other applications provide means to send data to the internet, so this permission is not required to send data to the internet.` Does this mean the app has this permission and even without it can fully access the internet? If so the primary "network" permission is very misleading. I wish for a smartphone-like device which installs apps with `cap_drop: ALL` by default. I wish for a government which would support such a standpoint and "assist" companies not able to provide a service which require intrusive data gathering. Either that or we're all just one big happy family with no secrets and no jealousy and no drama. sigh

Re: GrapheneOS has been ported to Android 17

#310
post #236

Earlier quoted context omitted.

Yes, you install the Google Play store via the GrapheneOS App Store. The OS comes with like 5 apps out of the box. The rest is up to you. Biggest caveats that I've encountered: tap to pay via Google Wallet is a no go, Android Auto can be flaky, MDM managed work profiles don't work at the moment, and some apps that use the Google Play integrity API fail to validate and refuse to work (I've only encountered one app tha…

> MDM managed work profiles Do you mean actual employer-spyware MDM work profiles? I suppose I never expected those to work. Or do you mean things like Shelter, which uses work profiles and which I use to quarantine certain less-trusted apps?

Yes, I mean MDM work profiles. I play an IT guy at work and am a Google Workspace admin. We have it running in BYOD mode and it's actually not intrusive at all. The most sensitive data you can see as an admin is what apps are installed in the work profile, the phone's make + model, and the version of Android. Nothing like location, charge level, or anything outside of the work profile. I'm fine with running it on my personal device (I actually really like the way it functions), but it's borked on current versions of GOS.
Post reply on HN