Live data from Hacker News

GrapheneOS has been ported to Android 17

discuss.grapheneos.org

401–410 of 653 posts

Re: GrapheneOS has been ported to Android 17

#401

Earlier quoted context omitted.

When using contactless payment with my card, about 10% of the time the payment terminal tells me to insert the card to the reader slot instead and enter my PIN. I assumed this is a general security feature, but I guess it depends on the issuing bank then. This in Europe.

Well, I still have a backup physical card. It just is annoying to get it out of my wallet.

[dead]

Re: GrapheneOS has been ported to Android 17

#402
post #397
post #369

I was using GrapheneOS for years, until the battery died while I was on an important call, trying to get someplace. Plugged it in, but little did I remember that I had installed OS update that was pending app optimization phase that happens during next boot. GrapheneOS has some hardening in this phase, which as I understand, essentially has to rebuild all apps without cache. And as I have a ton of apps, I was parked…

App optimization happens in the background now, and pops a notification when it is done, asking to restart all open apps.

Oh, then the biggest pain point I've had is now resolved. I should give it another go.

I've seen payments being another problem - but Garmin watch handles it for me. And paying with a watch becomes a conversation starter with merchants for some reason.

Re: GrapheneOS has been ported to Android 17

#403
post #359

Earlier quoted context omitted.

Any examples?

[flagged]

> GrapheneOS is security before anything else.

GrapheneOS is a privacy project highly focused on usability and compatibility. Privacy depends on security so it has to put a lot of work into security too and it has always been a major focus, but it's a misconception that it's all about security.

> This means they strongly advice against using other software many in their core audience are predisposed to like: Firefox, Signal, plugins for browsers, F-Droid, ect.

GrapheneOS doesn't recommend against Signal but rather it's the main recommendation for end-to-end encrypted chat from the project including via the Molly fork of Signal.

> The explanations are usually quite... blunt, and they're not exactly open for discussion (which makes sense, from a pure security perspective, those apps are indefensible).

This isn't true. GrapheneOS provides nuanced information with detailed explanations for these topics.

Re: GrapheneOS has been ported to Android 17

#404

Earlier quoted context omitted.

What's the app data backup/restore story on GrapheneOS? My understanding is that even with pseudo-D2D (device-to-device) transfers Seedvault doesn't backup everything[1]. Are there more-functional, non-root, local (non-cloud) alternatives? [1]: https://github.com/seedvault-app/seedvault/wiki/FAQ#why-do-s...

Seedvault is still woefully insufficient, but it sounds like there's work being done to replace it. I can't imagine the enterprise crowd will overlook that and I'm hoping the Motorola partnership enables faster development.

> Seedvault is still woefully insufficient

Ever since seedvault implemented local D2D API for app data availability and changed their repository format (inspired by restic's hashing) I've grown to trust seedvault enough that it's my sole phone backup.

Seems to schedule/backup/restore just fine, even cross-device. Gets all the apps and files I care about. Incremental runs are slow but efficient (I have some UX gripes and would prefer if key and snapshot management was more flexible but the sentiment I see seems to be rooted in the earlier days when seedvault was more naive.

Look forward to a GOS-native solution all the same.

Re: GrapheneOS has been ported to Android 17

#405
post #291

Earlier quoted context omitted.

The most hilarious is McDonald's app - it refuses to work without Play Integrity check. I wonder what braindamaged reasoning is behind this. Do they want to position themselves as a bank or something?

Huh, it works just fine in the UK. Wonder if they have different builds (or completely different apps) for different regions. Or maybe it's the GrapheneOS compatibility layer that makes it work? Not sure.

Play Integrity has several levels. GrapheneOS MEETS_BASIC_INTEGRITY, which I believe only requires a locked bootloader and no superuser.

There's also been some discussion of spoofing MEETS_DEVICE_INTEGRITY, since before Android 13 it didn't rely on a TPM, and many apps don't want to lock out older devices, but it's been decided against it [0].

[0] https://github.com/GrapheneOS/os-issue-tracker/issues/1986

Re: GrapheneOS has been ported to Android 17

#406

I took the plunge into GrapheneOS a week ago. I picked up a new Pixel10 Pro and never even tried the stock OS (except to unlock the boot loader). I've got almost everything working the way I want. There were a few non-essential banking apps that won't install. The most annoying problem I had is when I tried to install Strava, which I cannot get working. The app installs, but it will not let me sign in. I guess I need…

The most hilarious is McDonald's app - it refuses to work without Play Integrity check. I wonder what braindamaged reasoning is behind this. Do they want to position themselves as a bank or something?

I recall a year or so ago, there's been a story about someone hacking McDonalds loyalty program, with that app doing something stupid like storing your balance on the client or something. It seems instead of firing whatever offshore sweatshop that made that, they just doubled down on "mitigations".

Re: GrapheneOS has been ported to Android 17

#407
post #12

I've been running GrapheneOS for 7 months now and I'm not going back. When I bought my Pixel 10 last year, I wasn't actually planning on trying Graphene for a while....until I noticed Google had force bundled a 'Wicked For Good' movie promo theme with the latest security update.

Happy GrapheneOS user here too since 2+ years now.

Small point of critique: it would be nice if it was a little bit easier to switch between personas, for example by simply scrolling to a different workspace. Because now the feature is mostly unused on my phone.

Re: GrapheneOS has been ported to Android 17

#408

What are North American people doing for replacing contactless payment? Last time I checked, the solution was to use Curve but it only works for Europe.

There are a few other banks running their own NFC payment systems, like Swedbank in my country.

Re: GrapheneOS has been ported to Android 17

#409
post #402
post #397

Earlier quoted context omitted.

App optimization happens in the background now, and pops a notification when it is done, asking to restart all open apps.

Oh, then the biggest pain point I've had is now resolved. I should give it another go. I've seen payments being another problem - but Garmin watch handles it for me. And paying with a watch becomes a conversation starter with merchants for some reason.

I'm not sure how Garmin works, but for instance with Google Wallet-compatible watches, you need a phone where wallet can run. I've had this setup for a year where I loaded the cards from another phone and used a watch to pay.

However Wallet didn't like this setup. Tokens expired at varying delays, sometimes a day, sometimes a week or payment failed without reasons.

Nowadays, I just use my bank's app which work fine on GOS.

Re: GrapheneOS has been ported to Android 17

#410

Earlier quoted context omitted.

Does skimming still happen a lot? At least in Europe we have switched from magnetic strip to chip-based cards, which are protected against replay attacks.

We have chips but magnetic strips are still on most credit cards and payments are still accepted that way in many older payments gateways. From what I read on the topic the cost of lost business if this was disabled is greater than eating the cost of skimmer attacks. There is a several year plan to phase it out entirely. It's mostly because initially when chips came out a lot of business owners were angry that they h…

In the UK, many banks disable the magnetic strip by default, and you have to temporarily enable it from the bank's app/website if you want to use it.

You'd struggle to find a POS terminal that even has a reader for them in the UK. I've only ever had to enable them in the US or Japan.

Post reply on HN