Live data from Hacker News

Volkswagen started blocking GrapheneOS users

discuss.grapheneos.org

331–340 of 497 posts

Re: Volkswagen started blocking GrapheneOS users

#331

Earlier quoted context omitted.

If they have concerns about the security of their app on some platform, they have the choice to either put "security" into the app, or to trust the platform vendor to provide the security. The correct solution is the first way. Deferring trust to the platform provider is the lazy way. If their APIs are done correctly, they shouldn't be afraid to expose them.

How else would you build "security" into the app (in the sense of not allowing third-party modifications of it that would open them up to liability), except relying on hardware attestation that the app has not been modified? That attestation necessarily requires the platform provider to be involved.

Volkswagon has no jurisdiction over how I manage my fob, which is the client for the vehicle's unlock and start API. Once you hand a bearer token to me that governs full access to the vehicle, including the accelerator and steering wheel, it's not your job to babysit whether I chose to use it while drunk or hand it over to someone else.

Re: Volkswagen started blocking GrapheneOS users

#332
post #304

Earlier quoted context omitted.

Note that I am a GrapheneOS supporter. You seem to have a few misconceptions. GrapheneOS is one of, if not the most vocal organization against the abuse of attestation mechanisms. GrapheneOS and its userbase feel the consequences of play integrity every single day. Im not sure where you got the idea that all GrapheneOS wants is to be accepted by play integrity, because that is not the case. GrapheneOS has been workin…

My opinion: Any kind of attestation that is delivered to a non-user-controlled server about the state of a user's end device that the user (possibly using means outside of the end device) cannot change will be abused, e.g for anti-competitve purposes. I am hearing lots of arguments that grapheneOS is more secure (it is) and should therefore be included in remote attestation. The pinning you are proposing, does it imp…

To start, all attestation is remote. It fundamentally has to be remote, be it a server or another device.

GrapheneOS points out how its improved privacy and security should mean that it is accepted in a system like play integrity. But this is just to outline how flawed the logic of play integrity is. It is by no means an endorsement of play integrity. GrapheneOS wants people to know that google is lying and breaking the law, and uses its own exclusion as that evidence. Even if GrapheneOS were accepted into play integrity, it would still exclude any and all forks and self-signed builds of GOS, which is unacceptable. If companies absolutely insist on using this approach despite its flaws, they should use the generic attestation available in android, and permit using 3rd party roots of trust in some form, rather than outsourcing this verification to 3rd parties like google.

As for the pinned attestation approach, that is Trust On First Use, and is used to verify the integrity of a device based on the security of the devices early bootchain. The initial attestation is what future attestation is pinned to. This allows you to verify a device is the same one, it has not been downgraded, has not been tampered with, etc. This is awesome, and lets you do things like what GrapheneOS does with Auditor. But this is not used to restrict what operating systems are used. Root based attestation somewhat tries to resolve the Trust On First Use approach, but is used to arbitrarily ban operating systems in practice. It is super flimsy as any leaked keys can bypass it.

My only concern is your claim that GrapheneOS is for this technology when it is most certainly against it. The nuance is that pinned attestation is a different approach with different properties, and advocating for it does not mean GrapheneOS is not an ally against play integrity.

Auditor also functions as a proof of concept for the potential of attestation, check here for more info: https://attestation.app/about

Re: Volkswagen started blocking GrapheneOS users

#333

Earlier quoted context omitted.

Car apps, beside Tesla, are universally awful to use. Even Tesla's is not beyond reproach (app size is massive, for one), but at least it doesn't make me want to poke my eyes out. Apple should make a "Cars" app that's like the "Watch" app and let them standardize.

Why does a car even need an app? Don't they have a screen and internet connection on the car itself?

Why does a car even need an Internet connection? I'd prefer a car without. I recently bought a 2024 model Chinese EV, and it doesn't seem to have an internet connection of its own. Neither does it seem to have an app.

Reasons I could think of for an app: Remotely check battery charge, and that would purely be for interest rather than necessity.

I get why people might like or want remote heating/cooling as well, and I'd probably use it if I had it, but it would be an exceedingly rare occurrence (although I'm more sensitive than most as to becoming a 'soft' human being).

Re: Volkswagen started blocking GrapheneOS users

#334

Earlier quoted context omitted.

German companies, especially old school industrial ones like VW, have a very hard time understanding open platforms. The view everything through the lense of liability and compliance first. Their thinking is that if someone runs their app on a custom ROM and uses that to manipulate the app in any way, and that causes some extremely hypothetical damage, that they might be held liable for not having prevented this situ…

Germans will talk a lot about data privacy but then do stuff like this regularly.

One is people one is companies.

Re: Volkswagen started blocking GrapheneOS users

#335

I want a law that requires publishing your API for apps like this as well as allowing users to crate their own frontend based on it. That would enable more privacy aware versions of these apps.

If you pay for the privilege of using the app, that makes sense. I can't imagine such a law would ever be made for free apps as controlling the client experience is key for enabling them to offer it for free. The reason free apps often don't have a paid tier is because the folks who would pay for it are often the key demographic they need to not pay for the entire thing to be profitable for subsidizing the less desirable demographics.

I'm not trying to suggest that these sorts of things should be this way, but if there is a server involved in the economics of maintaining that endpoint come into play and can't be ignored. Ideally things were federated and you could point your car or whatever device at and endpoint you maintain, but that comes at a cost as well as maintaining software where both client and server are controlled by the same party is an order of magnitude easier than cases where they aren't the same.

Re: Volkswagen started blocking GrapheneOS users

#336

Earlier quoted context omitted.

Recently I rented Cupra for a week, its assistants were non intrusive, and helpful. It was a pleasant surprise. Now don't get me started on Toyota or Hyundai assitants... BTW the video you linked features a Toyota.

Our Mercedes: - beeps about the speed limit, especially if it misses a sign. For example every time starting on a parking lot it keeps the 5 kph even after multiple turns - warns about leaving the lane, including trying to stay on the lane by slightly couter steering while ignoring yellow construction lines - Sometimes when moving off from a standstill in a queue, it triggers all "careful you're about to crash into s…

My 2024-model Chinese EV allows for volume to be turned down for various things - and these volume settings are kept across 'reboots'. It makes the occasional 'bing' or 'bong' that I need to look at the screen to work out why (which is probably a 'new' safety issue caused by 'safety' settings), but it's nowhere near loud enough to awaken a sleeping passenger.

My sister-in-law has to reconfigure all of the cars safety settings every time she turns the car on as they reset to their seemingly maximal defaults upon boot.

Re: Volkswagen started blocking GrapheneOS users

#337
post #60
post #37

Earlier quoted context omitted.

There must be 10s of millions of x86 PCs with unlocked bioses in the UK. The issue won't be running an open device. The problem is software - what does someone running Linux do if the government mandates online services require proprietary attestation APIs? It's scary how quickly the banning is moving. The problem is what happens next. When they realise that banning things doesn't really work. The next logical step i…

Am currently trying to open a business bank account in the UK, several banks require running a proprietary ID validation app.

I want to downvote your comment to register my displeasure with the banks' actions.

Re: Volkswagen started blocking GrapheneOS users

#338

Earlier quoted context omitted.

>Make sure that dealers know why you changed your mind. "Some nerd couldn't use their nerd phone." What incentive does a dealer have to know or care about this?

What incentive does a dealer have to know or care why a sale fell through? Bizarre question

I'm thinking that the effort required to make that one sale in a thousand is not worth it. The 999 others didn't complain about that.

Re: Volkswagen started blocking GrapheneOS users

#339
post #314

Earlier quoted context omitted.

Note that Fairphone does not provide software updates for anywhere near as long as they claim, and using a modern device with 7 years of support, such as a pixel or iphone, will be far better in the long term. Fairphone is basically e-waste out of the box.

Somehow that stands in stark contrast with the many Fairphone users that I know use their device for many years. One of them uses it as their primary computing device, not owning something like a laptop because the Ubuntu Touch that runs on it plugs into a screen and keyboard and works like a desktop as well as a phone for them. I don't understand why the derogatory statement about that being e-waste out of the box w…

Im not disputing the ability to use the device for many years. Using the device for a long time and the device being supported for a long time are different things.

Fairphone doesnt make their own phones, its outsourced to an ODM and Fairphone has very little input on how its designed. They havent "sourced" anything. Fairphone also stops providing kernel updates very quickly and delays userspace/driver/firmware backports for months. They delay yearly updates for years too. This doesnt even touch upon the fact they used public signing keys in the past.

It is not derogatory to say that it is e-waste out of the box, it is simply accurate. Choosing to continue using it despite how unsafe it is does not change the abysmal support it is given. A modern iPhone/android used from launch to the end of its 7 year support time, then properly recycled, would be far better for privacy, security, and for the environment. A support window that long would also provide a strong used market to continue using these devices. Cheap ODM phones with short support windows, and not benefiting from economies of scale, is a waste.

Re: Volkswagen started blocking GrapheneOS users

#340
post #223

Earlier quoted context omitted.

If they have concerns about the security of their app on some platform, they have the choice to either put "security" into the app, or to trust the platform vendor to provide the security. The correct solution is the first way. Deferring trust to the platform provider is the lazy way. If their APIs are done correctly, they shouldn't be afraid to expose them.

You're proving the previous commenter's point. VW doesn't want liability. They do not care about "security" just liability. When they leave the "security" to the platform they can blame them in a lawsuit.

Google has a pretty good legal team. Their developer ToS that absolves them of any sort of liability for anything. So this means VW is just being lazy and not seeking legal protection.

https://play.google/developer-distribution-agreement.html

Post reply on HN