Live data from Hacker News

GrapheneOS recommended for domestic abuse victims

privacypros.com.au

91–100 of 228 posts

Re: GrapheneOS recommended for domestic abuse victims

#91
post #10

Can someone explain this? I've used custom ROMs back in the day (Cyanogen!) but I'm not familiar with GrapheneOS. I remember Cyanogen ships without Google Play etc., right? (Because if you install Google Services and a bunch of crap from their store (theirs and otherwise) that spies on you, it defeats the purpose of a privacy preserving OS. So I'm assuming Graphene is at least as strict as that? (Well Cyanogen at lea…

> The article mentions that an abuser could put spyware on your phone? Is that a realistic scenario? Yes, stalkerware is an entire genre of software and it is designed for exactly this purpose. How “stalkerware” apps are letting abusive partners spy on their victims https://www.technologyreview.com/2019/07/10/134249/stalkerwa... The Abuser in Your Pocket: How Stalkerware Threatens Women’s Privacy https://safeescape.o…

Happy GrapheneOS user here as well, but...

I am having a hard time believing your first link, which says:

> In Anna’s case, stalkerware was disguised as a picture message, sent to her by the man she was dating (let’s call him David), just a few weeks after they met. She was then under constant surveillance for about two years

That sounds like an NSO-level attack, right? I doubt abusers routinely pull that out?!

I totally get the problem that "the abuser knows the iCloud password and can use the FindMyPhone feature to track the victim", or "the abuser convinced the victim to install an app that would track the victim without their consent". But I am genuinely wondering how much GrapheneOS protects against that.

Re: GrapheneOS recommended for domestic abuse victims

#92
post #85
post #16

Earlier quoted context omitted.

[flagged]

Have you got a link to anything about hiding parallel accounts? I use GrapheneOS, and don't see anything in the UI about it. Am I looking for the wrong thing? From what I can see, it's the same as stock Android's user switching, which has obvious UI elements about switching session. I see hidden profiles is an open issue, here: https://github.com/GrapheneOS/os-issue-tracker/issues/5003

[flagged]

Re: GrapheneOS recommended for domestic abuse victims

#93
post #79
post #73

Earlier quoted context omitted.

And why not? Law enforcement does not represent supreme justice and good. There are higher moral principles out there. Respect for law enforcement in the absence of justice is a disaster for society. All it does is give cover for bad actors.

There's plenty of high moral principles, but "let's build technology that explicitly protects criminals - especially child and women traffickers - against investigation" ain't one of them for majority of people living in democracies.

How does it protect trafficers especially? Does it have some extra trafficking features? Does it unlock additional capabilities if you're a criminal? Or maybe it just protects everyone?

Re: GrapheneOS recommended for domestic abuse victims

#94
post #28
post #11

Earlier quoted context omitted.

What is that? I don't seem to be finding anything relevant on Google.

We're running into situations where the usage of smart phones and apps are becoming mandatory for using services. For example: The UK has a digital ID requirement which is required for you to be employed in the UK. Additionally the EU digital identity services have a hardware/software attestitation that is required to run their apps. (Many of those which 3rd party software can't run). Another example of this is the A…

This sucks. The solution is to buy the cheepest iPhone and use it just for the goverment services.

Re: GrapheneOS recommended for domestic abuse victims

#95

Very weird post, I dont see how a victim with not enough agency to control what apps are on their phone will somehow be able to install a custom os

You'd be surprised how easy GrapheneOS is to install. You literally do it through a browser with your phone connected via USB.

I don't think it was the point of the parent. Sure it's easy to install, but the point is that if an abuser can somehow control your phone and install that kind of app, then they probably won't let you remove it.

I am a (very happy) GrapheneOS user, I am certain that I can install a tracking app on it. I can even easily side-load an abusive app that would be banned on the Play Store...

Like I would totally recommend GrapheneOS because it's great, but I don't think it solves the problem of "a domestic abuser can access your phone by making you give access to your phone".

Re: GrapheneOS recommended for domestic abuse victims

#96

Very weird post, I dont see how a victim with not enough agency to control what apps are on their phone will somehow be able to install a custom os

Installing Graphene can be done through the browser: https://grapheneos.org/install/web

It's not as easy as it can be (the text is aimed at people familiar with Android flashing) but in practice you need to toggle one setting, reboot holding the volume button, and then click four buttons in your browser in order, with the exact names for settings spelled out in the guide itself.

I don't think wiping an abuser's malware is such a great solution unless you've already managed to get out of the DV situation. Perhaps GrapheneOS is a good idea on a secret second phone?

Re: GrapheneOS recommended for domestic abuse victims

#97
post #90

It's absolutely insane that phones have online accounts deeply integrated into the OS. You need to give Apple your phone number to download any apps on iOS. For example: Say anyone that downloaded IceBlock commited crime, Apple could give the govt everyone who downloaded its phone number, the govt could get the realtime location of everyone based on their phone number from the carrier. And that's not even mentioning…

Don't phones have identifiers outside of phone number anyway? I feel like you have to trust the hardware/os vendor anyway. So if you don't trust apple to not misbehave, maybe not getting an iphone is better than chasing the whole phone-number idea.

Your comment isn't super clear to me, let me know if I misunderstood anything.

Yes there are still identifiers when using cellular data service, but they aren't connected to your phone number that you give out. Phone number gets a determined threat actor real time location, which is what I explained. Threat actor gets location from any carrier identifier. Cellular was built in a terrible way for privacy and security.

Android doesn't let apps see hardware identifiers if that's related.

Yes you're correct about having to trust Apple, but my point is that the way Apple is collecting all this extra info allows them to be compelled to hand it over. It's not about trusting Apple, it's about them following the law, which they will do.

Re: GrapheneOS recommended for domestic abuse victims

#98

Earlier quoted context omitted.

Here's an article explaining why one should care: https://privacypros.com.au/privacy-hub/articles/dv-safe-phon... The tl;dr is that you can either share this data by accident through some sort of "locate my family" app, or because your abuser gets access to your Google/Apple account (for instance because you're signed in on another device they have access to). The threat model here can be: domestic abuse victim flees…

Even on grapheneos you got to install the play store and play services to get most app to work, which mean connecting to a Google account. Technically you can use fdroid, Aurora store, or only use stock applications but if we are serious, not all domestic abuse victims are also geeks that know how to do all these things. They will need their apps, for instance for social security. Also, many people use their phone to…

They don't need completely bare-bones setup. Sweet spot for non-geeks is installing play services, which can be used without signing into an account and by default have invasive permissions revoked. Then installing playstore apps from aurora store.

Re: GrapheneOS recommended for domestic abuse victims

#100
post #92
post #85

Earlier quoted context omitted.

Have you got a link to anything about hiding parallel accounts? I use GrapheneOS, and don't see anything in the UI about it. Am I looking for the wrong thing? From what I can see, it's the same as stock Android's user switching, which has obvious UI elements about switching session. I see hidden profiles is an open issue, here: https://github.com/GrapheneOS/os-issue-tracker/issues/5003

[flagged]

> I may very well be assuming things about G-OS that it doesn't yet have (or may never have).

No offence but... next time maybe make it clear that you are just assuming and don't have any experience with the thing you are describing?

> My mental picture would have been it having partitioned storage (to reduce chance of accidental over writes) filled with "random seeming 'noise'" that held hidden account specific data only accessible with a user provided key.

That would be a normal account on an encrypted phone. Nothing special about that.

Post reply on HN