Live data from Hacker News

GrapheneOS recommended for domestic abuse victims

privacypros.com.au

101–110 of 228 posts

Re: GrapheneOS recommended for domestic abuse victims

#101
post #92
post #85

Earlier quoted context omitted.

Have you got a link to anything about hiding parallel accounts? I use GrapheneOS, and don't see anything in the UI about it. Am I looking for the wrong thing? From what I can see, it's the same as stock Android's user switching, which has obvious UI elements about switching session. I see hidden profiles is an open issue, here: https://github.com/GrapheneOS/os-issue-tracker/issues/5003

[flagged]

As much as I don't like to, I do use Google things on phone, and I've really only ever used secondary profiles to use shady apps with far too broad permissions, such as the kind required to update firmware or get data from wireless/Bluetooth devices.

If you do want a smart phone, but don't want rubbish on it, Graphene is very bare-bones by default. F-Droid and other FOSS-friendly app stores can fill in a lot of gaps, and respect your privacy.

Some apps will simply not run without Play Services, but if you had to use such an app, I believe you could do it in a second profile and have Play Services disabled in your main. Regular apps installed for secondary profiles show as "Not installed for this user" in my main, but Play Services is a bit special.

Re: GrapheneOS recommended for domestic abuse victims

#103
post #15
post #10

Can someone explain this? I've used custom ROMs back in the day (Cyanogen!) but I'm not familiar with GrapheneOS. I remember Cyanogen ships without Google Play etc., right? (Because if you install Google Services and a bunch of crap from their store (theirs and otherwise) that spies on you, it defeats the purpose of a privacy preserving OS. So I'm assuming Graphene is at least as strict as that? (Well Cyanogen at lea…

I mean, some obvious things are there in the article, IMHO - - App isolation and hidden profiles (up to 32 separate profiles) - Verified Boot (tamper detection on every startup) So you can do stuff on there that's not going to tip off someone who's controlling enough to demand to see your phone, and so you'll at least be tipped off if someone compromises it.

> hidden profiles (up to 32 separate profiles)

I am a happy user of GrapheneOS, I don't know about "hidden" profiles. I am not sure what they are talking about.

> App isolation

That's an Android thing, not specific to GrapheneOS.

> Verified Boot (tamper detection on every startup)

That's an Android thing, not specific to GrapheneOS.

Re: GrapheneOS recommended for domestic abuse victims

#104

Earlier quoted context omitted.

>What good is free software if using it marks our devices as untrusted That is not what remote attestation is for. The operating system maintains isolation between apps, so a free software app being installed doesn't mean an app that needs high security is compromised.

I think you've misunderstood. It's not an app problem. The problem is that it makes Free Software OSes unviable. The copy of Android you compile and install yourself - or your copy of desktop Linux where you upgraded the kernel yourself - will never pass remote attestation, and it gives both the attestation provider and software that checks attestation the ability to unilaterally shut out any OS they like with no wor…

I don’t see how it’s incompatible with open source, just because my development builds aren’t being blessed.

Re: GrapheneOS recommended for domestic abuse victims

#105

It's absolutely insane that phones have online accounts deeply integrated into the OS. You need to give Apple your phone number to download any apps on iOS. For example: Say anyone that downloaded IceBlock commited crime, Apple could give the govt everyone who downloaded its phone number, the govt could get the realtime location of everyone based on their phone number from the carrier. And that's not even mentioning…

[flagged]

Law enforcement don't have a legal right to access all that people do, say, and think. They are there to investigate and present evidence to court incase of illegal activity, nothing more.

Re: GrapheneOS recommended for domestic abuse victims

#106
post #79
post #73

Earlier quoted context omitted.

And why not? Law enforcement does not represent supreme justice and good. There are higher moral principles out there. Respect for law enforcement in the absence of justice is a disaster for society. All it does is give cover for bad actors.

There's plenty of high moral principles, but "let's build technology that explicitly protects criminals - especially child and women traffickers - against investigation" ain't one of them for majority of people living in democracies.

You forgot terrorists on your usual list of reasons e2e is bad. Technology will always be used for bad and good, but there are far more people using it for good than bad.

Re: GrapheneOS recommended for domestic abuse victims

#107
post #100
post #92

Earlier quoted context omitted.

[flagged]

> I may very well be assuming things about G-OS that it doesn't yet have (or may never have). No offence but... next time maybe make it clear that you are just assuming and don't have any experience with the thing you are describing? > My mental picture would have been it having partitioned storage (to reduce chance of accidental over writes) filled with "random seeming 'noise'" that held hidden account specific data…

[flagged]

Re: GrapheneOS recommended for domestic abuse victims

#109
post #104

Earlier quoted context omitted.

I think you've misunderstood. It's not an app problem. The problem is that it makes Free Software OSes unviable. The copy of Android you compile and install yourself - or your copy of desktop Linux where you upgraded the kernel yourself - will never pass remote attestation, and it gives both the attestation provider and software that checks attestation the ability to unilaterally shut out any OS they like with no wor…

I don’t see how it’s incompatible with open source, just because my development builds aren’t being blessed.

It’s not incompatible with open source. It’s incompatible with free software. If Apple or Google or Microsoft or the government needs to “bless” your build, then you have no freedom to actually use your build.

Re: GrapheneOS recommended for domestic abuse victims

#110
post #101
post #92

Earlier quoted context omitted.

[flagged]

As much as I don't like to, I do use Google things on phone, and I've really only ever used secondary profiles to use shady apps with far too broad permissions, such as the kind required to update firmware or get data from wireless/Bluetooth devices. If you do want a smart phone, but don't want rubbish on it, Graphene is very bare-bones by default. F-Droid and other FOSS-friendly app stores can fill in a lot of gaps,…

[flagged]
Post reply on HN