Earlier quoted context omitted.
Remote attestation is not just insane, it's the technology that will end free computing as we know it today. What good is free software if using it marks our devices as untrusted and gets us banned from every service out there? Gets us ostracized from digital society? Because we "tampered" with the device? We should be able to run whatever software we want and they should be none the wiser. Instead, we are part of th…
You'll probably just need to keep two phones. One hostile spying device that you use for authenticating and dealing with government stuff, and that becomes e-waste every 2 years. Then you have one that you can repair and extend for your own stuff that respects you and your privacy.
GrapheneOS recommended for domestic abuse victims
131–140 of 228 posts
Re: GrapheneOS recommended for domestic abuse victims
#132This post is literally just SEO copy designed to sell degoogled phones to (justifiably) anxious DV victims? Their phones are more than twice as expensive as equivalent models at JF HiFi too (and 5-10x the price of an older, but still perfectly useful degoogled phone from Marketplace). Why is it on the front page of HN?
> and 5-10x the price of an older, but still perfectly useful degoogled phone from Marketplace
Devices with drastically worse privacy and security than the Android Open Source Project including lack of bare minimum updates aren't in the same space as GrapheneOS.
It's generally better for people to install GrapheneOS themselves since it's very easy and saves a lot of money. It takes 10 minutes to install GrapheneOS with the web installer. It also avoids needing to trust a company to do it, although it's possible to verify an install done by someone else is genuine with the verified boot key fingerprint and/or Auditor. An existing install by someone else should be factory reset it to avoid any sketchy configuration.
Re: GrapheneOS recommended for domestic abuse victims
#133Re: GrapheneOS recommended for domestic abuse victims
#134Can someone explain this? I've used custom ROMs back in the day (Cyanogen!) but I'm not familiar with GrapheneOS. I remember Cyanogen ships without Google Play etc., right? (Because if you install Google Services and a bunch of crap from their store (theirs and otherwise) that spies on you, it defeats the purpose of a privacy preserving OS. So I'm assuming Graphene is at least as strict as that? (Well Cyanogen at lea…
GrapheneOS is a privacy and security hardened OS. LineageOS and CyanogenMod aren't in that space. GrapheneOS preserves the standard privacy and security features and updates of the Android Open Source Project as a baseline. It greatly improves privacy and security with major privacy and security features along with much better privacy/security updates. It keeps up with the major OS updates including having a release based on Android 17 since the day it was released (2026-06-16).
> Can someone explain this? I've used custom ROMs back in the day (Cyanogen!) but I'm not familiar with GrapheneOS.
GrapheneOS is a production quality OS with around 15 people paid to work on it. It's not a hobbyist project. We've never used the term custom ROM since it isn't accurate and propagates misconceptions. It's best to avoid it.
> The article mentions that an abuser could put spyware on your phone? Is that a realistic scenario?
Yes, stalkerware is very common and there are a bunch of apps marketed for this purpose. It's helpful to get a new phone set up from scratch without the same accounts or automatically restoring any data on it. This can be a GrapheneOS phone but it doesn't particularly need to be. It's not GrapheneOS recommending itself for this purpose. There are an assortment of privacy and security features relevant to this in standard Android 17 and in the features added by GrapheneOS but nothing essential to this. GrapheneOS makes sense as a general choice for a new phone for many people due to being a highly usable, compatible, private and secure device but we're not specifically recommending it for being who are victims of stalkerware ourselves.
Re: GrapheneOS recommended for domestic abuse victims
#135Earlier quoted context omitted.
> The article mentions that an abuser could put spyware on your phone? Is that a realistic scenario? Yes, stalkerware is an entire genre of software and it is designed for exactly this purpose. How “stalkerware” apps are letting abusive partners spy on their victims https://www.technologyreview.com/2019/07/10/134249/stalkerwa... The Abuser in Your Pocket: How Stalkerware Threatens Women’s Privacy https://safeescape.o…
Happy GrapheneOS user here as well, but... I am having a hard time believing your first link, which says: > In Anna’s case, stalkerware was disguised as a picture message, sent to her by the man she was dating (let’s call him David), just a few weeks after they met. She was then under constant surveillance for about two years That sounds like an NSO-level attack, right? I doubt abusers routinely pull that out?! I tot…
There are many tiers of far easier remote attacks far easier than exploiting an up-to-date iPhone through iMessage of WhatsApp. It doesn't mean that's what happened but it's often not something that's extremely difficult. Many people use phones with years of missing security patches. It's getting increasingly easy to exploit those in the age of LLMs.
Regardless, it sounds more like a social engineering attack tricking someone into installing an invasive app and granting invasive permissions to it.
> I doubt abusers routinely pull that out?!
They do regularly use social engineering to trick their partners into setting up stalkerware or permitting it to be installed. Getting a new phone and accounts is a very helpful for people who are victims of it. They've often given access to their accounts and devices without knowing how to fully get rid of it. Reclaiming the existing devices and accounts is far easier if they have a clean one to start from where they can get technical help. It doesn't specifically need to be a GrapheneOS device, but it's a good choice in general and doesn't require being technically savvy to use or even install it.
Re: GrapheneOS recommended for domestic abuse victims
#136Earlier quoted context omitted.
Remote attestation is not just insane, it's the technology that will end free computing as we know it today. What good is free software if using it marks our devices as untrusted and gets us banned from every service out there? Gets us ostracized from digital society? Because we "tampered" with the device? We should be able to run whatever software we want and they should be none the wiser. Instead, we are part of th…
It can be used for security and used privately [1] but I entirely agree with you, Google's use of it is anti-competitive and terrible. [1] attestation.app
And even if our own keys could be used, who's going to trust those attestations? Nobody. They will trust Google's keys, Microsoft's keys, Apple's keys. Not ours.
Re: GrapheneOS recommended for domestic abuse victims
#137Earlier quoted context omitted.
You should be able to disable these alerts via the Wireless Emergency Alerts.
You cannot on many phones, and often phones will even lie when it says all categories are disabled, as some jurisdictions have laws against turning off some of the highest alert categories.
Re: GrapheneOS recommended for domestic abuse victims
#138On this subject since it's an Australian seller and marketed as "DV safe". Australia has a national test of it's phone alert system in 10 days at 27/07/26, 2PM AEST. (People in North America would know it as Cell Alerts/Presidential Alerts etc.) There have been warnings that hidden phones will almost certainly sound, and their recommendation is to ether power off the phone or put it into airplane mode at least an hou…
Re: GrapheneOS recommended for domestic abuse victims
#139Earlier quoted context omitted.
Remote attestation is not just insane, it's the technology that will end free computing as we know it today. What good is free software if using it marks our devices as untrusted and gets us banned from every service out there? Gets us ostracized from digital society? Because we "tampered" with the device? We should be able to run whatever software we want and they should be none the wiser. Instead, we are part of th…
>What good is free software if using it marks our devices as untrusted That is not what remote attestation is for. The operating system maintains isolation between apps, so a free software app being installed doesn't mean an app that needs high security is compromised.
Re: GrapheneOS recommended for domestic abuse victims
#140This is just dumb. I'm sorry, it's dumb. Why? Here we're discussing a domestic abuse situation, where people are forcing victims to hand over their phone, and have apps installed to keep track of them. Against their will. And the solution is to... what? Mysteriously have control of your own phone, and install an OS which prevents this? Seriously? I can just imagine it, when the unfamiliar OS is discovered, or the app…