Live data from Hacker News

GrapheneOS recommended for domestic abuse victims

privacypros.com.au

141–150 of 228 posts

Re: GrapheneOS recommended for domestic abuse victims

#141

Earlier quoted context omitted.

>What good is free software if using it marks our devices as untrusted That is not what remote attestation is for. The operating system maintains isolation between apps, so a free software app being installed doesn't mean an app that needs high security is compromised.

I think you've misunderstood. It's not an app problem. The problem is that it makes Free Software OSes unviable. The copy of Android you compile and install yourself - or your copy of desktop Linux where you upgraded the kernel yourself - will never pass remote attestation, and it gives both the attestation provider and software that checks attestation the ability to unilaterally shut out any OS they like with no wor…

You can apply my same comment 1 layer up.

The hypervisor maintains isolation between operating systems, so a free operating system being installed doesn't mean an app that needs a high security operating system is compromised.

Re: GrapheneOS recommended for domestic abuse victims

#143

Earlier quoted context omitted.

>What good is free software if using it marks our devices as untrusted That is not what remote attestation is for. The operating system maintains isolation between apps, so a free software app being installed doesn't mean an app that needs high security is compromised.

Then why can't we install whatever we want on "our" devices?

Because you are buying a device without the feature of installing a custom OS. If you want a feature, buy a device offering it.

Re: GrapheneOS recommended for domestic abuse victims

#144
post #28
post #11

Earlier quoted context omitted.

What is that? I don't seem to be finding anything relevant on Google.

We're running into situations where the usage of smart phones and apps are becoming mandatory for using services. For example: The UK has a digital ID requirement which is required for you to be employed in the UK. Additionally the EU digital identity services have a hardware/software attestitation that is required to run their apps. (Many of those which 3rd party software can't run). Another example of this is the A…

> The UK has a digital ID requirement which is required for you to be employed in the UK.

False

In fact I can't think of a single Government service or legal requirement that requires a smartphone in the UK.

In the past year I have applied for a passport, applied for benefits, opened a bank account, passed through border control, filed a company tax return, closed down a business, helped someone else claim for benefits, made police reports, filed a case with the small claims court, paid my council tax, received an incone tax refund, travelled on public transport extensively, hired a car.

All had alternatives as far as I can recall.

Quite a few were done online just with a computer and optionally a phone number

And based on prior discussions here I have to point out that "require" doesn't mean "ok but the alternative is kind of inconvenient"

Re: GrapheneOS recommended for domestic abuse victims

#145
post #104

Earlier quoted context omitted.

I don’t see how it’s incompatible with open source, just because my development builds aren’t being blessed.

Your "development build" is another person's daily driver. Case in point: GrapheneOS (or any other custom Android distro) is unlikely to be able to ever pass remote attestation, even a signed, secure boot build with the bootloader relocked, because it's not the original OS for the hardware. Same goes for any desktop Linux.

GrapheneOS implements its own attestation so you can attest that it's real GrapheneOS. The valid approach they've chosen is to try and get on a level playing field with the big guys rather than destroy the playing field. They have a good argument their OS is very secure, so you should accept its attestation. This is how a user-friendly OS backdoors into the attestation system.

I still think destroying the playing field is better, but less likely to succeed.

Re: GrapheneOS recommended for domestic abuse victims

#146
GrapheneOS user and community member here. TLDR: The blog post that this thread links is full of misrepresentations and falsehoods about what GrapheneOS offers and also is heavy mismarketing of the phones and services PrivacyPros offer. I recommend to avoid PrivacyPros.

The basic premise, that a secured and private phone, is useful for domestic abuse victims is of course okay. It is true that protecting your privacy from abusive family members can be useful and GrapheneOS' features, which are accurately described on their own website (contrary to the linked blog post), certainly help remove threats in that regard. See : https://grapheneos.org/features . This is dependent on the specific situation, of course, (e.g. huge difference between ex-partner stalking you and a current partner you live with abusing you), because if you are forced to give your phone password at the threat of being hurt, a secure phone won't really help you a lot.

While the licenses that GrapheneOS uses permit companies to establishes businesses using GrapheneOS software, it's not recommended by the project to buy pre-installed phones, certainly not pre-configured phones, like PrivacyPros offers. The install process of GrapheneOS is simple if you are using the WebInstaller, and there is a lot of free support available in the community chat rooms and fora if you bump into issues. This saves you a lot of money because you can buy a new, used or refurbished Pixel with the stock OS installed at a much lower price. If you install GrapheneOS itself the guide also mentions you have to verify the integrity of your installation. That also holds true for preinstalled phones, you should check the verified boot hash and set up Auditor app. Preconfigured phones should actually be completely factory reset, not only from the OS but preferably also from recovery mode and then set up again, with a check of the boot hash and a set up of Auditor app before you install any apps or start changing settings. You don't know what PrivacyPros has changed to the settings, what they loaded on the device and Auditor should be set up by yourself and straight from the beginning, before you start using the device, because pinning-based security is an important part of its security model and you would want to be pinned to a clean state from the post install.

The blog post and also the PrivacyPros website where they promote and sell their phones is riddled with unnecessary misguided advice and also falsehoods about what GrapheneOS offers and what the dangers of the stock Pixel OS and Android in general are. Pixel OS and Android in general are portrayed way too negatively. I'll just give a few examples because it will cost me way too much time too debunk and correct all of it. These ones are verified easily by yourself and I hope it just makes clear you can discard everything PrivacyPros has written and makes clear you should just consult the official GrapheneOS website. So, they pretend as if Android and Pixels themselves don't have a permission model, multiple users and verified boot. This is untrue. GrapheneOS hardens the app sandbox and permissions model more and offers stuff like storage scopes to work around to broad permissions, but the sandbox and permissions model itself exists for Android in general. Verified boot is also a standard Android feature, and also exists on iPhones and even on MacOS and ChromeOS. Multiple users are part of Android, GrapheneOS just increases the available number of users and increases their usability. Also note that users don't improve sandboxing. Sandboxing and access control exist within profiles as well, profiles are mainly meant for increased isolation via separate user data, user settings and VPN slots. They also offer separate encryption keys allowing you to selectively put data at rest etc. The whole idea of a "ghost" profile and user profiles being at the centre to security and privacy is misguided. They also call about kill switches, Pixels don't have hardware kill switches and the software kill switches are just part of Android.

Re: GrapheneOS recommended for domestic abuse victims

#147
post #6

Earlier quoted context omitted.

I agree with that.. additionaly, I'm finding it to be insane that organizations are trying to force you to have a "audited" phone to interact with them. (I.e. events, businesses, etc)

> that organizations are trying to force you to have a "audited" phone to interact with them. (I.e. events, businesses, etc) Even worse, GOVERNMENTS do that. EU Governments basically forcing you to give Google (via the Google Mobile Services rootkit) or Apple (and via the cloud act also the Trump Admin) access to your entire phone (including all of your saved personal data) to use the govt eID system...

Use the old-school ID system.

Re: GrapheneOS recommended for domestic abuse victims

#148
post #79
post #73

Earlier quoted context omitted.

And why not? Law enforcement does not represent supreme justice and good. There are higher moral principles out there. Respect for law enforcement in the absence of justice is a disaster for society. All it does is give cover for bad actors.

There's plenty of high moral principles, but "let's build technology that explicitly protects criminals - especially child and women traffickers - against investigation" ain't one of them for majority of people living in democracies.

Do you believe window curtains should be legal? Should it be legal for a TV to not include a microphone and require an internet connection (as recent LG TVs do)?

Re: GrapheneOS recommended for domestic abuse victims

#149

Earlier quoted context omitted.

[flagged]

I meant the government deciding that downloading iceblock is a crime, because it shouldn't be, not that people who downloaded it used it commit crimes. Apologies for not being clear if that's how you were interpreting.

Didn't that already happen?

Re: GrapheneOS recommended for domestic abuse victims

#150

It's absolutely insane that phones have online accounts deeply integrated into the OS. You need to give Apple your phone number to download any apps on iOS. For example: Say anyone that downloaded IceBlock commited crime, Apple could give the govt everyone who downloaded its phone number, the govt could get the realtime location of everyone based on their phone number from the carrier. And that's not even mentioning…

I mean... your sentiment is in the right place, but Android phones (non-GrapheneOS) can be used without Google account just fine.

Yes, you need to use F-Droid & Co. to get apps (just like on Graphene), but otherwise they're functional and many people are actually using them like that.

Post reply on HN