Live data from Hacker News

GrapheneOS recommended for domestic abuse victims

privacypros.com.au

181–190 of 229 posts

Re: GrapheneOS recommended for domestic abuse victims

#181
post #124

Earlier quoted context omitted.

You cannot on many phones, and often phones will even lie when it says all categories are disabled, as some jurisdictions have laws against turning off some of the highest alert categories.

GrapheneOS supports fully disabling wireless alerts via the Settings app. It's possible to disable it on other Android devices via ADB.

[flagged]

Re: GrapheneOS recommended for domestic abuse victims

#182
post #28
post #11

Earlier quoted context omitted.

What is that? I don't seem to be finding anything relevant on Google.

We're running into situations where the usage of smart phones and apps are becoming mandatory for using services. For example: The UK has a digital ID requirement which is required for you to be employed in the UK. Additionally the EU digital identity services have a hardware/software attestitation that is required to run their apps. (Many of those which 3rd party software can't run). Another example of this is the A…

> gov.br (Brazilian government app)

Sucks... At least brazilian banks don't ban it. At least not yet.

Re: GrapheneOS recommended for domestic abuse victims

#183
post #178

It's absolutely insane that phones have online accounts deeply integrated into the OS. You need to give Apple your phone number to download any apps on iOS. For example: Say anyone that downloaded IceBlock commited crime, Apple could give the govt everyone who downloaded its phone number, the govt could get the realtime location of everyone based on their phone number from the carrier. And that's not even mentioning…

Curious to hear: how much effort did it take to migrate to GrapheneOS? I own a pixel, grabbed it in anticipation of unlocking, but the effort it seems it would take from reading GrapheneOS docs has stopped me from committing to it on my daily driver. Would you please provide a quick time estimate and any snags you hit?

It took me about an hour. I sat down, read the docs, installed it via the web installer, then spent the next 45 min deciding how I wanted to segment separate profiles for play services.

Nowadays it seems a lot easier because there seems to be a separate profile isolater you can run in the main profile, which I would choose if I was installing today.

The only hiccup I've had is that sometimes group messages don't send correctly and send individual messages to everyone, but I think that's because I'm on a secondary profile, and it only happens when the phone is receiving a bunch of messages all at once while I try to send to the same group. But I deny network access to my installed swype keyboard, so it may have something to do with that too.

I've been running this for years, since the Pixel 7 came out, which I'm still using.

I love it. I can confidently go through customs knowing that if they yank my phone during some weird checkpoint and try to celbrite it, I'm as secure as can be.

Re: GrapheneOS recommended for domestic abuse victims

#184
post #79

Earlier quoted context omitted.

There's plenty of high moral principles, but "let's build technology that explicitly protects criminals - especially child and women traffickers - against investigation" ain't one of them for majority of people living in democracies.

In the era before the advent of mass digital surveillance, it was well understood that there are many different ways to fight crime. Now every time I see this conversation being had, it's treated as if keeping any amount of privacy beyond what you personally find acceptable is tantamount to endorsing the existence of human traffickers. Warrantless spread-shot digital surveillance is now often treated as essential. I…

> In the era before the advent of mass digital surveillance, it was well understood that there are many different ways to fight crime. Now every time I see this conversation being had, it's treated as if keeping any amount of privacy beyond what you personally find acceptable is tantamount to endorsing the existence of human traffickers. Warrantless spread-shot digital surveillance is now often treated as essential.

That's not what anyone writes, especially not me.

> I have a question for you. Why don't you advocate for more surveillance? The more active and widespread the surveillance, the more criminals can be caught. If you think it's not entirely practical, just embark on a thought experiment with me -- assume it would be practical. Would you do it? Would you have everyone be under perfect surveillance 24/7 in order to catch every criminal? Let's call this stance surveillance maximalism.

Because it's a bad tradeoff between free society and safe society. There's a reason why we put checks and balances on enforcement agencies and why it's so important to keep them up to date.

> If you agree with surveillance maximalism, then we're just very different people and I don't think we can find common ground. I hope we can live peacefully in different countries with different laws that suit our preferences.

I do not agree with surveillance maximalism.

> By adopting this moral high ground, the discourse is kept at a shallow level. We talk less about which surveillance measures are actually effective or not, what has happened to crime rates over time, what is the context in which crime occurs, what are the negative consequences of undermining privacy, what are the negative consequences of mass surveillance etc. Instead we waste our time and energy on cheap moral opprobrium.

I agree, so perhaps losing your mind and going into mindless screaming every time anyone opens a debate about tradeoff between access, surveillance and privacy isn't the best way forward. Which is what's happening here way too many times.

Just because I acknowledge an issue which gave us things like surveillance warrants and existence of police forces doesn't mean you can just strawman me into whatever position you hate. Perhaps think on the reason why every single stable prosperous society has concepts of police and police warrants which grant access to private spheres when deemed necessary.

Re: GrapheneOS recommended for domestic abuse victims

#185
post #162

Earlier quoted context omitted.

Yes, exactly, but if you actually follow all of those groups, none of them changed things by building bunkers into which police couldn't ever enter and any crime could happen there. As someone who grew up on the other side of the iron curtain, I find this idea that you'll make your own government an enemy and shield criminals against it utterly naive, since that's not what actually changes society. It's a form of tec…

Thats... exactly what they did. They relied on secrecy and hidden locations to aid their cause. Like... this is how the entire underground railroad and many other examples worked out.

Not in my part of the world, which is both safer and more democratic than the US approach you're defending.

There were also other groups hiding away and doing interesting things - killing, maiming murdering. It took access to private communication and files to take those down - you may have have heard of some [0].

[0]: https://www.npr.org/transcripts/138889467

Re: GrapheneOS recommended for domestic abuse victims

#186
post #32

Is GrapheneOS usable by everyone, including the most non-technical phone users, in a secure way? They also recommend at least 12 GB RAM. What about domestic abuse survivors requires that?

Yes, I find it much easier to set up and use than any other Android phone. There’s less bloatware, and battery life is noticeably better. Two tips for beginners: Google Play Store and Google Play Services can be installed from the App Store. They aren’t included by default because GrapheneOS works fine without them. If a trusted app has trouble running, try enabling Exploit protection compatibility mode on the app’s…

People in IT vastly overestimate what others understand:

> Google Play Store and Google Play Services can be installed from the App Store.

Few will manage this on their own. What is Play Store? And what are Play Services? What does 'services' mean? Do I need both? Can I just use one or the other? When would I use them?

> They aren’t included by default because GrapheneOS works fine without them.

It doesn't, from what I understand. For normal users, 'works fine' means they can download and install any app.

> If a trusted app has trouble running, try enabling Exploit protection compatibility mode on the app’s Info screen (long-press the app icon → Info → Exploit protection).

lol - 'exploit'? 'mode'? 'app’s Info screen'? Even 'long-press' is not usuable by many, especially older people and others with less manual dexterity than 20-something software designers.

> you should switch to a more trustworthy bank

That isn't a serious solution. I love GrapheneOS, but it isn't ready for typical end-users.

Re: GrapheneOS recommended for domestic abuse victims

#187
post #10

Can someone explain this? I've used custom ROMs back in the day (Cyanogen!) but I'm not familiar with GrapheneOS. I remember Cyanogen ships without Google Play etc., right? (Because if you install Google Services and a bunch of crap from their store (theirs and otherwise) that spies on you, it defeats the purpose of a privacy preserving OS. So I'm assuming Graphene is at least as strict as that? (Well Cyanogen at lea…

> So I'm assuming Graphene is at least as strict as that? GrapheneOS is a privacy and security hardened OS. LineageOS and CyanogenMod aren't in that space. GrapheneOS preserves the standard privacy and security features and updates of the Android Open Source Project as a baseline. It greatly improves privacy and security with major privacy and security features along with much better privacy/security updates. It keep…

> We've never used the term custom ROM since it isn't accurate and propagates misconceptions. It's best to avoid it.

It's a ROM (in the phone sense), and it's not stock (so installing it is a customization). In what way is it not a custom ROM?

Re: GrapheneOS recommended for domestic abuse victims

#188
post #176
post #103

Earlier quoted context omitted.

> hidden profiles (up to 32 separate profiles) I am a happy user of GrapheneOS, I don't know about "hidden" profiles. I am not sure what they are talking about. > App isolation That's an Android thing, not specific to GrapheneOS. > Verified Boot (tamper detection on every startup) That's an Android thing, not specific to GrapheneOS.

Indeed, whenever I reboot (which is very frequently, because Mastodon will only open, not reopen . If I close it, I need to reboot before using it again) I see the tamper detection. It warns me that I'm using GrapheneOS, not Android.

Yeah that's telling you that you are using custom signing keys (the ones of GrapheneOS, which should be compared once with those published on GrapheneOS' website).

Stock Android runs the tamper detection just the same; they just don't warn about the custom keys because the keys are not custom, they are the ones expected by the manufacturer :-).

Re: GrapheneOS recommended for domestic abuse victims

#189
post #32

Is GrapheneOS usable by everyone, including the most non-technical phone users, in a secure way? They also recommend at least 12 GB RAM. What about domestic abuse survivors requires that?

Yes it's usable by everyone. It's secure by default but anyone can make something insecure. For example granting malicious apps accessiblity permissions would not be great for security. It has 99.99% android app compatibility. Over 90% of banking and government apps work. These apps take extra measures to ban grapheneos, apps must put in work to make their app incompatible , not the other way around. I wouldn't say a…

See my response to the sister comment, if you don't mind.

> anyone can make something insecure

Many consumer products, including iPhones to a significant degree, are designed to prevent this, much to the frustration of hackers. 'What do you mean I can't sideload random apps?' Or other products: It takes a lot of effort to make your car insecure, or to make your stove leak gas. They are carefully designed for safety.

Re: GrapheneOS recommended for domestic abuse victims

#190
post #91

Earlier quoted context omitted.

Happy GrapheneOS user here as well, but... I am having a hard time believing your first link, which says: > In Anna’s case, stalkerware was disguised as a picture message, sent to her by the man she was dating (let’s call him David), just a few weeks after they met. She was then under constant surveillance for about two years That sounds like an NSO-level attack, right? I doubt abusers routinely pull that out?! I tot…

> That sounds like an NSO-level attack, right? There are many tiers of far easier remote attacks far easier than exploiting an up-to-date iPhone through iMessage of WhatsApp. It doesn't mean that's what happened but it's often not something that's extremely difficult. Many people use phones with years of missing security patches. It's getting increasingly easy to exploit those in the age of LLMs. Regardless, it sound…

> Many people use phones with years of missing security patches

Right, yeah that's actually a good reason to use GrapheneOS.

> It doesn't specifically need to be a GrapheneOS device, but it's a good choice in general and doesn't require being technically savvy to use or even install it.

I totally agree here. Very good choice, and I would argue that a "normal" person wouldn't make the difference between GrapheneOS with sandbox Play Services and stock Android. Installing may be intimidating, even though the GrapheneOS installer is extremely impressive (it just works and doesn't require any knowledge). Still normies tend to get intimidated just from the idea of reinstalling their system :-).

Post reply on HN