Live data from Hacker News

GrapheneOS recommended for domestic abuse victims

privacypros.com.au

191–200 of 228 posts

Re: GrapheneOS recommended for domestic abuse victims

#191
post #124

Earlier quoted context omitted.

You should be able to disable these alerts via the Wireless Emergency Alerts.

You cannot on many phones, and often phones will even lie when it says all categories are disabled, as some jurisdictions have laws against turning off some of the highest alert categories.

There was a tornado warning a few towns over a month ago. My spouse's phone for wireless emergency alerts kept going off every five minutes for the other town: no other warnings for our town specifically.

She ended up disabling the alerts entirely, which seemed a shame to me, but the ear splitting siren every 5minutes wasn't really conducive to our sanity or our dog's or our ability to actually hear the weather radio.

Moreover, it's a huge pain to get to the history of emergency alerts, which seems like a design flaw. Surprising how poorly a critical life system can be designed.

Re: GrapheneOS recommended for domestic abuse victims

#192
post #133

Earlier quoted context omitted.

I meant - explain how would that data retrieval actually happen in real life for a domestic abuser.

Abuser calls police and says the victim did some crime, police subpoena Google for location history.

How is that different from getting that data from the phone company?

Re: GrapheneOS recommended for domestic abuse victims

#194
post #162

Earlier quoted context omitted.

Your assumption that "criminals" are doing something morally wrong is fundamentally flawed. Civil rights activists were criminals, as were suffragettes, and the people who protected Jews in Nazi Germany, and gay or trans people just existing in countries where that isn't allowed. All criminals. Law enforcement isn't even always carrying out the law, as we've seen with ICE arresting, assaulting, searching, deporting p…

Yes, exactly, but if you actually follow all of those groups, none of them changed things by building bunkers into which police couldn't ever enter and any crime could happen there. As someone who grew up on the other side of the iron curtain, I find this idea that you'll make your own government an enemy and shield criminals against it utterly naive, since that's not what actually changes society. It's a form of tec…

It's not cowardice. It's a standard defence against tyranny. Governments can change quickly so even if you think your present government is democratic and healthy it still pays to keep the tools to defend against it if it changes.

If your government is seeking to remove those tools from you then that is a warning sign.

Re: GrapheneOS recommended for domestic abuse victims

#195

Earlier quoted context omitted.

Your assumption that "criminals" are doing something morally wrong is fundamentally flawed. Civil rights activists were criminals, as were suffragettes, and the people who protected Jews in Nazi Germany, and gay or trans people just existing in countries where that isn't allowed. All criminals. Law enforcement isn't even always carrying out the law, as we've seen with ICE arresting, assaulting, searching, deporting p…

You do realize there's another side to it, right? There are morally good examples where privacy is needed, and morally bad examples where not being able to access data is harmful. I personally agree with you, but for most people it's not black or white. They want privacy when it suits them, but would take yours away in a heartbeat.

I agree that privacy is not always a force for good. I think that when we remove privacy we normally lose much more than we gain.

People easily focus on negative consequences of privacy (dangerous people being able to communicate secretly) and don't notice the benefits they enjoy because of privacy.

Re: GrapheneOS recommended for domestic abuse victims

#196
post #178

It's absolutely insane that phones have online accounts deeply integrated into the OS. You need to give Apple your phone number to download any apps on iOS. For example: Say anyone that downloaded IceBlock commited crime, Apple could give the govt everyone who downloaded its phone number, the govt could get the realtime location of everyone based on their phone number from the carrier. And that's not even mentioning…

Curious to hear: how much effort did it take to migrate to GrapheneOS? I own a pixel, grabbed it in anticipation of unlocking, but the effort it seems it would take from reading GrapheneOS docs has stopped me from committing to it on my daily driver. Would you please provide a quick time estimate and any snags you hit?

Time estimate depends heavily on the apps you use (data migration in them) and maybe some features that don't easily work out-of-the-box in GOS like Google's find my device, where you'd ideally migrate to use foss alternatives like FMD[1]. For the easiest setup by far just install the sandboxed Google Play Store and get your apps from there. In general the more additional security features you enable, the more issues you may face, so I'd recommend leaving everything to GOS default, like leaving Sensors permission ON by default. There are a few gotchas that may not be mentioned in GOS official documentation or elsewhere such as BT tracker devices not being supported for the most part, requiring workarounds. There are also few apps that don't currently support GOS [2][3], so be sure to check them out beforehand.

1: https://gitlab.com/fmd-foss/fmd-android

2: https://grapheneos.org/articles/attestation-compatibility-gu...

3: https://privsec.dev/posts/android/banking-applications-compa...

Re: GrapheneOS recommended for domestic abuse victims

#197
post #154
post #94

Earlier quoted context omitted.

This sucks. The solution is to buy the cheepest iPhone and use it just for the goverment services.

The cheapest new iPhone is €720 (iPhone 17e)

It doesn't have to be new. They'll permit using an Android 8 to 10 device last updated over 6 years ago or a similarly old iPhone.

Re: GrapheneOS recommended for domestic abuse victims

#198
post #178

It's absolutely insane that phones have online accounts deeply integrated into the OS. You need to give Apple your phone number to download any apps on iOS. For example: Say anyone that downloaded IceBlock commited crime, Apple could give the govt everyone who downloaded its phone number, the govt could get the realtime location of everyone based on their phone number from the carrier. And that's not even mentioning…

Curious to hear: how much effort did it take to migrate to GrapheneOS? I own a pixel, grabbed it in anticipation of unlocking, but the effort it seems it would take from reading GrapheneOS docs has stopped me from committing to it on my daily driver. Would you please provide a quick time estimate and any snags you hit?

It takes around 10 minutes to install it. Most of the time people spend on it is deciding how they want to set things up. It's very easy to set it up in a similar way that you would use the stock OS. You can use a single profile with sandboxed Google Play installed.

Many people want to segment things more than that by having a dedicated profile for apps depending on sandboxed Google Play. A work profile, Private Space or secondary user can be used for it. A work profile or Private Space is a lot more convenient. Using a work profile avoids wasting the Owner user's Private Space if you want to use it for sensitive data. We want to add support for multiple Private Spaces per user in the future instead of only 1 per user to fully obsolete work profiles for local usage.

Re: GrapheneOS recommended for domestic abuse victims

#199

Earlier quoted context omitted.

And where the acceleration comes in in such description? Improving one's immediate circumstances in such context is talking to someone and asking for help, not spending days installing latest set of tools endorsed by privacy advocates and bricking one's phone due to accident while flashing privacy-friendly ROM.

There's no risk of bricking a device by using the official GrapheneOS web installer and it takes 10 minutes. Devices can also be purchased with GrapheneOS installed. Aside from that, GrapheneOS isn't read-only memory firmware and that incorrect term should be avoided since it propagates misconceptions.

Thanks for correction, I'll try to be more accurate in the future

Re: GrapheneOS recommended for domestic abuse victims

#200

Earlier quoted context omitted.

> So I'm assuming Graphene is at least as strict as that? GrapheneOS is a privacy and security hardened OS. LineageOS and CyanogenMod aren't in that space. GrapheneOS preserves the standard privacy and security features and updates of the Android Open Source Project as a baseline. It greatly improves privacy and security with major privacy and security features along with much better privacy/security updates. It keep…

> We've never used the term custom ROM since it isn't accurate and propagates misconceptions. It's best to avoid it. It's a ROM (in the phone sense), and it's not stock (so installing it is a customization). In what way is it not a custom ROM?

> It's a ROM (in the phone sense)

There are multiple ROMs involved but GrapheneOS isn't one. There's an SoC boot ROM which loads SoC firmware from the SSD, verifies it and transfers control to it. The littlekernel-based firmware stage which loads GrapheneOS isn't a ROM. GrapheneOS and most of the SoC firmware are simply stored on SSD partitions. There are A/B partitions for both the SoC firmware and the OS on the SSD. Installing (flashing) GrapheneOS involves writing out images to those partitions on the SSD and erasing an existing data partition which also happens as part of unlocking or locking the device. Those partitions aren't read-only from an OS perspective. Verified boot secures what's stored on those, not any form of hardware or firmware level write protection.

There are also boot ROMs for other hardware components. Many of those are responsible for receiving firmware uploaded by the OS to the hardware component at boot, verifying it and transferring control to it. The secure element has separate persistent firmware with a separate verified boot process since the OS isn't allowed to update it until the Owner user has successfully authenticated so it needs persistent firmware. Other hardware components mostly don't need persistent firmware and it's more secure if they don't have it.

> it's not stock

GrapheneOS will be available as the stock OS on multiple Motorola Mobility devices based on our partnership. It won't necessarily be available as the stock OS when the official support for it launches since it's not one of the minimum requirements but it's planned.

> so installing it is a customization

It's a separate OS forked from the Android Open Source Project but this terminology gives many people the incorrect impression that it's a modification of the stock OS. It leads to many people asking questions about what it removes from the stock OS and believing we removed Google integration when that was never present in the baseline. There are a lot of misconceptions which are propagated by this terminology. We don't use it and think it only serves to create unnecessary confusion and misconceptions.

> In what way is it not a custom ROM?

It was just never accurate terminology for forks of the Android Open Source Project on modern devices. The terminology originates from phone modding prior to Android and there was a time it made sense. It hasn't made sense for a long time.

Post reply on HN