Live data from Hacker News

GrapheneOS recommended for domestic abuse victims

privacypros.com.au

201–210 of 228 posts

Re: GrapheneOS recommended for domestic abuse victims

#201

Earlier quoted context omitted.

Grapheneos is the least shady OS. Why would a mass surveillance agency compromise hardware when they can simply spy at the software level though Google's deep insights into devices? Those Android distributions you refer to are not up to date, don't fully remove Google services, don't ship patches fast, don't improve exploit protections, have worse compatibility, don't make Google's services more private by running th…

[flagged]

There's a lot of evidence showing governments need to develop or purchase exploits for iPhones and Pixels. There's no evidence of there being any hardware backdoors.

> It is also suspicious the preferential treatment given to that suspicious distro while all others are left in the dark.

We don't receive any preferential treatment from Google. Android's business side disallowed us from receiving any form of partner access and took away the security patch preview access given to us by Android's security team. That has been the case for years. We have security preview patch access but it isn't from either Google. Google also hasn't ever allowed us to have early access to major Android releases but that doesn't mean we haven't obtained it.

> Using hardware from a vendor that cannot be audited and every possible business interest in spying you.

You can claim this about any hardware. Pixels meet our hardware requirements and we're expanding support to multiple upcoming Motorola Mobility (Lenovo) devices meeting our requirements. There will be a growing number of Motorola devices with official support for GrapheneOS.

> Same excuse argued by Signal

GrapheneOS has never received any government grants and is fully funded by donations. Signal didn't cover up that they were received Open Technology Fund grants and other government money.

> It is easy to be transparent about donations rather than opaque: publish the operating costs and level of donations by a certified auditor without need to disclose names.

The entirety of the GrapheneOS funding comes from donations. Our finances are audited every year as a requirement for a Canadian non-profit receiving more than $500k/year in revenue. The purpose of the audits is nearly entirely to make sure we're spending all of the money. It makes sure that all the money is accounted for and being spent appropriately. A subset of our expenses are specifically checked to make sure of it. It also involves more than that but it has little to do with where the donations are received from. Donations are largely made anonymously. We can see names for Wise and PayPal donations but they're often not the legal names of individuals or companies. Most donations are received via cryptocurrency.

We can publish information on our revenue and expenses but it's not clear what that has to do with the unsubstantiated claims you're making about us or why it would stop you from doing it.

> But you won't, strangely enough.

You weren't responding to anyone that's part of the GrapheneOS project.

Re: GrapheneOS recommended for domestic abuse victims

#202
post #99

Earlier quoted context omitted.

What do you think are the non-shady android distros?

[flagged]

> Android itself is shady as heck

In what sense is anything shady about the Android Open Source Project (AOSP)?

> WiFi and SIM card chips are compromised right out from the factory

This is an unsubstantiated claims not only lacking evidence but heavily contradicted by a large amount of available evidence. It also has nothing to do with Android.

> People are usually OK with options like postmarketOS (non-Android) or with the most popular distros like LineageOS. Some jump to things like SailFishOS (attention: russian financial hands on that one).

postmarketOS and the desktop software stack it uses is far less private and secure than AOSP.

SailfishOS isn't open source like AOSP and is far less private and secure than it. It combines many of the worst aspects of desktop operating system security with low-end Android device security.

LineageOS is another fork of AOSP but doesn't preserve all the standard updates and privacy/security protections.

None of those are a hardened OS greatly improving privacy and security compared to the baseline of AOSP. None are as private and secure as unmodified AOSP. Those aren't in the same space as GrapheneOS.

> Even a cheap chinese smartphone with their "stock" Android can argue for being less shady and raise less attention to yourself than a distro which forces you into specific poisoned hardware. That is just dumb.

You aren't backing up your claims of hardware being compromised with evidence. You're also not being specific about what it is you consider to be a problem. You have an issue with us using Pixels. Does that also apply to the upcoming Motorola Mobility (Lenovo) devices too? Which specific hardware do you think would be okay to use? We need hardware meeting our requirements for updates and hardware-based security features which is why Motorola needs to improve their devices to meet our requirements. GrapheneOS also needs extensive porting work to devices due to the hardware-based security features and the need for drivers/HALs to be made compatible with the exploit protections.

Re: GrapheneOS recommended for domestic abuse victims

#203

Earlier quoted context omitted.

What was troubling for you using it or setting it up?

[flagged]

Many of the GrapheneOS features including Contact Scopes, Storage Scopes, Sensors toggle and things most users can understand and are very interested in having. Most of what GrapheneOS provides is under the hood which is a good thing for usability but there are plenty of features non-technical users can see and understand.

Installing sandboxed Google Play is done by simply pressing the install button for it in the GrapheneOS App Store.

Re: GrapheneOS recommended for domestic abuse victims

#204

Earlier quoted context omitted.

It can be used for security and used privately [1] but I entirely agree with you, Google's use of it is anti-competitive and terrible. [1] attestation.app

It's all about who owns the keys and who trusts those keys. If you don't have the keys to "your" computer, then you don't own that computer, you're just renting it from the corporation. And even if our own keys could be used, who's going to trust those attestations? Nobody. They will trust Google's keys, Microsoft's keys, Apple's keys. Not ours.

the intent is that no one owns those keys, your silicon should be the only entity in "possession" of those keys.

but no one uses blind signatures for attestation so it can be used to fingerprint your device's serial. they do try to make it hard. but generally you should assume that if whoever you are attesting to colludes with google they will obtain your HWID - and if it's google you are attesting to you should assume they have your HWID.

GOS uses a proxy for attestation, but it does absolutely nothing for this threat model.

PS: DRM is even worse, there is no intermediary and the APIs are open to all apps. you probably need to be a well resourced intel agency to make use of it as you need to source a valid DRM license server certificate. technically, actual license servers are in violation of their agreements with google, apple, etc if they use the license request for fingerprinting. but they do retain the ability to blacklist silicon (invalidate pirate devices from pirated media watermarks).

Re: GrapheneOS recommended for domestic abuse victims

#205
post #28
post #11

Earlier quoted context omitted.

What is that? I don't seem to be finding anything relevant on Google.

We're running into situations where the usage of smart phones and apps are becoming mandatory for using services. For example: The UK has a digital ID requirement which is required for you to be employed in the UK. Additionally the EU digital identity services have a hardware/software attestitation that is required to run their apps. (Many of those which 3rd party software can't run). Another example of this is the A…

> We're running into situations where the usage of smart phones and apps are becoming mandatory for using services.

A new building is being built in my city, and the trash containers which were installed outside have instructions printed on them, indicating that you need to use a smartphone app to take out your trash.

I found this deeply offensive in a way that I cannot explain.

Re: GrapheneOS recommended for domestic abuse victims

#206
post #28

Earlier quoted context omitted.

We're running into situations where the usage of smart phones and apps are becoming mandatory for using services. For example: The UK has a digital ID requirement which is required for you to be employed in the UK. Additionally the EU digital identity services have a hardware/software attestitation that is required to run their apps. (Many of those which 3rd party software can't run). Another example of this is the A…

> The UK has a digital ID requirement which is required for you to be employed in the UK. That's untrue. There was a strong push towards the digital ID from the current administration, but it was abandoned 6 months ago. What you likely mixed up with digital ID is the old digital visa scheme, mandatory for all non-UK citizens to prove right to work. Re: your app list: looks a little bit eclectic, so it's worth mention…

> the old digital visa scheme, mandatory for all non-UK citizens to prove right to work.

Weren't they accepting refugees without documentation?

Re: GrapheneOS recommended for domestic abuse victims

#207

Earlier quoted context omitted.

> We've never used the term custom ROM since it isn't accurate and propagates misconceptions. It's best to avoid it. It's a ROM (in the phone sense), and it's not stock (so installing it is a customization). In what way is it not a custom ROM?

> It's a ROM (in the phone sense) There are multiple ROMs involved but GrapheneOS isn't one. There's an SoC boot ROM which loads SoC firmware from the SSD, verifies it and transfers control to it. The littlekernel-based firmware stage which loads GrapheneOS isn't a ROM. GrapheneOS and most of the SoC firmware are simply stored on SSD partitions. There are A/B partitions for both the SoC firmware and the OS on the SSD…

[flagged]

Re: GrapheneOS recommended for domestic abuse victims

#208
post #185

Earlier quoted context omitted.

Thats... exactly what they did. They relied on secrecy and hidden locations to aid their cause. Like... this is how the entire underground railroad and many other examples worked out.

Not in my part of the world, which is both safer and more democratic than the US approach you're defending. There were also other groups hiding away and doing interesting things - killing, maiming murdering. It took access to private communication and files to take those down - you may have have heard of some [0]. [0]: https://www.npr.org/transcripts/138889467

Critical thinking isn't exactly your strong suit, clearly.

Re: GrapheneOS recommended for domestic abuse victims

#209
post #161

Reasonably happy with GrapheneOS, but the number of bugs (maybe more ecosystem bugs) would make me hesitant to suggest other people rely on it as a communication device. I have notifications turned ON for WhatsApp, Signal and Telegram. I never receive notifications from Telegram. I have to open that app to see if anyone said anything. WhatsApp and Signal notifications seem to vary between late or never? This is despi…

This is not an issue with GrapheneOS, this is an issue with your configuration, which is trivial to solve. All of those apps support using google services FCM for push notification delivery. I dont think Telegram has a fallback, and Signal and Whatsapp have power-intensive fallbacks. You may also need to reinstall these apps for them to detect google services (apps generally dont check for google services more than o…

That's not how I understand the meaning of "trivial".

Re: GrapheneOS recommended for domestic abuse victims

#210

It's absolutely insane that phones have online accounts deeply integrated into the OS. You need to give Apple your phone number to download any apps on iOS. For example: Say anyone that downloaded IceBlock commited crime, Apple could give the govt everyone who downloaded its phone number, the govt could get the realtime location of everyone based on their phone number from the carrier. And that's not even mentioning…

"Phones have great potential to be the most private and secure computers."

How would that be achieved

We could assume that a user could make their own computer "private and secure"

But if a third party, e.g., Apple, Inc., Google, LLC, GrapheneOS Foundation, etc., has RCE, e.g., "auto-updates", then how can the computer be "private and secure" against that third party and any party that they "work with", voluntarily or not, e.g., a business partner, a government, but also others that might target these third parties, such as an attacker who isn't interested in their bug bounty programs, etc.

To achieve "private and secure", would the user need to remove the RCE capability of the third party (parties)

What about data collection and surveillance by the third party (the user would have to review the source code and compile the OS themselves to be sure about data collection and surveillance)

If there is data collection and surveillance, then how could the user be sure that the data collected and surveillance capability held by the third party is "private and secure" from that third party (e.g., Apple, Google, etc.), any third parties that work with them, and others who might target these third parties

Assuming the user even knows the identities of all these third parties, what if their operations are secretive and non-transparent

What if they have a history of dishonesty

What if they make no promises to the user that could be enforced and instead they just assume "trust"

Perhaps each user might have a different concept of "private and secure"

Post reply on HN