Live data from Hacker News

Android may soon restrict on-device ADB

kitsumed.github.io

531–536 of 536 posts

Re: Android may soon restrict on-device ADB

#531

Earlier quoted context omitted.

Android became a lost cause the second they introduced hardware remote attestation. Even if there was a way to install your own software, there's no point in doing so. You're "tampering" with the device. Fail attestation and you're untrusted. You get banned from everything. If you hack, you're ostracized from digital society. You're a second class citizen. Can't communicate. Can't bank. Can't stream. Can't play video…

> GrapheneOS is quite literally the last hope for Android Don't they support the idea of the hardware attestation and having no root?

All of this has already been explained to fsflover in detail numerous times, but for any onlookers here are some of the project's thoughts on the subject of hardware attestation:

https://grapheneos.social/@GrapheneOS/116550899908879585

https://attestation.app/about

On the subject of root, it completely breaks the security model of the OS, and for very valid reasons they have no interest in having official installations with widely varying security models.

They also have no opposition to people creating their own forks to do so, and they publish comprehensive build instructions: https://grapheneos.org/build

Lo and behold: https://github.com/schnatterer/rooted-graphene

Re: Android may soon restrict on-device ADB

#532

Earlier quoted context omitted.

> many banks in the UK no longer offer a web portal Same in Norway.

Is it that dire? I'm in with DNB and Nordea and they both have functioning netbanks. But I don't know how the rest are. I've been getting by with a bankid codebrick and web browser access (although Nordea and DNB apps work fine on GrapheneOS).

DNB killed the excellent SBanken website and the SBanken Android app. So now I have to use DNB's crap version of the SBanken app or DNB's really horrible website.

We all protested that DNB was simply killing a competitor but the government let them do it anyway.

Re: Android may soon restrict on-device ADB

#533

Earlier quoted context omitted.

> GrapheneOS is quite literally the last hope for Android Don't they support the idea of the hardware attestation and having no root?

All of this has already been explained to fsflover in detail numerous times, but for any onlookers here are some of the project's thoughts on the subject of hardware attestation: https://grapheneos.social/@GrapheneOS/116550899908879585 https://attestation.app/about On the subject of root, it completely breaks the security model of the OS, and for very valid reasons they have no interest in having official installatio…

Thanks for the first link. I think I agree with everything written there.

> On the subject of root, it completely breaks the security model of the OS

This is just the opinion of the GrapheneOS team. I've never seen any actual data supporting it. Also it contradicts to the security approach of Qubes OS, doesn't it?

Re: Android may soon restrict on-device ADB

#534

Earlier quoted context omitted.

> Hardly seems like a big deal? https://news.ycombinator.com/item?id=49047638

So the risk is the plug for that being yanked in the ~2-5 days between ordering it and unlocking it? So... not a big deal at all. Not even slightly lol.

Unless you want to unlock later, e.g., when the vendor support ends.

Re: Android may soon restrict on-device ADB

#535

Earlier quoted context omitted.

All of this has already been explained to fsflover in detail numerous times, but for any onlookers here are some of the project's thoughts on the subject of hardware attestation: https://grapheneos.social/@GrapheneOS/116550899908879585 https://attestation.app/about On the subject of root, it completely breaks the security model of the OS, and for very valid reasons they have no interest in having official installatio…

Thanks for the first link. I think I agree with everything written there. > On the subject of root, it completely breaks the security model of the OS This is just the opinion of the GrapheneOS team. I've never seen any actual data supporting it. Also it contradicts to the security approach of Qubes OS, doesn't it?

> Thanks for the first link. I think I agree with everything written there.

You're welcome, happy to help.

> This is just the opinion of the GrapheneOS team.

I don't think it can be dismissed as mere opinion, but even if it were, that's their prerogative: it's their project. A lot of people seem to think they should take counsel from everyone with an opinion about their free OS, even if it fundamentally changes the basic nature of the project, wihle people who are free to fork it and do what they like with it.

If we're going to invoke the concept that FOSS fundamentally means it's somehow more secure because we are free to audit it (a premise I find faulty but not for any relevant purposes here), we should expand that view to include the concept that anyone who publishes their FOSS project is under no obligation to increase their workload and change the fundamental nature of their project to satisfy requests they don't view as being in harmony with the project.

Anyone who's capable of auditing FOSS code is a thousand times more capable than they need to be to follow instructions to build a rooted GrapheneOS installation, and some do.

> I've never seen any actual data supporting it.

What kind of data are you envisioning that would support it?

> Also it contradicts to the security approach of Qubes OS, doesn't it?

That's an interesting question, but I want to make sure I'm understanding it right. In what way would it contradict it? Is it a case of, Qubes OS gives you root access in dom0, TemplateVMs and AppVMs, by GrapheneOS's logic, doesn't that undermine its security?

Or were you going a different direction with it?

Re: Android may soon restrict on-device ADB

#536

Earlier quoted context omitted.

So the risk is the plug for that being yanked in the ~2-5 days between ordering it and unlocking it? So... not a big deal at all. Not even slightly lol.

Unless you want to unlock later, e.g., when the vendor support ends.

That's fine, the device will have long since done the check-in and enabled the option.

And it's not contingent on "vendor support" in the typical sense it's used. As in, this doesn't stop working after the 5-7 year support window

Post reply on HN