Earlier quoted context omitted.
One of the parties involved in a call recording it is not surveillance. It's comparable to having chat logs for text messaging. Contrary to what you've claimed, vast majority of US states have one party consent for call recording. GrapheneOS Foundation is based in Canada where one party consent is the law. Our feature is designed for people to comply with the law in jurisdictions requiring two party consent. It shows…
[flagged]
GrapheneOS Overhauled Default Apps and Secure Clipboard
251–260 of 284 posts
Re: GrapheneOS Overhauled Default Apps and Secure Clipboard
#252Re: GrapheneOS Overhauled Default Apps and Secure Clipboard
#253Earlier quoted context omitted.
GrapheneOS does include GPLv2 code both via AOSP and our own but not GPLv3. We want GrapheneOS to have no additional restrictions beyond AOSP. AOSP uses GPLv2 but not GPLv3. We do need to be careful with GPLv2 due to license incompatibilities. For example, GPLv2-only licensing such as the Linux kernel is incompatible with Apache 2 and GPLv3. GPLv3 is compatible with Apache 2 so GPLv2-or-later can be compatible but on…
It seems like you have more freedom than you think you do. See this comment https://news.ycombinator.com/item?id=49594824 > Packaging software shouldn't change the license of GOS as such. If you haven't had already, maybe the free software foundation could provide you with assurance? I guess it will make your life much easier if you wouldn't have to restrict yourself that much.
Re: GrapheneOS Overhauled Default Apps and Secure Clipboard
#254Earlier quoted context omitted.
It would go against our approach to choose specific messaging apps and protocols to bundle with the OS beyond SMS/MMS/RCS. We shouldn't be the ones choosing Signal vs. SimpleX vs. Element or other options but rather that's up to users to decide. I disagree with this somewhat. Apple and Google make these sweeping decisions for their users and in effect promote one tech over another. Adopting RCS and integrating it nat…
RCS is a modern replacement for SMS/MMS with end-to-end encryption (E2EE) support via MLS. We have SMS/MMS so we need RCS to replace those. Similarly, carrier-based calls are there and should get replaced with a newer standard with E2EE. RCS is what GMS Android and iOS provide so that's what people need to talk to non-GrapheneOS users. Which non-carrier-based messaging app or protocol do you think we should include a…
I think in the short term, you should take a look at e.g. Cheogram, Conversations, and Element and consider ways to enhance integration. Address book integration, automatically extending contact do not disturb exceptions, and maybe even dialer integration.
In the long term, it would be best to try to guage antitrust regulator attitudes wrt to protocols like XMPP and Matrix. In the end, they are the only ones who can really force mass adoption of an open protocol. But alternative OSs having native support and integration for such messaging protocols can tip the scales and be used as evidence of the protocol's viability and legitimacy.
Re: GrapheneOS Overhauled Default Apps and Secure Clipboard
#255Earlier quoted context omitted.
The RCS spec has encryption in its documentation. I think the current spec version is 4.0?
It has it in its current documentation (maybe 3.0 too? I forget, but it's new this year), and Apple and Google have had messages to themselves encrypted for a while (but not to each other, which is what the RCS docs are intended to resolve). It took many years to get it documented though (despite loudly claiming RCS is more secure the whole time), and AFAIK none yet implement it. Definitely none with all the document…
I do! I have a old-ish but up-to-date and stock Pixel phone, and I see (what appears to be) full E2EE with several text contacts in Messages, with ability to verify keys (which admittedly I have not attempted to use yet). It only works if both devices / all of the devices in a group are fully compatible with the version that adds encryption or newer, but when they do, it just starts working automatically and transparently. AFAIK, that's primarily thanks to Google's work.
I think what we've learned from the rise and fate of current alternative messaging apps and services is that, if we actually want to get the majority of the world's population on modern-quality E2EE for all of their communication, it's going to have to be done gradually and transparently through the apps they already use. Getting everyone to switch to a different app is a pipe-dream that will never happen, at least not thanks to the work of any particular person or company.
Apple is pretty good at privacy and security for people playing within their ecosystem. They seem rather indifferent to any attempts to communicate or interact with anybody without an Apple device. Better than nothing, but not great IMO. Google has many faults in many areas, but I think they're doing awesome work at a difficult and thankless job as far as developing a standard for modern and fully encrypted communications that is actually possible for everyone to switch to transparently, and dragging everyone kicking and screaming into actually using it. Apple just rolled out support for it in beta 4 months ago. Very likely in the next year or so, we may see the majority of texts and group-chats between Android and iOS be actually E2EE without the users needing to do anything besides ordinary OS updates. That will be IMO 80% Google's doing, and 20% Apple's.
Re: GrapheneOS Overhauled Default Apps and Secure Clipboard
#256Re: GrapheneOS Overhauled Default Apps and Secure Clipboard
#257Certainly, with Opus 5 and GPT-6, modernizing or even completely rewriting self-contained, non-critical tools seems like a Friday afternoon job now. I wonder however how important this is, in the grand scheme of things. I use GrapheneOS and the bundled messaging app is serviceable. It isn't pretty, but it gets the job done.
We're definitely not churning out code with AI models. There's no vibe coding going on in GrapheneOS. We're carefully writing and reviewing code as we've always done. We now have additional tools to assist with it. The main way we're using AI models is for code review and helping to write a lot more tests than we used to. It's helping to improve our code quality, not reducing it. We're not trying to get things done s…
Re: GrapheneOS Overhauled Default Apps and Secure Clipboard
#258> RCS isn't an open platform in practice. It isn't even as open as SMS/MMS. It heavily depends on proprietary Google and carrier infrastructure in practice. We can start by replicating Google's approach and then we can work on only using carrier services for carriers where it's actually supported. What is the point of RCS though? It seems to be strictly inferior to Signal. It seems a Google product meant to serve Goo…
Re: GrapheneOS Overhauled Default Apps and Secure Clipboard
#259Earlier quoted context omitted.
If you are referring to Heliboard as an AOSP board replacement, that cannot work, GrapheneOS cannot use GPLv3 projects. If you mean it as a user installed app, please disregard.
Could you please elaborate? I wouldn't think this causes an issue unless they need to link against it, which I don't think they do.