Live data from Hacker News

Reclaiming Mobile Privacy with GrapheneOS

xn--gckvb8fzb.com

11–20 of 80 posts

Re: Reclaiming Mobile Privacy with GrapheneOS

#12
I had to switch back to iOS. My smartphone is my primary camera and I missed lots of important shots because the Graphene camera was so slow to double click launch from locked (on a flagship pixel $LATEST pro max whatever).

I really miss syncthing.

Re: Reclaiming Mobile Privacy with GrapheneOS

#16
post #7

I use CalyxOs without any Google Apps (camera app blocked via firewall). I find GrapheneOS horrible. If I want to get away from Google, I don't want to run Google Apps in the sandbox either

Well, than don’t? How does allowing the option making it terrible? Also, CalyxOS also support it in an objectively worse way (microG and basically not caring about signatures)

Be a tiny bit respectful at least.

Re: Reclaiming Mobile Privacy with GrapheneOS

#17

Quoted post unavailable.

The background story of the project is quite sad, so it sort of makes sense that he is very defensive of it. (The project got some monetary support initially from a company, which later tried to hijack the whole open-source project (going by copperhead os nowadays, I believe). Fortunately thanks to Micay the original was unharmed (he revoked private keys, big kudos!), but they do throw shade at GrapheneOS promoting their shady fork in many relevant threads)

Nonetheless, he is an excellent security researcher who has an excellent track record of prioritizing the security of his userbase, even if he may (more or less validly) be a bit overly defensive over it.

Re: Reclaiming Mobile Privacy with GrapheneOS

#18

I love GrapheneOS. Before trying it one should consider that unlike some "sister" projects, it does not support signature spoofing, so if you need SafetyNet or something similar, you will likely be out of luck. On one hand I like the no spoofing position the devs took, on the other hand my banking app.

They have a sandbox which can run google’s services. I read plenty of people saying that they could successfully run their banking app without spoofing.

Re: Reclaiming Mobile Privacy with GrapheneOS

#19

is microG still a viable solution for avoiding Gapps or is there something better now?

With GrapheneOS, specifically, it kind of defeats their design goals[0] -- so on Graphene I would say it is not a viable solution. On other custom ROMS such as CalyxOS (my go-to for my Pixels), or LineageOS, I have used microG and it works very well. [0] https://nitter.net/GrapheneOS/status/1437380576055541761

GrapheneOS instead went on to implement a whole sandbox which can run google services properly, without hacks like spoofing signatures (which is required for microG).

In practice, you can run most apps on GrapheneOS.

Re: Reclaiming Mobile Privacy with GrapheneOS

#20
post #7

I use CalyxOs without any Google Apps (camera app blocked via firewall). I find GrapheneOS horrible. If I want to get away from Google, I don't want to run Google Apps in the sandbox either

> camera app blocked via firewall

So you are using a Google app (Google Camera) in an objectively much weaker sandbox than the one provided by GrapheneOS. You're giving it shared storage access since it requires it and CalyxOS doesn't have features like https://grapheneos.org/features#storage-scopes. The whole point of sandboxed Google Play on GrapheneOS is that it runs in the full standard app sandbox. It has absolutely no special access or privileges. It's not different than running another app. Same sandbox, same permission model, and all the same GrapheneOS improvements to those including user-facing ones like Storage Scopes, Sensors permission toggle and the Network permission toggle which blocks more forms of access than a firewall-based approach.

Post reply on HN