Live data from Hacker News

F-Droid version of KDEConnect uninstalled by PlayProtect

discuss.kde.org

11–20 of 192 posts

Re: F-Droid version of KDEConnect uninstalled by PlayProtect

#11
post #9

Earlier quoted context omitted.

No I'm not. Does that mean I might as well cc the NSA to all my emails? Your comment is basically "is it perfect? No? Then it's not better".

I’m saying that, if people who use it aren’t careful, they could end up like the university kid. There was a university that received a bomb threat over Tor. They found one student who used Tor on the network at around the right time, and because he was the only Tor user, he’s in jail for a very, very long time. That kid was at Harvard, his persuer the FBI. If you are going to use GrapheneOS, don’t be naive and think…

Ah, yes, you're right. It's good to use, but it's not perfect.

Re: F-Droid version of KDEConnect uninstalled by PlayProtect

#12
post #9

Earlier quoted context omitted.

No I'm not. Does that mean I might as well cc the NSA to all my emails? Your comment is basically "is it perfect? No? Then it's not better".

I’m saying that, if people who use it aren’t careful, they could end up like the university kid. There was a university that received a bomb threat over Tor. They found one student who used Tor on the network at around the right time, and because he was the only Tor user, he’s in jail for a very, very long time. That kid was at Harvard, his persuer the FBI. If you are going to use GrapheneOS, don’t be naive and think…

Why are you under the impression that since I want to use a more secure OS than Android or the equivocating Apple that I must be wanting to bomb a university?

Please.

Re: F-Droid version of KDEConnect uninstalled by PlayProtect

#13
post #12

Earlier quoted context omitted.

I’m saying that, if people who use it aren’t careful, they could end up like the university kid. There was a university that received a bomb threat over Tor. They found one student who used Tor on the network at around the right time, and because he was the only Tor user, he’s in jail for a very, very long time. That kid was at Harvard, his persuer the FBI. If you are going to use GrapheneOS, don’t be naive and think…

Why are you under the impression that since I want to use a more secure OS than Android or the equivocating Apple that I must be wanting to bomb a university? Please.

Absolutely not. But if anything bad happens, or you are attending a protest and suddenly getting investigated for rioting, you might have second thoughts.

I do not condone or endorse illegal activity. That does not mean your use of GrapheneOS might not be used against you if you use it at an inopportune time. There is currently almost no discussion online about this, so it’s worth a mention.

Edit: I forgot to mention some obvious context in my head. Think journalist, in Russia, using GrapheneOS for “safety.” In such a situation, probably a terrible idea.

Re: F-Droid version of KDEConnect uninstalled by PlayProtect

#14
post #6

Earlier quoted context omitted.

You make a convincing argument. I'm switching to GrapheneOS for my next phone upgrade. Here is the source code: https://grapheneos.org/source > “he used GrapheneOS” is 100% going to be used against you in court. I look forward to using this as a litmus test for legal representation.

Are you personally capable of ensuring: A. The builds match the code? B. The NSA hasn’t stolen the signing key and isn’t feeding you customized images? True, you can’t verify that with iOS or Android either. I am saying though that trusting my security because it’s safer… by being in some guy’s garage feels like an odd trade. One that shouldn’t be casually ignored, at least.

> by being in some guy’s garage feels like an odd trade. One that shouldn’t be casually ignored, at least.

Let's give some credit to Daniel Micay and assume he isn't coding this by himself, especially after the CopperheadOS debacle.[0]

[0] https://grapheneos.org/history/

Re: F-Droid version of KDEConnect uninstalled by PlayProtect

#15
post #12

Earlier quoted context omitted.

Why are you under the impression that since I want to use a more secure OS than Android or the equivocating Apple that I must be wanting to bomb a university? Please.

Absolutely not. But if anything bad happens, or you are attending a protest and suddenly getting investigated for rioting, you might have second thoughts. I do not condone or endorse illegal activity. That does not mean your use of GrapheneOS might not be used against you if you use it at an inopportune time. There is currently almost no discussion online about this, so it’s worth a mention. Edit: I forgot to mention…

> There is currently almost no discussion online about this, so it’s worth a mention.

A mention, not a core argument against use.

In my reading, your core point is an old argument: https://en.wikipedia.org/wiki/Nothing_to_hide_argument

Re: F-Droid version of KDEConnect uninstalled by PlayProtect

#16
post #14

Earlier quoted context omitted.

Are you personally capable of ensuring: A. The builds match the code? B. The NSA hasn’t stolen the signing key and isn’t feeding you customized images? True, you can’t verify that with iOS or Android either. I am saying though that trusting my security because it’s safer… by being in some guy’s garage feels like an odd trade. One that shouldn’t be casually ignored, at least.

> by being in some guy’s garage feels like an odd trade. One that shouldn’t be casually ignored, at least. Let's give some credit to Daniel Micay and assume he isn't coding this by himself, especially after the CopperheadOS debacle.[0] [0] https://grapheneos.org/history/

It doesn’t matter who is coding it, it matters who owns the signing key that will make your phone recognize the authenticity of the software. And, of course, if anyone else has it.

Also Daniel Micay no longer works on the project.

Re: F-Droid version of KDEConnect uninstalled by PlayProtect

#17

Earlier quoted context omitted.

They only seem to support pixel, although pixels can be bought for cheap when compared to iphones, they're still expensive for countries which are still developing. For example Im using a device which is 1/4th the price of cheapest first hand pixel that I can get :(

LineageOS is supported on a bit more devices, and works with microG if you're willing to sacrifice Google Pay for better battery life and less privacy violations: https://lineage.microg.org/

This worked ok, but wasn't as nice as grapheneos' solution so I ended up upgrading to a pixel once my cheap chinesium phone was sufficiently old and haven't looked back since. If you do the microg route you should be using a throw away gmail account you don't care about losing with the aurora store (if you need access to the google play store) because there is a non zero chance they ban your account.

Re: F-Droid version of KDEConnect uninstalled by PlayProtect

#18
post #2

One way to be a little less constantly violated by your phone is to run GrapheneOS, instead of iOS or ordinary Android: https://grapheneos.org/

… as long as you trust the developers, and their ability to secure themselves, of course. I mean, if I was a three letter agency, sneaking into some GrapheneOS developer’s basement to add a camera to record his keystrokes would be the easiest trade ever for all the paranoid people using it. It’d be way easier than sneaking into Apple or Google. Might even be worth violating internal law to do it; because getting caug…

> “he used GrapheneOS” is 100% going to be used against you in court.

Has that ever happened?

I hadn't heard of that, and people have been running GrapheneOS (and Copperhead before it) for many years.

The first person I knew using it was a lawyer at Harvard Law School.

Re: F-Droid version of KDEConnect uninstalled by PlayProtect

#19
post #14

Earlier quoted context omitted.

> by being in some guy’s garage feels like an odd trade. One that shouldn’t be casually ignored, at least. Let's give some credit to Daniel Micay and assume he isn't coding this by himself, especially after the CopperheadOS debacle.[0] [0] https://grapheneos.org/history/

It doesn’t matter who is coding it, it matters who owns the signing key that will make your phone recognize the authenticity of the software. And, of course, if anyone else has it. Also Daniel Micay no longer works on the project.

>Also Daniel Micay no longer works on the project.

This isn't true. He stepped down as lead dev. Still one of the main contributors

Post reply on HN