Live data from Hacker News

Review: Copperhead OS

adventuresinoss.com

121–130 of 162 posts

Re: Review: Copperhead OS

#121
post #46

I think there are some misconceptions in this thread (due to the title). Personally I use CopperheadOS as my daily driver because it stays continually ahead of Google (and groups like AOKP, LineageOS etc) in terms of Android hardening. It goes well beyond just not having Google Play services. See their details on their approach and design: https://copperhead.co/android/docs/technical_overview They make continued patc…

Your otherwise good comment probably should include two things that are critical to Google's stance on Android security: 1. They're a surveillance company that has more actual and potential earnings the more they know about their customers. They get good margins when their customers lack privacy with devices locked into Google by default. 2. They don't care about users' safety since make billions off Android platform…

I'm not sure i follow, you can upstream any security feature to AOSP, CopperheadOS dev has upstreamed lots of stuff to improve security overall which is good. Google can do whatever they want but most of it is happening in house sadly, they could probably pay grsecurity devs to implement security features for Android & ChromeOS if they wanted to.

Re: Review: Copperhead OS

#122
post #117

Earlier quoted context omitted.

Your otherwise good comment probably should include two things that are critical to Google's stance on Android security: 1. They're a surveillance company that has more actual and potential earnings the more they know about their customers. They get good margins when their customers lack privacy with devices locked into Google by default. 2. They don't care about users' safety since make billions off Android platform…

Can you explain how 2.) follows from 1.) ? Or at least how exactly has Google incentive to keep Android insecure (especially in terms of all the security research/hardening being done by internal teams, both for Android and iOS)?

They're seperate. Bad security follows from both. For one, too little privacy is profitable for a company selling or matching against profiles obtained from surveilling their users' activities. On 2, redoing Android security or just handling it better would cost more for Google even though the problems are externalities: they cost the users, not Google. For-profit, public comoanies ignore externalities as much as possible to maximize profit.

So, Google securing Android would cost them a lot of money for fixing the customers' problems that dont affect Google. Then, it might cost them piles of money later in lost ad revenue when now-private services make customers black boxes of sorts.

I think there's a lot of middle ground to explore but surveillance or public companies don't usually go for it. Offering a paid, surveillance-off version of each ad service is one of those. You will rarely see that as simple as it is to do.

Re: Review: Copperhead OS

#123
post #121

Earlier quoted context omitted.

Your otherwise good comment probably should include two things that are critical to Google's stance on Android security: 1. They're a surveillance company that has more actual and potential earnings the more they know about their customers. They get good margins when their customers lack privacy with devices locked into Google by default. 2. They don't care about users' safety since make billions off Android platform…

I'm not sure i follow, you can upstream any security feature to AOSP, CopperheadOS dev has upstreamed lots of stuff to improve security overall which is good. Google can do whatever they want but most of it is happening in house sadly, they could probably pay grsecurity devs to implement security features for Android & ChromeOS if they wanted to.

That last part is exactly my point. They're making billions on Android but will barely patch it. They just dont care at all since the money will go into their pockets anyway. Instead, all these small players have to show up working nearly for free swimming upstream with their enhancements making almost nothing.

Re: Review: Copperhead OS

#124

Earlier quoted context omitted.

These only fail because there is extra unused noop functionality in AOSP that CTS complains about (a bug in AOSP), not because Google services are required to pass CTS.

The point was that AOSP isn't a perfect base, because the Android team obviously don't care enough to actually test it, not that Google services are required.

That makes your first comment completely irrelevant with respect to its parent. It's also a stretch to say that you need to do anything to make AOSP work as it should simply because it contains extra noop APIs.

Re: Review: Copperhead OS

#125

YalpStore [1,2] makes getting Play Store apps a lot less painful than going through the process of extracting an APK from one phone and side loading it onto another. There are some that simply won't / don't work without Google Play Services, but most do. This made switching to Copperhead OS much easier for me. [1] https://github.com/yeriomin/YalpStore [2] https://f-droid.org/packages/com.github.yeriomin.yalpstore/

And if something doesn't work without Google Play Services, it might work with microG instead.

Re: Review: Copperhead OS

#126

Earlier quoted context omitted.

I use that but it's all Google based. Not sure if you can decouple it from Play Services without breaking everything.

By default, LineageOS does NOT include google play services. And it works just fine if you don't expect to use apps which "require" google play services.

And if you expect to use them, try microG - the free software reimplementation of Google Play Services.

Re: Review: Copperhead OS

#127
post #121

Earlier quoted context omitted.

I'm not sure i follow, you can upstream any security feature to AOSP, CopperheadOS dev has upstreamed lots of stuff to improve security overall which is good. Google can do whatever they want but most of it is happening in house sadly, they could probably pay grsecurity devs to implement security features for Android & ChromeOS if they wanted to.

That last part is exactly my point. They're making billions on Android but will barely patch it. They just dont care at all since the money will go into their pockets anyway. Instead, all these small players have to show up working nearly for free swimming upstream with their enhancements making almost nothing.

Well it's already pretty hard to exploit Android, the kernel is the weak point at the moment. I've studied the grsecurity code a lot and if you can exploit that stuff you can get high paying jobs for either red team or blue ;) Making it harder and driving up the cost to use/write exploits and ofcourse making everyone more secure is the end goal for the sec team :D

Re: Review: Copperhead OS

#128
post #119
post #94

Earlier quoted context omitted.

Copperhead uses Grsecurity, and I used to use Grsecurity, when it was widely available, now that it's not and the developer has decided to act in hostile ways to the Linux community(1), it's made me rethink using his work and/or supporting him. Plenty of consultants make do fine without resorting to closing off their source code, and decide to act better with the community and/or companies. (1) https://www.theregiste…

CopperheadOS doesn't use grsecurity anymore afaik. https://twitter.com/CopperheadOS/status/933684025624993792

Thanks for the link. Happy to hear they're maintaining Linux-hardened themselves.

Re: Review: Copperhead OS

#129
post #59

Earlier quoted context omitted.

Yes please! I understand you can disable the notifications in Maps settings, but that likely doesn't disable the constant location tracking. Does anyone know how to disable this?

Created an account to share this, as it seems not many people know... You can use an AOSP such as lineage, or carbon. There are quite a few options. Then, use fdroid and a play store alternative. You DO NOT need the google play services, such as microgapps, or opengapps. Even to use Google Maps! I use google maps by downloading maps anonymously with the Yalp store, and then I don't sign in. I don't have the so called…

Well, Fdroid is great and with the automatic upgrade extension (totally optional) really easy to use. But using an Android without access to the Play Store is just kinda weird.

So yes, you can remove Google completely from your smartphone, but then many things are getting much more complicated. So I don't want to remove Google completely from my phone. I just want to have easy options to turn things off I do not like.

I just wish Google would respect their users wishes a little more and would keep developing their services in a direction which would embrace community contributions to the eco system.

Re: Review: Copperhead OS

#130
I'm overall quite pleased with my Copperhead phone, and very much appreciate getting actual OS updates.

I have one issue however that I thought I'd put out there from a customer service standpoint. If you buy a phone from them, you pay what seems to me like a nice premium (Pixel XL $1,269.00; though it's hard to find a good comparison point), and it comes with a service plan. Copperhead (as I understand) takes stock AOSP and (among other things) swaps out some of the default applications. Notably, the SMS application is something called Silence (silence.im).

Here's the issue. I've had a problem or two with Silence, and I contacted their customer support. They suggested trying other SMS apps to see if that solved my problem, which is in itself fine. However, at that point they closed the issue, because they claim that they're not responsible for 3rd party apps, even ones that they bundle and (I presume) update with system upgrades. The reason given is that they don't control the source for those, unlike the OS. I don't accept this at all. I paid a good premium (unless I'm mistaken) for the phone, I expect a _working phone_. This, these days, includes a functioning SMS client. How they go about making that happen is _their_ responsibility. They can work with me to find a suitable replacement, they can submit a pull request or a bug report, etc. But I argue they should consider the issue open until it's fixed or I decide it doesn't matter.

Anyway, not a big deal, I worked around it. Perhaps if I pressed enough they would have been okay with me returning the thing on these grounds, but it's nowhere near worth it. I just disagree with their philosophy on this issue. I understand it must be _really_ hard to deal with all this as such a small operation. But then they should put this point in big bold letters when you buy it, or something. ¯\_(ツ)_/¯

Post reply on HN