Live data from Hacker News

GrapheneOS fixes Android VPN leak Google refused to patch

cyberinsider.com

121–130 of 142 posts

Re: GrapheneOS fixes Android VPN leak Google refused to patch

#121

Earlier quoted context omitted.

And typically security is very bad, no good sandboxing, MAC (through e.g. SELinux), etc. I know that doesn't matter to everyone, but in the context of a discussion about GrapheneOS it does.

You’re going to struggle with that with most distros.

Indeed. Though in Europe is common for banking apps/auth, government ID apps, etc. to be phone-based, so they are the more interesting target.

Re: GrapheneOS fixes Android VPN leak Google refused to patch

#122
post #91

Earlier quoted context omitted.

I am patiently waiting for that one. I have been willing to move to GrapheneOS for a while, but I don't feel like buying Google hardware.

Fwiw the pixel phones are excellent hardware.

That's debatable. Pretty much every generation of the Pixel phones have had some major issues. They've even had to do multiple extended repair/replace programs due to some of them. Heck there is even an ongoing issue where one of their updates has caused multiple generations of their devices to be bricked (and that still hasn't been fixed) - https://www.androidauthority.com/google-pixel-march-update-b...

On a technical level, yea, it may be great hardware but in practice, I don't think it is. As an Android user, I wish it were but it's not. Samsung is so much more reliable as an end user (even with their own issues).

Re: GrapheneOS fixes Android VPN leak Google refused to patch

#123
post #91

Earlier quoted context omitted.

I am patiently waiting for that one. I have been willing to move to GrapheneOS for a while, but I don't feel like buying Google hardware.

Fwiw the pixel phones are excellent hardware.

They have consistently the worst battery endurance of any relevant phone maker since forever.

Re: GrapheneOS fixes Android VPN leak Google refused to patch

#124

Earlier quoted context omitted.

The truly independent solution is GNU/Linux. Sent from my Librem 5.

I don't think it's going to be a savior... the same things that make Android hard to modify can happen just as easily when GNU/Linux phones become popular.

How? Linux development is not steered by a monopolist acting to gain the maximal profit. It is distributed over many entities.

Re: GrapheneOS fixes Android VPN leak Google refused to patch

#125
post #111

Earlier quoted context omitted.

Your post sounds like you're trying to spread FUD. Librem says the Liberty phone is the same, it just costs more because it is assembled in the U.S. for people, companies, or governments that don't want it intercepted and modified by a bad actor.

This might justify the price of Liberty Phone, but doesn't invalidate my claim that these phones are low-end by todays standards. Why no hardware upgrade after 7 years?

You can't easily find vendors supporting free drivers: https://puri.sm/posts/breaking-ground/

Also this: https://puri.sm/posts/the-danger-of-focusing-on-specs/

Re: GrapheneOS fixes Android VPN leak Google refused to patch

#126
post #51

I bought a used Pixel 6 for cheap to try out grapheneos. Can't say I like it. UX of lineageos is much better. There is a weird russian doll kind of situation with the package managers going on. There is one builtin "App Store" with only a few basis programs, one of which is another package manager, accrescent, which offers a few more apps, but still not comprehensive at all, so another package manager is needed for w…

F droid is known to be highly insecure. It has many many bad practises that totally compromise security and they have proven to be woefully incompetent and ignorant to concepts as basic as the purpose of app signing. The all apps stemming from app stores in the builting App Store is to provide a minimalist experience by default whilst keeping google play apps accessible. GrapheneOS has a majour focus on accessibility…

F-Droid has arguably produced more value than GrapheneOS for open source community, independent ROM users, and android in general

Re: GrapheneOS fixes Android VPN leak Google refused to patch

#127

[flagged]

Project member here. > A distro with shady revenue sources (check for yourself) Do me a favor and tell me about our apparent shady revenue sources. We are run entirely by donations, there are large donors too. > with shady hardware restrictions that only permits to use spyware phones from google We cover this topic literally everywhere on a daily basis, with a thorough list of requirements found on our website. > aft…

For Motorola the management changed while government customers remained the same, perhaps now adding also the Chinese gov into the mix which certainly will "approve" the hardware within. You know this quite well.

I'd happily talk in detail about donors when you first make public the values and donor list for the bigger ones, which you don't for some shady reason and only reveal a few. Even from those few, your biggest public donor are the people well known to dodge real privacy in crypto faster than vampires dodging holy water. Please disclose how much money you pay to the blog/media to shill this project so frequently.

You won't do any of this. You know that, I know that, you know that I know that and still you will continue to profit on those who will never read these comments.

Re: GrapheneOS fixes Android VPN leak Google refused to patch

#128
post #51

I bought a used Pixel 6 for cheap to try out grapheneos. Can't say I like it. UX of lineageos is much better. There is a weird russian doll kind of situation with the package managers going on. There is one builtin "App Store" with only a few basis programs, one of which is another package manager, accrescent, which offers a few more apps, but still not comprehensive at all, so another package manager is needed for w…

First of all, I would like to state that just because a piece of software is free and open source, does not mean it is inherently more secure or private. "Open source" is merely just a licensing term. GrapheneOS has the "App Store" to get the most basic apps required for general usage. Accrescent is distributed there because it follows Android's security baseline for being an actual app repository while F-Droid and A…

I trust F-Droid. I don't trust millions of developers. I don't have time everytime I need an app to go investigate, especially now with quick LLM scam app developer

Developers are not geniuses at every aspect of security or app deployment. They can sell their projects. Get compromised. Or can get tricked like the xz exploit

Having an app store making any effort to prevent or correct problems, especially as transparent as F-Droid, is better

Wireguard app dev wanting to bypass the store and push an executable to your phone every day is ridiculous. No user of app/package manager expects it to be bypassed

Re: GrapheneOS fixes Android VPN leak Google refused to patch

#129

The technical detail that makes this egregious is that the leak happens in system_server, a privileged process. Android’s own lockdown mode explicitly promises that no traffic bypasses the VPN. When the system itself sends the packet over the physical interface, that promise is broken at the kernel level, not in userspace. Calling this “not security bulletin class” is hard to defend.

Thanks, Claude! Or perhaps Codex? Which type of AI spambot are you?

Re: GrapheneOS fixes Android VPN leak Google refused to patch

#130
post #55
post #51

I bought a used Pixel 6 for cheap to try out grapheneos. Can't say I like it. UX of lineageos is much better. There is a weird russian doll kind of situation with the package managers going on. There is one builtin "App Store" with only a few basis programs, one of which is another package manager, accrescent, which offers a few more apps, but still not comprehensive at all, so another package manager is needed for w…

> so another package manager is needed for which grapheneos people seem to favor obtainium over f-droid, which I find is another strange decision So just download f-droid yourself? Why the fixation on having a definitive, preloaded app store? >I much prefer a fully OSS package manager and there is real value in having people compile from the sources externally, maybe even reproducibly so, instead of trusting the gith…

> there's already f-droid, play store (plus aurora store), obtanium

Also Neo Store, Accrescent

Post reply on HN