Live data from Hacker News

GrapheneOS fixes Android VPN leak Google refused to patch

cyberinsider.com

131–140 of 142 posts

Re: GrapheneOS fixes Android VPN leak Google refused to patch

#131
post #39

Side question: what's a good way of getting a GrapheneOS phone? I have been interested in using GrapheneOS but hesitant about actually getting a Pixel phone. Used phone prices are usually >$300 even for "a" series unless I go back several generations. Whether the device bootloader can be unlocked is also a question. I am definitely not ready to spend $449 on a new Pixel 10a.

Upcoming Amazon Prime Day?

https://www.zdnet.com/article/my-sleeper-phone-deal-for-prim...

Re: GrapheneOS fixes Android VPN leak Google refused to patch

#132
post #51

I bought a used Pixel 6 for cheap to try out grapheneos. Can't say I like it. UX of lineageos is much better. There is a weird russian doll kind of situation with the package managers going on. There is one builtin "App Store" with only a few basis programs, one of which is another package manager, accrescent, which offers a few more apps, but still not comprehensive at all, so another package manager is needed for w…

First of all, I would like to state that just because a piece of software is free and open source, does not mean it is inherently more secure or private. "Open source" is merely just a licensing term. GrapheneOS has the "App Store" to get the most basic apps required for general usage. Accrescent is distributed there because it follows Android's security baseline for being an actual app repository while F-Droid and A…

Please study the https://en.wikipedia.org/wiki/XZ_Utils_backdoor That is the supply chain attack I know and it was discovered in debian with their outdated build system. Your arguments, which copy exactly those of the "grapheneos people", seem ignorant and arrogant to me. F-droid people are doing a lot of work for free, I think they deserve more respect than you give them.

Re: GrapheneOS fixes Android VPN leak Google refused to patch

#133
post #15

Earlier quoted context omitted.

> Now if home assistant could get thread network join*ng working without an android phone with a google account There is already a way to do this. It's fiddly, but not by much. Once set up it's a much better experience, though. https://www.matteralpha.com/how-to/how-to-use-home-assistant...

It needs to work theough bluetooth proxy and be a button click, not massive pain like the articlec

Yeah requires a free Bluetooth radio and has a bit of setup, but in my opinion, it's well worth it to not be reliant on Android or iPhone, which has always given me problems.

Re: GrapheneOS fixes Android VPN leak Google refused to patch

#134

Earlier quoted context omitted.

I don't think it's going to be a savior... the same things that make Android hard to modify can happen just as easily when GNU/Linux phones become popular.

How? Linux development is not steered by a monopolist acting to gain the maximal profit. It is distributed over many entities.

Well one way would be just like how Android phone manufacturers are doing it now... with locked bootloaders and binary blobs. Even current GNU/Linux phones still largely need blobs to work properly.

Re: GrapheneOS fixes Android VPN leak Google refused to patch

#135

Earlier quoted context omitted.

How? Linux development is not steered by a monopolist acting to gain the maximal profit. It is distributed over many entities.

Well one way would be just like how Android phone manufacturers are doing it now... with locked bootloaders and binary blobs. Even current GNU/Linux phones still largely need blobs to work properly.

This is misleading. The blobs are only in the firmware, not in the OS, not in the bootloader, not running on the CPU.

Having a technical possibility to lock down GNU/Linux phones in principle in undefined future by undefined entity that doesn't even produce them yet is a FUD argument.

Re: GrapheneOS fixes Android VPN leak Google refused to patch

#136

Earlier quoted context omitted.

Well one way would be just like how Android phone manufacturers are doing it now... with locked bootloaders and binary blobs. Even current GNU/Linux phones still largely need blobs to work properly.

This is misleading. The blobs are only in the firmware, not in the OS, not in the bootloader, not running on the CPU. Having a technical possibility to lock down GNU/Linux phones in principle in undefined future by undefined entity that doesn't even produce them yet is a FUD argument.

Not true, current GNU/Linux have OS-level blobs

Re: GrapheneOS fixes Android VPN leak Google refused to patch

#137

Earlier quoted context omitted.

This is misleading. The blobs are only in the firmware, not in the OS, not in the bootloader, not running on the CPU. Having a technical possibility to lock down GNU/Linux phones in principle in undefined future by undefined entity that doesn't even produce them yet is a FUD argument.

Not true, current GNU/Linux have OS-level blobs

PureOS running on my phone is endorsed by the FSF, i.e., has no blobs whatsoever: https://news.ycombinator.com/item?id=25504641

Re: GrapheneOS fixes Android VPN leak Google refused to patch

#138
post #104
post #92

Earlier quoted context omitted.

It can be done, fairphone rather famously did it once. But it is vastly uneconomical, and I doubt anyone is going to start doing it regularly. We really need some kind of regulation demanding firmware support for longer. The EU seems the most likely entity to achieve something like that. Phone vendors can't even control how long they support their own hardware, because the SoC is almost always Qualcomm, and once they…

> It can be done, fairphone rather famously did it once. No, they ported a new major Android release beyond what the SoC officially supported. They had already stopped providing firmware, kernel or driver security patches long before that point. They did what LineageOS regularly does by porting a new major Android release to hardware not officially supporting it. Unlike LineageOS, they had to convince a company to ce…

Thanks for the detailed response.

Re: GrapheneOS fixes Android VPN leak Google refused to patch

#139
post #87

Earlier quoted context omitted.

Ios does the same, only way around it is if you have an ?enterprise? licence (250+ devices) Mullvad and others reported on that one ages ago

a VPN enabled wifi router would suffice as a fallback tho right?

You could get one of those hotspots https://www.gl-inet.com/products/gl-mifi/

Haven't bought one (yet - but did quite a bit of research but again outdated by 2 years...)

Re: GrapheneOS fixes Android VPN leak Google refused to patch

#140
post #37

Earlier quoted context omitted.

Ios does the same, only way around it is if you have an ?enterprise? licence (250+ devices) Mullvad and others reported on that one ages ago

Is this really true? The Mullvad report a year or so ago was that they didn’t want to turn on no exceptions mode because it breaks network connectivity until reboot if you don’t pause it when updating the app, not that the feature doesn’t exist. They also recently shipped it anyway, opt in and behind a warning.

As a quick chatgpt check and following the links to apple's own site that still seems to be the case...

Force “most” traffic through VPN using includeAllNetworks Yes, but imperfect (normal) Yes (supervision)

stronger controls are tied to device management / supervision, usually for organization-owned devices.

https://developer.apple.com/documentation/NetworkExtension/N...

Post reply on HN