Live data from Hacker News

F-Droid version of KDEConnect uninstalled by PlayProtect

discuss.kde.org

171–180 of 192 posts

Re: F-Droid version of KDEConnect uninstalled by PlayProtect

#171

Earlier quoted context omitted.

The only acceptable phone for me has been a Pixel phone, with GrapheneOS installed. I do wish the permission to install/uninstall were separated for something like this (I may be naive). I have everything installed to a work profile in Android (using the Shelter app). I can globally pause all work-profile apps. It's not the best, because when unpaused I'm not getting some notifications. I need to figure that out.

Graphene is not acceptable either, since it requires putting trust in someone who does not exibit enough stability or rationality to justify that kind of trust. I mean it's only the keys to your whole life, no big.

I'm curious about the "trust" discussion that keeps being brought up here. What does GrapheneOS do differently from say, Debian GNU/Linux or Fedora?

It seems to me that it's no different than running a non-Microsoft/Apple operating system on desktop.

Re: F-Droid version of KDEConnect uninstalled by PlayProtect

#172
post #2

One way to be a little less constantly violated by your phone is to run GrapheneOS, instead of iOS or ordinary Android: https://grapheneos.org/

Sadly device attestation has all but destroyed installing other OS. I couldn't use government or banking apps back in my old phone with LineageOS.

You can run all of these apps with GrapheneOS, in that regard it's very different than LineageOS because it has a compatibility layer as a first class feature [0]. You can either create a different user profile and install the play services there or create a work profile (with shelter) and install google services there. I keep my banking apps in a work profile and shelter completely freezes/disables them when I'm not using them. Otherwise they work fine. I do want to note that I'm fine with only using apps from F-Droid in my main profile. I mostly use NewPipe, FairEmail, KeePass and Harmonic (HN client) and that's about it. I don't tend to create accounts on websites but if you use social media this setup will probably not be the most compatible. It's honestly mind blowing though. I've never ran a custom ROM with such a "vanilla" experience, even getting OTA updates within a week of them being out for Android.

[0]: https://grapheneos.org/faq#google-services

Re: F-Droid version of KDEConnect uninstalled by PlayProtect

#173

Earlier quoted context omitted.

https://news.ycombinator.com/item?id=37880628

It’s still the best of all worlds for many people, a great intersection of privacy tool availability and general app usability.

I do not dispute that. If you have to run random untrusted apps, grapheneOS is more suitable. But it's not a long-term solution.

Re: F-Droid version of KDEConnect uninstalled by PlayProtect

#174

Earlier quoted context omitted.

I doubt grapheneOS requires much less effort to daily drive than others. Sent from my Librem 5.

In the past year, I have used a pinephone+keyboard with Arch, a oneplus 6t with postmarketOS, and a pixel 7a with GrapheneOS. In my opinion, Graphene is significantly easier to daily drive because the applications are designed for a phone's form factor.

Could you share which Pinephone apps you needed that aren't designed for a phone's form factor?

Re: F-Droid version of KDEConnect uninstalled by PlayProtect

#175

Earlier quoted context omitted.

> a throw away gmail account you don't care about losing with the aurora store They also have a pool of accounts you can use by clicking “anonymous”. They do get banned frequently, and you have to re-login once in a while (for me it's almost every time I want to download something new again), but it is definitely usable.

It's a lot less usable lately because of the "Oops this account is rate limited" error unfortunately. Sometimes it takes me 10 tries. Updates are fine though, it's just searching for new apps that trigger it.

Yeah, I thought search was completely broken tbh. Usually I search in browser then use “Open in app” to open in Aurora and download.

Maybe they can add some web scraping thing to sidestep this issue completely?

Re: F-Droid version of KDEConnect uninstalled by PlayProtect

#176

Earlier quoted context omitted.

LineageOS is supported on a bit more devices, and works with microG if you're willing to sacrifice Google Pay for better battery life and less privacy violations: https://lineage.microg.org/

Yeah I love MicroG. But I really wish there was a big-tech-free payment solution :(

Yeah. It's either that or state-supported systems (UPS in India, SBP and MirPay in Russia). Cryptocurrencies could be the answer but governments would never let that happen I think.

Re: F-Droid version of KDEConnect uninstalled by PlayProtect

#177
post #51

Earlier quoted context omitted.

Interesting, can I still use the Play Store with mircoG? I already run LineageOS, but with Play services. I would like to be able to ditch Play services, but still need the Play store for things like my banking app, and an app to log in to government services.

You can install apps from Play Store with Aurora Store, which is in F-Droid. I'd say it's a toss up whether specific apps will definitely work. But if they don't I'd recommending segmenting between different physical devices, and making the one that lives in your pocket as secure as possible. It's likely that you don't need to run banking and government apps on the same device that's privy to your movement.

I've heard something about using Play Store proper with microG, but obviously that's very flaky. Aurora Store is the way to go.

And banking / government apps tend to work in Europe (at least the ones I have tried). Notable exceptions for me are Revolut (shame!) and McDonalds (who knew microG is the healthier option haha). Of course, in the US things might be vastly different.

Re: F-Droid version of KDEConnect uninstalled by PlayProtect

#178

Earlier quoted context omitted.

I use GrapheneOS daily and use banking, government, and other sensitive apps without problem. It's a common myth that you can't use those apps on GrapheneOS.

It's not a myth. I run GrapheneOS, and my bank app doesn't work, the Blind app doesn't work, and another common marketplace app (not amazon) has shadow banned me for using it on a device without hardware attestation. I only found out after reaching out to support and having a lengthy conversation with them. It's idiotic that they require hardware attestation, but let's not fall into the trap of "it worked for me". Ev…

Fair enough, but on the flipside I wanted to point out that for at least some of us it's possible to use GrapheneOS with no compromises to the experience. Usually you only hear about those telling you categorically that you "can't" use banking, government and other sensitive apps when that's not true. Anyone on the fence should try it out themselves.

Re: F-Droid version of KDEConnect uninstalled by PlayProtect

#179
post #163

Earlier quoted context omitted.

Last I checked, GrapheneOS is open source. Don't trust. Verify.

Why? There are other equally open source os's I can just run instead, that don't require me to excuse or verify anything? Even if there were something special about graphene that made it more desirable, the real way to deal with an open source project with something unacceptable about it's production or management, is to fork it. But I already have something else to do all day, and am happy to run lineage or calyx or…

The point is, you don't have to trust Micay about a darn thing. The code is open. That's the whole point. Dismissing open source software because you don't trust the developer is absurd.

Re: F-Droid version of KDEConnect uninstalled by PlayProtect

#180

Earlier quoted context omitted.

Device attestation works for banking applications on GrapheneOS. The only thing which doesn't work is google wallet because they explcitly expect a Google signed operating system.

That's probably what those apps use, then. Because all those tricks people mentioned never worked. Some explicitly failed saying that my ROM signature wasn't official.

Have you actually tried using your banking application on a recent (post introduction of sandboxed Google Play) GrapheneOS?

Restricting things to only Google ROMs basically also means your banking app won't work on a bunch of non-google Android phones and even most banks don't want to go that far.

Post reply on HN