Live data from Hacker News

Reclaiming Mobile Privacy with GrapheneOS

xn--gckvb8fzb.com

21–30 of 80 posts

Re: Reclaiming Mobile Privacy with GrapheneOS

#21
post #15
post #7

I use CalyxOs without any Google Apps (camera app blocked via firewall). I find GrapheneOS horrible. If I want to get away from Google, I don't want to run Google Apps in the sandbox either

Care to elaborate more on how you find GrapheneOS "terrible"?

They don't know much about it and haven't used it. CalyxOS isn't a hardened OS and isn't at all comparable to GrapheneOS. They recently didn't even ship half the baseline Android security patches for 2 months, let alone providing much better patching and substantially hardening the privacy and security of the OS. Unfortunately, they've chosen to promote it through inaccurate talking points about GrapheneOS and fabricated stories about our developers. They've heavily invested in this. You can see their developers doing it earlier today. You'll see it in every thread about GrapheneOS on this site from people promoting CalyxOS, which again, is a highly insecure non-hardened OS rolling back the Android security model substantially and not shipping full baseline Android patches on time. I don't understand why they come to pick this fight. GrapheneOS provides far better privacy, security and usability (much broader app compatibility).

Re: Reclaiming Mobile Privacy with GrapheneOS

#24

Quoted post unavailable.

Could you elaborate on what you consider personal attack? The bar is extremely low these days, and I have an experience of the opposite: One day I was inspecting the traffic from my GOS device with tcpdump, and I noticed lookups and traffic to the connectivity test servers going outside my VPN. I raised this in the IRC channel, and criticised the lack of option to turn them off or route them via the VPN on the basis that it leaked metadata. The main developer disagreed that it constituted a security issue. After considerable back and forth, I took it upon myself to implement the feature. Before I got round to it, I found it in the next update of GOS. GOS is the single most reliable android distro I have ever used by a considerable margin.

Re: Reclaiming Mobile Privacy with GrapheneOS

#25

I love GrapheneOS. Before trying it one should consider that unlike some "sister" projects, it does not support signature spoofing, so if you need SafetyNet or something similar, you will likely be out of luck. On one hand I like the no spoofing position the devs took, on the other hand my banking app.

I am able to run all banking apps from my 3 different banks that I use. Try it, you might be surprised.

Re: Reclaiming Mobile Privacy with GrapheneOS

#26
post #12

I had to switch back to iOS. My smartphone is my primary camera and I missed lots of important shots because the Graphene camera was so slow to double click launch from locked (on a flagship pixel $LATEST pro max whatever). I really miss syncthing.

You can just use any other camera app. I use the Google Camera on my Pixel 6.

Re: Reclaiming Mobile Privacy with GrapheneOS

#27

I love GrapheneOS. Before trying it one should consider that unlike some "sister" projects, it does not support signature spoofing, so if you need SafetyNet or something similar, you will likely be out of luck. On one hand I like the no spoofing position the devs took, on the other hand my banking app.

GrapheneOS has the sandboxed Google Play compatibility layer. Most banking apps work fine on GrapheneOS. Certain banking/financial services check for a Google certified OS via remote attestation. SafetyNet attestation is deprecated and being shut down and the Play Integrity API is the current way. Both of these support hardware-based attestation available on every device launched with Android 8 or later which cannot be spoofed.

You should read https://grapheneos.org/usage#banking-apps and https://grapheneos.org/articles/attestation-compatibility-gu.... GrapheneOS has full hardware-based attestation support and we use it ourselves in a much more secure way than this weak anti-fraud approach. The long-term solution is convincing major apps wanting to deploy this to allowlist GrapheneOS via hardware attestation.

We currently choose not to ship patches spoofing the traditional software-based SafetyNet attestation / Play Integrity API attestation. The reason for this is because we don't really want to ship a set of hacks which will stop working when they improve it and will permanently stop working when a service starts checking for strong verification. Having users start depending on Google Pay NFC payments working and then having it go away would be a problem for a production quality OS in a way that it wouldn't for a hobbyist project where expectations are different. We don't want to essentially commit to providing something we know is impossible to keep providing due to hardware attestation.

You can only spoof the weak basic verification, and whether it passed strong verification is always there in the result. It's only a matter of time before those services require it. It's based on when they're ready to start phasing out support for devices launched with Android 7.x and earlier along with a few phones that shipped with broken verified boot / attestation support even after it was required such as OnePlus. They can require it only for certain features if they want. Android 10+ is needed for security updates, so if they truly do care about security, nearly 100% of devices launched with Android 7.x and earlier are irrelevant now since only a small portion got upgraded to Android 10 (almost none beyond it) and those are now losing security support. Android 10 will be losing security support soon.

We may reconsider and ship spoofing for the legacy software-based attestation (known as non-strong verification by those APIs) if not shipping it becomes an adoption issue due to others shipping it. It doesn't mean we think it's a good idea but we'd rather have people using a more secure OS than a highly insecure one often without proper security patches and a fake patch level displayed...

Re: Reclaiming Mobile Privacy with GrapheneOS

#28
post #17

Quoted post unavailable.

The background story of the project is quite sad, so it sort of makes sense that he is very defensive of it. (The project got some monetary support initially from a company, which later tried to hijack the whole open-source project (going by copperhead os nowadays, I believe). Fortunately thanks to Micay the original was unharmed (he revoked private keys, big kudos!), but they do throw shade at GrapheneOS promoting t…

In my understanding, it's CalyxOS throwing shade, not Copperhead, although the whole situation is murky. In my estimation, there do seem to be comments devoid of substance disparaging GOS every time it is promoted somewher like HN.

Re: Reclaiming Mobile Privacy with GrapheneOS

#29
post #11

I've used GrapheneOS for a while now and have been impressed by it. I'd recommend it to all those who value privacy and security. Battery life is way better now as well.

Any comparisons to project /e/ or clyxOs?

GrapheneOS is a hardened OS. It not only preserves the whole standard privacy and security model including all the hardware-based security features but also substantially improves it. https://grapheneos.org/features provides an overview of only the improvements made by GrapheneOS compared to Android 13 (specifically, the stock Pixel OS). We make a fair number of upstream contributions and those aren't listed on our features page once they're shipped by the stock Pixel OS.

GrapheneOS provides our sandboxed Google Play compatibility layer allowing using the Google Play apps as regular apps in the full standard app sandbox with no special access or privileges. We've made them work like any other apps, with absolutely no ability to do something a regular user installed app can't do. You also don't need to grant them permissions to use 95% of functionality and can revoke our added Sensors toggle (Network COULD be revoked and you can use GSF + Google Camera + Google Photos with Network revoked from each but most of Play services exists to provide Google services so it would somewhat defeat the purpose, but it's possible).

Re: Reclaiming Mobile Privacy with GrapheneOS

#30
post #11

I've used GrapheneOS for a while now and have been impressed by it. I'd recommend it to all those who value privacy and security. Battery life is way better now as well.

Any comparisons to project /e/ or clyxOs?

/e/ supports loads of random phones without a strong HSM. In my estimation this means it will be much easier to get into a locked phone with physical access. I imagine the phone would get imaged, and then the passcode bruteforced on another machine without rate limiting.

Calyx supports Pixel3 and Fairphone, but otherwise looks pretty similar. According to GOS's main developer's comments in this thread, Calyx:

- doesn't have features like https://grapheneos.org/features#storage-scopes.

- doesn't have the Play sandbox

- "isn't a hardened OS and isn't at all comparable to GrapheneOS. They recently didn't even ship half the baseline Android security patches for 2 months, let alone providing much better patching and substantially hardening the privacy and security of the OS"

My opinion is biased since I'm a GOS user, and I have a very positive opinion of the project, so take this with a pinch of salt.

Post reply on HN