Live data from Hacker News

GrapheneOS is the only Android OS providing full security patches

grapheneos.social

291–300 of 467 posts

Re: GrapheneOS is the only Android OS providing full security patches

#291
post #278

Earlier quoted context omitted.

Signal can be used without a phone using signal-cli. You can sign up with it and either attach your account to signal-desktop or keep using signal-cli

"You don't need a smartphone, you can just carry a laptop with you" :-)

You don't have to be available on instant messaging 24/7.

It is a convenience or inconvenience you decides to have or not.

Re: GrapheneOS is the only Android OS providing full security patches

#292
post #248

Earlier quoted context omitted.

Has no one mentioned not using a smartphone as an option?

It's not really an option. Beside various communication tools, many many banks require you to have a smartphone as their 2FA option.

They don't publicize it because they'd rather sell all the data they don't have already through your payments and bank movements but many still send you a dedicated device if you mention you don't have a smartphone.

Re: GrapheneOS is the only Android OS providing full security patches

#293
post #260

Earlier quoted context omitted.

It does on Intel, AMD and a bunch of other huge corps though

Which is not the same as one single, hostile corp.

I do agree that each company's influence in case of the kernel is much lower, than Google's relevance in Android, but there are other big-ish players in the space as well, like Samsung.

Re: GrapheneOS is the only Android OS providing full security patches

#294

[flagged]

Hacker News Guidelines [1]: > Please don't post insinuations about astroturfing, shilling, brigading, foreign agents, and the like. It degrades discussion and is usually mistaken. If you're worried about abuse, email hn@ycombinator.com and we'll look at the data. > Please don't comment about the voting on comments. It never does any good, and it makes boring reading. [1] https://news.ycombinator.com/newsguidelines.ht…

I won't be silent to the obvious honeypotting and mob tactics to silence people around here.

Re: GrapheneOS is the only Android OS providing full security patches

#295

Earlier quoted context omitted.

I wonder if a real OEM supports graphene if that would solve device attestation for things like banking apps.

Non-Google attestation is still a bad thing. I'd much rather GrapheneOS continue to get popular enough that banking apps are forced to support phones without attestation.

Will never happen. Banks will not support this unless insurance companies include that. And that will never happen because they will never support something that a large company doesn't committ to.

Re: GrapheneOS is the only Android OS providing full security patches

#296
post #12

Earlier quoted context omitted.

They have different goals: GrapheneOS wants to make a FOSS Android with the security model that makes it hard for any bad party to break into the phone. LineageOS wants to make a FOSS Android that respects user's privacy first and foremost - it implements security as best as it can but the level of security protections differs on different supported devices. Good news is that if you have a boot passphrase, it's secur…

How can LOS's security be somewhat close to GOS if it's worse than OEM? LOS lacks verified boot, hardware security features, it's often behind is security patches.. With "advanced protection" enabled stock OEMs are even more secure, but GOS is even more secure still. When it comes to EOL devices, LOS may be more secure than OEM depending on your threat model. https://eylenburg.github.io/android_comparison.htm

It very much depends on your personal threat model, if you expect targeted attacks LOS doesn't hold a candle to GOS, but at least for my threat model verified boot and hardware security features outside of my control don't have a substantial security benefit.

Obviously it would be preferable to have up to date security patches, but as long as there are plenty oven even more easily exploitable devices, and there is no WannaCry level attack ongoing it is a risk I'm willing to accept for more user freedom.

Re: GrapheneOS is the only Android OS providing full security patches

#297
post #73

Earlier quoted context omitted.

Nobody gave you the actual answer. IBM was under an antitrust decree and had to openly license their technology for a nominal fee. (Supposedly about $5/PC.) So yes, they were in a hurry and used generic parts, but they still had tons of patents on it. When they got out from under this, they came up with Microchannel.

I guess antitrust is the keyword here. Something that is considerably weakened in today's USA.

I continue to be of the opinion that many of our economic problems could be improved with more competition. (Depending on your definition of "problem" of course. The current state of affairs is fantastically profitable some.)

Re: GrapheneOS is the only Android OS providing full security patches

#298

Earlier quoted context omitted.

Now that their market is established, I don't think open-source is a requirement anymore. They would of course share with hardware vendors strategically.

True. All the big OEMs are in too deep with Android now, there's no going back. They could easily make it code share under NDA instead of open source.

Those OEMs are responsible for the Android lock-in situation, and they do profit off it. They have the power to break that dependency easily with any alternative platform of choice.

Consider a GNU flavored Linux distro (includes busybox+musl also) or a BSD as an example. The difficulty that their devs face on smartphones is the driver set. Everything above it is open and free for anyone to implement any functionality without the need for any reverse engineering. All that the OEMs need to make them work is to release the hardware drivers for the platform - especially of the RF baseband. Open source drivers are preferable, but even proprietary driver blobs work to some extend (like the nvidia proprietary drivers on PCs).

But if the OEMs do that, then people would do a lot more with their smartphones. No more OEM blot/malware, infinite customizability and app options and the biggest of all - endless updates. People would use them till something in it dies, and then use it for something else that doesn't need the dead part. For example, how many smartphones are thrown out because their screens died? How many kubernetes clusters could you build with them? Naturally, that would affect the phone sales and OEMs certainly don't want that.

So then, what happens instead? Have you noticed how Graphene and Lineage struggle to support devices that already run Android? Obviously the drivers for AOSP exist. Google and the OEMs enter into a direct partnership where Google supplies the Android part with all its proprietary and play components, while OEMs convert it into the final blobs after adding their drivers and malware. The only way an external party is going to get those drivers is if somebody manages to extract them from those blobs. The OEMs supply updates for them for a few years and conveniently drop them after that. The consumer is forced to buy a new phone eventually, because their software becomes hopelessly outdated.

In addition to this, similar restrictions are imposed by manufacturers of subsystems like SoCs and RF baseband. Make no mistake about it. No matter how open any of it seems, the entire group of companies involved in this is a racket that's out to squeeze out every penny and bit of personal information from you. The OEMs are very willing participants in this scam.

Re: GrapheneOS is the only Android OS providing full security patches

#299

The GrapheneOS obsession with picking a fight with everyone else is the most unfortunate part of the project.

It doesn't seem to be the entire project, just one dev (afaik) that's quite outspoken and does make accusations that they don't always seem to back with evidence. Also insofar as the actual "product" remains completely untouched by any spats it shouldn't be a dealbreaker for anyone wanting to use GOS, but of course it isn't ideal to have any drama attached.

He never shows any evidence. Always accusing without any images/links. I love the project but it looks not normal.

Re: GrapheneOS is the only Android OS providing full security patches

#300

So this is interesting, they release the patched binaries several months before anyone else does and several months before the source code of the patches is released? This implies that anyone can download GrapheneOS firmware images and use binary diffing techniques to find what are still 0-day vulnerabilities on every Android other than GrapheneOS. Useful! Thank you GrapheneOS developers.

You can extend your thanks to Google, as what you said is also easily done with Google's own updates.
Post reply on HN