Live data from Hacker News

eOS DeGoogled Privacy Smartphone in the US Review

ramblinggit.com

31–36 of 36 posts

Re: eOS DeGoogled Privacy Smartphone in the US Review

#32
post #24

Earlier quoted context omitted.

Holy hell, the FUD. YES THEY WILL — I wouldn't even say it's "many" or "some", anymore. "Most" is just insulting.

You believe less than 51% of commercial Android apps on the app store use even one single Google Play Service? No push alerts, maps, ads, etc.

There are varying (read: dropping weekly) levels of dev reliance on Google/GCM etc for those things in apps, now.

I'd evaluate what you're using, because it's likely to work just fine.

Re: eOS DeGoogled Privacy Smartphone in the US Review

#33

How are these phones with regard to an unlocked bootloader and passing Safety Net? Online banking apps refuse to launch on some de-Googled Android versions, on the grounds that the device is now supposedly insecure. The new COVID vaccine passports, which several governments have announced will exist only as an Android/iOS app producing limited-time QR codes (because paper certificates are too easily forged), might ha…

This is really a problem. Ideally this would be approached in a similar way to TLS errors in browsers - scary warning, but ability to proceed anyway if you understand the risks. Certainly for banking apps etc at least

Re: eOS DeGoogled Privacy Smartphone in the US Review

#34
post #26
post #9

Earlier quoted context omitted.

If you're not savvy at installing custom anything, and just want a setup that keeps the Android security model intact (unlike all of these LineageOS forks), check out GrapheneOS.org.

> want a setup that keeps the Android security model intact (unlike all of these LineageOS forks) Can you expand on how LineageOS breaks the Android security model?

Not standard LineageOS, but LOS forks that provide microG in place of Google Apps have to support "signature spoofing" so that MicroG can impersonate the missing proprietary Google apps.

More details here: https://blogs.fsfe.org/larma/2016/microg-signature-spoofing-...

> I’d also like to point out a myths I heard regarding signature spoofing. Some people assume, that signature spoofing allows to break the Android signature security model and thus rogue applications can access private app storage. But in fact signature spoofing is only applied after installation if the permission was granted, it has no influence on the package manager security model.

Re: eOS DeGoogled Privacy Smartphone in the US Review

#35
post #26

Earlier quoted context omitted.

> want a setup that keeps the Android security model intact (unlike all of these LineageOS forks) Can you expand on how LineageOS breaks the Android security model?

Not standard LineageOS, but LOS forks that provide microG in place of Google Apps have to support "signature spoofing" so that MicroG can impersonate the missing proprietary Google apps. More details here: https://blogs.fsfe.org/larma/2016/microg-signature-spoofing-... > I’d also like to point out a myths I heard regarding signature spoofing. Some people assume, that signature spoofing allows to break the Android sig…

Correct me if I'm wrong, but your quote then implies that it's still fine even with microg installed, right? So maybe OP is talking about something else? Or are you saying that they're misguided?

Re: eOS DeGoogled Privacy Smartphone in the US Review

#36
post #35

Earlier quoted context omitted.

Not standard LineageOS, but LOS forks that provide microG in place of Google Apps have to support "signature spoofing" so that MicroG can impersonate the missing proprietary Google apps. More details here: https://blogs.fsfe.org/larma/2016/microg-signature-spoofing-... > I’d also like to point out a myths I heard regarding signature spoofing. Some people assume, that signature spoofing allows to break the Android sig…

Correct me if I'm wrong, but your quote then implies that it's still fine even with microg installed, right? So maybe OP is talking about something else? Or are you saying that they're misguided?

I'm not enough of an expert to say for certain, and I'm not exactly sure what parent comment means when they accuse LineageOS of "destroying" the "Android security model", but from what I've read, concerns about signature spoofing are overblown - provided the user is very selective about what apps they grant spoofing powers to.
Post reply on HN