Live data from Hacker News

Reclaiming Mobile Privacy with GrapheneOS

xn--gckvb8fzb.com

31–40 of 80 posts

Re: Reclaiming Mobile Privacy with GrapheneOS

#31

is microG still a viable solution for avoiding Gapps or is there something better now?

GrapheneOS developed our sandboxed Google Play compatibility layer to provide support for running Google Play as regular apps in the full standard app sandbox. They work like any other apps and can't do anything that a regular user installed app can't do. Since they're regular apps, all our work on improving the app sandbox and permission model in a compatible way applies to them. For example, you can revoke our Sensors toggle from them (or even Network, but that would prevent using their services, which many apps depend on for real use) and can use Storage Scopes instead of granting any storage permissions, etc. In practice, you don't need to grant any permissions to Google Play when using sandboxed Google Play. Our location rerouting feature reimplements the Play services geolocation API based on the standard AOSP location API based on GNSS (GPS, GLONASS, etc.) + A-GNSS. If you really want to use Google Play network location, it's possible, by granting background location access to it, enabling their network location toggle and disabling our location request rerouting feature. We plan to provide more of these rerouting features in the future when it makes sense.

Re: Reclaiming Mobile Privacy with GrapheneOS

#32

is microG still a viable solution for avoiding Gapps or is there something better now?

With GrapheneOS, specifically, it kind of defeats their design goals[0] -- so on Graphene I would say it is not a viable solution. On other custom ROMS such as CalyxOS (my go-to for my Pixels), or LineageOS, I have used microG and it works very well. [0] https://nitter.net/GrapheneOS/status/1437380576055541761

The thread you're linking explains why we developed sandboxed Google Play compatibility layer for better privacy, security and far broader app compatibility. On an OS using microG, you still have the Google Play code running in each of the apps you're using which depend on Google Play. You aren't avoiding the Google Play code. In fact, you're running it with more privileges than it has on GrapheneOS where there's a stronger sandbox and permission model. You're avoiding part of the Google Play code: the part sitting between the Google Play SDK / libraries and their services (but not quite, since microG downloads and runs droidsec/snet within the context of microG, which has significantly elevated privileges on CalyxOS).

Re: Reclaiming Mobile Privacy with GrapheneOS

#33

Glancing over to https://news.ycombinator.com/item?id=33550824 I'm wondering... does this GrapheneOS have plausible deniability?

It doesn't. I requested a feature to software-wipe the phone after X incorrect password attempts, but was rejected on the basis that this would be security theatre if implemented in software not hardware. I would like to implement a set of features to this end, but have not found the time. I would like:

- wipe after X incorrect attempts

- configure a "kill" passcode instantly wipes phone

- configure arbitrary passcodes that are mapped to actions when entered

- there's a feature to make phone reboot every X hours, if not unlocked, add a parallel feature to wipe phone if not unlocked in X hours.

- something where the passcodes are use once, and using an already used passcode wipes the phone. So you can bait LE and say "last time I unlocked it with X" and if they're stupid enough to not question you further, and just try X, it'll wipe, and it'll be their fault

- something to set a chance of wipe on the correct passcode, so you can say "any passcode might wipe the device"

I'm interested in hearing more ideas here.

Re: Reclaiming Mobile Privacy with GrapheneOS

#34
post #12

I had to switch back to iOS. My smartphone is my primary camera and I missed lots of important shots because the Graphene camera was so slow to double click launch from locked (on a flagship pixel $LATEST pro max whatever). I really miss syncthing.

You can speed up app launching by turning off the optional exec-based spawning feature. Our camera app also has a Latency mode which recently became the default instead of Quality mode. Google and Apple camera apps essentially always use something resembling the Latency mode, but with lower JPEG quality by default.

Re: Reclaiming Mobile Privacy with GrapheneOS

#35
post #7

I use CalyxOs without any Google Apps (camera app blocked via firewall). I find GrapheneOS horrible. If I want to get away from Google, I don't want to run Google Apps in the sandbox either

What I love about GrapheneOS is that it gives people a choice. It starts out slim, without any Google services. You have the choice to use them if you need them, and you can use them in the same way and with the same sandbox as you would any other app. But the most important thing is choice and options.

You can even use Sandboxed Google Play in a specific user profile, instead of options like MicroG where it has to be privileged for a lot of its features/functionality to function, and where it's ever-present in all of your profiles.

Furthermore, since we're talking about Google apps and services, I find the fact that CalyxOS ships with the privileged eSIM activation Google app which is enabled by default and to my understanding cannot be disabled very concerning...

https://blog.privacyguides.org/2022/04/21/grapheneos-or-caly...

On the other hand, (again) GrapheneOS has it disabled by default and you're given the choice to use it if you need it, instead of having it forced on you by default.

After looking at all options for alternative Android OSes, not matter which way you slice it, GrapheneOS takes the cake, so I don't really understand how someone who has actually looked at both options can call it "terrible".

Re: Reclaiming Mobile Privacy with GrapheneOS

#36
post #21
post #15

Earlier quoted context omitted.

Care to elaborate more on how you find GrapheneOS "terrible"?

They don't know much about it and haven't used it. CalyxOS isn't a hardened OS and isn't at all comparable to GrapheneOS. They recently didn't even ship half the baseline Android security patches for 2 months, let alone providing much better patching and substantially hardening the privacy and security of the OS. Unfortunately, they've chosen to promote it through inaccurate talking points about GrapheneOS and fabric…

(First, strcat, thank you so much for your work on GrapheneOS. I should have a little ETH to send to the project in a few weeks, to make this sentiment a bit more concrete.)

Regarding community among people valuing security and privacy...

On my most recent big phone/handheld switch, I tried CalyxOS first, but found that I personally preferred GrapheneOS.

I think CalyxOS also has its merits.

Users of CalyxOS and GrapheneOS are relatively small groups, with overlapping interests, and together are stronger, if the tone is friendly competition and mutual assistance.

Re: Reclaiming Mobile Privacy with GrapheneOS

#37
post #26
post #12

I had to switch back to iOS. My smartphone is my primary camera and I missed lots of important shots because the Graphene camera was so slow to double click launch from locked (on a flagship pixel $LATEST pro max whatever). I really miss syncthing.

You can just use any other camera app. I use the Google Camera on my Pixel 6.

OpenCamera is great, but there's no substitute for the stock one that's tailored to the phone hardware.

Re: Reclaiming Mobile Privacy with GrapheneOS

#39
I have been using GrapheneOS since April. I have not used any alternatives in a long time (my previous phone was the Galaxy S9):

First, let me preface this with the fact that, in my opinion, overall it's a pretty solid OS. After having done research several times, the only other mod I've considered is LineageOS, but last I checked, there were no builds for my Pixel 6 Pro.

My biggest two issues with it are that it doesn't have any usability improvements other mods have. It's not on them though, as it's an expectation I have of mods, but obviously this is like having an expectation of support for FLOSS. It's annoying, but it is what it is.

The default camera app is subpar compared to the stock camera app of Pixel phones. I use OpenCamera, but it's also not great (though that opinion might stem from me not knowing how to use it properly).

The bigger issue I have with it is that, while sandboxed Google services generally work pretty well, some apps don't work properly with the location requests proxy. I'd love to enable it, but, for example, Citymapper is unable to track me when I use it. Finding a location sometimes can take very long.

I would love to have LineageOS improved by having the hardening patches that are in GrapheneOS.

Re: Reclaiming Mobile Privacy with GrapheneOS

#40
post #31

is microG still a viable solution for avoiding Gapps or is there something better now?

GrapheneOS developed our sandboxed Google Play compatibility layer to provide support for running Google Play as regular apps in the full standard app sandbox. They work like any other apps and can't do anything that a regular user installed app can't do. Since they're regular apps, all our work on improving the app sandbox and permission model in a compatible way applies to them. For example, you can revoke our Sens…

Thanks; if network and other permissions can be revoked from GApps, which otherwise have all possible device permissions, it eliminates the need for MicroG. I will try it out.
Post reply on HN