Live data from Hacker News

GrapheneOS – Break Free from Google and Apple

blog.tomaszdunia.pl

361–370 of 967 posts

Re: GrapheneOS – Break Free from Google and Apple

#361
post #142

Been using this for about a year on a p9 pro. It works very well. I hear the google tap to pay does not work, but I've never tried it. However Vipps with their tap to pay works fine. BankID works but not with biometric login, which some things require IIRC. And for some reason DnB private works fine, but you are not allowed in on the corp app. It's mind boggingly stupid that they lock down apps like this, when you ca…

> It's mind boggingly stupid that they lock down apps like this, when you can just open the thing in a website anyway. I can use my bank on some linux distro... Not in Spain. I can access my bank's website but I can't do anything without their bank app. Even sometimes they require to confirm my identity using their app in order to access their website. I have several linux phones but I can only do banking with their…

Similar in Canada.

- RBC 2FA is that if I try to login through my browser, the phone app will ask if I authorize the login. I think I can disable this and use sms/call, but that's even more insecure, so I don't.

- TD lets me login fine and do everything in the browser. But any online transaction that is moderately large or presumably fishy, will force me to authorize the transaction via the app.

These are among the largest banks in Canada.

Re: GrapheneOS – Break Free from Google and Apple

#362
post #231

It's a shame only Pixel phones are supported. I have PWM sensitivity and Pixel phones are notoriously bad for this, my eyes hurt when I look at one for more than 30mn. Due to the lack of good, secure alternative, I have had to give up on privacy in exchange for manufacturer updates.

Seriously. Especially if you're someone who wants to cut ties with Google.

So, buy it refurbished? Google doesn't directly profit from it, you create less pollution, and once you have GrapheneOS on it you can leave Google out the door.

The problem with nearly every other phone, except maybe Samsung flagships, is that they don't fulfill the security requirements. And Samsung is hostile against unlocking (even when it was still possible, it would burn a Knox eFuse).

Re: GrapheneOS – Break Free from Google and Apple

#363
post #211

Earlier quoted context omitted.

> why they're unable to continue supporting a release just because the upstream removes support for something. If you have an EOL Pixel and a new major version of Android is released, Google will not port this new version of Android (and therefore AOSP) to it. So GrapheneOS would have to do it. GrapheneOS just say they don't have the resources to do that, so they follow the Google releases. Could you keep an EOL Pixe…

Sounds a bit disingenuous then for an article to have a title that includes the phrase "break free from Google".

It was first "break free from Android", but somebody complained so they changed it. Titles are hard, I guess :-).

Re: GrapheneOS – Break Free from Google and Apple

#366
post #306

"Break free from Google" and buy a Pixel phone from them to do so. But unironically Pixels are currently some of the best actually open phones. They do not lock down or require shady practices for unlocking the bootloader (although they do require a network check once that happens automatically, but it will permanently allow unlocking the bootloader if successful once. Pixels are very easy to restore and almost un-br…

I have a Pixel 6a with GrapheneOS. Runs great for years, except for one or two apps that require an "official" Android.

Anyway, I now need to get the battery replaced, because apparently they are dangerous and Google pays for the replacement. Unfortunately, the replacement process requires the stock android to be installed. Meaning, I would need to backup the whole phone, reinstall stock android, then restore everything - and hope the whole ordeal works out.

Re: GrapheneOS – Break Free from Google and Apple

#367
post #27

They should get the same level of financing (donations) as Tor project at least. Some big organization like Open Technology Fund or NLnet should give them yearly grants.

900+ donors on github (https://grapheneos.org/donate#github) is not *too* bad, but likely not enough to cover a full salary.

Re: GrapheneOS – Break Free from Google and Apple

#368
post #321

Earlier quoted context omitted.

Feels like you don't know what "the sandbox" is. It's not "their" sandbox, it's from AOSP. When you run an app on Android, it runs in a sandbox. Meaning that your social media app cannot access the files of your banking app by default . They are "sandboxed". On a normal Android, the Play Services are installed as a system app. It is privileged app that has "system" access. A system app is not sandboxed. GrapheneOS al…

If the Tiktok app passes your data to Play Services (say, to support notifications with GCM) then it doesn't make any difference that Play Services is nominally "sandboxed". I agree there's some marginal benefit that sandboxed GApps need to prompt the user for permissions (rather than having privileged system level access) but at the end of the day, Google Maps will get GPS perms and Google will know everywhere your…

> If the Tiktok app passes your data to Play Services (say, to support notifications with GCM) then it doesn't make any difference that Play Services is nominally "sandboxed".

Sure, but that's the same if you run TikTok with microG (which will relay your data to the Google servers just like the Play Services) or in waydroid on a Mobile Linux. But you can't blame the system for what the apps are allowed to do by the user.

Take your Google Maps example: if the user wants to run Google Maps, obviously they will be sharing data with Google. It's very weird to blame the system for that.

What the sandbox brings is that for users who want to run the Play Services (because they want to run TikTok, knowing that it will share data with some servers, including but not limited to the Google servers through the Play Services), then at least the Play Services are not root on their OS. So then instead of running microG, you can run the Play Services and have the same kind of benefits.

Now if you don't want your apps to contact Google, then by all means, don't install the Play Services! But don't install microG either! And don't install Google Maps!

It's all about trade-offs, it's not an all or nothing situation. Sandboxed Play Services is better than privileged Play Services.

Re: GrapheneOS – Break Free from Google and Apple

#369

Been running GrapheneOS for a while on a Pixel 9, and extremely happy with it! Apart from the usual perks of the FOSS ecosystem, there are a few things specific to GrapheneOS that are not immediately apparent but have turned out to work very well - 1. The Pixel camera app works, including all modes and settings. A camera that takes good photos was absolutely a requirement for me, and the FOSS camera apps are not quit…

wish my yubikey would work with bitwarden

Re: GrapheneOS – Break Free from Google and Apple

#370

Switched to this from Apple a year and a half ago. Works for most things. Unexpectedly, replacement apps lack polish. Also, RCS works very inconsistently (been without it for months), seems to be Google's fault. There may be workarounds, but I haven't had the energy to try the more complicated suggestions. I am probably going to switch back to a used old iPhone for "phone appliance" tasks, but keep around the Pixel f…

The RCS issue is why I switched back to iPhone, reluctantly.

If anything, iOS seems buggier and less reliable, but I know (and am related to) a lot of people who insist on using iMessage/RCS, and I can't be missing messages.

Post reply on HN