Live data from Hacker News

Reclaiming Mobile Privacy with GrapheneOS

xn--gckvb8fzb.com

41–50 of 80 posts

Re: Reclaiming Mobile Privacy with GrapheneOS

#42
post #26

Earlier quoted context omitted.

You can just use any other camera app. I use the Google Camera on my Pixel 6.

OpenCamera is great, but there's no substitute for the stock one that's tailored to the phone hardware.

Which, as I wrote, is what I am using on my Pixel 6 with GrapheneOS. I don't get your point?

Re: Reclaiming Mobile Privacy with GrapheneOS

#43
Graphene certainly looks impressive by all accounts, but are there any 3rd party audits? I can't find any.

I've learned to expect that from FOSS software that has any kind of security claims and purports to help me be more private or secure. Particularly since I don't have the necessary skills/knowledge to do so myself.

Re: Reclaiming Mobile Privacy with GrapheneOS

#44
GrapheneOS is a very nice mobile OS - I use it on multiple devices and its my top pick for android ROMs. Some thoughts:

1. They're the only ROM project that actually focuses on improving application level safety. This is a bigger deal than a lot of people realise.

2. They offer installation remote attestation - again, worth using if you can.

3. Lots of drama with Calyx and GrapheneOS which is very hard to familiarise with. This is because the discourse is often deleted (this is the policy of the Graphene OS chatrooms) and so it is difficult to verify claims without pointing to another instance of deleted comments/purported harassment. If you can help it, I recommend to just try ignore the whole thing until they start screenshotting the actual harassment.

4. A lot of people talk about Graphene having worse performance than a lot of other ROMs but this is actually counter to my own experience. Graphene is consistently the fastest ROM I have used.

5. You may see people kick up a shit about how Graphene uses sandboxed play store and how that's a bad thing somehow. If you are worried, keep in mind you can still use Aurora if you want your install to be anonymised (but frankly I am not sure what the extent of the changes that Aurora makes). Similarly F-Droid is available, but is super weird about how they sign apps.

6. There are a LOT of updates. This is a good thing but it can throw you off if you're coming from another ROM.

Re: Reclaiming Mobile Privacy with GrapheneOS

#46
post #32

Earlier quoted context omitted.

With GrapheneOS, specifically, it kind of defeats their design goals[0] -- so on Graphene I would say it is not a viable solution. On other custom ROMS such as CalyxOS (my go-to for my Pixels), or LineageOS, I have used microG and it works very well. [0] https://nitter.net/GrapheneOS/status/1437380576055541761

The thread you're linking explains why we developed sandboxed Google Play compatibility layer for better privacy, security and far broader app compatibility. On an OS using microG, you still have the Google Play code running in each of the apps you're using which depend on Google Play. You aren't avoiding the Google Play code. In fact, you're running it with more privileges than it has on GrapheneOS where there's a s…

> we developed sandboxed Google Play compatibility layer for better privacy, security and far broader app compatibility.

Does this mean you could install and run Google Play apps on GrapheneOS now? Last I used GrapheneOS (2020), I wasn't able to.

Thank you for the explanation!

Re: Reclaiming Mobile Privacy with GrapheneOS

#47
post #17

Quoted post unavailable.

The background story of the project is quite sad, so it sort of makes sense that he is very defensive of it. (The project got some monetary support initially from a company, which later tried to hijack the whole open-source project (going by copperhead os nowadays, I believe). Fortunately thanks to Micay the original was unharmed (he revoked private keys, big kudos!), but they do throw shade at GrapheneOS promoting t…

No post body was provided.

Re: Reclaiming Mobile Privacy with GrapheneOS

#48
I am using Graphene on a Pixel 5 for some years now. It's a blast. I don't want to miss it. My battery runtime is much longer than with the stock OS. I am glad the folk at the GrapheneOS team made my value my privacy more by educating me about the implications, the current vendor operating systems inflicts on our privacy.

Re: Reclaiming Mobile Privacy with GrapheneOS

#49
post #21
post #15

Earlier quoted context omitted.

Care to elaborate more on how you find GrapheneOS "terrible"?

They don't know much about it and haven't used it. CalyxOS isn't a hardened OS and isn't at all comparable to GrapheneOS. They recently didn't even ship half the baseline Android security patches for 2 months, let alone providing much better patching and substantially hardening the privacy and security of the OS. Unfortunately, they've chosen to promote it through inaccurate talking points about GrapheneOS and fabric…

Commments like this are precisely why the "rivalry" continues to exist.

GrapheneOS handily beats out every other project on security and technical merit -- let the code and project speak for itself, because jumping in to every single convo between end users you can find, doesn't help quell any of it.

From a GrapheneOS user for many years who thanks you for your work and dedication

Re: Reclaiming Mobile Privacy with GrapheneOS

#50
Few notes:

- some crapplications do not want to run on custom rom

- more than mere mobile privacy I'm MUCH worried about new cars (witch happen to be mobile crapware connected crap)...

As a small dumb example, I've got my new EV, formally already fitted by default of crappy surveillance contracts with some vendors "pre-payed" and I have to unsubscribe to them all one-by-one. Car itself is a mobile OS, connected to the vendor and who knows what PLUS Android Auto/Apple CarPlay. Being semi-autonomous and connected can potentially blocked or cracked from remote and I doubt we can even LEGALLY flash other firmware's.

To add a small anecdote I found the car already bound to the vendor phone, it's new but probably they have do some test being a vehicle in their exposition, he simply forget to unbind it. Witch means he potentially track, remote open, remote power on etc the car.

In such terms while I prize all FLOSS efforts we can't have privacy on mobile crapware and craphw: the sole option is IMPOSING with popular acclaim mandatory FLOSS for anything and all "connections" must be in the term "your device can expose, at your options as the real owner of the device, some services to the net. All we offer is a connection service, with a public IPv6 address and a (sub)domain name for you. You choose what to do with it". No "push-OTA" and other stuff allowed by laws, with sanctions severe enough no one would even try to.

Post reply on HN