Live data from Hacker News

F-Droid Board of Directors nominations 2026

f-droid.org

41–50 of 160 posts

Re: F-Droid Board of Directors nominations 2026

#41
post #13
post #7

Earlier quoted context omitted.

Would love to ditch google and use grapheneOS, however have so many banking and (stupid) outlook for work.

You can check banking app compatibility here: https://privsec.dev/posts/android/banking-applications-compa...

Even if it works now, how can you be sure the next app update doesn't break it in the name of security?

Re: F-Droid Board of Directors nominations 2026

#42
post #7

Earlier quoted context omitted.

Would love to ditch google and use grapheneOS, however have so many banking and (stupid) outlook for work.

> Would love to ditch google and use grapheneOS grapheneOS only works with google phones.

For now[0].

And I don't really think that people mean using google hardware but rather being mined by google software.

May I ask, if you (a) just want to be technically correct, (b) don't see the difference or (c) are trying to make a point I don't understand and if so would be willing to explain?

---

[0] https://piunikaweb.com/2026/02/02/grapheneos-non-pixel-hardw...

Re: F-Droid Board of Directors nominations 2026

#43

Earlier quoted context omitted.

Indeed. Sadly the reality is that most other Android devices are simply not secure enough. Many Android phones do not have a separate secure enclave (outside Pixel and IISC Samsung flagship and A5x range), so they are vulnerable to breaking PIN-based unlocking, side channel attacks, etc. Besides that they often only provide old vendor kernel trees, old firmware blobs, etc. So, you have to wonder whether you want such…

Reduced security has always annoyed me a bit as an argument. Sort of in the same way as signal deprecating SMS because it's insecure. I get all or nothing when your threat model is state actors. However, for most people, the benefit is just freedom from corporate agendas. Not everyone needs kernel hardening, or always E2EE (as with signal). Personally I just like the features it provides (e.g. scoped storage, disabli…

Reduced security has always annoyed me a bit as an argument.

Security is one of one of the main selling points of GrapheneOS, I can fully understand that they don't want to weaken that by supporting fundamentally insecure devices.

I think a nice side-effect is that they only focus on a small number of devices (Pixels) and support those really well. I have followed the /e/OS forums for a while and many devices have constant regressions because it is hard to validate each release on tens of devices.

I get all or nothing when your threat model is state actors.

People do have different thread models, though I think up-to-date software should be the baseline for everyone and where pretty much every phone outside iPhone, Google Pixel, and a subset of Samsung phones fail. Also, I think having a secure enclave should be the baseline, since phones do get stolen.

Its also an easier sell to people who are apathetic to security when the product is just better and more secure, the same way apple does

That's really a weird example though for supporting the argument that GrapheneOS should support more devices. Isn't Pixel + GrapheneOS then pretty much iPhone + iOS? Privacy-respecting, secure, not pushing AI subscriptions all the time (though iOS is getting worse in that respect), offering useful functionality?

At any rate, I understand if you have another phone, you wouldn't buy a Pixel for GrapheneOS, but it does make sense to buy your next phone for running GrapheneOS. Pixel covers a pretty wide price range to, e.g. the Pixel 9a was 349 Euro here recently, all the way up to the Pixel fold.

Re: F-Droid Board of Directors nominations 2026

#44

Earlier quoted context omitted.

GrapheneOS works only with Pixel devices, which doesn't make it much useful for the vast majority of Android users.

Indeed. Sadly the reality is that most other Android devices are simply not secure enough. Many Android phones do not have a separate secure enclave (outside Pixel and IISC Samsung flagship and A5x range), so they are vulnerable to breaking PIN-based unlocking, side channel attacks, etc. Besides that they often only provide old vendor kernel trees, old firmware blobs, etc. So, you have to wonder whether you want such…

Every GrapheneOS proponent I've seen has claimed that other devices are inferior to Pixel security wise, and that's why they're not supported. That always sounded a bit odd to me and certainly seems to have a bit more nuance based on your comment. Thank you for adding some clarity here.

Re: F-Droid Board of Directors nominations 2026

#45
post #39

Earlier quoted context omitted.

Indeed. Sadly the reality is that most other Android devices are simply not secure enough. Many Android phones do not have a separate secure enclave (outside Pixel and IISC Samsung flagship and A5x range), so they are vulnerable to breaking PIN-based unlocking, side channel attacks, etc. Besides that they often only provide old vendor kernel trees, old firmware blobs, etc. So, you have to wonder whether you want such…

Imagine if the Linux project had this same mentality. Thank goodness they don't.

Imagine if Apple had this same mentality, they would never be where they are.

(/s in case it is needed.)

As a smaller project, choosing a small set of hardware and supporting it really well (aside from security reasons) seems like a much better strategy than supporting tens of devices badly (go to e.g. the /e/OS forums to see what regressions people are dealing with after monthly updates).

Re: F-Droid Board of Directors nominations 2026

#46

Earlier quoted context omitted.

I would rather pay a one off ransom to google, than have them harvest all my data and profit from them in perpetuity. Better yet, you can buy a used pixel phone.

Pixel 9 Pro handsets are going for around $500 on the secondary markets like ebay. That's a only a single generation off from their current Pixel 10 models and you still get OS and security updates until 2031. Not a bad deal and pretty crazy how fast smartphones depreciate now.

Indeed and Pixel 10 was 549 Euro here just a few weeks ago and Pixel 9a as low as 338 Euro.

Re: F-Droid Board of Directors nominations 2026

#47
post #25

Earlier quoted context omitted.

> Also, what kind of banking are people doing that requires an app? I genuinely don't know what it could be. Close to every bank in the EU requires their user to have an app, for MFA (both for logging in and for validating transactions - transfers, payments). They use the smartphone's TPM. I have yet to see one that allows you to use your own MFA app. The few I've seen that don't require it will validate the same thr…

>Close to every bank in the EU requires their user to have an app Possibly this was hyperbole but in any case it's not correct at all. Anecdotally, of my two EU (massive legacy French) banks, neither requires a mobile app. SMS all the way. Even Wise, a cutting-edge neobank, does not require you to use its app. And its website accepts standard TOTP authenticator for 2FA. Revolut is app-only, which is why I never use i…

Here in The Netherlands banks used to offer authenticator devices, which they are phasing out (you can still use them, but they wont replace them once they run out of battery). Pretty much all banks switched to app-only.

No SMS at all (which is not surprising, because SMS is not secure).

Also, IMO fingerprint/face-based authentication is much nicer/quicker, especially for online payment flows like iDEAL (Dutch predecessor to Wero). And banks here work on GrapheneOS, so not much is lost.

Re: F-Droid Board of Directors nominations 2026

#48

Earlier quoted context omitted.

I agree, but the probability that this is going to happen anytime soon is near-0. The current US administration is not going to rein in the tech broligarchy and if they did, it would be done out of spite and the pieces wold sold to administration-aligned oligarchs (e.g. Ellison), which might end up being worse. The EU is not going to force this, because it has enough fights to pick with the US, and this is not the hi…

Not sure if you know this, but both Biden and Trump (in his previous admin) had their DOJ file lawsuits against Google. "United States v. Google LLC," which was filed in 2020 and focused on Google's dominance in search and advertising markets. A separate case was filed in 2023 targeted Google's monopolization of digital advertising technologies. The State of Texas also sued them in 2020. Google lost all three cases.…

Trump 2 is very different from Trump 1 though. Trump 1 still had competent, less corrupt people in many positions. Grifters are going to grift.

Anyway, I am going to stop here, since this will probably derail in a non-productive political discussion otherwise.

Re: F-Droid Board of Directors nominations 2026

#49
post #25

Earlier quoted context omitted.

> Also, what kind of banking are people doing that requires an app? I genuinely don't know what it could be. Close to every bank in the EU requires their user to have an app, for MFA (both for logging in and for validating transactions - transfers, payments). They use the smartphone's TPM. I have yet to see one that allows you to use your own MFA app. The few I've seen that don't require it will validate the same thr…

>Close to every bank in the EU requires their user to have an app Possibly this was hyperbole but in any case it's not correct at all. Anecdotally, of my two EU (massive legacy French) banks, neither requires a mobile app. SMS all the way. Even Wise, a cutting-edge neobank, does not require you to use its app. And its website accepts standard TOTP authenticator for 2FA. Revolut is app-only, which is why I never use i…

> Anecdotally, of my two EU (massive legacy French) banks, neither requires a mobile app. SMS all the way.

My wording was bad, sorry; but try to install their app just once. After that, I'd bet you won't ever be able to go back to SMS validation (which is what I was talking about at the end of my comment).

If not, I'd be curious to know the banks you're talking about (to consider switching to them, for one thing). What I said above is true of Caisse d'Epargne, HSBC, CCF, among others.

Re: F-Droid Board of Directors nominations 2026

#50
post #13

Earlier quoted context omitted.

You can check banking app compatibility here: https://privsec.dev/posts/android/banking-applications-compa...

Even if it works now, how can you be sure the next app update doesn't break it in the name of security?

Because it would cause public uproar.
Post reply on HN