Live data from Hacker News

GrapheneOS is the only Android OS providing full security patches

grapheneos.social

431–440 of 467 posts

Re: GrapheneOS is the only Android OS providing full security patches

#431

Earlier quoted context omitted.

Rossman only ever commented on kiwi farms on a thread about himself. You are lying again, confirming the words of the parent comment. And deserved criticism is not harassment.

People in that thread mention a GrapheneOS project member together with the worst of bigotry, slurs and death wishes. And Rossman just decides to keep replying and talking in that thread. Like its worth engaging with these people and they deserve attention.

He didn't say anything about Gos devs in there, yet they say he did. It's just not true. Do you have a Facebook account? Facebook is full of scams, are you also a scammer? Probably.

Re: GrapheneOS is the only Android OS providing full security patches

#432
post #360

Earlier quoted context omitted.

I don't think that's a fair comparison. OEMs have quite a lot of extra steps before releasing any build to the public. They have to pass xTS, the set of test suites required before getting certified by Google, possibly carrier certification, regulatory requirements and more depending on where the build will be released. There are "quicker" release channels for security fixes, but I don't think it's common for OEMs to…

We'll have the same update pace for security updates and major releases with the devices we're working on with our OEM partner. That's not specific to Pixels. It will in fact be easier to support the devices with the OEM partner due to them planning on doing most of the device support work including getting MTE working properly. For Pixels, we have to do a lot of work on device support, while for non-Pixels that work…

Thanks for following up here. I’m glad to hear the OEM stuff is ongoing that’s going to be so big. Congrats and good luck!

Re: GrapheneOS is the only Android OS providing full security patches

#433
post #412

Earlier quoted context omitted.

> We don't have to bring Google or Apple into this relationship, it's a choice people make because the prefer texting and being available to everyone they ever met 24/7 You're changing the discussion now. The original point is this: Given that people want to be able to text with their friends in what is perceived as a normal way , how can they do it without a smartphone? If you change the rules ("Given that people ar…

I don't think that 24/7 availability is universally perceived as "a normal way". A large number of my contacts will answer several days after a message. In my experience it is usually only inside the nuclear family that people expect answer within 2 hours and these are the kind of people who can always choose to call instead of text if they know their child/sibling/parent is not usually text available.

I don't know how many time I would have to repeat it, so I'll do it one last time.

The beginning was:

> what would it take to escape the Apple/Google duopoly?

To which someone answered:

> Has no one mentioned not using a smartphone as an option?

To which I answered that in a ton of situations this is just not an option.

And yet I keep getting answers that give examples of when it is an option. Sure, sometimes it is an option. Now for the majority of normal people who don't consider "not having a smartphone" as an option, I was saying that it is very, very hard to escape Apple/Google.

I am NOT saying that most people would die on the stop if they suddenly did not have access to a smartphone. I am saying that there is no solution to that that most people would consider viable.

> I don't think that 24/7 availability is universally perceived as "a normal way".

I never said 24/7 availability. I said "not having access to WhatsApp/Signal [in one's pocket, some of the time]". The part in brackets was implicit because we were talking about smartphone operating systems.

Re: GrapheneOS is the only Android OS providing full security patches

#434

Earlier quoted context omitted.

Every reasonable, independent organization confirms that Manifest V3 is the end of privacy for Chrom(ium) users, e.g., https://news.ycombinator.com/item?id=29502439 https://news.ycombinator.com/item?id=41871873 https://news.ycombinator.com/item?id=44543660 > It restricts and controls the access of extensions much more. You mean, it restricts users even more and gives to websites the freedom to track you? I won't enga…

You link three things, that doesnt equate to "every independent organization". One of your links is a post by Brave and Brave isnt independent in this. The unsubstantiated fear of people for MV3 is beneficial for them, it could grow their userbase because they keep the support for MV2. Content blocking (ad and "tracker" blocking) are convenience features, they dont foundationally improve security. Defining what a tra…

> You link three things, that doesnt equate to "every independent organization".

Seriouslu, is this the only counter-argument you could invent? I didn't have the goal to list all independent organizations in the world. Now, you have to find one saying the opposite to EFF.

> If you dont trust a site to not send data to third party domains directly, why do you trust it to not send it indirectly?

Because there were examples when 3rd-party ads delivered malware to clients: https://www.networkworld.com/article/946902/forbes-malware-a...

Also, because FBI recommends it: https://www.pcmag.com/news/fbi-recommends-installing-an-ad-b...

> MV3 helps against tracking

Against tracking by whom? By FLOSS add-ons intentionally installed by user and verified by the community? In contrast to random, untrusted websites running megabytes of proprietary JS?

Re: GrapheneOS is the only Android OS providing full security patches

#435
post #406

Earlier quoted context omitted.

That is also my feeling, at least from a part of the GrapheneOS community. I have seen them despising and bullying /e/OS, Debian, F-Droid, the Linux kernel... Too bad for this project, that is amazing, to have such toxic folks. Open source communities should help each other, and work together, not fight.

You can't equate actions from a part of the community with actions by the project. If you would see any bigotry by a GrapheneOS community member, please report it to the moderators. Bullying, toxcity and misinfo are not allowed. Action will be taken. I havent noticed a lot of that in the community myself, in which im very active. Its exceptional in my eyes. Common though is technical criticism on other projects when…

*There is no big conflict with Debian or Linux kernel at all.

(Typo)

Re: GrapheneOS is the only Android OS providing full security patches

#436

Earlier quoted context omitted.

> completely wrong comparisons between GrapheneOS and GNU/Linux get posted Can you be more specific here? I don't see anything like that in my links. > dont opt for GNU/Linux either given the large code contributions made by Google You're trolling again, with no reasonable arguments. You can find a reply here: https://news.ycombinator.com/item?id=46176660 > How is GrapheneOS having access to the embargoed patches and…

> Can you be more specific here? I don't see anything like that in my links. You made a general statement about attacks from GOS on GNU/Linux. I replied that this happens in the context of wrong comparisons being made. > You're trolling again, with no reasonable arguments. You can find a reply here: https://news.ycombinator.com/item?id=46176660 Im not trolling. You say you dont trust Google at all. Thats your positio…

> You made a general statement about attacks from GOS on GNU/Linux.

No, I provided two specific examples, one quoted and another linked to. None of them happend in the context of wrong comparisons being made.

> You say you dont trust Google at all. Thats your position. Then my argument is to not trust their code, regardless of which project its submitted to. How is that unreasonable.

Your argument is completely unreasonable. Google has full control over Android and therefore GrapheneOS. It has very little control over Linux. All their contributions to Linux are carefully verified by many independent parties and suspicious things not accepted by community are rejected. The latter doesn't happen in Android, see my examples above.

> The issue gets patched. Whether the code is published doesnt change the code...

Only if you 100% trust Google. I see you do and promote them. I wonder why you would defend a trillion-dollar, monoppolistic megacorp hostile to its users.

> People can also sti reverse engineer the code.

This takes huge effort and time. One can't rely on it to be secure.

> If Google were to put the restriction in AOSP, GOS can simply remove it from the code...

The effort to keep a hard Android fork up-to-date will grow exponentially. I don't expect that GOS team will manage to do it for long.

> This metaphor doenst make any sense in relation to the planned sideloading restrictions.

This is exactly what is happening with Android right now. Users are constantly loosing their control over the device in the name of the false sense of security.

> I suggest reading the blogposts from Google about what the process will look like.

This is not even funny. Are you working at Google? I suggest you to read blog posts by a non-profit instead: https://eff.org.

Re: GrapheneOS is the only Android OS providing full security patches

#437
post #202

Earlier quoted context omitted.

For me the bank app was working, but the electric scooter app didn't and that was it for me :( Damn e-scooters, can't live without them. But I still haven't contacted the support to ask them to verify phones in another way.

Be sure to leave them a one-star review, and maybe name them here so others can do the same. Anyone who does that sort of crap deserves at least that tiny bit of punishment for it.

The thing is they are the best e-scooters provider in town. They have fantastic support, few times agreed to my feature requests. They have very forgiving policy for when you forgot to lock the scooter and so on. I really believe that if I messaged them off season (when they work on the app, like now in winter), and suggested changing the way they attest phones, they would consider using the attestation that GOS can pass.

Re: GrapheneOS is the only Android OS providing full security patches

#438
post #45

Earlier quoted context omitted.

FWIW, Jolla just announced a new phone: https://commerce.jolla.com/products/jolla-phone-preorder

It was discussed here when it was announced. I believe it was determined the hardware is an ultra-low-budget Aliexpress design that normally retails for ~$100 that they had custom built with a mic cutoff switch added to it (probably the cause of a large portion of the hardware price increase). I dont remember the specifics, but even thr most optimistic were pretty sure it won't get hardware vendor support for even a…

What phone with OLED, 12GB RAM, 256GB storage, and user replaceable battery is $100 on Aliexpress?

Re: GrapheneOS is the only Android OS providing full security patches

#439

Earlier quoted context omitted.

People in that thread mention a GrapheneOS project member together with the worst of bigotry, slurs and death wishes. And Rossman just decides to keep replying and talking in that thread. Like its worth engaging with these people and they deserve attention.

He didn't say anything about Gos devs in there, yet they say he did. It's just not true. Do you have a Facebook account? Facebook is full of scams, are you also a scammer? Probably.

He engaged / replied to the people that were talking about both a GrapheneOS dev and an Asahi Linux dev.

Imagine the following: People in a thread made about you start posting death wishes about people you have conflicts with, make bigotted comments about them and on top of that are in general being ableist and hateful towards multiple societal groups (things akin to "I wouldnt trust the GOS dev just like I wouldnt trust a ").

Would you think it makes sense having a friendly chat with these people, as if they are worthy conversation partners? Shouldnt they either be ignored or judged?

Re: GrapheneOS is the only Android OS providing full security patches

#440

Earlier quoted context omitted.

> Can you be more specific here? I don't see anything like that in my links. You made a general statement about attacks from GOS on GNU/Linux. I replied that this happens in the context of wrong comparisons being made. > You're trolling again, with no reasonable arguments. You can find a reply here: https://news.ycombinator.com/item?id=46176660 Im not trolling. You say you dont trust Google at all. Thats your positio…

> You made a general statement about attacks from GOS on GNU/Linux. No, I provided two specific examples, one quoted and another linked to. None of them happend in the context of wrong comparisons being made. > You say you dont trust Google at all. Thats your position. Then my argument is to not trust their code, regardless of which project its submitted to. How is that unreasonable. Your argument is completely unrea…

> No, I provided two specific examples, one quoted and another linked to. None of them happend in the context of wrong comparisons being made.

You made a general statement here ("being known for"). You put a link there indeed with a quoted example and another link.

  > Indeed the GrapheneOS community is known for attacking the GNU/Linux mobile with false claims, https://news.ycombinator.com/item?id=45562484.
You have to look at the parent replies of what you link. Read the thead properly, please. Like I said , "What happens is that there are posts on the internet about GrapheneOS or mentioning GrapheneOS in which or under which completely wrong comparisons between GrapheneOS and GNU/Linux get posted". Replies that were literally mentioning GrapheneOS got a reaction. Thats not an unfounded attack. The statements that those other options are less secure are clearly backed up with technical information.

> All their contributions to Linux are carefully verified by many independent parties and suspicious things not accepted by community are rejected. The latter doesn't happen in Android, see my examples above.

That's really not how it works in practice. There is a ridiculius amoumt of code and code changes. Systematic proper exhaustive auditing doesnt happen. Also, you distrust Google and think they are malicious. Google can do their best to hide bad stuff in their code so quick reviews wont notice it. Do you think malware developers write functions called doTheBadStuff()?

> I see you do and promote them. I wonder why you would defend a trillion-dollar, monoppolistic megacorp hostile to its users.

I am not promoting Google. I am just countering your posts critizing Google using bad arguments. Google is a multi-faceted compamy some of the things they do are good for end users, some aren't, most things will be liked by some and disliked by others.

> This takes huge effort and time. One can't rely on it to be secure.

Reading and properly understanding source code also takes huge effort and time. And like I said, if you dont trust the devs, you cant trust function names, variables names and code comments to give a faithful portrayal of functionality anyway. So do you really lose that much if you decompile Java bytecode and mainly just miss naming and comments? It can even be argued it will remove preconceptions and let you read the code with a more open mind. Its a hurdle and annoying for sure, though. I would prefer Google to lower the embargo as well. But, public source availability just isnt the magic silver bullet you think it is.

> The effort to keep a hard Android fork up-to-date will grow exponentially. I don't expect that GOS team will manage to do it for long.

You dont need a hard fork for that. If the sideload restriction were to be put in AOSP you can remove that in a soft fork.

> This is exactly what is happening with Android right now. Users are constantly loosing their control over the device in the name of the false sense of security.

I agree Googles plans arent a good approach. But it isnt a false sense of security either. Registering app IDs and associated public keys is a usefil thing. There are other, begger approaches though, tbat dont have the downsides of what they planned.

> This is not even funny. Are you working at Google? I suggest you to read blog posts by a non-profit instead: https://eff.org.

Based on what you were saying and your bad metaphor it is just clear you arent accurately informed or up to date about what the sideloading restrictions will be. The best place to read what the procedures will be is in Google's blog posts and documentation. I am not saying you have to go read that to make a value judgement on the merits. You just need to read that to understand what is actually being talked about. I dont like Google's plans either but I am aware of what they are.

Something being a non-profit doenst automatically mean all posts they write are of good quality. EFF does many good things but I dont see why their posts about things are somehow automatically good and authoritative because of their non-profit model. Best to judge individual posts on their merit.

Post reply on HN