Live data from Hacker News

GrapheneOS – Break Free from Google and Apple

blog.tomaszdunia.pl

431–440 of 967 posts

Re: GrapheneOS – Break Free from Google and Apple

#431
post #368

Earlier quoted context omitted.

> If the Tiktok app passes your data to Play Services (say, to support notifications with GCM) then it doesn't make any difference that Play Services is nominally "sandboxed". Sure, but that's the same if you run TikTok with microG (which will relay your data to the Google servers just like the Play Services) or in waydroid on a Mobile Linux. But you can't blame the system for what the apps are allowed to do by the u…

I agree it's about trade-offs. I think MicroG - which provides dummy no-op implementations of Google Play tracking APIs, and allows you to select alternative Location Providers and notification backends - is a better option than running first-party Google software. You're of course correct that we can't blame the system for choices made by users, but I do think GOS lulls users into complacency by focusing on the secu…

> I think MicroG - which provides dummy no-op implementations of Google Play tracking APIs, and allows you to select alternative Location Providers and notification backends - is a better option than running first-party Google software.

microG still forwards the requests to the Google servers. Not sure what you mean by "tracking APIs"? microG is a reverse-engineered, open source implementation of a subset of Play Services, right? It's not obviously a better option: for instance, some things that are supported in Play Services are not supported in microG, and microG sometimes breaks (because of changes in the API).

> allows you to select alternative Location Providers

GOS does that, too.

> I do think GOS lulls users into complacency by focusing on the security angle only and encouraging users to install sandboxed GApps

I don't get that. It does not encourage them to install Play Services, it makes it available. Because for many (most?) users, it is important to have it.

I am not sure what you are trying to say: is your opinion that there is no point in using an alternative OS (like GOS, /e/OS, LineageOS, IodeOS, ...) or are you trying to say that GOS is not the most secure/private alternative OS?

Re: GrapheneOS – Break Free from Google and Apple

#432
post #233
post #142

Earlier quoted context omitted.

> It's mind boggingly stupid that they lock down apps like this, when you can just open the thing in a website anyway. I can use my bank on some linux distro... Not in Spain. I can access my bank's website but I can't do anything without their bank app. Even sometimes they require to confirm my identity using their app in order to access their website. I have several linux phones but I can only do banking with their…

> Not in Spain. I can access my bank's website but I can't do anything without their bank app. Even sometimes they require to confirm my identity using their app in order to access their website. https://triodos.es has 2FA via SMS, for what is worth.

My bank used to have it as well but not anymore. I wonder for how long Triodos will be able to keep that option.

Re: GrapheneOS – Break Free from Google and Apple

#433
post #339
post #80

Earlier quoted context omitted.

I have been a user of /e/OS for 5 years, and also of GOS and would like to share my opinion on this: > it's worth noting that the GOS community is absurdly toxic to anyone doing anything privacy-related that isn't under the banner of GOS What I have seen (and I am not involved in any of those projects) is that GOS does care a lot about security, has a higher quality in that regard than anything else, and tends to be…

I guess on /e/OS you can just run Google Maps in a browser if you really want Google Maps features (like searching for a restaurant). Organicmaps works fine if you just need to get from A to B. It does lack live traffic, but you'll have to live with fewer features if you really want to not use Google for most stuff.

> Organicmaps

I would suggest having a look at CoMaps, a recent fork of OrganicMaps :-).

Re: GrapheneOS – Break Free from Google and Apple

#434

Earlier quoted context omitted.

Your password must be between 8 and 12 characters, and must have lowercase, uppercase, numbers, and punctuation. Pick up the can!

Having more than just alphanumeric characters widens the domain of the password hash function, and this directly increases the difficulty of brute-force cracking. But having a such a small maximum password length is... puzzling, to say the least. I would accept passwords of up to 1 KiB in length. With rainbow tables, even 11-character simple passwords like 'password123' can be trivially cracked, and as the number of…

I recommend all my friends and family to use a password manager like Bitwarden, and if they can't do that for some reason, at least use a 3-word passphrase separated by a hyphen.

The amount of times people have complained to me that this doesn't work because of low max-chars on passwords is insane.

Re: GrapheneOS – Break Free from Google and Apple

#435
post #319

Earlier quoted context omitted.

I hope and pray that is a Samsung S Ultra device. The built-in stylus transforms the whole user experience, I would not go back to a device that I must swipe my dirty fingers across.

I’m just imagining myself pulling out the stylus on the train/plane, dropping it, and watching it roll away forever.

The Palm Pilot experience. But that stylus was required for operation. Fortunately, just a plastic stick, so 3-pack replacement were cheap.

Re: GrapheneOS – Break Free from Google and Apple

#436
post #271
post #66

Earlier quoted context omitted.

> I wish banks would do something and support NFC payment systems that don't require the device to be controlled by Google There are countries where it's possible to pay everywhere with the banking app scanning a QR code. No need for NFC :-).

The point of NFC-on-a-phone is that you don't need the damn banking apps and internet and retailer support for all that to validate a simple transaction. My credit card has NFC, no internet and no app, and it's universal.

> you don't need the damn banking apps

You need the Google/Apple app though, don't you? Or can you write your own personal app that will handle that?

Re: GrapheneOS – Break Free from Google and Apple

#437

Earlier quoted context omitted.

Your password must be between 8 and 12 characters, and must have lowercase, uppercase, numbers, and punctuation. Pick up the can!

Having more than just alphanumeric characters widens the domain of the password hash function, and this directly increases the difficulty of brute-force cracking. But having a such a small maximum password length is... puzzling, to say the least. I would accept passwords of up to 1 KiB in length. With rainbow tables, even 11-character simple passwords like 'password123' can be trivially cracked, and as the number of…

I bet the rationale would be "anything over 12 characters will be too hard to remember and people will just write down the password."

Re: GrapheneOS – Break Free from Google and Apple

#438

Earlier quoted context omitted.

Your password must be between 8 and 12 characters, and must have lowercase, uppercase, numbers, and punctuation. Pick up the can!

Having more than just alphanumeric characters widens the domain of the password hash function, and this directly increases the difficulty of brute-force cracking. But having a such a small maximum password length is... puzzling, to say the least. I would accept passwords of up to 1 KiB in length. With rainbow tables, even 11-character simple passwords like 'password123' can be trivially cracked, and as the number of…

It's easier for me to remember really long passphrases than even short alphanumeric strings - small maximum password lengths set my teeth on edge. The passwords should be getting hashed anyway right?

Re: GrapheneOS – Break Free from Google and Apple

#439

Earlier quoted context omitted.

Oh how I fucking wish "security" wasn't a stupid cargo cult checkbox list 3/4 of the times. Unfortunately, the rot runs too deep.

Your password must be between 8 and 12 characters, and must have lowercase, uppercase, numbers, and punctuation. Pick up the can!

Haha having such a low range of max chars just makes it that much easier to brute force doesn't it?

On password length, I once had an account on Aetna that let me put whatever I want for my password, so I used a three-word passphrase that bitwarden generated for me. It ended up being like 20 chars.

Then I tried to log in with that password. Whooosies, the password input only allowed max 16 chars!

Ended up using a much less secure password because of this.

Re: GrapheneOS – Break Free from Google and Apple

#440

Earlier quoted context omitted.

Having more than just alphanumeric characters widens the domain of the password hash function, and this directly increases the difficulty of brute-force cracking. But having a such a small maximum password length is... puzzling, to say the least. I would accept passwords of up to 1 KiB in length. With rainbow tables, even 11-character simple passwords like 'password123' can be trivially cracked, and as the number of…

I recommend all my friends and family to use a password manager like Bitwarden, and if they can't do that for some reason, at least use a 3-word passphrase separated by a hyphen. The amount of times people have complained to me that this doesn't work because of low max-chars on passwords is insane.

One time I had to reset my password with the power company - they had such a system, and the lady had to read me something like:

Uh4zB4DP55WD!

Apparently I was a bit salty with the system when I set it.

The fact that she shouldn't have even been able to look up the password in the first place due to hashing was lost on her.

Post reply on HN