Live data from Hacker News

GrapheneOS is the only Android OS providing full security patches

grapheneos.social

441–450 of 467 posts

Re: GrapheneOS is the only Android OS providing full security patches

#441

Earlier quoted context omitted.

or you could slap a GSM shield on a Raspberry Pi.

As I wrote: that's a MVP, not something you can sell to anyone less nerdy than Richard Stallman, and it's based off of the work of a lot of the people I just spent 58 minutes to think of and write down.

Then you can copy the relevant parts of the designs from both boards onto one smaller board.

Re: GrapheneOS is the only Android OS providing full security patches

#442

Earlier quoted context omitted.

[flagged]

Source:

The source is Apple. They can access any phone if they want to. In this case, they didn't want to.

https://en.wikipedia.org/wiki/Apple%E2%80%93FBI_encryption_d...

Re: GrapheneOS is the only Android OS providing full security patches

#443

Earlier quoted context omitted.

Source:

The source is Apple. They can access any phone if they want to. In this case, they didn't want to. https://en.wikipedia.org/wiki/Apple%E2%80%93FBI_encryption_d...

I don't see anything written there that says Apple has a current capability to "access any phone" which I am assuming to mean personal info like SMS message contents... just a whole lot of reasoning why they haven't had that capability in years.

Re: GrapheneOS is the only Android OS providing full security patches

#444

Earlier quoted context omitted.

Hardware relying on free drivers is almost non-existent in the mobile world. There is nothing to choose from, obviously.

Then aim for freely distributable drivers. You can share copies of Raspbian, so it seems possible.

You mean the Linux distro that exists because it needs to contain broadcom drivers/blobs/etc that are under NDA?

Re: GrapheneOS is the only Android OS providing full security patches

#445

Earlier quoted context omitted.

As I wrote: that's a MVP, not something you can sell to anyone less nerdy than Richard Stallman, and it's based off of the work of a lot of the people I just spent 58 minutes to think of and write down.

Then you can copy the relevant parts of the designs from both boards onto one smaller board.

Good luck getting that to perform. Or even boot. High-speed buses are the darkest of the dark arts to design, at the kind of frequencies particularly PCIe runs even the slightest trace length mismatch, impedance issue with the PCB itself, vias, or even external RF sources can, do and will mess with your sanity.

That's my entire point. It's not easy to design a complex thing such as a smartphone.

Re: GrapheneOS is the only Android OS providing full security patches

#446

Earlier quoted context omitted.

The source is Apple. They can access any phone if they want to. In this case, they didn't want to. https://en.wikipedia.org/wiki/Apple%E2%80%93FBI_encryption_d...

I don't see anything written there that says Apple has a current capability to "access any phone" which I am assuming to mean personal info like SMS message contents... just a whole lot of reasoning why they haven't had that capability in years.

[flagged]

Re: GrapheneOS is the only Android OS providing full security patches

#447

Earlier quoted context omitted.

A company buys laptops for its employees and they get shipped from outside the US, and before they get delivered nice changes have been made. Any specific individual that is high value will walk into a store and buy from stock.

Ok and buys the laptop with malware? How the customs knows that high value target will buy that specific laptop they swapped the ssd? And what they do exactly? Put malware to steal his data?

You are working inside freaking customs and know where it is being delivered. Read between the lines.

Re: GrapheneOS is the only Android OS providing full security patches

#448

Earlier quoted context omitted.

I wonder if a real OEM supports graphene if that would solve device attestation for things like banking apps.

Non-Google attestation is still a bad thing. I'd much rather GrapheneOS continue to get popular enough that banking apps are forced to support phones without attestation.

What do you mean? Graphene OS devices DO support Hardware-based attestation (AOSP standard), they just don't support STRONG or DEVICE Play integrity checks.

Now developers can choose to support it (and some of the developers do!) aside or apart of google "attestation". How it should be, reliable providers should be able to certify it equally firmly.

Google should be forced to accept a valid hardware-attestation certification as their own. GOS have raise the issue with the European Commission and I hope Google will get fined and forced.

in quotes because it mostly confirms that google runs in the privileged mode and can't detect one of the issues. But google also gives a pass to many very old, insecure, rooted devices. It's a scam.

Re: GrapheneOS is the only Android OS providing full security patches

#449
post #295

Earlier quoted context omitted.

Non-Google attestation is still a bad thing. I'd much rather GrapheneOS continue to get popular enough that banking apps are forced to support phones without attestation.

Will never happen. Banks will not support this unless insurance companies include that. And that will never happen because they will never support something that a large company doesn't committ to.

Some do. Don't want to give out names, but it's slowly happening.

Re: GrapheneOS is the only Android OS providing full security patches

#450

Earlier quoted context omitted.

I wonder if a real OEM supports graphene if that would solve device attestation for things like banking apps.

I'm writing this on a grapheneos pixel 5. I have the app for very-large-USbank and a few others. With 'exploit protection compatibility toggle' enabled they works fine. In what regard this applies to device attestation I couldn't say.

It doesn't. The app likely uses one of the others, dumb methods of detection.
Post reply on HN