Earlier quoted context omitted.
Every reasonable, independent organization confirms that Manifest V3 is the end of privacy for Chrom(ium) users, e.g., https://news.ycombinator.com/item?id=29502439 https://news.ycombinator.com/item?id=41871873 https://news.ycombinator.com/item?id=44543660 > It restricts and controls the access of extensions much more. You mean, it restricts users even more and gives to websites the freedom to track you? I won't enga…
You link three things, that doesnt equate to "every independent organization". One of your links is a post by Brave and Brave isnt independent in this. The unsubstantiated fear of people for MV3 is beneficial for them, it could grow their userbase because they keep the support for MV2. Content blocking (ad and "tracker" blocking) are convenience features, they dont foundationally improve security. Defining what a tra…
GrapheneOS is the only Android OS providing full security patches
461–467 of 467 posts
Re: GrapheneOS is the only Android OS providing full security patches
#462Earlier quoted context omitted.
Yes, I’m familiar with the case. He was caught interfering with equipment on the MIT campus in order to additionally violate TOS of JSTOR, wasn’t he? He shouldn’t have expected to prevail in court, and I’m saddened by his decision to end his own life. That said, he did a whole lot more besides violating TOS, so I’m not sure how applicable his case is to the topic under discussion, strictly speaking.
The charge of computer fraud was based on the breaking of TOS for MIT and JSTOR
He wasn’t convicted, so that’s not been proved to be against the law in this case, so it doesn’t support the argument you’re advancing in this thread.
Re: GrapheneOS is the only Android OS providing full security patches
#463Earlier quoted context omitted.
I think you're not asking for enough here. A scooter rental app does not need to attest phones. It doesn't even have a bad excuse for wanting to attest phones since payment information is surely stored server-side and it would be surprising if the scooters didn't have their own network connections and GPS trackers.
They kind of do - you can have bad actors messing with scooters. Myself I used GPS spoofer once to park out of the allowed zone (just a few meters, for lulz). There can be people messing with the system, and limiting the OSes that can access your network looks like low hanging fruit. Just like Riot (League of Legends) banned Linux users to "solve" botters. But like with botters, there are better alternatives that don…
I feel like we (that is anyone nerdy enough to post on HN) have been far too patient with people who are choosing to wage a war on general-purpose computing, and it's past time to push back harder.
Re: GrapheneOS is the only Android OS providing full security patches
#464Earlier quoted context omitted.
What exactly are they going to do? Support GNU/Linux?
If Google goes proprietary with AOSP? They could fork AOSP, or go with their own proprietary system (like Huawei is successfully doing). Linux distros (including non-GNU/Linux distros, e.g. busybox/Linux distros) are way behind for smartphones. I don't think they would switch to that.
Re: GrapheneOS is the only Android OS providing full security patches
#465Earlier quoted context omitted.
> You made a general statement about attacks from GOS on GNU/Linux. No, I provided two specific examples, one quoted and another linked to. None of them happend in the context of wrong comparisons being made. > You say you dont trust Google at all. Thats your position. Then my argument is to not trust their code, regardless of which project its submitted to. How is that unreasonable. Your argument is completely unrea…
> No, I provided two specific examples, one quoted and another linked to. None of them happend in the context of wrong comparisons being made. You made a general statement here ("being known for"). You put a link there indeed with a quoted example and another link. > Indeed the GrapheneOS community is known for attacking the GNU/Linux mobile with false claims, https://news.ycombinator.com/item?id=45562484. You have t…
> Thats not an unfounded attack.
Have you got actual arguments and not just personal attack on me combined with the negation?
> completely wrong comparisons between GrapheneOS and GNU/Linux
Can you quote them?
> The statements that those other options are less secure are clearly backed up with technical information.
Which technical information? Security doesn't exist without a threat model, https://www.kicksecure.com/wiki/Threat_Modeling. I don't see one in the posts.
> public source availability just isnt the magic silver bullet you think it is.
FLOSS is certainly better to avoid backdoors, https://www.kicksecure.com/wiki/Malware_and_Firmware_Trojans...
> If the sideload restriction were to be put in AOSP you can remove that in a soft fork.
Until the code changes a lot, which will eventually happen.
> Best to judge individual posts on their merit
You didn't judge their post I linked on its merit. You just replied with a general statement basically saying that everything is complicated.
Re: GrapheneOS is the only Android OS providing full security patches
#466Earlier quoted context omitted.
This is true, and important. Thanks for the reminder. The list linked above (and the price tag deduced from it) is restricted to unlocked phones only for this reason.
There's no way to easily tell that those phones have unlocked bootloaders, though. Ex-Verizon phones may be completely carrier unlocked, will work on any network, and still have locked bootloaders. This isn't an issue for anyone running stock Android, but will restrict those phones from being used to run GrapheneOS.
If you have the IMEI, this will answer whether or not a Pixel is Verizon-sold, and thus, bootloader-locked. https://www.verizonwireless.com/bring-your-own-device/#check...
Re: GrapheneOS is the only Android OS providing full security patches
#467Earlier quoted context omitted.
> Google for one updates their devices for 7 years since Pixel 6 Pixel 8 https://endoflife.date/pixel
Pixel 8 updates end in 2030. Or did you think the 7 years of updates didn't apply to it?