Live data from Hacker News

GrapheneOS – Break Free from Google and Apple

blog.tomaszdunia.pl

461–470 of 967 posts

Re: GrapheneOS – Break Free from Google and Apple

#461
post #119

Earlier quoted context omitted.

Thanks for the Norwegian perspective. I agree that the locking down is truly stupid. For what it’s worth, the reasoning for locking down mobile apps is allegedly that mobile users are a less technologically competent demographic than desktop users. I do not think so myself, given the difficulty in trying Graphene vs. Desktop Linux.

I agree that the locking down is truly stupid. I don't agree that it is stupid. Both banking on a Windows PC or on an unlocked + rooted phone is potentially catastrophic. Windows because of the prevalence of malware, unlocked phones with custom AOSP forks because people download 'ROMs' (as they call them) from the most shady sites. Once 10,000s of Euros are siphoned from a bank account, it's usually the bank that has…

Needing to use a verified boot chain with keys that the bank trusts is essentially the same as using the authenticator device from said bank, except this one costs 100€ or more, has a microphone and camera built in, and you use it for private messages as well. That's not a future I want to live in

We have secure hardware already, it's called a smartcard and is what you find in all bank cards, SIM cards, authenticator devices... my phone is my phone, not a second factor, or at least I (as a hacker/tinkerer) don't want it to be that way, just like with my desktop which is also not the bank's to mandate whatever from

Somehow they got the memo for devices where it is normal to have admin permissions, but for mobile devices the two big tech companies successfully scaremongered non-techies

Re: GrapheneOS – Break Free from Google and Apple

#463
post #382

Earlier quoted context omitted.

Can the PIN change? How to issue new key if needed? How does it integrate with the voting?

> Can the PIN change? You can change it in the app, yes. > How to issue new key if needed? I think you’ll have to reissue your ID. There’s also digi-ID (similar e-signature certificate on a card, but without any ID features), Mobiil-ID (e-signature on a SIM-card, no idea how it works), Smart-ID (in app, tied to secure storage in Android/iOS, cross-signed by the server which is supposed to check the device somehow) an…

> You can change it in the app, yes.

Is the app tied to Google or Apple?

Re: GrapheneOS – Break Free from Google and Apple

#464
post #285

Do they just not have ANY screenshots of the OS anywhere on the web site

It is just Android. If you're familiar with the usual Material styling of Android, you're familiar with what Graphene looks like.

If they'd put a screenshot, that would then have been immediately clear to casual visitors.

My initial assumption was "this is gonna look like a typical OSS product, and not as polished as iOS or Android". A single screenshot would have dispelled that notion.

Re: GrapheneOS – Break Free from Google and Apple

#465

Earlier quoted context omitted.

I bet the rationale would be "anything over 12 characters will be too hard to remember and people will just write down the password."

I think we (whoever we is) should start normalizing the concept of passphrases; on sign-up screens they should show the benefits of a passphrase. I'm surprised that Googles PW generator does not use passphrases, and I don't know about ios because I haven't tried theirs yet. I started using passphrases after I saw this xkcd https://xkcd.com/936/ When I'm trying to log into something on a device that has a terrible key…

correct horse battery staple; knew it before I clicked the link.

Re: GrapheneOS – Break Free from Google and Apple

#467

Been using this for about a year on a p9 pro. It works very well. I hear the google tap to pay does not work, but I've never tried it. However Vipps with their tap to pay works fine. BankID works but not with biometric login, which some things require IIRC. And for some reason DnB private works fine, but you are not allowed in on the corp app. It's mind boggingly stupid that they lock down apps like this, when you ca…

> It's mind boggingly stupid that they lock down apps like this, when you can just open the thing in a website anyway. I can use my bank on some linux distro, crazy that they trust me since it is not Windows - the truly secure OS!

I'm worried the day will come when some sites will require, even on a computer, a full-chain verification from the bootloader to the OS, all the way down to the browser. By requiring that each of these elements be digitally signed so that if you're not on a "secure" platform, from the bootloader to the browser, sites such as home banking could restrict access. Imagine not being able to login to your home banking because your linux box is rooted.

Btw, the good old days of modding are gone...

Re: GrapheneOS – Break Free from Google and Apple

#468

Earlier quoted context omitted.

Yeah that's the first thing a pentest will complain about, had the same problem too. I pushed back enough so that it's trivial to bypass but the bank and pentesters also agreed with me that it's security theater or else I would never had the chance.

I always ask them if they have root/admin on their computer. Then follow up playing dumb with "shouldn't we lock out PCs too?". Watching them stammer is worth the 30 second aside.

> Then follow up playing dumb with "shouldn't we lock out PCs too?".

Unfortunately, some banks do, for various functionality; there are many things you can do via bank apps and not typically via their website.

Re: GrapheneOS – Break Free from Google and Apple

#469

Earlier quoted context omitted.

I like Organic Maps because it isn't full of the social things. Every time I open Google Maps it shows that card at the bottom with "what's popular in your area", full of pictures of people's breakfasts and other nonsense. Organic Maps is free of this noise. Also, the desktop client on Linux is quite useful. Alternatives for Windows etc. are Cruiser Maps, a Java application (and also available as an Android app).

All map apps I tested so far were kind of usable but nowhere near Apple or Google maps. Especially for longer trips I often got lost and had to re-navigate by different reasons (voice announcement too late, no lane instructions, etc.). However, I listed it because it is a "usable" alternative that works offline.

Idk, pedestrian navigation has been pretty decent for me so far. (There’s been one case of it showing a path in Tbilisi that would require me to jump from a 3 m wall, but it was exactly once.) I suppose it depends on which city you’re in and how well mapped it is on the OSM.

Where it’s lacking is POIs – there’s way more stuff on Google Maps, and if I’m looking for some place in particular, I usually go straight to Google, then copy the location over to CoMaps.¹ I then try to add it to OSM when I have the time. Still again, there’s no reviews or photos (in the app; OSM does support photo linking).

Public transit is another problem. It’s usually okay for metro (MRT/LRT/etc), but I wouldn’t trust it with buses just yet.

¹ – yes, there’s been another fork: https://en.wikipedia.org/wiki/CoMaps#History

Re: GrapheneOS – Break Free from Google and Apple

#470
post #135

Been using this for about a year on a p9 pro. It works very well. I hear the google tap to pay does not work, but I've never tried it. However Vipps with their tap to pay works fine. BankID works but not with biometric login, which some things require IIRC. And for some reason DnB private works fine, but you are not allowed in on the corp app. It's mind boggingly stupid that they lock down apps like this, when you ca…

> I can use my bank on some linux distro, crazy that they trust me enjoy it while it lasts. hardware attestation requirement for (at least) banking apps is a question of 'when', not 'if'.

My bank has always had hardware attestation, but it was their hardware that was being attested. Customers get it loaned when signing up

I have no problem with a device that they trust being used for transaction approval, but that device shouldn't also be the device I use for my daily life and do all sorts of private things on. We should want to be able to inspect that one

Post reply on HN