Live data from Hacker News

On privacy and control

toidiu.com

51–60 of 132 posts

Re: On privacy and control

#51

As much as I'd love to daily drive an OS like GrapheneOS, the risk of running into apps that use Google Integrity API thereby making it impossible to run those apps on Graphene is too much of an inconvenience. I took a look at this curated list of bank apps[1] supported on Graphene OS and I'm glad that a large majority of them work on Graphene. However, just my luck that one of the banks I use on this list isn't supp…

As someone who daily-drives GrapheneOS, there isn't a single app that I want to use that is broken. I don't see any reason to use regular Android.

Re: On privacy and control

#52
post #19

As much as I'd love to daily drive an OS like GrapheneOS, the risk of running into apps that use Google Integrity API thereby making it impossible to run those apps on Graphene is too much of an inconvenience. I took a look at this curated list of bank apps[1] supported on Graphene OS and I'm glad that a large majority of them work on Graphene. However, just my luck that one of the banks I use on this list isn't supp…

I've seen a couple of apps try to use Play Integrity, get blocked by GrapheneOS, and keep on running. Maybe I'm being locked out of something, but it's not something I use anyway. Note that I don't use banking or government apps. If I bank online it's via the web.

It does seem like a lot of apps continue to function on GrapheneOS after the "Play Integrity" check fails (or at least after Graphene notifies the user that the Play Integrity API has been called). I suspect either:

A) These apps have implemented only the check so far, and will eventually refuse to run or limit functionality at some point in the future.

B) These apps have noted the failure and certain functionality, especially communicating with servers to load "protected" content, will fail even if the app otherwise continues to run.

Re: On privacy and control

#53

As much as I'd love to daily drive an OS like GrapheneOS, the risk of running into apps that use Google Integrity API thereby making it impossible to run those apps on Graphene is too much of an inconvenience. I took a look at this curated list of bank apps[1] supported on Graphene OS and I'm glad that a large majority of them work on Graphene. However, just my luck that one of the banks I use on this list isn't supp…

> As much as I'd love to daily drive an OS like GrapheneOS The Play Integrity shenanigans is mostly on app developers. That said, good thing GrapheneOS will launch its own Android phone: https://discuss.grapheneos.org/d/27687-new-manufacturer-theo... / https://piunikaweb.com/2025/10/13/grapheneos-ending-pixel-ex... / https://www.androidauthority.com/grapheneos-phone-wait-or-bu... Provided GrapheneOS is cleared by Goo…

> The Play Integrity shenanigans is mostly on app developers.

I completely agree, but as a user I'm the victim of the developers choice.

Re: On privacy and control

#54
> can’t be bothered to host my own email

Never host your own email. It’s a nightmare if legacy systems, edge cases, layered on trust systems, malicious actors, and endless spam. It’s a good way to spend a bunch of time and effort making sure most of your mail never gets delivered.

Re: On privacy and control

#55
Somewhat related - I want control over devices in my home. Too many things these days need an internet connection to be useful. I run my own OpenWRT router and set up firewall policies for them so they only get the access they need to provide their function. But I'm getting tired of it.

I'm looking for a nice tool that would give me that "control" over my home network -- at the very least, proper observability. Like "little snitch / open snitch" but running on my home router... and I haven't found anything like that yet.

Re: On privacy and control

#56

Earlier quoted context omitted.

Who cares what the average person will go through and do though? We’re each responsible for ourselves and how we choose to go about life, even if vastly differs from the general population.

Ironically, if your setup is too niche (e.g. browsing privacy configuration) you can be easily tracked, though no one will bother, but captcha's will certainly not miss you.

This is the rub, tech is able to track you based on your browser, viewport size, os, location (a vpn still has a location if you aren’t rotating) and more. I use Firefox for privacy and just that measure alone rules out 97% of internet traffic and zeros down who I am within 3%. How private am I if I default to that 3%. 1440p monitor and a half screen Firefox viewport? Now we’re building an advertising profile!

Re: On privacy and control

#57

As much as I'd love to daily drive an OS like GrapheneOS, the risk of running into apps that use Google Integrity API thereby making it impossible to run those apps on Graphene is too much of an inconvenience. I took a look at this curated list of bank apps[1] supported on Graphene OS and I'm glad that a large majority of them work on Graphene. However, just my luck that one of the banks I use on this list isn't supp…

You're blowing this entirely out of proportion. The vast vast majority of apps work without issue with sandboxed play services. Yes it's less plug and play than a stock os. No it's not a life-ending inconvenience.

Re: On privacy and control

#59

As much as I'd love to daily drive an OS like GrapheneOS, the risk of running into apps that use Google Integrity API thereby making it impossible to run those apps on Graphene is too much of an inconvenience. I took a look at this curated list of bank apps[1] supported on Graphene OS and I'm glad that a large majority of them work on Graphene. However, just my luck that one of the banks I use on this list isn't supp…

Another daily GrapheneOS driver here. I've kept banking apps off my phone anyway, and I do banking via desktop/website (I don't understand why people need to do banking 'on the go') and just use a physical credit card for tap payments when I'm out and about.

I do have older Android devices that I have run banking apps on, that I can revert to if necessary, but there's a fair bit of inconvenience I would be happy to endure to avoid being forced into that final option.

What I would recommend is a slow transition, and just start using it at home. If you have GrapheneOS on it's most paranoid settings (exploit protections) there will be exceptions you'll need to allow for a few apps.

Re: On privacy and control

#60
post #54

> can’t be bothered to host my own email Never host your own email. It’s a nightmare if legacy systems, edge cases, layered on trust systems, malicious actors, and endless spam. It’s a good way to spend a bunch of time and effort making sure most of your mail never gets delivered.

On the other hand, I've been hosting my own E-mail (exim and dovecot) on a $5 VPS for the past 15 or so years, and it's pretty much set and forget. The most maintenance I have to do is when certbot fails to renew my ssl certificates and I have to manually go in and babysit it, but that's certbot/LetsEncrypt's fault, not the E-mail software. I have maybe had deliverability problems twice in those many years.
Post reply on HN