Live data from Hacker News

GrapheneOS fixes Android VPN leak Google refused to patch

cyberinsider.com

51–60 of 142 posts

Re: GrapheneOS fixes Android VPN leak Google refused to patch

#51
I bought a used Pixel 6 for cheap to try out grapheneos. Can't say I like it. UX of lineageos is much better. There is a weird russian doll kind of situation with the package managers going on. There is one builtin "App Store" with only a few basis programs, one of which is another package manager, accrescent, which offers a few more apps, but still not comprehensive at all, so another package manager is needed for which grapheneos people seem to favor obtainium over f-droid, which I find is another strange decision. I much prefer a fully OSS package manager and there is real value in having people compile from the sources externally, maybe even reproducibly so, instead of trusting the github packages. The grapheneos security model seems oddly centralized to me. I can't really comment on the reported privacy and security benefits.

Re: GrapheneOS fixes Android VPN leak Google refused to patch

#52
post #51

I bought a used Pixel 6 for cheap to try out grapheneos. Can't say I like it. UX of lineageos is much better. There is a weird russian doll kind of situation with the package managers going on. There is one builtin "App Store" with only a few basis programs, one of which is another package manager, accrescent, which offers a few more apps, but still not comprehensive at all, so another package manager is needed for w…

I'm really glad calyxos is starting up again. Grapheneos has a lot of cool technical implementation but there are a lot of things that Calyx seems to do in a simpler, more vanilla Android manner.

Re: GrapheneOS fixes Android VPN leak Google refused to patch

#53
post #39

Side question: what's a good way of getting a GrapheneOS phone? I have been interested in using GrapheneOS but hesitant about actually getting a Pixel phone. Used phone prices are usually >$300 even for "a" series unless I go back several generations. Whether the device bootloader can be unlocked is also a question. I am definitely not ready to spend $449 on a new Pixel 10a.

Refurbished phones are cheap and even going back 3, 4, 5 years you have great hardware, indistinguishable from what you would pay 1000$ new now. 200 or 300$ for a high quality refurbished pixel is really not that bad.

Re: GrapheneOS fixes Android VPN leak Google refused to patch

#54
post #39

Side question: what's a good way of getting a GrapheneOS phone? I have been interested in using GrapheneOS but hesitant about actually getting a Pixel phone. Used phone prices are usually >$300 even for "a" series unless I go back several generations. Whether the device bootloader can be unlocked is also a question. I am definitely not ready to spend $449 on a new Pixel 10a.

> unless I go back several generations

Yeah, do that.

It’ll still be the snappiest phone you’ve ever used.

Re: GrapheneOS fixes Android VPN leak Google refused to patch

#55
post #51

I bought a used Pixel 6 for cheap to try out grapheneos. Can't say I like it. UX of lineageos is much better. There is a weird russian doll kind of situation with the package managers going on. There is one builtin "App Store" with only a few basis programs, one of which is another package manager, accrescent, which offers a few more apps, but still not comprehensive at all, so another package manager is needed for w…

> so another package manager is needed for which grapheneos people seem to favor obtainium over f-droid, which I find is another strange decision

So just download f-droid yourself? Why the fixation on having a definitive, preloaded app store?

>I much prefer a fully OSS package manager and there is real value in having people compile from the sources externally, maybe even reproducibly so, instead of trusting the github packages.

Operating an app store is almost as much work as maintaining an Android fork, and it's hard to fault the authors for not sinking massive amounts of effort into doing it, when there's already f-droid, play store (plus aurora store), obtanium, and many others.

Re: GrapheneOS fixes Android VPN leak Google refused to patch

#56
"In its latest release, GrapheneOS says it has "disable[d] registerQuicConnectionClosePayload optimization to fix VPN leak," effectively neutralizing the attack vector on supported Pixel devices."

"GrapheneOS responded by disabling the underlying optimization entirely in release 2026050400."

GrapheneOS "fixed" the leak by disabling the optimisation

Some HN commenters in the past have praised QUIC and downvoted comments that questioned who QUIC stands to benefit the most

Using QUIC may serve the interests of others but for me the tradeoffs are not worth it; I block QUIC traffic

QUIC is sometimes on by default in software distributed by Google, like Android, and in some cases there is no option to disable it

Re: GrapheneOS fixes Android VPN leak Google refused to patch

#57
post #17

Stock Android is spyware and adware, back in the day we called such software malicious and removed it, now it's the default.

We all agree. But what's the solution? We know 99% of the users don't care. So, the only pressure point is phone manufacturers. I don't have any power to influence anybody significant in this space. I feel helpless.

For me, it's litigation, because the nature of GMS and Play Integrity is highly anticompetitive and these shouldn't even be legal (and most likely already aren't)..

See, mobile phone vendors have their hands tied - they can offer bootloader unlocking, but they can't touch Google spyware, otherwise they won't be "certified", won't be able to use Google Play or even the name Android.. That's of course not enough for Google, they also want to go after users which of such systems / modified systems (with unlocked bootloader) - that's what "Play Integrity" is about, they work hard to make sure the phone gets as useless as possible.. Together those two basically prevent vendors from making the mobile privacy landscape any better.

In the EU, we should outlaw Play Integrity first, by mandating that security level attestation might only be done in a way there's an independent auditing body that might certify alternative operating systems (these could use standard Android attestation) based on objective security criteria, not the Google spyware criteria. I heard about the "UnifiedAttestation" initiative but I'm not sure what's the progress on that.. not that I'm a fan of attestation at all, but you need to understand that it's a different thing when you attest the security model of the system, and a different thing where a system being "secure" actually implies Google spyware must be installed. For banking apps, I'd just want a secure OS, like GrapheneOS - without GMS.

Howver, the main antitrust investigation should happen in the US, only US courts can bring relevant Google executives to justice.

Re: GrapheneOS fixes Android VPN leak Google refused to patch

#58

The issue reported on lowlevel.fun [0] and discussed on GrapheneOS forums [1] does seem like a security issue. It isn't clear why engineers in charge would mark it infeasible as the breach demonstrates more than one failure. 1. A new (albeit "hidden" [2]) network API registerQuicConnectionClosePayload(fd, payload) lets a process set any byte array for the OS to send on its behalf. 2. No ("panaroid networking") permis…

[deleted]

Re: GrapheneOS fixes Android VPN leak Google refused to patch

#59
post #45
post #39

Side question: what's a good way of getting a GrapheneOS phone? I have been interested in using GrapheneOS but hesitant about actually getting a Pixel phone. Used phone prices are usually >$300 even for "a" series unless I go back several generations. Whether the device bootloader can be unlocked is also a question. I am definitely not ready to spend $449 on a new Pixel 10a.

I answered this in another thread: https://news.ycombinator.com/item?id=48076522 Basically, buy a Pixel 6 or later (I suggest Pixel 7 or later, since Pixel 6 will be minimal support soon) that you are sure has an unlockable bootloader . The majority you'll see don't have an unlockable bootloader. Which mostly means either buy direct from Google, or buy one on eBay that already has GrapheneOS/CalyxOS/LineageOS on it o…

I'd say buy Pixel 8 or later, Pixel 8 is the first version with support for MTE, which is a significant security improvement.

Re: GrapheneOS fixes Android VPN leak Google refused to patch

#60
post #51

I bought a used Pixel 6 for cheap to try out grapheneos. Can't say I like it. UX of lineageos is much better. There is a weird russian doll kind of situation with the package managers going on. There is one builtin "App Store" with only a few basis programs, one of which is another package manager, accrescent, which offers a few more apps, but still not comprehensive at all, so another package manager is needed for w…

App store is about as much as you need to decide what to do/where to go for the apps.

Out of the box it has only a launcher and the minimal OS. All the minimalist needs.

If you want more, you get to decide where to go for that.

I call it empowering users, you call it inconvenience, but maybe in that case it's not the best OS for you?

Post reply on HN