Live data from Hacker News

GrapheneOS has been ported to Android 17

discuss.grapheneos.org

501–510 of 653 posts

Re: GrapheneOS has been ported to Android 17

#501
post #236

Earlier quoted context omitted.

> MDM managed work profiles Do you mean actual employer-spyware MDM work profiles? I suppose I never expected those to work. Or do you mean things like Shelter, which uses work profiles and which I use to quarantine certain less-trusted apps?

Yes, I mean MDM work profiles. I play an IT guy at work and am a Google Workspace admin. We have it running in BYOD mode and it's actually not intrusive at all. The most sensitive data you can see as an admin is what apps are installed in the work profile, the phone's make + model, and the version of Android. Nothing like location, charge level, or anything outside of the work profile. I'm fine with running it on my…

How to say "I work for a company too cheapass to provide work devices".

Its all fun and games until the company gets hit with a lawsuit and discovery hits your phone and ALL your accounts, corporate and personal.

Re: GrapheneOS has been ported to Android 17

#502
post #91

Earlier quoted context omitted.

Presumably any new Android 17 features that aren't counter to GrapheneOS's mission, such as "Bubbles allows you to turn any app into a compact, floating window" https://blog.google/products-and-platforms/platforms/android...

Does GrapheneOS run on tablets? I don't see a whole chat app (shown in the example) fitting on my phone screen alongside something like a web browser, and the screenshot is from a square screen

Not sure about tablets, but you can connect most of the recent pixels to a display

Re: GrapheneOS has been ported to Android 17

#503
post #406

Earlier quoted context omitted.

The most hilarious is McDonald's app - it refuses to work without Play Integrity check. I wonder what braindamaged reasoning is behind this. Do they want to position themselves as a bank or something?

I recall a year or so ago, there's been a story about someone hacking McDonalds loyalty program, with that app doing something stupid like storing your balance on the client or something. It seems instead of firing whatever offshore sweatshop that made that, they just doubled down on "mitigations".

Was it this it this one by Eaton Works?

https://news.ycombinator.com/item?id=42462354

Re: GrapheneOS has been ported to Android 17

#504

Earlier quoted context omitted.

> Let's say, if I was a bank, I can understand why I would want to block such devices. So as a bank, you would be forcing your customers into the duopoly of the American megacorps. Thankfully, there are banks that do not do this.

Nice strawmanning! Obviously I want banks to support alternatives, but I can understand if they only want to support secure OSes. Some banks support GrapheneOS remote attestation besides Google Play Integrity at the strong level.

By your reasoning, 99.9% of people use awfully insecure OSes on desktop and servers. And yet, the world hasn't collapsed. My bank account is not hacked regularly, too (actually, not at all).

Re: GrapheneOS has been ported to Android 17

#505
post #487

Earlier quoted context omitted.

It's interesting how you are able to conclude that. e/OS is clearly a step up from default Android

Insinuating that real privacy /security is for pedophiles and criminals is primarily what supports my conclusion. It doesn't matter what your marketing says, what's important is what your devices do, and /e/ is much less secure or private than iOS. Attacking GrapheneOS which makes real progress at privsec. Thinking that badness enumeration is effective for improving privacy while ignoring real solutions like improvin…

This German security researcher maintains a comparison table showing the differences between mobile OSes.

https://eylenburg.github.io/android_comparison.htm

Re: GrapheneOS has been ported to Android 17

#506

Earlier quoted context omitted.

Yes, GOS has excellent compatibility with Google. The play services are sandboxed like a normal app and work great.

Does this mean I could install Google wallet? I feel like this would be the only thing really stopping me.

Yes you can install and use it (I hold my passes, tickets and loyalty cards in there), BUT payments won't work for now because Google says malware-ridden Oreo handset is safe and secure, but phone without ad delivery network running in the privileged mode isn't.

There are alternatives for payments (scroll the thread, maybe look up on GOS discussion site).

Re: GrapheneOS has been ported to Android 17

#507

Earlier quoted context omitted.

> I'm not looking to fully de-Google but I want Google as apps and not my OS. This is entirely possible as other posters have explained. But I think it kind of defeats the point of Graphene, at least somewhat. Google is already profiling every aspect of your life by reading your emails, files, calendar, location, etc? In that case, OS access becomes moot. I think that GrapheneOS makes most sense as part of a broader…

What are some good alternatives

The best alternatives are self-hosted, e.g. your own email, CalDAV, CardDAV, and file servers, with e.g. K9 as email client.

Re: GrapheneOS has been ported to Android 17

#508
post #471

Earlier quoted context omitted.

Any issues with banking insurance or healthcare applications?

Chase bank app wont even load on my GrapheneOS lol

From what I recall, you need to enable exploit protection compatibility mode for that app, and it should work just fine.

Re: GrapheneOS has been ported to Android 17

#509
post #12

I've been running GrapheneOS for 7 months now and I'm not going back. When I bought my Pixel 10 last year, I wasn't actually planning on trying Graphene for a while....until I noticed Google had force bundled a 'Wicked For Good' movie promo theme with the latest security update.

I want to run graphene but I make android apps and need to test on device with a somewhat standard setup… login with google, etc. is this reasonable to do with graphene?

Yes. GrapheneOS maintains 99% app compatibility, and the 1% that is lacking is due to apps using incredibly misguided and nonsensical "antiabuse" mechanisms.

GrapheneOS is often better for testing apps due to it being trivial to test with and without google services, most of the hardening options can be used for debugging and provide a crash log to determine what failed, and there is an easily accessible log viewer available in app info.

Re: GrapheneOS has been ported to Android 17

#510

Earlier quoted context omitted.

> Pixel phones are not sold worldwide Still boggles my mind the fact Google doesn't sell their phones worldwide. Obtaining a Pixel has proven to be quite difficult for me.

It still boggles my mind that the most popular privacy OS requires Google manufactured hardware, that fact alone makes me not trust it at all.

GrapheneOS is not going to compromise on hardware security for the sake of spiting one specific company. GrapheneOS supports all viable platforms, and right now that is the pixel lineup. Additional device support requires OEMs step up their game, and so far, only Motorola is up to the task, and we should get Motorola devices with official GrapheneOS support next year.

There is nothing crazy about doing something properly.

Post reply on HN