Live data from Hacker News

Your phone is about to stop being yours

keepandroidopen.org

541–550 of 927 posts

Re: Your phone is about to stop being yours

#541

Earlier quoted context omitted.

> That's mainly because of device trees. Huh? The device tree is the one thing trivially recoverable from the blob. I'm talking about drivers, the same kind as when you install, let's say, the non-free Nvidia driver on a PC. They run as part of the OS and handle various stuff, most commonly comms like VoLTE/VoWiFi, but often also camera ISPs, GPUs, fingerprint readers etc. > are all isolated and sandboxed So isolated…

I see. So it is better in the sense that the drivers are open-source. Though the drivers in Android/GrapheneOS are not open-source, I believe the drivers are also isolated from full kernel-level access. But it still brings the point that you can't make a phone without proprietary chips and firmware from the mobile industry giants. > You want to reflash it before use, obviously. I think that is non-obvious to the majo…

The real question is whether it affects me as a user. The RF spectrum used by cellular networks is highly regulated, so I wouldn't be able to use it freely either way. The PC keyboard I type on right now most likely has some kind of microcontroller running some code in it, but it's of little consequence to me whether it's free or not. I do care about what runs on *my* system though, as that has tangible implications, and I care about it the same way whether it's my laptop or my phone.

> that is non-obvious to the majority of users

Yes, and the consequences of that can be seen in TFA - locking things down due to ill-defined security concerns. Why not go a bit further - the most secure device is the one you can't use to do anything at all.

On a side note, app attestation is already unironically getting us there - you have to either accept that you have no control over "your" device or not be able to use it to interface with the world. For me, any platform that allows applications to attest the environment they run in is insecure by design, as it can be exploited against me.

> An important consideration for consumers is that their data is secure if they lose their phone

Well, it's a good thing that PureOS is LUKS-encrypted by default then. It even has a smartcard reader, so key storage can be decoupled from the phone's hardware.

Re: Your phone is about to stop being yours

#542

Earlier quoted context omitted.

I see. So it is better in the sense that the drivers are open-source. Though the drivers in Android/GrapheneOS are not open-source, I believe the drivers are also isolated from full kernel-level access. But it still brings the point that you can't make a phone without proprietary chips and firmware from the mobile industry giants. > You want to reflash it before use, obviously. I think that is non-obvious to the majo…

The real question is whether it affects me as a user. The RF spectrum used by cellular networks is highly regulated, so I wouldn't be able to use it freely either way. The PC keyboard I type on right now most likely has some kind of microcontroller running some code in it, but it's of little consequence to me whether it's free or not. I do care about what runs on *my* system though, as that has tangible implications,…

>> An important consideration for consumers is that their data is secure if they lose their phone

> Well, it's a good thing that PureOS is LUKS-encrypted by default then.

My bad, I meant leave their phone unattended. Wherein someone can compromise the device from boot, so that when unlocked, the device is fully compromised.

Re: Your phone is about to stop being yours

#543

Earlier quoted context omitted.

Even after Google puts this crap in place, you can still uplodad your own apps to your own Android devices, using ADB. Doing the same for iOS, using Xcode, costs you USD 100 or more (depending on country) per year . I'm in no way defending Google here, just pointing out you're going from bad to worse and think it's a good thing.

Yeah but where you were losing a lot, you're now losing only a little bit. And on the other side, the benefits of using iOS over Android spyware outweighs the cons now.

I haven't seen new data from celbrite in awhile, but I believe that grapheneos was the only truly secure phone from it for both bfu and afu as of a couple years ago.

Apple lost my confidence after they removed Advanced Device Encryption for British users (plus implemented age verification for them).

https://discuss.grapheneos.org/d/14344-cellebrite-premium-ju...

Re: Your phone is about to stop being yours

#544

Earlier quoted context omitted.

Alongside TV we had cameras, and families across the country filming birthdays and other special occasions. Alongside newspapers we had 'zine culture and mail-order pamphlets. There has always been the option to contribute - the Apple iPhone is quite possibly the first exception.

You could film and put it on your tv, but you couldn’t create and distribute to the medium at large

Not with the same reach, but some people kinda could! Specifics depended on where you were in the world, but it existed and to some extent still does. In spite of a very rough decade and a half since 2010 culling many of them.

https://en.wikipedia.org/wiki/Public-access_television https://en.wikipedia.org/wiki/Community_television_in_Canada https://en.wikipedia.org/wiki/Swindon_Viewpoint https://en.wikipedia.org/wiki/Community_television_in_Austra...

Re: Your phone is about to stop being yours

#545

Earlier quoted context omitted.

The real question is whether it affects me as a user. The RF spectrum used by cellular networks is highly regulated, so I wouldn't be able to use it freely either way. The PC keyboard I type on right now most likely has some kind of microcontroller running some code in it, but it's of little consequence to me whether it's free or not. I do care about what runs on *my* system though, as that has tangible implications,…

>> An important consideration for consumers is that their data is secure if they lose their phone > Well, it's a good thing that PureOS is LUKS-encrypted by default then. My bad, I meant leave their phone unattended. Wherein someone can compromise the device from boot, so that when unlocked, the device is fully compromised.

You don't have to lock things down to solve that either - see the measured boot process with Librem Key for an example.

(that said, this is a completely different threat vector that I doubt the common masses actually care about; and if I really had to choose between openness and evil-maid resistance, I'd choose the former)

Re: Your phone is about to stop being yours

#546

Earlier quoted context omitted.

Ah. I see. So the blobs are loaded into the separate microprocessors. Either way, it's the same as pretty much any modern phone, where the modem (and other secondary processors) are running some proprietary firmware and is communicating with the OS processor. I don't see how it's different from running a free open-source ASOP OS. On the mainstream Android devices, the wireless hardware is also isolated and communicat…

Pretty much any modern phone is also full of blobs that run on the main CPU to ensure basic functionality, with only a handful of exceptions. Just consider how many features stop working or get severely degraded on various phones when you use a clean AOSP build on them (provided that you can do it at all in the first place). Android's driver infrastructure effectively encourages non-free blobs in "vendor" partitions,…

> You can have "some debate" on absolutely anything, but that doesn't yet mean it makes any sense.

Sure, but from the fact that anything can be debated it does not follow that any given debate is nonsensical, which is kind of what you did there.

> ...whatever debate you're referring to is unlikely to be held in good faith.

I don't know which is odder, that assertion, or the notion that two completely different security models can't be debated in good faith because they're effectively identical, because of hand-wavy reasons like, "You have communication protocols on top of IOMMUs as well which are subject to exactly the same security considerations as potential exploits in the USB stack..."

Certainly there's some kind of argument to be made that the Librem 5 is relevant to this post as its adherents see it as a viable alternative to iOS and/or Android-based devices. I disagree, but everyone's willing to make different compromises and that's fair.

I only mention that because a contingent of voices as high in volume as they are few in number endlessly shoehorning the Librem 5 into numerous threads no matter how much of a non-sequitur it takes, has me suddenly paying more attention these days to what's coming from the Purism camp. The more I do the more disingenuous the rhetoric seems.

It may just be a coincidence, but for a project with such a fraught history and tarnished reputation, it doesn't do anything to increase my trust in it.

Re: Your phone is about to stop being yours

#547

Earlier quoted context omitted.

I don't know if that is sarcasm, but a chair I buy is mine to do whatever I want with it. Same goes for clothes, a mattress, paint, or any other non-software enabled physical item. Why does having software/hardware make a difference?

Because your clothes and paint do not need security updates, since they do not talk to the internet. Your mattress cannot be made part of a botnet.

Somehow my computer has not become part of a botnet despite having a free OS.

Re: Your phone is about to stop being yours

#548
I have to admit, in ancient times when the googleists could point schadenfreude at the appleists and brag about how open Android was compared to iOS, I was a bit envious. Now that terminal enshittification has infected Android too, I'm not feeling schadenfreude in turn. It's a sad day all around.

Re: Your phone is about to stop being yours

#549

Earlier quoted context omitted.

Or choose freedom. I've been enjoying GrapheneOS for a couple of years now and recommend it.

Do you run into issues with apps not supporting it? Things like banking or auth? That is the main complaint I see for alternative phone OSes, and I don't know if that has gotten any better.

GrapheneOS user here, on my only phone, aka my daily.

I love my phone and when I replace it, I will be flashing GrapheneOS again. This is my second phone with it so far, and roughly year 4 or 5.

With that said, it isn't for everyone. I definitely remember some issues upon first install, a learning curve if you want to call it that. I also introduce intentional obstacles in certain "workflows" in my life that dissuade certain usage, like excessive social media use. With that said, I no longer remember what I introduced myself and what was an OS characteristic. I do remember having frustrations with most banking apps IF I didn't log into the play store mirror. Since I'm "hardcore" and am not willing to sign into a Google product on my phone, they just don't work. However I don't think they would be an issue for most people.

If you are on the fence, you can make a backup of your phone, try it out, and if you don't like it, you can reinstall the default Android and restore your backup. I've done it before when I used my previous GrapheneOS phone for store credit for my next phone, and figured they'd want a factory reset default OS on there.

Re: Your phone is about to stop being yours

#550

Earlier quoted context omitted.

Such is the cost of computing freedom. This line of thinking is analogous to surveillance justifications in meatspace.

The concepts don't need to be at odds with each other. But also, I don't think that "computing freedom" means you get to use other people's computers without consent. Let's be clear here: Google's requirement for ID only applies to apps distributed from their computer. Presuming that you do actually respect computing freedom, I'd guess you'd support them in this. I think a good compromise is that they could permit yo…

> But also, I don't think that "computing freedom" means you get to use other people's computers without consent.

Who said anything like that? This is about being able to install software on your own device.

Post reply on HN