Live data from Hacker News

Your phone is about to stop being yours

keepandroidopen.org

551–560 of 927 posts

Re: Your phone is about to stop being yours

#551

Earlier quoted context omitted.

>> An important consideration for consumers is that their data is secure if they lose their phone > Well, it's a good thing that PureOS is LUKS-encrypted by default then. My bad, I meant leave their phone unattended. Wherein someone can compromise the device from boot, so that when unlocked, the device is fully compromised.

You don't have to lock things down to solve that either - see the measured boot process with Librem Key for an example. (that said, this is a completely different threat vector that I doubt the common masses actually care about; and if I really had to choose between openness and evil-maid resistance, I'd choose the former)

I think the common masses just expect it in the first place. If you told someone that leaving their phone unattended could lead them to getting their data stolen, they would probably be surprised. I know this isn't a surprise to the HN crowd, but it is for regular people.

I would also guess that the common masses would choose the opposite as shown by them choosing convenience over openness. It's convenient to not have a separate key to prevent evil-maid attacks.

Re: Your phone is about to stop being yours

#553

>Android's openness was never just a feature. It was the promise that distinguished it from iPhone. Millions chose Android for exactly that reason. Google is now revoking that promise unilaterally, on devices already in people's pockets, because they've decided they have enough market dominance and regulatory capture to get away with it. This is why I've stuck with Android for the past 15 years.

This is a very HN view of Android. The "openness" of Android was for mobile device manufacturers, not app developers and end-users. Android's prominence was driven by the myriad of low-cost Android devices by multiple device manufacturers, whereas iOS is only available via iPhones. The vast majority of users don't care about "openness" of the OS. They care about the utility of their phone in everyday life. Can I acce…

When a platform ditches openness, you lose more than a seemingly insignificant market segment that makes no money. Using money as the only metric is stupid and myopic.

Re: Your phone is about to stop being yours

#554
post #234
post #68

This change has served me well! I have been a Mac OS X users for years who used an android phone. As soon as google announced their impending walled garden status, I went out and bought into the ios eco system. I have really been enjoying my iphone, ipad, and apple watch. You see, the only value that Android really offered me was the ability to run my own code on my own device. Since they are taking that away that ju…

> stop being yours As if most android maker phones don't already fully own your device - preventing you from unlocking of bootloader and installing an OS that actually doesnt enforce the restriction google is introducing in their flavour of android. To pretend that with this change android becomes exactly like iOS is... ridiculous? I can pick any 10yo old android phone from my drawer and develop for it, no problem an…

It's the slippery slope that's the issue, 24hrs is just the first iteration of the restriction. After couple of iteration of restrictions, they could force everyone to have govt-id approved by goog to install any app.

Re: Your phone is about to stop being yours

#555

Earlier quoted context omitted.

> the vastly superior apple experience After switching away from GrapheneOS to iOS after RCS stopped working for me, I can safely say my experience has been the opposite. The camera is the only thing better for me on iOS - everything else is buggier and worse. A few of my favorites: 1. Safari is buggy as hell, and requires installing apps to run things like ad blockers. 2. The settings are ALL over the place and very…

I'm considering switching to GrapheneOS... What's this about RCS not working?

RCS is proprietary so it only works on GrapheneOS if you have Google's Messages app. At least, that was the case a year ago, but I'm assuming it hasn't changed.

On the bright side, Messages works without linking to a Google account

Re: Your phone is about to stop being yours

#556

Earlier quoted context omitted.

You don't have to lock things down to solve that either - see the measured boot process with Librem Key for an example. (that said, this is a completely different threat vector that I doubt the common masses actually care about; and if I really had to choose between openness and evil-maid resistance, I'd choose the former)

I think the common masses just expect it in the first place. If you told someone that leaving their phone unattended could lead them to getting their data stolen, they would probably be surprised. I know this isn't a surprise to the HN crowd, but it is for regular people. I would also guess that the common masses would choose the opposite as shown by them choosing convenience over openness. It's convenient to not hav…

[deleted]

Re: Your phone is about to stop being yours

#557

Earlier quoted context omitted.

I see. So it is better in the sense that the drivers are open-source. Though the drivers in Android/GrapheneOS are not open-source, I believe the drivers are also isolated from full kernel-level access. But it still brings the point that you can't make a phone without proprietary chips and firmware from the mobile industry giants. > You want to reflash it before use, obviously. I think that is non-obvious to the majo…

The real question is whether it affects me as a user. The RF spectrum used by cellular networks is highly regulated, so I wouldn't be able to use it freely either way. The PC keyboard I type on right now most likely has some kind of microcontroller running some code in it, but it's of little consequence to me whether it's free or not. I do care about what runs on *my* system though, as that has tangible implications,…

> Why not go a bit further - the most secure device is the one you can't use to do anything at all.

That's not far off a reasonable criticism of Purism's security model, that a device so wholly compromised it requires one to activate all physical kill switches to disable the hardware in order to so much as safely enter one's device PIN (per Purism's own site content), that it's no longer useful.

Everyone has to make their own trade-offs, but for me that's a model so questionable that its utility value rapidly approaches zero.

Re: Your phone is about to stop being yours

#558

Earlier quoted context omitted.

This is a very HN view of Android. The "openness" of Android was for mobile device manufacturers, not app developers and end-users. Android's prominence was driven by the myriad of low-cost Android devices by multiple device manufacturers, whereas iOS is only available via iPhones. The vast majority of users don't care about "openness" of the OS. They care about the utility of their phone in everyday life. Can I acce…

When a platform ditches openness, you lose more than a seemingly insignificant market segment that makes no money. Using money as the only metric is stupid and myopic.

> When a platform ditches openness, you lose more than a seemingly insignificant market segment that makes no money.

Openness for users/consumers was never a goal for the Open Handset Alliance.

> Using money as the only metric is stupid and myopic.

Publicly traded companies will be publicly traded companies.

Re: Your phone is about to stop being yours

#559

Earlier quoted context omitted.

> This is a very HN view of Android. Just because you're HN dweller doesn't make it HN view. The openness, freedom, customizability and accessibility (money wise) were the tenets that differentiated Android from Apple devices.

Android is developed by the Open Handset Alliance, a consortium of mobile industry giants . https://web.archive.org/web/20260420021444/https://www.openh... Openness for end-users was never a tenet. It is a very HN view to think that open-source equals freedom for users, and to state that it was a promise when it never was.

Freedom for users was the motivating factor that created open source in the first place. Rewriting history to serve your own ends doesn't help your credibility.

Re: Your phone is about to stop being yours

#560

Earlier quoted context omitted.

You don't have to lock things down to solve that either - see the measured boot process with Librem Key for an example. (that said, this is a completely different threat vector that I doubt the common masses actually care about; and if I really had to choose between openness and evil-maid resistance, I'd choose the former)

I think the common masses just expect it in the first place. If you told someone that leaving their phone unattended could lead them to getting their data stolen, they would probably be surprised. I know this isn't a surprise to the HN crowd, but it is for regular people. I would also guess that the common masses would choose the opposite as shown by them choosing convenience over openness. It's convenient to not hav…

To be frank, I'm tired of this security theater. Yes, let's lock things down to prevent evil-maid attacks and bring in the technological dystopia in the process, who cares that the same evil maid could put your finger onto the fingerprint sensor and unlock the phone while you sleep without ever fiddling with the bootloader.

"The masses" used to use completely unencrypted devices for decades. That doesn't mean they don't deserve security, but it's up to us, the technologically savvy ones, to determine how to implement it and which trade-offs are worth making to provide it. The term "security" only ever has any meaning when paired with a threat model, and some threats are more plausible than others. Some people will absolutely require proper evil-maid resistance, some wouldn't care the slightest. The common masses would be equally surprised if you told them that they can't change the boot animation on their phone without preventing access to their bank app, so go figure.

Post reply on HN