Live data from Hacker News

GrapheneOS has been ported to Android 17

discuss.grapheneos.org

551–560 of 653 posts

Re: GrapheneOS has been ported to Android 17

#551

Earlier quoted context omitted.

The most hilarious is McDonald's app - it refuses to work without Play Integrity check. I wonder what braindamaged reasoning is behind this. Do they want to position themselves as a bank or something?

What would anyone use an app to order food from McDonald's? Just walk into the restaurant, pay cash, and walk out with the food.

McDonald's app (other other similar apps) offer discounts to ordering through their app.

For example, McDonald's has a long running campaign, 99¢ for coffee. Any size, iced or hot.

Re: GrapheneOS has been ported to Android 17

#552

Earlier quoted context omitted.

This is not really about me, but understanding if these apps have issues running under the OS. These type of apps typically have extra "security" features.

Such as? If there is dependency on proprietary software, you can install it on GOS if you want and consider it more "safe".

> Such as? If there is dependency on proprietary software, you can install it on GOS if you want and consider it more "safe".

Again, this isn't about me. I'm fine giving up some convenience, but I know other people aren't. The average person is just going to simply install the app. Part of me asking this questions is gauging average user experience.

Re: GrapheneOS has been ported to Android 17

#553

I took the plunge into GrapheneOS a week ago. I picked up a new Pixel10 Pro and never even tried the stock OS (except to unlock the boot loader). I've got almost everything working the way I want. There were a few non-essential banking apps that won't install. The most annoying problem I had is when I tried to install Strava, which I cannot get working. The app installs, but it will not let me sign in. I guess I need…

The most hilarious is McDonald's app - it refuses to work without Play Integrity check. I wonder what braindamaged reasoning is behind this. Do they want to position themselves as a bank or something?

Fastfood apps typically offer deals to new customers.

I suspect this is an attempt to prevent folks from spinning up many new accounts to get these deals.

Re: GrapheneOS has been ported to Android 17

#554

I took the plunge into GrapheneOS a week ago. I picked up a new Pixel10 Pro and never even tried the stock OS (except to unlock the boot loader). I've got almost everything working the way I want. There were a few non-essential banking apps that won't install. The most annoying problem I had is when I tried to install Strava, which I cannot get working. The app installs, but it will not let me sign in. I guess I need…

The most hilarious is McDonald's app - it refuses to work without Play Integrity check. I wonder what braindamaged reasoning is behind this. Do they want to position themselves as a bank or something?

Also on the homepage: "Volkswagen started blocking GrapheneOS users"

  https://news.ycombinator.com/item?id=48571526

Re: GrapheneOS has been ported to Android 17

#555

Earlier quoted context omitted.

What are the reasons to avoid /e/, according to you? (And not according to the GrapheneOS maintainer).

Because why would you trust an operating system of which the companies CEO says that security hardening is only for criminals and spies? Besides doing many other shady things, like putting a proxy between their App Louge and F-Droid (cleanapk.org), while simultaneously not wanting to reveal who owns/controls that proxy? Remember that Android relies on trust on first use. Or running Google proprietary DroidGuard blobs…

>I could go on for a while

Well I am genuinely interested so I am all for continuing that discussions in details. I am happy to finally meet someone who had a real look and isn't just repeating things read online. So if you have time to share the result of your investigation I'm super interested. But here is not the good place I imagine, where can we continue that discussion?

Re: GrapheneOS has been ported to Android 17

#556
post #523
post #394

Earlier quoted context omitted.

GrapheneOS will eventually have a GrapheneOS RCS app, but for now RCS is fully supported via Google Messages and sandboxed Google Play: https://grapheneos.org/usage#rcs

There have been consistent problems with activating RCS, for many years. But it does work for some/many, yes. And AFAIK they have only been desiring to build their own RCS app, and researching it, but have no concrete plans. It'll probably be extremely hard to do, given how much interaction it requires with individual telecoms, and how large the specs are and how much they change - it'll be signing up for significant…

For what it's worth, strcat is the GrapheneOS founder so they will have a keen insight into current plans.

Re: GrapheneOS has been ported to Android 17

#557

Earlier quoted context omitted.

Nice strawmanning! Obviously I want banks to support alternatives, but I can understand if they only want to support secure OSes. Some banks support GrapheneOS remote attestation besides Google Play Integrity at the strong level.

By your reasoning, 99.9% of people use awfully insecure OSes on desktop and servers. And yet, the world hasn't collapsed. My bank account is not hacked regularly, too (actually, not at all).

This is a personal anecdote and you are making up an absurd conclusion. No one said things would collapse. Security can be evaluated objectively, and the better the security, leads to fewer instances of exploitation. I'm certain the actual data around InfoSec would support that idea.

Re: GrapheneOS has been ported to Android 17

#558
post #556
post #523

Earlier quoted context omitted.

There have been consistent problems with activating RCS, for many years. But it does work for some/many, yes. And AFAIK they have only been desiring to build their own RCS app, and researching it, but have no concrete plans. It'll probably be extremely hard to do, given how much interaction it requires with individual telecoms, and how large the specs are and how much they change - it'll be signing up for significant…

For what it's worth, strcat is the GrapheneOS founder so they will have a keen insight into current plans.

It's always good to be wrong about good news, then :)

I'll definitely be curious about the source code when that happens, and if it'd be reasonable to get it into a SMS-provider-like shape eventually. Particularly since Android's original PoC did that, but it was abandoned for some reason.

Re: GrapheneOS has been ported to Android 17

#559
post #85

Earlier quoted context omitted.

Because AOSP is open source and can be built without Google Play running at the background unlike the other alternative: giving up privacy to yet another big tech Apple. Graphene adds many privacy features on top of regular AOSP. But it only works on phones that has good security features that are not woefully outdated or completely closed-off. Google has complete control over Pixel supply chain and they can make the…

Perhaps you may be interested in GNU/Linux phones, which do not rely on Google in any way.

I have bad news; Do you know who is a major contributor to the Linux kernel? (It's Google)

Re: GrapheneOS has been ported to Android 17

#560

Earlier quoted context omitted.

You have the ability to do what you want on your device. Root access in AOSP is just used as a hacky shortcut to achieving specific functionality. To do it properly while maintaining the security model would be to build it into the OS itself. The same concept applies to desktop platforms and the Librem 5. This isn't related to freedom. That device, and the Debian derivative it runs, are not private or secure.

What do you mean when you say "not private"? Are you accusing the company of sending private data to their servers, as Google and Apple do? Freedom of computing on Librem 5 doesn't end with the root account. It also allows to natively run any desktop software and develop it in any language, without reliance on Google's decision on how one must use the phone, how your OS must evolve and when you may get your updates.…

Maintaining one's data as private requires that it is protected as a baseline. Privacy violations do not solely exist as telemetry or data offered up by the platform to some other party.

The protection is achieved through security. The major goal of something like GrapheneOS is privacy, which needs solid security as a prerequisite.

The blobs, while proprietary, are not opaque. They are able to be examined and they are.

The security of a device should not be dependent on what you choose to run on it. You should trust and be able to verify that the platform on which you are running the software prevents something malicious from accessing data which doesn't belong to it or otherwise violates the rules set by the platform (OS).

In this respect, the Librem 5 would do a horrible job compared to even stock AOSP. Thinking that you are secure because you only run "trusted" software on an insecure platform is cope.

Post reply on HN