Live data from Hacker News

GrapheneOS – Break Free from Google and Apple

blog.tomaszdunia.pl

561–570 of 967 posts

Re: GrapheneOS – Break Free from Google and Apple

#562

Been using this for about a year on a p9 pro. It works very well. I hear the google tap to pay does not work, but I've never tried it. However Vipps with their tap to pay works fine. BankID works but not with biometric login, which some things require IIRC. And for some reason DnB private works fine, but you are not allowed in on the corp app. It's mind boggingly stupid that they lock down apps like this, when you ca…

A collegue of mine was tech lead at a large online bank. For the mobile app, the first and foremost threat that security auditors would find was "The app runs on a rooted phone!!!". Security theater at its finest, checkboxes gotta be checked. The irony is that the devs were using rooted phones for QA and debugging.

Who do we lobby to get this removed from the auditors checklists? This is a solvable problem but it’s political. And if we don’t solve it personal computing is at risk.

Re: GrapheneOS – Break Free from Google and Apple

#563
post #37

Does anyone have a good grasp of the differences between GOS and /e/OS? I'm buying a Fairphone soon and was wondering what both are like

Read this: https://eylenburg.github.io/android_comparison.htm In short, GrapheneOS is vastly superior.

Read the rest of the thread here. The blanket statement is a bit short-sighted (some people might even say 'vastly')

Re: GrapheneOS – Break Free from Google and Apple

#564

I personally tend to own two Phones. One all-day carry GrapheneOS device (Pixel 8) and an older WiFi and at home only iPhone for all payment and ensurance stuff. This is inconvenient in some ways, but at least it is sort of privacy as good as it gets while still being able to run official apps when I need them at home. To de-google the phone, I use F-Droid as primary App store, Aurora as fallback for non-f-droid Apps…

Thanks for this, it's so helpful for people trying out a new platform.

I'd love to have something like this for Linux desktops as well. Maybe a website that has app-lists, where people can then potentially add info about their use cases and reasoning for their choices. Could be a great subreddit!

I tried Omarchy specifically because installed an opionated selection of apps to covered most bases, and it got me started in Arch fairly quickly. I've now completely swapped out all the components so I no longer use Omarchy at all, but it was a great way to get back into desktop Linux after being away for 20 years.

Re: GrapheneOS – Break Free from Google and Apple

#565

I personally tend to own two Phones. One all-day carry GrapheneOS device (Pixel 8) and an older WiFi and at home only iPhone for all payment and ensurance stuff. This is inconvenient in some ways, but at least it is sort of privacy as good as it gets while still being able to run official apps when I need them at home. To de-google the phone, I use F-Droid as primary App store, Aurora as fallback for non-f-droid Apps…

Some other FOSS apps I use daily: Aegis - 2FA ( https://github.com/beemdevelopment/Aegis ) Breezy Weather - A very good looking weather app ( https://github.com/breezy-weather/breezy-weather ) OnlyOffice Documents - MS Office suite replacement ( https://github.com/ONLYOFFICE/documents-app-android ) Fossify Calendar ( https://github.com/FossifyOrg/Calendar ) Fossify Messages ( https://github.com/FossifyOrg/Messages )…

Thanks for the links. I am concerned about supply chain attacks and such with FOSS tools these days. It seems like the easiest attack surface. In my dev opinion it’s not if it’s when. Kinda sucks and I think the adversary is moving faster than the provider. (I have created and maintained public domain software but not currently. Now I’m crapping on the thread sorry. But no one else is sorry for crapping on threads…I need to stop over thinking or maybe just close this tab)

Re: GrapheneOS – Break Free from Google and Apple

#566
post #562

Earlier quoted context omitted.

A collegue of mine was tech lead at a large online bank. For the mobile app, the first and foremost threat that security auditors would find was "The app runs on a rooted phone!!!". Security theater at its finest, checkboxes gotta be checked. The irony is that the devs were using rooted phones for QA and debugging.

Who do we lobby to get this removed from the auditors checklists? This is a solvable problem but it’s political. And if we don’t solve it personal computing is at risk.

Start by calling (or visiting the area office of) your senator and congressman. If you are reasonably articulate, they engage and listen. Doesn't matter if the listener is not a techie; they will ask questions around policy and why it affects constituents.

This is 1000x more useful than online petitions or other passive stuff. Politicians know that one person to have taken the effort to do this, means 1000 others are feeling the same thing but are quiet.

Re: GrapheneOS – Break Free from Google and Apple

#567

Earlier quoted context omitted.

The DSA European digital wallet spec currently requires Google or Apple attestation, so not for much longer. And that is mandated by the EU.

Sigh.

Reputational awareness is what keeps people safe!

Re: GrapheneOS – Break Free from Google and Apple

#568
post #560

Earlier quoted context omitted.

> security hardening first and foremost (above usability or compatibility). Right. Something that GrapheneOS boosters often fail to mention. It's not like those guys at Google are just idiots and don't know how to make a hardened allocator. Android uses a different hardened allocator that is much, much faster and uses less space. GrapheneOS is slower and uses more memory.

I assume this is all technically correct, but in practice I've not noticed any speed difference between stock Pixel and GrapheneOS. Maybe their Vanadium browser when tab switching, that feels slow, but I wasn't planning on being part of the Chromium monoculture anyway so this doesn't matter to me

That's great and, of course, only your experience matters to the choice of which OS you use. I just don't want people to get the impression there are no tradeoffs.

Another tradeoff GrapheneOS makes is because of the way they configure the USB port makes it more possible that you will irreversibly brick your phone by accident. You could say that the USB management is the only really material difference between Android and GrapheneOS when it comes to a law enforcement search threat model, but that also comes with a tradeoff.

Re: GrapheneOS – Break Free from Google and Apple

#569
post #219

Earlier quoted context omitted.

You may be surprised to learn what that "A" stands for.

You may be surprised to realise that you actually don't understand the difference between AOSP and Android :-). See https://news.ycombinator.com/item?id=47047167

I would love if there were a different OS name to designate "Android phones with Google Services snooping in the background" but with the Android Open Source Project being called what it is, I fear "Android" will continue to be understood as a word for either variant

Re: GrapheneOS – Break Free from Google and Apple

#570
post #329

Earlier quoted context omitted.

TOTP not accepted? (When will people learn that biometrics are not another factor: they're entirely public and irrevocable. It's not just security theater, but Apple & Google know that this forces you into their ecosystem, which should be illegal. Of course, Brussels is full of rubes anyway.)

The question is what generated that TOTP code. The banks must ensure that they "are independent, in that the breach of one does not compromise the reliability of the others," as article 4(30) states. That text is vague as hell, but published opinion of the European Banking Authority on the matter[0] is: "a device could be used as evidence of possession, provided that there is a ‘reliable means to confirm possession t…

But they do use apps, and since everything happens on a smartphone - a single point of failure - they aren't independent.
Post reply on HN