Live data from Hacker News

Reclaiming Mobile Privacy with GrapheneOS

xn--gckvb8fzb.com

61–70 of 80 posts

Re: Reclaiming Mobile Privacy with GrapheneOS

#61
post #50

Few notes: - some crapplications do not want to run on custom rom - more than mere mobile privacy I'm MUCH worried about new cars (witch happen to be mobile crapware connected crap)... As a small dumb example, I've got my new EV, formally already fitted by default of crappy surveillance contracts with some vendors "pre-payed" and I have to unsubscribe to them all one-by-one. Car itself is a mobile OS, connected to th…

> - some crapplications do not want to run on custom rom

If you need help getting apps working, please ask on https://discuss.grapheneos.org/ or #grapheneos:grapheneos.org on Matrix. We'll be happy to help you get them working and if they aren't working we'll fix the remaining rare compatibility issues. Nearly every application works on GrapheneOS if you install the sandboxed Google Play compatibility layer and make use of the per-app exploit protection compatibility toggle for apps with memory corruption bugs. The compatibility mode doesn't reduce OS security, it just disables certain features protecting the app itself against attackers. We may eventually maintain a list of apps requiring the compatibility mode to do this for major apps like Among Us automatically. Also, note some apps require dependencies like Google Play Games which aren't installed for you automatically.

Re: Reclaiming Mobile Privacy with GrapheneOS

#62
post #26

Earlier quoted context omitted.

You can just use any other camera app. I use the Google Camera on my Pixel 6.

OpenCamera is great, but there's no substitute for the stock one that's tailored to the phone hardware.

GrapheneOS uses our own camera app, not Open Camera. Our camera app supports HDR+ for images and HDRnet for videos on Pixels along with zoom-based multi-camera on devices with support for it in 3rd party apps including Pixels and current generation Samsung phones. It has Night, Portrait and HDR modes on Samsung phones. Pixels don't provide those CameraX extensions yet, but they provide HDR+ / HDRnet for it in the normal Camera and Video modes. Our app also supports optional EIS. It's not as featureful as Google Camera or Samsung's camera app but it's getting better, and you don't have to use it.

Google Camera works fine as a sandboxed app on GrapheneOS. You can install GSF as a regular sandboxed app alongside Google Camera and use it. Google Photos works fine too. You can disable the Network toggle for all 3 apps if you'd like.

https://grapheneos.org/usage#camera has more information on these topics, although it needs to be updated for recent improvements in our Camera app.

You don't need Play services or the Play Store for Google Camera, but you can use those as part of our sandboxed Google Play feature on GrapheneOS to run nearly all apps from the Play Store.

https://grapheneos.org/usage#sandboxed-google-play

Re: Reclaiming Mobile Privacy with GrapheneOS

#63
post #56
post #26

Earlier quoted context omitted.

You can just use any other camera app. I use the Google Camera on my Pixel 6.

I tried the google camera app on GrapheneOS and can't make it work, in CalyxOS it just works

Google Camera works perfectly on GrapheneOS, and unlike CalyxOS runs as a regular sandboxed app. It's as simple as following our instructions and installing GSF from our app repository followed by Google Camera:

https://grapheneos.org/usage#google-camera

You can revoke Network from Google Camera and GSF if you'd like. Google Photos works that way too. None of those need Play services and the Play Store, but you can use Play services and the Play Store as regular sandboxed apps on GrapheneOS. GrapheneOS has MUCH broader app compatibility than CalyxOS and without making the privacy/security sacrifices it does to integrate microG into the OS. CalyxOS has privileged Google services integration built into the OS so you don't need to install anything, but installing apps from our app repository and getting far broader app compatibility with fewer sacrifices isn't a problem for users.

CalyxOS isn't a hardened OS. It substantially reduces security rather than improving it. They roll back the security model and go months without shipping the baseline Android privacy/security updates. They shipped half the August and September security part of the way into October including multiple critical remote code execution vulnerabilities. This happens every year and throughout the year. It's not simply not hardened but not a safe option even for people not focused on privacy/security. Providing proper security updates is the bare minimum. There are still missing security patches with it today, and they're still downplaying and misleading users about it. Just check their recent news posts announcing the August and September updates while admitting they aren't providing half of them. Note: what they say about providing all the open source patches is wrong, since lots of what they skipped was open source, and the updates they skipped were mostly more important than the ones they shipped.

Re: Reclaiming Mobile Privacy with GrapheneOS

#64
post #55
post #26

Earlier quoted context omitted.

You can just use any other camera app. I use the Google Camera on my Pixel 6.

I was using whatever app launches when double clicking the lock button. I don’t think the issue was with the specific app launched, but with the system to launch it.

Please read https://grapheneos.org/usage#exec-spawning. You can choose not to use this feature if you can't tolerate up to a 200ms delay for cold start app spawning. Application spawning on GrapheneOS is as fast as the stock OS when using the standard Android app spawning system. We give users a choice.

Re: Reclaiming Mobile Privacy with GrapheneOS

#65
post #17

Earlier quoted context omitted.

The background story of the project is quite sad, so it sort of makes sense that he is very defensive of it. (The project got some monetary support initially from a company, which later tried to hijack the whole open-source project (going by copperhead os nowadays, I believe). Fortunately thanks to Micay the original was unharmed (he revoked private keys, big kudos!), but they do throw shade at GrapheneOS promoting t…

Quoted post unavailable.

GrapheneOS was started in 2014 and was previously known as CopperheadOS. I co-founded the Copperhead company in 2015 and I still own half of the shares today, which gives me 50% control over the company. GrapheneOS (formerly CopperheadOS) remained an open source project under my control and ownership, not the company we founded to sell services and devices based on the project. Unfortunately, my former business partner decided to unilaterally take over the company and manage it in his interests. He tried and failed to take over the open source project. Edward Snowden was one of the CopperheadOS users who helped me defend the project against the takeover attempt and helped to fund the continuation of the project under the Android Hardening and then GrapheneOS brand names. He helped me get a lawyer via the EFF and is the reason I continued the project instead of giving up and moving on. You're spreading talking points from a scammer who chose a Raytheon contract requiring access to the signing keys for GrapheneOS (CopperheadOS) over fulfilling the company's commitments to the open source project it was supporting, and to me as a co-owner of the company with equal voting rights. Again, I still have those shares. I'm speaking as 50% owner of Copperhead and one of the 2 co-founders of the company, which was founded in late 2015, a year after the open source project was started. Note: there was a 3rd co-founder who my former business partner pushed out of the company early on and didn't give shares they were probably entitled to getting, and that person (Daniel McGrady) supports me.

Today, CopperheadOS is used as a brand by that company for a completely closed source fork of legacy GrapheneOS code. They don't develop anything of value and simply take our code months or years later. Anyone who looks into it can see that the Git repositories from 2014/2015 belong to the GrapheneOS organization and are the repositories we're using today. We still have the legacy issue tracker for mid-2018 and earlier too:

https://github.com/AndroidHardeningArchive/legacy_bugtracker

Ask Edward Snowden if he thinks I did the right thing by protecting him and other GrapheneOS (CopperheadOS) users from James Donaldson. The vast majority of users / customers supported me and continued supporting GrapheneOS afterwards. Only a tiny number of people supported Copperhead and most of the people they duped were people who discovered it post-2018 based on them pretending to have made my project and pretending to own the legacy code, which they don't, and they've already lost that battle. Why did the legal battle not go their way if they were in the right? ...

Re: Reclaiming Mobile Privacy with GrapheneOS

#67

GrapheneOS is a very nice mobile OS - I use it on multiple devices and its my top pick for android ROMs. Some thoughts: 1. They're the only ROM project that actually focuses on improving application level safety. This is a bigger deal than a lot of people realise. 2. They offer installation remote attestation - again, worth using if you can. 3. Lots of drama with Calyx and GrapheneOS which is very hard to familiarise…

Note: GrapheneOS is simply an OS. It's currently available as an aftermarket OS but will be available on devices built to run GrapheneOS eventually. It's not a ROM and we don't use that incorrect terminology. It's needlessly confusing to end users unfamiliar with that jargon from the Android modding community and it's also wrong. There are ROMs included on the supported devices such as the SoC boot ROM and other boot ROMs so it's important to use the terminology correctly due to the relevance to things we work on like verified boot and attestation.

> 3. Lots of drama with Calyx and GrapheneOS which is very hard to familiarise with. This is because the discourse is often deleted (this is the policy of the Graphene OS chatrooms) and so it is difficult to verify claims without pointing to another instance of deleted comments/purported harassment. If you can help it, I recommend to just try ignore the whole thing until they start screenshotting the actual harassment.

You can see the usual clearly inaccurate talking points from several of them in this thread including one of them making personal attacks and fabrications about me with their comment buried at the bottom. We've posted lots of information and proof including screenshots of harassment. Look at my personal @DanielMicay Twitter account where you can see blatant harassment from @maxtannahill, a Calyx reseller working with them and participating in their communities / private groups. He's openly a neo-nazi and I linked a post of his on Twitter where he openly engages in holocaust denial, but there's a lot more where that came from. You can look at what the Calyx devs/leadership were doing in their chat room yesterday, happily talking with someone who has repeatedly called for me to kill myself and spreading misinformation about myself and GrapheneOS with them. What proof is missing for you? We've posted screenshots / logs of their developers repeatedly calling me "crazy", "delusional", "schizophrenic", etc. as part of that consistent, pervasive bullying they've started across platforms.

> 5. You may see people kick up a shit about how Graphene uses sandboxed play store and how that's a bad thing somehow. If you are worried, keep in mind you can still use Aurora if you want your install to be anonymised (but frankly I am not sure what the extent of the changes that Aurora makes). Similarly F-Droid is available, but is super weird about how they sign apps.

It's an optional feature: the ability to run Google Play in the full standard app sandbox. It's the same sandbox used for every other user installed app and it's not clear why that would be concerned. The feature we provide is a compatibility layer which teaches Play services and the Play Store to work within the standard app sandbox by reimplementing all the privileged functionality they try to use with unprivileged implementations. Since they run as regular sandboxed apps, they simply get an exception / error if they try to use functionality that's not yet stubbed out or reimplemented. It's not a special sandbox, and we give them absolutely zero special access or privileges. People are running Google Play code inside apps like Tinder and Discord since those include the Google Play SDK / libraries, and those apps run in the same sandbox. No permissions need to be granted to sandboxed Google Play to have 99% of the functionality working well, which is more than can be said for most apps.

Re: Reclaiming Mobile Privacy with GrapheneOS

#68
post #56
post #26

Earlier quoted context omitted.

You can just use any other camera app. I use the Google Camera on my Pixel 6.

I tried the google camera app on GrapheneOS and can't make it work, in CalyxOS it just works

It works flawlessly on GrapheneOS, you can even isolate it from your main profile and run it in a second profile with just GSF. Never had any issues with it.

Re: Reclaiming Mobile Privacy with GrapheneOS

#69
post #67

GrapheneOS is a very nice mobile OS - I use it on multiple devices and its my top pick for android ROMs. Some thoughts: 1. They're the only ROM project that actually focuses on improving application level safety. This is a bigger deal than a lot of people realise. 2. They offer installation remote attestation - again, worth using if you can. 3. Lots of drama with Calyx and GrapheneOS which is very hard to familiarise…

Note: GrapheneOS is simply an OS. It's currently available as an aftermarket OS but will be available on devices built to run GrapheneOS eventually. It's not a ROM and we don't use that incorrect terminology. It's needlessly confusing to end users unfamiliar with that jargon from the Android modding community and it's also wrong. There are ROMs included on the supported devices such as the SoC boot ROM and other boot…

Re the use of "ROM", it seems like I used a bad colloquialism rather than a technical term but you make a good point that " aftermarket OS" is a clearer term. Thanks for the suggestion there, I'll do that moving forward.

Re: your response to point 3, I appreciate that engaging with trolls and other harassment is not fun for the person being targeted, so my comment here is not actually targeted at you specifically, but anyone in Graphene willing to help here. Here is what I mean specifically:

Your provided examples are definitely better than the chatlog situation but there is still something that I would like to see different if possible. In each of your examples in your text block, you potentially provide with something I would call documentation, but the format is transient. There is no direct quote and no link.

More explicitly, there is a verbal reference to posts by @maxtannahill (I quickly browsed his twitter but just saw crypto nonsense), but missing are a direct quote with link to the tweets he made. The direct quote means he cannot delete the tweet and delete the wrongdoing, and the link provides a way for third parties to verify claims.

For example, this might look like e.g. "strcat did so and so"[1]. Then in the references section - [1] - quote pulled from https://URLofSpecificTweetInQuestion. Again, it wouldn't be something I'd ask you to do because if it is targeting you in particular, that would be somewhat confronting.

The same issue exists for the harassment you mentioned in this thread. There is a deleted comment by joemazerino, whom I assume is the harasser you are mentioning, and his replies are vague as fuck and slightly hostile (which is suspicious) but his post is deleted so its hard to come into it "fresh". A preemptive direct quote and link in situations like this is ideal.

Re: 5 I think I may have made an error that I need to correct. Based on the sandbox model, does that mean that, other than install and updates, the sandboxed playstore apps are just as private as the Aurora offering? And is there any plans to provide anonymisation for installs and updates moving forward?

Re: Reclaiming Mobile Privacy with GrapheneOS

#70
Grapheme OS is the best OS. I really like the sensor and network permissions they add. It is quite a clean and professional OS with hardening that just works under the hood without getting in your way. It looks amazing with the new material 3 theming. My only regret is that a supported (Pixel) tablet won't be released until 2023. I'll gladly wait for it though.
Post reply on HN