Live data from Hacker News

GrapheneOS has been ported to Android 17

discuss.grapheneos.org

631–640 of 653 posts

Re: GrapheneOS has been ported to Android 17

#631

Earlier quoted context omitted.

By your reasoning, 99.9% of people use awfully insecure OSes on desktop and servers. And yet, the world hasn't collapsed. My bank account is not hacked regularly, too (actually, not at all).

This is a personal anecdote and you are making up an absurd conclusion. No one said things would collapse. Security can be evaluated objectively, and the better the security, leads to fewer instances of exploitation. I'm certain the actual data around InfoSec would support that idea.

My point was about the word "awful", or, as many GrapheneOS supporters say here, "atrocious" security. This is definitely an overstatement.

Otherwise, you're not wrong.

Re: GrapheneOS has been ported to Android 17

#632

But the we need a compact high-end phone for this.

From two months ago: In the USA, I think most people can easily afford a Pixel 9a at $56/year of device support starting from today. Calculator checks yearly cost based on device support: ( https://ibb.co/xq82YQCw ) Sources for device lifetime from calculator: ( https://grapheneos.org/faq#device-lifetime ) I used a New+Unlocked+Pixel+X on eBay to find a rough price of the phone. Most people get scammed by their carri…

It's quite a big phone compared to the S10e.

Re: GrapheneOS has been ported to Android 17

#633
post #28

Earlier quoted context omitted.

I'm in Europe, but I had accepted that I had to do without. I hadn't heard of curve, going to check that out.

the Play store reviews for Curve are attrocious, especially the most recent ones. Looks like Curve is absolutely unusable, for many reasons

I notice that their user identity verification involves "Entrust":

https://help.curve.com/en_gb/your-curve-account-verification...

https://www.entrust.com/products/identity-verification?edc_r...

As the second URL suggests, Entrust used to be called Onfido.

https://uk.trustpilot.com/review/onfido.com

Oh dear...

Re: GrapheneOS has been ported to Android 17

#634

Earlier quoted context omitted.

> What do they need to support to convince you? I know you're already aware of this because it's been provided to you before, but for the folks reading at home, here are the device requirements: https://grapheneos.org/faq#future-devices

You completely missed the context here. my comment was not about skipping the security features of GrapheneOS. The original parent comment was > No, them supporting e/OS corroborates the claim that their goal is not privacy or security. and I asked how they could be convinced about Fairphone's intentions given that the company is tiny and can't develop Pixel-level hardware.

I didn't miss the context.

You can't simultaneously claim (incorrectly) that they're incapable of shipping secure hardware while claiming that they intend to ship a secure and private device. (Maybe Fairphone 7 will be the one.) Even if that is is their intention, they're doing a good job keeping it a secret, as their site's main traffic drivers talk solely about environmental ethics and the climate.

Several companies are shipping devices with worthwhile hardware security, and the standards are fairly well enumerated at the link I provided. If Fairphone's intention is to ship reasonably secure hardware then they're failing miserably at it. Same goes for their choice of OS.

Again, that link wasn't for you. You've been told all this stuff for many years. It's for anyone who trips over the thread without already knowing the sheer tonnage of misleading and often downright factually false statements you continually dump in these threads.

Re: GrapheneOS has been ported to Android 17

#635
post #320

Earlier quoted context omitted.

The kernel drivers are fully open source and moving to new kernel branches is a standard part of the update process. Pixels are currently moving from 6.1 and 6.6 to 6.12 with Android 17 QPR2. This is part of the hardware requirements for GrapheneOS listed here: https://grapheneos.org/faq#future-devices

Are you saying that GraphebneOS running on Google Pixels has no proprietary blobs apart from the firmware?

We don't assume bad faith 'round these parts, so I have to ask a genuine question: Have you been diagnosed with any reading and/or learning disabilities? His comment was straightforward, clear, and three brief sentences long, yet you got something out of it that completely wasn't there.

You ask the same questions again of the same audience, year after year after year, either misunderstanding or totally disregarding the numerous simple, clear and direct answers you receive.

What's going on?

Re: GrapheneOS has been ported to Android 17

#636

Earlier quoted context omitted.

>> Maintaining one's data as private requires that it is protected as a baseline. > So you're conflating privacy with security, as I expected. That's a totally defective reading of their comment. > These are separate matters, although I agree that privacy can't exist without security. He didn't conflate them, he stated something very similar to your formulation above. > not purely on code correctness This assumes a l…

So this comment of yours just states that I'm wrong and the parent is right. I see how you advanced the discussion here. > He didn't conflate them, he stated something very similar to your formulation above. My formulation is not equivalent to "Librem 5 has no privacy", at all.

Again, you're misreading. He stated that security is a necessary condition for privacy, you assumed that he's conflating the two things (he clearly doesn't), then...essentially agreed with his point. It's just totally defective.

My comment, which you accuse of not advancing the conversation, was that your comment was internally incoherent. Like some (not all) of your comments, it sets discourse back significantly and the discussion would be much better off without such things.

You admit to holding a preconceived notion that he thinks security and privacy are the same things, which might have something to do with why you consistently fail to interpret some of even the simplest comments. You'd already reached your conclusion about him and didn't truly read his comment, but responded to your preconceived notion of it as soon as you saw the slightest opening. You do that a lot. It doesn't advance discussion.

You're in the second half of your first decade doing exactly the same thing here year after year with an absolute litany of people, including multiple elite developers who are doing incredibly difficult and important work, highly qualified people whose opinions you completely disregard repeatedly. Searching this site for your old threads shows a certain imperviousness of thought. You already have your talking points and you're not budging from them.

Which is fine, some people are just like that, and I'll continue to weigh in on high-traffic threads to make sure you don't harm important projects with your usual comments, but engaging directly with you is as tedious as it is pointless and I won't be doing that much.

I'm not sure what your motives are, but either way there's no upside to doing anything beyond making sure casual readers of high-traffic discussions won't see your more defective comments go mostly unchallenged (as many others have already wisely moved on from engaging with you).

Re: GrapheneOS has been ported to Android 17

#637

Earlier quoted context omitted.

You completely missed the context here. my comment was not about skipping the security features of GrapheneOS. The original parent comment was > No, them supporting e/OS corroborates the claim that their goal is not privacy or security. and I asked how they could be convinced about Fairphone's intentions given that the company is tiny and can't develop Pixel-level hardware.

I didn't miss the context. You can't simultaneously claim (incorrectly) that they're incapable of shipping secure hardware while claiming that they intend to ship a secure and private device. (Maybe Fairphone 7 will be the one.) Even if that is is their intention, they're doing a good job keeping it a secret, as their site's main traffic drivers talk solely about environmental ethics and the climate. Several companie…

Your accusations and personal attacks already go beyond any limits here. Please stop, as this is explicitly against the HN Guidelines. Especially, without clear links/evidence, as here. Anyone who trips over the thread should know this, too.

Fairphone has a very clear goal of sustainability, which doesn't contradict cutting-edge security per se, but given how tiny the company is, makes it practically impossible. This doesn't mean they wouldn't add the security features if they could. You also like to falsely accuse all vendors producing alternative hardware to Google Pixels, like this one or, earlier, Librem 5 (which btw has the same problem with the small company and big goals).

Re: GrapheneOS has been ported to Android 17

#638

Earlier quoted context omitted.

I didn't miss the context. You can't simultaneously claim (incorrectly) that they're incapable of shipping secure hardware while claiming that they intend to ship a secure and private device. (Maybe Fairphone 7 will be the one.) Even if that is is their intention, they're doing a good job keeping it a secret, as their site's main traffic drivers talk solely about environmental ethics and the climate. Several companie…

Your accusations and personal attacks already go beyond any limits here. Please stop, as this is explicitly against the HN Guidelines. Especially, without clear links/evidence, as here. Anyone who trips over the thread should know this, too. Fairphone has a very clear goal of sustainability, which doesn't contradict cutting-edge security per se , but given how tiny the company is, makes it practically impossible. Thi…

You can't call comprehensive replies "disingenuous walls of text" and then later complain about a lack of thoroughness when people stop finding it worth the time. You've done it extensively with me and others. That's not an attack or accusation, it's there to see with years of history of you doing the same things to people from casual observers (me) to some of the most qualified participants in the industry.

I'm comfortable with others taking in everything and drawing their own conclusions. That's my only motivation for engaging at this point.

For example, Fairphone has something approaching 200 employees. They're punching well below their weight on the security side, both in terms of hardware and software. Defend them all you want but their approach to security is objectively poor. Repairability and sustainability are good concepts, but not if the device fails at being a decently secure device, which it does. If there's a good reason they can't spec out a better device to be made for them and properly support it, I haven't seen them state it. I wish they would because they've made some pretty neat devices over the years. But a neat device with poor hardware security is an absurd build target to burn finite dev hours on. Something which has been explained to you many times.

Purism, on the other hand, likely can't produce a phone that has security remotely approaching any one of a number of contemporary phone options (beyond just Apple/Google). As you say, they're too small and probably spread too thin. They could stand to dial back their claims to match their reality. They still haven't made a dent on significant issues they themselves flagged more than a half decade ago. Its modem runs on a bus so untrustworthy you probably run a disposable sys-usb Qube on your computer. But that's OK, because you only run trusted software, etc. To each their own.

Re: GrapheneOS has been ported to Android 17

#639

Earlier quoted context omitted.

I just moved away from GrapheneOS to Motorola because I decided I needed an audio jack again. There's definitely some annoying things about leaving, but at least now I can use again the three apps that didn't work for me on GrapheneOS...

Which apps didnt work?

Waymo, Philz coffee, Partiful

Re: GrapheneOS has been ported to Android 17

#640

Earlier quoted context omitted.

I just moved away from GrapheneOS to Motorola because I decided I needed an audio jack again. There's definitely some annoying things about leaving, but at least now I can use again the three apps that didn't work for me on GrapheneOS...

I use usb-c dac and it is honestly fine. you can get one with charging bypass and keep that one with the charger

I've gone through about 5 USB-C adapters which eventually broke inexplicably. They also have extra noise in the audio when the volume is low for some reason.
Post reply on HN