Live data from Hacker News

Reclaiming Mobile Privacy with GrapheneOS

xn--gckvb8fzb.com

71–80 of 80 posts

Re: Reclaiming Mobile Privacy with GrapheneOS

#71
post #58
post #36

Earlier quoted context omitted.

(First, strcat, thank you so much for your work on GrapheneOS. I should have a little ETH to send to the project in a few weeks, to make this sentiment a bit more concrete.) Regarding community among people valuing security and privacy... On my most recent big phone/handheld switch, I tried CalyxOS first, but found that I personally preferred GrapheneOS. I think CalyxOS also has its merits. Users of CalyxOS and Graph…

I don't think a highly insecure OS not shipping privacy/security updates for months is even a reasonable choice for people who don't care much about privacy and security. Their site presents standard Android privacy/security features as their own and has news posts claiming to ship security updates where half the patches were skipped, so that's not a reliable source of information to use. They've heavily marketed Cal…

I'm sorry to hear this.

I hope any pressing harm to anyone stops immediately.

If necessary, I think you could get advice from US and Canada lawyers.

Re: Reclaiming Mobile Privacy with GrapheneOS

#72
post #56
post #26

Earlier quoted context omitted.

You can just use any other camera app. I use the Google Camera on my Pixel 6.

I tried the google camera app on GrapheneOS and can't make it work, in CalyxOS it just works

You didn't try very hard then, I could just install it from play store on my Pixel 6

Re: Reclaiming Mobile Privacy with GrapheneOS

#73

Why is it that these projects dedicated to de-Googling, either exclusively or in vast majority, support Google devices? I'd love to run one of them but I bought a Motorola explicitly because it wasn't a Google device.

The reason (afaik) is that you can enroll a developer key and re-lock the bootloader on a pixel, so your phone will check OTA updates against the enrolled key to be sure you didn't get a compromised update. This is not possible on other hardware, I guess.

I also want to be as far away from Google as I can, but I felt as though the hardware was probably a loss leader for goog and worth it to me for what I would gain.

Re: Reclaiming Mobile Privacy with GrapheneOS

#74
post #34
post #12

I had to switch back to iOS. My smartphone is my primary camera and I missed lots of important shots because the Graphene camera was so slow to double click launch from locked (on a flagship pixel $LATEST pro max whatever). I really miss syncthing.

You can speed up app launching by turning off the optional exec-based spawning feature. Our camera app also has a Latency mode which recently became the default instead of Quality mode. Google and Apple camera apps essentially always use something resembling the Latency mode, but with lower JPEG quality by default.

What is the benefit of the "secure app spawning" toggle? Also, it would be great to be able to disable this for system apps or per-app (assuming it makes sense in the security model).

Re: Reclaiming Mobile Privacy with GrapheneOS

#75
post #39

I have been using GrapheneOS since April. I have not used any alternatives in a long time (my previous phone was the Galaxy S9): First, let me preface this with the fact that, in my opinion, overall it's a pretty solid OS. After having done research several times, the only other mod I've considered is LineageOS, but last I checked, there were no builds for my Pixel 6 Pro. My biggest two issues with it are that it doe…

>The default camera app is subpar compared to the stock camera app of Pixel phones. I use OpenCamera, but it's also not great (though that opinion might stem from me not knowing how to use it properly).

I've personally found the GrapheneOS camera to be great, and it's what I use 995 of the time on GrapheneOS. I especially like that it has the ability to remove Exif data from photos without me having to run them through a metadata eraser app.

That said, Google Camera works great on GrapheneOS with Sandboxed Google Play. In fact, you currently only need GSF to use it (not Play Services or Play Store). You can even put GSF + Google Camera in its own user profile and deny the network permission to both of those apps. Doesn't get much better than that.

>The bigger issue I have with it is that, while sandboxed Google services generally work pretty well, some apps don't work properly with the location requests proxy. I'd love to enable it, but, for example, Citymapper is unable to track me when I use it. Finding a location sometimes can take very long.

It's important to understand that Sandboxed Google Play re-routing location to the OS is an option that can be changed. A lot of apps will expect the same kind of location accuracy present on Stock OS with regular Play Services, and so they may not work as expected. It's not really something that GrapheneOS can fix, but it does of course provide the ability to switch to the same kind of location services that are used on Stock for maximum compatibility. In general, with GrapheneOS, you get choices; that's the magic of it.

Re: Reclaiming Mobile Privacy with GrapheneOS

#76

These camera and microphone switches are available by default in current version of Android. You don't need graphene for that.

That is correct! I believe that these toggles were added in Android 12.

GrapheneOS takes great care to only list features that they add on top of AOSP, instead of marketing AOSP features as their own. You can check their features page here:

https://grapheneos.org/features

Re: Reclaiming Mobile Privacy with GrapheneOS

#77
post #11

Earlier quoted context omitted.

Any comparisons to project /e/ or clyxOs?

/e/ supports loads of random phones without a strong HSM. In my estimation this means it will be much easier to get into a locked phone with physical access. I imagine the phone would get imaged, and then the passcode bruteforced on another machine without rate limiting. Calyx supports Pixel3 and Fairphone, but otherwise looks pretty similar. According to GOS's main developer's comments in this thread, Calyx: - doesn…

Thanks for the comparisons!

Although it's missing the cons of GOS (if any) and citation for:

> without a strong HSM

So the post smells a bit like a sales pitch for GOS, nonthless it's useful info. Thanks again!

Re: Reclaiming Mobile Privacy with GrapheneOS

#78
post #29
post #11

Earlier quoted context omitted.

Any comparisons to project /e/ or clyxOs?

GrapheneOS is a hardened OS. It not only preserves the whole standard privacy and security model including all the hardware-based security features but also substantially improves it. https://grapheneos.org/features provides an overview of only the improvements made by GrapheneOS compared to Android 13 (specifically, the stock Pixel OS). We make a fair number of upstream contributions and those aren't listed on our f…

Thanks but... Where's the comparison?

Re: Reclaiming Mobile Privacy with GrapheneOS

#79
post #65

Earlier quoted context omitted.

Quoted post unavailable.

GrapheneOS was started in 2014 and was previously known as CopperheadOS. I co-founded the Copperhead company in 2015 and I still own half of the shares today, which gives me 50% control over the company. GrapheneOS (formerly CopperheadOS) remained an open source project under my control and ownership, not the company we founded to sell services and devices based on the project. Unfortunately, my former business partn…

Interesting.. Why would Raytheon need signing keys? I have not heard or seen any OSS project in use by them ever complain about this.

Edward Snowden is a bad example. He is a SharePoint admin and traitor to the West. It makes sense that he would betray his country, hide under Putin and undermine Western companies.

Re: Reclaiming Mobile Privacy with GrapheneOS

#80
post #64
post #55

Earlier quoted context omitted.

I was using whatever app launches when double clicking the lock button. I don’t think the issue was with the specific app launched, but with the system to launch it.

Please read https://grapheneos.org/usage#exec-spawning . You can choose not to use this feature if you can't tolerate up to a 200ms delay for cold start app spawning. Application spawning on GrapheneOS is as fast as the stock OS when using the standard Android app spawning system. We give users a choice.

Can I enable it for the camera app and only the camera app?
Post reply on HN