Live data from Hacker News

GrapheneOS – Break Free from Google and Apple

blog.tomaszdunia.pl

721–730 of 967 posts

Re: GrapheneOS – Break Free from Google and Apple

#721
post #557
post #101

Earlier quoted context omitted.

I think it's more of a marketing claim from less secure systems that "privacy is not security, and GrapheneOS focuses on security while we focus on privacy". GrapheneOS does care about both, quite obviously. And GrapheneOS tends to say that if your security is bad, then it is affecting your privacy too. Whereas others say "sure, we break the Android security model by unlocking the bootloader and signing our system wi…

> I think it's more of a marketing claim from less secure systems that "privacy is not security I'm not sure Cyanogenmod had a marketing team that convinced me of anything when I first installed their rom in 2013 and explored my phone's capabilities with root. Accessing the sensor devices, inspecting what the different apps do, what the OS is doing, installing Xprivacy to provide fake data to tracking apps... none of…

I am not sure what you are trying to say.

My point is that

1. If you care about privacy, you should care about security. If your email server is compromised and your emails leak in the public internet, then they are not private anymore.

2. GrapheneOS does care about both security and privacy.

> explored my phone's capabilities with root. Accessing the sensor devices, inspecting what the different apps do, what the OS is doing, installing Xprivacy to provide fake data to tracking apps... none of that is possible on GrapheneOS

I think you're talking about something like "freedom", here. GrapheneOS doesn't claim to give you the freedom to do whatever you want. In fact, part of the Android security model is to limit your freedom.

Which is not to say that you should not want the freedom to have root access on your phone. But if that's what you want, GrapheneOS is probably not it.

Re: GrapheneOS – Break Free from Google and Apple

#722
post #163

Earlier quoted context omitted.

Not in Spain. I can access my bank's website but I can't do anything without their bank app. Even sometimes they require to confirm my identity using their app in order to access their website. I've seen this elsewhere, and it's absolutely ridiculous. Why? Because in almost all cases, the apps may only be installed with Google Play, and require the framework to work correctly. And that means? If you are not in good s…

In Germany for some banks you can buy a TAN generator and then you do not need a smartphone app anymore. Is this an option in your area as well?

At my "traditional" bank I even need the TAN generator for my phone. While at my "neo" bank I even need the phone app to access the website. :-) (That is how the neo bank tricked me. I read "website access" in their ad and thought I could still access the bank account if I lose my phone. But no, you can't login without the app.)

Re: GrapheneOS – Break Free from Google and Apple

#723
post #651

Earlier quoted context omitted.

I also disagree with that, I trust my Linux distribution to behave well much more than I trust any Android platform and it doesn't even have much app sandboxing at all. You can't fix a lack of trust like you have in Android with technical solutions. The flaw in Android is fundamentally a social problem.

There's a massive open source app ecosystem for Android which is far larger than the subset available in F-Droid. Open source does not imply private or trustworthy. Completely trusting applications with access to all your data with no insight in to what they're accessing or sending to services means you wouldn't know if your privacy is being violating anyway.

The (desktop) Linux security model is different. You trust the distro maintainers in the same way you trust the GOS devs, and instead of "app sandboxing" you use user accounts, containers or VMs to protect personal information. The Android security model makes sense in the context of laypeople using mostly commercial malware on the stock OS however.

Re: GrapheneOS – Break Free from Google and Apple

#724
post #245

Break free from Google by paying money to Google for a Pixel phone? Even with a used Pixel, you're helping prop up their used market value which helps Google

You could buy a used Pixel. Also, they are working with a partner to create their own phone hardware.

Re: GrapheneOS – Break Free from Google and Apple

#726
post #431

Earlier quoted context omitted.

> I think MicroG - which provides dummy no-op implementations of Google Play tracking APIs, and allows you to select alternative Location Providers and notification backends - is a better option than running first-party Google software. microG still forwards the requests to the Google servers. Not sure what you mean by "tracking APIs"? microG is a reverse-engineered, open source implementation of a subset of Play Ser…

I'm trying to say the same thing I said up at the top: GOS's approach to privacy is obtuse. They deliberately conflate security with privacy (you even write "secure/private" as though they're the same thing) in a way that does a disservice to users. My opinion is that GOS is very successful at its own stated goal of having an extremely secure mobile OS that rolls out patch updates quickly. I think it's far less succe…

> as you even admit, many/most of them will find their phones unusable with vanilla GOS and immediately follow the GOS user guide to install Google Play

I installed the Play Services right away, just like I installed microG right away on a LineageOS system (I don't know about iodeOS, but /e/OS comes with microG by default). In terms of privacy, I don't think it is very different: microG is an open source implementation of the Play Services, that also contacts the Google servers. Many will use something like the Aurora store, which is a client for the Play Store. Etc.

GrapheneOS has proxies, e.g. for the location service. They are doing a lot for privacy, that's very clear.

> I think iodéOS and /e/OS are more in line with what I want from a mobile OS.

And that's your right. I think that GrapheneOS is more secure, and not less private than those. Actually in my experience with /e/OS, it was less secure than Stock Android (though more private, admittedly).

Re: GrapheneOS – Break Free from Google and Apple

#727
post #641

Earlier quoted context omitted.

GrapheneOS is primarily privacy project. It keeps up with important Android updates with major privacy enhancements and very important privacy patches. It builds crucial privacy protections such as Storage Scopes, Contact Scopes, Sensors toggle and much more into the OS. Privacy depends on security so security protections and security patches are part of providing strong privacy too. It's a misconception that Graphen…

Since you seem to be one of the developers, one thing that I wish Graphene focused on more is browser fingerprinting. This is is probably the number one threat against privacy nowadays. Vanadium is very usable, but it seems to be quite easily fingerprintable.

The founder, afaik, not just a developer.

Tor Browser seems to be a project that requires multiple full time developers. I don't think GrapheneOS have the resources right now to do this alongside their OS development, device support and app overhaul plans.

Also please don't take this as any criticism of your suggestion, but there have been multiple 'privacy' browser projects based on Chromium for Android. It's a little frustrating that they couldn't collaborate some base like this to the open source community.

Re: GrapheneOS – Break Free from Google and Apple

#728

Google is so much engrained in our lives that we can't really break free. You can't just don't use youtube and for that you need a google account.These projects are nice and good for tinkering, but can't use this as a dialy driver.

Like others have said, you can use Youtube without Google account. Moreover, you can give Google the middle finger by using uBlock Origin or viewing though a third party client like VacuumTube. Also don't forget the shorts filter recently featured on HN to remove those annoying portrait format videos.

Re: GrapheneOS – Break Free from Google and Apple

#729

Earlier quoted context omitted.

I commented elsewhere but GrapheneOS on Pixels actively siphon resources from Google and is arguably a good protest against google. They subsidize Pixel hardware (to incentivize users to adopt their spyware OS), you (buying used obviously) take their subsidized hardware and do not repay them by using their spyware, replacing it with Graphene. Only google loses. Their hardware is technically very good otherwise (in fa…

How about they start supporting more devices instead?

[dead]

Re: GrapheneOS – Break Free from Google and Apple

#730
post #615
post #91

Earlier quoted context omitted.

I have been using /e/OS for 5 years, and also GOS. My take is: - If your phone is supported by GOS, you should go for GOS. - If your phone is not supported by GOS, you should look carefully and compare between /e/OS and Stock Android. I had a Fairphone 3, and after 5 years, /e/OS was outdated by 4 years w.r.t. the manufacturer updates. In other words, Stock Android coming from Fairphone was more secure than /e/OS on…

> If your phone is not supported by GOS, you should look carefully and compare between /e/OS and Stock Android. If you have an iPhone that's still supported, you have strong privacy and security. If you have a phone that's not an iPhone and not supported by GrapheneOS then you likely have a phone with atrocious privacy and security regardless of OS choice. If people can afford to get a secure device with years of pro…

> many people still wrongly believe they're getting patches they aren't after the OEM dropped support.

I can confirm that I did, and was not very happy when I realised it.

Post reply on HN