Live data from Hacker News

GrapheneOS – Break Free from Google and Apple

blog.tomaszdunia.pl

781–790 of 967 posts

Re: GrapheneOS – Break Free from Google and Apple

#781
post #521

Earlier quoted context omitted.

I regularly conduct transactions at the branch of my local bank wherein they ask me for no credentials whatsoever. I also once forgot to bring my account number with me and the teller said "no worries, I'll look it up for you." Kind of horrifying.

It helps that it’s a jailable offense to make fraudulent transactions

Isn’t unauthorized access to a computer system also a jailable offence in most places?

Would using the password you gain through this social engineering be doubly illegal?

Re: GrapheneOS – Break Free from Google and Apple

#782
post #547

Earlier quoted context omitted.

What if I don't want to give money to Google at all?

Then GrapheneOS is currently not an option, however they are working with another OEM to have non-Google phones available with GrapheneOS by next year [1]. [1] https://grapheneos.social/@GrapheneOS/115987006592879172

Ok that is great news, thanks for sharing.

Re: GrapheneOS – Break Free from Google and Apple

#783
post #763

Earlier quoted context omitted.

Meanwhile, it's probably A-OK for the app to run on a phone that hasn't received security updates for 5 years. I don't get it. If they're worried about liability, why not check the security patch level and refuse to run on phones that aren't up to date? I'm guessing it's because there are a lot of phones floating around that aren't updated (probably far more than are rooted), and they're willing to pretend to be secu…

Because a phone running an unknown OS is significantly more dangerous than a phone that hasn't received security updates for years. For example, a malicious OS maker could add their own certificate to the root store, essentially allowing them to MitM all the traffic you send to the bank. Liability works on the principle that "if it's good enough for Google, it's good enough for me." A bank cannot realistically vet ev…

> Because a phone running an unknown OS is significantly more dangerous than a phone that hasn't received security updates for years.

I'm not convinced this is generally true, at least as can be detected by an app. Back when I had my phone rooted, it was configured so that it would pass all the Google checks and look like the stock OS. That configuration was probably dangerous, but apps were happy with it. Now that I run an OS that doesn't lie about what it is, I'm flagged as untrustworthy. What's the point in being honest?

Overall, I don't think they really have any idea what's a threat based on the checks they're doing, so I don't think they can say at all what's more or less trustworthy. But I think that a phone that reports being years out of date should reasonably not be expected to be secure, but yet they mark it as secure anyway. Many of those devices can be rooted in a way that can still pass their checks. I would think, if nothing else, that would be reason to block them, since they're interested in blocking rooted devices.

Re: GrapheneOS – Break Free from Google and Apple

#784
We need an Euroepean vendor or organ or consortium taking up Android or Graphene or whatever and stamping a cert on phones allowed to run bank apps, after which banks (etc) have to support those phones. And/Or having to offer all functionality in the app(s) also in mobile web, but having users who want to use that requiring an OTP (or so) hardware token. I would be in favour of having the latter no matter what; no I can do this with my bank, but it doesn't offer the same as the mobile app and the site is not mobile optimised either.

Re: GrapheneOS – Break Free from Google and Apple

#785

Earlier quoted context omitted.

It helps that it’s a jailable offense to make fraudulent transactions

Isn’t unauthorized access to a computer system also a jailable offence in most places? Would using the password you gain through this social engineering be doubly illegal?

Well... sure. But people be crimeing, and some of these attacks can be done internationally.

Re: GrapheneOS – Break Free from Google and Apple

#786

Earlier quoted context omitted.

If the government (or school) is going to require us to have a smartphone in order to access critical government information, then we should demand that the government provide us with a compatible smartphone.

Would you use that phone?

If your employer required the use of a smartphone for essential components of your job and provided you with a smartphone and cellular data plan, would you not use that smartphone for those components of your job?

I'd not use employer- or government-furnished equipment for tasks that the equipment wasn't provided to complete, but I'd definitely use it for those tasks.

Re: GrapheneOS – Break Free from Google and Apple

#787

I can't take this seriously when their mission statement is to "break free from Google and Apple" and their entire output is a fork of a Google repo. If you're based on AOSP, the project is still 100% reliant on Google! It seems extremely cynical to me to depend on the work of a thousand-man team to build your OS, then patch out a couple of lines and claim you've broken free from them. Without Google, none of this pr…

i don't understand your issue - using grapheneos does allow you to break free from google in the sense that you have an android OS that works well, is secure and private, and gives you the choice to use google or not. if you choose to use play store/services, they run as sandboxed, unprivileged applications like every other app. on samsung/stock pixels etc, play services is a privileged component of the os and you can't avoid this. grapheneos gives you the freedom to break free from it in this sense.

soon enough grapheneos will be available on non-pixel devices, but if you really have, say, a philosophical problem with using google devices, get a used 2nd hand pixel. or wait til the oem partnership announcement.

Re: GrapheneOS – Break Free from Google and Apple

#788

Been using this for about a year on a p9 pro. It works very well. I hear the google tap to pay does not work, but I've never tried it. However Vipps with their tap to pay works fine. BankID works but not with biometric login, which some things require IIRC. And for some reason DnB private works fine, but you are not allowed in on the corp app. It's mind boggingly stupid that they lock down apps like this, when you ca…

This reads like a very norwegian experience!

Re: GrapheneOS – Break Free from Google and Apple

#789
post #695

I use this and lineage, but in a few years time this could be moot if Google decides to completely lock down devices. That leaves commercial options like Fairphone

Fairphone is far from meeting the update and security requirements for GrapheneOS. It isn't a viable platform for a hardened OS to use and isn't likely to ever become one due to security being very far from a priority for them. GrapheneOS has a partnership with one of the largest Android OEMs. They're going to be announcing it in March 2026. Devices meeting all of the update and security requirements from them with o…

That OEM has yet to be named. It would be nice to see it happen, but it's yet to materialize.

> It isn't a viable platform for a hardened OS

Breaking from google/Apple doesn't in itself require a hardened OS, as we see in LineageOS.

Re: GrapheneOS – Break Free from Google and Apple

#790

Earlier quoted context omitted.

My comment was about push service sharing generally, not banks, from a technical point of view that many people aren't aware of but may find interesting. Clearly, real-time notifications are useful with many apps, notably real-time messaging, even if you don't think they have a place with bank apps. For bank and credit card apps, I find their push notifications to be very useful. They are among the most useful notifi…

> But SMSs are just push notificatons with a worse UI and worse visual cues. ... and no dependence on Google or Apple.

> ...worse visual cues

I'm on Android, and SMS notifications look exactly like every other notification (with one caveat I'll mention below), so I don't know what this guy is on about.

> ...SMSs are just push notificatons with a worse UI...

By this, does OP mean that shit where programs can put buttons and bigass images into their notifications? If yes, I don't want that shit. That's just more opportunity to accidentally trigger unwanted behavior with one's fat fingers, and more screen space gobbled up by overly-self-important software.

The thing that's shitty about SMS is that it's "worst^Wbest effort" delivery... which means that messages can (and will) get delivered late, out of order, or never. Don't use SMS; use email. Email is also best-effort, but -based on my personal experience- far more email server operators give a shit about delivering your messages than SMS relay operators.

Post reply on HN