Live data from Hacker News

GrapheneOS fixes Android VPN leak Google refused to patch

cyberinsider.com

81–90 of 142 posts

Re: GrapheneOS fixes Android VPN leak Google refused to patch

#81
post #47

Earlier quoted context omitted.

10a will get longer support, so why not (unless 9a is significantly cheaper)?

Isn’t part of the point of wanting GrapheneOS is that the official support periods don’t matter?

Graphene OS only supports devices for as long as the manufacturer is providing security updates for the phone's firmware. Firmware is binary blob, so there'd be no practical way for anyone else to provide/develop security updates once the manufacturer is no longer providing official updates.

Their partnership with Motorola, I think, involves some ability of Graphene OS devs to access/harden/update the firmware, but I'm not 100% sure. Firmware on phones, especially for the baseband processor, often involves a nasty confluence of copyright, trade secrets, patents, and government rules/demands.

Re: GrapheneOS fixes Android VPN leak Google refused to patch

#82
post #45

Earlier quoted context omitted.

I answered this in another thread: https://news.ycombinator.com/item?id=48076522 Basically, buy a Pixel 6 or later (I suggest Pixel 7 or later, since Pixel 6 will be minimal support soon) that you are sure has an unlockable bootloader . The majority you'll see don't have an unlockable bootloader. Which mostly means either buy direct from Google, or buy one on eBay that already has GrapheneOS/CalyxOS/LineageOS on it o…

If you have time and the ebay listing is unclear, I would definitely ask. That way if they say you can unlock the boatloader and in reality you can't, you can return it to them as an item "not as described" at no cost.

I tried asking, years ago, with the rationale of I'm not wasting people's time, since they could get more money if they knew about bootloader unlocking.

Then I decided everyone who knows about bootloader unlocking would've already checked and mentioned if it was unlockable (but not if it wasn't, since why confuse normal buyers with a fringe thing), and I've never gotten a positive response trying to tell any seller about it, so I think I'm just wasting everyone's time.

Your mileage may vary.

Re: GrapheneOS fixes Android VPN leak Google refused to patch

#83

Earlier quoted context omitted.

Is the CalyxOS Vs GrapheneOS shitflinging about to start up again?

Not sure where CalyxOS came up in this?

The developers of each have engaged in a few flamewars and the commenter I replied to was critical of GrapheneOS using similar language, so I made a (tongue in cheek comment) implying the commenter was starting the flamewar back up

Re: GrapheneOS fixes Android VPN leak Google refused to patch

#84

Earlier quoted context omitted.

We all agree. But what's the solution? We know 99% of the users don't care. So, the only pressure point is phone manufacturers. I don't have any power to influence anybody significant in this space. I feel helpless.

The truly independent solution is GNU/Linux. Sent from my Librem 5.

Why is there no Librem 6? Librem 5 is 7 years old, it's a low-end smartphone with a flagship price tag :(

Re: GrapheneOS fixes Android VPN leak Google refused to patch

#85
post #84

Earlier quoted context omitted.

The truly independent solution is GNU/Linux. Sent from my Librem 5.

Why is there no Librem 6? Librem 5 is 7 years old, it's a low-end smartphone with a flagship price tag :(

Oh wait they released "Liberty Phone" - still low end(!), this time with absurdly high price.. You can get true linux phone 10x cheaper by buying something that supports PostmarketOS

Re: GrapheneOS fixes Android VPN leak Google refused to patch

#86

[flagged]

Project member here.

> A distro with shady revenue sources (check for yourself)

Do me a favor and tell me about our apparent shady revenue sources. We are run entirely by donations, there are large donors too.

> with shady hardware restrictions that only permits to use spyware phones from google

We cover this topic literally everywhere on a daily basis, with a thorough list of requirements found on our website.

> after years of complaints now permits you to use hardware from an NSA long time contractor.

Motorola Solutions and Motorola Mobility are entirely different companies. We've partnered with the latter.

> No, claiming that some magic hardware makes you more secure is not a valid reason

To bring you a rather extreme but also straightforward example, leaked documents from forensic software show we're holding up incredibly well.

> when you are using hardware where they have every reason to track you even further. Saying "nothing was found so far" is no excuse

Okay, so nothing we say will encourage you to change your thinking then.

> Now claims to solve a VPN leak when not long ago this same group were exposed promoting a governamental VPN and honeypot, a.k.a. Tor.

What?

> Just don't expose yourself to bait distros that forces you into spyware.

Strong claims like yours should ideally be backed up with equally strong sources and evidence, otherwise you quickly run out of steam.

> (not even complaining about their shady software choices).

Which are?

Re: GrapheneOS fixes Android VPN leak Google refused to patch

#87
post #7

> Because system_server operates with elevated networking privileges and is exempt from VPN routing restrictions So a VPN isn't a VPN on Android? Regardless of this bug. Do other locked down operating systems act the same?

Ios does the same, only way around it is if you have an ?enterprise? licence (250+ devices) Mullvad and others reported on that one ages ago

a VPN enabled wifi router would suffice as a fallback tho right?

Re: GrapheneOS fixes Android VPN leak Google refused to patch

#90
post #22

Earlier quoted context omitted.

Sadly, Verizon Pixel phones, even after carrier unlocking, seem to be forever blocked from using GrapheneOS.

Carrier-sold Pixels generally don't have "OEM-unlockable" bootloaders. Your best bet for now is to buy a new Pixel direct from Google, or a used one from eBay that the seller advertises as already having GrapheneOS on it (or otherwise guarantees that the bootloader is unlockable). These ones are worth a lot more than the ones that can only run Google/carrier Android. https://grapheneos.org/install/web#prerequisites I…

Is this true for all carriers? Or just Verizon? Several Reddit threads say that it's just Verizon. T-Mobile users report being able to bootloader unlock after getting their phones carrier unlocked by T-Mobile.
Post reply on HN