Live data from Hacker News

GrapheneOS – Break Free from Google and Apple

blog.tomaszdunia.pl

811–820 of 967 posts

Re: GrapheneOS – Break Free from Google and Apple

#811

Earlier quoted context omitted.

How much the certificate costs and lasts?

It costs as much as your ID card costs by the government, and lasts as long as well. They are one and the same. Applying for a new ID card / national ID document in Estonia costs 35€ and the document is valid for 5 years. If you forget your PIN code, you can reset it with your PUK codes, but if you also lose your PUK codes you need to apply for a new ID card. The process for getting a new ID card from the moment you…

> but if you also lose your PUK codes you need to apply for a new ID card

Or it seems you can reset the PIN/PUK for 10 €: https://www.politsei.ee/en/instructions/state-fee-amounts

Re: GrapheneOS – Break Free from Google and Apple

#812

Earlier quoted context omitted.

Meanwhile, it's probably A-OK for the app to run on a phone that hasn't received security updates for 5 years. I don't get it. If they're worried about liability, why not check the security patch level and refuse to run on phones that aren't up to date? I'm guessing it's because there are a lot of phones floating around that aren't updated (probably far more than are rooted), and they're willing to pretend to be secu…

It's more frustrating because my partner's pixel 4A cannot use google pay or the bank apps because it is an invalid os - I am guessing due to lack of updates? So, perfectly fine hardware, but crippled in functionality due to the lack of software updates.

My partner has a 4a and no such issues. Are you talking about stock Android or something else,

Re: GrapheneOS – Break Free from Google and Apple

#813
post #511
post #290

Earlier quoted context omitted.

What binary format?? Go read facebook's "source code", is that any more open than a random apk? If anything, apks decompile quite well.

So long as browsers allow you to open the developer tools and inspect memory etc., they're more open than remote attestation of a stock android or ios device Decompiling apps only works if you can get the app. I don't understand GP's problem with the apk format either, but you do need to break terms of service to get the files if you don't have a phone with Google services installed. Whether that's ethical or legal i…

> but you do need to break terms of service to get the files if you don't have a phone with Google services installed

Why would I care? It's not like what Big Tech does is ethical or legal. You need to fight fire with fire.

Re: GrapheneOS – Break Free from Google and Apple

#814
post #718

Earlier quoted context omitted.

The #1 security problem your average Android user face isn't an attack by some Israeli firm but data leaks by advertisers and unless I missed something (it's possible), GrapheneOS does not have an equivalent of ublock origin built into the OS which I'd consider step 1 of fighting the problem. The "ideal android" in my head would just have a dynamic ruleset to patch/nop tracking libraries as the app loads, which as fa…

GrapheneOS provides greatly improved privacy including through features like Contact Scopes and Storage Scopes. > GrapheneOS does not have an equivalent of ublock origin built into the OS which I'd consider step 1 of fighting the problem. Enumerating badness by trying to list domains which are solely used for advertising, telemetry, etc. doesn't address any of the main privacy invasive behavior by apps which is done…

> Using a fundamentally unworkable approach that's increasingly becoming less useful is not how GrapheneOS approaches privacy.

I feel like we agree on the premises but not the conclusion then.

If there's no way to make a Revanced on steroids system work on Android, it means that Android's security model is fundamentally broken for me and beyond repair.

Fundamentally, Android is built with untrusted as its core value. Google doesn't trust Qualcomm, which doesn't trust the manufacturer, which doesn't trust app makers, which doesn't trust the user. It's a chain of untrusted parties all the way to the user. With one single exception, in your average phone, the user has to trust all the the above. So the user is the one trusting everybody blindly and nobody else has to do it.

The only way to make this untrusted chain model work is to go one step further, make the user not trust all of the above with a heavily modified system, including dynamic patching and that's almost impossible.

The reason why it works differently on a Linux distribution is it's built on the opposite values. The maintainers trust contributors which trust app makers ... all the way to the user. If one of them breaks that trust, they are out for good, they know they have one chance and this makes the stack fundamentally less hostile.

You can't easily fix a broken social contract like in Android with just tech.

Re: GrapheneOS – Break Free from Google and Apple

#815

Earlier quoted context omitted.

GrapheneOS requirement of Pixel devices is a dependency on Google too. They are currently working with an OEM to release a non-Pixel GrapheneOS phone in the future.

I hope and pray that is a Samsung S Ultra device. The built-in stylus transforms the whole user experience, I would not go back to a device that I must swipe my dirty fingers across.

I saw one last week. I can't comment about the stylus (but I'm swiping with my thumb to write this message). I held it in my hands and it's a brick but most phones of the last years are bricks so I expect that they will deliver another nearly 7" 200 grams brick. We used to call them phablets. This is one of the models that defined the category in the early 2010s https://m.gsmarena.com/samsung_galaxy_note_n7000-4135.php

It's almost lightweight nowadays and it's definitely small. I remember that we thought that it was insanely huge when pressed to a ear to talk.

Re: GrapheneOS – Break Free from Google and Apple

#816
post #508

Earlier quoted context omitted.

A collegue of mine was tech lead at a large online bank. For the mobile app, the first and foremost threat that security auditors would find was "The app runs on a rooted phone!!!". Security theater at its finest, checkboxes gotta be checked. The irony is that the devs were using rooted phones for QA and debugging.

> the first and foremost threat that security auditors would find was "The app runs on a rooted phone!!!". GrapheneOS is not rooted, or is not required to be.

Moreso, the project advises against rooting your phone and tells you that if you install GrapheneOS and root it that you aren't running GrapheneOS anymore.

Re: GrapheneOS – Break Free from Google and Apple

#817
post #142

Earlier quoted context omitted.

> It's mind boggingly stupid that they lock down apps like this, when you can just open the thing in a website anyway. I can use my bank on some linux distro... Not in Spain. I can access my bank's website but I can't do anything without their bank app. Even sometimes they require to confirm my identity using their app in order to access their website. I have several linux phones but I can only do banking with their…

This should be illegal that the government forces people into apps controlled by private, commercial entities. I call such a government corrupt. Here in central Europe I can still access the bank website fine without smartphone. I need a physical device to yield a TAN though, but I can access and do online transactions fine. So I think something is wrong with the spanish government. People need to protest.

Where is the government forcing you here? Does Spain have regulation that obliges the use of apps for banking for certain functionality and disallows websites? Or what are you talking about?

Re: GrapheneOS – Break Free from Google and Apple

#818
post #577

Should be noted that in order for OEM unlocking toggle to work, you need to turn on WiFi and connect to the internet.

Huh, and here I thought Google was one of the few manufacturers left that simply support it on their hardware. So it depends on some cloud service being alive. Do you know if it's the same for Fairphone or Shiftphone? Or is there another manufacturer that doesn't require this? I've recently bought a new phone so it's not relevant for me anymore but when I next go looking, it can factor into it. As it was, I had Googl…

It's probably worth pointing out that the online process is one time and it installs a token that permanently lets the setting be toggled offline afterwards. This persists across factory resets and flashing any OS.

I wrote more details about it works under the hood here: https://news.ycombinator.com/item?id=35856171

Re: GrapheneOS – Break Free from Google and Apple

#819
post #719
post #711

Earlier quoted context omitted.

>GrapheneOS does not have an equivalent of ublock origin built into the OS which I'd consider step 1 of fighting the problem. Content filtering is built into the browser. GrapheneOS have always maintained that you cannot prevent an app from exfiltrating data, especially if it has internet access. Enumerating badness is an unsustainable approach they don't want to encourage. Instead they attack the heart of the issue…

> Something similar was addressed some years ago as a feature request for GrapheneOS https://github.com/GrapheneOS/os-issue-tracker/issues/284 . To summarise there was no way to do this without an unacceptable security cost to the OS, but this is sort of doable if you run your own userdebug build which you have the power to do. It's badness enumeration which is an unworkable approach to providing strong privacy. It f…

> You don't need the OS providing anything to use arbitrarily modified APKs. We also don't want to give apps a legitimate reason to ban GrapheneOS as opposed to being able to convince the tiny number of apps enforcing Google certification to allow it.

I think you said the truth out loud, a rom which tries too much to fight for your privacy would just be banned. (And I do agree with that)

Re: GrapheneOS – Break Free from Google and Apple

#820

Been using this for about a year on a p9 pro. It works very well. I hear the google tap to pay does not work, but I've never tried it. However Vipps with their tap to pay works fine. BankID works but not with biometric login, which some things require IIRC. And for some reason DnB private works fine, but you are not allowed in on the corp app. It's mind boggingly stupid that they lock down apps like this, when you ca…

All of my banking related apps work fine.

The only apps that haven't worked are Google wallet for NFC payments and, strangely "macrofactor" a calorie tracking app.

Google wallet works for things like library cards, tickets etc, just not NFC payment.

Macrofactor since seem to have fixed their app, the features that did not work now do.

Graphene used to lack android auto support but it has since been added and works perfectly.

They maintain a guide for app developers as well as a list of apps that refuse to add comparability here:

https://grapheneos.org/articles/attestation-compatibility-gu...

Post reply on HN