Live data from Hacker News

Your phone is about to stop being yours

keepandroidopen.org

841–850 of 927 posts

Re: Your phone is about to stop being yours

#841
post #738
post #51

Earlier quoted context omitted.

I'm running GrapheneOS too and while I've experienced the same, I'm dreading the day any of my banking apps update and suddenly start demanding full Play Integrity API support (GrapheneOS only has Basic) causing them to fail to open. Hasn't happened yet but it could.

Happened to me. Stopped working on GrapheneOS because of some goddamn check they make, but still runs on an outdated /e/OS signed with the Google test keys (i.e. without a proper secure boot). The real fight is to prevent companies (like those banks) to do that kind of shit. And to force manufacturers into allowing us to install alternative systems, instead of preventing unlocking/relocking of the bootloader for inst…

Yeah, and legislation would be needed here but that's just not going to happen. With the GrapheneOS Motorola partnership (only a Lenovo subsidiary but its something) and hopefully more with other manufacturers, this might turn the tide, but its a long shot.

Re: Your phone is about to stop being yours

#842

Earlier quoted context omitted.

> But beyond whether the OS is good or not, "fuck you, I've got mine"... What about, "I got mine and you can have it to." Nobody is preventing access to graphene.

>>> I don't care, I run Graphene, and my phone is definitely mine. I really don't see an implied "and you can too".

Graphene is available to everyone.

Re: Your phone is about to stop being yours

#843

Earlier quoted context omitted.

GNU/Linux phones exist: https://en.wikipedia.org/wiki/Librem_5 and https://en.wikipedia.org/wiki/Pinephone

They're insecure [1] and far from usable. [1] https://madaidans-insecurities.github.io/linux-phones.html

Only if your threat model is equal to the one from the GrapheneOS crowd, and only if you value freedom less than maximal security. It's fine if this is your choice, just don't say this is the only reasonable choice.

Concerning "usable", Librem 5 is my daily driver. I have no backup phone.

Also, after skimming your link and seeing "Hardware kill switches are nothing but marketing frills", I can state that this is nothing else than FUD. Kill switches can protect me, when GrapheneOS can't. You have to trust that your proprietary modem never spies on you. I don't have to. Also, here is a couple of nice discussions of this article: https://news.ycombinator.com/item?id=37507414 and https://news.ycombinator.com/item?id=28500824

Re: Your phone is about to stop being yours

#844

Earlier quoted context omitted.

I don’t know what you’re going on about “rewriting history”. I never mentioned the history of open source. From the Open Handset Alliance: “The Android platform will be made available under one of the most progressive, developer-friendly open-source licenses, which gives mobile operators and device manufacturers significant freedom and flexibility to design products.” Give mobile operators and device manufacturers fr…

That's perhaps because typical consumers don't build their own operating systems?

Right. Phones won’t be built open for consumers because they aren’t built by consumers. They’re built by corporations for consumers.

The software may be built by consumers for consumers, e.g., AOSP distros. But, the hardware and mobile infrastructure, probably not.

Re: Your phone is about to stop being yours

#845

Earlier quoted context omitted.

> WHERE DO I SEND MY MONEY? Good question. Here you go: https://puri.sm/products/librem-5

If you want an outdated, insecure, and extremely overpriced phone, sure, go ahead. It's literally 2018 hardware being sold for 800 bucks. 3 GB of RAM? Seriously? The iPhone XS, also from 2018, has 4 GB of RAM, just saying. And regarding the security: https://madaidans-insecurities.github.io/linux-phones.html

> you want an outdated, insecure

Please stop spreading FUD. I replied here: https://news.ycombinator.com/item?id=47945696

> 3 GB of RAM? Seriously?

https://puri.sm/posts/the-danger-of-focusing-on-specs/

Re: Your phone is about to stop being yours

#846
post #840
post #831

Earlier quoted context omitted.

This is an idealism vs realism fight. You're both right in that you're both fighting for the end user to have ultimate control of their device. However, there's a major caveat here. Google's play protect prevents me from using some apps on my phone running graphene. My banking app is one of them. Yes I know there's technical workarounds. Yes I know they have a website (for now). But the point is, this is the directio…

> Google's play protect prevents me from using some apps on my phone running graphene. My banking app is one of them. Well, your bank is the one choosing to prevent your from running it on GrapheneOS. That's my whole point again! We need to regulate that: it should be forbidden to ban alternative OSes! Now complaining about the fact that side-loading will require a ONE TIME, "annoying" procedure is not helping this A…

I'd be happy with either approach, frankly. I just think yours is slightly less realistic.

> Well, your bank is the one choosing to prevent your from running it on GrapheneOS. That's my whole point again! We need to regulate that: it should be forbidden to ban alternative OSes!

The bank isn't banning graphene os. They're banning anything Google labels as untrusted. I think that's an important distinction. This is Google's doing. I don't have the ability to declare "this is my device and I trust it and everything on it" to the banks. And I can see Google's point in that it would be extremely difficult to do this in a way that couldn't be exploited maliciously. Are there ways for the .001 percent of people out there who understand this? Absolutely. But only if our overlords let us and even then we're back to the point that this is only for the people in the know.

Which is why I personally don't think enforcing alt OSes will help. We have it now; most people don't know and wouldn't care if they did. Play protect is the same. The amount of people this would impact is beyond minimal. However the problem isn't minimal; this is already a huge problem and it's getting bigger quickly. Giving people the keys won't fix it fast enough, or for enough people.

Tech already controls our life and that fact is only getting more worrisome. It's past time for the governments to treat this the same as electricity. Everything standardized, everything regulated, and I can plug whatever the hell I want into it. I don't want to just break free for myself. In order to really make change, my grandma needs to think of her phone like a power outlet.

This is a great discussion, by the way.

Re: Your phone is about to stop being yours

#847

Earlier quoted context omitted.

> Quite frankly, the whole Librem ecosystem is significantly less "open" than GrapheneOS or any desktop Linux variant to anyone who look at things objectively instead of using weird FSF semantics. You will have a point when your Google phone runs Replicant. Now this is just empty words, i.e., FUD. Which blobs are running on the Librem 5 CPU? Which blobs are running on GrapheneOS CPU?

Which blobs are running on the Librem 5 CPU? Which blobs are running on GrapheneOS CPU? Both the Pixel and Librem 5 have firmware baked into the SoC that is executed. On GrapheneOS, the firmware is signed and updated along with the OS. On the Librem 5, the firmware for Wifi/Bluetooth is stored on a NOR chip, which is read from and mounted into the OS by the initramfs into /lib/firmware. Not-withstanding the above, Li…

You keep repeating this everywhere. Consider reading what a Librem 5 developer says instead, https://news.ycombinator.com/item?id=47943487

Also, Librem 5 has "proper" firmware updates (whatever that means). Please do not spread false information.

Re: Your phone is about to stop being yours

#848

Earlier quoted context omitted.

I'll take his word that no blobs are running on the main CPU. But the process itself is error prone. It's mounting flash storage with blobs into the filesystem of the OS. The OS can load modules directly from the storage. > There is not a single non-free blob in the OS that runs there once the bootloader is up (unless you put some there by yourself, which you're of course free to do). "unless you put some there by yo…

The SOC still has firmware baked in as per usual. And the firmware for Bluetooth/Wifi is loaded in by having the initramfs read it from the NOR flash, mount it in /lib/firmware, then it is business as usual like a desktop Linux distribution. It's not something special. It's just a hackjob. They shuffle the files around and made it much harder to update. https://source.puri.sm/Librem5/librem5-fw-jail/-/blob/pureos...…

You keep repeating this everywhere. Consider reading what a Librem 5 developer says instead, https://news.ycombinator.com/item?id=47943487

Re: Your phone is about to stop being yours

#849

Earlier quoted context omitted.

You missed that I do not recommend Librem 5 to "almost everyone". We are not on a normies forum but on HN. Also, I do not recommend Librem 5, when somebody asks for a secure device. I mention it, when somebody asks about alternatives to the duopoly, a possibility to have a full, general-purpose computer in a pocket allowing you to tinker with it, or wants to run GNU/Linux baremetal. Such people aren't the audience of…

> We are not on a normies forum but on HN. Being on HN does not mean that you are familiar with the intricacies of hardware and low-level software. > I only say, that if you want to have a third option, you can have it today. There will be compromises, which can be dealt with by technical users. I think it’s irresponsible to promote it as an alternative device without noting that it’s less secure and full of footguns…

This is not a forum with legal advises. I inform people about an option, which they asked for. GNU/Linux phones have a similar security approach to GNU/Linux on desktop. People explicitly seeking GNU/Linux should know this. They can also ask or search the Internet.

> I think it’s irresponsible to promote it as an alternative device without noting that it’s less secure and full of footguns

I disagree with you here. Informing about options is better than not informing. "Less secure" depends on a threat model. GNU/Linux on desktop is working well enough for millions of people. So it is a viable security approach for many. Saying that your threat model is the only one that should exist and be promoted is crazy.

> only fits that definition under FSF technicalities

This is one of the strictest definitions there is. By which definition does GrapheneOS run FLOSS?

> same set of proprietary hardware, just with different communication mechanisms/boundaries

More choice is always good, isn't it? If it is not for you, you are free to use and promote the duopoly. (Yes, I consider AOSP obeying Google's development strategy long term. It will not end well. See: this topic.)

Re: Your phone is about to stop being yours

#850
post #738

Earlier quoted context omitted.

Happened to me. Stopped working on GrapheneOS because of some goddamn check they make, but still runs on an outdated /e/OS signed with the Google test keys (i.e. without a proper secure boot). The real fight is to prevent companies (like those banks) to do that kind of shit. And to force manufacturers into allowing us to install alternative systems, instead of preventing unlocking/relocking of the bootloader for inst…

Yeah, and legislation would be needed here but that's just not going to happen. With the GrapheneOS Motorola partnership (only a Lenovo subsidiary but its something) and hopefully more with other manufacturers, this might turn the tide, but its a long shot.

> legislation would be needed here but that's just not going to happen

Why not? The EU DMA is going in that kind of direction...

Post reply on HN