Live data from Hacker News

Your phone is about to stop being yours

keepandroidopen.org

851–860 of 927 posts

Re: Your phone is about to stop being yours

#851
post #846
post #840

Earlier quoted context omitted.

> Google's play protect prevents me from using some apps on my phone running graphene. My banking app is one of them. Well, your bank is the one choosing to prevent your from running it on GrapheneOS. That's my whole point again! We need to regulate that: it should be forbidden to ban alternative OSes! Now complaining about the fact that side-loading will require a ONE TIME, "annoying" procedure is not helping this A…

I'd be happy with either approach, frankly. I just think yours is slightly less realistic. > Well, your bank is the one choosing to prevent your from running it on GrapheneOS. That's my whole point again! We need to regulate that: it should be forbidden to ban alternative OSes! The bank isn't banning graphene os. They're banning anything Google labels as untrusted. I think that's an important distinction. This is Goo…

> The bank isn't banning graphene os. They're banning anything Google labels as untrusted.

I don't agree here :-). AOSP provides an attestation mechanism that totally works with GrapheneOS [1]. Google provides Play Integrity on top of that, as an easy way to check that the phone is signed by Google. It doesn't say "it's unsafe if it is not signed by us", it just says "here is a way to verify that it is signed by us".

The bank chooses to check that it is signed by Google and to refuse everything that is not. The bank chooses that.

First, they don't need to check at all. Many banks don't, it seems like it's a new thing. I don't believe that there is any security concern there: it probably has to do with policy, or security theatre. It isn't serious security, because serious security would not ban GrapheneOS. I doubt it is to help Google, I think it's just incompetence (and a cheap way to do security theatre).

Most apps run on GrapheneOS, most apps don't use Play Integrity. Those who do choose to do it. And there are banks that choose to support the GrapheneOS attestation, though it's the exception.

[1]: https://grapheneos.org/articles/attestation-compatibility-gu...

Re: Your phone is about to stop being yours

#852

Earlier quoted context omitted.

It's basically taking the blobs that would be normally shipped with the OS in a sensible manner, shuffle it around, then calling it "free" while the same blobs would still be there, just on different flash storage chips.

> https://news.ycombinator.com/item?id=47943487 You keep repeating this everywhere. Consider reading what a Librem 5 developer says instead, https://news.ycombinator.com/item?id=47943487

Because it's true, and I know what he said, I am not confused at all. Did you not read anything at all?

On the Librem laptop, the tampering is done by PureBoot and inject into /run/firmware. The other user was linking the stuff with the laptop.

*On a Librem 5, it is stored on a separate chip, then they read it with the initramfs, then mount it on top of the regular filesystem at /lib/firmware*.

Like I said, it's just shuffling stuff around.

Here is the actual code, if you care enough to read it: https://source.puri.sm/Librem5/librem5-fw-jail/-/blob/pureos...

If you can't read code, here is the marketing material: https://puri.sm/posts/shipping-new-sparklan-wifi-cards-with-...

If you don't know that the firmware for components/peripherals can either be uploaded to them by Linux or just stored on some flash chip on the component, read: https://www.chromium.org/chromium-os/developer-library/refer...

Re: Your phone is about to stop being yours

#853

Earlier quoted context omitted.

Which blobs are running on the Librem 5 CPU? Which blobs are running on GrapheneOS CPU? Both the Pixel and Librem 5 have firmware baked into the SoC that is executed. On GrapheneOS, the firmware is signed and updated along with the OS. On the Librem 5, the firmware for Wifi/Bluetooth is stored on a NOR chip, which is read from and mounted into the OS by the initramfs into /lib/firmware. Not-withstanding the above, Li…

You keep repeating this everywhere. Consider reading what a Librem 5 developer says instead, https://news.ycombinator.com/item?id=47943487 Also, Librem 5 has "proper" firmware updates (whatever that means). Please do not spread false information.

Since you copy pasta your response, I will link to my other comment and do a bit of copy pasta here:

https://news.ycombinator.com/item?id=47953726

It is exactly how it works. Read the actual code for yourself: https://source.puri.sm/Librem5/librem5-fw-jail/-/blob/pureos...

If you can't read code, here is the marketing material: https://puri.sm/posts/shipping-new-sparklan-wifi-cards-with-...

If you don't know that the firmware for components/peripherals can either be uploaded to them by Linux or just stored on some flash chip on the component, read: https://www.chromium.org/chromium-os/developer-library/refer...

Re: Your phone is about to stop being yours

#854
post #599

Earlier quoted context omitted.

In the words of a Great American: "Those who would give up essential Liberty, to purchase a little temporary Safety, deserve neither Liberty nor Safety."

AFAIK there is more to that quote and it is usually misrepresented.

I think the excerpt fits well enough for my intent.

Re: Your phone is about to stop being yours

#855

Earlier quoted context omitted.

The SOC still has firmware baked in as per usual. And the firmware for Bluetooth/Wifi is loaded in by having the initramfs read it from the NOR flash, mount it in /lib/firmware, then it is business as usual like a desktop Linux distribution. It's not something special. It's just a hackjob. They shuffle the files around and made it much harder to update. https://source.puri.sm/Librem5/librem5-fw-jail/-/blob/pureos...…

You keep repeating this everywhere. Consider reading what a Librem 5 developer says instead, https://news.ycombinator.com/item?id=47943487

Why do you copy paste the same thing over and over a bunch of times? Linking to an irrelevant post doesn't change how it works.

Read the code posted above.

Re: Your phone is about to stop being yours

#856
post #345

Earlier quoted context omitted.

I realize this is a different discussion, but shouldn't it be? The way that it has been since home computers were a thing, as far as I know at least? I don't think we'd stand where we stand today if Commodore and other hardware vendors had required a license on every piece of software from the get-go (if we pretend that there was a known, exportable, and safe signature scheme back then)

Should the GPL3 software you download and run also be yours?

Pardon?

Re: Your phone is about to stop being yours

#857
post #337

Earlier quoted context omitted.

It's not about paying Google. People can buy gift cards with cash and do that; that's not the problem, especially not for commercial use. It's everything else that they're imposing or could impose on a whim and whose device it is they're putting restrictions on.

Google will not accept prepaid cards for verification. Google's identity requirements serve basic security needs and are fine.

> Google will not accept prepaid cards for verification.

Precisely?

Maybe to spell it out once more, that it's about the other restrictions and not the 25$. Identity requirements is one of those others.

> identity requirements serve basic security needs

Last I heard, Google doesn't employ law enforcement. I can auth to the people we vote for and any laws they make such as bank KYC against specific criminal activity. Nobody gets scammed via an apk when it's infinitely easier to put up a webpage or socialmedia profile

Re: Your phone is about to stop being yours

#858
post #330

Earlier quoted context omitted.

Had to read that sentence twice. You really think that there's more people getting scammed via "please tap the build number seven times and then go to extra settings and enable untrusted installs and then go to this website that I will dictate the URL of and you should ignore that install warning" etc etc etc. to install an apk to run software that can barely access more than a simple webpage could, than there are pe…

> You really think that there's more people getting scammed via "please tap the build number seven times Yes, because this whole procedure is new > Also note that "crapware" describes basically every app you find in google's store Go back to emacs then I guess

Installing apks has required going into settings for years now. 'Scary' steps aren't new

> Go back to emacs then I guess

way to have a conversation

Re: Your phone is about to stop being yours

#859
post #319

Earlier quoted context omitted.

No need to play this scenario in your head, here it is in the real world: https://en.wikipedia.org/wiki/Windows_RT Few interested hardware vendors, discontinued after 4 years. "mixed reviews at launch, while critics and analysts deemed it to be commercially unsuccessful" Windows 10 S was another attempt that "Similarly [restricts] software installation to applications obtained via Windows Store." Cancelled after one…

I think it’s because the Microsoft Store barely has any apps that users use. The Microsoft Store didn't support the Win32 API, so developers had to rewrite their apps. iOS was a new SDK from the start.

Wait, you lost me somewhere. The MS store didn't support the old way of doing things, people had to rewrite their software; yet iOS was... new as well? People had to start from scratch and so that worked?

Re: Your phone is about to stop being yours

#860
post #330

Earlier quoted context omitted.

Of course they have other motivations But for 1 person wanting to run their own software there are hundreds of people with the potential to install malware/crapware/etc

Had to read that sentence twice. You really think that there's more people getting scammed via "please tap the build number seven times and then go to extra settings and enable untrusted installs and then go to this website that I will dictate the URL of and you should ignore that install warning" etc etc etc. to install an apk to run software that can barely access more than a simple webpage could, than there are pe…

> more people getting scammed via "please tap the build number seven times and then go to extra settings and enable untrusted installs and then go to this website that I will dictate the URL of and you should ignore that install warning" etc etc etc.

I don't really understand. You seem to be against the 'annoyance' of the protections, but that annoyance is precisely why the scammed count is lower, no?

I certainly believe _more generally_ that the market for scam victims is much bigger than the market for sideloaders, for example.

Post reply on HN