Live data from Hacker News

GrapheneOS – Break Free from Google and Apple

blog.tomaszdunia.pl

871–880 of 967 posts

Re: GrapheneOS – Break Free from Google and Apple

#871

Earlier quoted context omitted.

No, they will either immediately or shortly thereafter require you to link a phone number, etc

You can create a Google account without adding a phone number, that's still possible currently. To do this you need to make it within an app, for example Google Play Store or YouTube, not on the websites. You also need to use a trusted IP, so you shouldn't use a VPN. To avoid handing out your home WiFi IP, you can use a public WiFi point or use cellular which cycles IPs more quickly.

Prepare for a subsequent login to result in a 'security check' that asks for more personal details to confirm your account, or you'll be locked out.

In my experience, this can come as soon as the first login after creating the account, or a few logins later.

Re: GrapheneOS – Break Free from Google and Apple

#872

I've used GrapheneOS on a Pixel 3a, 5, 8 and 10 Pro so far and it's worked really well. I couldn't imagine going back. The only things I'm missing (which don't exist in other OS'es either): - Being able to configure contact scopes in such a way that the app in question only gets access to the phone numbers of the contacts belonging to the label I specified, e.g. "WhatsApp", nothing more. Yes, one can of course add co…

> Being able to configure multiple VPNs at once, e.g. for Tailscale, ad filtering, blocking HackerNews during times when I should be doing something more productive AdAway (in F-Droid) can block with /etc/hosts (no VPN involved) if you have root. The hosts blocking still works even when connected to a VPN. Aside from loading ad domain lists into /etc/hosts, it also allows you to specify custom domains to block - I pe…

> AdAway (in F-Droid) can block with /etc/hosts (no VPN involved)

lifts head

> if you have root

Sigh. :)

Sure, on LineageOS back in the day I used to edit /etc/hosts by hand. On GrapheneOS I no longer have root, though (unless I compile it myself), which generally I think is a good idea, weren't it for Linux's absolutely abysmal access control system that requires you to be root for almost everything.

Re: GrapheneOS – Break Free from Google and Apple

#873

Earlier quoted context omitted.

I switched bank in the UK due to enforced app use, from Starling to Nationwide. They use a card reader to issue codes, so I can still use the web. I see this as a much of a must-have as physical bank branches with real cashier services.

But Starling has always been app only?

You can bank via the website here: https://app.starlingbank.com/login

Might be more limited than the app though.

Re: GrapheneOS – Break Free from Google and Apple

#874

Earlier quoted context omitted.

Alternatively, consider PineTime, which even offers a choice of the OS it runs: https://pine64.org/documentation/PineTime/

Also there's AsteroidOS which is a wrist sized linux for your watch, and looks fantastic! - https://www.youtube.com/watch?v=U6FiQz0yACc

Related discussion: https://news.ycombinator.com/item?id=47051852

Re: GrapheneOS – Break Free from Google and Apple

#875

I've used GrapheneOS on a Pixel 3a, 5, 8 and 10 Pro so far and it's worked really well. I couldn't imagine going back. The only things I'm missing (which don't exist in other OS'es either): - Being able to configure contact scopes in such a way that the app in question only gets access to the phone numbers of the contacts belonging to the label I specified, e.g. "WhatsApp", nothing more. Yes, one can of course add co…

> Being able to install browser extensions in Vanadium. You can use IronFox - available in Accrescent store that comes with GrapheneOS, and install firefox extensions

So uh… why not just use Firefox directly?

Yes, I already do that but: - Vanadium is said to be safer. - The reality is that websites often don't work in Firefox anymore. - I want to be able to block social media at certain times. (Today I often circumvent such blocking in FF by just opening Vanadium…)

Re: GrapheneOS – Break Free from Google and Apple

#876
post #731

Earlier quoted context omitted.

You might want to read my comment again. :) If you use labels, the app will have full access to the associated contacts, not just to their names & phone numbers.

So it's not about labels, but you want the ability to restrict the fields an app has access to rather than an all or nothing – full access to a contact or none at all?

Precisely!

Re: GrapheneOS – Break Free from Google and Apple

#877

Earlier quoted context omitted.

You might want to read my comment again. :) If you use labels, the app will have full access to the associated contacts, not just to their names & phone numbers.

I'm annoyed at everyone who shares my name, phone number and any other details with Meta. I never consented to it. The behavior of their app slurping up your contacts database is despicable. This doesn't answer your question, but in case it helps for others out there: it's possible to use WhatsApp with no access whatsoever to your contacts and I used it that way for years. Connecting with people is slightly jankier b…

> it's possible to use WhatsApp with no access whatsoever to your contacts and I used it that way for years.

Yeah, that's what I do right now.

> Connecting with people is slightly jankier but it still works.

Without GrapheneOS's contact scopes, how exactly do you do that? Doesn't the other person have to message you first?

Re: GrapheneOS – Break Free from Google and Apple

#878

Earlier quoted context omitted.

Meanwhile, it's probably A-OK for the app to run on a phone that hasn't received security updates for 5 years. I don't get it. If they're worried about liability, why not check the security patch level and refuse to run on phones that aren't up to date? I'm guessing it's because there are a lot of phones floating around that aren't updated (probably far more than are rooted), and they're willing to pretend to be secu…

> If they're worried about liability, why not check the security patch level and refuse to run on phones that aren't up to date? Google doesn't provide an API or data set to figure out what the current security patch level is for any particular device. Officially, OEMs can now be 4 months out-of-date, and user updates lag behind that. Your guess is good, but misses the point. Banks are worried about a couple things w…

[dead]

Re: GrapheneOS – Break Free from Google and Apple

#879

Earlier quoted context omitted.

That's pretty funny on a few levels, not in the least that they required a "secure" password like that but stored them in plain text.

My bank’s password field is case insensitive. Of course they could have lowercased it before hashing but I doubt it.

That's scary. I wonder if incompetence like that could lead to a lawsuit in the case of a breach.

At this point I wouldn't be surprised if there exists a system that just asks for username with a checkbox "check here if you are the owner of this account"

Re: GrapheneOS – Break Free from Google and Apple

#880
post #345

Earlier quoted context omitted.

A collegue of mine was tech lead at a large online bank. For the mobile app, the first and foremost threat that security auditors would find was "The app runs on a rooted phone!!!". Security theater at its finest, checkboxes gotta be checked. The irony is that the devs were using rooted phones for QA and debugging.

ive seen: -"but ios can be jailbroken and it doesnt have an AV!" while the MDM does not allow jailbroken devices, and they also allowed sudo on linux. auditors are clueless parasites as far as im concerned. the whole thing is always a charade where the compliance team, who barely knows any better tries to lie to yhe auditor, and the auditor pick random items they dont understand anyway. waste of time, money and human…

[dead]
Post reply on HN