Earlier quoted context omitted.
Gotcha, I guess my question is, why not both? Is it the requirement of special chars over a min-length password that is in question here? Like the system is like "minimum 8 char password but also three special chars, ancient heiroglyphs, and the blood of your firstborn child" when you can omit the special chars and just have min 16 char password for the same security benefit?
Not very meaningful to create yourself a problem to heroically overcome it later. You can already create enough problems unintentionally.
GrapheneOS – Break Free from Google and Apple
901–910 of 967 posts
Re: GrapheneOS – Break Free from Google and Apple
#902Earlier quoted context omitted.
Meanwhile, it's probably A-OK for the app to run on a phone that hasn't received security updates for 5 years. I don't get it. If they're worried about liability, why not check the security patch level and refuse to run on phones that aren't up to date? I'm guessing it's because there are a lot of phones floating around that aren't updated (probably far more than are rooted), and they're willing to pretend to be secu…
Because a phone running an unknown OS is significantly more dangerous than a phone that hasn't received security updates for years. For example, a malicious OS maker could add their own certificate to the root store, essentially allowing them to MitM all the traffic you send to the bank. Liability works on the principle that "if it's good enough for Google, it's good enough for me." A bank cannot realistically vet ev…
Also in my experience a rooted phone experience is by far more secure than the OEM androids. Security is supposed to assess risk objectively, yet "running on a Xiaomi phone with 3rd party apps that cannot be uninstalled and have system access" is somehow more secure than "running on a signed LineageOS where user can edit hosts file".
Re: GrapheneOS – Break Free from Google and Apple
#903The main problem with the Pixel phones, along with most Android phones these days, is the lack of a μSD card slot and a 3.5mm headphone jack. When I recently had to purchase a new phone, I had to go with a Motorolo G, as it had both of those features.
Re: GrapheneOS – Break Free from Google and Apple
#904Earlier quoted context omitted.
> I'd never use GrapheneOS since I don't trust the project Fair enough, you choose what you trust. But personally, I have never seen a technical claim from GrapheneOS that was wrong or misleading. But I have seen many claims from /e/OS that were technically wrong or misleading. So I trust GrapheneOS more. Then there is the drama, and all sides annoy me when they behave like this. But I have seen drama coming from all…
I have never seen drama from /e/ or any other project GrapheneOS attacks, like Calyx. Please link me to it - I asked this several times, people never can follow up. So far?
Re: GrapheneOS – Break Free from Google and Apple
#905Earlier quoted context omitted.
The founder and CEO of /e/ and Murena openly spreads content from Kiwi Farms and neo-nazi sites. He directly engages in harassment towards the GrapheneOS team. Here's him supporting authoritarians smearing GrapheneOS by replying to threads about it linking to harassment content based on fabrications on a neo-nazi conspiracy site: https://archive.is/SWXPJ https://archive.is/n4yTO The communities of several projects in…
Extraordinary claims require extraordinary evidence. I find it very hard to reconcile claims like "repeated swatting attacks aimed at killing our team members...Child Sex Abuse Material..." with the proof offered being a blog post that makes the fairly anodyne (especially read in light of this comment) case that you are an extremely paranoid person whose paranoia leads you to extreme judgements that may harm users. I…
It's your claims which are extraordinarily and have been thoroughly debunked. You're directly engaging in bullying with baseless personal attacks. You make false accusations about us while you're actively engaging in those things.
> I find it very hard to reconcile claims like "repeated swatting attacks aimed at killing our team members...Child Sex Abuse Material..." with the proof offered being a blog post that makes the fairly anodyne (especially read in light of this comment) case that you are an extremely paranoid person whose paranoia leads you to extreme judgements that may harm users. If you are the target of extreme attacks, it seems far more plausible to me that those originate from state actors and security adversaries, rather than from erstwhile allies also trying to build better mobile OSes.
It's very easy to see that the site which was linked is a neo-nazi conspiracy site. Gaël Duval knew that when linking to it. Gaël Duval has repeatedly spread harassment and libel content from Kiwi Farms and elsewhere. He has linked to the same harassment content linked in the post. Both of those videos are from Kiwi Farmers and one of them participates on the site with an account in their real name which received identity verification. They openly use the site as their personal army and were the one to involve them.
Duval very clearly knows that he's directing his community to target our team with harassment by spreading fabricated stories about us. Anyone can take a look around the site which was linked and see a whole lot of the paranoia and delusion you falsely attribute to me with no basis. Duval is opportunistically spreading harassment content to benefit his for-profit business for the same reason he has heavily invested in spreading misinformation about GrapheneOS.
Duval is not an ally. He's a grifter selling phony privacy products with dramatically worse privacy and security than an iPhone. They're scamming people with false marketing for their products. The supposedly private speech-to-text service from Murena actually just sends user data to an OpenAI service vs. iOS and GrapheneOS doing it locally which is very representative of their overall approach to the apps, services and OS.
https://community.e.foundation/t/voice-to-text-feature-using...
https://discuss.grapheneos.org/d/24134-devices-lacking-stand...
GrapheneOS is the only open source privacy and security hardened mobile OS based on AOSP in practice. Products using privacywashing for marketing aren't in the same space. They're not allies but rather the misinformation they propagate and the attacks they make on our team are extremely harmful to us. They're the main adversaries. Companies like Microsoft tend to be very friendly to us and open to collaboration vs. these small companies building a business around false marketing who feel very threatened by us so they engage in spreading misinformation and personal attacks on us. Claiming that it's state sponsored is ridiculous. It has been ongoing since long before GrapheneOS had significant adoption and has always been primarily caused by companies who feel threatened by GrapheneOS trying to harm it. Multiple companies have engaged in it because it's very convenient for them to hop onto the existing bandwagon of fabrications/harassment started in 2018. The privacy and security industries are filled with charlatans and scams. We have good relationships with a bunch of legitimate privacy and security projects including QubesOS, secureblue, Molly, Accrescent and MANY others. It's these companies selling supposedly private/secure phones which are in reality not very private and extraordinarily insecure where nearly all the attacks originate from.
> Rather than reading this as "harassment", I would suggest you should try to take it as constructive feedback: You do not play well with others and your prickly interpersonal demeanor hampers the adoption of what is (by all accounts) technically strong software.
It's libelous harassment content based on fabricated stories. You're claiming it's not happening while directly engaging in it. You're making the ridiculous claim that it's from state actors while the actual perpetrators are plainly visible and include yourself. It's the community around /e/ and several other projects which are extraordinarily toxic and engaging in harassment. Our community and project doesn't do it. You folks cross-reference your libel, bullying and harassment content entirely based on making up stories, personal insults, etc. while claiming a bunch of fabrications referencing each other is evidence. Calling me paranoid, delusional, etc. with no basis is nothing more than sociopathic bullying. Hacker News moderators shouldn't be allowing it.
Re: GrapheneOS – Break Free from Google and Apple
#906Earlier quoted context omitted.
> Sorry, but then I take this as the usual Sure, you're free to do what you want. Just sharing my opinion given that I follow those projects from the outside. > You or other readers can check I guess what I am trying to say is that it takes multiple sides to argue. For what it's worth, your link shows the founder of /e/OS engaging there. I have seen both technically wrong and misleading claims from the founder of /e/…
I still haven't seen what you describe, the behaviour of other projects. And I dont believe it without proof (since it was claimed so often by GOS without proof being shown, or in some cases with it obviously not existing). For the security thing: It is wrong to claim that an unlocked bootloader completely breaks the android security model. If anything, it breaks one specific aspect, one that doesn't matter for many…
Re: GrapheneOS – Break Free from Google and Apple
#907Earlier quoted context omitted.
I think it's more of a marketing claim from less secure systems that "privacy is not security, and GrapheneOS focuses on security while we focus on privacy". GrapheneOS does care about both, quite obviously. And GrapheneOS tends to say that if your security is bad, then it is affecting your privacy too. Whereas others say "sure, we break the Android security model by unlocking the bootloader and signing our system wi…
This is only my opinion, but GrapheneOS's approach to privacy seems obtuse to me. They will claim that an unlocked bootloader is a risk, but then turn around and recommend you install proprietary apps GApps in their sandbox. The sandbox doesn't matter if all the private data is in the same sandbox! Reminds me of https://xkcd.com/1200/
They don't recommend you to do that. They tell people that if people want to install apps, Google Play Store is a secure and easy way to get apps. They inform people about this because some have the misconception that using the Play Store defeats the whole purpose of GOS (which it doesn't) or that the Play Store is highly problematic (it's better than most alternatives). But, the user itself is free to decide what they do. If you look at project members of GrapheneOS, some say they use Play, some say they don't.
> The sandbox doesn't matter if all the private data is in the same sandbox!
That's not how sandboxing works. The sandbox is around the app. Each app is in the sandbox. On GrapheneOS even the componenents of Google Play (Play Store, Play Services and on older installs Play Services Framework) are sandboxed. On Android OSes that bundle Google Mobile Services (GMS), Play gets an exception and is a priviliged app. On GrapheneOS they are regular apps. They are each put in their own sandbox. The access of each is controlled by their own set of fine-grained run-time permissions.
With all due respect, you fundamentally misunderstand how sandboxing works, even on Android in general. I recommend reading this to understand sandboxing in the AOSP: https://source.android.com/docs/security/app-sandbox . On GrapheneOS the sandbox is hardened a bit, but that's not the most significant feature of the OS at all, and Play is forced to run sandboxed if users choose to install it.
Re: GrapheneOS – Break Free from Google and Apple
#908Earlier quoted context omitted.
Feels like you don't know what "the sandbox" is. It's not "their" sandbox, it's from AOSP. When you run an app on Android, it runs in a sandbox. Meaning that your social media app cannot access the files of your banking app by default . They are "sandboxed". On a normal Android, the Play Services are installed as a system app. It is privileged app that has "system" access. A system app is not sandboxed. GrapheneOS al…
If the Tiktok app passes your data to Play Services (say, to support notifications with GCM) then it doesn't make any difference that Play Services is nominally "sandboxed". I agree there's some marginal benefit that sandboxed GApps need to prompt the user for permissions (rather than having privileged system level access) but at the end of the day, Google Maps will get GPS perms and Google will know everywhere your…
If you just grant Google Maps location permission and don't give it to Play Services and keep your sandboxed google play settings to the default, the location requests are rerouted through the GrapheneOS servers. If you want to use network location to get quicker location locks and location indoors, you can also use GrapheneOS network location, so you don't need to use the Google implementation for that.
And, even if you would decide to use Google directly for the location, you can perfectly avoid giving permanent location access. You can hand it over only once or only when the app is in use. So Google doesn't know everywhere your phone goes, at all.
Re: GrapheneOS – Break Free from Google and Apple
#909Earlier quoted context omitted.
> If the Tiktok app passes your data to Play Services (say, to support notifications with GCM) then it doesn't make any difference that Play Services is nominally "sandboxed". Sure, but that's the same if you run TikTok with microG (which will relay your data to the Google servers just like the Play Services) or in waydroid on a Mobile Linux. But you can't blame the system for what the apps are allowed to do by the u…
I agree it's about trade-offs. I think MicroG - which provides dummy no-op implementations of Google Play tracking APIs, and allows you to select alternative Location Providers and notification backends - is a better option than running first-party Google software. You're of course correct that we can't blame the system for choices made by users, but I do think GOS lulls users into complacency by focusing on the secu…
Also, it's not a better option to use MicroG. MicroG is in most OSes where it's bundled running priviliged and still connects to Google. Moreover, their reimpementation isn't complete and also not as well odne as Google's.
> encouraging users to install sandboxed GApps
What you link isn't an encouragement at all. It's offered as an option, because there is a demand for it in order to keep compatability with apps high. It's a usability feature (compatability) that's implemented much more securely and privately than on other OSes because it runs in the sandbox. Users are not forced at all to use it nor are they pushed to it.
Not all GrapheneOS project members (devs and moderators) even use Google Play, so how would they be "lulling us into complacency".
> focusing on the security angle only
The app sandbox isn't only a security feature, it's a privacy feature. Access to your data is gated behind permissions due to the sandbox. This is privacy.
Re: GrapheneOS – Break Free from Google and Apple
#910Does anyone have a good grasp of the differences between GOS and /e/OS? I'm buying a Fairphone soon and was wondering what both are like
GrapheneOS claims to be a lot more secure, having additional hardening. See https://eylenburg.github.io/android_comparison.htm - keep in mind that it is not an independent comparison, the Graphene guys directly feed what this table is supposed to say in the issue tracker, https://github.com/eylenburg/eylenburg.github.io/issues/ . But it gives a good representation of the state of the ROMs according to Graphene. In re…