Live data from Hacker News

GrapheneOS – Break Free from Google and Apple

blog.tomaszdunia.pl

921–930 of 967 posts

Re: GrapheneOS – Break Free from Google and Apple

#921
post #560

Earlier quoted context omitted.

I assume this is all technically correct, but in practice I've not noticed any speed difference between stock Pixel and GrapheneOS. Maybe their Vanadium browser when tab switching, that feels slow, but I wasn't planning on being part of the Chromium monoculture anyway so this doesn't matter to me

That's great and, of course, only your experience matters to the choice of which OS you use. I just don't want people to get the impression there are no tradeoffs. Another tradeoff GrapheneOS makes is because of the way they configure the USB port makes it more possible that you will irreversibly brick your phone by accident. You could say that the USB management is the only really material difference between Android…

It doesn't make it more possible to irreversibly brick your phone. Even if you set it to the most strict setting the port still works when you are in the bootloader and recovery modes. See https://grapheneos.org/features#usb-c-port-and-pogo-pins-con...

Also, it isn't the only materials difference in that threat model. To just give on example, the autoreboot feature is also useful for that.

Re: GrapheneOS – Break Free from Google and Apple

#922
post #416

Earlier quoted context omitted.

Yeah Pixels are poor quality. Mine developed the common pink vertical line display issue after 18 months The flag ship should not be more than $500

> The flag ship should not be more than $500 Which is (almost) the case during sales. The P10 was on sale for $599 not long ago, and you could buy a 9a for little more than $300. That is extremely good value compared to any iThing repoted your every move to Apple.

$600 to last 18 months? Disagree

Re: GrapheneOS – Break Free from Google and Apple

#923
post #581

Earlier quoted context omitted.

That's great and, of course, only your experience matters to the choice of which OS you use. I just don't want people to get the impression there are no tradeoffs. Another tradeoff GrapheneOS makes is because of the way they configure the USB port makes it more possible that you will irreversibly brick your phone by accident. You could say that the USB management is the only really material difference between Android…

Not sure if I'm understanding you right, but I wasn't saying that my experience is the only one that matters. Just that it's not a thing one notices in practice, at least not under conditions I've experienced (I figure a reader can fill in that last bit for a comment written in the first person). Saying AOSP's is "much, much faster" suggests it would be noticeable and afaik it's not (at human timescales), so I wanted…

Leaving USB dubbing enabled just exposes a lot of attack surface. And if you use USB debugging you are placing a lot of trust in the computer you are connecting to. You don't need USB debugging to reflash GrapheneOS or to sideload updates from the recovery mode. So, it's not relevant to prevent a device brick.

Re: GrapheneOS – Break Free from Google and Apple

#924
post #636

Earlier quoted context omitted.

GOS creates a complete bunker of a phone that can provide defense against pretty much all but the most dedicated state level actors. If you're worried that someone would steal your phone specifically to target you, Graphene will protect against that. Securitywise it's hard to argue against them, although GOS tends to sacrifice usability in favor of security, which leads to odd decisions. Their device depreciation tim…

It's a misconception that GrapheneOS is focused on security over everything else. It's a privacy project and privacy depends on security so it heavily focuses on both. It also provides major privacy improvements on a technical level rather than only avoiding privacy invasive apps and services. Privacy involves a lot more than which apps and services are bundled with the OS, contrary to how most supposedly private pho…

Given I don't disagree with you about GOS being the best on security, I think there's only one thing really worth mentioning:

> The attacks towards us including your libelous claims about us here are what's absurdly toxic.

I want to make this clear upfront: I have no connection to /e/, Calyx, DivestOS or whatever other projects you've had issues with over the years. If you've had trouble with them I find that very unfortunate for you, but they are entirely unrelated to this conclusion. I do not consider these claims to be libelous when they're fairly easy to check:

The reason I consider GOS' community to be extremely toxic and find official channels enabling this is for a few very simple reasons:

1. I've seen several incidents of GOS users coming into adjacent Android communities to start beef with those communities while giving off the attitude of zealots. For a concrete example, the F-Droid forums have a thread about Googles impending changes to letting users install their own software ( https://web.archive.org/web/20250903081432/https://forum.f-d... ). The original OP for this thread has a pointless attack on the F-Droid project, declaring GOS to be superior. Moderators eventually changed this to be more mild (but it's why the first replies are snarking on low-hanging fruit about GOS), but I've seen similar behavior in other places - there's a reason that a lot of Android communities generally respond with trepidation and annoyance whenever the project is brought up and it's because of this behavior from the userbase.

2. I can read the GrapheneOS forums; they're public. Nearly every issue I've seen people have with GOS on the forums is effectively met by a "you're holding it wrong". This sets a tone for the community that makes it come across as extremely hostile to potentially interested users.

3. In the same sense, it's trivial to notice that the official GrapheneOS account on this forum is a frequent participant in these discussions, generally backing up the hostility on the virtue of technical accuracy. This to me suggests endorsement of this attitude. (See a sibling to my initial comment where the official account makes a post on the GOS forums about an unrelated blog for daring to recommend a different ROM/phone combo. This to me is not indicative of healthy communications, but rather of an obsession to promote GrapheneOS at every corner.)

4. I remember, as a Bromite user, the futzing with the Vanadium license in order to prevent other Android Chromium forks from making use of it's patches for the crime of... considering a contribution from someone the GOS project has beef with. That to me is the most telling thing really. The goal with that license futzing was never to actually help advance privacy/security or anything like that. It was to try and force a different project to conform to GrapheneOS' demands over something extremely minor and GOS went ballistic and threatened license changes (which they eventually did) the moment the maintainer asked for a bit more information because "GOS doesn't like this person" isn't enough to immediately warrant kicking someone off a project. Cromite (the fork of Bromite, as Bromite's maintainer went AWOL) still doesn't include Vanadiums hardening patches because of this. It's fucking absurd.

4 is the big one for me. It is absolutely unacceptable, unbecoming and to put it plainly: toxic behavior from an official voice in the project. It's fucking rich and borderline hypocritical to talk about GOS' consistent upstreaming of Android hardening patches while making it impossible through a license change for other projects to share it's contributions.

(Here's a source for that btw; https://github.com/bromite/bromite/issues/2141 and https://github.com/bromite/bromite/pull/2102 for the original incident. csagan5 essentially got jumped with extreme hostility for something they couldn't have been aware of and was very reasonable about, and all they got in response was more threats and hostility.)

Re: GrapheneOS – Break Free from Google and Apple

#925
post #571

One thing that is a game changer on GrapheneOS is the network toggle for apps. Turn off network access for your keyboard, camera app, calculator, files, etc.

Definitely one of the best features to have this in the native UI, though it's also possible in other ways If anyone wants this without GrapheneOS: https://f-droid.org/packages/dev.ukanth.ufirewall If anyone wants this without GrapheneOS and without root: https://f-droid.org/packages/net.kollnig.missioncontrol.fdro...

That's not at all a similar approach so it doesn't quality as "if anyone wants *this*). The GrapheneOS feature pretends the network is down and local host is also inaccessible. This is good for compatability (apps generally take into account that a network can be down) and too avoid apps knowing you are using the feature.

Re: GrapheneOS – Break Free from Google and Apple

#926

FYI: Google Fi + GrapheneOS doesn't work. My son recently tried setting up GrapheneOS and got everything working but couldn't get connected to Google Fi to work, even with a SIM card.

It works but you need to install the Google Fi app from the Google Play Store.

Re: GrapheneOS – Break Free from Google and Apple

#927
post #700

This is the phone version of saying “the power utility is an evil awful monopoly that treats me like shit, so I’m gonna get solar and batteries and go off grid.” It’s cool it’s possible, but it’s not practical for most people.

What do you think the major practical downsides are? Maybe you are not aware of how many things perfectly work or how easy some workaround are, so I am wondering.

Re: GrapheneOS – Break Free from Google and Apple

#928

Does anyone have an answer to the problem of an OS for a laptop? I'm thinking about strong security here, less so about privacy (which is doable, for example via a Linux distribution).

ChromeOS (most secure OS), MacOS (most secure firmware and still much more secure OS compared to non-ChromeOS competitors)

Re: GrapheneOS – Break Free from Google and Apple

#929

There's several AOSP based ROMs in forums like xda. Mostly developed by enthusiasts. Recall using one years ago on my Samsung device with happy results. That was long before banking apps etc. Wondering what's the difference with this? Extra security?

This is a production grade OS, it's made by professionals, it's not hobbyist. It keeps up with updates of upstream Android and Linux kernel. It has a ton of good security and privacy features.

Re: GrapheneOS – Break Free from Google and Apple

#930
post #9

Earlier quoted context omitted.

Because google actually cares about hardware and software security. Read the FAQ: https://grapheneos.org/faq#supported-devices

>Because google actually cares about hardware and software security. That statement might not have aged so well, especially consindering googles attempt to lock out apps from their devices, If the developers do not comply with being oficially registered.

That's not at all what Google announced.

It has nothing to do with devices. It has to do with OSes, most notably OSes certified by Google, which GrapheneOS isn't.

Also, it will be possible to bypass it even on certified OSes.

Post reply on HN