Live data from Hacker News

GrapheneOS – Break Free from Google and Apple

blog.tomaszdunia.pl

931–940 of 967 posts

Re: GrapheneOS – Break Free from Google and Apple

#931

I really don't want to give Google money so the Pixel is off for me until GrapheneOS supports something else. For now I consider smartphones as disposable toys that can't be trusted with anything sensitive and use a computer for privacy. I also don't like the idea of running Android, I still hope for a real linux phone at some point.

Phones, to just give one example, at least have fine-grained run-time permission controls while on Linux apps can just access anything the user can, except if you use something like Flatpak which gives you sandboxing but the quality of that sandboxing is still worse than Android 4.4 KitKat. How can you protect your sensitive info without such permission controls that gate access to your personal data?

Note that this is just one example, there are also other problems with traditional desktop OSes and a large portion of desktop hardware.

Re: GrapheneOS – Break Free from Google and Apple

#932

As great as GrapheneOS has been, I'm still tempted to switch to LineageOS. Sure, it would be objectively less secure, but at least then I might be able to disable the obnoxious "automatically disabled 3 unused background apps" notifications. The biggest problem with security culture is its obsessive hyperfocus on security. Any change that could possibly be less secure (even in extremely exclusive circumstances) must…

> Even if it improves accessibility, it must be rejected out of hand

GrapheneOS has many exploit mitigations and those that would break compatability with too much apps are opt-in instead of opt-out. They also have per app toggles so you can decide to use them per app. So they certainly don't sacrifice accessibility for the highest level of security.

> GrapheneOS promises to liberate us from the enshittification of Google's anticompetitive moat

This isn't something GrapheneOS promises anywhere on their website. They aim to offer a secure and private OS with good compatability with Android apps.

> but it focuses that effort exclusively on security.

They focus on privacy and usability as well. Security is actually only focused on because the privacy features aren't enforceable without security.

> Why is that constantly treated as an unreasonable fantasy?

Because tinkering, hackability and unrestricted freedom aren't the purposes for which GrapheneOS was made.

Re: GrapheneOS – Break Free from Google and Apple

#933
post #306

"Break free from Google" and buy a Pixel phone from them to do so. But unironically Pixels are currently some of the best actually open phones. They do not lock down or require shady practices for unlocking the bootloader (although they do require a network check once that happens automatically, but it will permanently allow unlocking the bootloader if successful once. Pixels are very easy to restore and almost un-br…

[dead]

Re: GrapheneOS – Break Free from Google and Apple

#934
post #858

Earlier quoted context omitted.

I originally wanted to get the Pixel camera app working when I got started with GOS a few years ago, but then I found Open Camera and haven't looked back. Does it do something cool that Open Camera doesn't?

You can select the different cameras and avoid digital zoom.

Open Camera does that though. It's right next to the main "take photo" button. At least on the version I have.

Re: GrapheneOS – Break Free from Google and Apple

#935
post #160

Earlier quoted context omitted.

Same with Lineage OS, may daughter has an old Samsung with Lineage on it and the Wallet app doesn't work because the phone's been rooted.

Wallet app is still impossible to get working, but there’s been some development recently: https://github.com/microg/GmsCore/issues/361 Some other apps are often willing to accept my current setup (Lineage for microG [0], plus Magisk, if you don’t need root – Magisk Hide does some magic I don’t really understand, but even without Play Integrity passing, apps just start working). With more tweaks, you might be able to…

Well, I’ve jinxed it. My current “neobank” of choice, TNG eWallet, is onto me now :(

(Not because of my comment, probably – I’ve upgraded LineageOS and had to reinstall everything. But just in case you guys read this – please, just let me bypass it, I’m aware of the risks :)

Re: GrapheneOS – Break Free from Google and Apple

#937

Earlier quoted context omitted.

Not very meaningful to create yourself a problem to heroically overcome it later. You can already create enough problems unintentionally.

I don't quite follow your reasoning. All bugs are (usually) unintentional and created by the programmer.

By not using special chars in the first place, you can be sure you will not be able to run into any (unintentional) bugs later.

And not using special chars is cheap, as by requiring a min-length of 13 instead of 12, you can get an even greater level of security.

Re: GrapheneOS – Break Free from Google and Apple

#938
post #371

About his comment: > Unfortunately, I must recommend Windows 10/11 here, because then you don’t have to mess around with any drivers; it’s the simplest option. When I worked at Microsoft but ran FreeBSD at home, I often used my work Windows laptop to install custom ROMs. This is because FreeBSD was finicky with adb. Now I run Fedora and the Android drivers are pre-installed. I installed GrapheneOS on both a Pixel 10…

You can even install GrapheneOS from another GrapheneOS Vanadium browser. No computer required.

Re: GrapheneOS – Break Free from Google and Apple

#939

Earlier quoted context omitted.

I'm trying to say the same thing I said up at the top: GOS's approach to privacy is obtuse. They deliberately conflate security with privacy (you even write "secure/private" as though they're the same thing) in a way that does a disservice to users. My opinion is that GOS is very successful at its own stated goal of having an extremely secure mobile OS that rolls out patch updates quickly. I think it's far less succe…

> They deliberately conflate security with privacy (you even write "secure/private" as though they're the same thing) in a way that does a disservice to users. That's not really true. In fact, the way you are presenting it, as if they were seperate is doing a disservice to the reality and therefore to the users. You can't have privacy without security. Security is what enforces the privacy. If your system is insecure…

> You can't have privacy without security. Security is what enforces the privacy. If your system is insecure, privacy controls can be bypassed.

Again, this is an obtuse perspective. A system that doesn't collect or store private data never needs to concern itself with securing that data.

I am concerned with reducing casual data exposure to the adtech industry. I am not worried about being targeted by nation state actors.

Re: GrapheneOS – Break Free from Google and Apple

#940
post #247

Earlier quoted context omitted.

Some others that I use: * NextCloud -- client for personal NextCloud server; this app is used primarily for file sync, with other features accessed with other apps. ( https://nextcloud.com/features/?filter=Clients#android-clien... ) * KeePassDX -- password manager, shares DB with KeePassXC on desktop, which is synced via NextCloud. Also functions as a TOTP authenticator. ( https://www.keepassdx.com/ ) * DAVx5 -- CalD…

> I don't see F-Droid itself mentioned F-Droid itself is great, but I find that the NeoStore front end to F-Droid is superior because it has multi-repository capability, offering a long list of alternative apk sources that can readily be verified for quality.

Neo Store looks interesting, but the readme in the GitHub repo includes emojis in the feature list, which is a bit of a red flag for me, especially since the project appears to have started only two years ago.
Post reply on HN