Live data from Hacker News

GrapheneOS – Break Free from Google and Apple

blog.tomaszdunia.pl

941–950 of 967 posts

Re: GrapheneOS – Break Free from Google and Apple

#942
post #937

Earlier quoted context omitted.

I don't quite follow your reasoning. All bugs are (usually) unintentional and created by the programmer.

By not using special chars in the first place, you can be sure you will not be able to run into any (unintentional) bugs later. And not using special chars is cheap, as by requiring a min-length of 13 instead of 12, you can get an even greater level of security.

Got it, thanks! That makes sense.

Re: GrapheneOS – Break Free from Google and Apple

#943
I've found that your experience with GrapheneOS greatly depends on which country you're in and which mobile provider you use. I'm on Freedom Mobile in Canada and I had enough issues that I went back to stock. RCS didn't work at all, and my phone would regularly lose the cellular connection to the point I had to reboot the phone and reset the cellular network settings. I didn't feel like I could trust it in an emergency situation so I reverted. There are also times I'm out of cell coverage and having satellite SOS would be invaluable.

Some of these issues are known and some are just features the project won't support. Last I heard they aren't going to support satellite messaging at all.

Re: GrapheneOS – Break Free from Google and Apple

#944

Earlier quoted context omitted.

No, because most banking apps call upon the Google Play Integrity API, which GrapheneOS doesn't (or can't?) use. There's a decent list kicking around of which ones work (Monzo, for instance). https://privsec.dev/posts/android/banking-applications-compa...

It's more common in banking apps than in other apps to implement Play Integrity but it's cetainly not "most banks" that do it. It's still only a small subset. Sucks of course if it's your bank.

Maybe not in your region, but here in the UK I think the majority of high street banks do not function on GrapheneOS.

Re: GrapheneOS – Break Free from Google and Apple

#945
post #895
post #727

Earlier quoted context omitted.

The founder, afaik, not just a developer. Tor Browser seems to be a project that requires multiple full time developers. I don't think GrapheneOS have the resources right now to do this alongside their OS development, device support and app overhaul plans. Also please don't take this as any criticism of your suggestion, but there have been multiple 'privacy' browser projects based on Chromium for Android. It's a litt…

> Tor Browser seems to be a project that requires multiple full time developers. I don't think GrapheneOS have the resources right now to do this alongside their OS development, device support and app overhaul plans. We're in the process of hiring a bunch of full time developers and will have more people working on Vanadium soon. The bottleneck isn't money but rather building out the organization and hiring people. W…

I missed this in the bustle of this thread but that's fantastic news. Hugely appreciative of the work yourself and your team at GrapheneOS are doing and it is great to hear it will be expanding/growing too.

Re: GrapheneOS – Break Free from Google and Apple

#946

Earlier quoted context omitted.

No it's not, but it's bundled in the same basket. "Didn't pass DEVICE_INTEGRITY -> rooted"

Yep that's my experience as well, if you don't get the play protect™ absolution your device is seen as rooted. Latest app to display this BS behavior was PagerDuty, I guess they have to protect their secret sauce of calling an API and showing notifications

Huh, that would be absurd if PD did that.

I know some people have issues with Duo, I don't, with pager duty i _just_ installed th last version from Play store, logged in with sso to my org and I'm in, can do or see everything.

Maybe it's play services in your case, not play integrity? I'm on the last release from the stable channel.

Re: GrapheneOS – Break Free from Google and Apple

#947

Earlier quoted context omitted.

If the open hardware offers at least comparable security then maybe. If the hardware is an open book then no. A short list of the hardware security measures necessary to consider it "not a toy" ;) -- https://grapheneos.org/faq#future-devices

I'm not convinced that all of these is required for security. My Qubes OS desktop is probably more secure than any GrapheneOS phone, and it only requires good hardware virtualization for that. > If the hardware is an open book then no. So you choose security through obscurity. I have no further questions.

If you choose open platform with barely any hardware security measures then indeed, no questions from me either :)

Re: GrapheneOS – Break Free from Google and Apple

#948

Earlier quoted context omitted.

I wish I could stop using them for these rare occasions I need a transport. Taxi across the town is £20, Uber usually 5-10. There are no other providers. Taxi from my airport (some 15 miles away) is £60-80, Uber usually £30-ish. Public transportation (2 trains + 2 buses) over £50. I wish I had an option.

I get public transport being more "difficult" than uber, but more expensive too? Where are you from if you don't mind me asking?

Yeah, it's more expensive - in this case because of the changes and separate operators on every part of the journey. I could potentially swap one train for a bus and then take different train and skip one of the buses saving some £5 but extending trip by about a hour at least.

Re: GrapheneOS – Break Free from Google and Apple

#949

As great as GrapheneOS has been, I'm still tempted to switch to LineageOS. Sure, it would be objectively less secure, but at least then I might be able to disable the obnoxious "automatically disabled 3 unused background apps" notifications. The biggest problem with security culture is its obsessive hyperfocus on security. Any change that could possibly be less secure (even in extremely exclusive circumstances) must…

> Even if it improves accessibility, it must be rejected out of hand GrapheneOS has many exploit mitigations and those that would break compatability with too much apps are opt-in instead of opt-out. They also have per app toggles so you can decide to use them per app. So they certainly don't sacrifice accessibility for the highest level of security. > GrapheneOS promises to liberate us from the enshittification of G…

It's good enough for you, and therefore it can't get any better. Interrupting the user with pointless notifications is not security. Removing the ability to disable those notifications is only a security feature if the user wants then in the first place!

The problem here is more than the lack of interest in making a system that is both secure and usable. It's the outright rejection of usability as a goal.

Re: GrapheneOS – Break Free from Google and Apple

#950
post #905

Earlier quoted context omitted.

> Extraordinary claims require extraordinary evidence. It's your claims which are extraordinarily and have been thoroughly debunked. You're directly engaging in bullying with baseless personal attacks. You make false accusations about us while you're actively engaging in those things. > I find it very hard to reconcile claims like "repeated swatting attacks aimed at killing our team members...Child Sex Abuse Material…

Please print out this comment and the one that preceded it and show it to a friend you trust to be honest. You should seek therapy, and it will make you a more effective technical leader.

I'm surprised Graphene foundation haven't banned or heavily restricted Daniel Micay from publicly representing GOS. He's fine when he's providing product updates and technical information but he absolutely needs to see a therapist. I know he's been told this a million times and I'm not sure if he takes it serious enough. If he doesn't do something about this behaviour, his spiraling will be the downfall of GOS.
Post reply on HN