Live data from Hacker News

GrapheneOS – Break Free from Google and Apple

blog.tomaszdunia.pl

951–960 of 967 posts

Re: GrapheneOS – Break Free from Google and Apple

#951
post #415
post #397

Earlier quoted context omitted.

> I like Organic Maps Does anybody know of a project that offers public transport routing? Ideally with real time information, but I can live with only using schedules or even just average passage interval. The other general sticking point for me is the reviews, but I could invite more serendipity to my restaurant search.

Öffi, if it has coverage for the areas relevant to you: https://oeffi.schildbach.de/index.html

Thanks for the tip, I'll check it out for when I am back in central Europe, but I am currently based in south Europe and sadly my country/city are not covered.

Re: GrapheneOS – Break Free from Google and Apple

#952
post #638
post #93

Earlier quoted context omitted.

/e/OS/ was bad with updates for a long time (I had to switch 2022). IodéOS is very good at it, in my experience (I have used all three)

iodéOS lags far behind on Android, Linux kernel, browser engine and other updates too. It's much less behind than /e/ and misleads users less but they still do. They set an inaccurate Android security patch level which misleads users just as /e/ does.

I didn't know. Do you have a link to one specific announcement where they mislead people about the patch level? It would help to start a conversation to change that.

Re: GrapheneOS – Break Free from Google and Apple

#953

Earlier quoted context omitted.

> Being able to install browser extensions in Vanadium. You can use IronFox - available in Accrescent store that comes with GrapheneOS, and install firefox extensions

So uh… why not just use Firefox directly? Yes, I already do that but: - Vanadium is said to be safer. - The reality is that websites often don't work in Firefox anymore. - I want to be able to block social media at certain times. (Today I often circumvent such blocking in FF by just opening Vanadium…)

IronFox is Firefox with different settings. IronFox is security focused and hardens gecko preferences - https://ironfoxoss.org/docs/features/

Using a Chrome based browser (i.e. Vanadium) is not an option for me because I need my extensions and generally prefer using firefox everywhere.

Re: GrapheneOS – Break Free from Google and Apple

#954

Earlier quoted context omitted.

I'm not convinced that all of these is required for security. My Qubes OS desktop is probably more secure than any GrapheneOS phone, and it only requires good hardware virtualization for that. > If the hardware is an open book then no. So you choose security through obscurity. I have no further questions.

If you choose open platform with barely any hardware security measures then indeed, no questions from me either :)

Which security measures? I do have TMP with Heads.

Re: GrapheneOS – Break Free from Google and Apple

#955
post #858

Earlier quoted context omitted.

You can select the different cameras and avoid digital zoom.

Open Camera does that though. It's right next to the main "take photo" button. At least on the version I have.

I hadn't seen that button, but at least for me it's not enough: I want to be able to select the camera directly. And in Open Camera I can only select two out of the three cameras.

Re: GrapheneOS – Break Free from Google and Apple

#956

Earlier quoted context omitted.

If you choose open platform with barely any hardware security measures then indeed, no questions from me either :)

Which security measures? I do have TMP with Heads.

Let me list several of the more impactful.

- dedicated, certified security coprocessor (Titan M2) - on pixel it's fused with verified boot, offers key storage, firmware isolation and anti rollback.

- verified boot: mandatory and backed by Titan, immutable boot from. Almost all laptops lack as much as anti rollback.

- strong hardware-backed key protection and actually isolated TEE. Yes, I know about Intel (SGX/TDX) and AMD (SEV/SME). Broken into many times over. How many commodity hardware devices offer comprehensive protections like Titan-backed TEE?

- secure hardware-backed disk encryption key derivation (with throttling of course)

- on-device attestation: complete verification of the entire chain. Dreaded Play Integrity or open AOSP / GrapheneOS hardware attestation. Which PC vendors can offer that? Perhaps Apple but that's not a pc and you won't run qubes on that?

- physical anti-tamper: which laptops wipe encryption keys stored in the secure hardware when you're trying to unlock the bootloader?

- physical memory tagging (see ARM MTE). Apple offers some but again, that's not for qubes. Intel promises MKTME in the future.

- does your laptop disable all the unconnected ports whilst the laptop is broken? Does your pin/password verification happen inside TEE/TPM, not in the OS?

- modes similar to PXN/SMEP, SMAP/PAN (to stop these pesky wifi/gpu firmware from reading userpace memory). There's some support for SMEP and SMAP on intel/amd

- microcode and firmware upgrades velocity

There are reasons GOS doesn't support any hardware other than pixels. Regrettably and thankfully that is about to change soon Don't read me wrong, qubes is brilliant and on SOME hardware (business grade laptops with TPM 2.0, verified firmware upgrade process with some protections and proved track progress with rapid hardware drivers and firmware upgrades -- sure, brilliant choice. For pcs.

But is not even remotely close security-wise..

Best available would be probably Purism Libre (lacking TPM if I read it correctly, weak hardware but, oh well, pixel is not super fast either lol), or something with coreboot perhaps?

Whats the safest and still useful laptop hardware you cna think of? Let's compare with with pixel.

Re: GrapheneOS – Break Free from Google and Apple

#957

Earlier quoted context omitted.

Which security measures? I do have TMP with Heads.

Let me list several of the more impactful. - dedicated, certified security coprocessor (Titan M2) - on pixel it's fused with verified boot, offers key storage, firmware isolation and anti rollback. - verified boot: mandatory and backed by Titan, immutable boot from. Almost all laptops lack as much as anti rollback. - strong hardware-backed key protection and actually isolated TEE. Yes, I know about Intel (SGX/TDX) an…

Thanks for the detailed answer. Librem laptop is exactly what I use, with TPM and a hardware token. Also with Qubes OS.

Re: GrapheneOS – Break Free from Google and Apple

#958

I've found that your experience with GrapheneOS greatly depends on which country you're in and which mobile provider you use. I'm on Freedom Mobile in Canada and I had enough issues that I went back to stock. RCS didn't work at all, and my phone would regularly lose the cellular connection to the point I had to reboot the phone and reset the cellular network settings. I didn't feel like I could trust it in an emergen…

I’m with Freedom Mobile in Vancouver, currently using a rather old iPhone. My next phone will probably run GOS.

I have issues with Freedom on my iPhone too. Poor signal, or else “good” signal but poor data backhaul.

Are you pretty sure your issues went away after going back to stock Android? Or is it possible it’s just Freedom Mobile’s general issues?

Re: GrapheneOS – Break Free from Google and Apple

#959

Earlier quoted context omitted.

Wallet app is still impossible to get working, but there’s been some development recently: https://github.com/microg/GmsCore/issues/361 Some other apps are often willing to accept my current setup (Lineage for microG [0], plus Magisk, if you don’t need root – Magisk Hide does some magic I don’t really understand, but even without Play Integrity passing, apps just start working). With more tweaks, you might be able to…

Well, I’ve jinxed it. My current “neobank” of choice, TNG eWallet, is onto me now :( (Not because of my comment, probably – I’ve upgraded LineageOS and had to reinstall everything. But just in case you guys read this – please, just let me bypass it, I’m aware of the risks :)

Okay, I am pleasantly surprised. The fix was to... remove Magisk. Apparently they’re not looking at the Play Integrity, so no workarounds needed. The more you know!

This is way offtopic, so I’ll stop here, but final note in case anybody is looking to get Play Integrity working as well: try the built-in microG implementation first, and if it doesn’t work, go for KernelSU, it seems more stealthy than Magisk. Good luck!

Re: GrapheneOS – Break Free from Google and Apple

#960
post #700

This is the phone version of saying “the power utility is an evil awful monopoly that treats me like shit, so I’m gonna get solar and batteries and go off grid.” It’s cool it’s possible, but it’s not practical for most people.

What do you think the major practical downsides are? Maybe you are not aware of how many things perfectly work or how easy some workaround are, so I am wondering.

The average person uses Chrome with no ad-blocker on and has never opened a terminal emulator. HN wildly sways to a tech-aware audience. I think most people would read the simple instructions provided by the author and immediately be overwhelmed and confused - "what's a bootloader, why do I need to care about unlocking it, is this going to break my phone?!"
Post reply on HN