7 ms·
AMA: Gaël Duval, founder of the de-Googled Android OS /e/
- ForHackernews 6y agoI've been using /e/ on my primary phone for about a year now, and I've been very happy with it. I'd love to see it succeed as a user-friendly, FLOSS alternative to the Google/Apple duopoloy. They're developing in the open, too: https://gitlab.e.foundation/e https://gitlab.e.foundation/e
- wuschel 6y agoAre your banking apps working? I faintly remember that being an issue when switching to LineageOS.
- tadfisher 6y agoSpeaking as someone who has been writing Android banking software for eight-odd years, requiring SafetyNet attestation is a crock of user-hostile shit so long as the same institution allows random desktop Web browsers access to the same APIs. I have a feeling it was invented for anti-cheat in games but it became a line-item in every security director's checklist because Google offers it.
- ForHackernews 6y agoI don't use any banking apps, sorry. AFAIK /e/ supports signature spoofing/pretending to have normal Google Play Services available, so some stuff might work.
- bklaasen 6y agoWorks with "BOI Mobile", the Bank of Ireland mobile app, which I downloaded from the Aurora store. I get a notification on starting the app indicating that the phone is "rooted" (it isn't) but I'm not prevented from using the app.
- mdoms 6y ago/e/ is easily, EASILY the worst name for a product I have ever seen. I don't know how to pronounce it, I can't Google it, I can't make a guess what it's domain might be. Just awful in every possible way.
- burundi_coffee 6y agoI think I read somehwere that they chose this name as their "beta" version since it's not easily googleable. As soon as they gain more traction, they will rebrand.
- rapnie 6y agoThey started with eelo, but then had to change: > Eelo was subsequently renamed to /e/ in July 2018 due to a conflict with the "eelloo" trademark, which was owned by human resources company Meurs HRM B.V. https://en.wikipedia.org/wiki//e/_(operating_system) https://en.wikipedia.org/wiki//e/_(operating_system) PS. I agree on it being the worst name possible.
- raverbashing 6y agoAlso it might cause confusion with https://www.enlightenment.org/ https://www.enlightenment.org/
- flyingfences 6y agoAlso it might cause confusion with https://boards.4chan.org/e/ https://boards.4chan.org/e/ (NSFW)
- SirLotsaLocks 6y agoOr elementeryOS which is commonly referred to as eOS
- karmakaze 6y agoThat's only until it becomes ubiquitous: C programming language.
- marcodiego 6y agoI have a de-googled old e-os phone as my daily driver. Very nice choice. My hope is that my next one will be a full linux phone like librem 5 ir pinephone. I'm just waiting for it to get more mature. If I had a bit more money, I'd buy one now just to support the cause.
- jhardy54 6y agoI'm considering switching from Android to iOS because I don't want to throw away my phone once my 2-4 years of security updates are over. How do firmware updates factor into your thinking around Android and security? Is there a way off of the "buy a new phone if you want firmware updates" treadmill? (I don't expect you to have a solution, but I'm curious to hear how you're thinking about this problem.) See-also: https://ollieparanoid.github.io/post/security-warning/ https://ollieparanoid.github.io/post/security-warning/ --- Example: https://blog.exodusintel.com/2017/07/26/broadpwn/ https://blog.exodusintel.com/2017/07/26/broadpwn/ If your phone is new, you'll get firmware updates to resolve this. If your phone is old, you need to buy a new phone or live with a vulnerable device.
- em-bee 6y agoat least fairphone is still providing updates for their 5 year old fairphone 2: https://news.ycombinator.com/item?id=26593274 https://news.ycombinator.com/item?id=26593274
- richardfey 6y agoSome time ago I had to decide about which ROM to put on an old phone of mine, I went with llLineageOS. Thus blog post was spooky: https://infosec-handbook.eu/blog/e-foundation-first-look/ https://infosec-handbook.eu/blog/e-foundation-first-look/ I also tried VanadiumOS but it wasn't for me
- flas9sd 6y agowhile that was a fair assessment (maybe not the ntp pool), it was followed up on at that time - https://gitlab.e.foundation/e/backlog/-/issues?scope=all&utf8=%E2%9C%93&state=closed&search=Infosec+Handbook+Review+Issues https://gitlab.e.foundation/e/backlog/-/issues?scope=all&utf...
- throwaway0x1 6y agoWhen compared to GrapheneOS, Duval claims: "If you want something with hardened security, use Graphene, if you want something that help you keep your data safe from Google, use /e/. It depends on your needs." GrapheneOS is already de-Googled, so, it's the better option?
- em-bee 6y agois it de-googled? there is nothing about it in the features list, and the FAQ mentions the option of switching between using gooogle and graphene servers for things like the connectivity check, suggesting that people want to keep using google in order to "blend in". it is neither clear that these switches cover ALL ways that android has to send data to google, nor that there is any desire to remove all of them. the old FAQ apparently had this text (found that in a forum discussion): GrapheneOS leaves these set to the standard four URLs to blend into the crowd of billions of other Android devices with and without Google Mobile Services performing the same empty GET requests. For privacy reasons, it isn't desirable to stand out from the crowd and changing these URLs or even disabling the feature will likely reduce your privacy by giving your device a more unique fingerprint. GrapheneOS aims to appear like any other common mobile device on the network. that text has been replaced with: You can change the connectivity check URLs via the Settings Network & internet Advanced Internet connectivity check setting. At the moment, it can be toggled between the GrapheneOS server and the standard Google servers used by billions of other Android devices. This can be used to blend in with other Android devices, both with and without Play services. Changing this to the Standard (Google) mode will use the same URLs used by AOSP and the stock OS along with the vast majority of other devices there is more here: https://forum.xda-developers.com/t/general-about-grapheneos.4021161/post-83424999 https://forum.xda-developers.com/t/general-about-grapheneos.... a forum member claims that: Connections of android location services to get GPS constellations were shown before to send sim card imsi and connected cellular tower id to provider (qualcom/google) Graphene still allows those connections Android services make other weird connections. Example: AOSP dialler app is querying phone numbers against online database leaking all contacts to google. How was this taken care of in graphene? Are all AOSP services/apps security-verified to not leak any data? this suggests that while graphene developers do consider concerns about sending data to google, their goals are orthogonal to those of /e/OS, as Duval claims.
- craftoman 6y agoThis is great news. People & small companies are entering a market focused on privacy. Graphene OS is also a great project, I hope more people will follow.