3 ms·
GrapheneOS and CalyxOS might have slightly less tracking, but are similarly anti-User as they do not grant any higher-level access to the user (root for example
by summm 5y ago
GrapheneOS and CalyxOS might have slightly less tracking, but are similarly anti-User as they do not grant any higher-level access to the user (root for example), and similarly enforce app authors' arbitrary restrictions against the user. All under the guise of "security".
- ranger_danger 5y agoGiving the user root access to the phone is one of the worst ideas you could possibly do with regards to security, which is why it's not possible. It's anti-user because the user is a huge source of information leakage and that's what the project is trying to protect, your information. GrapheneOS also requires a lockable bootloader, because that is another attack vector. Malicious software could alter or downgrade the bootloader and load different software that could then spy on your device or read its contents. Yet user-friendly Android options routinely tout features like "root access" and "unlocked bootloader" (LineageOS even requires it stay unlocked!)... but in reality these are enormous security holes that should not be there in the first place. Just like how on the desktop... booting from recovery software or into a "single user mode" practically washes away all security and lets you access all the data. Besides encryption, things like Secure Boot and Mandatory Access Control should be used a lot more often to protect our data, but today unfortunately it is mostly relegated to mobile devices.
- summm 5y agoSingle-user mode is clearly not what is happening with root. It's not like any app just can elevate to root, there's always a request requiring authorization, just like account elevation on windows and sudo on Linux. This is not idiot-proof, but if you view your users as idiots, that's telling... About the bootloader: root does not require secure boot off, if (!) root is built into the rom in the first place. In this case it still protects against many attacks. FS encryption protects against many of the remaining attacks. Lineageos does not offer root anyway, so that cannot be the reason it doesn't have secure boot. Its probably just that they do not have that focus on pixel, and other bootloaders don't support relocking security for custom roms.
- cute_boi 5y agoAs long as device is encrypted properly I don't think security is washed away.
- 0xdeadb00f 5y agoThe "guise of security"? You clearly don't understand the implications of the root account, and why it's a bad idea to give any app on your phone the potential to have that kind of power
- summm 5y agoSecurity cannot exist in vacuum, it always refers to a threat. That security you speak of is the security of apps against "attacks" by the user. This fight should take place on the app's backend, not the user's phone. The phone should be a user's agent, not an idiot-proof tool of oppression.