4 ms·
I'm currently on with this. Got my own domain, starting to change over accounts to new email. My webservers are at home, my NAS is being built. I'm getting Gr
by mPReDiToR 4y ago
I'm currently on with this.
Got my own domain, starting to change over accounts to new email. My webservers are at home, my NAS is being built.
I'm getting GrapheneOS because I love my PinePhones but can't quite use one exclusively yet.
- daneel_w 4y agoBut GrapheneOS only runs on the Google Pixel phones, doesn't it?
- mPReDiToR 4y agoOfficially, yes. There are unofficial versions. As it happens, I'm being gifted a Pixel 4, so full steam ahead. Check their site/wiki for info, if this interests you.
- daneel_w 4y agoI do like the idea of GrapheneOS, I just don't feel 100% comfortable running hardware made by Google.
- _N0x 4y agoI'm quite sure the hardware is fine. From what I recall google phones actually have some of the best security hardware. It's one of the reasons GrapheneOS chose Nexus/Pixel phones as official base as well as the long support for those devices. What is the alternative? Running some chinese hardware and chips? I guess iPhones would work but you have no real softwarecontrol over those. And what do you worry about regarding the hardware if I may ask? That there is some way the hardware bypases the software running on the device and send out information?
- daneel_w 4y ago> "And what do you worry about regarding the hardware if I may ask? That there is some way the hardware bypases the software running on the device and send out information?" Yes, the firmware.
- _N0x 4y agoSorry if that came of wrong. It was a genuine question. I don't quite know what is the alternative to putting some trust into either google devices and an OS like graphene or not owning a phone in the first place. Since I imagine if googles firmware bypasses things that every other chip manufacturer does the same. Wouldn't that be discovered quite quickly by security folks? As in noticing stuff being send on the network that is not expected?
- daneel_w 4y agoIt has been discovered before. As an example, a few years back someone found out that some Android phones' cellular modems were passively collecting base tower information when the phone was turned off, and then uploading it to Google when the phone came back online. The software portion responsible for doing it was Google's. I don't have any links to the articles covering this, but it ended up being quite a big deal, especially in relation to privacy/integrity laws in the EU.
- omegacharlie 4y agoPerhaps not perfect but in consideration of some of the barriers other OEMs may posses with a security device I think the situation reads as 'being better than the alternatives'. Pixels are also an reference device by Google for Google so that is another incentive for them to suck less.
- daneel_w 4y agoI agree that the hardware seems technically impeccable. My worry is in trusting the firmware Google put in it.