7 ms·
GrapheneOS always strikes me as "perfect is the enemy of good". I don't necessarily need top-notch security features, I've been all right with all kinds of Andr
by yason 7mo ago
GrapheneOS always strikes me as "perfect is the enemy of good". I don't necessarily need top-notch security features, I've been all right with all kinds of Android phones. The things I'd like are:
- ability to sandbox Google Play and Google Apps so that they live in their nice little Google bubble and have no control over my phone overall
- ability to run all applications sandboxed with fake permissions that I can whitelist for each application and without letting the app know it doesn't have the permissions it wants. Want location? Give the app a location point I've fixed for that app. (Or pass through real GPS location if I've chosen so.) Want contacts? Give the app empty contacts list. Or if I've allowed, give the app the contacts I've whitelisted.
The Android/Google ecosystem is all right in itself, I just want to limit all of it inside a cage that I control. I want the exact same for my browser: I want webpages to run in a highly controlled sandbox with my choice of spoofed environment and permissions instead of assuming any power over my system. Or my Linux desktop where I firejail or sandbox certain proprietary apps outside of my distro's repositories.
- hypfer 7mo agoSounds like you might not be the target audience of GrapheneOS then? That's fine. You don't have to be
- carpenecopinum 7mo agoI mean, GrapheneOS hits at least 2/3 of your demands pretty well. The Play services are "regular" apps with permissions that you can take away. For contacts and files you get "scopes", i.e. you decide what the app can see, while the app is left to believe that it can see everything there is. That said, I think the marketing of GrapheneOS could be better. Every introduction of GrapheneOS I've seen paints the image of Graphene being "Absolute security, no compromises", whereas in reality GrapheneOS is the most "Things need to work, no compromises. Then make the rest as safe as possible" custom ROM that I've used thus far (in particular regarding them allowing you to install Google Play, rather than using MicroG).
- yason 7mo agoI would certainly be using GrapheneOS if only I could get one to run on something else than a Pixel. I have a perfectly good phone whose bootloader can be unlocked and I can install LineageOS or other AOSP installations there but all I'm aware of and I've researched come short on the sandboxing and permissions. I'd be willing to use GrapheneOS without support for specific security hardware (if only they supported that configuration) just for the features mentioned but Pixel phones are just too expensive. I've always been more than happy with a decent low-tier phone and I don't see a technical reason to change that. Nothing wrong with my phone.
- jasonvorhe 7mo agoPixel A's are quite affordable. GrapheneOS is open source so if there was a need, people could get it to run on insecure devices that aren't Pixels. Expecting that to be done by GrapheneOS developers who care about security just seems weird.
- ethbr1 7mo ago> Pixel A's are quite affordable There's first-world, upper-middle-class affordable (~$500) and then there's global affordable (<$250).
- Gander5739 7mo agoI got a Pixel 7 secondhand (but good condition) for the equivalent of about $270. It would have been less but I needed 256 gb of storage.
- subscribed 7mo agoI usually buy refurbs similarly like I buy 2 year old cars. Currently I can get brand new Pixel 8a on ebay for £250 or similar, and refurbs from "flawless" to mint" conditions for half of it. Still good enough.
- palata 7mo ago
- deleted 7mo ago[deleted]
- tarruda 7mo agoOne thing that annoys me is the ability that my mobile carrier has to just throw ad popups. Is that something that GrapheneOS fixes?
- pluc 7mo agoYour carrier does what now?
- tarruda 7mo agoI have a pixel 8a with a TIM SIM card and every once in a while I see an ad popup on my phone.
- deno 7mo agoGo to [Settings] » [Apps] » [Special app access] » [Display over other apps] and check if any preinstalled carrier apps or anything suspicious has this permission granted.
- tarruda 7mo agoJust checked, and only "Phone" and "Google" have this permission. There are no preinstalled apps, I bought this phone clean on Germany and then added a Brazil's SIM card when I got back. Could it be that the SIM card has some control over the Phone app?
- deleted 7mo ago[deleted]
- deno 7mo agoApparently this is handled by the privileged STK[1] service. It can launch browser which is I think what's happening. GrapheneOS presently doesn’t do anything different in this case, they pull it from AOSP without modifications. However you can disable it using the frontend app (SIM Toolkit) as someone pointed out, but as far as I can tell this requires the applet on SIM card to cooperate (offer the opt out). Otherwise you can disable the STK altogether with ADB but that will also block you out of other SIM card interactive functions, which might not be a big deal however. Edit: "We plan to add the ability to restrict the capabilities of SIM Toolkit as an attack surface reduction measure. (2022)"[2] and open issue[3]. [1] https://wladimir-tm4pda.github.io/porting/stk.html https://wladimir-tm4pda.github.io/porting/stk.html [2] https://discuss.grapheneos.org/d/1492-blocking-sim-toolkit-messages-and-popover-advertisements https://discuss.grapheneos.org/d/1492-blocking-sim-toolkit-m... [3] https://github.com/GrapheneOS/os-issue-tracker/issues/875 https://github.com/GrapheneOS/os-issue-tracker/issues/875
- niam 7mo agoThat relates more to the public rhetoric surrounding Graphene than with how the OS itself operates imo. It's pretty practical and enables (or allows you to enable) everything that a typical Android does, except where Google Play Integrity checks fail, which is not in Graphene's control (e.g Google Wallet payments). People bill it as making a ton of usability compromises in the name of security, but that doesn't match my experience. The only redeeming observation is that your phone _does_ lean towards secure-er and ungoogled defaults, which _does_ break functionality that a lot of people expect to "just work" OOTB. But it's trivial to restore it, and the upfront effort getting things to work is amortized over the lifetime of the device. It's maybe an hour's worth of work. The counterfactual world where users need to forumcrawl how to get to secure/private defaults seems worse to me. By contrast, it's pretty easy to recognize when an app isn't working.
- II2II 7mo agoI agree with your post, but I wanted to point out one thing: > People bill it as making a ton of usability compromises in the name of security, but that doesn't match my experience. When you are talking about something like GrapheneOS, most of the people who are talking about usability compromises aren't worth listening to since they are looking for something that is pretty much the exact opposite of what GrapheneOS is trying to provide. While there are likely some legitimate criticisms in the mix, the compromises required for "works by default, for everyone" are pretty much the opposite of what GrapheneOS is.
- strcat 7mo agoIt's worth noting tap-to-pay is available via Curve Pay and other options in Europe. We intend to get the Google Pay issue resolved.
- unicornporn 7mo ago> Want location? Give the app a location point I've fixed for that app. How do I do that? Been using Graphene for many years but did not know this was possible.
- whatsupdog 7mo agoI want to know too.
- strcat 7mo agoThere's a standard Mock Location feature in Android usable for it. We're making a better per-app Location Scopes feature as a replacement. Mock Location is global which has bad usability.
- Dusseldorf 7mo agoYou can't; OP was making a list of GrapheneOS wants without realizing they were mostly just describing how GOS works. That bit was the only miss.
- strcat 7mo agoThere's a standard Mock Location feature in Android usable for it. We're making a better per-app Location Scopes feature as a replacement. Mock Location is global which has bad usability.
- unicornporn 7mo agoThanks. So, a misunderstanding from the OP and not a feature specific to Graphene? > We're making a better per-app Location Scopes feature Cool!
- strcat 7mo agoThere's a standard Mock Location feature in Android usable for it. We're making a better per-app Location Scopes feature as a replacement. Mock Location is global which has bad usability.
- II2II 7mo ago> GrapheneOS always strikes me as "perfect is the enemy of good". GrapheneOS, as it ships, is rather bleak but you also need to consider that it is addressing the concerns of a very broad audience. That ranges from people who want to completely get rid of data leaking apps to those who want the apps but expect them to be sandboxed. Shipping two different versions won't really help them. It would only make more work on their end, with the results only reflecting two extremes. You are going to have some people willing to put up with some apps, but not others. You are going to have some people wanting some of those apps feeding fake data, but not others. It's probably best to think of GrapheneOS as a base system that you build up to serve your personal needs, rather than thinking of them shipping it in a "perfect" state. While a handful of people will be happy with it in its default state, many will install something like F-Droid along with a collection of privacy preserving apps. Many others will install the Google Play Store along with a personally curated list of apps that reflect their needs, providing or denying access to their data as they see fit. I believe the "build up" approach is the only viable way to handle this situation since we are talking about a group of users who are actively seeking out a third-party OS since they are particular about their needs. This isn't the typical consumer who will (gleefully or begrudgingly) put up with whatever the device vendor feeds them.
- strcat 7mo agoOur approach is why we have a partnership with Motorola where we're working with Motorola and Qualcomm on improving security of the devices to meet our requirements. It takes longer to get things done the way we want but that's part of the purpose of GrapheneOS. For example, it took us longer to have our own network-based location and geocoding but now we have great implementations of both. Our network-based location currently closely matches iOS but is going to have full offline support developed for it. We're working on our own local model text-to-speech at the moment too, although our focus is currently Android 16 QPR3 related work as a higher priority which delayed it. We do plan to overhaul or replace all the legacy AOSP apps, but our priority has been working on things people can't simply replace by installing more apps.
- whatsupdog 7mo ago> Want location? Give the app a location point I've fixed for that app. How do you do that in graphene os?
- dns_snek 7mo agoThat's doesn't seem to be a thing [yet]. All I managed to find was this comment from the developer which talks about it (CTRL+F, "location"): https://news.ycombinator.com/item?id=42536302 https://news.ycombinator.com/item?id=42536302
- strcat 7mo agoThere's a standard Mock Location feature in Android usable for it. We're making a better per-app Location Scopes feature as a replacement. Mock Location is global which has bad usability.
- dns_snek 7mo agoThat's true. Do those caveats from that older comment still apply? Will apps be able to tell that location is being spoofed when using location scopes?
- whatsupdog 7mo agoHopefully not.. Otherwise it defeats the whole purpose. Right now there is no way for apps to find out media and contact scopes, so it might be something similar.
- strcat 7mo agoThere's a standard Mock Location feature in Android usable for it. We're making a better per-app Location Scopes feature as a replacement. Mock Location is global which has bad usability.
- birdsongs 7mo agoIn what ways has the pursuit of perfection harmed the good in their development? (Your words, I don't agree.) Graphene does everything you're asking, except for the niche fixed location feature you specifically want, which you're welcome to request, or just implement yourself and make a PR. I'm going to be a bit snarky here, but I always find the entitlement around features in open source software baffling. This isn't a multi billion dollar corporation selling you something. It's enthusiasts making you something (honestly, incredible), for free, in their spare time, outside of their daily jobs. They're doing their absolute best here.
- deleted 7mo ago[deleted]
- aaron_m04 7mo agoYes, but do these enthusiasts care at all if it meets some need for the users? I suspect that they do. And how can they find out how well it meets that need other than receiving (respectful!) feedback?
- the_real_cher 7mo agoI want them to implement a feature where the phone prints money.
- birdsongs 7mo agoI don't follow. The poster above my comment complained that graphene os was lacking a list of features is already has, so I corrected that. > Yes, but do these enthusiasts care at all if it meets some need for the users? ... And how can they find out how well it meets that need other than receiving (respectful!) feedback? What makes you think they don't? Can you point to any instances of them ignoring the community at large? You can open an issue in any of the open source repositories and request a feature. Others can vote and comment on it. Or you can discuss it in the very lively forum. All methods used to steer the project towards the desires of the users. In case you can't find them: https://github.com/GrapheneOS https://github.com/GrapheneOS https://discuss.grapheneos.org/ https://discuss.grapheneos.org/ This whole conversation just feels weird and specious to me.
- fsflover 7mo ago> GrapheneOS always strikes me as "perfect is the enemy of good"... I've been all right with all kinds of Android phones I fully agree with you. I never received a reasonable reply to this from GrapheneOS fans or developers. Latest attempt: https://news.ycombinator.com/item?id=47182376 https://news.ycombinator.com/item?id=47182376
- gruez 7mo ago>Latest attempt: https://news.ycombinator.com/item?id=47182376 https://news.ycombinator.com/item?id=47182376 Your Qubes OS comparison doesn't really work because Android distributions need extra work to support each new device, whereas for Qubes OS, they're probably using some virtualization framework that makes it pretty trivial to add support for CPUs without virtualization. There's nothing stopping you from starting a new fork that supports your motorola phone, for instance.
- fsflover 7mo agoI understand that supporting new phones is a lot of extra work. My only question is whether the developers of GrapheneOS would accept patches from community for such support without full set of security features.
- throawayonthe 7mo ago"accepting patches" is still a lot of work and often means taking on the maintenance burden; i suspect that if qubes had to do extra hardware enablement work/maintenance for VT-d-less devices they might've had the same position
- handedness 7mo agoQubes hasn't always shipped Xen patches nearly as quickly as I would like. It's the unfortunate reality of the situation they're in, simultaneously trying to catch up with broad-spectrum device support, with a miles-long HCL with many entries having sub-threads attempting to resolve significant compatibility issues. Don't buy hardware that's too new, don't buy hardware that's too old, certified hardware doesn't necessarily stay certified, and so on. It's a mess. I love what they're doing and it's my preferred daily driver, but from a security standpoint they're still pushing molasses up a sandy hill.
- doug-moen 7mo agoThe ability to fake the location on a per-app basis is called "location scopes". It is being worked on, as mentioned here: https://discuss.grapheneos.org/d/27926-per-profile-location-spoofing-is-it-possible-at-all https://discuss.grapheneos.org/d/27926-per-profile-location-... Currently there is a Mock Location feature, but it is globally scoped and not what you asked for.
- ferguess_k 7mo agoI'd also like to remove as many apps as I want. If something breaks I'd eat it and re-install the whole system.
- strcat 7mo agoYou can disable many system apps via the Settings UI. For ones where the naive heuristics or manual exceptions believe it may break something and have it disabled, you can use ADB. You can also uninstall apps from a profile including Owner with ADB instead of disabling them which is NOT a good idea but you can do it...
- throawayonthe 7mo agoi don't understand, doesn't that make graphene the opposite of what that saying refers to? it's a real life project that has almost all of the features you mention while not being lagged down by pursuit of perfectionism?
- strcat 7mo agoGrapheneOS has an OEM partnership with Motorola where they're working on improving their devices to meet our requirements because we won't lower our standards for updates and security features. A lot of work needs to be done for each supported device. There's a massive amount of work bringing the security-oriented, production-quality hardware memory tagging integration from Tensor to Snapdragon. We're working with Motorola and Qualcomm on it. If we simply ported it to many insecure devices we'd need have the time to work on features like this or the power to get an OEM and SoC vendor to work with us on it. GrapheneOS has Contact Scopes and Storage Scopes for pretending all of the contacts, media and storage permissions are granted with the app unable to access any additional user data without the user explicitly adding it on a case-by-case basis. Unlike the recent iOS feature, apps can't see the Contacts permission group isn't granted and it supports giving less data than the whole contact too. It also supports labels for groups of contacts shared between apps. Mock Location is a standard Android feature. We're working on a per-app Location Scopes replacement. We're also working on Camera Scopes and Microphone Scopes. We plan to continue down that road covering less major permissions too. Sandboxed Google Play already works near perfectly with close to 100% app compatibility. It's only apps disallowing using a non-stock OS via the Play Integrity API or to a lesser extent certain other methods which aren't compatible. McDonalds is a major example. X forbids password login but you can use Vanadium to login with a passkey and then use that in the app. ~10% of banking apps do it but not most. We've convinced multiple banks to permit GrapheneOS, and that's going to become MUCH easier now.
- jonpurdy 7mo agoThis is very useful context. Especially around Contact Scopes etc. It's never made sense to me that iOS shares if the user is choosing to not share their contacts. Apple seems to basically do privacy-related things to an 80% level but not bothering with getting it totally correct. This makes business sense because the extra 20% is way more difficult, but it's great to see GrapheneOS going all the way.
- ibejoeb 7mo ago> We've convinced multiple banks to permit GrapheneOS, and that's going to become MUCH easier now. I did not know that. That is very interesting. On that topic, an honest question: what is the killer feature of banking apps that everyone is so hot on? Are we talking like retail banking or money transmitters? I am not using any bespoke banking apps, and I don't feel like I'm missing out, but maybe I just don't know what I'm missing. What does detract from my GrapheneOS experience is the keyboard. It's just ok. I need swipe typing though, and I haven't found anything even close to gboard glide.
- subscribed 7mo agoThis is your lucky day! First is very comprehensively delivered, second is halfway done, halfway in progress. Good luck!
- deleted 7mo ago[deleted]
- aaravchen 7mo agoI have to say up front, that I think GrapheneOS in its most locked down mode needs to exist. There are important audiences for which most nation state actors and their related corporate entities are real threats (e.g. journalists). That said, I don't think the majority of users want or need that level of lockdown. I do agree with the OP somewhat. While GrapheneOS has a hard job with too much to do and too few resources, they also take a very all-or-nothing stance when it comes to real world practicalities for the average user. Specifically: they're all or nothing on app stores and Google. For some reason some of the key developers seem to constantly bash every "store" except Accrescent, ignoring the fact that Accresent is missing the key feature of telling you what you're even installing (which fails security 101: "you're only secure if you're usable and secure"). It's a very all or nothing viewpoint. No there is no secure app "store". None. Every one of them has security issues in one way or another. But short of an ultra locked down burner device for national secrets (a real use case in fact), users need to be able to get apps. The only "acceptable" solution seems to be to use the (patched) official Google Play Store. Which brings me to the second all-or-nothing area. Google is the single biggest threat actor for most users. They control the upstream AOSP, so you start with constant attempts to compromise your supply chain in nefarious ways. They're one of the key gateways to the Internet, and they run the world's largest surveillance network (by a factor of many thousands). They're the very reason most users come to GrapheneOS in the first place. Every one of Googles apps is, or can safely be assumed to be, malware to violate your privacy as much as it can, and may incidentally provide some functionality. GrapheneOS has done well to replace many of the OS-baked in functionality that normally uses Google with alternatives, but is very adamant that they will not try to support allowing non-Google-signed apps in place of Google signed ones for any purpose. While I understand it ensures the AOSP feature of verifying against a trusted source, Google itself is not inf act a trusted source. It won't try and mine crypto on your device or use the passwords and wallet keys it steals to drain your accounts or steal your identity, but it will almost always cooperate with authoritarian nation states to install targeted surveillance tools on your devices instead of the "real" apps, and track all data it can possibly get access to. Sandboxing the system apps helps a lot, but as we know from Stock Android devices, that's not sufficient to completely protect systems from known malicious apps. The counterpoint is always "then don't install any Google apps". Great, I'd love to. But I live in the real world where Google controls most of the electronic world, and everyone else has mandates Google usage. I need to control my level of exposure for my personal usage requirements and threat model, and neither 0 or 100 are feasible options. Just like almost all users. I definitely understand from a practical sense that GrapheneOS doesn't have the resources to supply de-Googled version of Google Maps (unfortunately the only map navigation that works in most of the US still), or implement and maintain a rework of the binder and intents system to allow custom per-app filtering of all IPC. But I don't hear about the practicalities and maintenance costs (especially for complex drive-by contributions), or risks of accidental misuse causing severely degraded security. I only hear "that's not secure" (which is often incorrect for the actual user's threat model) as the reason something won't be supported, pursued, or allowed to be contributed.