14 ms·
GrapheneOS will remain usable by anyone without requiring personal information
- wearethecompute 7mo ago[dead]
- calvinmorrison 7mo agoso what is going to happen? Will California issue slave catcher warrants for those who violate laws? will Free Stater sheriffs dispatch citizens on long haul flights to meet their fate in the Golden State?
- test7rocks 7mo agoI hear, maybe someone can verify this, that US states not only can't enforce state laws on anyone outside state borders, but also can't even mess with post and delivery services so as to intercept (in the case of California, and far worse New York, age verification OS level tyranny) non-compliant respects-your-freedom devices as they cross the state-border.
- dpifke 7mo agoLet me introduce you to California's way of doing things: https://guncad.substack.com/p/special-issue-state-of-california https://guncad.substack.com/p/special-issue-state-of-califor... They're suing Florida residents with no ties to California for linking to pictures of guns on the internet. They will likely lose, but the goal is not to win, it's to score points with their political base and maybe bankrupt the defendants with legal fees.
- tzs 7mo ago> They will likely lose, but the goal is not to win, it's to score points with their political base and maybe bankrupt the defendants with legal fees. Or the goal might be to lose, but to establish some precedent that will hamper states like Texas that have tried similar things with abortion providers.
- deleted 7mo ago[deleted]
- deleted 7mo ago[deleted]
- beeburrt 7mo agoFuck yeah! I was wondering about this.
- test7rocks 7mo agoIsn't there already another HN thread about this? I'll rephrase here what I said there: Well done GrapheneOS. But It would be nicer if they said "If GrapheneOS devices can't be LEGALLY sold in a region due to their regulations, so be it" keeping the door open for GrapheneOS to ensure it would still try to supply the residents of authoritarian hellholes with a secure OS, the same way that Signal has been quite open about how if they pull out of a country for legal reasons then they'll do all they can to ensure service is still avalable to users in such places. Also: when they're partnering with manufacturers maybe they could get the manufacturers to guarantee that bootloaders on device sold everywhere (including in regions which ban freedom respecting software) will be unlocked, or if the manufactuer is banend from selling unlocked bootloader devices then make sure any bootloader locking is trivilally vulnerable to some means of easily achievable local bypass (shorting a pin or something which a user in posession of a device can do but which can't pose an atack surface for a remote adversary).
- logdahl 7mo agoOf course :^) I'm close to jumping ship to GrapheneOS, but as a Swedish resident I really need our digital id services, digital mailbox, and banking apps. I have seen their page on app support, but I am slightly afraid its not up to date / will break any time. I guess the solution is to use one banking android phone and one GrapheneOS for everyday use.
- buckle8017 7mo agoSounds like your issue is with your government.
- amarant 7mo agoIt's not an issue, we're just spoiled. It's such an amazing convenience that anything else seems like a huge and unnecessary hassle. There is actually more a second MFA provider that is accepted almost everywhere, including the tax authority. I forget it's name and I've never tried it, so I can't say too much, but presumably it provides similar functionality as BankID
- Tistron 7mo agoIt's called Freja. It's also possible to get a special hardware device to do the bankID dance, which is great to have if your phone breaks, as having that device will make it possible to provision a new bankID without visiting a bank office.
- girvo 7mo agoDo the banking apps have features that the (mobile?) websites do not? Genuine question, I have no frame of reference for Swedish banks
- buckle8017 7mo agoThe less free states are starting to require remote attestation to send payments at all.
- 7mo ago
- glass1122 7mo agoI hope you are allowed to operate in Canada Freely. If I am right, there is already something called Bill C-22, which is again a censorship and state level surveillance act under the guise of Child protection. Sooner or later Canada introduce this rule too.
- ipcress_file 7mo agoThe bill to watch on age verification is S-209 (the "S" because it originates in the Senate). Section 12(2) includes the requirements for potential verification methods. https://www.parl.ca/DocumentViewer/en/45-1/bill/S-209/first-reading https://www.parl.ca/DocumentViewer/en/45-1/bill/S-209/first-... Keep an eye on michaelgeist.ca. If there are petitions to sign to oppose it, you'll probably find out there.
- EmbarrassedHelp 7mo agoCarney also recently signaled that he was open to a "debate" on a child social media ban. Such a ban would likely be enforced by age verification. You should preemptively be messaging the Liberal cabinet ministers. And make sure to explicitly demand that anything that could force age verification or age assurance on Canadians is rejected: > Marc Miller (Heritage Minister, the minister responsible for the upcoming online harms legislation that might implement such a ban): Marc.Miller@parl.gc.ca > Sean Fraser (Justice Minister): sean.fraser@parl.gc.ca > Mark Carney (Prime Minister): mark.carney@parl.gc.ca > Mélanie Joly (Minister of Industry): melanie.joly@parl.gc.ca It may also be worth messaging: > Gary Anandasangaree (Minister of Public Safety): gary.anand@parl.gc.ca > Rechie Valdez (Minister of Women and Gender Equality): rechie.valdez@parl.gc.ca
- Sophira 7mo agoI have to wonder how this will impact their partnership with Motorola. Presumably, Motorola will have more difficulty if they're found not to be complying with relevant law... I hope GrapheneOS isn't completely banking on their partnership succeeding. If Motorola devices ever became the only devices that GrapheneOS works on, and it's being done with Motorola's blessing, then it could be more easily legislated out of existence.
- nickorlow 7mo agoI'd think they just can't sell the phones preloaded with graphene in regions where these laws exist.
- monkaiju 7mo agoId also want to load GOS myself, pre-loading it seems like it defeates some of the point
- preisschild 7mo agoGrapheneOS allows you to verify the integrity https://grapheneos.org/install/web#hardware-based-attestation https://grapheneos.org/install/web#hardware-based-attestatio...
- lifis 7mo agoI think that's worse than reinstalling because there could be a non-persistent exploit in the secure element allowing a malicious OS to fake attestation
- throwawayqqq11 7mo agoWhy dont they just offload the legal burden onto the users with a "Enter your * or decline" and move on? Taking this half compromizing position is easier to defend i think.
- 7mo ago
- blacksmith_tb 7mo agoI appreciate the principled stand, but on the other hand the CA law only requires users to self-identify when setting up accounts (and then the OS will expose age to apps), that seems fairly toothless (though wrongheaded) compared to TX and UT wanting to scan photo IDs[1] 1: https://www.tomshardware.com/software/operating-systems/california-introduces-age-verification-law https://www.tomshardware.com/software/operating-systems/cali...
- nullpoint420 7mo agoUntil CA matches the TX and UT laws. Boiling the frog
- lazide 7mo agoBut somehow in the opposite (yet same?) way.
- tzs 7mo agoIf that's what they wanted there is no reason not to start with laws like the TX and UT laws. You need the boiling the frog when you are trying to push the evelope.
- nullpoint420 7mo agoWdym? The reason is that people would oppose the TX and UT laws harder in California. Everyone is calm now in CA because "oh it's just an age dropdown guys!!" But once the infrastructure is built give it a few years it's not going to be a dropdown. And it will not be able to be bypassed in the same way you can't bypass permissions on iOS and Android today.
- BobbyJo 7mo agoWhy should we be ok with laws just because they won't accomplish anything?
- lazide 7mo ago
- gslepak 7mo agoIf you're considering switching to GrapheneOS from iOS, here's a guide: https://blog.okturtles.org/2024/06/the-ultimate-ios-to-grapheneos-migration-guide-and-review/ https://blog.okturtles.org/2024/06/the-ultimate-ios-to-graph...
- iLoveOncall 7mo agoReading the pros and cons list made it very clear to me that I'll never switch to GrapheneOS.
- wilkystyle 7mo agoNot sure why you are being downvoted, as this is a very valid conclusion for you to arrive at, individually. To those downvoting, please note that this person did not say that nobody should switch, only that the information provided was a clear indication that it is not the right fit for them. I, for one, greatly appreciated the detailed pro/con list in the post, as many of these would be genuine annoyances to me, and would have probably taken several months to encounter all of them.
- olyjohn 7mo agoMaybe it doesn't add anything to the conversation. How does it help anybody that this one person gave no reasons for why it won't work for them?
- wolvoleo 7mo agoThe author is being a bit pedantic though. Complaining about stuff that can't be fixed. For example yes aurora store sometimes doesn't work and definitely not over tor. But that's because its 'anonymous' option uses pooled Google accounts. Google tends to block them when they see thousands of users using the same account and blocking traffic to their servers over tor. Yet connecting directly to Google is the safest option here. And Google maps does not require a Google account. I always use my android phones without any Google account and maps works fine. I think OSMAnd is way way better anyway but they don't have the public transport integration so I still use Google maps for that once in a while. For everything else OSMAnd really rocks and its maps are better than what Google and apple offer especially when you're not a car user. But really expecting apple level polish from a free outfit it's just not fair.
- varispeed 7mo agoIf Motorola releases a phone with flagship specs that runs LineageOS, I am buying.
- joecool1029 7mo agoThey have a Graphene partnership, not a LineageOS one. The latter is entirely up to volunteers to port it.
- varispeed 7mo agoI am sorry, I meant Graphene!
- RRRA 7mo agoCanadians not being able to disable Amber alerts sent at presidential level all the time might also be interested to be able to sleep again...
- leca 7mo ago[flagged]
- EmbarrassedHelp 7mo agoDoes GrapheneOS fix that problem as well? Because at some point sending everything at the max alert level is going to get people killed. The max alert level should be reserved only for immediately threats to your life in the nearby area, because otherwise you train people to ignore the alerts.
- Telaneo 7mo ago> Wireless alerts are completely optional since GrapheneOS adds a toggle for the otherwise mandatory presidential alert type. This is particularly useful in Canada where the government abuses the system and sends every type of alert as a presidential alert to stop users from being able to opt out of weather and amber alerts. https://grapheneos.org/features#other-features https://grapheneos.org/features#other-features
- wolvoleo 7mo agoUmm Canada doesn't even have a president, lol. But pretty nasty to use that feature as an override yeah.
- _blk 7mo agoNot yet ;)
- bitwize 7mo ago"We've got some great people, phenomenal people, up there in Toronto, Ottawa, Vancouver... we're working with them on ideas for what it's gonna be like when I'm their President. Gonna be the best era ever in Canadian history. You're gonna see success like you wouldn't believe."
- crimsonnoodle58 7mo agoRelated and also on the front page: https://news.ycombinator.com/item?id=47479183 https://news.ycombinator.com/item?id=47479183
- joecool1029 7mo agoOne of the reasons I build my own LineageOS builds is because of terrible one-party consent recording laws (in places like California) there’s no geographic way in Android to check it on a state-by-state way. It just goes off country code and disables it for the US since quite a few states it’s illegal to do. For my state it isn’t illegal so I modified my builds to allow it. There are other things like this too in Android disabled on per-country. Japan has a camera shutter noise that cannot be disabled but this was a request by their carriers, apparently not a law, big discussion under this review: https://review.lineageos.org/c/LineageOS/android_frameworks_base/+/305659 https://review.lineageos.org/c/LineageOS/android_frameworks_...
- mschuster91 7mo ago> Japan has a camera shutter noise that cannot be disabled but this was a request by their carriers, apparently not a law In some countries, regulation works in a way that the economy gets a chance to fix issues before the legislative needs to intervene. And with the Japanese and their massive issues with rampant sexual abuse... I get where that one came from, in addition to the two major phone brands not wanting to be associated with sexual abuse (which the last comment of the thread also references). And personally, I do believe that this is the better way when forced with widespread ignorance of difficult to enforce laws - target the "accomplices" or "toolmakers".
- joecool1029 7mo agoI'm not making a judgement on it either way. These are things that are available to change in source. I'm just pointing it out, since others aren't aware of how things can be done. But there are things locked out in the US I cannot get to. One of the things I've wanted to do for some years is turn on BeiDou reception, but it has a firmware geofence while inside CONUS. For Qualcomm devices there's no way that I've been able to find a way around this, it's not an opensource component. Just to preempt anyone saying it's because it's Chinese spywhere, Qualcomm/Tomtom engineers don't feel receive-only reception is a security risk (there's a report somewhere where military said the same, it's strictly a political prohibition): https://www.uscc.gov/sites/default/files/Research/Staff%20Report_China%27s%20Alternative%20to%20GPS%20and%20Implications%20for%20the%20United%20States.pdf https://www.uscc.gov/sites/default/files/Research/Staff%20Re...
- diowldxiks 7mo agoI did the switch to graphene on my pixel 9 pro recently and have 0 regrets. it's just a better OS than the google infected android. Here's what I did: * Follow instructions to install graphene on their website: https://grapheneos.org/install/ https://grapheneos.org/install/ * Set up a private space which will be used for google play services required apps (bank stuff, etc). Install google play and google play services in the private space. Do not install google play services on your main profile. Set the private space to lock after 5 mins of inactivity. Set up google play on a brand new google account. You'll need to provide a phone number during setup. I used my normal phone number, others who are more concerned about deanonymization could use rental phone numbers or other things. Install any apps into the private space. * Try to install apps on your main profile, ideally open source, privacy respecting stuff. Some recent apps I've found that work great and replace google infested stuff - AntennaPod for podcasts, OrganicMaps for OSM maps, Obsidian for notetaking (google keep), KOReader for ebooks, Molly/Signal for messaging. Vanadium as the default browser works well, except it doesn't have adblock plus for youtube (it does some other ad blocking though and works fine). Things I still don't have a great solution for: * Android auto - I don't think it works from a private space due to auto locking. Still figuring this out * Spotify - since it also needs to run in the background and I haven't found a better music replacement. Overall graphene has been a far better experience and I like it much more, and feel more in control of my hardware.
- drnick1 7mo agoYou should be able to install Android Auto, Google Maps, etc. in a separate user profile with Google Play on and no autolock.
- diowldxiks 7mo agoI did try that as a first solution. I found switching profiles to be pretty unusable. Having it all in a private space so that it's accessible from main profile was much more ergonomic but does come with some privacy downsides for sure.
- jazzyjackson 7mo agoThing is Android Auto only interacts with google blessed devices, iirc device manufacturer has to pay license fee to support android auto. Android auto is not FOSS, I don’t think any automaker would allow their smartphone mirroring to work with rooted hardware that may not comply with safety regulations.
- ChrisArchitect 7mo ago[dupe] https://news.ycombinator.com/item?id=47479183 https://news.ycombinator.com/item?id=47479183
- pigpag 7mo ago[dead]
- niksmac 7mo agoRelated: https://news.ycombinator.com/item?id=47479183 https://news.ycombinator.com/item?id=47479183
- bivlked 7mo agothe commitment to not requiring google play services is what makes this different from most privacy ROMs. the real question is whether the app ecosystem holds - banking apps and 2FA are always the pain point that pushes people back to stock android.
- shevy-java 7mo agoGood. It is time to get rid of those corporate lobbyists that try to sniff for user data and then write up corporate laws. I would not understand in the slightest why my computer should provide any information about myself to the outside world - so why is the law suddenly changed? Who, aside from Meta, is pushing for this? Clearly the "but but but protect the kids!" is the red herring here. The whole law could have been worded differently than it was - that was not "accidental".
- nclin_ 7mo agoThis is for mass surveillance by the US government.
- matheusd 7mo agoUnfortunately, it doesn't look like this is sufficient. While I had great success with GrapheneOS in the past, bank apps in Brazil have started blocking it, even when the profile you run it under has Google services installed. So GrapheneOS (again, even with all Google Play Services and all other dependencies installed in a given profile) is still not completely transparent to apps. This may be a coincidence (as I don't use it every day), but I noticed blocking started just as the recent Felca Law (which introduced mandatory age verification for every software, app and OS in Brazil) came into effect.
- sounds 7mo agoBank is saying it doesn't want your money, correct?
- abc123abc123 7mo agoOn a google pixel? No thank you. Please come again when you run on jolla or some other ethical companiys hardware. I cannot buy a phone that will lead to google earning money.
- Thorrez 7mo agoSoon GrapheneOS will support Motorola phone(s). https://motorolanews.com/motorola-three-new-b2b-solutions-at-mwc-2026/ https://motorolanews.com/motorola-three-new-b2b-solutions-at...
- bigC5560 7mo agoYou can buy a used phone that will give no money to Google. I also hope for it to come to other smartphones, but not at the cost of compromised privacy and security. The reason that GrapheneOS only runs on Pixels is that they support the specific hardware requirements of GrapheneOS, including having an unlockable and relockable bootloader which is pretty cool of Google. I am sure that the GrapheneOS team would love to move on from being tied to a specific vendor's hardware and are working with Motorola to do just that.
- iAMkenough 7mo agoIf you bought used, the seller would earn the money instead of Google.
- hananova 7mo agoThat's a very arrogant and hubristic statement. It'll come back to bite them in the ass when a government with a long enough arm forces them to retract such an absolute statement. Even if they genuinely believe that they will never do it, in the future it will be seen as a lie regardless.