3 ms·
GrapheneOS or other custom ROMs don't solve the actual problem that you can't just buy a smartphone and install any operating system like you can with an actual
by Elfener 2mo ago
GrapheneOS or other custom ROMs don't solve the actual problem that you can't just buy a smartphone and install any operating system like you can with an actual computer, despite technically being one.
Also, GrapheneOS supports device attestation (the non-google kind at least), which is still ridiculous as such systems have no benefit to people, only to technofeudalist corporations.
- gruez 2mo ago>which is still ridiculous as such systems have no benefit to people, only to technofeudalist corporations. GrapheneOS literally has an app that uses attestation and isn't for "technofeudalist corporations". https://attestation.app/about https://attestation.app/about
- hparadiz 2mo agoDevice attestation is how you can use private keys you don't actually have access to. It has a lot of value to literally anyone who wants to store tokens or use one time authentication codes. Linux folks need to implement the full stack and offer an open alternative to payments, secrets, and tokens. In the age of LLMs there is no excuse. It is annoying as hell that I can't buy a System76 or Framework laptop with a fingerprint sensor but a Lenovo comes with one that works on Linux perfectly.
- sophrosyne42 2mo agoFramework has a fingerprint sensor. [1] [1] https://frame.work/products/fingerprint-reader-kit?v=FRANTD0001 https://frame.work/products/fingerprint-reader-kit?v=FRANTD0...
- hparadiz 2mo agoIt needs to come stock on every Linux laptop from now going forward period. Like you expect a screen to come with your machine. Every Mac has one now and I'm not going back to typing my password in every single time.
- jeroenhd 2mo agoLots of laptop vendors do. Very few integrate fingerprint scanners into any kind of secure authentication flow, though. There are decent fingerprint drivers for various brands, but connecting fingerprints to authentication beyond basic login requires manual setup. You don't actually need biometrics to use key material, that's what (f)TPMs are for. They're not set up to be usable out of the box in any Linux distro I've tried, though.
- sophrosyne42 2mo agoThat's more of a problem on the distro side, no?
- dingaling 2mo ago"Device attestation is how you can use private keys you don't actually have access to." Read that phrase back and then ask "is this the future of computing that we wanted?" The likes of passkeys, essentially user-hostile ssh keys that live on your device but aren't accessible by you, would have been an unbelievable dystopia to us in the 90s. "Linux folks need to implement the full stack" Nah it's fine thanks, I'd rather opt out of corporate serfdom than compromise my principles.
- hparadiz 2mo agoThat's just your opinion. Has nothing to do with Linux. And yes I would like a device like a soldered in tpm device that can generate private keys and verify signatures signed with the public key. Your misunderstanding of the technology not withstanding it does appear to me to be quite a valuable technology since it's in basically every computer these days. Stop speaking for Linux.
- rstuart4133 2mo ago> Read that phrase back and then ask "is this the future of computing that we wanted?" It is what I want. If you own a mobile phone it's unavoidable. The physical SIM is a guarded area with secrets you can't know or touch - the secrets it holds prove you paid for access to their network. If you want to carry a zillion others devices you can't access the innards of that prove something about you then good for you. But don't assume the rest of us think that's a good idea. We no more object to carving out a little bit of firewalled memory for the exclusive use of the bank than we object to the electricity meter in our houses. It's also a locked down piece of equipment we can't modify or touch that lives on our property. Most people are happy to grant that intrusion on their personal space in exchange for having the electrity connected. It's no different on your phone. In return for your phone protecting its details from you, you no longer have to carry a credit card, or driver's licence, or prove you paid for ads to go away in some app, or access your works VPN. I honestly can't see much difference between carrying a credit card the hides some information from me, or putting the same info in the phone and it hiding the info. Except for having one less device to haul around, of course.
- subscribed 2mo agoIf this is your stance it's trivial to have your cake and eat it. You can easily build your own GrapheneOS based image, which will then be unable to use attestation (because your own keys you'll use for the secure boot won't match). And I'm not trying to be snarky, if that's the only thing, it's solvable right now. Everything else will work. And concerning "you can't just buy a device and install is" - android and iOS are far more secure than any desktop os, and both pixel/iPhones are far more secure than any computer (or any other phone as well (we'll get the third one next year)). GrapheneOS actually explains "whys" in their hardware support faw section. Generally maintaining an os is a hard work, so that perhaps explains why there's not many mature offerings.
- spogbiper 2mo ago> install any operating system like you can with an actual computer This is in practice only true of IBM PC compatibles these days, you really can't install any OS on modern Macs. Maybe you can on (some?) Chomebooks?
- smw 2mo agoYou can install Linux on modern macs? That doesn't mean that driver info is available, but there's nothing stopping you from installing another os.
- AlienRobot 2mo agoA piece of wisdom I read here is that "install any operating system like you can with a [PC]" is something that you can only do with a PC. PC's are the exception. Every other device is controlled by the manufacturer.
- Gander5739 2mo ago> you can't just buy a smartphone and install any operating system like you can with an actual computer, despite technically being one. What's stopping you from buying a phone, unlocking the bootloader, and flashing whatever ROM you want?
- nsonha 2mo agothe "whatever ROM"s are all Android, what difference does it make? Many bank apps have this SafetyNet thing and will refuse to run on non-official ROMs, that too.
- Gander5739 2mo agoWell, there's various linux options like postmarketOS. So long as you have the fundamental freedom, that is, an unlocked bootloader, everything else follows. If you decide to write a new OS for a phone, notning is stopping you.
- nsonha 2mo agoThe linux distros support very few devices officially. Even including community maintained ports, it's always old devices that you would not buy if you wanna maximize specs to run as a server. That is one of the reasons you want linux in the first place. I have several old Android phones, the newest one is s10e from 2019, decent specs but only supports an abandoned version of UBports, not the current one, and no port for postmarketOS.
- Gander5739 2mo agoWhy would you buy a phone to run as a server anyway? If you really want linux you can root the phone and chroot.
- nsonha 2mo agoI don't need to root the phone to run linux, and even rooting it doesn't change the fact that you're running linux on top of android.
- teravor 2mo ago> GrapheneOS supports device attestation (the non-google kind at least) they have an app that does GOS to GOS attestation. they also run a remote attestation proxy to a google attestation intermediary (doesn't really accomplish anything). they unfortunately don't provide you with the option to disable the Android APIs that can be used to get a unique hardware identifier from your device (cryptographic identity burned into the silicon) with some extra steps. APIs such as remote attestation and DRM handshake initiation.