3 ms·
>The first ticket you link is not by someone who seems to work on GrapheneOS https://github.com/flawedworld https://github.com/flawedworld for example as part
by ysnp 18d ago
>The first ticket you link is not by someone who seems to work on GrapheneOS
https://github.com/flawedworld https://github.com/flawedworld for example as part of GrapheneOS organisation and has interviewed for GrapheneOS in the past (https://www.youtube.com/watch?v=WkQ_OCzuLNg https://www.youtube.com/watch?v=WkQ_OCzuLNg).
>preventing basically nation state attackers who either compromise or compel a CA
I don't think the compromising, self-compromise or compelling of a Certificate Authority is a feat reserved for state-level attackers. I am not sure why it would exclude any malware that gains enough privileges, or existing campus-enterprise mobility management apps/parental control/antivirus that get compromised or hijacked. But really it comes back to one of the original points which was that GrapheneOS are comfortable recommending and promoting solutions with a high level of security/privacy as a general rule.
>The second ticket
Yeah, I believe I confused the 'frosting metadata' part with the important whole APK Signing Block. The part I wanted which the app store client should verify would be the signing certificate hash which you compare to what the server says the package should give you. As far as TOFU mainstream users basically trust in Google's Play Security & reviews process instead of developer signing certificates/keys because most developers do not publish that out-of-band somewhere they individually control. Widget on Dev's Socials/Site + Publishing hurdles + Developer Console auth + Google security/review add up to a non-zero chance the listing is good. When you get the app you have the benefit of certificate pinning and app signature verification to make sure that non-zero isn't majorly reduced in distribution/transit.
GrapheneOS don't even recommend getting apps from Play anyway if you can verify and source the apps directly from the developer.
>very common among GrapheneOS users btw
Can't say anything for your experiences, but of course I only speak for myself. I can say though that the GrapheneOS developers themselves will never tell you the OS is specifically for high-risk oppressed journalists and whistle-blowers. Another big disconnect is that GrapheneOS believe things need to be much more attack/abuse-resistant for the 99% than they are now, so asking them to aim a little lower than current standards will cause a lot of misunderstandings: https://xcancel.com/GrapheneOS/status/2044440381803069778#m https://xcancel.com/GrapheneOS/status/2044440381803069778#m
>You still have to be wary of what you download, deny it internet access if applicable, etc. Aurora at least lets you filter on apps that don't have GMS listed as a dependency, and works with Exodus to show other trackers, making this process a lot easier than via Google Play
I agree mostly with this, but I think you can see it would be a bit painful and tedious for GrapheneOS to say "We can't endorse violating Google's TOS but Aurora Store is an option under specific circumstances and technical conditions. Apps from Play/Aurora may not contain any Google libraries, GMS dependencies or involve sending data to Google as potentially stated in their privacy policy but there is no accessible way to determine this per-app at a glance." every time they need to talk about Aurora Store.
>Do you happen to have a link for that, or remember where they wrote that?
Recent examples:
https://xcancel.com/GrapheneOS/status/2093353794247467344#m https://xcancel.com/GrapheneOS/status/2093353794247467344#m
https://news.ycombinator.com/item?id=49548219 https://news.ycombinator.com/item?id=49548219