3 ms·
There are multiple things in play here: GrapheneOS gives you a very secure device with some neat features that make it basically impossible to get to the data
by Grimeton 25d ago
There are multiple things in play here:
GrapheneOS gives you a very secure device with some neat features that make it basically impossible to get to the data w/o the right pin (so we believe). To make that happen it uses some hardware features that make this possible (so the developers and we believe). You get a highly secure phone with an option to destroy the data on it by handing out the wrong pin. So if you don’t want the customs officer to see that shady stuff on your phone, this one is for you.
And the average Joe? Is that what he wants? Needs? Or is he rather looking for a phone that gives him back control over his data? No Google, no manufacturer spying on him. No option to remotely disable it, no microphone that you cannot trust to not be turned on anyway and so on? If that is what the average Joe is looking for then he doesn’t need GrapheneOS. All it takes is a custom ROM that removes these services.
However, I don’t really see the win here. Joe would move from stock ROM/Google/manufacturer to custom ROM/random developer on the intertubez and so would his trust. And even Joe knows trusting a random guy on the Interwebtubez is the last thing one should do.
The way I look at this Joe is just moving problems around, not solving a single one, creating ten new ones.
Besides that: If anyone really wants to change anything ROMs need to be made for $100 phones, but that’s not an option because the manufacturer won’t make the $$ back via the data so the phone needs to be more expensive in the first place.
slaps Nokia 6150
- em-bee 25d agoJoe would move from stock ROM/Google/manufacturer to custom ROM/random developer on the intertubez and so would his trust. And even Joe knows trusting a random guy on the Interwebtubez is the last thing one should do. but that either applies to GrapheneOS as well, or there actually are trustworthy alternative ROMs out there. GrapheneOS being one, /e/OS being another, for example. there are more that i am less familiar with, so i can't talk about them, but /e/OS is run by Gael Duval, who has been running a Linux distribution before that for many years. and even tough there are criticisms against /e/OS including the claim that it overstates its security and supposedly hasn't removed all google connections, i will trust Gael based on his reputation far above anything coming from google. even more so compared to other OEMs who stuff their android versions with bad apps that you can't remove. so no, i am not trusting a random guy on the internet. i am trusting someone with a known reputation, someone who i have actually exchanged private messages with, someone who i could even meet in person if i were to come to the right conference.
- microtonal 25d agoi will trust Gael based on his reputation Don't? He has mentioned in multiple interviews that security hardening is only for pedophiles and spies (sort of implicating GrapheneOS). They are inaccurate about /e/OS being degoogled. They install F-Droid packages through a proxy (CleanAPK.org) that they do not want to reveal the purpose or owner of, which combined with the Android Trust On First Use (TOFU) model is a big red flag. And then we haven't talked about all the kernel trees, firmware trees, and Android releases that are way behind and have hundreds of known vulnerabilities. Either they are very incompetent or just fishy.
- em-bee 24d agoplease provide references or evidence for those claims
- Cider9986 25d agoActually other Roms do not do a good job at privacy from corporations compared to GrapheneOS. See "Degoogling" section: https://eylenburg.github.io/android_comparison.htm https://eylenburg.github.io/android_comparison.htm