3 ms·
I really liked silence. I stopped using it when f-droid said the source code was no longer available. Fossify messages is the best replacement I've found. (I d
by nosioptar 15d ago
I really liked silence. I stopped using it when f-droid said the source code was no longer available. Fossify messages is the best replacement I've found.
(I dont bother with encrypted messenging apps. I prefer to assume that anything I do on my phone is doubleplus unprivate. If I want privacy, I head over to my computer.)
- Cider9986 15d agoGrapheneOS is more well-roundedly private than any desktop OS. Competition is Qubes but that has usability issues and does not have good hardware security.
- nosioptar 15d agoI'm not about to trust a google branded device. Even if the Graphene folks are on the up and up, google sure as hell isn't.
- Cider9986 15d agoThat's not based in reality. Why would Google have a hardware backdoor when 99.9% of their users run their software giving them the data they want. Google Pixels have no evidence of a hardware backdoor when a desktop is proven to be much less secure against remote and local exploitation. It has been shown through leaks that Pixels running GrapheneOS are the most secure against Cellebrite in AFU. GrapheneOS was the first to implement a reboot timer feature which brings the device to BFU (much more secure) and then Android and iOS copied it (with longer, non-customizable duration). You can inspect network traffic to see that GrapheneOS phones only connect to GrapheneOS-run services. Here's a team member's thoughts: https://discuss.grapheneos.org/d/10150-not-your-average-why-pixel-thread/7 https://discuss.grapheneos.org/d/10150-not-your-average-why-...
- ranger_danger 15d agoBut GrapheneOS relies on a proprietary, black-box security chip from Google... who pinky-promised to open-source it but never did, and that just doesn't sit well with me. I think it's entirely possible that a compromised Titan module (whether such code ships with the device or is updated at a later point) could leak keys via some covert method, and possibly transmit via the baseband or through some other application/method where the OS is not really aware of what's going on.
- mitxela 15d agoThe government only gets to use this once, and they probably won't use it on you.
- fsflover 14d agoI don't believe that they will use this against me. But I do believe in the right to use devices without backdoors for everyone, so I support something else instead.
- drdexebtjl 14d agoWhy? They’ll use it as many times as they want while claiming they used something else.
- ranger_danger 12d agoThat, or they'll just decline to actually prosecute any targets that aren't worth revealing a backdoor during discovery.
- Cider9986 12d agoSo you'd rather choose a chip with demonstrated weaker security over one with demonstrated stronger security because of a hypothetical risk that has no supporting evidence?
- nosioptar 14d agoWhy would google serve malware and scams in their ad network? Google is a dodgy company. Placing any trust in them is foolish.
- Cider9986 12d agoThere's insider attack resistance and there's evidence that the chips hold up against real forensics attacks. They perform better than iPhones in Cellebrite (leading digital forensics company) support matrix leaks. Other options also rely on closed-source security chips or have none at all, and are demonstrated to be much weaker against AFU attacks or are able to be extracted in BFU and then brute-forced if there's a weak password.
- wolvoleo 15d agoThe problem for me is writing on a mobile device is a terrible user experience. When I'm at home I don't wanna use a virtual keyboard on a 6.3" (or 7.9 unfolded). I just want to use my triple monitor PC setup with a real keyboard and a wealth of display space. Mobile is cool for on the go but a productivity killer.
- fsflover 14d agoQubes can be used together with Heads and a hardware key to verify the boot integrity. Works for me. This is more than good enough for most users, unless you think that your device can be captured while being on by a state adversary I guess. Also it doesn't remove control from the user unlike with GrapheneOS.
- Cider9986 10d agoI'm also talking about AFU security which is actually a very common threat which GrapheenOS defends against better than iPhones based on leaks. GrapheneOS is just so easy to use securely.