Y
HN Search
Hacker News Search
new
|
comments
|
top
|
jobs
_rdvw
searching PlanetScale…
1.
▲
2.
▲
3.
▲
4.
▲
5.
▲
6.
▲
7 ms
·
31.
▲
by
_rdvw
3y ago
They've already leaked user data once and never published a follow up like they said they would, just told users to delete files/contacts/calendars that weren't their own. https://community.e.foundation/t
32.
▲
by
_rdvw
3y ago
My DivestOS supports decade+ old devices and provides monthly security updates for seven versions of Android, no other project does this. GrapheneOS has good reason to only support Pixel devices, they consistently do the right thing with re
33.
▲
by
_rdvw
3y ago
Be opt-in like the other systems, not opt-out.
34.
▲
by
_rdvw
3y ago
You can use a work profile via Shelter/Insular instead which makes this entirely seamless, simply swipe right on your launcher to launch work apps. They even get their own VPN slot too!
35.
▲
by
_rdvw
3y ago
They literally include Google Widevine DRM and Google EUICC: https://gitlab.e.foundation/e/devices/android_device_fairpho... https://gitlab.e.foundation/e/devices/android_device_fairpho..
36.
▲
by
_rdvw
3y ago
/e/OS falls significantly behind the other alternative Android systems with regards to privacy and security. Please see this independent comparison table: https://eylenburg.github.io/android_comparison.htm And add
37.
▲
by
_rdvw
3y ago
My DivestOS patched this on Android 7 through 13 in the December update: https://divestos.org/pages/patch_counts
38.
▲
by
_rdvw
3y ago
Some of these are not like others: https://eylenburg.github.io/android_comparison.htm
39.
▲
by
_rdvw
3y ago
DivestOS is my project. Here are the 170+ kernel CVE patches applied on top of what Lineage provides for Pixel 2 series: https://gitlab.com/divested-mobile/divestos-build/-/blob/mas... Plus it just provi
40.
▲
by
_rdvw
3y ago
Please note /e/OS currently uses a highly insecure version Chromium from December of 2022: https://gitlab.e.foundation/e/os/browser/-/commit/911e34fe66... This impacts more than just the d
41.
▲
by
_rdvw
3y ago
re Android: My DivestOS 14.1 (A7) through 19.1 (A12) has this patched, and 20.0 (A13) is currently compiling: https://divestos.org/pages/news#2023-09.2 GrapheneOS shipped it: https://grapheneos.org/rele
42.
▲
by
_rdvw
3y ago
No, GrapheneOS has its own alternative implementation where users can completely revoke network permission from the app, it has been proven more robust a few times now, eg. https://review.lineageos.org/q/topic:%2213-fir
43.
▲
by
_rdvw
3y ago
Fun fact: Brave Browser on Android contains the proprietary Google Play Services library: https://divestos.org/images/Brave-GMS.png I cover this in depth more here: https://divestos.org/pages/brows
44.
▲
by
_rdvw
3y ago
This is just a feature inherited from LineageOS, not anything special to /e/OS.
45.
▲
by
_rdvw
3y ago
/e/OS is not well rounded. It is currently shipping Chromium Browser/System WebView from December of 2022 with 265 known security issues: https://divestos.org/misc/ch-dates.txt Users cannot change th
46.
▲
by
_rdvw
3y ago
This will be in today's Firefox 117.0.1 and Fenix 117.1.0: https://hg.mozilla.org/releases/mozilla-release/rev/e245ca21...
47.
▲
by
_rdvw
3y ago
It should be noted that Iceraven is not compiled from source, ie. it only compiles the UI/app layer, and not the engine or other components. https://github.com/fork-maintainers/iceraven-browser/issues/...
48.
▲
by
_rdvw
3y ago
Kindly, how can you seriously be calling this secure? By your pictures this is /e/OS, a system which hasn't had the browser/WebView updated in 7+ months, is consistently 2 months behind the ASB, is 1 year behind the PSB,
49.
▲
by
_rdvw
3y ago
> check listed there /e/OS changes the connectivity check from Google to their own server, great, but then it still connects to Google services via microG. So why bother changing the connectivity check? > Chromium updates Y
50.
▲
by
_rdvw
3y ago
AOSP actually has handling when it detects a SIM MCC matching China: https://cs.android.com/android/platform/superproject/+/main:...
51.
▲
by
_rdvw
3y ago
Not all of these return 204, some just return 200 with an "OK" or "success". $ curl --verbose "https://detectportal.firefox.com" < HTTP/2 200 success
52.
▲
by
_rdvw
3y ago
Except /e/OS then throws that out the window because it installs and enables microG by default which immediately connects directly to Google: https://github.com/microg/GmsCore/wiki/Google-Network-Con
53.
▲
by
_rdvw
3y ago
Or switch to a custom OS that provides controls for this and more: - my DivestOS (includes nine presets): https://divestos.org/pages/network_connections - GrapheneOS (includes two presets): https://grapheneo
54.
▲
by
_rdvw
3y ago
I never claimed to be funny, but I think how you seek me out each time to call me names is.
55.
▲
by
_rdvw
3y ago
> awful I think most people agree that such an ancient kernel is awful and can understand the comical take of that title. No where have I claimed their project is bad. > So you just come and drop a huge PR that you haven't tested
56.
▲
by
_rdvw
3y ago
I appreciate the reply, happy to hear mainline efforts progressing too. :)
57.
▲
by
_rdvw
3y ago
Only applying patches that may be necessary is absolutely non-trivial to compute, especially with dependent patchsets, kernel trees used by multiple devices, or future changes to their configs. I already provide monthly software updates for
58.
▲
by
_rdvw
3y ago
If it couldn't be merged as-is that is completely understandable, but why close it then? Why not say "can you tame this back?" instead the response was "this will break things and maybe you added malware".
59.
▲
by
_rdvw
3y ago
I'm happy to see things done right in the form of mainlining the necessary parts, but that takes _years_. Users shouldn't have to suffer with known security issues that have fixes readily available. I've used this tool to sup
60.
▲
by
_rdvw
3y ago
It isn't uncommon for vendors to ship with Qualcomm Secure Boot not enforcing.
More ›