Y
HN Search
Hacker News Search
new
|
comments
|
top
|
jobs
skorp01
searching PlanetScale…
1.
▲
2.
▲
3.
▲
4.
▲
5.
▲
6.
▲
2 ms
·
1.
▲
by
skorp01
5d ago
The expectations of desktop platforms to behave the way they do is a holdover of early computing not giving much regard to malicious actors. Having a system where you can run a binary and grant it admin/superuser permissions, giving it
2.
▲
by
skorp01
6d ago
You have a fundamental misunderstanding of what AVB is used for. Fully supporting and using AVB grants protection against persistence of *all* kinds. If an attacker gains privilege escalation through a remote attack, persistence become much
3.
▲
by
skorp01
7d ago
It absolutely is. You can fork GrapheneOS, modify it, and sign the images with your own key; all to your heart's content. Exposing root to userspace does not make you the owner of it, and serves to erode the guarantee that the OS is
4.
▲
by
skorp01
7d ago
There is a nice little post here from one of the GrapheneOS project members/moderators. https://discuss.grapheneos.org/d/10150-not-your-average-why-... the tl;dr: - There has never been any evidence found of any h
5.
▲
by
skorp01
7d ago
You are expecting and hoping that it will act the same as desktop environments do. Desktop environments can't/don't because there is an inherent expectation of users that they should work a certain way and they are built upon
6.
▲
by
skorp01
7d ago
Robert Braxman's provisions have ranged from highly insecure devices, EOL devices, charging for TOR as a service, an "e2e encrypted" chatroom that sends the key in plain text, etc. He is a serial fabricator and charlatan. ht
7.
▲
by
skorp01
7d ago
It is not the OS "used by drug dealers". The vast majority of criminals use the stock OS on whichever device they purchase. It is pure make believe to think that people are installing any alternate OSes to commit crimes. There i
8.
▲
by
skorp01
14d ago
Minimum Target SDK is the opposite of user hostile. Privacy and security changes are added to the SDK consistently. Apps that fail to comply with that SDK are much more of a privacy risk. Feel free to look at the AOSP SDK changes for each m
9.
▲
by
skorp01
21d ago
This is not an apt analogy. A couple of the tenets of computing security are: - Defense in depth - Principle of least privilege It is a foundational reality that software (especially in unsafe languages) will invariably have vulnerabilities
10.
▲
by
skorp01
21d ago
This is largely untrue. You would be missing out on: - Minimum Target SDK Enforcement Blocks installation of apps that target ancient versions of Android and legacy APIs. - Restricted settings for sideloaded apps - Null-Cipher rejection and
11.
▲
by
skorp01
3mo ago
Maintaining one's data as private requires that it is protected as a baseline. Privacy violations do not solely exist as telemetry or data offered up by the platform to some other party. The protection is achieved through security. The
12.
▲
by
skorp01
3mo ago
I have bad news; Do you know who is a major contributor to the Linux kernel? (It's Google)
13.
▲
by
skorp01
3mo ago
This is a personal anecdote and you are making up an absurd conclusion. No one said things would collapse. Security can be evaluated objectively, and the better the security, leads to fewer instances of exploitation. I'm certain the ac
14.
▲
by
skorp01
3mo ago
You have the ability to do what you want on your device. Root access in AOSP is just used as a hacky shortcut to achieving specific functionality. To do it properly while maintaining the security model would be to build it into the OS itsel
15.
▲
by
skorp01
10mo ago
That absolutely is not the point of the project and completely misses out on the many general privacy improvements that GrapheneOS makes, as well as the huge privacy improvement offered by running Play Services in the untrusted and unprivil