Y
HN Search
Hacker News Search
new
|
comments
|
top
|
jobs
tranq_cassowary
searching PlanetScale…
1.
▲
2.
▲
3.
▲
4.
▲
5.
▲
6.
▲
8 ms
·
1.
▲
by
tranq_cassowary
3mo ago
GrapheneOS user and community member here. TLDR: The blog post that this thread links is full of misrepresentations and falsehoods about what GrapheneOS offers and also is heavy mismarketing of the phones and services PrivacyPros offer. I r
2.
▲
by
tranq_cassowary
6mo ago
KiwiFarms is a platform created for the purpose of cyber bullying, harassment and encouraging self-harm. This is very different from a general purpose social media platform that happens to have people signing up that misbehave. The whole po
3.
▲
by
tranq_cassowary
6mo ago
Rossman leaked private messages without properly giving background information about preceding private conversations that they had and about the circumstances that occured just before the conversation he leaked. It was very bad faith.
4.
▲
by
tranq_cassowary
8mo ago
> Even if it improves accessibility, it must be rejected out of hand GrapheneOS has many exploit mitigations and those that would break compatability with too much apps are opt-in instead of opt-out. They also have per app toggles so you
5.
▲
by
tranq_cassowary
8mo ago
Phones, to just give one example, at least have fine-grained run-time permission controls while on Linux apps can just access anything the user can, except if you use something like Flatpak which gives you sandboxing but the quality of that
6.
▲
by
tranq_cassowary
8mo ago
That's not at all what Google announced. It has nothing to do with devices. It has to do with OSes, most notably OSes certified by Google, which GrapheneOS isn't. Also, it will be possible to bypass it even on certified OSes.
7.
▲
by
tranq_cassowary
8mo ago
This is a production grade OS, it's made by professionals, it's not hobbyist. It keeps up with updates of upstream Android and Linux kernel. It has a ton of good security and privacy features.
8.
▲
by
tranq_cassowary
8mo ago
ChromeOS (most secure OS), MacOS (most secure firmware and still much more secure OS compared to non-ChromeOS competitors)
9.
▲
by
tranq_cassowary
8mo ago
What do you think the major practical downsides are? Maybe you are not aware of how many things perfectly work or how easy some workaround are, so I am wondering.
10.
▲
by
tranq_cassowary
8mo ago
It works but you need to install the Google Fi app from the Google Play Store.
11.
▲
by
tranq_cassowary
8mo ago
That's not at all a similar approach so it doesn't quality as "if anyone wants *this*). The GrapheneOS feature pretends the network is down and local host is also inaccessible. This is good for compatability (apps generally t
12.
▲
by
tranq_cassowary
8mo ago
Leaving USB dubbing enabled just exposes a lot of attack surface. And if you use USB debugging you are placing a lot of trust in the computer you are connecting to. You don't need USB debugging to reflash GrapheneOS or to sideload upda
13.
▲
by
tranq_cassowary
8mo ago
It doesn't make it more possible to irreversibly brick your phone. Even if you set it to the most strict setting the port still works when you are in the bootloader and recovery modes. See https://grapheneos.org/feature
14.
▲
by
tranq_cassowary
8mo ago
> /e/OS focuses on privacy (i.e. reducing data leakage to adtech) /e/OS literally sends STT data straight to OpenAI... /e/OS uses priviliged MicroG, which connects to Google for some of its functionality &#x
15.
▲
by
tranq_cassowary
8mo ago
You can perfectly fine use it without, many people do. If you can tell us what issues you exactly bump into when trying to use the phone without Play, feel free to share, we might be able to suggest you some apps or workflows to work around
16.
▲
by
tranq_cassowary
8mo ago
> They deliberately conflate security with privacy (you even write "secure/private" as though they're the same thing) in a way that does a disservice to users. That's not really true. In fact, the way you are pre
17.
▲
by
tranq_cassowary
8mo ago
Regarding location, please see my comment higher in the thread about the location rerouting through GrapheneOS. Also, it's not a better option to use MicroG. MicroG is in most OSes where it's bundled running priviliged and still c
18.
▲
by
tranq_cassowary
8mo ago
Communication between apps using IPC happens on mutual consent and is explicit. You can't just throw data to Play Services and expect it to accept it and process it well, that's not how it works. Communication via IPC is always ve
19.
▲
by
tranq_cassowary
8mo ago
> recommend you install proprietary apps GApps in their sandbox They don't recommend you to do that. They tell people that if people want to install apps, Google Play Store is a secure and easy way to get apps. They inform people ab
20.
▲
by
tranq_cassowary
8mo ago
https://mastodon.social/@gael/115067300718940033 https://nitter.net/GrapheneOS/status/1996683131358007487#m here you go
21.
▲
by
tranq_cassowary
8mo ago
The founder of /e/OS regularly comments on posts about GrapheneOS on social media, almost always unsubstantive and of a low level.
22.
▲
by
tranq_cassowary
8mo ago
There are some problems with this, often if a microSD card is used the storage on that SD card isn't encrypted because of the portability goal of it. It would be a bad fit for the project. As per the headphone jack, the headphone jack
23.
▲
by
tranq_cassowary
8mo ago
They for sure control the direction of the development but it's not really that problematic given that things downstream projects take issue with can just be removed from the source and things they want can be added.
24.
▲
by
tranq_cassowary
8mo ago
If your criterium for choosing an OS is tinkering and hackability freedom to do modify almost anything to your liking (even if it will compeltely break your system or poke extra security holes in), then desktop Linux OSes ported to mobile m
25.
▲
by
tranq_cassowary
8mo ago
It's more common in banking apps than in other apps to implement Play Integrity but it's cetainly not "most banks" that do it. It's still only a small subset. Sucks of course if it's your bank.
26.
▲
by
tranq_cassowary
8mo ago
GrapheneOS distrusts the network. Connections use HTTPS and the integrity of important things like updates is also verified via signatures.
27.
▲
by
tranq_cassowary
8mo ago
x86 virtualization isn't perfect at all QubesOS certainly has some good things going for it with isolation but the guest VMs which run traditional desktop OSes are generally much less secure than mobile OSes like Android OSes and iOS I
28.
▲
by
tranq_cassowary
8mo ago
There is no way to know whether the phone you buy corresponds to the open schematics that are published. It's not verifiable like with software.
29.
▲
by
tranq_cassowary
8mo ago
The firmware being proprietary is compeltely unrelated to how much attack surface it has compared to open source firmware. The only thing that matters is how secure the firmware is.
30.
▲
by
tranq_cassowary
8mo ago
Chromium is the only web engine present on a fresh install. If a user doesn't install a browser with another engine, the attack surface doesn't get increased. Chromium/Blink is more secure than Safari/Webkit overall so I
More ›