Y
HN Search
Hacker News Search
new
|
comments
|
top
|
jobs
ysnp
searching PlanetScale…
1.
▲
2.
▲
3.
▲
4.
▲
5.
▲
6.
▲
4 ms
·
1.
▲
by
ysnp
7d ago
GrapheneOS is not made for nerds, it is made for normal people.
2.
▲
by
ysnp
7d ago
For what it is worth, GrapheneOS have expressed interest in a new base OS with an Android compatibility/virtualisation layer, but they do not have the resources to build it themselves and a suitable open source one does not already exi
3.
▲
by
ysnp
7d ago
Historically, some very large Android OEMs based in China and selling in China also provided bootloader unlocking support in their devices including Xiaomi https://github.com/zenfyrdev/bootloader-unlock-wall-of-shame...
4.
▲
by
ysnp
7d ago
What if GrapheneOS believe that privacy/security is what gives users real abuse-resistant agency and control over what happens on their device with their data?
5.
▲
by
ysnp
7d ago
GrapheneOS is permissively licensed so that people can do exactly that (and fork for different hardware platforms) if they want to. It is a donation-supported open source project with a small team, and it is not a crime or moral failing for
6.
▲
by
ysnp
7d ago
GrapheneOS have discussed and explored replacing Google Play/Google Mobile Services functionality with equivalent or open source replacements. See: eSIM management, location services, push notifications et cetera. What they have refuse
7.
▲
by
ysnp
7d ago
What about issue tracker discussions, mailing list discussions, security vulnerability reports etc.?
8.
▲
by
ysnp
13d ago
Can you report this to GrapheneOS?
9.
▲
by
ysnp
18d ago
>The first ticket you link is not by someone who seems to work on GrapheneOS https://github.com/flawedworld for example as part of GrapheneOS organisation and has interviewed for GrapheneOS in the past ( https:/
10.
▲
by
ysnp
21d ago
Since we're steelmanning, I would like to add a bit more. GrapheneOS will never be closed source/proprietary because they believe code freedom (and user freedom by extension) is paramount. They have repeatedly said they don't
11.
▲
by
ysnp
22d ago
>Aurora is a lot less invasive while achieving that same goal, but they recommend installing Googleware instead... GrapheneOS vehemently opposes 'for security'.. It's more accurate to say they suggest improvements not vehe
12.
▲
by
ysnp
22d ago
Could you list a couple of the biggest functionality losses from AOSP due to GrapheneOS changes? I might be misunderstanding what you mean.
13.
▲
by
ysnp
24d ago
What functionality and features are lost in the base Pixel OS (not apps) as a direct result of GrapheneOS's changes to AOSP?
14.
▲
by
ysnp
24d ago
GrapheneOS have mentioned wanting to expand the logging/intrusion detection capabilities of their Auditor app but contend with the need to include it as a system app which is against their philosophy (PoLP). It is not accurate to say t
15.
▲
by
ysnp
24d ago
Could you please explain why supporting MTE/potentially EMTE in production as a goal represents a niche use case? Isn't mitigating memory corruption issues a mainstream ideal? How else would you propose to do it?
16.
▲
by
ysnp
24d ago
Are there any alternatives for a similar runtime security improvement?
17.
▲
by
ysnp
24d ago
As far as I'm aware, they do not get the security patches and early bulletin access from Google. They get that from an undisclosed OEM.
18.
▲
by
ysnp
24d ago
>For example they have stated they won't try to spoof SafetyNet because "we don't lie about security features" They said they don't want to do it because it would stop working in the future when Google move to en
19.
▲
by
ysnp
24d ago
I have mentioned F-Droid many times in the official Matrix before they moved to Discord and not been banned. You might be misunderstanding what actually happened or have not asked the moderators why someone was banned.
20.
▲
by
ysnp
24d ago
>Citation needed. grapheneos themselves sure doesn't understand this The GrapheneOS team understand full well that in cases where the Play Store does not allow installing an app on your device due to device or georestrictive rules y
21.
▲
by
ysnp
24d ago
They (GrapheneOS development team) live and breathe the principled stance you seem to be describing. They are staunchly against authoritarianism and mechanisms that are vulnerable to government coercion which is why they promote Android IAR
22.
▲
by
ysnp
24d ago
They suggest PlayStore if you need to get apps that are only available on the Play Store. They do not recommend it above other options, and have mentioned that they very much disapprove of Play App Signing being mandatory.
23.
▲
by
ysnp
27d ago
Much of that is out of their hands unfortunately. Motorola don't use the latest Snapdragon SoCs in most of their more affordable models, and Qualcomm are the only ones so far (outside Samsung/Google) who seem willing to support wh
24.
▲
by
ysnp
27d ago
As far as I understand, broad device support is a non-goal for the GrapheneOS project. They are striving for decent security/privacy rather than wanting to attach their name and resources to mediocre standards. I believe nothing preven
25.
▲
by
ysnp
27d ago
If you know any top level mobile division people at Sony you could encourage them to reach out and commit to meeting GrapheneOS's requirements.
26.
▲
by
ysnp
27d ago
They have bare minimum sane standards for device support but it seems picky from the outside because most Android OEMs are incompetent.
27.
▲
by
ysnp
28d ago
Can someone from AOSP/Pixel hardware security shed some light? This is strange timing, especially when the approach has been validated by Apple also.
28.
▲
It appears Google cut ARM hardware memory tagging support on Pixel 11 series
(grapheneos.social)
7 points
by
ysnp
28d ago
|
0 comments
29.
▲
by
ysnp
2mo ago
Just to note Revolut are quite famously anti-security and GrapheneOS have had to work around attempts to ban it on a few occasions. You may have meant the swiss finance app Yuh or something else.
30.
▲
by
ysnp
3mo ago
Can Android OEMs, bundling Google Mobile Services for Android certification, choose different trust roots for verification? >The correct thing to complain about is requiring developer mode for unverified installs, which doesn't seem
More ›