Y
HN Search
Hacker News Search
new
|
comments
|
top
|
jobs
ysnp
searching PlanetScale…
1.
▲
2.
▲
3.
▲
4.
▲
5.
▲
6.
▲
11 ms
·
91.
▲
by
ysnp
1y ago
GrapheneOS have mentioned in the past that the Qualcomm baseband processors compare well to competition in terms of security and isolation support on their respective SoCs. There may be other aspects they need to catch up to Pixels on regar
92.
▲
by
ysnp
1y ago
They have to start somewhere. Unfortunately part of the issue is that most OEMs do not even support their budget models as well as their flagships, so they would fall short of basic reasonable GrapheneOS requirements like 5+ years of timely
93.
▲
by
ysnp
1y ago
As far as I'm aware, their flagship Xperia phones do support bootloader re-locking [1]. The problem is they haven't fulfilled GrapheneOS's other requirements: https://grapheneos.org/faq#future-devices [1]
94.
▲
by
ysnp
1y ago
The base operating system is quite far behind on app compatibility, privacy and "deGoogling" in comparison to GrapheneOS https://eylenburg.github.io/android_comparison.htm .
95.
▲
by
ysnp
1y ago
It's hopeful news. GrapheneOS have had access to security patches as part of their agreement with an OEM partner already, so I assume these discussions/plans have been with the same partner. They are also hopeful of getting full a
96.
▲
by
ysnp
1y ago
All mobile computing and connectivity hardware is unverifiable in reality and by design. It's not some property exclusive to Google Pixels. Their business model also does not involve selling data afaik, it's selling access to thei
97.
▲
by
ysnp
1y ago
I don't know the exact terminology, but they described what they currently have as security partner access or at least advanced access to security patches. To my knowledge they are still working on full partner access that would gran
98.
▲
by
ysnp
1y ago
> It would be "more secure" to have a per-application firewall that blocks particular apps from outbound traffic over certain networks or to certain destinations. This prevents a malicious app from consuming roaming data. Linea
99.
▲
by
ysnp
1y ago
There is Destiny https://leastauthority.com/community-matters/destiny/ . Although there hasn't been much activity lately.
100.
▲
by
ysnp
1y ago
Can anyone comment on where this puts Signal now in relation to iMessage with PQ3[1]? As an aside, can anyone comment on earlier (fast/rushed/sound?) attempts at quantum-resistant encrypted messaging in Cyph[2] and Simplex[3] in c
101.
▲
by
ysnp
1y ago
TextSecure (which later merged with RedPhone to become Signal) had existed since 2010. So it would be interesting to know if there were many other end-to-end encrypted services and products at the time since this was pre-leaks.
102.
▲
by
ysnp
1y ago
You're confusing the founding of the Signal Foundation with the release of Signal. Textsecure/Redphone which Signal came from existed in some part around 2010 or thereafter. Their merging and re-release as an all-in-one IP-based e
103.
▲
by
ysnp
1y ago
Using multiple profiles is completely optional. It is completely the user's choice to put sandboxed google play in a private space or secondary user profile. It is completely the user's choice to put sandboxed google play services
104.
▲
by
ysnp
1y ago
> Nevertheless GOS on Librem 5 or Pinephone would be a nice idea, except the GOS developers are against that: https://news.ycombinator.com/item?id=45101400 GrapheneOS are against using their development resources on a p
105.
▲
by
ysnp
1y ago
> I just wanted to get a statement from them concerning what's a reasonable goal and what isn't Please contact the OEMs/manufacturers and ask them why they cannot support reasonable requirements like: minimum five years o
106.
▲
by
ysnp
1y ago
Sorry, but it is very difficult to understand what you mean and what you want from GrapheneOS. GrapheneOS is a FOSS project and they have committed to that being the case for the forseeable future. They have expressed interest in open hardw
107.
▲
by
ysnp
1y ago
> Sure it's cool you can turn off google play Google Play and associated services are not bundled with GrapheneOS, they are completely optional. > I found the profile feature to be only slightly more convenient than having two
108.
▲
by
ysnp
1y ago
Sharing files requires a bit of creativity. You can share with file synchronisation apps like Syncthing/Ouisync [0], exploit a temporary weakness in the isolation model with Inter Profile Sharing [1], or simply copy the files over
109.
▲
by
ysnp
1y ago
Contactless payments via phone would only be possible if you had a banking app that provided the feature independently. Google Wallet/Google Pay does not work on OSes not certified by Google.
110.
▲
by
ysnp
1y ago
In my country most of them do. It depends on the bank and their application. https://privsec.dev/posts/android/banking-applications-compa... offers a possibility to check which apps may work fine.
111.
▲
by
ysnp
1y ago
Apparently multiple user profiles is available on their tablets but not on their smartphones.
112.
▲
by
ysnp
1y ago
GrapheneOS primarily exists to give you tools to exert more control over what apps have access to and to better protect your data. What you do with those tools is entirely your own concern. Where those apps come from is not GrapheneOS'
113.
▲
by
ysnp
1y ago
I think it depends on the Android distribution. I am not sure it is available on Samsung's One UI.
114.
▲
by
ysnp
1y ago
> This was later obsoleted by the OS adding that feature natively, which is an interesting angle to consider; directly supporting the things people root for definitely helps, but you're unlikely to ever get everything so it's n
115.
▲
by
ysnp
1y ago
> their security model is the only reasonably secure approach in the world They have not said anything like that. In fact there are plenty of things about the current GrapheneOS + Pixel end result that they would change if they had the
116.
▲
by
ysnp
1y ago
> This is not what people are referring to when they talk about rooting on Android Would this have been easier or more possible if Android had a full capability-based security model?
117.
▲
by
ysnp
1y ago
MTE is only available in hardware on Pixel 8 and later https://googleprojectzero.blogspot.com/2023/11/first-handset... . GrapheneOS supports all the Pixel 8 and 9 series phones. They plan to support Pixel 10 once G
118.
▲
by
ysnp
1y ago
I didn't mean to imply Apple (and Google) hadn't been spearheading multi-year efforts to ship this in collaboration with Arm, I regret a little that it came across that way. Just that it would be nice to see production use of it a
119.
▲
by
ysnp
1y ago
https://saaramar.github.io/memory_safety_blogpost_2022/ is a nice article which goes into this topic for MTE in the past.
120.
▲
by
ysnp
1y ago
> Google took a great first step last year when they offered MTE to those who opt in to their program for at-risk users. But even for users who turn it on, the effectiveness of MTE on Android is limited by the lack of deep integration wi
More ›