7 ms·
I would not trust any of these. They are a security disaster, lacking even basic features for securing your device against tampering and hacking. There is a re
by kahnclusions 9mo ago
I would not trust any of these. They are a security disaster, lacking even basic features for securing your device against tampering and hacking.
There is a reason GrapheneOS is number one and a reason why they only run on Pixels (for now).
- DANmode 9mo agoDepends on your threat model, but yes.
- udev4096 9mo ago[flagged]
- DANmode 9mo agoThis is true. Many more care about neither, or intermittently care about neither, than most take into account.
- fsflover 9mo agoNo, it doesn't. It obeys Google's long-term development strategy for the OS. Google and privacy are absolutely incompatible. See: https://news.ycombinator.com/item?id=29502439 https://news.ycombinator.com/item?id=29502439
- tranq_cassowary 9mo agoGoogle has implemented lots of privacy and security features in AOSP over time. The app sandbox and permission model has evolved a lot, in a good direction. The codebase is also modernized with the increasing adoption of memory safe code. At least Google seemes to have a thought out development strategy to enhance security and privacy, contrary to the projects you mentioned elsewhere in this Hacker News thread. Also, what you link doesnt prove what you think it does. Manifest V3 is a very good thing for privacy and security. It restricts and controls the access of extensions much more. With MV2 you have much less control over your data.
- fsflover 9mo agoEvery reasonable, independent organization confirms that Manifest V3 is the end of privacy for Chrom(ium) users, e.g., https://news.ycombinator.com/item?id=29502439 https://news.ycombinator.com/item?id=29502439 https://news.ycombinator.com/item?id=41871873 https://news.ycombinator.com/item?id=41871873 https://news.ycombinator.com/item?id=44543660 https://news.ycombinator.com/item?id=44543660 > It restricts and controls the access of extensions much more. You mean, it restricts users even more and gives to websites the freedom to track you? I won't engage in further discussion with you, you're just trolling.
- tranq_cassowary 9mo agoYou link three things, that doesnt equate to "every independent organization". One of your links is a post by Brave and Brave isnt independent in this. The unsubstantiated fear of people for MV3 is beneficial for them, it could grow their userbase because they keep the support for MV2. Content blocking (ad and "tracker" blocking) are convenience features, they dont foundationally improve security. Defining what a tracker is is difficult and you cant list them exhaustively. Also smart businesses and organisations can just shift to sending all data to the main domain and handling it server side to send it onwards to other domains, including third-party domains. If you dont trust a site to not send data to third party domains directly, why do you trust it to not send it indirectly? No, I meam it restricts extensions because it does. Vouching for MV2 is like vouching for an Android OS without a proper permission model. MV3 helps against tracking, its good for privacy and security. If you want the convience of content blocking, uBlock Lite still works good enoough for many people. Though, you still lose on security and meaningful privacy (again, define a tracker and list them all, impossible) because extensions in general hurt site isolation and increase your fingerpint.
- fsflover 9mo ago> You link three things, that doesnt equate to "every independent organization". Seriouslu, is this the only counter-argument you could invent? I didn't have the goal to list all independent organizations in the world. Now, you have to find one saying the opposite to EFF. > If you dont trust a site to not send data to third party domains directly, why do you trust it to not send it indirectly? Because there were examples when 3rd-party ads delivered malware to clients: https://www.networkworld.com/article/946902/forbes-malware-ad-blocker-advertisements.html https://www.networkworld.com/article/946902/forbes-malware-a... Also, because FBI recommends it: https://www.pcmag.com/news/fbi-recommends-installing-an-ad-blocker-to-dodge-scammers https://www.pcmag.com/news/fbi-recommends-installing-an-ad-b... > MV3 helps against tracking Against tracking by whom? By FLOSS add-ons intentionally installed by user and verified by the community? In contrast to random, untrusted websites running megabytes of proprietary JS?
- fsflover 9mo ago> security disaster, lacking even basic features for securing your device against tampering and hacking Indeed the GrapheneOS community is known for attacking the GNU/Linux mobile with false claims, https://news.ycombinator.com/item?id=45562484 https://news.ycombinator.com/item?id=45562484. Security is a meaningless word without defining a threat model. Try to defend your GrapheneOS against Google, especially these two problems: https://news.ycombinator.com/item?id=45208925 https://news.ycombinator.com/item?id=45208925 and https://news.ycombinator.com/item?id=45017028 https://news.ycombinator.com/item?id=45017028. See also good replies by other people here comparing GOS with Pinephone: https://news.ycombinator.com/item?id=32496220 https://news.ycombinator.com/item?id=32496220
- tranq_cassowary 9mo agoGrapheneOS doesnt really proactively attack GNU/Linux. What happens is that there are posts on the internet about GrapheneOS or mentioning GrapheneOS in which or under which completely wrong comparisons between GrapheneOS and GNU/Linux get posted. It makes sense that you care to clarify or correct if you spot people are talking about your project and are (intentionally or unintentionally) spreading wrong information about it by making comparisons based on misconceptions or falsehoods. The thing you link about restricting network traffic doesnt make much sense. GrapheneOS has a proper network permission which other OSes dont have. The outbound traffic restrictions to certain destinations which are being referred to are just a bad approach. You can send the traffic to one server and just process it there and send out to other servers. You also say : > Also, if I explicitly don't trust Google with anything, GOS is extraordinarily insecure for me until a new vendor If thats the case, dont opt for GNU/Linux either given the large code contributions made by Google. Also avoid any software built with LLVM, written in Go, written in Flutter, using Angular, ... The two "problems" you link arent really huge security issues. How is GrapheneOS having access to the embargoed patches and being able to ship them a security issue? Also the planned sideloading restrictions dont even apply to GrapheneOS. It would only apply to certified OS that license Google Mobile Services. Also, that isnt even a security issue. Its a freedom issue.
- fsflover 9mo ago