←back to thread

194 points sleirsgoevy | 3 comments | | HN request time: 0s | source
Show context
asimops ◴[] No.45776925[source]
While it is technically feasible, it is not a good idea to try and find a technical solution to a people/organisation problem.

Do not accept the premise of assholes.

I hope we can get the EU to fund a truly open Android Fork. Maybe under some organisation similar to NL Labs.

--- edit ---

Furthermore, the need for a trustworthy binary to be auditable to a certain hash or something would make banning this a simple task if Google would want to go that route.

replies(8): >>45777355 #>>45778228 #>>45778511 #>>45779765 #>>45779867 #>>45780458 #>>45780743 #>>45781937 #
singpolyma3 ◴[] No.45778228[source]
What's wrong with lineage?
replies(3): >>45778633 #>>45779667 #>>45781332 #
IlikeKitties ◴[] No.45779667[source]
It's not a good, secure project by a longshot. There's a good comparison floating around:

https://images.squarespace-cdn.com/content/v1/60f1421e1afcf4...

replies(1): >>45779785 #
AnthonyMouse ◴[] No.45779785[source]
That looks like someone made a list of mostly features specific to GrapheneOS so they could make a chart where all of the other alternatives (including stock Android) are full of red boxes.

Several of those are the opposite of security features, like SafetyNet support, which might be a convenience in some cases but it mostly makes it so you can't upgrade certain parts of the system to newer versions even when the old versions have security vulnerabilities.

replies(2): >>45779891 #>>45782945 #
Itoldmyselfso ◴[] No.45782945[source]
Or, far more playsibly, they added to the table features GrapheneOS has, but others don't.

Here's the up-to-date comparison: https://eylenburg.github.io/android_comparison.htm

As far as I know, there is no significant features other distros have that increase their privacy or security over what GOS has. I'm not entirely sure about the SafetyNet thing, but GOS is by far the most up-to-date to the AOSP out of these distros.

replies(1): >>45783867 #
1. AnthonyMouse ◴[] No.45783867{3}[source]
The point isn't that GrapheneOS is bad but rather that it doesn't imply there is anything wrong with LineageOS when it's still better than Android itself.

Moreover, some of the stuff with green boxes is still kind of a privacy fail. For example, with GNSS (i.e. GPS) your device calculates its location from the timing of radio broadcasts emitted by a network of satellites. It has extremely good privacy properties because your device is a passive radio receiver and neither the satellites nor anyone else know you're there when you use it. "Network-based location" can sometimes work when you're somewhere you can't hear the satellites, but now you have Google or someone else building a database of nearby wireless APs etc. in order to make it work, and in the process you're effectively uploading your location to them.

replies(1): >>45784557 #
2. Itoldmyselfso ◴[] No.45784557[source]
GOS developers have said on multiple occasions that they think LineageOS is worse for security than the stock OS on multiple devices, as it doesn't keep up with current privacy/security patches or provide all of the standard protections. The comparison also does bring up these faults. See also https://www.kuketz-blog.de/lineageos-weder-sicher-noch-daten...
replies(1): >>45789120 #
3. AnthonyMouse ◴[] No.45789120[source]
"Device does not force you to update" isn't a bug. The bug is "device forces you not to update" which is the thing you get with stock Android on the large majority of Android devices.

Their objections in general seem to be fairly pedantic, e.g. objecting to a connectivity check which could be improved in a theoretical sense but in practice that shouldn't be leaking anything you're not already giving up by having a phone which is turned on and connected to a cellular network.