←back to thread

455 points akyuu | 1 comments | | HN request time: 0s | source
Show context
derbOac ◴[] No.45766747[source]
They couldn't answer the question most on my mind: "We’ve reached out to Google to inquire about why a custom ROM created by volunteers is more resistant to industrial phone hacking than the official Pixel OS. We’ll update this article if Google has anything to say."
replies(10): >>45766778 #>>45777056 #>>45778032 #>>45778056 #>>45779079 #>>45779102 #>>45779404 #>>45780503 #>>45781099 #>>45783125 #
LoganDark ◴[] No.45778032[source]
GrapheneOS makes security trade-off that are inconvenient to the user. This results in a far more secure device, but nonetheless a device that the general public would find far more annoying. Google would lose a proportion of its user base by implementing the same protections.

Example: https://old.reddit.com/r/GooglePixel/comments/ytk1ng/graphen...

Also Google Pay is missing.

replies(4): >>45778078 #>>45779111 #>>45779935 #>>45780063 #
zb3 ◴[] No.45778078[source]
Which particular thing you consider inconvenient or even annoying? You can even install Google Play there.

I see just one minor tradeoff - no face unlock.

replies(4): >>45778348 #>>45778541 #>>45779117 #>>45781598 #
chasil ◴[] No.45781598[source]
They removed pattern lock, which makes me uncomfortable.

I don't care for touch/fingerprint (or face) because biometrics aren't protected in the fifth amendment right to be free from self-incrimination.

The only screen lock is PIN.

replies(2): >>45782122 #>>45784401 #
subscribed ◴[] No.45782122[source]
Straight from the horse's mouth: https://discuss.grapheneos.org/d/16393-maybe-re-instate-patt...

> Pattern unlock is a badly designed lock method that's a major downgrade from the security of a PIN for multiple reasons.

> Pattern lock is even more dangerous to people who are as you say more casual users. It is a badly designed and dangerous feature. iPhones not having this is very good for users. We will not add back a major flaw in the OS security design.

If this makes you uncomfortable somehow? OK? Maybe it's not an OS for you :)

replies(1): >>45782975 #
chasil ◴[] No.45782975[source]
That is hardly the only problem.

The browser is astonishingly bad at dark mode.

The launcher forces almost all icons to greyscale black and white and does not accept icon packs.

I feel like I'm downgrading by my compulsion for Brave and Lawnchair, but some attention is lacking in aesthetics. (e/os has this problem to a lesser degree with the Bliss launcher.)

There is no rooted ADB. Even if a giant OS TAINTED notification appears every five minutes if I ever turn it on, I want it.

There are a few other annoyances that regulate Graphene to one of my experimental spares.

replies(1): >>45785887 #
subscribed ◴[] No.45785887[source]
Vanadium is pretty good but I agree there are problems I can circumvent only by using another one (Brave); I presume it's the strict tracking protection that breaks some sites.

Not sure about your launcher problem, but you had to turn it on yourself? I don't experience anything like this on my phones. I miss Nova though; none of the other launchers I tried came near (last tried: uLauncher, Kvaesito, Olauncher, Lawnchar, Niagara. Need to try Square home perhaps).

Lack of rooted adb is a good, conscious choice for the security focused OS. It's not about _you_, it's about the integrity of the OS.

You demand access to adb root. Today Cellebrite cannot extract entire phone with one profile unlocked. I bet they'd be thrilled to hear about the new, beautiful target.

If you really need that, you can build yourself debug image and have access to it. You want it, but that's incompatible with the security model. They give you ways to get it, of course, but without their stamp of OS integrity.

To me safe defaults are a good choice.

replies(1): >>45786256 #
1. chasil ◴[] No.45786256[source]
I understand that Magisk can be applied to Graphene if the final device lock step is not applied.

I might try that if I elevate it to my daily driver.

I'm not comfortable without root. I have the absolute right to have root on my device.

I don't know why Graphene didn't just take Trebuchet.