Posted by microtonal 1 day ago
All that talk about sovereignty, and we are giving full control of our digital lives to 2 American companies.
Only a few politicians, some of whom happen to be currently in power, in the EU or elsewhere, are pushing for those agendas. But fortunately, they do not represent the majority.
These things wouldn't go away if the EU or a company within the EU would provide a phone OS.
They would just serve different masters.
Andy Rubin was no saint, on so many levels, but when he was removed from Android leadership and the Chrome culture effectively took over this was always how it was going to go.
Just look at how many pay for music and video streaming services, when it's trivial to download anything for free from illicit sources.
No you don't, otherwise we wouldn't have banking apps on it.
I just know that the app can just be cracked - there are plenty of sites that do that for android. Because you can't just load your app on iOS - this is just not possible (well perhaps there are a few percent of some jailbroken iPhones, but that is neglibile).
On Android though, you can soon see such app stolen and on some of the apk warez sites. It just breaks the model.
Think about Windows and software privacy
- You have to setup a developer account with Apple first, and dev-signed apps can only be installed onto specific provisioned devices only[0]
- The free tier of that developer account is inconvenient for actually using dev-signed apps as a daily-driver, and won't let you use certain entitlements
- Apple's dev tooling is designed to make it feel like you can only sign code you're compiling yourself
On the surface level, this might seem like a big difference, because Android has a command that lets you load arbitrary APKs with no particular fanfare or ceremony, while Apple's dev signer is buried inside of a compiler/IDE suite. But people have built tools to make it easy to take an arbitrary .ipa, sign it using your dev account, and resign it once the free tier's 7 day limit expires.
Of course, this still requires you actually go and obtain an .ipa of the app you want to use, and Apple distributes App Store[1] app binaries[2] encrypted. That part requires actually having a jailbroken device to dump the app binary with. But once the app is cracked anyone can install it.
If you want an actual "uncrackable" app you need to put a critical part of your app's workflow onto a server, and then have your app send an iOS DeviceCheck or Google Play Integrity attestation that the phone is running the actual App Store/Google Play version of your app. But that's also incredibly draconian behavior towards your customers as it basically forces your app to be always-online... which is why a disturbingly high number of games do this.
[0] Yes, I know about Enterprise signing, but Apple specifically forbids distributing Enterprise-signed apps outside of your organization and those apps get revoked all the time. Signing with your own dev account is way more robust and that's what most iOS power users actually use.
[1] I have no clue if FairPlay encryption applies to EU-DMA-compliance signed apps.
[2] ONLY binaries - all your resources are unencrypted and can be downloaded off the App Store CDN and inspected by anyone. Code signing signatures do apply to resources, AFAIK
No, smart normies are sideloading with the 7-day limit and leveraging automation to have their pirated apps automatically re-sign and re-push. If you pay the $99 to Apple for a dev cert (or like $10 to a service that'll sell you a cert off someone's account), it'll even just sign out for the year for you. No screwing with Xcode or anything, just drag-drop-sign. Even gives you the options to patch the app out at resigning so you can do hacks and mods like the good old jailbreak days.
It wasn't hard before LLMs and it's nearly trivial now.
> which are like you said handled
Also, I corrected your misstatement about payments. They have absolutely nothing to do with decomp, and certainly can't be used to dismiss the entire attack surface of a mobile banking app. Your example is complete nonsense.
You are really digging a hole here.
There's MNT in the EU.
The EU has enough tech talent to do it, but the political and managerial class lack both the strategic ability or the willingness to adequately reward the effort it would take, almost certainly preferring to, again, outsource the concern, and then be shocked Pikachu later.
Anyone doubting this should see how BMW think about their in car software. And that is for a supposedly premium product.
BMW isn't the EU government. Like I said, someone has to actually do it. BMW Actually Did It in a really user hostile way, and that's the best we have. Why is nobody Actually Doing It but good? Or why aren't we buying MNT products?
As is your comment. It is basically “someone else should do this properly and I will take the benefits” but not actually willing to put up the hard bit themselves.
The root problem here is the EU is culturally broken, and until some grand disaster will simply decline ever further with everyone involved wondering why no one else is doing anything about it.
Because there is way more impact potential of doing so from within the US than from Europe.
Also, because moving to another country with the primary intent to "export culture" is not something (I suspect) most people are interested in (I know I am not). Overall, it feels like a weird proposal. And I expect most of the residents of those countries to treat you with both suspicion and bewilderment, if you told them that this was your reason for moving to their country (and rightfully so, in my opinion).
Take up the White Man's burden—
Send forth the best ye breed—
Go bind your sons to exile
To serve your captives' need;
To wait in heavy harness
On fluttered folk and wild—
Your new-caught sullen peoples,
Half devil and half child.
</sarcasm>Because kids, because pornography, because terrorism, whatever. This is too powerful an option for control freaks to resist.
What is so pernicious about the EU approach is the enthusiasm and efficiency with which it stops anyone from doing anything, while simultaneously attempting to regulate what everyone else in the world can do. If they put even a small part of that energy into encouraging the right thing to happen they would be in such a better place it is insane.
They said if the government “drive the process of forking” which could mean encourage a group of academics to do it, or a commercial consortium. It does not mean the EU government take on the task themselves. *
It is self evident from actual EU behaviour that any mobile os that gets to users will be legally required to be a surveillance disaster area, regardless of origin, and the only people that have prevented this already are evil US corporations.
* edit to add, the EU did encourage many technical efforts vital to the mobile phone industry at different times with a mix of funding, political support etc. The Arm people would tell you AMBA (a standard relating to SoC component integration) wouldn’t exist without this, and yet no one would classify this as “a creation of the EU” but very much enabled by them. For whatever reason since about 2005 their strategic ability in this area has not merely disappeared but become actively wrong.
Look at how they treat Graphene, and that is an afternarket mod niche.
Wrt Graohene the problem isn’t the politicians making announcements, the police assume you are a criminal if you have Graohene and are profiling you on this basis.
In practice they’re the same thing.
And they need a plan to spend it.
But also, I doubt any polity would have its sovereignty undermined if their general-purpose computing hardware doesn't fit into their pockets.
And, for a nominal one-time payment, you can register as a developer, and compile, install and run absolutely anything you want on a non-rooted Android phone with a locked bootloader (within the constraints of the security system, which is, of course, A Good Thing).
Gonna have to post the storage dimensions of your preferred pockets.
So maybe they prefer another solution to the sovereignty issue.
Note that there are competing political groups and MEPs in the EU from far right neo-fascists, to corporate lobbyist right-wingers, to Greens and even digital privacy maximalist Pirates.
Lobbyist right-wingers are now the biggest group and they pass laws like Chat Control because it gives the impression that they do something and it makes corporations money. EU has been founded as a maximally neo-liberal union. The broad human rights are remnants of the Soviet scare and world-war trauma.
Links?
Which, if one's comfortable with the HAP bit flip as a solution to that problem, then one should arguably also be comfortable with bit flips controlling baseband radios which still haven't been demonstrated to transmit when disabled.
Some system apps are being overhauled, so that's something to look forward to. Gallery will be [2] based on ReFra [3].
[1] Except phone and messaging but that's the cell network.
GrapheneOS recommends Signal/Molly or SimpleX instead.
[2] https://nitter.net/GrapheneOS/status/2083724696722301266#m
Also, GrapheneOS supports device attestation (the non-google kind at least), which is still ridiculous as such systems have no benefit to people, only to technofeudalist corporations.
GrapheneOS literally has an app that uses attestation and isn't for "technofeudalist corporations".
Read that phrase back and then ask "is this the future of computing that we wanted?"
The likes of passkeys, essentially user-hostile ssh keys that live on your device but aren't accessible by you, would have been an unbelievable dystopia to us in the 90s.
"Linux folks need to implement the full stack"
Nah it's fine thanks, I'd rather opt out of corporate serfdom than compromise my principles.
It is what I want.
If you own a mobile phone it's unavoidable. The physical SIM is a guarded area with secrets you can't know or touch - the secrets it holds prove you paid for access to their network.
If you want to carry a zillion others devices you can't access the innards of that prove something about you then good for you. But don't assume the rest of us think that's a good idea. We no more object to carving out a little bit of firewalled memory for the exclusive use of the bank than we object to the electricity meter in our houses. It's also a locked down piece of equipment we can't modify or touch that lives on our property. Most people are happy to grant that intrusion on their personal space in exchange for having the electrity connected.
It's no different on your phone. In return for your phone protecting its details from you, you no longer have to carry a credit card, or driver's licence, or prove you paid for ads to go away in some app, or access your works VPN. I honestly can't see much difference between carrying a credit card the hides some information from me, or putting the same info in the phone and it hiding the info. Except for having one less device to haul around, of course.
Stop speaking for Linux.
[1] https://frame.work/products/fingerprint-reader-kit?v=FRANTD0...
You don't actually need biometrics to use key material, that's what (f)TPMs are for. They're not set up to be usable out of the box in any Linux distro I've tried, though.
> GrapheneOS supports device attestation (the non-google kind at least)
they have an app that does GOS to GOS attestation.they also run a remote attestation proxy to a google attestation intermediary (doesn't really accomplish anything).
they unfortunately don't provide you with the option to disable the Android APIs that can be used to get a unique hardware identifier from your device (cryptographic identity burned into the silicon) with some extra steps. APIs such as remote attestation and DRM handshake initiation.
And I'm not trying to be snarky, if that's the only thing, it's solvable right now. Everything else will work.
And concerning "you can't just buy a device and install is" - android and iOS are far more secure than any desktop os, and both pixel/iPhones are far more secure than any computer (or any other phone as well (we'll get the third one next year)). GrapheneOS actually explains "whys" in their hardware support faw section.
Generally maintaining an os is a hard work, so that perhaps explains why there's not many mature offerings.
What's stopping you from buying a phone, unlocking the bootloader, and flashing whatever ROM you want?
This is in practice only true of IBM PC compatibles these days, you really can't install any OS on modern Macs. Maybe you can on (some?) Chomebooks?
This is very useful on OEM ROMs with a bunch of scrapware, no one expects a custom ROM to have this issue.
I find it ironic that an organisation which touts "privacy" so much, asks you to financially support one of the biggest anti-privacy corporations, which is why I can't take GrapheneOS seriously.
(And yes I'm aware of the upcoming Motorola partnership, but the release has already been delayed several times. I'll believe it when it actually ships).
Do you have evidence for this? Since the collaboration was announced, I've heard no delays and they're going to be available on the 2027 Razrs.
>financially support one of the biggest anti-privacy corporations, which is why I can't take GrapheneOS seriously.
You don't meaningfully financially support Google if you buy second hand or refurbished or Open Box. Google already likely has low margins if you buy their phones on significant discount from them.
You don't understand GrapheneOS's rationale. They are focused on delivering a privacy focused OS, not avoiding Google.
If you're smart enough to buy a phone that supports GrapheneOS, AND install it, yeah you should have root.
And tools like XPrivacy and plugins allow control of subsystems like GPS spoofing and lying to apps.
Mobile phones store incredibly intimate data and are incredibly vulnerable to seizure. It stores my message history, pictures I've taken, so many other records that together would provide an incredibly detailed view into my private life. And it is on my person at all times, even through checkpoints where I have minimal protections against search and seizure like borders! This is not a device that I want a broad surface for modification of system software on.
Providing a good interface for that access is a specific missing capability. But we shouldn't presuppose that the only way to supply it is a global su. The former is a bounded fix; the latter changes the isolation model of the entire system. A portal is mediated, scoped to what you asked for, and revocable. Root is none of those things.
Seedvault is itself an example. The need for backups can be met either with a narrow backup service or by handing out root and letting you do it however you like. Those two have very different security properties, and you can want the new capability without wanting a generic privilege escalation path to deliver it.
So you're arguing the same technofascist arguments that Apple and Google both claim. I own my phone, not technofascist sky daddy, or whatever developer also envisions that role.
My hardware. My rules. More people like you need to learn what ownership actually bloody means.
The graphene team provides so much value already. I don't expect them to cater to every need 100%. They are a positive force in the ecosystem when every other Android provider is locking down their builds they still provide everything as open source with security updates as best as they can.
I think the decision of GrapheneOS to maintain the attestation features and not providing user root is what gives it a fighting chance of being accepted as legitimate 3rd choice. See: Revolut and others adding GrapheneOS keys and trusting their attestation
Like or not, for most users, having root access is a liability, especially with more and more important things being held on phones . Someone downloading a photo editing app and then having a rootkit installed in the background that waits to empty their bank account is not a workable situation.
Yes, that would be absurd. Thankfully, that isn't how root access has worked in a very very long time if ever. If photo editing app requests root access... you click deny and uninstall it.
You don't even need to patch it, AFAIK. You can just install magisk, which is how you're supposed to get root on LineageOS as well.
Why not root has been explained many times and you actually either want the official image with no root exactly because of the benefits, or you want custom image because you don't need these benefits.
For location faking Mock location works on GOS,l.
I see much bigger problem with not having a reliable backup than not having root.
It's not anti-user if it doesn't add the features you want that would destroy the security of the OS.
It has many features that give the user more control. Like disabling emergency alerts, protecting your data from attackers, contact and storage scopes (lying to apps for more privacy while retaining functionality), sensors permission, network permission.
"Disabling" an app does not do that much, the OS can re enable it with an update or prevent you from disabling it.
I doubt there is true full privacy on a phone anymore with a stock ROM.
It's horrible. I don't think I can trust them to produce a Graphene phone at all, really, despite all of everyone's assurances.
I think GrapheneOS might have issues in the future considering that Android will be getting more and more locked down. People say GrapheneOS is the better OS when it just is hardened Android; it is doomed purely because of the Android base.
Perhaps a Linux based edition of GrapheneOS would do well, even if it will not have a lot of app compatibility. There's only so much patching you have to do to Android before it just becomes more work than good.
Despite it's name it can also block IPs and specific apps from connecting to specific servers. I use it to block all manufacturer and OEM related apps that I cannot uninstall through adb or disable. Very handy for blocking constant Chinese phone telemetry pings, as well as additional network level blocklists for ads (Pi-hole like), completely locally so you can trust it unlike a shady VPN.
I checked out your link; it seems to be a mailing list for a hosts file for telemetry? Why is there no option to just see the file without giving in my email? Not the most private.
I'll check Rethink again because all in all it's a fantastic software, just doesn't work very stable for me.
Can’t you run an android sandbox in Linux?
Docker phone?
I’m sure I’m missing something here, but what?
postmarketOS and other projects are working tirelessly at bringing Linux to phones. SailfishOS too. Plenty of Android apps even run inside these runtimes.
App compatibility relies on apps supporting (very) old Android versions, though. It's also flaky in many areas and with how few Linux phones have decent GPU support, there's also a performance challenge there.
For some apps, running on Linux doesn't work because the app developers chose to only run on Play Certified, original firmware (Play Integrity and friends). Those apps cannot be patched to work right unless they implemented their checks badly.
Because of Google's cartel-like structure where OEMs get more profit by joining, Google shares some revenue from screwing the user.
> postmarketOS and other projects are working tirelessly at bringing Linux to phones.
postmarketOS has ZERO partnerships with any OEM, their device support is "as is" and done by volunteers, not by vendors like Qualcomm or Mediatek.
> SailfishOS
This one is interesting, but currently the "Jolla Phone" can't be bought "right now", you can order for October..
I see some hope in Murena too, they partnered with Fairphone / Gigaset, so the device support is real there, but it's still Android..
Not to mention that the options outside iOS and Android are slim and for the most part bad (or atleast simply even worse than those).
Because to me it sounds like a cat and mouse game that Google and banking apps are destined to lose.
The strongest levels require hardware key attestation (which, in my understanding, uses a certificate that's baked in secure hardware and signed by Google): - https://grapheneos.org/articles/attestation-compatibility-gu... - https://developer.android.com/privacy-and-security/security-...
Unless you know how to build a sandbox that can simulate a TPM with a key inside that only Google knows. Or something like that. I'm not an expert but there's plenty of information on the internet about this. It's definitely more than "the sandbox is buggy".
Haven't tried an emulator yet. Don't think I will - they're slow enough on my laptop, and I'm not interested in spending my time on reversing anti-emulator checks all day. And I don't like being forced into having a Google account, so anything that goes beyond a calculator app won't run anyway.
This model is attractive for almost everyone - Google, OEMs, operators and even governments.. the only side that loses here is.. the user.
This situation can't be solved with market forces alone, it must be solved by law.
I mean, it really sucks that so many people have made themselves dependent on this crap, but at some point you just have to stop buying the poison or stop complaining that it makes you sick.
The poison to utility ratio has gotten so high that it’s getting increasingly attractive just to ditch the whole thing. You either have to draw the line or accept that there is no line, and that you will yield any degree of agency in exchange for convenience.
For so many people, big corporations decide what they will buy, where they will eat, who they will date, how they will interact, what they believe, where they will go, how they will get there.
Multiple choice is not choice. It is the illusion of choice in a fully packaged life.
It's easy to have a principled stance when the only currency it costs you is your own convenience and standard of living. For many people, life is not as simple as that.
While I have developed skills that have enabled me to do the work involved, this was done without having even meeting the median household income.
So, no, it’s not the only way, but it may be the only way while staying on the reservation. You have to want freedom bad enough to give up the security of the beaten path in favor of the uncertain and often unpredictable consequences of your own decisions.
yet, I write this on my hostilephone lol.
Whenever someone buys an unrootable phone, ask them if they enjoy living under HOAs. That's the same level of control they've agreed to without root. Framing it this way will neatly land your point and just maybe reset their concept of what they should have purchased.
Computers don't have to follow the same design choices as were done 50 years ago.
It doesn't have to be named root, the point is that my device should act in my interest to the fullest extent permitted by the law.
But those running illegal monopolies no longer fear the user and blantantly ignore their choices (yes vs "remind me later" is a good example), if I can't enforce my choice, I don't own that.
What you also seem to be ignoring is that the fact that for example there's no simple runtime internet permission toggle is NOT an accident, this functionality is deliberately not directly exposed despite creating no "security risks" and you know it very well.
Even if a toaster doesn't have such a setting or an easy way to add, you still own it. When products are designed they have a specific design that they implement.
However, it's pointless to focus on what's not available but could - it's the WHY that matters. A toaster without fancy functionality might be mine, but a toaster that only cooks a specific brand of bread, or that displays ads doesn't feel like mine. This is not just a lack of a feature - it's deliberately not there to prioritize the manufacturer over my experience..
It was always a bit surprising you could uninstall an app in a "read only" partition
If an app is installed to both partitions Android uses the one with a higher version.
I'd probably get more useful information reading Hindi Telegram groups without translating anything
The modern societies run via those devices and the enforcement will move to the mostly free Internet that was "a long time ago, when it didn't matter as much".
From keyboards to phones to tractors.
The appstore will die, and the walled gardens will die.
Unless they use 'for the children' to make open machines illegal.
The six or seven percent of us that know how to use Linux will complain, but eventually I can even imagine bootloaders being locked down so much that you need to spend significantly more to buy a computer that actually lets you install what you want.
> many system apps run in the background after being uninstalled, but it's unknown whether they do when disabled.
Is this because some real system apps (as opposed to vendor bloat that just got the "system" flag through bribery) have components in the OS outside the "app" framework that genuinely can't be removed?