Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

That's your argument? Mate, you can make explosives out of stuff you can buy in literally any supermarket and no one bats an eyelash. You don't have to legally be adult to buy any of the things you'd need and I say that as someone who only struggled with chemistry in school, that's now low the bar is. What's the solution then? Ban sea salt? If someone is using Graphene, the chances of them getting hacked are astronomically lower than any Chinese spyware-infested phone.
 help



The problem here seems to be that the phone is detected as rooted, not specifically that it's running grapheneOS. But I agree that it's a big problem. That's how you end up in a situation where google has full control from hardware to final apps like on iphones. When devs assume that everybody is using the stock android with google services enabled.

GrapheneOS is not rooted. The phone not being rooted is part of the GrapheneOS' security model.

I assume the issue is it failing the deeper play integrity check which is about it not being "Google approved."


It isn't due to the Play Integrity API. That shows a notification on GrapheneOS with a toggle for blocking it to work around it for services not enforcing providing a result. If that was the issue, the original poster would have known from the notification. The issue ended up being PayPal shipping incorrect anti-tampering code incompatible with secure spawning. The original poster figured that out and got it working by disabling the per-app secure spawning toggle.

How did we let "rooting" become some evil thing?

It's normal to have root (or Administrator) on your devices. After all, they are yours. They don't belong to the device manufacturer. You should have full access to your own devices by default.

Only recently did we somehow normalize the idea that the user should not be the ultimate decider over their own devices.


We've already progressed from "the user should not be" to "the user should never be". Perhaps we will even grow out of calling it "their own devices" eventually. If they can brick it remotely it kinda already isn't really yours?

[flagged]


It does not have a root privilege mode. GrapheneOS doesn't weaken any aspect of the standard security model. It has all of the standard security model and features including hardware-based security intact. It greatly improves security rather than doing that.

User accessible root access is available in userdebug (non-production) builds. There's no system for granting root access to apps. It's no different from the stock OS in this regard, but it's a lot more secure than the stock OS.


Parent has a point by playing devil's advocate. Practical considerations indicate that platform is gonna platform. Solution here to greed driven development is some level of 'non possumus' from the general public. Sadly, I am starting to think is what we really need is a lot of valve like companies, where company stay private, founder is not a complete asshole and so on. Tall order, but that is the only real way to reverse some of the damage. I am done counting on the public to see light.

It was an analogy, or metaphor, I forget the distinction. But I don't think it was stood up to be literally argued against though.

then it was a bad analogy.

Their problem is that stock Android doesn't allow the user to muck around with the insides of apps, and will make it harder for you to trick the PayPal app, while a custom ROM gives you full control to do unfriendly things to the app like reverse-engineering, inspecting it at runtime, and messing around with its internal state.

Edit to clarify: I don't say I agree with that, I believe that if they don't want you messing around inside their app, then they shouldn't ask to be on your device.


Do you like science?

I propose you buy enough ingredients from the supermarket and make a big batch.

The scientific test is: how far do you get, before your door is kicked in?

If that fails, then science #2: have fun lighting it!!

You almost win both ways. (although I admit I wouldn't fund you even via a trustworthy intermediary say a Kickstarter campaign.


physical risks, like your example, do not map well to digital risks faced by large international companies.

It was a response to the gun example which is a physical risk. My argument is that Paypal (much like all other tech-bro companies) are incompetent. The incompetence grows exponentially the larger a software company is. I speak of experience.

On a side note, if you want to be extremely specific, the line between the physical and digital threat does not exist anymore. There are two things people need to be afraid of: incompetent friends and competent enemies. Tech giants are already filled to the brim with incompetent friends, which drastically lowers the bar for the competence of their enemies.




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: