Hacker News new | ask | show | jobs
by 0xdeadb00f 1708 days ago
It looks like this is a more general overview for people who don't have any background on this concept, but I have some issues/suggestions.

Step one should be to install GrapheneOS (or if this isn't Android specific, at least mention it). Don't bother with any other ROM, it's the only one that actually takes security seriously [0].

No mention of alternative app stores that don't require a Google account e.g. F-Droid Aurora Store.

No mention of user profiles for isolating apps.

Browser hardening section is fine.. But I think mentioning Bromite would be a good idea. It's a chrome-based browser with privacy protections and ad-block built in [1].

0: https://grapheneos.org/features (list of security features).

1: https://www.bromite.org/

1 comments

Thanks for your constructive suggestions! I opened a ticket and I will look through them in detail. https://github.com/aronmolnar/smartphone-hardening-guide/iss...

My problem with GrapheneOS is that only Pixel devices are officially supported, which makes it a very tight use case in my point of view. > "GrapheneOS also supports generic targets, but these aren't suitable for production usage and are only intended for development and testing use."

https://grapheneos.org/faq#supported-devices

> My problem with GrapheneOS is that only Pixel devices are officially supported, which makes it a very tight use case in my point of view.

Yes that's fair enough, especially for your guide which again seems to be more general to all mobile phones (which is not a bad thing). Not sure if their website touches on it, but I can see a couple reasons they've gone for Pixel devices only:

- Guaranteed support by google for some time - Official AOSP source (straight for Google) - Titan security chips

If you take sec seriously, you buy your device after reviewing software and hardware viability... not the other way around.
Absolutely. You find this in the section "Choosing a phone". In my point of view, it would be the wrong recommendation, everyone should buy a Pixel phone, just because it supports a certain operating system.