Hacker News new | ask | show | jobs
by microtonal 3 hours ago
And way less security, sandboxing is far more limited and the default profile looks pretty much YOLO:

https://github.com/sailfishos/sailjail-permissions/blob/mast...

Given how sensitive information most people have on their phones (banking, chats, and whatnot), it's a disaster in the making.

The typical answer is "but I'll only use open source apps that I trust". Sandboxing doesn't only protect you against rogue apps, it primarily protects you against 0-days in apps that you do trust.

1 comments

It's very simple, this is about the threat model.

If you are worried about big players profiling you (hard to avoid, high likelihood of happening, low likelihood of damage), then you want Sailfish.

If you are worried about apps profiling you (easy to avoid, high likelihood of happening, moderate likelihood of damage), you want Android or iOS.

Graphene and Sailfish sit on different points on that spectrum, just like OpenBSD and Linux do.