Hacker News new | ask | show | jobs
by kuschku 26 days ago
If I hand my windows laptop to someone, they can also install a keylogger.

But no one said we have to copy that flawed concept. macOS and Linux already have a good solution, requiring your full unlock password in a privileged dialog to authorize changes.

It's ridiculous that changing the settings on my device is protected 10× more than transferring all my money to a random person.

1 comments

> But no one said we have to copy that flawed concept. macOS and Linux already have a good solution, requiring your full unlock password in a privileged dialog to authorize changes.

You use operating systems that have significantly worse security than GOS, iOS and even stock Android as your examples?

Also you literally are the owner with GrapheneOS, lacking security is not "full ownership." You can create your own build of GOS, you can modify it ahead of time, you can literally see all of the source code it's running.

Claiming GOS isn't true ownership is like complaining that you can't change your car's wheel alignment while driving it and saying it means you don't truly own your car.

> lacking security is not "full ownership"

It kind of is. A locked box with no key, is a very secure device with no utility. If I can't unlock the box ever, just because someone could steal my key and unlock it as well, doesn't make the box an example of a perfect security model.

The issue with taking away root access, and providing no alternative for modifying installed apps, it's just taking away rights from user. An app can modify its own data (which is fine), but a user modifying the data of an app is somehow a big no no. GOS also provides no proper firewall solution, other than the stupid VPN-based solutions available on Android.

If the intention of GrapheneOS is to serve the app developers and not the owner of the device, it should just say so.

Even in your flawed analogy, I can stop at any time and adjust my wheels. Without losing the contents of my trunk.