Hacker News new | ask | show | jobs
by Cider9986 16 days ago
It's absolutely insane that phones have online accounts deeply integrated into the OS. You need to give Apple your phone number to download any apps on iOS.

For example:

Say anyone that downloaded IceBlock commited crime, Apple could give the govt everyone who downloaded its phone number, the govt could get the realtime location of everyone based on their phone number from the carrier.

And that's not even mentioning the other problem that nobody can download IceBlock anymore[1].

It's so refreshing for my phone not to ask for any identifying information when I set it up. GrapheneOS is a better software experience than iOS anyway[2].

Phones have great potential to be the most private and secure computers, cell services not withdrawing. And iPhones are one of the most private and secure devices. But, Apple uses that to restrict its users freedom and it makes Apple's users can easily be controlled by any government.

GrapheneOS delivers that dream.

[1] https://www.iceblock.app/

[2] once you install good apps. This is coming from a lifelong iOS user. Not prejudiced against Apple, I use a Mac (without an account) and their Advanced Data Protection is great (when I had an account).

7 comments

I agree with that.. additionaly, I'm finding it to be insane that organizations are trying to force you to have a "audited" phone to interact with them. (I.e. events, businesses, etc)
Remote attestation is not just insane, it's the technology that will end free computing as we know it today.

What good is free software if using it marks our devices as untrusted and gets us banned from every service out there? Gets us ostracized from digital society? Because we "tampered" with the device?

We should be able to run whatever software we want and they should be none the wiser. Instead, we are part of the threat model now. Our devices are now cryptographically attesting that they are corporate owned and that we are under corporate control. It's so disgusting. The future we're heading towards is terrifying. Everything the word hacker ever stood for will be destroyed if this keeps up.

It can be used for security and used privately [1] but I entirely agree with you, Google's use of it is anti-competitive and terrible.

[1] attestation.app

It's all about who owns the keys and who trusts those keys. If you don't have the keys to "your" computer, then you don't own that computer, you're just renting it from the corporation.

And even if our own keys could be used, who's going to trust those attestations? Nobody. They will trust Google's keys, Microsoft's keys, Apple's keys. Not ours.

the intent is that no one owns those keys, your silicon should be the only entity in "possession" of those keys.

but no one uses blind signatures for attestation so it can be used to fingerprint your device's serial. they do try to make it hard. but generally you should assume that if whoever you are attesting to colludes with google they will obtain your HWID - and if it's google you are attesting to you should assume they have your HWID.

GOS uses a proxy for attestation, but it does absolutely nothing for this threat model.

PS: DRM is even worse, there is no intermediary and the APIs are open to all apps. you probably need to be a well resourced intel agency to make use of it as you need to source a valid DRM license server certificate. technically, actual license servers are in violation of their agreements with google, apple, etc if they use the license request for fingerprinting. but they do retain the ability to blacklist silicon (invalidate pirate devices from pirated media watermarks).

Yeah same as TPM and Secureboot. They can improve your own personal security (and thereby privacy) drastically, but it has to be controlled by the user.
You'll probably just need to keep two phones. One hostile spying device that you use for authenticating and dealing with government stuff, and that becomes e-waste every 2 years. Then you have one that you can repair and extend for your own stuff that respects you and your privacy.
I am doing this now. I have had a carrier locked iPhone SE 2020 which I only use on Wi-Fi for over five years now. I also have an android phone and I don't install any banking apps on my android phone.
>What good is free software if using it marks our devices as untrusted

That is not what remote attestation is for. The operating system maintains isolation between apps, so a free software app being installed doesn't mean an app that needs high security is compromised.

I think you've misunderstood. It's not an app problem. The problem is that it makes Free Software OSes unviable. The copy of Android you compile and install yourself - or your copy of desktop Linux where you upgraded the kernel yourself - will never pass remote attestation, and it gives both the attestation provider and software that checks attestation the ability to unilaterally shut out any OS they like with no workaround, even those that do pass attestation.

In a world of deeply untrustworthy Big Tech, and trend of governments, banks and other basic services needed to exist in society relying on apps and in the future, websites that use remote attestation, that is very troubling.

There are better ways of dealing with the bad actors problem, but Big Tech has chosen violence.

You can apply my same comment 1 layer up.

The hypervisor maintains isolation between operating systems, so a free operating system being installed doesn't mean an app that needs a high security operating system is compromised.

That still requires you to have an OS installed that can not be trusted.

And who maintains and "runs" that hypervisor?

I don’t see how it’s incompatible with open source, just because my development builds aren’t being blessed.
It’s not incompatible with open source. It’s incompatible with free software. If Apple or Google or Microsoft or the government needs to “bless” your build, then you have no freedom to actually use your build.
Your "development build" is another person's daily driver.

Case in point: GrapheneOS (or any other custom Android distro) is unlikely to be able to ever pass remote attestation, even a signed, secure boot build with the bootloader relocked, because it's not the original OS for the hardware.

Same goes for any desktop Linux.

Then why can't we install whatever we want on "our" devices?
Because you are buying a device without the feature of installing a custom OS. If you want a feature, buy a device offering it.
The whole point of this discussion is the trend towards societal scale denial of that feature by both market forces and governmental forces.

There is no such a thing as "just buy a different device" when this "different device" is actively discriminated against to the point it's a paper weight. I wouldn't be surprised if remote attestation becomes necessary to even get an internet connection in the future.

I miss the days when iOS jailbreaks allowed you to completely circumvent basically all DRM because the trust in Apple was so high that you could just assume a device is secure. Contrast that with Android, which has always had invasive attestation mechanisms because of widespread mistrust in OEMs. On iOS, sometimes you had individual apps trying to check for jailbreak but that was it
Apps trying to check for jailbreak is still a thing on iOS and as you would expect, it's jank and can trigger on stock iOS if you are unluky
What is that? I don't seem to be finding anything relevant on Google.
We're running into situations where the usage of smart phones and apps are becoming mandatory for using services.

For example: The UK has a digital ID requirement which is required for you to be employed in the UK. Additionally the EU digital identity services have a hardware/software attestitation that is required to run their apps. (Many of those which 3rd party software can't run).

Another example of this is the Australian eTA - (Everyone has to have a visa to visit Australia.. but the real only way to get a visa* is you have to get an electronic travel authorization which only works via an App)

https://grapheneos.org/articles/attestation-compatibility-gu...

Apps that ban graphene-os being used:

    myGov (Australian government app)
    gov.br (Brazilian government app)
    Ticketcorner
    Authy
    Chyrpe Dating
    TextNow
    mada Pay (Saudi NFC payment app)
    McDonald's (International app used for many but not all countries not including the US)
    Dott
    My SEAT (Connectivity for SEAT cars)
    SwissID
    Volkswagen
    BKK Faber-Castell & Partner
    TK-Doc
    TK-Ident
    TK-App (Blocks access to TK-Safe, TK-GesundheitsMessenger, fingerprint login)
    IO (Italian government app which uses it to gate access to the digital wallet feature)
    PosteID (Italian postal service’s app used to access the national digital identity system "SPID")
    Singpass
> The UK has a digital ID requirement which is required for you to be employed in the UK.

That's untrue.

There was a strong push towards the digital ID from the current administration, but it was abandoned 6 months ago.

What you likely mixed up with digital ID is the old digital visa scheme, mandatory for all non-UK citizens to prove right to work.

Re: your app list: looks a little bit eclectic, so it's worth mentioning most of the apps don't ban GoS specifically, but enforce Google play strong or device integrity pass, which GoS doesn't pass.

Some trip on some exploit protections, like secure app spawning, but these can be turned off per app in the latest releases based on Android 17.

> the old digital visa scheme, mandatory for all non-UK citizens to prove right to work.

Weren't they accepting refugees without documentation?

At some workplaces?

I don't know, probably? That always was an offence[1] anyway.

New scheme, mandatory digital ID, would simply stop Britons from being able to use their physical passport to prove they can work. For everyone else that would swap existing electronic-only scheme with another electronic-only scheme.

I don't think anyone half awake would mistake a refugee with a Brit. At least it's not a problem that would explain introducing a whole huge PITA -- like with mandatory IDs for voting: if I'm not mistaken TWO people total were sentenced for voting-related offences, yet we spend double digits of millions of pounds only to (knowingly) disenfranchise voters traditionally voting against the Conservative government.

Look, I'm a citizen of the EU country and my country's physical ID holds electronic layer containing private keys I can use to remotely sign stuff or authenticate myself. It also allows me to using a digital only ID, and the app ecosystem around that is truly amazing. And I'm a picky one.

Basically it's everything, along with basically every single one European physical ID with electronic layer built-in.

British digital ID was *nothing' of that. If it was a physical smartcard first, optional and not mandatory, I'd probably support it, but the government messaging about that was full of lies and handwaving, especially when people were bringing up the failures of digital only systems like Settled Status for Europeans. Nothing mattered, steamrolling over arguments with soundbites.

No, long story short: no, digital IDs are NOT mandatory and no, employment fraud is not that widespread, and the new system won't fix the employers skirting the law.

[1] https://www.gov.uk/government/publications/illegal-working-p...

GrapheneOS and others should have lobbyists or rather lawyers and lawmakers to fight for using secure systems to mandatory be allowed for these. Sure, there must be some type of OS guarantee, but that should not be exclusive to Google and Apple. And indeed browsers with otp/authn devices (not one per service but yubi/thetis type of thing as those can be made sovereign for a large part); when an OS is not allowed, the browser and app should be mandatory allowed with such a device as that is, actually, more secure than the original device as it is an external encryption and encryption key source the hacker cannot reach.
Us users might be effective as well. Hopefully anti-trust law catches up and bans play integrity. They are probably going to spend their money improving features and experience to get more users. There's threads on the forum dedicated to sending emails to Volkswagen to get them to support Grapheneos and it may be working.
> The UK has a digital ID requirement which is required for you to be employed in the UK.

False

In fact I can't think of a single Government service or legal requirement that requires a smartphone in the UK.

In the past year I have applied for a passport, applied for benefits, opened a bank account, passed through border control, filed a company tax return, closed down a business, helped someone else claim for benefits, made police reports, filed a case with the small claims court, paid my council tax, received an incone tax refund, travelled on public transport extensively, hired a car.

All had alternatives as far as I can recall.

Quite a few were done online just with a computer and optionally a phone number

And based on prior discussions here I have to point out that "require" doesn't mean "ok but the alternative is kind of inconvenient"

> We're running into situations where the usage of smart phones and apps are becoming mandatory for using services.

A new building is being built in my city, and the trash containers which were installed outside have instructions printed on them, indicating that you need to use a smartphone app to take out your trash.

I found this deeply offensive in a way that I cannot explain.

There are breastfeeding pods in airports that require an app and registration to use them as well. (But it's a well known code to use them. 80085 )
This sucks. The solution is to buy the cheepest iPhone and use it just for the goverment services.
The cheapest new iPhone is €720 (iPhone 17e)
It doesn't have to be new. They'll permit using an Android 8 to 10 device last updated over 6 years ago or a similarly old iPhone.
> gov.br (Brazilian government app)

Sucks... At least brazilian banks don't ban it. At least not yet.

Likely referring to Android's Play Integrity/hardware attestation API (good explainer from GrapheneOS [1]) that is practically used to restrict what devices/brands/Android builds an app will allow itself to be run on.

[1] https://grapheneos.org/articles/attestation-compatibility-gu...

> that organizations are trying to force you to have a "audited" phone to interact with them. (I.e. events, businesses, etc)

Even worse, GOVERNMENTS do that. EU Governments basically forcing you to give Google (via the Google Mobile Services rootkit) or Apple (and via the cloud act also the Trump Admin) access to your entire phone (including all of your saved personal data) to use the govt eID system...

Use the old-school ID system.
> organizations are trying to force

If it were only that and we actually had “free market capitalism” and “competition” you could simply choose, but leering and steering these “organizations” is the treasonous and inherently illegitimate government, which is increasingly indistinguishable from private corporations, mostly because it’s the same pool of people, which are reflexively moving us all towards a common focal point of a form of tyranny similar to hereditary oligarchy and/or serfdom.

Don't phones have identifiers outside of phone number anyway? I feel like you have to trust the hardware/os vendor anyway. So if you don't trust apple to not misbehave, maybe not getting an iphone is better than chasing the whole phone-number idea.
Your comment isn't super clear to me, let me know if I misunderstood anything.

Yes there are still identifiers when using cellular data service, but they aren't connected to your phone number that you give out. Phone number gets a determined threat actor real time location, which is what I explained. Threat actor gets location from any carrier identifier. Cellular was built in a terrible way for privacy and security.

Android doesn't let apps see hardware identifiers if that's related.

Yes you're correct about having to trust Apple, but my point is that the way Apple is collecting all this extra info allows them to be compelled to hand it over. It's not about trusting Apple, it's about them following the law, which they will do.

Curious to hear: how much effort did it take to migrate to GrapheneOS? I own a pixel, grabbed it in anticipation of unlocking, but the effort it seems it would take from reading GrapheneOS docs has stopped me from committing to it on my daily driver. Would you please provide a quick time estimate and any snags you hit?
It took me about an hour. I sat down, read the docs, installed it via the web installer, then spent the next 45 min deciding how I wanted to segment separate profiles for play services.

Nowadays it seems a lot easier because there seems to be a separate profile isolater you can run in the main profile, which I would choose if I was installing today.

The only hiccup I've had is that sometimes group messages don't send correctly and send individual messages to everyone, but I think that's because I'm on a secondary profile, and it only happens when the phone is receiving a bunch of messages all at once while I try to send to the same group. But I deny network access to my installed swype keyboard, so it may have something to do with that too.

I've been running this for years, since the Pixel 7 came out, which I'm still using.

I love it. I can confidently go through customs knowing that if they yank my phone during some weird checkpoint and try to celbrite it, I'm as secure as can be.

Thanks for the info! Might take the dive.
Time estimate depends heavily on the apps you use (data migration in them) and maybe some features that don't easily work out-of-the-box in GOS like Google's find my device, where you'd ideally migrate to use foss alternatives like FMD[1]. For the easiest setup by far just install the sandboxed Google Play Store and get your apps from there. In general the more additional security features you enable, the more issues you may face, so I'd recommend leaving everything to GOS default, like leaving Sensors permission ON by default. There are a few gotchas that may not be mentioned in GOS official documentation or elsewhere such as BT tracker devices not being supported for the most part, requiring workarounds. There are also few apps that don't currently support GOS [2][3], so be sure to check them out beforehand.

1: https://gitlab.com/fmd-foss/fmd-android

2: https://grapheneos.org/articles/attestation-compatibility-gu...

3: https://privsec.dev/posts/android/banking-applications-compa...

Thanks for the references, especially FMD tip; have the Google version disabled due to lack of trust.
It takes around 10 minutes to install it. Most of the time people spend on it is deciding how they want to set things up. It's very easy to set it up in a similar way that you would use the stock OS. You can use a single profile with sandboxed Google Play installed.

Many people want to segment things more than that by having a dedicated profile for apps depending on sandboxed Google Play. A work profile, Private Space or secondary user can be used for it. A work profile or Private Space is a lot more convenient. Using a work profile avoids wasting the Owner user's Private Space if you want to use it for sensitive data. We want to add support for multiple Private Spaces per user in the future instead of only 1 per user to fully obsolete work profiles for local usage.

Wow, straight from the source! Heartfelt thanks for maintaining this project; it becomes more pertinent by the day as we slide ever deeper into living into this dystopian surveillance state.
I’m on the edge of migrating from my iPhone to a Pixel with GrapheneOS.

But there is ONE feature I love on iOS and it’s the Live Photos. I feel like it’s an amazing way to keep family memories. Do you know if it exists on GrapheneOS?

Natively it doesn't.

There are 3rd party camera apps that support it, but you'd have to download them separately. GrapheneOS camera app is fine but nothing outstanding. It will give you decent pictures but don't expect any fancy upscaling or editing features.

But you can install google camera without giving it network permissions.
Sure but that's arguably 3rd party at that point.
Only in Google camera, which is usable on grapheneos: You get a live shot feature, it ain't exactly the same tho, look into that.

I run pixelos and the amount of stuff I miss from iphone is staggering, the difference between pixelos/grapheneos isn't as big as the difference between iphone/pixel.

Hmm, don't really miss anything from iOS besides tap the top screen to go to top of page. Also Apple Notes is great.

No back button on iOS is madness and also the Android rotate screen integration is way better than iOS.

Obsidian might be even greater for notes. Looks beautiful, and it's super immersive on OLED especially. Worth trying for sure.

Tap to scroll might be possible to get also. Haven't felt need for it when it takes a few regular scrolls anyway.

Thanks for the rec, I'll try it it. I like the open nature with markdown but when I tried on Mac it was a bit confusing.
It's mostly the app. Nothing come close to apple notes or reminder for instance.

Even safari... On Android, you get chromium that doesn't have any extension or Firefox that has incredibly frustrating UI and doesn't work well on some website.

I can understand extensions but I like Vanadium a lot more than Safari. Reminders is hard to replace unfortunately. Overall I like android apps a lot more though. Once you find the right ones.
Yes, I have it and I use Google camera and Google photos. Not sure if default camera and gallery have it.
"Phones have great potential to be the most private and secure computers."

How would that be achieved

We could assume that a user could make their own computer "private and secure"

But if a third party, e.g., Apple, Inc., Google, LLC, GrapheneOS Foundation, etc., has RCE, e.g., "auto-updates", then how can the computer be "private and secure" against that third party and any party that they "work with", voluntarily or not, e.g., a business partner, a government, but also others that might target these third parties, such as an attacker who isn't interested in their bug bounty programs, etc.

To achieve "private and secure", would the user need to remove the RCE capability of the third party (parties)

What about data collection and surveillance by the third party (the user would have to review the source code and compile the OS themselves to be sure about data collection and surveillance)

If there is data collection and surveillance, then how could the user be sure that the data collected and surveillance capability held by the third party is "private and secure" from that third party (e.g., Apple, Google, etc.), any third parties that work with them, and others who might target these third parties

Assuming the user even knows the identities of all these third parties, what if their operations are secretive and non-transparent

What if they have a history of dishonesty

What if they make no promises to the user that could be enforced and instead they just assume "trust"

Perhaps each user might have a different concept of "private and secure"

I mean... your sentiment is in the right place, but Android phones (non-GrapheneOS) can be used without Google account just fine.

Yes, you need to use F-Droid & Co. to get apps (just like on Graphene), but otherwise they're functional and many people are actually using them like that.

well you cant blame apple for that since Government can literally force your company to doing shit like this
I blame them for collecting the phone numbers. They can already make sure you're running an apple account on real hardware. If they didn't collect phone numbers, they couldn't give them away, that's how all good privacy respecting companies like Signal operate.