Hacker News new | ask | show | jobs
by SXX 7 days ago
Apple is very much like WhatsApp. Yes you cant perfectly trust their E2EE against state actors, but both in fact put some effort into making world have little bit more privacy.

At least on Desktop we have usable Linux, but on the phones there is literally nothing usable because thanks to Google efforts switching to GrapheneOS mean tons of apps either not working or break every few months.

Yes its possible to make Andoid spy on you a little less, but even for tech savvy person its damn inconvinient and Google making platform worse with every single release.

Thanks to Google "security" I can use my banking apps on 9 years old device with 6 years outdated firmware, but not on GrapheneOS.

4 comments

> hanks to Google efforts switching to GrapheneOS mean tons of apps either not working or break every few months.

I've been using GrapheneOS for years and that hasn't been my experience. There are two financial apps that don't work for me, and that's it. Pretty much everything else I use is fine. But, to be fair, I'm very scrupulous about my apps and tend to avoid installing an app for every little thing that wants me to.

My experience is the same as yours, and I run a huge number of apps for work purposes. A few have required disabling exploit protection but otherwise work fine.

With only one brief exception, all of my financial institution's apps have worked fine, too, including some banks I see drive-by complaints about on here.

Anyone curious should refer to the tracker: https://privsec.dev/posts/android/banking-applications-compa...

My experience is the same as yours. Even several financial apps work. And why shouldn't they? It's a safer OS to do finances than any other. Apps that blacklist Graphene are either data-stealing or just misguided.
> thanks to Google efforts switching to GrapheneOS mean tons of apps either not working or break every few months.

Sometimes, all you need is a Web browser. I personally don't want any "apps" on my phone that aren't basic utilities.

I am aware some banks in Europe require 2FA on a mobile device. Short of switching banks, my answer to that is a cheap or e-waste Googled Android phone that stays at home and serves that sole purpose.

A lot of banks in UK and EU simply dont offer web access at all.
But you can switch to one that does.
It's sadly becoming harder. I've been playing that game for quite long and hope to stick to web apps, but still.

Some banks limit functionality on web apps, which is annoying.

More importantly, many refuse to provide a decent 2FA other than push notifications inside the app or SMS, which is insecure and EU has mandated its phaseout.

The thing that works for me is to pretend to be clueless and get an old hardware OTP generator, but those are susceptible to impersonation attacks on the bank side.

Yes I can, but then I wont be able to use some of very convinient fintech services.

I also need to maintain my own nextcloud, photo sync infrastructure and backups.

Its inconvinient. This is exactly what I talking about.

WhatsApp insists on having access to your contact list. Pro-privacy, it ain't. It's still a Meta product.
Perhaps not anymore [1] and they have usernames as well.

[1] https://discuss.privacyguides.net/t/no-longer-neccesary-to-s...

So does Signal.
Signal keeps contacts in a privacy-preserving way and It doesn't demand access (i guess WhatsApp doesn't either).
> Apple is very much like WhatsApp. Yes you cant perfectly trust their E2EE against state actors, but both in fact put some effort into making world have little bit more privacy.

They probably use E2EE just so they don't have to respond to court orders and such.

Like when Google got tired of handling geofencing warrants.
For the uninitiated: Google stopped hosting your location timeline on its servers just because it kept getting orders to search or reveal it.