HN user

Itoldmyselfso

41 karma
Posts0
Comments62
View on HN
No posts found.

Passkey comprises of public key that the website you created it on holds, and the private key you store on your pw manager or in the TPM/secure element. As long as you can copy the private key to the new device, you don't need to recreate the whole passkey. In your case, you would just need access to a backup of the Keepass database in case you lose the device.

The biggest point of confusion in my opinion comes from Windows especially having lacked a way (and kind of still does) to save the private key of a passkey to your password manager, defaulting to saving it to Windows Hello, which saves the private key to your PC's TPM. In this scenario you can no longer easily copy the private key to other devices, and if you lose that Windows PC, you also lose the private key and the whole passkey as a result.

Paywalling with extremely easy, one-click payment of very small amount might work. Paywalling does still incentivize things like misleading, sensationalized click-bait titles, but that's pretty much the norm everywhere.

Alternatively, if there was a subscription that covered a massive amount of blogs/news bundled into one low-cost subscription, that might also work. What I heavily doubt is if donation-based micropayments will ever find enough users to remain profitable.

Time estimate depends heavily on the apps you use (data migration in them) and maybe some features that don't easily work out-of-the-box in GOS like Google's find my device, where you'd ideally migrate to use foss alternatives like FMD[1]. For the easiest setup by far just install the sandboxed Google Play Store and get your apps from there. In general the more additional security features you enable, the more issues you may face, so I'd recommend leaving everything to GOS default, like leaving Sensors permission ON by default. There are a few gotchas that may not be mentioned in GOS official documentation or elsewhere such as BT tracker devices not being supported for the most part, requiring workarounds. There are also few apps that don't currently support GOS [2][3], so be sure to check them out beforehand.

1: https://gitlab.com/fmd-foss/fmd-android

2: https://grapheneos.org/articles/attestation-compatibility-gu...

3: https://privsec.dev/posts/android/banking-applications-compa...

It's valid question for people unfamiliar with the project, but it is the AOSP in terms of looks, GrapheneOS does not customize the UI in any way beyond what their own features require as additions. Note that Pixel OS is not AOSP. The default home app of course also influences the experience quite the bit unless you replace it, which is what I'd personally recommend everyone to do as it's so incredibly barebones. Lawnchair is already a big step up as an open source alternative.

There's nobody gatekeeping what can be studied and what can't. You claim millions are being wasted; by who? Is the goverment funding the studies you deem as wasted? If so you'd think that rather than making up a study you'd be able to give a single example. Should be very easy if millions are being wasted on these what I'd assume you'd call "bogus" studies.

Motorola devices that match the GrapheneOS requirements are coming next year. It's good thing they're not compromising on hardware requirements that would undermine the goals of the project. If there's anyone to blame it's the dismal state of affairs on the hardware security side of my most Android phone manufacturers.