I was referring to confusion experienced by people new to the passkeys creating passkeys for the first time ("Where am I saving this to?", "How do I store this in my password manager?").
HN user
Itoldmyselfso
The anti-phising benefits are still very much there even if you sync them to pw manager. Yes it introduces single point of failure (pw manager), but at the same time you no longer need to go reset all your passwords to every service you use if you happen to lose that device. Tradeoffs.
Passkey comprises of public key that the website you created it on holds, and the private key you store on your pw manager or in the TPM/secure element. As long as you can copy the private key to the new device, you don't need to recreate the whole passkey. In your case, you would just need access to a backup of the Keepass database in case you lose the device.
The biggest point of confusion in my opinion comes from Windows especially having lacked a way (and kind of still does) to save the private key of a passkey to your password manager, defaulting to saving it to Windows Hello, which saves the private key to your PC's TPM. In this scenario you can no longer easily copy the private key to other devices, and if you lose that Windows PC, you also lose the private key and the whole passkey as a result.
Paywalling with extremely easy, one-click payment of very small amount might work. Paywalling does still incentivize things like misleading, sensationalized click-bait titles, but that's pretty much the norm everywhere.
Alternatively, if there was a subscription that covered a massive amount of blogs/news bundled into one low-cost subscription, that might also work. What I heavily doubt is if donation-based micropayments will ever find enough users to remain profitable.
Time estimate depends heavily on the apps you use (data migration in them) and maybe some features that don't easily work out-of-the-box in GOS like Google's find my device, where you'd ideally migrate to use foss alternatives like FMD[1]. For the easiest setup by far just install the sandboxed Google Play Store and get your apps from there. In general the more additional security features you enable, the more issues you may face, so I'd recommend leaving everything to GOS default, like leaving Sensors permission ON by default. There are a few gotchas that may not be mentioned in GOS official documentation or elsewhere such as BT tracker devices not being supported for the most part, requiring workarounds. There are also few apps that don't currently support GOS [2][3], so be sure to check them out beforehand.
1: https://gitlab.com/fmd-foss/fmd-android
2: https://grapheneos.org/articles/attestation-compatibility-gu...
3: https://privsec.dev/posts/android/banking-applications-compa...
That's ublock origin preinstalled, not internal/built-in adblocking.
You're accusing them of ties to Russia... based on their names?
You can install MS store (not sure about the login though) on ltsc with one command: wsreset -i
How can you be so sure they have never been used in the wild? Surely not all uses of them get reported...
It's valid question for people unfamiliar with the project, but it is the AOSP in terms of looks, GrapheneOS does not customize the UI in any way beyond what their own features require as additions. Note that Pixel OS is not AOSP. The default home app of course also influences the experience quite the bit unless you replace it, which is what I'd personally recommend everyone to do as it's so incredibly barebones. Lawnchair is already a big step up as an open source alternative.
It works exactly the same as in the original "Pixel OS", you just install the same camera app from Play store.
Do you refer to app-accessible root or user root access? The former is absolutely inherently insecure and compromises the security model of Android/GOS.
There's nobody gatekeeping what can be studied and what can't. You claim millions are being wasted; by who? Is the goverment funding the studies you deem as wasted? If so you'd think that rather than making up a study you'd be able to give a single example. Should be very easy if millions are being wasted on these what I'd assume you'd call "bogus" studies.
There's also Simple tab groups which allows creation of file backups at regular intervals https://addons.mozilla.org/en-US/firefox/addon/simple-tab-gr...
What bugs have you found with Tresorit? Has worked great for my company so far.
Comment you're replying to should've specified afterwards. Feature that were never there is very different than pay walling a such essential feature.
It can be a factual statement about the commercial VPN landscape at large, but an incorrect statement about many individual VPN providers. It lacks nuance as a statement.
A very relevant article: "On the security of plugins" (in notes app)
It was announced a while ago to be Mororola: https://motorolanews.com/motorola-three-new-b2b-solutions-at...
Motorola devices that match the GrapheneOS requirements are coming next year. It's good thing they're not compromising on hardware requirements that would undermine the goals of the project. If there's anyone to blame it's the dismal state of affairs on the hardware security side of my most Android phone manufacturers.
Their app also blocks the use of it on GrapheneOS, for no proper reason.
Agreed. Sandboxed Google play really is the non-tinkerer's approach on GOS, including for Android Auto.
Fox news, the biggest mass media in US by far, doesn't seem to drive this narrative
https://privsec.dev/posts/android/banking-applications-compa...
So far it has only gotten better over time, so risk seems minor if your bank is listed as supported.
Are you behind finnish IP? The site owner decided to ban all Finnish IPs due to a dispute with Finnish person who doesn't even seem to be living there. Also they DDoSed their blog leading to archive.is being banned from wikipedia
Pixel camera app is fully supported by GOS, you just install it from Play store (or from other sources). If you don't have Google Photos installed the last photo preview won't work, but you can install a 'shim' app that fixes it without need for Photos app: https://github.com/lukaspieper/Gcam-Services-Provider
Sandboxed Google Play receives no special access at all, so you can deny it all permissions if you want, but you should grant network (and maybe notifications) permission for it to actually function.
The claim that it actually has any measurable effect on the collective health and well-being currently lacks any proof besides "intuition".
Motorola just made a deal with GrapheneOS, so I'd vager they're going to be around for longer on that basis alone.
It is an entirely realistic scenario which afaik data backs up that most people don't change their default privacy related settings which Google profits from, but in case of actually setting their provided privacy settings ON, they do work.