HN user

_vere

80 karma
Posts1
Comments27
View on HN

Netzpolitik.org actually reported on what you can do with this type of data a while ago. They tricked a databroker into getting a free sample of geolocation data, 3.6 billion datapoints. They were able to build individual movement profiles for people and link that with real identities by putting just a little bit of work in. For a government with access to stuff like palantir this would mean a full movement profile for pretty much everyone with a phone. German article about movement profiles: https://netzpolitik.org/2024/databroker-files-firma-verschle... Broader article about their research into the databroker topic: https://netzpolitik.org/2024/databroker-files-die-grosse-dat... Wired article for English speakers: https://archive.ph/DmWrw Wired frames this a little strange, around how the government is powerless to stop it and such, especially considering how they now actively admit this is in their interest.

It's unlikely for the Razr line to support microsd since those are foldables, and flagships like the signature line generally tend not to, but nowhere on their hardware requirements list does it say that a potentially supported device cannot have a microsd card slot, thats just wrong. There is nothing about a memory slot that would make the phone less safe inherently, they already support USB drives, internal emmc memory isnt that much more crazy than that, right? I just think its super weird to be like preemtively mad at them for an imagined aversion to supporting hardware that doesnt exist. I get that the people involved with the project can be a little prickly when you ask them for advice about stuff, but what do you expect them to do here? They support the devices they do not out of some sort of adherence to a skewed model of security, they actually genuinely need the hardware to be able to do all of the things they ask for, which currently literally only the pixel line offers. If a manufacturer like Sony who tends to do aux, microsd slots and no holepunch cameras were to adapt to their hardware standards (https://grapheneos.org/faq#future-devices) there would likely be an effort by people to get these supported, its not the lack of will from the devs, its the lack of support from phone manufacturers that has kept the line of supported devices constrained to pixels.

They said on Twitter that future devices in the Razr (foldable) and signature line will be supported. The current devices by Motorola do not fulfill their hardware requirements, so no need to buy one yet. This is speculation on my part, but its not unthinkable that non-flagship support could happen eventually, although mid tier SoCs generally don't have the hardware required to support graphene (hardware memory tagging, sufficiently open secure element, etc), so in the medium term, it's unlikely that anything but the flagships will be supported by graphene.

Their hardware requirements do not say this, where'd you get that idea? Graphene has stated they'll work with the Motorola team on supporting their devices, starting with the successors of the Razr foldable and the signature line, but there really hasn't been any talk about how additional peripherals like aux would be a no-go. USB is also a security concern, which is why they give you the option to disable it outright, disable data or disable until after-first-unlock. I don't see what would keep them from implementing this for aux, although since it's unidirectional I'm not sure if it even makes sense to compare aux to USB. They've supported pixels with aux ports in the past, and I don't think it's inclusion would be a blocking criteria. The comment about the camera is also kinda misguided. They zero out the camera input if you disable it, unlike traditional android. You can have a camera toggle in your quick settings and keep it disabled literally all the time. Enabling it when you bring up any camera related app takes either pin or biometrics, having the hardware here really shouldn't be a concern since you can look at how the code handling it works yourself. I'm not trying to convince you to use a pixel or a Motorola phone, do what you want, but at least be informed about stuff like this when you state things as if they are facts.

Treating Linux as a monolith here is kind of missing the point. Desktop Linux and Android have an entirely different application model, a solution for Android would have to be applied in a significantly different manner to desktop Linux. It'd likely be folded in to play services, as was the case with the exposure notification framework during covid for example.

To a degree. You have the duress pin, so you can wipe your phone quickly if need be. But I wouldn't call that guarding, your phone won't get searched but if TSA or ice saw you wipe your phone in front of them with a, to them, unknown feature, I doubt they'll let you enter the country.

Interesting they'd chose to move to germany with their infra after the whole "gov sued Tutanota into providing a backdoor into e2ee email and won" thing happened. I've been with proton specifically because they are one of the few privacy focused email providers that isnt based in germany. Maybe it's time to say screw it and host my own, even if deliverability is gonna be an issue. I don't feel like my email is safe if it's hosted in germany.

This is just conspiratorial fearmongering based on vibes. If pixels somehow phoned home on a hardware level, do you think we wouldn't be able to tell? Do you think we wouldn't see it in our network logs? GrapheneOS supports pixels because they are currently the only devices that fulfill their list of requirements, like an actually usable secure element, hardware memory tagging, etc. They have said and continue to reiterate that they would support other devices that fulfill their requirements and seem to be currently looking into working with OEMs to move away from pixels in the long term. Just saying "you claim to degoogle phones yet the phone you use is a GOOGLE pixel, suspicious" is baseless nonsense.

Actually insane that this isn't patched in AOSP yet, literally the only android devices that aren't vulnerable are those running graphene. For companies as big as google, there really ought to be just disgusting financial penalties if they leave something like this unfixed for this amount of time.

It's also notable that these companies often dont respect the terms of foss software at all. Anyone worth their salt can tell you that training your LLM on gpl3 code would make it a derivative product, as it is able to reproduce large parts of that code. LLMs that are currently earning Google, Facebook, Openai, etc, billions, while they obviously dont make "their" products available under gpl3.

Stuff like this will just keep happening unless a major jurisdiction goes after these digital mercinaries. The fact that we ignore all laws for no reason other than "our agencies really like spying on people" is laughable. Literally crime as a service, sanctioned by most governments. Should not be surprising that such criminal organizations use their tools to spy on people who don't deserve it.

There was a court case here a while ago because the feds wanted access to someone's emails. They won the case and forced tuta to build them a way into their system that allows them to get at non end to end encrypted emails before they get at-rest-encrypted. German article https://www.heise.de/news/Gericht-zwingt-Mailprovider-Tutano... English article about the same topic https://hackread.com/encrypted-email-provider-tutanota-backd... This essentially means they are forced to save a copy of the non encrypted emails somewhere, at least for german customers. You can argue its not a "backdoor" in the typical sense, since end to end encryption is still in place, but like, come on

Call me crazy but i don't think european media should hype up an airbnb-like company, just because it has the capability to make money does not mean its good for the world or should exist. We do not need a european amazon, we need to move away from companies like that full stop.

I will never not be mad at the fact that they built a developer base by making all their tech open source, only to take it all away once it became remotely financially viable to do so. With how close "Open"AI is with Microsoft, it really does not seem like there is a functional difference in how they ethically approach AI at all.

If a power company suddenly shuts down and after the logistics nightmare that follows, they get replaced, they are still infrastructure. If just a few products that google make go offline for only a few hours, the economic damage that causes is in the hundreds of millions at least. Just because googles services could feasibly be replaced, it does not mean they are not infrastructure.

The luxury goods market is not infrastructure. Not to say they shouldn't be broken up, but google is owning the roads you drive on, your car, everyone else's car and every parking space. The scale of the issue is just MUCH worse. Its not good that if you want the expensive child labor clothes, you have little choice but to buy from LVMH, but like, you can get other clothes. If you want to rid yourself of googles influence in your life, you have to abandon basically every tech item you own and live in the woods.

Allowing a giant supercorperation to exist is generally not in the interest of the public. Google has been using the incomparable amount of money they have in many ways that do not serve the interests of anyone but themselves. Allowing one company to own the most visited websites, the most used browser, the most used advertising tools + marketplace, half of the mobile market and much more has not really brought us a lot of good. Their search service quality has decreased massively in recent years. Google searches for products are basically useless as all of the results are SEO optimized AI compiled listicles with amazon ref links, you can basically only find relevant info by adding "reddit" to the end of your search. Saying "see how you do without google for a day" is the same as saying "see how you would do without electricity for a day". They have worked very hard to become infrastructure, rather than a service.