HN user

icefog

110 karma
Posts0
Comments21
View on HN
No posts found.

Of course that means basically no 3rd party apps

I'm using LineageOS without Play Store/Services and would like to dispel this myth. Here are just some of the third party applications I can install directly from the developer using adb, without going through a third party store: Signal, Firefox, NetGuard, NewPipe, Orgzly, OsmAnd, Tor Browser. Those pretty much cover all of my smartphone needs and more.

Removing OnStar antenna and power was one of the first things I did on my new GM truck. It doesn't require any special tools or knowledge and only takes several minutes. The fact I had to do any of this at all instead of being asked to opt-in to data collection is depressing, but not unexpected in today's data-hungry market.

It doesn't offer end-to-end encryption, therefore there is little reason to be interested. It speaks volumes about the product and company that built it, that it's 2019 and it isn't so much as an optional feature to encrypt your sensitive, personal communications.

Does mutt support oauth yet? If not, this will be the last straw for G Suite from me. I can sort-of understand turning off "less secure" apps in consumer Gmail, but forcing "security" requirements for private, paid enterprise accounts is ludicrous. Time to find a provider which treats me as a grown-up capable of independent security risk judgement.

Librem 5 USA 7 years ago

What does any of this have to do with whether or not AOSP is open source? The Play Store isn't even part of AOSP nor Lineage/Graphene, so the point of that tangent is even less clear.

Librem 5 USA 7 years ago

AOSP is absolutely open source: the code can be viewed, modified, built and deployed as desired. There's good reason to be skeptical of Google-developed software, but your characterization of AOSP as "not open source" is simply not tenable.

Librem 5 USA 7 years ago

I value this sentiment and do feel charitable, but $2000 is not a small amount for me - I could buy 10 or more used Android phones for the same price and flash them with open source software to give to friends and family. Wouldn't that maximize my contribution to collective privacy instead?

Librem 5 USA 7 years ago

The problem is no matter what custom flavor of Android you run, you are still running an OS made by an ad company designed from the ground up to spy on you.

LineageOS and GrapheneOS are based on AOSP, which is an open source project not really "made by an ad company". I agree with your latter point about supporting their hardware and typically buy used phones/computer for that same reason.

Firefox is on a serious roll this year, from performance improvements to actual privacy hardening that matters. Since Chrome rolled out auto-login, I've made it my personal mission to stop using it, and now I'm realizing I haven't even installed Chrome on my newly imaged laptop. I doubt I'll have any reason to switch back.

Librem 5 USA 7 years ago

I'm unsold on spending $2,000 or even $700 on a new phone, but I also care deeply about privacy and security. Is there any strong reason to choose "Librem" over a cheaper Android running LineageOS or GrapheneOS? They can be purchased for a fraction of the cost and have been quite reliable for me.

No, but that would be fairly easy to configure - put the IoT devices on their own VLAN with dedicated DNS server. My household is small and the list of new domains visited is manageable and interesting to inspect by hand. It's definitely more of a hobby than a scalable solution, I must warn.

But not all of them, right? Some of the vulnerabilities do require upstream microcode updates, and without them, I feel like the risk introduced outweighs any benefit provided by Libreboot.

On my home network, using dnscrypt-proxy, I keep a whitelist of top-level domains my devices have connected to. The few new domains to resolve are forwarded to a remote server and logged for periodic review, to update the whitelist or spot suspicious queries. So while it may not scale, it could be useful for spotting DNS C2C.