HN user

tholdem

154 karma

meet.hn/city/fi-Helsinki

Interests: AI/ML, Cybersecurity, Hacking, Hardware, Open Source, Privacy, Programming, Research, Technology, UI/UX Design, Web Development

---

Posts1
Comments69
View on HN

I am currently using 4 banking apps from 3 different banks on GrapheneOS, they all work just fine. I'm also using WhatsApp and would not use the backup feature to Google Drive even on PixelOS. Uber (haven't tried the for drivers app), and other ride hauling apps also work fine.

Why would I choose LineageOS instead of GrapheneOS? I can't see any benefits in using LineageOS, I only see major drawbacks.

Why is it always 0 or 1 with privacy? Why can't I use GrapheneOS with sandboxed Google Play Services? Seems like the best option. I can still use all the apps I want and also get privacy and security benefits. I only give Google what I want and still get to live like a normal person, without making huge compromises on security, privacy, usability and GrapheneOS has been the most stable OS I've used. More stable than the stock PixelOS.

Yes, all notifications work fine with sandboxed Play Services installed. All my banking apps also work fine. I haven't really had any problems with app support or any other problems for the many years I've run GrapheneOS as my daily driver.

If you allow root, there is no need for additional privEsc exploit. Also does LineageOS actually ship security patches reliably for software and firmware? How is Magisk helping to resist attacks?

If you are fine running an OS with horrible security and privacy, then LineageOS and it's forks are fine. If you want the best privacy and security, then GrapheneOS is the best option.

This just doesn't work the way you think, this mentality is not just outdated, but dangerous. People who think like that are more subject to "low IQ" attacks than people who accept the fact they are subject to the same "low IQ" attacks that work on everybody. You are overly confident. You can't be 100% alert and suspicious 24/7, around the clock. At some point you are tired, your attention is elsewhere or you are just not up-to-date on the latest techniques that attackers combine with some form of social engineering.

Also no matter how technical you are, it's almost impossible for you to detect zero-click 0days for which you are more vulnerable to than people without root privileges. You running rooted OS actually become easier and less costly target than people without rooted OS.

No root is a major security feature, you have chosen an OS that prioritizes security.

Use some other browser if dark mode is really important to you.

I think the launcher is good and I can't think of anything to improve on it. I'm happy it's the default, but I'm sure you can switch to a different launcher if you want.

Pattern unlock is also not there because of security.

So you're saying don't use a smartphone at all, which isn't possible, or use CalyxOS, which not only suffers from the same "problems" you criticize in GrapheneOS, but is also inferior in every way when it comes to security and privacy?

This does not make sense at all.

Your logic seems to fall apart here.

an operating system which essentially handles all of your private data.

This is exactly why one should continue using GrapheneOS as it is by far the best, most secure and private option. If you do not agree with one project member about something that is not related to the technical features of the project, it does not matter, since you can not be targeted with any GOS updates. Same updates would have to go to all GOS users and as stated before, the previous project leader has a stellar reputation when it comes to their work and prior actions regarding users security and privacy.

the artist being "Google" and all their controversial practices

You believing this is a problem, you should then be using an iPhone anyway.

You are worrying GOS devs might push a malicious update, even when there are no proofs of that happening? What prevents the same from happening with other projects that are already inferior in every way? You are implying people should switch to less secure options because of this one thing that also applies to all other options? It does not make any sense and seems dishonest.

There is so much misinformation about GrapheneOS. Other hardware is not supported for very good reasons. Mainly because the most basic security features are simply not available on other hardware. Google goes out of their way to support other operating systems with proper verified boot using custom signing keys. Also Pixels have proper dedicated security module, Titan M, which I believe are missing from most, if not all other options. Also MTE support. Hardware security is important and none of the current options match Pixels.

How can you compare iOS or Android security with desktop Linux security?

Have you checked what it takes to achieve those 0-click root exploits on iOS or Android compared to a desktop Linux distro?

Not even in the same league.

Yes, but this was about Silverblue and how it implements some additional sandboxing, which it doesn't. SELinux is great, but maintaining it and creating configs is huge amount of work and where on AOSP, every process is strictly confined with SELinux, on Fedora, not so much. Not to mention the additional software the user installs. Not at all comparable to real Android or iOS sandboxing.

It may be in the future, but for now it is no different from Fedora Workstation in terms of security. Please correct me if I am wrong. AFAIK Silverblue has no additional sandboxing or any other improvements to security.

Sandboxing should be built in and by default, not DIY and glued on, like with apparmor and firejail.

"Your car does not come with a seatbelt? Seatbelt parts are easy to order online and assembled on any car, it's your fault for not using one."

Also the very same npm backdoors have already hit android apps. What can sandboxing do if you backdoor a dependency of your banking app?

The whole point of sandboxing is that one compromised app can not compromise the whole system and other apps. Compromised dependency on my banking app on Android or iOS only compromises that banking app and nothing else.

What concerns me more is that Apple is the only company audibly making a stand.

But still Apple operates in China and Google does not. This is weird to me. Google left China when the government wanted all keys to the citizens data. Apple is making a stand when it's visible and does not threaten their business too much.

Apple is not really in the business of protecting your data, they are just good at marketing and keeping their image.

This is significantly underestimating the benefits of Qubes. Are you using your online banking in the same browser that you use for random web surfing? I do it in separate VMs with hardware isolation. Same compartmentalization with all other things.

What about NetVM? All AppVMs us that so what if that get's compromised? Since the templates are not hardened at all, could the attacker jump from NetVM to AppVM?

I'm not using the same VM for everything but dedicated VMs for bank, email, HN, instant messaging and so on. A malware on a random website would only get the access to an empty VM, nothing more.

So how many Templates and AppVMs do you have? Each of those dedicated VMs would need their own AppVMs at least. You have Domain: Bank, Domain: Email (do all email accounts get their own domain?), Domain: HN, Domain: Github, Domain: Stackoverflow, Domain: Signal and so on.

If your VM is compromised, no hardening will save your data

So that means layered security is totally meaningless and instead of keeping it default, let's remove mitigations?

you never run anything untrusted in trusted ones and never have anything valuable in untrusted ones.

In practice, this is close to impossible.

I don't understand why one wouldn't use them for everything not requiring saving the data

Disposable VMs were the best part of QubesOS, but unfortunately, it's is pretty common that you need to login to something or save something, which means you can't use DisposableVMs for everything.

QubesOS is great if you need to do work and personal stuff on the same computer. I do most of my stuff in the browser and have a separate computer for work. I am mostly interested in making initial access as expensive and difficult as possible.

You are still just as vulnerable or more vulnerable to malware stealing browser sessions, passwords, and everything you have on the AppVM the browser is running on than you are on a regular Fedora Workstation. Unless you only use disposable VMs, which you probably don't. If QubesOS had hardened templates, I would use it. When I used it, SELinux was not enforced, and I believe it still has passwordless sudo. Not sure what other mitigations are disabled in the default templates compared to regular, non-QubesOS Fedora Workstation.

Tldraw Computer 2 years ago

I want to use Tldraw as a simpler alternative to Figma. I want to drag and drop Web Components (or React components) into the canvas to play around with different UI ideas. Maybe a built in library of Shadcn components I could mock up an UI with.

Thing is that Android is probably no more secure than a standard desktop experience specifically due to the very uncontained Play Store, the prevalence of sideloading apps and rooting doesn't really help at all.

This is completely untrue. There is lot more to OS security than where software can be downloaded from. The point about root and sideloading is completely missing the point as those are even worse on desktop operating systems. On desktops you can basically run whatever from wherever and there is usually no sandboxing at all. On Android, there is a strict sandbox and you can't run whatever you want. Android is not rooted by default.

Every app is strictly sandboxed on Android, point me to a desktop OS that has anything close to that. Every process is confined using SELinux policies on Android, which desktop OS has as strict MAC setup? Android has a proper, working verified boot, which desktop OS has something similar? Not to mention all the other hardening and exploit mitigations that are usually completely missing from standard desktop operating systems.

Good actors do it mostly for money and fame, bad actors do it mostly for money. Both actors do it for open source and closed source software.

Isn't it a good thing that anyone can effectively use tools to check for potential vulnerabilities?

This is just speculation, but I think open source projects may mature faster in terms of security because the low-hanging fruit is maybe found faster than in closed source projects?

Another interesting case I think about a lot is the classic AOSP vs. iOS. Apple tried to sue Corellium for making it easier to research iOS. Then Apple started the Apple Security Research Device program to make it easier for researchers to do iOS research. These two things seem to me to be a kind of involuntary open-sourcing of iOS. Why did Apple see Corellium as a threat and why did they provide researchers with these special devices?

Why do you think bad actors "audit" open source more than good actors?

Isn't it more the case that all actors audit all software? Open source just has potentially more "auditors" than closed source?

(I don't understand what you mean by "usual exploits" and "keys to the castle")