this post was submitted on 11 Aug 2024
1249 points (99.1% liked)

Technology

59055 readers
3173 users here now

This is a most excellent place for technology news and articles.


Our Rules


  1. Follow the lemmy.world rules.
  2. Only tech related content.
  3. Be excellent to each another!
  4. Mod approved content bots can post up to 10 articles per day.
  5. Threads asking for personal tech support may be deleted.
  6. Politics threads may be removed.
  7. No memes allowed as posts, OK to post as comments.
  8. Only approved bots from the list below, to ask if your bot can be added please contact us.
  9. Check for duplicates before posting, duplicates may be removed

Approved Bots


founded 1 year ago
MODERATORS
 

TL;DR

  • Efforts like Graphene OS face increasing pressure from apps that refuse to run on non-standard Android.
  • The custom ROM project characterizes Google’s approach to device attestation as incomplete and flawed.
  • Graphene OS is prepared to take legal action if Google won’t let it pass Play Integrity checks.
top 50 comments
sorted by: hot top controversial new old
[–] [email protected] 7 points 2 months ago

I really hope they fix this. When support for my old OnePlus 6 stopped, I was going to install a custom ROM until I realized bank apps, and most security-centered apps, wouldn't work. So I ran with an out-if-date, possibly vulnerable OS for a year until (probably) corrosion from liquid exposure finally did the phone in.

Really bad thing to incentivize.

[–] [email protected] 17 points 2 months ago* (last edited 2 months ago)

What gets me is the "this phone cant be trusted" message on boot. Implying OEM roms are trustworthy, but nothing i choose or create could possibly be.

[–] [email protected] 6 points 2 months ago (2 children)

the only reason I've wanted to be rooted in recent years is when I didn't have hotspot on my plan and the most complete way around that was with root.

I think I would like a degoogled Lineage/Graphene OS though

[–] [email protected] 3 points 2 months ago

Wtf, plans locking down device features. That's mindblowing.

[–] [email protected] 14 points 2 months ago* (last edited 2 months ago) (2 children)

Why is stuff like that included not included in every plan by default? As a European, I can't even imagine paying extra for that. If I want to hotspot my data, my operator can kiss my ass and simply allow it, I'm paying for the data anyway.

[–] [email protected] 1 points 2 months ago (1 children)

for this case it was a plan that's pretty discounted and also unlimited without hard throttle. they don't want people using it on computers or game consoles probably

[–] [email protected] 7 points 2 months ago

As [email protected] said: @NetworkOperator: Kiss my ass. I pay your for service. You wanna restrict me, I switch my damn plan. If I use it on my phone streaming 4K stuff from my home server or watch 1GB of data over hot spot on my phone is not their business.

[–] [email protected] 6 points 2 months ago

In less free countries the provider also provides the handset and locks it all down.

[–] [email protected] 19 points 2 months ago* (last edited 2 months ago)

Really the only thing holding me back from switching to GrapheneOS is that some of my apps fail CTS.

If a proper pathway is defined for custom ROMs I'd switch in a heartbeat.

Hoping this initiative leads to a reasonable outcome.

[–] [email protected] 4 points 2 months ago (1 children)

I love running a custom ROM, but I'm concerned RCS is going to become a deal break for me :(

I love that text messaging will finally not be complete shit between iOS and Android, but RCS is such a shitty locked down protocol.

[–] [email protected] 4 points 2 months ago (1 children)

but I'm concerned RCS is going to become a deal break for me

For what it's worth, I have RCS working with GrapheneOS. I don't think I did anything special, but it did take awhile. I did see stuff on their forum about others having a bigger issue with it, though.

And of course, I prefer Signal, where possible.

[–] [email protected] 1 points 2 months ago (1 children)

Interesting. Do you have Google services installed? I use MicroG, which afaik has no RCS support.

[–] [email protected] 2 points 2 months ago (1 children)

Do you have Google services installed? I use MicroG...

Yes, I have Google Plays Services, Google Services Framework, and the Google Play Store installed, which are all sandboxed. MicroG isn't supported by GrapheneOS.

https://grapheneos.org/usage#sandboxed-google-play

[–] [email protected] 1 points 2 months ago* (last edited 2 months ago) (1 children)

Oh interesting, I didn't know that's how GrapheneOS handles Google services. I'd love to have working NFC pay and RCS, so I'm going to have to take a look at it. Thanks for sharing!

[–] [email protected] 1 points 2 months ago (1 children)

I'd love to have working NFC pay

NFC works. NFC payment is dependent on the app as some block those that fail Play Integrity / Google certification. Google Wallet / Pay does not work for payment because Google blocks it.

[–] [email protected] 1 points 2 months ago* (last edited 2 months ago)

I'm aware, I assumed being able to install sandboxed Google services would allow Google Wallet to pass, unlike on CalyxOS, but I might be wrong.

[–] [email protected] 12 points 2 months ago (1 children)

Even just being rooted on the stock Pixel rom is a fight. It's a constant cat and mouse game to pass basic and device integrity, but as of recently a lot of us have been able to pass strong integrity as well which has been nice.

[–] [email protected] 3 points 2 months ago (1 children)

Even just being rooted on the stock Pixel rom is a fight.

That, I can see being more of an issue than an unmodified, trusted 3rd party OS. If I remember right, rooting makes the device fail Verified Boot:

It establishes a full chain of trust, starting from a hardware-protected root of trust to the bootloader, to the boot partition and other verified partitions including system, vendor, and optionally oem partitions.

https://source.android.com/docs/security/features/verifiedboot

[–] [email protected] 2 points 2 months ago

Fair point. At least with stock rooted as I said there's ways around it and I can pass all play integrity checks and such.

load more comments
view more: next ›