12
38
Nicro

@discuss.tchncs.de

Nicro 38 points 6 months ago

App verification is only enforced on ROMs that honor it. You can choose to patch it out of the OS as the maintainer. Which will bar you from being a google certified OS.

The people behind GOS have gone on record, stating that they don't care about being google certified, and GOS will not enforce dev verification. So this changes nothing for GOS.

To stop GOS, google would need to change their bootloader policy. I haven't heard of any indicators for this though.

In summary, you're fine to use it on new and used Pixels. Given current information.

Reference: https://discuss.grapheneos.org/...

path: 0 22123182, hotness: undefined, score: 38, children: 0
Nicro 29 points 2 years ago

I'm currently on Tuta, because I can't imagine Mail without a free tier. It's run out of Germany(EU). Its 3€ a month for the normal tier, free takes away most features. Like Proton, you need to use their (OSS)-Client, for encryption reasons. It's currently growing and I hope they don't go crazy anytime soon.

I was looking at Posteo, but I don't want my entire internet identity to be gone, if I ever can't pay for it.

path: 0 14502019, hotness: undefined, score: 29, children: 3
Nicro 20 points a year ago

Well the idea of having attestation isn't the problem. The problem is that apps requiring attestation (banks, insurance providers, ID-systems) use the most convenient solution. Slapping on Googles prebuild attestation. Graphene for example, provides alternative attestation for their OS and offers docs for anyone to implement a more fitting set of checks.

There are two approaches here: If you're upset that your hacked-to-bits, rooted, unlocked and/or unencrypted device is failing checks: I'd say, tough luck. Until we can create provably untampered app-containers, that level of access genuinely breaks TOS on apps and regulations on handling personal data. Breaking those checks is then breaking those compliances in an unsafe way.

If you believe your setup is actually secure and compliant, just not in a way the allmighty Google intended: Try and get an attestation module for your setup. Fight for these apps to accept non-Google attestation and fight for devices that don't artificially limit what can pass as secure.

path: 0 17518581, hotness: undefined, score: 20, children: 6
Nicro 14 points 2 years ago

Yeah, it's kinda telling, if you look at my prime subscription for example. I can either:

  • Hook into the web-service with Kodi, breaking TOS and theoretically risking the account. While Google, missing their widevine tax, limits the quality.

  • Pirate the same content without an account, at full 4K.

It's truly a service problem.

path: 0 13858124 13858234, hotness: undefined, score: 14, children: 4
Nicro 11 points 8 months ago

In reality they do help superficially, but they very much inflate their numbers on a shiny dashboard, showing you how much they're helping. All while only hitting a small fraction of databrokers.

I also think, that as a subscription solution to a problem, they could turn into the online version of turbotax any second now. Lobbying for harder self-optouts so that their service stays relevant.

path: 0 21112266, hotness: undefined, score: 11, children: 0
Nicro 8 points 2 years ago

Afaik google-pay is prone to fail even with faked safetynet. Magisk can also fix safetynet, but I don't want to enable root-access. Kinda dumb that the way to fix overcritical security checks is to break security even more. :)

Thanks for the idea though.

path: 0 13495801 13497028, hotness: undefined, score: 8, children: 0
Nicro 7 points a year ago

Hey there, for starters A-GPS, stun, secure DNS, and several other preconfigured servers default to Google. Some of these can be changed with ADB. Check out a guide on de-googleing LineageOS for a more complete list. It's not AOSP, but close enough. There are also Google servers configured in the sources. How valuable those connections are, depends on your threat-model. If you'd like a paranoid GSI, check out LeOS. It's probably the most complete treble-compatible option. AOSP by default, isn't very private.

path: 0 17348226, hotness: undefined, score: 7, children: 0
Nicro 7 points 2 years ago

Depends on how far you want to go. From what I've been able to tell, they pedel a lot of flashy metrics and still had a bunch of google calls. Some of which you can manually remove, same as LOS. I would avoid buying into their cloud and keeping an eye on things yourself, if you want to install it. I saw them rebrand a bunch of OSS tooling as their own products back then. Don't know if things changed since then, but I don't trust the marketing.

path: 0 14726454, hotness: undefined, score: 7, children: 0
Nicro 6 points 2 years ago

Like others said, banking needs licensing and licensing costs money. If you already have a bank account, you already trust one party. Ask them if they roll their own app-payment or are already partnered with a service. That way, you can avoid google/Apple and minimize spreading the trust to other parties. My bank cooperates with Fidesmo, for example. Fidesmo then sells wearables with nfc-pay.

path: 0 13770291, hotness: undefined, score: 6, children: 0
Nicro 6 points a year ago

I feel there are plenty of local activist/independent servers all over the EU. As long as you mind the encryption/anonymization, you can even round-robin them. Having a central EU authority is better than Google/Cloudflare and should be safe, if the implementation is sound. But there is a lot of room to meddle.

path: 0 17493704, hotness: undefined, score: 6, children: 0
Nicro 5 points 2 years ago

An advantage of Tuta and Proton is, that there is a basic free tier. Your Mail is a center-point of your online activity. Hoping it to never happen, if you ever can't afford the (cheap) price, you won't lose access to your mail. Which would suck, for all accounts linked to it.

path: 0 13916584, hotness: undefined, score: 5, children: 0
Nicro 5 points 2 years ago

Honestly, I was avoiding Debian for the staleness, but it might be what I go for. I use ungoogled chromium, and all but the flatpak version seem to lag behind. I don't like the packaged dependencies for each app, since there tend to be a lot of redundancies and bigger deltas. Though if you fully commit to flatpak, with Debian as a stable base, that might be good. The more I try to customize Mint, the more it fights me.

path: 0 13947318 13948152, hotness: undefined, score: 5, children: 1
Nicro 5 points 2 years ago

Custom roms with relocked bootloader only work on pixels by design. You'll have to live with an unlocked bootloader.

As for easy installs, Murena's e/os exists with support. But I can't vouch for their cloud ecosystem. Other than that, maybe an officially supported lineage device. You will lose safetynet on both unless you want to root.

path: 0 13496862, hotness: undefined, score: 5, children: 5
Nicro 5 points 2 years ago

I'd be a good start, if content platforms had to apply the same guidelines to ads, as they do to content. It's kinda telling that people on the platform need to not swear, while the ad below goes "You can't last 5 seconds in this NFT gambling waifu gatcha collector aimed at teens." or just offer money freud scams directly.

path: 0 13976120 13976941 13977097 13978421, hotness: undefined, score: 5, children: 0
Nicro 4 points a year ago

Not to sound stupid, but it really depends on how smart you want the watch to be. From connectionless firmware device to fully-featured Android. +1 for gadget bridge either way.

I have a Fossil Hybrid, that combines physical hands with a 2-color e-ink display. It can't do apps, but it has standalone timers, notifications, media control, pulse/oxygen and step counter. I personally don't need more. It's cloudless and lasts a week.

If you need full Android/WearOS check AsteroidOS and specific ROMs. Hardware tends to be on the older side here.

The only thing that's hard to do is sleep tracking. That tends to rely on proprietary algorithms and cloud compute a lot.

path: 0 18702775, hotness: undefined, score: 4, children: 0
Nicro 4 points 2 years ago

Yes, that's what I meant by "widevine tax", the certification is done by Google for a fee.

path: 0 13858124 13858234 13858371 13863021, hotness: undefined, score: 4, children: 0
Nicro 4 points 2 years ago

Seen them recommended in dumb-tv articles. Will check them out.

path: 0 13641665 13641697, hotness: undefined, score: 4, children: 0
Nicro 4 points 2 years ago

I do have a Jellyfin server, this is mainly about being able to use the subscriptions I happen to already pay for. Decoding on the pi is actually quite decent with hvec and x264.

path: 0 13857974 13858173, hotness: undefined, score: 4, children: 0
Nicro 3 points a year ago

I don't disagree with owning your hardware. I'm saying that a regulatory body can pose rules on where critical software can run. Part of this is data exposure: A banking app running in a tampered environment makes some malwares possible, which is the side you want an "I know what I'm doing"-button for. But it also creates risk for the bank. In letting you look into network-traffic and memory-dumps, you may discover ways to manipulate an unrooted instance or the backend server. This is security through obscurity and I'd much rather have everything open-source, but it's what we're dealing with.

On the other hand, the bank promises to cover damages, whenever they do mess up. You could give them an easy excuse by taking on that responsibility. But regulations don't allow that, much like they don't allow you to do your own high-voltage, high-current electricity. And frown upon you breaking load-bearing walls in a housing complex to have a more open kitchen. There is a line where "let me do what I want" becomes anarchy.

Now bringing DRM into this, misses the point. There is telemetry in these apps. But there is no piracy or copyright infringement to be had. The bank doesn't fear you giving yourself a million dollars by changing your balance in memory. It's all about responsibility in case something goes south. They would love to shift it all onto you, but they're not allowed to do that. Attestation was never about protecting you, it's about protecting them from being blamed.

There is a bunch of parties making guarantees and complying with rulesets. Domino-ing all of them would make you extremely vulnerable. Which is why I opted for "tamper-proof containers running in a unproven host", rather than signing an unlimited waiver.

path: 0 17518581 17526565 17534158, hotness: undefined, score: 3, children: 1
Nicro 3 points a year ago

LeOS isn't very popular, because it's a passion-project by one guy, with little marketing. Said guy is a somewhat opinionated Woodstock-era hippie, hence the colorful icons (they can be easily swapped via an icon-pack of your choice.) Though he is a friendly person.

To my knowledge it's the only Treble-option with a hard stance on de-googling. Specifically made as an answer to some policies in eOS. There is an interview with him floating about, if you want the backstory. https://nixfaq.org/...

path: 0 17352758 17354029 17357806, hotness: undefined, score: 3, children: 2

thanks for using Leebra!

go to feed...