I’m considering the switch to GrapheneOS, so I watched this interview with one of the members of the GrapheneOS team, and honestly, I feel it was a great general introduction to it and touched on common features and misconceptions.

For those who don’t know, it’s one of the most secure and private mobile operating systems out there. Some things that I took away:

  1. They touched upon MAC randomization. I researched a bit on my own about what the need for it is. Apparently, it’s standard practice to randomize MAC addresses when scanning WiFi connections. However, GrapheneOS (and Pixel firmware) are even better at this, as they make sure they don’t leak any other identifiers when doing so. They also allow you to get a new random MAC for every connection that you make (not sure whether this is very useful, as this can cause problems). On a related note, even when WiFi/Bluetooth are “off,” stock Android can still scan in the background to improve location accuracy (by matching visible networks/devices against Google’s database). So basically, even with WiFi/Bluetooth off, Google still knows where you are. In GrapheneOS, this option is off by default.

  2. They have their own reverse proxies that they use to talk to Google on your behalf when needed.

  3. Apparently, in the USA you can be compelled to provide a fingerprint or Face ID. Courts have ruled this doesn’t violate the 5th Amendment because it’s physical, not testimonial. BUT you cannot be compelled to provide a password/PIN. That’s considered testimonial evidence, protected by the 5th Amendment. GrapheneOS has a two-factor system where, after using your fingerprint, you still need to enter a PIN, so it helps with this. They also have a BFU state after reboot, which is the safest and requires you to enter your full passphrase.

    • dentacle@bookwyr.me
      link
      fedilink
      English
      arrow-up
      14
      ·
      17 hours ago

      No need to go down the conspiracy road, I just don’t want to give money to that evil company. As soon as Graphene runs on Fairphone I’m switching from e/OS.

      • Mugita Sokio@lemmy.today
        link
        fedilink
        English
        arrow-up
        4
        ·
        17 hours ago

        As far as I’m aware, they don’t have Fairphone support for reasons they already explain. Despite the baggage of the Pixel hardware, it’s the best hardware security wise, which is why the devs chose it (McCay firstly before someone else took over while that troll continued to be on the board).

        • AmbitiousProcess (they/them)@piefed.social
          link
          fedilink
          English
          arrow-up
          5
          ·
          16 hours ago

          Yeah, Fairphone doesn’t have a huge focus on security architecture, so a lot of GrapheneOS security features would not just be severely crippled, but would simply not be available at all.

    • Ludicrous0251@piefed.zip
      link
      fedilink
      English
      arrow-up
      4
      ·
      edit-2
      16 hours ago

      Pretty impressive to have an OS that’s “almost impossible to crack” with backdoored firmware.

      • Mugita Sokio@lemmy.today
        link
        fedilink
        English
        arrow-up
        2
        arrow-down
        3
        ·
        15 hours ago

        They probably must’ve known, and disabled some of the nonsense. At least, that’s how I see it.

        • Ludicrous0251@piefed.zip
          link
          fedilink
          English
          arrow-up
          5
          arrow-down
          1
          ·
          15 hours ago

          Must’ve… If only GOS was open source and the devs were incredibly outspoken about privacy, we could verify this speculation through their statements (or lack thereof). Alas…

          • IceFoxX@lemmy.world
            link
            fedilink
            arrow-up
            1
            ·
            edit-2
            3 hours ago

            You guys are still ignoring SS7… How closely do forensic experts work with authorities to get them access to SS7 at the ISP? A specially prepared message could arrive at any time for subsequent installation… The mere fact that it is an operating system for smartphones with mobile phone functionality destroys the remaining fake security.

            Who knows how all and EVERY IC is constructed… Rofl, anything could be integrated that the OS can’t recognize… Ohhh, and Canada… 5 eyes… Canada is right up there when it comes to spying…

            • Ludicrous0251@piefed.zip
              link
              fedilink
              English
              arrow-up
              2
              arrow-down
              3
              ·
              11 hours ago

              Oh sure, and next you’re gonna tell me the devs are outspoken about privacy??

              I guess since you’ve found the source, can you find the patch titled “Google Firmware Secret Backdoor Patch”?