Avatar
Gareth Kitchen
4ccb4096d76c3a22767d68bd680ddccfde4943f7c6136f5e8f6deb5f2bb871da

The fixes come after Amnesty alerted Google, following the analysis of a Serbian student protester's phone. Ekk!

https://techcrunch.com/2025/02/28/researchers-uncover-unknown-android-flaws-used-to-hack-into-a-students-phone/

If you take 'Don't look up', add a dose of sci-fi, then put it on steroids, you'll end up with 2073. tbh, it's dystopian and disturbing. British made 2024.

https://2073.film/

Not sure about giving UK Police the power to search homes without a search warrant.

Which focus group dreamt that one up?

#ukpol

I did have huge respect for Greenwald, post Snowden, the Intercept and all, but I thought he seemed to go off the rails after that.

Just a heads up. Your fix worked with Lloyds Bank too. But the app itself doesn't work great, probably because I don't run gapps/playstore bits. Thanks for your efforts on this. :)

I just tapped the heart to like your post, something the ux doesn't permit in amethyst.

Replying to Avatar GrapheneOS

nostr:nprofile1qy2hwumn8ghj7un9d3shjtnddaehgu3wwp6kyqpqfn95p9khdsazyanadz7ksrwuel0yjslhccfk7h50dh4472acw8dqpkmmk6 nostr:nprofile1qy2hwumn8ghj7un9d3shjtnddaehgu3wwp6kyqpq9dxzvzpewcce5zkqtupqqypju4y2p5je6k7zq6wzme7gnkv0ja4smmrhum It may work again after our recent changes to work around Revolut banning GrapheneOS. They may be using the same SDK as Revolut to ban using GrapheneOS. Neither appears to be enforcing a Play Integrity API device or strong integrity level yet, only their own very weak checks which we can easily bypass if we work on it. The issue is that there are a huge number of apps and they're creating work for us doing this.

Bah, you got my hopes up then! No dice. I realise this isn't in you, so no probs.

So why have no contemporaneous videos survived huh? That's the context we need.

Replying to Avatar GrapheneOS

nostr:nprofile1qy2hwumn8ghj7un9d3shjtnddaehgu3wwp6kyqpq9dxzvzpewcce5zkqtupqqypju4y2p5je6k7zq6wzme7gnkv0ja4smmrhum You can see Revolut shows an error about custom firmware not been supported where they claim they are "serious about keeping your data secure". This is them using an SDK to specifically detect GrapheneOS and then banning it. It is not related to the Play Integrity API at the moment. It's a client side check within the app. Play Integrity API is something their service can enforce based on the app triggering it and their service obtaining the result from Google's service.

This is a pain. Lloyds Bank (UK) app used to work well until a year or so ago when they did similar. :(

Are you aware of any info, anywhere, on which banking apps are happy to run on custom firmware?

Replying to Avatar GrapheneOS

nostr:nprofile1qy2hwumn8ghj7un9d3shjtnddaehgu3wwp6kyqpq5tvv6c5rdcj2z03r5sw5dzl36qx2kkpqe47yscckve5a2h0psstsa9skc4 nostr:nprofile1qy2hwumn8ghj7un9d3shjtnddaehgu3wwp6kyqpqg8pqukfm966n6h9dkashxtuuudztqgpwtgwhyy6mvw6yx8xj7vhqlkkckx

Fairphone 4 used publicly available private keys for signing the firmware and OS. Lack of working verified boot and attestation is far from the most serious security drawback but helpful for understanding how little goes into securing most Android devices.

Lots of people regularly ask them to implement the security requirements we list so GrapheneOS could support it and they explicitly said they don't even plan to add a basic secure element for working encryption for most users.

I'm pretty sure that I could relock the bootloader on my FP3 with LineageOS.

Please don't chastise me for saying that. ;) I have seen the light now! :)

Replying to Avatar Tinker ☀️

With all the BS of Apple doing their AI spying (amongst other issues), it's that time of year where I once again look for a "third party" phone to migrate to as a daily driver.

I've followed lots of Linux phones (running Ubuntu Touch, KDE Plasma Mobile, postmarketOS and others), feature phones running KaiOS, and others.

Heck I was even building my own phone on an RPi years ago (https://web.archive.org/web/20210725154717/https://www.tinker.sh/kde-plamo-rpi/ ) and have been following the PinePhone project for a very long time.

My current research is pointing towards a Fairphone 4 running e/OS (degooglefied android). I live in the US, so this is as close to the Fairphone as I can get currently: https://murena.com/america/shop/smartphones/brand-new/murena-fairphone-4/

Really I just need a phone that runs Signal and can run some sort of GPS app. Everything else I can do via a web browser.

I hate Apple/iOS phones. The only thing I hate more than Apple phones are Google/Android phones.

#phone #android #ios #apple #google #fairphone #privacy #linuxphones

I ran a FP4 with vanilla LineageOS. Rock solid. However I have now upgraded to a Pixel 8a with nostr:npub1235tem4hfn34edqh8hxfja9amty73998f0eagnuu4zm423s9e8ksdg0ht5. It is also rock solid, but much better generally in terms of security.

My only gripe is that the hardware profits Google who I detest. I purchased the phone secondhand to mitigate that.