• 14 Posts
  • 408 Comments
Joined 2Y ago
cake
Cake day: Mar 21, 2022

help-circle
rss

This. Androids permission toggles combine multiple ones. GrapheneOS actually adds more of these toggles, as some things like Network and various sensor permissions are always on (wtf Android). But even those are combined toggles.

You can also display more permissions on the permission page, top right.


Nice, own Gitlab instance with locked registration (?) so I cannot report this bug:



Social= contact with people you want to contact

Privacy= the stuff you share is not sent to random people but only who you want to

It uses the Matrix protocol which is kind of a red flag because of performance, but its encrypted.


Yes. It is only needed for /storage/emulated/0/Android/obb which is legacy afaik and GrapheneOS has a specific toggle just for this.




Nice! You should use an override.js to avoid missing out on updates.

Also have a look at my messy project arkenfox softening


Btw.

  • on GrapheneOS you do not need the legacy “manage all files” permission. GrapheneOS has a specific “obb” permission for installing apps, thats it and even that is legacy
  • use the session installer, nothing else.


Okay fair. They have shady sponsors.


If the link preview above displays an ad, ignore it. [Article](https://thehackernews.com/2017/09/crackas-with-attitude-hackers.html)
fedilink


Or just using their official release APK over obtainium



Banking is a hit or miss, GrapheneOS should pass all security checks and more, but none of them is Google certified and apps start to request that, which sucks



This was about screenshots, sorry. No idea, dont think you can change that without a different android OS


GrapheneOS Camera is very nice. May only work on Pixels, but on stock android (which is an insane tracking platform you should ditch) too.

Https://github.com/grapheneos/apps/releases/latest

Download their appstore, there you get the camera app.



Wow this is great!

if you are using your own index, I think you could use a more economical approach to fight the spam bullshit of the modern web.

  • instead of using badness enumeration, crawling everything and filtering malware, use an opt-in principle
  • have a community method of gathering new trusted websites
  • use websites internal search functions to get more results
  • use categories to split up the websites, reinventing what people should find: general, news, navigation, science, politics, IT, technology (not code), art, music, philosohy, …
  • have an app or submission website where users can submit new websites, and some form of community control over it (kinda censorship but in a good way)

This could fix the web as it currently is, by rethinking what should be found, pushed etc. Rating websites by quality could also be helpful.

Also if you support payments in crypto or cash, there should be no problem to make it paid.


You need to contact them, if they connect to known to-be-blocked sites to get their IPs.

Googerteller does this:

Note: Find it ironic or not, but to query the list of all Google IPs/subnets, this needs to contact one Google domain, actually. (That request does not emit a sound, though.)

And I would ask DDG how their “tracker blocker” works and if it would also block such requests.0


Thanks, I think it is very relevant to understand how this DDG VPN “tracker blocking” works.

If it is about an app sending requests to lots of domains, this may have many reasons. For example it could check the IP addresses of all these tracking serverers to block apps from communicating with them via IP and not URLs.

This would be a reason that a trusted app connects to tracking servers to update their internal filterlist.

This “known to collect” seems to be unrelated to the actual connection, just “this service often collects data about x”.

If this is true, that is HIGHLY misleading and please update your post to explain that possibility.


You are using that Duckduckgo thing which is not a reliable source of information.

I would be interested in what a “tracking attempt” would look like.

Your VPN sees EVERYTHING you connect to, if you use HTTPS that is not a big deal but can help target stuff to your usage.

If it is tracking or just traffic passthrough is decided on their servers, which no weird Duckduckgo app can access.


Mull, but use the DivestOS repository. F-droid also builds it but too much delayed.




That DDG app is interesting, so it records inter process communication without root? How?



Really cool! How is the database stored, can it be encrypted using the masterpassword, or a different one? Can it be only loaded into RAM?

On traditional desktops like any app can read your browser data, which would be very problematic.


No it doesnt, it is a password and a secret stored on that device. A password might get stolen on the database, or entered on a fishing website, but with 2FA that would be useless.

It goes against ONE idea of 2FA, that phones are more secure (thanks Android) and your Browser might get hacked.


Thanks a lot! I selectively keep cookies for login sites, which is not a good solution.

The threat is websites escaping the browser sandbox and reading stuff. I dont know if this is really that realistic though.


This is suuuper cool! So you just need a second android device and can run the UnifiedPush on there?


No for sure thats criminal, but its possible. Rufus makes it easy with a single click to bypass it. But when not using that silly media creation tool Windows may not boot on Thinkpads etc.

Thinkpads with Windows are a joke, they are basically nonfunctional without all these lenovo drivers for anything.




Search for some addon using “desktop view” on addons.mozilla.org



GrapheneOS discuss. Their Github repo looks like they actually have the sources for everything.


No its not. They download Google Binaries which run as system apps and have privileged access.

They practice badness enumeration in some form, while their permission model (only activating what is needed) is a better approach but incomplete.

Any app that relies on Play has those libraries implemented, so they could show ads etc. on their own. But with microG they have a component with privileged system access, in contrast to sandboxed play where no component is privileged.


Just check grapheneos.org

They have only a minimal appstore preinstalled, which they use for their own apps. It is the best there is with full background updates etc. Every store could do this if they used modern libraries.

You have Vanadium preinstalled, from which you can install “F-Droid Basic” (the modern client), or Aurorastore, or accrescent, obtainium etc.

Their own solution is sandboxed google play, installed as regular user apps with way more restricted permissions and an opt-in method (only dedicated calls are allowed) in contrast to the extremely privileged microG or even “GAPPS” which can do everything (and in the place of microG having selected things removed, badness enumeration while still using proprietary Google code).

GrapheneOS is basically Android done right, play services etc. work, you can install all Google apps from the playstore, not as system apps, if you wanted to. (wallet and others are exceptions as they require a Google certified OS).




> We can also break down users by country. The largest contingent of Snowflake users are in Iran, which has been the case since the Mahsa Amini protests in 2022 1. The graph shows also a large number of users apparently from the United States, but we believe that may be partly the result of geolocation errors, and many of them are actually from Iran. After Iran, the countries with the most Snowflake users are Russia and China.
fedilink

https://donate.torproject.org/ ![](https://feddit.de/pictrs/image/9a101698-406b-47ab-94e8-a7d57925f1e5.jpeg)
fedilink

Firefox needs a 180° turn to full privacy out of the box.
Its the only thing making is a good choice, while people choose Brave, TorBrowser or Librewolf instead. Come and join the discussion. Firefox needs to have some courage. Get rid of all those fake funding by Ad companies. Block Ads and trackers by default. Actually. Dont use damn Google as that contract will run out anyways. Chrome is the Google browser. Firefox simply offering nothing more (on the outside) than it. What do you think? Do you use Firefox out of the Box? Or another browser?
fedilink

I recently saw Alex's video about XMPP and I got curious. I am using Element and Schildichat a bit, trying Element X and curious about the new Development here. It seems vibrant, they rewrite stuff in rust, the Apps are fancy and all. But I tried Conversations and it seems based too, has transparent encryption, it is damn fast, usable, supports groups and files and all. Probably doesnt use the latest fancy Android SDKs but it seems solid. I was surprised about how fast it was, as Matrix drastically varies per server. But also I found many dead communities, and in general I dont see XMPP at all, while many Projects (if not using Discord, bruh...) have a Matrix room. How secure is OMEMO in todays standards? Or OpenPGP, compared to Matrix or Signal Encryption? I heard it also has rotating keys and all. There are other things, like permission systems, chosen federation, privacy, bridge support and more, that are interesting. Are there advanced modern WebUIs for XMPP you like? I saw that it uses up waaay less resources, why is that? Really, is "simply encrypted mail" somehow worse in an important way? Similar to IRC, where I never found nice usable apps for my taste, I thought XMPP was deprecated, but that doesnt seem so? What can you tell me about XMPP, is it modern, secure, privacy friendly?
fedilink


GrapheneOS People being toxic again… and again… | The other face of “community-ran servers”
There have been very very bad experiences with Daniel Mikay, the former (?) lead dev of GrapheneOS. GrapheneOS is an awesome project. It doesnt suit everyone, as it only focuses on security, doesnt add many LineageOS features, ships no Appstore preinstalled and pretty much promotes hunting down your APKs from Git* releases, doesnt work with microG, ... But its a really valuable piece of software, extremely critical for the opensource community, as its really the only degoogled and secure Android there is. Now I am close to ditching it... again... as I am pissed off by "the community", or more these/this weird anonymous people/individual identifying as "GrapheneOS" on their self-controlled Matrix server. ## Background Not wanna cry here, but giving the scenery: I went into their room and discussed a bit. Points where pretty much: - Android is a deviation of Linux with its own Kernel and way different release numbers - it sucks being dependend on a big Corp for their Android Desktop, as there simply is on Custom ROM creating a different one - Linux is awesome, as it is so free. Android immutable model could totally work with more customizability like desktops, and still be secure. What happened? I got perma-banned for "doubling down on spreading misinformation". Prior I went into a Private chat with this "GrapheneOS" person, and asked what exactly where the points where I spreaded misinformation. They said "Android is Linux. You have no idea what you are talking about but think you do. You cant spread misinformation in our community anymore." After these messages and still no explanations, they left the private chat and blocked be from rejoining. Wow. This is what a self-run server can also look like it seems. Well, I guess I will be switching to Calyx or DivestOS soon, if I have no community to discuss in. I would be happy if some critical voices could join the server and do some constructive discussions. Right now its a forced echo chamber. PS: If that was you Daniel, please just take a pause. You did some great work but personally you act extremely toxic. This is not how to talk to people.
fedilink

Should I watch mirrored videos through Invidious or Peertube?
This is not about privacy I guess, but I am really uncertain. Lots of Youtubers also have Peertube channels. Newpipe on Android can play those too, so I always watch the Peertube "mirrors". But what is best from multiple points? Privacy, efficiency, saving data resources from nice people? There are some Invidious instances embedding "googlevideo" javascript, I think those are not proxies and I dont suck their resources that much. The same goes for Newpipe and Freetube, which watch the videos locally, unless they break, they are best. But then, Peertube on Newpipe? I guess its nice for reliability, anticensorship and "freedom". But it sucks resources from nice people, and I already have a VPN. On the other hand, is peertube better than Invidious proxy? I think I suck resources from both, maybe its better to use Peertube here, as they dont get blacklisted, so their servers just have higher usage. And points? I am curious.
fedilink

Autofill-focused password manager?
Thanks for all the comments. Currently I use KeepassXD/DX + Syncthing. I hash my password with fingerprint on Android, keep a seperate database containing that one in another place for backup. Maybe thats stupid, but I cant type on a phone. On Linux I use KWallet, store the Keepass password there, and have a shortcut fetching that password and inserting it into the Keepass wallet using KeepassXC. Works with one click too. ## Problems - all entries are either locked or unlocked - to have autofill working, the app cant be killed (Android) - also, all passwords need to be decrypted for it to work I dont see that this is the best solution. Decrypted, maybe hashed metadata possible to detect autofill fields, and then selectively unlock the needed credentials, would be better.
fedilink

A entry-based password manager?
I dont agree with many things apple does at all, and I also think their password manager has flaws like revealing usernames without authentification. It is pretty handy though, to have a file where the entries are stored unencrypted, and if the password manager detects an entry it prompts to decrypt exactly that field, maybe with a fingerprint. KeepassDX needs to run in the background and be completely unlocked to even detect apps or password fields. Do you know any existing app that can do this?
fedilink