• 2 Posts
  • 9 Comments
Joined 7M ago
cake
Cake day: Dec 08, 2024

help-circle
rss
Is F-droid insecure?
In the GrapheneOS forum, I encountered a claim that F-droid is insecure (and not good at privacy as well). These links (and more) were given as an evidence: - https://privsec.dev/posts/android/f-droid-security-issues/ - https://xcancel.com/GrapheneOS/status/1883895255142932816#m - https://github.com/obfusk/fdroid-fakesigner-poc While there are some attitude against FOSS app, I think the arguments are generally sound and in good-faith. Which makes me confused, as I've been hearing good words about F-droid in lemmyverse. I am not good at assessing arguments, so I want to ask you guys for more aspects and information. Also, if not F-droid, what should I use? Is Aurora store, a frontend of play store, not fine to use as well?
fedilink

Yeah, the problem is with the one banking app I frequent.


Oh my, that sounds difficult. What does “permanently locked bootloader” mean? I was just going to buy at local phone shop…

EDIT: Turns out, local phone shop does not sell Google Pixel. Gotta buy from official google store…


What phone should I buy for privacy?
My current phone is 7 years old, does not support recent android versions, and battery life is becoming atrocious. This feels like right time to change my phone. Currently, I know of & am considering 3 options: - Google Pixel - iPhone - Samsung Galaxy I heard that Pixel is the best choice for privacy, despite it being Google^TM. Should I go with it, and install Graphene OS or similar options? The very fact that the name "Google" is attached makes me nervous. Also, I don't think I can trust android, so I would have to install Graphene OS or the like. In the case, app support would be lacking, though. I am considering iPhone as well, since it has "reputation" of being secure. Of course, Apple can access my data, but that might be a good enough compromise? Honestly, I don't know. It's the best supported option as well - lots of apps support iPhone. Galaxy is just the one that I am the most familiar with (my current one is Galaxy S8). I don't trust it, though. Do they even make good hardware nowadays? EDIT: Turns out, Pixel phones are poorly supported by local telecomm companies. It is relatively cheap though. Still worth it? EDIT2: I heard that data & message is fine, but the call quality is impacted by lack of VoLTE compatibility.
fedilink

I don’t think this community is a stronghold of linux, as you can see in the comments. We need to start from somewhere.



IIRC, for this kind of guarantee, you need a CCA(Chosen-ciphertext attack)-security. I dunno if this scheme satisfies such a security.



At least it’s not going to be the overhyped LLM doing the analysis, it seems, considering the input is a photo data.


It might still be possible to compare ciphertexts and extract information from there, right? Welp I am not sure if the whole scheme is secure against related attacks.


I have an iPad, now I am scared… Should I do something about this?