-
greenmoon[m]
Lmao encrophone have been pwned
-
fluoridatedsheep
bad powned
-
greenmoon[m]
Oops wrong chat
-
greenmoon[m]
Why I can't delete message
-
DannyWorkOrderP4
Because you touch yourself at night
-
greenmoon[m]
Damn
-
DannyWorkOrderP4
Seems to be working fine on this end!
-
DannyWorkOrderP4
;D
-
greenmoon[m]
Strange, the option is not avaible anymore here
-
glct[m]
Hello
-
BeingFrey[m]
Hello fellow GrapheneOS folks! 🤩
-
BeingFrey[m]
Officially I am now part of the GOS Club!
-
BeingFrey[m]
😆
-
BeingFrey[m]
Pixel 3a successfully converted!
-
BeingFrey[m]
Thanks!
-
nickcalyx[m]
🥳
-
BeingFrey[m]
LOL
-
sixBit[m]
Are we able to turn off the haptic feedback when pressing the keyboard? I'm not able to find it in the settings...
-
brenneke[m]
<animalchin[m] "Does anyone know what the System"> But that is not on GrapheneOS right? I used to always disable Presence.
-
greenmoon[m]
Omg no
-
greenmoon[m]
In that vice article about endrophone there is literally an ads for Omerta phones that ship with grapheneOs 😹
-
outsider[m]1
<greenmoon[m] "In that vice article about endro"> yeah. omerta is trash btw
-
-
outsider[m]1
"encrypted sims" and overpriced pixels. $750 USD for a pixel3a lol. "Stealth" cases for $80. like what the fuck. its a phone case
-
brenneke[m]
<neonfuz2 "I guess maybe things would go wr"> Not sure what your point is or hat you are asking but if you need a good calendar app, aCalendar.
-
outsider[m]1
<brenneke[m] "Not sure what your point is or h"> simple calendar isnt bad
-
ruddo[m]
<outsider[m]1 ""encrypted sims" and overpriced "> I dont think they were using Pixels. Either way, trust in proprietary software really fucked them up. Looks like they all got malware targeted to their phones — is this doable via the baseband?
-
greenmoon[m]
I known it from the beginning that this site was targeting criminals. Also their site is full of trackers lol
-
outsider[m]1
<ruddo[m] "I dont think they were using Pix"> encro wasnt on pixels. was roasting omerta
-
brenneke[m]
<outsider[m]1 "simple calendar isnt bad"> Don't doubt it, Simple apps are good but they are simple.
-
outsider[m]1
<outsider[m]1 "encro wasnt on pixels. was roast"> from what i understand, they got popped from shitty infrastructure and terrible encryption implementation
-
outsider[m]1
had they been less centralized, prob wouldve only had minor casualties
-
ruddo[m]
I would like to know how they got compromised.
-
brenneke[m]
<greenmoon[m] "In that vice article about endro"> Personally find it difficult to imagine that there will ever be trust in a system like that again.
-
ruddo[m]
In any case it's pretty clear that a phone with secure messaging and a phone that plays media or surfs the web are 100% incompatible.
-
greenmoon[m]
A malware have been pushed to the ROM according the article
-
greenmoon[m]
Do we need a malware pushed to our privacy ROM when they will try to take down omerta?? Lol
-
greenmoon[m]
Hopefully they will target only the service used by their phone
-
greenmoon[m]
* Hopefully they will target only the services used by their phones
-
ruddo[m]
<greenmoon[m] "A malware have been pushed to th"> I am skeptical that the article got that detail right.
-
ruddo[m]
It's most likely an exploit that deployed a persistent RAT.
-
ruddo[m]
That would not go in the ROM.
-
-
greenmoon[m]
Hmm yea
-
greenmoon[m]
But they sent it to all users of the rom
-
ruddo[m]
Who? The phone manufacturer is the only group who can pull that off.
-
greenmoon[m]
And it used the update system according another article, their update system was maybe not secured
-
greenmoon[m]
I don't even know how its possible if updates are signed
-
greenmoon[m]
I'm stopping the offtopic
-
-
ruddo[m]
Epic, epic incompetence on the part of those encromorons.
-
renor
Does GOS have problems with funding? There's someone on reddit saying so
-
cyredanthem[m]1
renor: in a word no
-
cyredanthem[m]1
Contributions are the goal
-
renor
Yeah.. I know..., Daniel always says so, but I thought that maybe there was something I missed lately
-
-
greenmoon[m]
<ruddo[m] "Who? The phone manufacturer is "> It was user apps updates I guess, not phone updates.
-
alicebobandeve[m
Due to the above message being a copy/paste from Joplin, mentions did not work so just adding them here strcat renlord anupritaisno1 , also madaidan. in case you know something about this.
-
cyredanthem[m]1
alicebobandeve: GrapheneOS is all open source even all the server stuff you need
-
cyredanthem[m]1
You could host it all yourself to minimize trust
-
cyredanthem[m]1
Daniel has proven himself with the whole Copperhead situation (Copperhead user here)
-
cyredanthem[m]1
This is a very unique situation and I trust this project in spite of me not being very trusting
-
alicebobandeve[m
cyredanthem: copperhead user as well. That's not the question though, not everyone is capable of building and that includes journalists.
-
cyredanthem[m]1
Daniel also thoroughly checks all contributions himself
-
cyredanthem[m]1
Renlord and anu couldn't backdoor it if they wanted too(they most certainly don't)
-
alicebobandeve[m
Again not relevantcyredanthem please let the answers come from the devs themselves
-
cyredanthem[m]1
You are absolutely missing the point. There's no absolute trust you can have in anything. There's no guarantees in this world
-
cyredanthem[m]1
Trust is subjective
-
cyredanthem[m]1
GrapheneOS does the best they can by letting you build and host everything yourself and by having one person manage the contributions and offline building
-
alicebobandeve[m
cyredanthem: it's not about me missing the point lol, it's other users which include users who cannot build it themselves.
-
cyredanthem[m]1
Less points of failure
-
alicebobandeve[m
Please wait for devs to respond cyredanthem thanks
-
cyredanthem[m]1
<cyredanthem[m]1 "Less points of failure"> alicebobandeve: you should clarify what you are looking for since you're not making any sense
-
alicebobandeve[m
cyredanthem: I've mentioned everything needed for an answer so unless Daniel needs further clarification, I'll provide it, until then, let's not spam this discussion and let the devs respond.
-
cyredanthem[m]1
A lot of the things you brought up don't make sense or wouldn't practically effect trust.
-
alicebobandeve[m
<cyredanthem[m]1 "GrapheneOS does the best they ca"> Also, this is known as SPOF if you look at it practically. So let's hold up and let Daniel respond. If I'm wrong or if the question is not relevant, I'll be happy to admit it and face the brunt for it from strcat when he responds.
-
cyredanthem[m]1
You probably should think through and explain your questions better. I don't think many of them make sense in a practical trust model for a community project. What do I know
-
alicebobandeve[m
cyredanthem: I hate it when people argue with others confidently but end their sentence with what do I know, if you don't know, could you please just let someone who knows respond?
-
alicebobandeve[m
Patience
-
cyredanthem[m]1
You're dimissing my questions and concerns about your question. My apologies for the sarcasm 😂
-
cyredanthem[m]1
Welcome
-
alicebobandeve[m
cyredanthem: you are still missing the point, if I had to ask the community, I would have framed my question that way, I'm posing the questions to the devs responsible for the project. It's not a debate.
-
cyredanthem[m]1
All I'm asking you is to think through your question more
-
alicebobandeve[m
cyredanthem: thanks for the suggestion but what do you know right? Patience.
-
cyredanthem[m]1
I'm saying you should put more effort into your question and the community can help you with that
-
cyredanthem[m]1
That's how I see it anyway
-
TheJollyRoger
alicebobandeve[m: this is bikeshedding. cyredanthem[m]1's already said it: the code is open, the builds are reproducible, Daniel signs the builds and inspects them and has actually /fought back/ in the face of legal threats.
-
mrxx_0[m]
Hey what happened, did I get removed from the channel ?
-
TheJollyRoger
Hi mrxx_0[m], welcome back. Were you removed from the channel? Probably yes, but likely not by a moderator; it's far more likely that what happened was that the bridge between Matrix and Freenode hiccuped and kicked you off.
-
TheJollyRoger
This occasionally happens from time to time.
-
TheJollyRoger
When it does, just rejoin the channel and carry on.
-
hitchhooker[m]
ah so Pixel 3A are getting out of the market too :/
-
JTL
Tis a shame
-
TheJollyRoger
Too soon :(
-
anupritaisno1[m]
<renor "Does GOS have problems with fund"> Yes we need funding for our legal issues
-
anupritaisno1[m]
<renor "Yeah.. I know..., Daniel always "> Funding will not help development because it will be used to fight the legal issues created by James. Contributions are needed for helping in development
-
-
strcat[m]
most people are probably a lot worse off building it themselves and securing their own build environment + signing keys
-
anupritaisno1[m]
Even if they follow the instructions on the site?
-
anupritaisno1[m]
If that's his threat model though it's the only option he's got
-
strcat[m]
alicebobandeve: it's open source and the builds are reproducible - I'm not sure what more there could be with the size / resources available
-
strcat[m]
alicebobandeve: you say there's a single of failure but would you rather have multiple points of failure that are equally damaging
-
strcat[m]
multiple people with access to the official build infrastructure and signing keys?
-
strcat[m]
that's not an improvement
-
strcat[m]
so I'm not sure what you expect
-
strcat[m]
if people want to make their own builds and use a decentralized trust model where 3/5 signatures are required for update packages or something like that they're welcome to but I'm not planning on added more trusted parties / blockers to development
-
JTL
I think given the current state of things, is a fair response
-
strcat[m]
make a fork with that model if you want - good luck finding trustworthy, productive people with the same goals who will stay interested long-term
-
strcat[m]
and handle replacement of those people over time somehow
-
strcat[m]
I can't think of any OS that works that way
-
strcat[m]
it's open source so people are free to do that if that's what they want
-
strcat[m]
I don't think it's going to turn out well
-
hypokeimenon[m]
what about the dead man's switch?
-
strcat[m]
?
-
strcat[m]
not sure what you mean
-
alicebobandeve[m
Hi
-
alicebobandeve[m
Thanks for the replies
-
alicebobandeve[m
Sorry my replies might be slow, caught up with something
-
alicebobandeve[m
I'm actually not talking about myself, my threat model doesn't require it.
-
strcat[m]
okay so take snowden as an example then
-
strcat[m]
who are 4 other highly trustworthy people in countries without oppressive / coercive laws
-
strcat[m]
involved with the project
-
strcat[m]
who are highly technical and able to secure signing keys well
-
strcat[m]
and also some more people since people might need to be replaced
-
alicebobandeve[m
A team in my company has over 200 people and they want to switch as mentioned earlier, your suggestion is we should build it ourselves? They completed testing today and their concern is basically SPOF and risk mitigation.
-
alicebobandeve[m
Also, a few journalists from my country want to use it, people I know.
-
alicebobandeve[m
All based on my suggestions.
-
JTL
Should read up DNSSEC key ceremonies if you want to bikeshed multiple signatures for OS builds, etc.
-
alicebobandeve[m
So obviously, I have no intention of undermining GOS.
-
strcat[m]
no my suggestion isn't to build it yourself
-
alicebobandeve[m
I understand your point strcat
-
strcat[m]
my suggestion is to realize that most open source software projects including core infrastructure are developed by 1 person
-
strcat[m]
with a few contributors at most
-
strcat[m]
and little funding / support
-
alicebobandeve[m
Agreed, I have to get corporate to agree and the guy in charge is smart but very paranoid.
-
strcat[m]
I can't name a single core infra android/linux project that uses N-of-M signing key releases
-
alicebobandeve[m
Absolutely
-
alicebobandeve[m
Interesting point
-
strcat[m]
and I don't actually want to do it because I don't want to trust other people
-
strcat[m]
if people want to do that they should make their own builds
-
alicebobandeve[m
Fair
-
alicebobandeve[m
I was on a call an hr back trying to explain to them this exact thing so I don't think otherwise either but I was wondering if there's already something in place to mitigate SPOF so that I could share it with them.
-
alicebobandeve[m
But your points are valid and I agree.
-
strcat[m]
open source + reproducible builds for as much as that accomplishes
-
alicebobandeve[m
But asking questions such as the ones I posted are not obvious or indulge in bikeshedding. They were posed for the sake of clarity.
-
strcat[m]
not sure what else can be expected
-
alicebobandeve[m
<strcat[m] "open source + reproducible build"> Will move it forward
-
alicebobandeve[m
And let them know
-
strcat[m]
a project like a typical linux distribution is many point failure - many trusted people
-
strcat[m]
1 person can do great harm
-
alicebobandeve[m
Thanks for your replies.
-
strcat[m]
and hundreds are trusted
-
strcat[m]
that's not a better system
-
alicebobandeve[m
Yeo
-
joshman[m]
Sorry. Prolly answered 100 times. Nothing found in logs. How to screenshot Vanadium in incognito mode?
-
alicebobandeve[m
Yep*
-
dazinism
Guess if part the worry is Daniel dying. Then theres seedvault backups that could be used to migrate to another OS that includes seedvault
-
alicebobandeve[m
<dazinism "Guess if part the worry is Danie"> Umm, no lol.
-
alicebobandeve[m
Dead man's switch should not be taken literally lol
-
alicebobandeve[m
But yes, I'm aware.
-
dazinism
josh.man: the point is you can't
-
alicebobandeve[m
Even I was not of the opinion that they should build it themselves strcat
-
alicebobandeve[m
So I'll try and get it through their thick heads
-
alicebobandeve[m
Thanks strcat and anupritaisno1
-
hitchhooker[m]
so if organization builds their own build with multisig, they also need to be deliver the updates too?
-
TheJollyRoger
Of course they have to; the phone will only accept updates from those keys once they've been provisioned.
-
alicebobandeve[m
It would involve cherry-picks from upstream but yes they are responsible for it
-
TheJollyRoger
So if they want to hold their own keys, they take matters into their own hands. This includes running their own update server.
-
hitchhooker[m]
is update infra open source as well?
-
alicebobandeve[m
TheJollyRoger: exactly
-
dazinism
hitchhooker: yeah
-
TheJollyRoger
hitchhooker[m]: yes.
-
alicebobandeve[m
Everything is open source hitchhooker
-
alicebobandeve[m
Coral has kernel pre-builts correct? anupritaisno1
-
dazinism
Would also need to build auditor & attestation server if they wanted that, or get Daniel to add the sigs for their OS builds to his Auditor
-
alicebobandeve[m
Yes
-
alicebobandeve[m
I'm aware
-
joshman[m]
-
glct[m]
Hello all I joined barely 10 hours ago and mostly observing the good conversations so far.
-
glct[m]
Noticed that this chat isn't encrypted, I mean it doesn't look like sensitive chat and with the channel essentially open there aren't any secrets shared here openly but if we have the encryption feature, why not use it?
-
glct[m]
I'm aware there are probably good reasons as to why it isn't been enabled but thought I'd put this out there. I am new to Matrix so I'm learning on two fronts, getting round this new messenger and GOS :-)
-
hitchhooker[m]
its public discourse and logs are intentionally shared online as well
-
glct[m]
<hitchhooker[m] "its public discourse and logs ar"> This makes sense, thanks.
-
hitchhooker[m]
freenode.logbot.info/grapheneos/20200704 searching here first is quite useful before committing question
-
cyredanthem[m]1
> The Titan M is closed source right?
-
cyredanthem[m]1
Yes, it's a closed source component the OS doesn't have direct control over.
-
cyredanthem[m]1
(y)
-
madaidan[m]
There are plans to open source it but they've been stalled for eons
-
geritol[m]
Thanks
-
dazinism
I added some stuff about calendar and contacts to
hub.libranet.de/wiki/graphene-os/wiki/Apps
-
hitchhooker[m]
opentitan looks promising tho
-
FinnwwwBackFromt
Can Graphene be like Gentoo?
-
neonfuz2
So I put music on my phone and its not showing up on my vanilla music app
-
neonfuz2
I tried the SD scanner app too
-
neonfuz2
¡Finnwww Back From the Dead! Like gentoo in what ways
-
FinnwwwBackFromt
<neonfuz2 "¡Finnwww Back From the Dead! Lik"> Have a package manager that helps you compile everything yourself
-
neonfuz2
No not really, graphene is just a security focused fork of AOSP. It doesn't add any ability to compile apps on the device
-
FinnwwwBackFromt
Can I compile my own kernel?
-
neonfuz2
Yes but part of the security of graphene is checking system integrity at boot, adding your own kernel would make this fail and so this is against the point of graphene
-
neonfuz2
though
-
FinnwwwBackFromt
Ah
-
neonfuz2
If you want you can compile all of graphene youeself and sign it yourself and make your own update server
-
q22[m]
neonfuz do your audio files show up in the file manager?
-
neonfuz2
Graphene is not meant for maximized custom ability its meant for maximized security
-
neonfuz2
Customizability*
-
neonfuz2
q22 yes
-
neonfuz2
They're mostly flac and opus files if that matters
-
neonfuz2
Maybe all flax and opus
-
neonfuz2
¡Finnwww Back From the Dead! Just wondering, why do you want a custom kernel, just for fun or some real reason?
-
FinnwwwBackFromt
<neonfuz2 "¡Finnwww Back From the Dead! Jus"> For fun and smaller size
-
FinnwwwBackFromt
And customization
-
neonfuz2
There's nothing stopping you from messing around with graphene and building your own kernel etc if you don't care about the security a ton
-
nickcalyx[m]
The source is all there, and the build scripts
-
nickcalyx[m]
I think you need 100GB of free disk space
-
nickcalyx[m]
To build the whole OS
-
nickcalyx[m]
A lot less if you just want to build the kernel
-
anupritaisno1[m]
nickcalyx: 75. Take it or leave it
-
anupritaisno1[m]
The answer is btrfs with zstd:6
-
anupritaisno1[m]
You can even fit it in 40gb
-
anupritaisno1[m]
If you want
-
anupritaisno1[m]
rm -rf .repo after syncing
-
anupritaisno1[m]
If you want to shrink it even further btrfs deduplicator can shrink it a lot
-
anupritaisno1[m]
Now f2fs,
-
anupritaisno1[m]
Haven't tried what f2fs has
-
nickcalyx[m]
Zfs has dedup too
-
hitchhooker[m]
going through grapheneos.org nginx file to learn more securely setting up one and it seems like http and www.grapheneos.org have been rooted to root /var/empty; . does this help against some attack vector?
-
anupritaisno1[m]
I think you can use /dev/null too
-
anupritaisno1[m]
It's not an attack vector protection
-
anupritaisno1[m]
It just means there's no default site
-
hitchhooker[m]
and such folder does not even have to exist?
-
anupritaisno1[m]
You can use /nonexistent
-
hitchhooker[m]
alright
-
anupritaisno1[m]
It's the folder for the nobody user
-
anupritaisno1[m]
hitchhooker: read nginx documentation
-
-
anupritaisno1[m]
Or try this
-
anupritaisno1[m]
location / {
-
anupritaisno1[m]
return 444;
-
anupritaisno1[m]
}
-
anupritaisno1[m]
In nginx 444 iirc is a special case return code.
-
anupritaisno1[m]
It doesn't actually return anything to the browser. It just closes the connection
-
anupritaisno1[m]
Sorry 403 not 503
-
neonfuz2
<nickcalyx[m] "Zfs has dedup too"> Zfs dedupe is apparently really expensive
-
neonfuz2
I use zfs with lza compression but that's it
-
ruddo[m]
<neonfuz2 "Zfs dedupe is apparently really "> Offtopic.
-
anupritaisno1[m]
There's no lza compression
-
anupritaisno1[m]
You either mean lzo or lzma
-
-
georgeaux[m]
Hey. Is everything okay in case of my install?
-
sheruleeya[m]
Try running the auditor again and see for yourself.
-
sheruleeya[m]
(Also, would be preferred not to use internet before using auditor after flash)
-
sheruleeya[m]
Also, scrub that metadata before sending pics here
-
georgeaux[m]
Okay. It was my first try with the os. After the next release I will do so. Thank you.
-
sheruleeya[m]
Well, yeah, you can definitely try running auditor again, like right now and see if it forms a strong pairing
-
sheruleeya[m]
* Well, yeah, you can definitely try running auditor again, like right now and see if it forms a strong pairing.
-
sheruleeya[m]
Also a good practice to do it after every release, which could be nearby.
-
georgeaux[m]
This time its green, so I guess I'm fine until the next release. Sounds cool, waiting on it.
-
demonMachina
missed this part of this conversation, but as long as you're not authenticating with a new device, or "clear Auditee/or pairings", in the future it should be green
-
georgeaux[m]
<sheruleeya[m] "Also, scrub that metadata before"> You mean the pictures metadata? Is there a good practise/ app in fdroid? Or you are talking about the identity and boot hash?
-
cx2[m]
Scrambled Exif
-
sheruleeya[m]
The pic metadata, which can be sadly only scrubbed properly on exifcleaner or mat2 on desktop OS
-
cx2[m]
Scrambled Exif does a pretty solid job.... Mat2 barrows code form scrambled Exif
-
sheruleeya[m]
will try it
-
georgeaux[m]
<demonMachina "missed this part of this convers"> So its a better to always clean the app data on the auditor device right?
-
demonMachina
georgeaux: That's not what those options are there fo
-
demonMachina
*for
-
demonMachina
If you would like the nice green screen each time, so that there is no mistake, conduct remote attestation, set an interval, and let it run.
-
sheruleeya[m]
Just tested it and it doesnt work.
-
sheruleeya[m]
The metadata is still there
-
neonfuz2
<ruddo[m] "Offtopic."> Its on topic because people were talking about how much space compiling graphene takes on various filesystem configurations
-
cx2[m]
<sheruleeya[m] "The metadata is still there "> Scrambled Exif?
-
sheruleeya[m]
Yeah, sadly doesn't work.
-
sheruleeya[m]
Won't talk too much about it.
-
neonfuz2
<anupritaisno1[m] "There's no lza compression"> Oh yeah I guess I meant lz4, whatever that is
-
sheruleeya[m]
Not sure if this will ever be a viable option, but has anybody tried building Vanadium on 4gb ram?
-
demonMachina
<sheruleeya[m] > I havent had any issues with it. Have tested it a handful of times.
-
demonMachina
re: scramble topic
-
sheruleeya[m]
Sharing it on AOSP gallery, and the metadata wont get off
-
sheruleeya[m]
<demonMachina "<sheruleeya[m] > I havent had an"> What gallery app do you use btw
-
demonMachina
scrambled exif is meant to be used when sending a photo.
-
georgeaux[m]
Worked for me too with stock GrapheneOS gallery. Removed maker,model,data,etc.
-
sheruleeya[m]
I knew that though, but maybe something is wrong with what I got from fdroid
-
demonMachina
quick second.
-
sheruleeya[m]
Nvm, restart made it work
-
sheruleeya[m]
Any side effects of frequently restarting your phone though, besides the button possibly sinking? Just really liking to utilize the verified boot and encryption before first unlcok
-
sheruleeya[m]
* Any side effects of frequently restarting your phone though, besides the button possibly sinking? Just really liking to utilize the verified boot and encryption before first unlock
-
sheruleeya[m]
(I meant hardware-wise)
-
demonMachina
glad you got it working.
-
demonMachina
As far as power-cycling the phone, I have no idea. I'm sure theres a metric out there somehwere, but I have never seen one. I can't really see a scenario it would be an issue though.
-
demonMachina
maybe limit it to times when it seems sane? e.g. after using public wifi or the like.
-
sheruleeya[m]
* Any side effects of frequently restarting your phone though, besides the button possibly sinking? Just really liking to utilize the verified boot and encryption before first unlock
-
sheruleeya[m]
(I meant hardware-wise, like battery, etc)
-
cyborgninjaneer[
If you're worried about an After-First-Unlock exploit, use lockdown mode.
-
cyborgninjaneer[
It's supposed to put the phone back in a before-first-unlock state
-
TheJollyRoger
Started CTS on Vendor OS, 4th July 19:31 UTC
-
TheJollyRoger
(Flame)
-
hiya
Does 8G of RAM on Android consume more battery vs 6 or 4GB? Is it noticeable?
-
anupritaisno1[m]
hiya: no
-
hiya
In fact it can save battery, correct? Since less swapping or no swap?
-
hiya
Less work for CPU to compress/decompress
-
anupritaisno1[m]
No
-
rover1[m]
is pop sound when changing from vibrate to ringtone supposed to happen?
-
cyborgninjaneer[
Probably
-
interceptingfist
What search engine does grapheme recommend
-
nickcalyx[m]
Bing
-
nickcalyx[m]
🤣
-
glct[m]
Lol what are you asking, the community or the OS?
-
Mobius[m]
bing is best indeed
-
cdesai
from what I've read bing is pretty good for image search
-
cdesai
>_>