-
faxing[m]
<jneplokh "As stated, use the Network permi"> I've been doing both, should I not be doing it that way?
-
jneplokh
I don't see why you should use both
-
jneplokh
-
faxing[m]
I was doing it that way so I could use NetGuard to block system things/apps and NetGuard plus system permissions to block normal apps for double insurance that they were being blocked so to speak
-
faxing[m]
If I shouldn't be doing it that way, like if it's an actual bad thing that I am or something, then I'd change it
-
aeonsolution[m]
-
aeonsolution[m]
entry1: they all are, but they need to be unlocked and that is beyond the scope of the project. the only model you should avoid, is buying an unlocked Verizon Pixel 3a
-
aeonsolution[m]
-
aeonsolution[m]
here is the info on Verizon that you can browser in the logs <
freenode.logbot.info/?ch=grapheneos&q=verizon>
-
aeonsolution[m]
the fullproof way to avoid that issue is getting the phone from google or retailer, by from the secondary market is a hit or miss
-
aeonsolution[m]
* the fullproof way to avoid that issue is getting the phone from google or retailer, buying from the secondary market is a hit or miss
-
aeonsolution[m]
carriers usually have a lot of restrictions on unlocking devices too
-
aeonsolution[m]
i know everyone doesn't have the luxury of buying a new device
-
aeonsolution[m]
but thats unforunately what it comes down too
-
aeonsolution[m]
you're welcome, happy hunting
-
M0xC0ncord[m]
<entry1[m] "Sorry to bump again. Would Googl"> You can do that yourself on the repair page.
-
aeonsolution[m]
0xC0ncord: the repair page tells you that?
-
M0xC0ncord[m]
<aeonsolution[m] "0xC0ncord: the repair page tells">
store.google.com/us/repair
-
M0xC0ncord[m]
IMEI or S/N in that box and it tells you the model.
-
aeonsolution[m]
it can tell you if a phone is carrier variant?
-
M0xC0ncord[m]
<aeonsolution[m] "it can tell you if a phone is ca"> Yes. Here's mine:
-
-
aeonsolution[m]
nice, i did not know that
-
aeonsolution[m]
thank you for the share
-
M0xC0ncord[m]
It will say "Unlocked" or "Verizon"
-
M0xC0ncord[m]
<entry1[m] "0x UnlockedC0ncord Unlocked is "> Correct
-
switchdominion[m
Just finished installing GOS on my Pixel 4. Given the information I've been seeing recently of faults with F-Droid, does anyone here have other package managers / app stores to recommend? I saw someone mentioned Aurora.
-
LinusArchTips[m]
Aurora Droid is nice, gives you the option to use many non F-droid repositories
-
switchdominion[m
entry1: I would use the F-Droid app for some package management on my previous device. I only used the website to download the F-Droid apk.
-
switchdominion[m
entry1: My understanding is that they aren't very timely in publishing updates for apps in the store and have apps that are targeted for old versions of Android but can still be installed on a device that has newer software which can be a security risk. Is that different on the website? I would find that a bit odd.
-
izymandias[m]
I have a question guys...What the hell is a Windows secure core PC?
-
renlord
izymandias[m]: have you read the microsoft marketing material?
-
renlord
the laptops sold under this branding goes thru a vigorous certification program with Microsoft
-
izymandias[m]
renlord: is it just laptops?
-
renlord
izymandias[m]: yep, just laptops only
-
izymandias[m]
will this be coming to PC's?
-
renlord
izymandias[m]: no and my guess is that it would be impossible
-
renlord
unless you happy to buy integrated builds with PCs
-
aeonsolution[m]
hey renlord, are you helping with the kernel patches for Android 11 by any chance
-
renlord
aeonsolution[m]: no
-
aeonsolution[m]
kk thanks
-
renlord
anyone know if there are actually apps that break if sensors permission was revoked?
-
renlord
besides google maps
-
renlord
or other maps that provide navigational assitance.
-
izymandias[m]
renlord: will it be coming to PC's?
-
renlord
izymandias[m]: no
-
renlord
never desktop PCs
-
renlord
not in its current state/form
-
renlord
could possibly come to those dell workstations, but definitely not enthusiast builds
-
izymandias[m]
renlord: are they going to get more secure?
-
renlord
izymandias[m]: i dont want to speculate on desktop pc security and it is offtopic in this channel
-
renlord
lets end on the fact that is less secure than mobile OSes
-
izymandias[m]
renlord: that sucks
-
renlord
it is hard to secure flexibility.
-
grindlefang[m]
Hello, I have previously been able to build Vanadium and GrapheneOS many times successfully but it appears for the last 1-2 weeks the Vanadium build is broken. I came here last week and was told the Vanadium build was broken but it's a problem with upstream. Today strcat told me Vanadium build is not broken and hasn't been.
-
grindlefang[m]
I'm compiling with python 2.7.13 as it was suggested to make sure its python 2 . After running "ninja -C out/Default/ trichrome_webview_64_32_apk trichrome_chrome_64_32_bundle trichrome_library_64_32_apk " it gets to step 78838/82828... then crashes:
-
renlord
grindlefang[m]: logs?
-
grindlefang[m]
ld.lld: error: undefined symbol: content::CrossOriginEmbedderPolicyReporter::CrossOriginEmbedderPolicyReporter(content::StoragePartition*, GURL const&, base::Optional<std::__1::basic_string<char, std::__1::char_traits<char>, std::__1::allocator<char> > > const&, base::Optional<std::__1::basic_string<char, std::__1::char_traits<char>, std::__1::allocator<char> > > const&)
-
grindlefang[m]
I've posted a longer snippet of my log here:
pastebin.com/mfxu10vV
-
izymandias[m]
renlord: another question. Is the game valorant safe to play?
-
renlord
izymandias[m]: dont know
-
faxing[m]
<izymandias[m] "renlord: another question. Is th"> No, their anticheat is basically glorified spyware
-
renlord
TIL ^
-
renlord
lulz
-
faxing[m]
It also broke a ton of people's computers because of how deeply embedded it is into the system and it had a few problems
-
renlord
i dont know how else can anticheat works besides spying on you
-
izymandias[m]
faxing: is it different from other epics and steams anticheat?
-
grindlefang[m]
renlord I tried to take a look at build changes to Vanadium or the grapheneos build page but it didn't seem there was anything major and I am following the build guide commands
-
faxing[m]
Anonymously collecting open processes and comparing them and their function to a list of known cheat software without keeping logs
-
faxing[m]
That's how you build an anticheat that doesn't spy on you
-
renlord
fuck this matrix bridge
-
grindlefang[m]
strcat: take a look at my above messages about Vanadium build problems when you have a chance cheers
-
faxing[m]
<izymandias[m] "faxing: is it different from oth"> VAC is complicated and not something I'm familiar enough with, though from my knowledge it is much less invasive. Epic doesn't really have an antichat per say, but they do use EAC (Easy Anti Cheat) for their games like Fortnite
-
aeonsolution[m]
grindlefang: there isn't any problems with Vanadium builds
-
renlord
grindlefang[m]: what are your gn args configs
-
grindlefang[m]
Sure all post my args.gn one sec
-
grindlefang[m]
I'll*
-
faxing[m]
But their isn't truly a platform wide anticheat developed in house for Epic like Steam has
-
faxing[m]
* But theirs isn't truly a platform wide anticheat developed in house for Epic like Steam has
-
cdesai
enable_remoting (or was it reporting, check vanadium args)
-
aeonsolution[m]
post the errors in the chat and let us help you out, no need to ping strcat for things the chat can help with
-
grindlefang[m]
I did post the error in chat
-
grindlefang[m]
-
izymandias[m]
faxing: so Epic games' anticheat is spyware too?
-
grindlefang[m]
I changed enable_reporting = false
-
renlord
pls take the anticheat discussion offline
-
renlord
it is off-topic
-
grindlefang[m]
Because I saw the comment in Vanadium args.gn about the build being broken and it was breaking with a different error before
-
grindlefang[m]
I'm building on ubuntu . I can still build GrapheneOS just not Vanadium since a couple weeks ago
-
aeonsolution[m]
you're probably missing dependencies that aren't listed in the building instructions
-
aeonsolution[m]
can you show the error you're getting
-
grindlefang[m]
-
grindlefang[m]
Just to clarify... changing "enable_reporting = false" was a good move right? I can change it back and build again to show you the other error it was giving me when it was set to true, if that helps
-
aeonsolution[m]
either or should work, what is breaking ninja is probably missing dependencies
-
renlord
grindlefang[m]: when you changed enable_repoting = false
-
renlord
did some stuff rebuild?
-
renlord
or it proceeded to link anyways?
-
renlord
have you tried a clean build again when you changed
-
grindlefang[m]
I just did a clean build no . Setup a fresh environment, synced the code from scratch, and built from scratch with enable_reporting = false
-
grindlefang[m]
now*
-
izymandias[m]
faxing: valorant isnt on epic games. Its riot games
-
grindlefang[m]
What OS / environments are you guys building on ?
-
overheadscallop[
Ubuntu 20.04
-
overheadscallop[
no problems
-
grindlefang[m]
I just don't understand why a dependency issue would cause that specific error in the Chromium source to manifest itself
-
aeonsolution[m]
ninja uses python
-
grindlefang[m]
<overheadscallop[ "Ubuntu 20.04"> you're building vanadium from source?
-
overheadscallop[
yes, clean build syncing to latest stable 84.0.4147.89
-
faxing[m]
<izymandias[m] "faxing: valorant isnt on epic ga"> I didn't say Valorant was on Epic Games?
-
faxing[m]
I'm aware that it's on Riot Games
-
aeonsolution[m]
grindlefang: can you try starting over, i'll be here if you have questions
-
izymandias[m]
faxing: sorry just confused. are you saying epic games' anticheat is spyware like valorants?
-
renlord
izymandias[m]: faxing[m]: pls take it offline
-
renlord
ffs
-
grindlefang[m]
Sure.. I'm going to try on debian buster
-
grindlefang[m]
is running
-
grindlefang[m]
build/install-build-deps-android.sh
-
grindlefang[m]
gclient runhooks
-
grindlefang[m]
Still necessary to install chromium build dependencies? I've been doign that and it seems to be working fine but wondering if that could be interfering with things
-
aeonsolution[m]
yes, some of those tools are used to complete the build
-
aeonsolution[m]
its just safer to have it even if its not all used
-
grindlefang[m]
Ok
-
aeonsolution[m]
because figuring out whats missing wastes so much time
-
grindlefang[m]
it would be amazing if there was a grapheneos dockerfile. I think that could seriously help development
-
grindlefang[m]
Anyways thanks for your help so far guys I'll tinker around and let you know if I have any other questions
-
grindlefang[m]
One last question: is deleting the out/ directory enough for a new clean Vanadium build? Don't want to have to delete the whole src dir and download the source again
-
aeonsolution[m]
just delete the out/Default if your ninja build added stuff in there
-
aeonsolution[m]
everything else can stay
-
grindlefang[m]
Cool, thanks
-
aeonsolution[m]
you didn't edit any other files or directs under src/ right?
-
grindlefang[m]
Nope
-
aeonsolution[m]
* [correction] you didn't edit any other files or directories under src/ right?
-
aeonsolution[m]
yeah, just delete out/Default
-
-
renlord
i have a dockerfile
-
renlord
but i dislike using docker
-
renlord
im gonna use systemd nspawn instead
-
renlord
it does funny things with my network
-
renlord
its shit ass with ipv6
-
renlord
always causes intermittent network failures
-
-
aeonsolution[m]
👍️
-
grindlefang[m]
renlord: are you able to post it? It could be helpful in setting up a build env for devs or sorting out dependencies issues like mine
-
renlord
im testing the latest version for vanadium
-
renlord
are you still having issues
-
grindlefang[m]
Yeah just doing another build now on debian buster
-
faxing[m]
<izymandias[m] "faxing: sorry just confused. are"> Epic Games doesn't really have an anticheat like I said. It's just that their top games (i.e. Fortnite) use EasyAntiCheat (EAC), but that is not "Epic Games' Anticheat" as much as it is just an anticheat that they make use of for some of their more popular titles
-
faxing[m]
Also it's still very invasive but not to the extent of Valorant's
-
renlord
zzz
-
renlord
3-strikes, you have been asked to cease offtopic discussions.
-
cn3m[m]
faxing: stop talking about anti cheat man
-
cn3m[m]
it's off topic you got told
-
switchdominion[m
faxing: Just private message or take it to #freenode_#grapheneos-offtopic:matrix.org
-
renlord
are they still spamming the matrix side?
-
izymandias[m]
faxing: thanks for responding anyway. i didnt know either
-
izymandias[m]
how comes graphene doesnt use Face ID? is it lacking the camera or is Face ID insecure?
-
aeonsolution[m]
izymandias: we need more developers to work on these features, please feel to help out
-
cn3m[m]
<izymandias[m] "how comes graphene doesnt use Fa"> you mean it is not working on your Pixel 4?
-
switchdominion[m
With regards to US law, Face ID and fingerprinting is insecure as those can be subpoenaed, to the best of my knowledge.
-
cn3m[m]
<switchdominion[m "With regards to US law, Face ID "> on the other hand bio-metrics pretty much kill shoulder surfing and
-
switchdominion[m
From what I've read about Face ID and facial recognition software in general, there are false positives that could allow someone to access your device.
-
izymandias[m]
switchdominion: Oooo I see. so the technology itself isnt insecure, its just that the government can force you to unlock your device with your face
-
switchdominion[m
<cn3m[m] "on the other hand bio-metrics pr"> Agreed. It all depends on which attack vectors an individual is most susceptible.
-
cn3m[m]
yeah face is especially strong(with require attention)
-
cn3m[m]
since someone can't do it when you are sleeping
-
switchdominion[m
<izymandias[m] "switchdominion: Oooo I see. so t"> With fingerprinting, yes. But when I tested out Face ID, which was years ago, granted, I was able to access another persons device using my face.
-
izymandias[m]
switchdominion: o really. was that on an android or IOS?
-
switchdominion[m
<izymandias[m] "switchdominion: o really. was th"> It was on Android. LG Stylo 2 or 3, if I recall correctly.
-
switchdominion[m
Granted, my experience and research with Face ID is likely outdated.
-
cn3m[m]
Yeah FaceID is far far stronger
-
cn3m[m]
and Pixel 4 got a great patch
-
cn3m[m]
I think it is just as good now
-
renlord
does it work with a mask on?
-
renlord
hehe
-
izymandias[m]
does the Pixel 4's match IOS's ?
-
switchdominion[m
<cn3m[m] "Yeah FaceID is far far stronger"> That's good. Though I would still warn those in certain countries that allow a subpoena, such as the US, for biometrics to use them based on their need.
-
izymandias[m]
is it the same tech. infrared?
-
cn3m[m]
izymandias: Yeah, iirc you can even use the infrared camera for photos
-
nickcalyx[m]
at the data center where I have my servers, I have to do finger print and then later face scanning, as well as rfid, and talk to a person, then rfid again and rfid a third time and then a combination lock
-
nickcalyx[m]
its quite the security theater
-
cn3m[m]
Trusted Face in Android is not nearly as good
-
nickcalyx[m]
oh and I understand they now put another rfid check in the elevator, so it will be 4 rfid checks
-
cn3m[m]
nickcalyx: xD
-
Knull[m]
This is why i don't even record biometrics
-
izymandias[m]
Knull: why?
-
Knull[m]
The subpoenas. Id rather my device not even have that information in the first place
-
cn3m[m]
<Knull[m] "The subpoenas. Id rather my devi"> it is stored fuzzed in the Titan or SEP
-
cn3m[m]
they are fine
-
Knull[m]
Access should strictly be what you know unless combined with what you have. Not just 'what you have '
-
switchdominion[m
cn3m:
-
Knull[m]
Password or two factor
-
switchdominion[m
* cn3m: are there whitepages on the Titan?
-
switchdominion[m
* cn3m: Are there whitepages on the Titan?
-
cn3m[m]
-
nickcalyx[m]
someone who takes your phone can hold it up to your face or press it to your finger
-
izymandias[m]
Knull: why not just enable password in the moment if such a situation was to arise?
-
cn3m[m]
-
Knull[m]
<nickcalyx[m] "someone who takes your phone can"> Exactly. That's why you don't only use that if possible
-
nickcalyx[m]
cn3m: let me guess, that's the one about beating them with the $5 wrench ?
-
cn3m[m]
between this and shoulder surfing
-
cn3m[m]
:)
-
cn3m[m]
biometrics have some notable advantages
-
Knull[m]
If face scan unlocked a pin screen that you still need to enter, great. Face alone, no
-
broda721[m]
Is it possible to set two factor in grapheme rn?
-
izymandias[m]
Knull: can that not be enabled?
-
cn3m[m]
Knull: the goal is you never put in your password in public
-
cn3m[m]
<broda721[m] "Is it possible to set two factor"> not at this point
-
Knull[m]
Or have a complex enough password that a simple shoulder surf cant remember
-
cn3m[m]
could be recorded
-
switchdominion[m
<cn3m[m] "
reddit.com/r/Graphen"> I read a bit of that earlier and I'll take a closer look now. Mostly I was wondering what you meant by Face ID and/or biometrics being "stored fuzzed in the Titan or SEP."
-
Knull[m]
Recorded though? Probably a little outside most ppl's threat models
-
renlord
grindlefang[m]: i have no issues building
-
renlord
-
renlord
you need to update args.gn and resync
-
renlord
run the docker container interatively with a shell and then follow the instructions on grapheneos.org
-
cn3m[m]
<Knull[m] "Recorded though? Probably a litt"> switchdominion: Here is what Apple says(they say roughly the same on FaceID)
-
cn3m[m]
Anything iPhone/Pixel Finger/Face is good
-
Knull[m]
That's great, paired with a pin/ password
-
Knull[m]
In the two -factor model, even if recorded, they need your finger
-
cn3m[m]
it is very easy to lockdown the device to not accept biometrics
-
grindlefang[m]
I just tried on debian buster again and its failing at the same spot complainging about CrossOriginEmbedderPolicyReporter
-
cn3m[m]
I think the advantages outweigh the drawbacks
-
cn3m[m]
they time out too
-
Knull[m]
And the other way around.. maybe they got ur cold dead finger, but dont know your pin
-
cn3m[m]
Pixel is 48 hours for example
-
cn3m[m]
to fake biometrics it could take a while
-
grindlefang[m]
<renlord "grindlefang: i have no issues bu"> renlord: your docker file is pointing to a much older version of chromium.
-
cn3m[m]
In general biometrics are very smartly designed on iPhone/Pixel
-
renlord
grindlefang[m]: ya, just do the gclient sync step iteractively
-
renlord
the container image is not bound to wtv chromium version you're building
-
cn3m[m]
<faxing[m] "I didn't know you could have it "> you can't
-
Knull[m]
You cant that i know of, my point is biometric is only good paired with a password. If i had to choose 1, its a pin
-
renlord
`docker run -v vanadium-path:/vanadium -it image /bin/bash`
-
Knull[m]
Sorry im confusing ppl
-
cn3m[m]
<Knull[m] "You cant that i know of, my poin"> alphanumeric password + face recognition is likely the best
-
Knull[m]
Yes
-
cn3m[m]
can't easily be fooled(can't at all without preplanning). Easily locked
-
renlord
grindlefang[m]: you might just want to reclone depot tools
-
renlord
and try again
-
renlord
between my old chromium build and this most recent one, depot_tools was completely broken
-
cn3m[m]
I would recommend biometrics for most people. My password has been recorded a few times thinking back
-
grindlefang[m]
Also that ubuntu 18 only ubuntu 20 is officially supported? I just tried from debian stretch and buster but no go... which is supposed to be officially supported. I'll try from ubuntu 18.04 now like the dockerfile
-
Knull[m]
Maybe something that will come unique to graphene
-
grindlefang[m]
I'm doing a clean build everytimerenlord:
-
renlord
depot_tools is separate
-
LinusSexTips[m]
isnt law enforcement allowed to force you to give up your fingerprint though?
-
cn3m[m]
<cn3m[m] "I would recommend biometrics for"> between the long encryption password, reasonable timeouts, safe storage, and quicking locking out biometrics you have far less to worry about.
-
cn3m[m]
> <@cn3m:privacytools.io> I would recommend biometrics for most people. My password has been recorded a few times thinking back
-
cn3m[m]
* between the long encryption password, reasonable timeouts, safe storage, and quickly* locking out biometrics you have far less to worry about.
-
grindlefang[m]
Yes, fresh build environment
-
renlord
-
cn3m[m]
<LinusSexTips[m] "isnt law enforcement allowed to "> Depends. In the US that is a maybe, currently it is leaning no. That is not set in stone
-
cn3m[m]
Just lockdown your phone or ideally reboot
-
cn3m[m]
it is qucik
-
cn3m[m]
do it before bed and in any situation you might have your phone taken
-
Knull[m]
No fingerprint reader on 4xl it seems though 😕
-
grindlefang[m]
cn3m: that is a very bad recommendation. fingerprints do not have anywhere near the same level of security or legal rights as a password. You can clone artifical fingers that bypass fingerprint scanners using high-resolution photos of a hand
-
cn3m[m]
<grindlefang[m] "cn3m: that is a very bad recomme"> I said facial recognition. Fingerprinting is legacy tech at this point
-
grindlefang[m]
ok just replace fingerprints with biometrics what i said still stands
-
cn3m[m]
fingerprint you can still lock out and it is very effective against recording or shoulder surfing
-
izymandias[m]
I've seen videos of people recording their interaction with police only for their phones to be snatched out of their hands suddenly. Then i wonder how many were actually snatched and the footage deleted. if graphene had a feature that could use video recording while the phone was in lock or is put lock once the phone is snatched would be awesome.
-
cn3m[m]
<grindlefang[m] "ok just replace fingerprints wit"> someone has to do it before the time out
-
cn3m[m]
that is some serious commitment
-
-
grindlefang[m]
not really... in most emergency or high-stress situations people are often on their phones to call for help or let their loved ones know what is going on
-
grindlefang[m]
you're basing your security on the hope your timer runs out... seems risky
-
cn3m[m]
Well they could just wait for an AFU exploit and see how long they can keep your phone alive
-
cn3m[m]
GrapheneOS and iOS both have very robust protections against this, but not perfect ofc
-
Knull[m]
<izymandias[m] "I've seen videos of people recor"> Interesting idea for physical record button, once released, phone locks, recording keeps running
-
cn3m[m]
you really should reboot if you think you will lose access to your phone
-
grindlefang[m]
again... you're deflecting the securtity of biometrics
-
cn3m[m]
<Knull[m] "Interesting idea for physical re"> this could be done from the lock screen with public key cryptography
-
renlord
depending on your threat model and environment, you can alter your op sec
-
LinusSexTips[m]
<izymandias[m] "I've seen videos of people recor"> cant you access the camera from the lockscreen via a setting?
-
cn3m[m]
<grindlefang[m] "again... you're deflecting the s"> you are deflecting the insecurity of having your password recorded as you put it in
-
cn3m[m]
you are also taking longer to access your phone with that long password
-
cn3m[m]
or using a PIN and putting a lot of faith into the hardware timer(which yeah the device will brick more than likely)
-
cn3m[m]
there is no one answer
-
switchdominion[m
<cn3m[m] "or using a PIN and putting a lot"> Isn't the hardware timer for a 4-digit pin upwards to over a century?
-
cn3m[m]
<switchdominion[m "Isn't the hardware timer for a 4"> 650 years, though there could always be a flaw
-
Knull[m]
Two factor is the answer, lol
-
cn3m[m]
it is very unlikely
-
cn3m[m]
<Knull[m] "Two factor is the answer, lol"> yes password with pin+bio as the 2fa is decent
-
cn3m[m]
but still doesn't account for AFU attacks so still just reboot
-
LinusSexTips[m]
will graphene ever have the option for bio+pin?
-
cn3m[m]
> <@knull:matrix.org> Two factor is the answer, lol
-
cn3m[m]
* yes password with pin+bio as the 2fa is decently ideal
-
Knull[m]
Hopes and prayers, Linus, hopes and payers
-
cn3m[m]
<LinusSexTips[m] "will graphene ever have the opti"> yes, probably. What I heard it might be ideal to wait until fingerprint dies
-
LinusSexTips[m]
yeah rip no facial recog on 3a
-
cn3m[m]
someone just needs to add it
-
cn3m[m]
<LinusSexTips[m] "yeah rip no facial recog on 3a"> unfortunately 4a looks like it won't since holepunch
-
izymandias[m]
Knull: dont think you would even need a physical button. maybe have a mode in the camera that requires you to have your finger on the record button and is locked once released. and have a feature that allows you to start recording again if you were to accidently release the finger from the screen. dont know how it would be done
-
switchdominion[m
<cn3m[m] "650 years, though there could al"> Specifically, I'm referring to brute forcing a pin with a Titan M. What flaw might you be referring to?
-
cn3m[m]
<switchdominion[m "Specifically, I'm referring to b"> It is not outside the realm of possibility for their to be a flaw in the hardware timer
-
cn3m[m]
it is a hardware system that is designed to brick if tampered
-
cn3m[m]
youtube.com/watch?v=7UNeUT_sRos here is a good talk on an old version of the SEP. These are just systems they could have flaws of course
-
switchdominion[m
<cn3m[m] "It is not outside the realm of p"> Of course. That is probably why Google has a $1.5 million bounty for anyone that can find a bug in the Titan M.
-
cn3m[m]
isn't it $1 million?
-
renlord
it is 1mil
-
renlord
1.5mil are android RCE bugs
-
LinusSexTips[m]
basically 1.5mil CAD by this point lol
-
renlord
paid by some security firm that i cant remember the name of
-
cn3m[m]
yeah, though this could be exploited any time after they obtain it
-
switchdominion[m
I've seen 1-1.5 from different articles
-
cn3m[m]
<renlord "paid by some security firm that "> gray market?
-
cn3m[m]
it is $250k to Google iirc
-
cn3m[m]
from*
-
cn3m[m]
for kernel control with POC
-
renlord
-
renlord
2.5mil for android fcp zero click
-
switchdominion[m
-
switchdominion[m
The top prize is for a “full chain remote code execution exploit with persistence” of the dedicated security chip. On top of that, there’s an additional 50 percent bonus if a security researcher is able to find an exploit on specific developer preview versions of Android, resulting in a potential prize of $1.5 million.
-
cn3m[m]
renlord: I rather take the $250k
-
renlord
the one i recall is not zerodium though
-
renlord
but man, so many people paying top dollars
-
cn3m[m]
to think so few people actually have a phone you need a zero day for
-
cn3m[m]
Any iPhone in the last 7 years, Samsung Galaxy S series for the past 3 years(the 4th doesn't count as it is quarterlies), Any Pixel in the past 3 years. Not even a quarter of phones
-
aeonsolution[m]
does anyone know the reasoning behind migrating the kernel patches to R-Preview-4 instead of R-Beta-2?
-
aeonsolution[m]
i got the answer everyone, thank you for reading my gripes lol
-
cn3m[m]
<aeonsolution[m] "i got the answer everyone, thank"> What is the answer if you don't mind?
-
aeonsolution[m]
since the commits can be rebased using git, it is not as important where you start because you can add missing commits later
-
aeonsolution[m]
but its not an excuse to be sloppy either
-
aeonsolution[m]
the order of the commits still need to make sense
-
grindlefang[m]
renlord: do you have the full list of commands you're using for Vanadium? The build guide is a little ambiguous . I'm still getting the same error. Just to clarify as well... enable_reporting = true ? Because that is not mentioned in build guide but seems to be a necessary temporary workaround
-
Knull[m]
Am i blind or there's really no headphone Jack on pixel?
-
nickcalyx[m]
<Knull[m] "Am i blind or there's really no "> Only on the pixel 3a
-
Knull[m]
Whats this world coming to
-
ojkuiyln
digital world and the end of analog world
-
warturkey[m]
Long live the headphone jack
-
g65434-2[m]
i love my focal headphone, i can use Bluetooth and Jack on it
-
g65434-2[m]
but i get let output with jack because of impedance
-
anupritaisno1[m]
g65434-2: for me the jack any day
-
anupritaisno1[m]
Even LDAC for some of my files hardly comes close
-
ojkuiyln
but do you keep charging those old jack headsets or just don't use noise canceling?
-
anupritaisno1[m]
I have a phone that still does analog
-
anupritaisno1[m]
Noise cancelling not so much
-
cdesai
grindlefang[m]: yeah you need to enable reporting check the vanadium args.gn
-
cdesai
Need to file an upstream bug about this and check on master
-
marlow11[m]
I'm having an issue with the camera. Most of the time the button is greyed out and it won't take a picture. I can eventually take one if I close the app and reopen a bunch of times. Then sometimes I'll press the button and it will take up to 10 seconds to actually take the picture. Is this a known issue? I'm pretty sure it just started recently
-
testingtesting12
Does anyone have experience using WhatsApp on GrapheneOS? I know it works, just wondering about notifications though
-
testingtesting12
Reading some conflicting information. Some say you don't get notifications, some they're iffy and some say you do
-
renlord
grindlefang[m]: following the build guide verbatim is sufficient
-
renlord
with the docker image
-
renlord
didnt need `enable_reporting = true`, mine was set to false
-
renlord
and enable_remoting = false too
-
rickza[m]
Good day all, could anybody give me some assistance in sorting out my remote verification ? I keep on getting emails stating that the attestation has failed
-
ojkuiyln
it work fine testingtesting12
-
dreth[m]
<testingtesting12 "Does anyone have experience usin"> The only thing you dont get is google drive backups but you probably don't want those if youre considering installing grapheneos because theyre not encrypted.
-
switchdominion[m
Has anyone had any trouble with sending files over Bluetooth?
-
justchill[m]
<dreth[m] "The only thing you dont get is g"> Don't the notifications on Whatsapp use Google's push notifications service?
-
justchill[m]
I did see
fosdem.org/2020/schedule/event/dip_openpush recently but I don't know the current status of the project.
-
LinusSexTips[m]
I have WhatsApp in a separate user profile
-
LinusSexTips[m]
And I still get notifications despite just getting it from the Aurora Atore.
-
LinusSexTips[m]
* And I still get notifications despite just getting it from the Aurora Store
-
grindlefang[m]
renlord: I'm not sure what you're building from then, the default args.gn has enable_reporting = true
github.com/GrapheneOS/Vanadium/blob/10/args.gn#L27 t . I have built with enable_reporting = false and It's giving me the same error.
-
grindlefang[m]
I'm following the vanadium build guide and chromium build guide verbatim and it's not working, I've tried on debian stretch, debian buster and ubuntu 18. Seems strange also it only suddenly happened about 1-2 weeks ago. I'll keep investigating...
-
grindlefang[m]
The fact it is complaining about the same lines every time seems a little weird too.
-
grindlefang[m]
ld.lld: error: undefined symbol: content::CrossOriginEmbedderPolicyReporter::CrossOriginEmbedderPolicyReporter(content::StoragePartition*, GURL const&, base::Optional<std::__1::basic_string<char, std::__1::char_traits<char>, std::__1::allocator<char> > > const&, base::Optional<std::__1::basic_string<char, std::__1::char_traits<char>, std::__1::allocator<char> > > const&
-
steve9
nick demonMachina
-
demonmachina[m]
Close....Jake.
-
grindlefang[m]
The grapheneos vanadium build instructions are really ambiguous as well.. it just links to chroimiums android build instructions for fetching dependencies, telling you to get dependecies before syncing.. but the chromium page says you should sync before fetching dependencies
-
grindlefang[m]
renlord: your dockerfile had a lot of unnecessary steps in it as well for example calling install-build-deps.sh before calling install-build-deps-android.sh even tho install-build-deps-android.sh calls install-build-deps, and apt installing the same packages multiple times. However I'll try to use that as a base for an environment and hopefully I can guess the right commands needed to build Vanadium
-
aeonsolution[m]
<grindlefang[m] "The grapheneos vanadium build in"> Vanadium is just Chromium with hardening patches, strcat adapted the build rules for Vanadium development. In general, external links are for reference material. Not for steps to follow as part of the install.
-
aeonsolution[m]
There are a lot of steps it so it does feel overwhelming at first but I can gurantee you the steps there will help you succesfully build Vanadium.
-
aeonsolution[m]
Anything from the Chromium page is just for reference. If you want to dive into that and see how it relates to how Vanadium gets built for GrapheneOS, you should definitely jump in. It'll definitely help you with development.
-
interceptingfist
Why is my terminal sayingfastboot is too old?
-
aeonsolution[m]
What instructions did you follow interceptingfist?
-
interceptingfist
I'm on 30.0.3
-
interceptingfist
Hated one
-
interceptingfist
But he didn't explain the flash all part
-
interceptingfist
He only mentioned how to flash all on windows
-
aeonsolution[m]
As a general rule, don't use instructions that aren't from the Official Website <
grapheneos.org>.
-
interceptingfist
I'm also using thosr
-
interceptingfist
They are already pulled up
-
aeonsolution[m]
Right, but if someone else gives you directions that don't verbatim stick to these instructions. You'll get that error.
-
grindlefang[m]
<aeonsolution[m] "Vanadium is just Chromium with h"> I have built Vanadium many many times. It's not that the instructions are overwhelming.. .it's that they are incomplete and ambiguous
-
interceptingfist
No,sometimes it's easier to see the process
-
aeonsolution[m]
-
aeonsolution[m]
In the logs, you'll see that error you get is always from people watching videos.
-
grindlefang[m]
renlord: Judging from what you said about enable_reporting seems you are building from QQ3A.200705.002.2020.07.06.20 and not the 10 branch which is the latest
-
grindlefang[m]
-
aeonsolution[m]
Let's try to figure it outinterceptingfist. Close all your windows, and start from step 1.
-
grindlefang[m]
You can see this is the previous version of chromium "83.0.4103.106" which was also building fine for me
-
aeonsolution[m]
We'll narrow down the issue from there.
-
grindlefang[m]
I can see also there is a lot of active development under the 10 branch in the last week that is not in the tagged version
-
aeonsolution[m]
grindlefang: the issue are the packages with Ubuntu not so much that the instructions
-
aeonsolution[m]
if you have successfully built Vanadium and have suggestions to improve the install process, please make a pull request
-
grindlefang[m]
<aeonsolution[m] "grindlefang: the issue are the p"> Yeah.. I have built on debian buster, sid and ubuntu and all are giving the same error. I used the same dependencies mentioned
-
grindlefang[m]
I am, the build is broken
-
aeonsolution[m]
we don't have enough people building Vanadium on Ubuntu and Debian to lend their insight
-
aeonsolution[m]
most of us use Arch based OSes
-
grindlefang[m]
Ubuntu and Debian are supposed to be officially supported
-
grindlefang[m]
Arch is not
-
aeonsolution[m]
Arch gives us the packages to avoid the problems you are having with dependencies
-
grindlefang[m]
Well then looks like the build instructions are incorrect
-
grindlefang[m]
If they say to use debian and ubuntu not arch
-
aeonsolution[m]
who is they?
-
grindlefang[m]
The build instructions friend
-
grindlefang[m]
-
aeonsolution[m]
Arch is the first one
-
aeonsolution[m]
?
-
grindlefang[m]
Right, and ubuntu and debian are next
-
aeonsolution[m]
the devs that work on GOS and Vanadium use Arch
-
aeonsolution[m]
if you have suggestions to improve Ubuntu and Debian development
-
aeonsolution[m]
please create a pull request
-
grindlefang[m]
It doesn't build on officially supported environment and builds, I would suggest that is a problem with your build instructions not the developer ;)
-
aeonsolution[m]
Debian and Ubuntu are supported by Google to do Android testing
-
aeonsolution[m]
and development
-
grindlefang[m]
I will setup a new environment in arch to build Vanadium and GrapheneOS, altho AOSP does not support arch
-
dazinism
switchdominion: entry1 for apps and appstores (and even app repos) have a look at
hub.libranet.de/wiki/graphene-os/wiki/Apps
-
aeonsolution[m]
you need to figure out the dependencies to build Vanadium and if you have suggestions to improve the process please make a pull request
-
interceptingfist
Nothing mentions the error that see
-
interceptingfist
Thanks though
-
grindlefang[m]
Also.. I am starting to doubt it's a dependency issue as there are no complaints when installing the dependencies and it manages to get 95% build complete and complains about the same CrossOrigin error on all 3 OSes
-
interceptingfist
If only grapheme could make a install video
-
aeonsolution[m]
-
LinusSexTips[m]
<interceptingfist "If only grapheme could make a in"> What OS are you trying to install from?
-
LinusSexTips[m]
I found one that worked perfectly for me
-
LinusSexTips[m]
Using Ubuntu
-
grindlefang[m]
Well that's a little dismissive, like I said your build guide is broken and I have "figured it out" many many times before with identical set of commands that built Vanadium. The 10 branch is broken and significantly different than the QQ3A.200705 version of Vanadium
-
interceptingfist
Linux pop
-
interceptingfist
I'm platform tools was downloaded from google lmao
-
interceptingfist
It's not out of date
-
interceptingfist
I also have a windows machine going to try it
-
LinusSexTips[m]
-
LinusSexTips[m]
That's what I used
-
LinusSexTips[m]
Should be fine on Pop!_OS
-
aeonsolution[m]
grindlefang: I can't help diagnose and issue on a distro, I don't use. The advice I am offering is based on my previous experiences building Vanadium. I was trying to led you to that understanding. I'm not being dismissive.
-
aeonsolution[m]
interceptingfist: did you set up your environment variables correctly?
-
aeonsolution[m]
if you close powershell, the path to fastboot gets lost
-
interceptingfist
I don't think I closed it
-
aeonsolution[m]
what command step are you on?
-
interceptingfist
Where you do flash all
-
aeonsolution[m]
ok, lets start from the beginning, let me pull the instructions
-
aeonsolution[m]
open a new powershell window
-
interceptingfist
Terminal is new
-
interceptingfist
I'm on 3a
-
aeonsolution[m]
`cd .\Downloads\`
-
aeonsolution[m]
after that run the curl command
-
aeonsolution[m]
for windows
-
aeonsolution[m]
i know we are doing it all over, but its to help find the issue
-
aeonsolution[m]
working backwards from the last step doesn't always work
-
aeonsolution[m]
because i don't know what changes accidentally/intentionally were made
-
aeonsolution[m]
-
interceptingfist
Ok
-
aeonsolution[m]
cool when that is done
-
aeonsolution[m]
we need to set the path the platform-tools so run `$env:Path = "$pwd\platform-tools;$env:Path"` afterwards
-
aeonsolution[m]
then run `fastboot --version afterwards` to check if your path is set to fastboot
-
aeonsolution[m]
* [correction] then run `fastboot --version afterwards` to check if your path is set to find fastboot
-
aeonsolution[m]
if your phone is OEM unlocked, you can then unlock the bootloader
-
aeonsolution[m]
by running: `fastboot flashing unlock`
-
aeonsolution[m]
using the same powershell window
-
aeonsolution[m]
make sure you are booted in the bootlader
-
interceptingfist
Ok
-
aeonsolution[m]
since you already downloaded the images
-
interceptingfist
I'm step by stepping the instructions for linux
-
aeonsolution[m]
?
-
aeonsolution[m]
aren't you on window
-
interceptingfist
I'm trying to get either one to flash
-
aeonsolution[m]
thats a really important detail to leave out
-
interceptingfist
Well neither does anything for the flash part
-
aeonsolution[m]
leaving your shell or powershell untouched
-
aeonsolution[m]
please move the factory images
-
interceptingfist
I'm on the Linux right now 1 minute left on the dl
-
aeonsolution[m]
oh ok, you are downloading the images again
-
aeonsolution[m]
are you using a USB A to USB C cable?
-
interceptingfist
C
-
interceptingfist
Yea a to c
-
aeonsolution[m]
nice, did you download and unzip the images already
-
interceptingfist
Unzipping
-
interceptingfist
Yep
-
interceptingfist
All that's left is flash command
-
aeonsolution[m]
cool run `./flash-all.sh` afterwards, make sure the phone is plugged in and that you are in the bootloader still
-
aeonsolution[m]
use the USB port closest to the motherboard
-
interceptingfist
No such fi
-
aeonsolution[m]
is it flashing?
-
interceptingfist
No
-
interceptingfist
And this riot froze up on me lol
-
aeonsolution[m]
nice
-
aeonsolution[m]
ok, what are you trying to do now
-
interceptingfist
Trying to make sure its all connected
-
interceptingfist
And just try one more time I guess
-
aeonsolution[m]
you changed the directory to the sargo right
-
interceptingfist
Ya
-
aeonsolution[m]
kk
-
aeonsolution[m]
yeah run the flash script
-
aeonsolution[m]
hopefully now you dont get fastboot error
-
aeonsolution[m]
-
aeonsolution[m]
Here's this for if you get other common errors related to Linux
-
aeonsolution[m]
if you close the shell, your path gets reset so the fastboot commands wont work until you update your path again just fyi
-
interceptingfist
Redownloading it
-
interceptingfist
When I do export path it doesn't show anything
-
aeonsolution[m]
why did you run export path again?
-
aeonsolution[m]
do you still have the shell we used for the initial steps active?
-
aeonsolution[m]
if you do, use that shell to run the commands
-
aeonsolution[m]
the steps are setup in a way where you can do everything in one shell
-
aeonsolution[m]
if you use different shells, the paths will not match up
-
interceptingfist
I'm started over from scratch
-
aeonsolution[m]
kk
-
aeonsolution[m]
you're almost there
-
aeonsolution[m]
i think we figured out that issue
-
aeonsolution[m]
fastboot problems are usually path problems
-
aeonsolution[m]
or downloading third part stuff not in the instructions
-
aeonsolution[m]
party*
-
interceptingfist
It still says nonsuch directoru
-
interceptingfist
No such directory
-
interceptingfist
I don't understand why it fails to try to flash
-
aeonsolution[m]
lets do this
-
aeonsolution[m]
cd $HOME/Downloads
-
aeonsolution[m]
then run ls
-
aeonsolution[m]
you should see platform-tools and the factory-images(unzipped) and the factory-images(zipped)
-
aeonsolution[m]
if you don't then you had the paths wrongs when you switched to Linux without mentioning it to me
-
aeonsolution[m]
if you do see all this
-
aeonsolution[m]
use the fastboot --version command
-
aeonsolution[m]
and see if you path is still up to date
-
aeonsolution[m]
if it is not
-
aeonsolution[m]
run `export PATH="$PWD/platform-tools:$PATH"`
-
aeonsolution[m]
and the try fastboot again
-
aeonsolution[m]
if you get the correct version as a response
-
aeonsolution[m]
now change into the unzipped directory
-
aeonsolution[m]
and run ls
-
aeonsolution[m]
you should see the flash-all scripts
-
aeonsolution[m]
if you directories you move into should be the sargo one
-
aeonsolution[m]
not the one in the examples on the website
-
aeonsolution[m]
* [correction] the directory you move into should be the sargo one for the pixel 3a
-
interceptingfist
<aeonsolution[m] "cd $HOME/Downloads"> Nothing happens
-
interceptingfist
Nvm
-
interceptingfist
I hit wrong letter
-
aeonsolution[m]
progress is progress, you are almost there
-
interceptingfist
I'm on downloads directory bit its waiting forna command
-
interceptingfist
Its not showing me anything after downloads
-
-
aeonsolution[m]
thats because the files didnt get downloaded there
-
aeonsolution[m]
you downloaded them somewhere else
-
aeonsolution[m]
wait did you run `ls`
-
aeonsolution[m]
if there is nothing there
-
aeonsolution[m]
you need to do the steps all over again
-
aeonsolution[m]
and do all the commands using that shell you are using
-
aeonsolution[m]
dont open new ones
-
interceptingfist
<LinusSexTips[m] "
invidio.us/watch?v=o"> This video is the way the truth and the life
-
interceptingfist
<aeonsolution[m] "thats because the files didnt ge"> Thanks for you help
-
aeonsolution[m]
did you get it up and running
-
interceptingfist
Yea mann
-
interceptingfist
:)
-
aeonsolution[m]
awesome, persistence pays off
-
interceptingfist
Yea
-
interceptingfist
Do you use a VPN?
-
aeonsolution[m]
i do, but im not using GOS as a personal phone right now, its just testing and development stuff for now; you can ask the group for specifics on that if you're curious
-
aeonsolution[m]
the logs might have gold in there too
-
nickcalyx[m]
<interceptingfist "Do you use a VPN?"> if you install f-droid there are a couple of free VPN's.. riseup VPN and calyx VPN
-
nickcalyx[m]
some people use orbot as a vpn too, to push traffic over Tor
-
nickcalyx[m]
the problem with Tor though is it only handles tcp but not udp
-
interceptingfist
<nickcalyx[m] "the problem with Tor though is i"> Thanks
-
nickcalyx[m]
Did you know that getting the same app from @fdroidorg instead of Google Play can mean it won't track you?
twitter.com/t_grote/status/1279779673128534016
-
SchismXL[m]
Right, I've "fixed" the 90hz flickering on my device. I used adb.
-
SchismXL[m]
I've basically forced the display to always be at 60hz
-
SchismXL[m]
adb shell settings put system peak_refresh_rate 60
-
SchismXL[m]
adb shell settings put system min_refresh_rate 60
-
SchismXL[m]
I wonder if an app could be made for that? I know nothing about Android development (or any type of dev work for that matter), but it doesn't seem like too much of a "challenge" to make an app that could toggle those settings, using adb? I dunno. Just a thought!
-
SchismXL[m]
Rebooted and the adb command is persistent, yay. I can't tell you how much this has made me happy lol
-
nickcalyx[m]
I never understood the 90hz thing, it seems silly IMO
-
SchismXL[m]
It does look smoother when scrolling through the UI and whatnot, but it isn't a game changer
-
SchismXL[m]
Well, maybe for games
-
SchismXL[m]
<SchismXL[m] "It does look smoother when scrol"> A little smoother*
-
mrsenshi[m]
Good evening.
-
mrsenshi[m]
Brilliant project.
-
mrsenshi[m]
Might I ask: What difficulties prevent other ROMs from allowing the bootloader to be relocked, as is the case with GrapheneOS?
-
mrsenshi[m]
Secondly, if there were to be an implementation rootless theming along the lines of Android 8 (requiring ADB), would this pose any security risk?
-
cn3m[m]
<mrsenshi[m] "Might I ask: What difficulties p"> hardware and interest. Pixels and OnePlus(OP has had a rocky history at best) devices support it across the line. Most roms don't support it on Pixels or OP since lack of interest largely due to people wanting to root(which breaks it).
-
cn3m[m]
<mrsenshi[m] "Secondly, if there were to be an"> ADB is not recommended for security reasons
-
nickcalyx[m]
<SchismXL[m] "It does look smoother when scrol"> It reminds me of that scene in 'this is spinal tap'. . But this one.goes to 11 !!!
-
helpimaloser
Hey im trying to install graphenos on my second pixel and i get this error:
-
helpimaloser
-
helpimaloser
I got this error with my first pixel and someone just told a code
-
helpimaloser
and it fixed it
-
helpimaloser
But i dont know any coding someone who might knows
-
helpimaloser
I have the latest fastboot
-
overheadscallop[
Are you following the official guide?
-
overheadscallop[
and you should be using powershell
-
helpimaloser
Mind private messaging me?
-
helpimaloser
I'll pay u for helping me out im not that techy
-
renlord
helpimaloser: you are not flashing correctly
-
renlord
you have not installed fastboot yet
-
geckoflip
Sup guys
-
geckoflip
Got my first install of graphene on pixel 3 thru
-
geckoflip
theres lot under the surface in terms of features but wondering the similarity and lack of interactive privacy features
-
geckoflip
similarity to android 10
-
geckoflip
and some system apps remainin even though most removed