• dastanktal@lemmy.ml
    link
    fedilink
    English
    arrow-up
    1
    ·
    5 days ago

    No, it’s really not. Just go buy any of the old Pixel phones and they all work with lineage. I mean, it’s not that big of a deal. You’re making it sound like it’s a huge effort to find a new phone, and you just have to accept the fact that you’re going to have a couple of generations older to run these type of OSes.

    A phone will only call out to Big Brother if it has the code to do so. It needs the code. If the phone is flashed a certain way, it won’t call out to Big Brother.

    It’s not exactly a fun experience, but I wouldn’t call it a massive problem either. More of a small headache.

    As far as Graphene goes, it goes down to literal hardware chips in your phone that drive security that are only found in certain devices, typically enterprise-style devices. It’s like a TPM chip in your computer.

    As far as security goes, there’s no competition. Graphene OS is the best, and that includes current modern OSes. Governments really fucking hate this OS and have been targeting people that have it on their phones Because there’s absolutely no backdoors and there’s no way to get the data off the phone, unlike a Google or an Apple device.

    • solrize@lemmy.ml
      link
      fedilink
      English
      arrow-up
      1
      ·
      edit-2
      5 days ago

      But I like my Moto G which has an SD slot, 3.5mm audio jack, more battery life, stylus, and easier to replace battery than a Pixel. So I’d rather not downgrade my phone just to run Graphene. Why would I want a TPM chip anyway? Those are mainly intended to enforce DRM. I can believe no backdoors in the OS, but no vulnerabilities in the hardware? That’s a stretch, think of the Intel management platform and everything else (https://tpm.fail/). If the hardware was really that secure, the govt would block its manufacture. There would also be no market in HSMs. I can believe in TPM slowing attackers down but that’s about it.

      Anyway I distrust my phone enough to not have anything super sensitive on it. I don’t think a TPM chip would change that. So I’m still skeptical.

      Do Graphene users really bother to enter a 128 bit decryption key to unlock their phone? How do they do it? I’ve thought of a few ways but am unfamiliar with anyone using them.

      • dastanktal@lemmy.ml
        link
        fedilink
        English
        arrow-up
        1
        ·
        5 days ago

        You know that Moto G is like a first-class supported phone on lineage, right? It seems like every one of their newest models is on lineage.

        I’m not sure where you got the idea that a TPM chip is used for DRM, because that is not their function. It’s a hardware encryption chip used to generate Cryptographically secure keys.

        DRM Enforcement works with or without these hardware chips being installed on your phone.

        You want something like the TPM chip because it makes your phone very difficult to break into when you do things like encrypt the entire drive. HSMs Are far more effective at securing your phone than the standard baseline security that you get from a CPU. This isn’t an opinion. This is a well-researched fact.

        You also are, I think, maybe conflating technological vulnerabilities? Also, you said phones call back to Big Brother intentionally. What you’re talking about are vulnerabilities that can be exploited that are not intentional features of the chip. Intel is kind of famous for their insecurity. There was a big fucking vulnerability their CPUs had due to a hardware bug like a decade ago that AMD managed to get by because they don’t use the same architecture. Now I do get what you’re coming at that these vulnerabilities probably exist on every model of phone, but it’s best to go for a phone os that’s actively trying to close all of these vulnerabilities rather than one that says they “exist on all phones, I don’t care”.

        I disagree with your assessment that the government wouldn’t shoot themselves in the foot by giving people a technology that would allow them to hide shit from the government. They have, and they do constantly. I mean, the US is kind of famous for having more firearms per capita than people. Also somebody has clearly never heard of the legend of TrueCrypt. There’s a reason the original developers ended up fucking off somewhere to obscurity, and the project is now VeraCrypt.

        Also, the government does want corporations to be able to protect their private information from foreign entities. That seems like it would be prudent for the US to be able to do. You know what I mean? They don’t want China all up in their business. In fact, it’s a big concern from the business perspective. So having something like a TPM chip on every laptop to encrypt all of your data is a good thing. And typically, that’s what the US wants. They just want a software backdoor To get at the data they want. They also have so much monitoring that it’s almost a moot point.

        As far as graphene users go, it’s secure enough that Various governments consider graphene phones a dead end when they collect them And I’m pretty sure the US has never been able to crack one As far as we are aware and we would definitely be aware because they would be stupid enough to sing it from the fucking mountaintops with this administration.

        I understand you’re skeptical, but there is a reason that Graphene is preferred by the security community. There is no competition for security. They are the best hands down. When you have various Western governments admitting that they can’t get into these phones, that’s as Good as a recommendation you can get. Notice how they aren’t bothered about Apple phones and Google phones. The governments hate graphene phones and are making it harder to get a hold of them.

        • solrize@lemmy.ml
          link
          fedilink
          English
          arrow-up
          2
          ·
          edit-2
          3 days ago

          Sorry for the slow reply. And wow, yeah, about Lineage, I checked yesterday and my current phone (Moto G Stylus 5G 2023) is now supported. This is new, it wasn’t there last time I looked some months ago. Not all of the G models are there now, and not so many very recent ones, but it’s nice that I now have a Lineage-capable phone. So I might switch over at some point, maybe after getting another phone in case the reinstall goes wrong.

          About Graphene, I have trouble believing “governments hate this one weird OS” and “Motorola is about to mass produce phones with the weird OS pre-installed” at the same time. And while I can admire a phone that resists a “govt seizes my phone” attack, that’s pretty far down my list of threats. Even skipping TPM vulnerabilities, the phone by design broadcasts its location everywhere it goes, spews metadata (even if not plaintext content) about everything it does on the network, is subject to supply chain attacks from every app getting periodic updates, etc. I’ve never understood how “frequent security patches” is supposed to indicate a secure app. If the app was secure it wouldn’t need patches. Tbh I haven’t travelled outside the US since before 2019, and if I do it again, I expect to leave my phone at home. I’ll bring a burner or a flip phone or something like that. What does the Graphene user do when the govt says “unlock your phone or we’ll arrest you”? See e.g. the guy being prosecuted for erasing his phone when border patrol wanted to examine it.

          AMD’s SEL stuff has vulnerabilities too. Intel put real effort into making SGX secure but oops. Even the IBM 4758 security processor, a very high end tamper reactive HSM that bricked itself on purpose if you breathed the wrong way, turned out to have protocol bugs. IDK about the current version if such a thing exists.

          The Graphene folks themselves say that the Motorola Graphene phone is intended for corporate and government customers who currently by Apple and Google phones, fwiw: https://grapheneos.social/@[email protected]/117136564050537120

          Yes TPM in PC’s was historically intended for DRM, thus the political opposition to it back in the day. “Trusted platform” meant that media companies could trust the machine to prevent the user from running unauthorized software, getting the keys out, etc. TPM’s use in Graphene still seems to be key encapsulation, but I don’t see the importance. I’d rather keep my file decryption key as a QR code on a slip of paper, so I unlock the phone by clicking the camera at the QR code. If I’m about to return from another country, I throw away the paper before getting on the plane, and then truthfully tell the border patrol that I have no way to unlock the phone there at the airport. They want the data after I unlock it at home? Fine, show me a warrant first. That’s about the best you can hope for with a Graphene phone anyway.

          Anyway if Moto makes a G series Graphene phone or other affordable model, I’m up for it, but I expect whatever they do will be closed and expensive.

          This might also be of interest, predicting another iteration of govt demanding mandatory backdoors in eerything: https://blog.cryptographyengineering.com/2026/08/14/everything-is-about-to-go-dark/

          • dastanktal@lemmy.ml
            link
            fedilink
            English
            arrow-up
            1
            ·
            2 days ago

            I mean, I understand the skepticism. I get the concerns and complaints you’re having.

            Personally, for me, I’ve done the research on how TPM chips work, and the encryption behind it, and generally find it to be very, very secure, and I’m perfectly comfortable using the technology. As far as needing it for graphene, I mean, yeah. If it’s used for security hardening, then yeah, they’re going to need it. Graphene developers are even highly critical of Debian security practices, and Linux security practices, and standard hardening. They’re like the experts at this. I’m going to very heavily trust what they have to say. I mean, they’re so overly critical. I mean, it’s actually kind of a point of contention in the open source community with how aggressive and obtuse the graphene developers can be over perceived security flaws.

            Graphene phones typically don’t “phone” home either. All that code was ripped out. Apps can still though.

            Even if you get in trouble of legally, I still like that feature of graphene. Also, the little trouble you get for wiping your phone will probably be worth depending on what your activities are Considering this administration is giving people 30 years for doing things like moving magazines.

            Didn’t know TPM was for DRM originally. Tech was a little before my time and had already rebranded.

            • solrize@lemmy.ml
              link
              fedilink
              English
              arrow-up
              2
              ·
              2 days ago

              Tbh the Graphene devs sound sort of like the OpenBSD devs. We’ve seen this before. It will be interesting to see what happens to the guy who wiped his phone at a border stop. He should have wiped it before getting on the plane, especially if he has a remote backup. With a Moto G phone he could of course put all the sensitive files on an SD card and then taken the card out of the phone.

              I also wonder if there are any obstacles to forking Graphene to remove the TPM dependency. That would hopefully allow installing it on any phone for which there is current Lineage support.

              I want to give up on smartphones altogether, and just bring a Raspberry Pi, maybe even just the board, scrounging a monitor and keyboard at the destination. One thing I like about the Pi is that it has no built in storage, just a card slot. So you know that if you remove the card, you haven’t still somehow left sensitive data in the built in storage. With a phone, you can’t be really sure.