<rss version="2.0" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:atom="http://www.w3.org/2005/Atom"><channel><title>Hacker News: HybridStatAnim8</title><link>https://news.ycombinator.com/user?id=HybridStatAnim8</link><description>Hacker News RSS</description><docs>https://hnrss.org/</docs><generator>hnrss v2.1.1</generator><lastBuildDate>Thu, 18 Jun 2026 03:13:50 +0000</lastBuildDate><atom:link href="https://hnrss.org/user?id=HybridStatAnim8" rel="self" type="application/rss+xml"></atom:link><item><title><![CDATA[New comment by HybridStatAnim8 in "GrapheneOS has been ported to Android 17"]]></title><description><![CDATA[
<p>For context, GMSCompat is Google Mobile Services Compatibility. GrapheneOS installed the google play store and services as normal apps, and worked backwards to make it behave. There is no google specific sandbox, rather it uses the standard android user app sandbox. This means google is bound by the same rules, as special casing anything creates more maintenance burden and attack surface. GMSCompat is fully open source.<p>> "Thanks, but there's no way..."<p>Its reposted because the information is accurate, and misinformation regarding it is very prevalent.<p>> "Yes, I knew it's in a sandbox..."<p>Relative to MicroG, sandboxed google play is much more private, secure, and usable. I would not describe it as a privacy paradise, but MicroG does not improve upon this, and instead makes these aspects worse.<p>> "The sandbox still needs internet access..."<p>Most google libraries operate independently of google services and do not depend on them to function. FCM is an exception due to how push notifications are optimized (by using one app for the connection). MicroG does not avoid this.<p>> "For example, Signal will actively reach..."<p>You do not need to provide an identity to google. This can also be avoided with a VPN, and is not specific to google. There is the concern of metadata but Signal sends empty notifications without any identifying info. They are only used to wake the app up to fetch its own notifications.<p>> "So while the sandbox is definitely very useful..."<p>It confines google services to the same rules and restrictions as all other apps. MicroG does not. MicroG also does not avoid running unwanted software, referring to the google libraries in apps and the google code MicroG downloads.<p>> "Do you know what privileged context means..."<p>MicroG violates the security model by necessitating signature spoofing, which puts it in a position to receive data it was not intended to receive, there is also attack surface exposed by having access forbidden by the app sandbox. Sandboxed google play is bound by the same app sandbox as all other apps, and would not be any more or less capable of exploiting the device than any other app. The idea that google would try to exploit the device is nonsensical though. But granting both google and a 3rd party privileged access is still unacceptable.<p>> "Rather than running the unwanted proprietary (but necessary) software..."<p>Google play services runs in the android user app sandbox. It is not an "attempt", it is successful at doing this. MicroG being open source does not matter in regards to privacy or security. It did not change how MicroG has leaked location to apps without location permissions, it does not change how it downloads and runs google code both privileged and outside of its own APK, and it does not change how other apps are running google libraries anyway. Note that the proprietary code it downloads is not confined to the app sandbox.<p>> "For example, microG will replace Gmaps..."<p>Im unsure if you are referring to the app Google Maps, or google maps integration. GrapheneOS reroutes googlefusedlocation requests to the OS, rather than google services. You can use an app other than google maps, and apps with google map integration can simply send your location to google directly, independent of google services or MicroG.<p>> "It seems fairly obvious to me that less data sharing..."<p>Googles access to data is not limited by using MicroG, relative to sandboxed google play. And the size of proprietary code is irrelevant, that code can be anything. It can be malicious with 2 lines, or benign with 2 million. Access is what is vital, not size. Google is not permitted to "run wild", and is granted no additional access compared to any other app. Im unsure what you mean by self updating functionality, but for apps from the playstore, nearly all of them are signed with a key that google holds, and MicroG can do nothing about this. GrapheneOSs App Store is responsible for updating google play and google services, it cannot update itself.<p>> "What threat would sandboxed microG pose that sandboxed GMS doesn't?..."<p>Using MicroG necessitates GrapheneOS violate the android security model, trust a 3rd party unnecessarily, cripple 99% perfect compatibility, use code that is not near as battletested as play services, run google code as privileged, and run a software that has had serious privacy violations in the past. Not only is the base insufficient, but any finished product based on it still would not compare to GMSCompat. The logic is that GrapheneOS wants the best compatibility, the least changes to the android app sandbox, 0 privileged google components, no violations to the android security model, and no need to maintain a reimplementation when google services and store are already maintained by a huge organization.</p>
]]></description><pubDate>Thu, 18 Jun 2026 01:40:56 +0000</pubDate><link>https://news.ycombinator.com/item?id=48579506</link><dc:creator>HybridStatAnim8</dc:creator><comments>https://news.ycombinator.com/item?id=48579506</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=48579506</guid></item><item><title><![CDATA[New comment by HybridStatAnim8 in "Volkswagen started blocking GrapheneOS users"]]></title><description><![CDATA[
<p>Im not disputing the ability to use the device for many years. Using the device for a long time and the device being supported for a long time are different things.<p>Fairphone doesnt make their own phones, its outsourced to an ODM and Fairphone has very little input on how its designed. They havent "sourced" anything. Fairphone also stops providing kernel updates very quickly and delays userspace/driver/firmware backports for months. They delay yearly updates for years too. This doesnt even touch upon the fact they used public signing keys in the past.<p>It is not derogatory to say that it is e-waste out of the box, it is simply accurate. Choosing to continue using it despite how unsafe it is does not change the abysmal support it is given. A modern iPhone/android used from launch to the end of its 7 year support time, then properly recycled, would be far better for privacy, security, and for the environment. A support window that long would also provide a strong used market to continue using these devices. Cheap ODM phones with short support windows, and not benefiting from economies of scale, is a waste.</p>
]]></description><pubDate>Thu, 18 Jun 2026 00:48:13 +0000</pubDate><link>https://news.ycombinator.com/item?id=48579107</link><dc:creator>HybridStatAnim8</dc:creator><comments>https://news.ycombinator.com/item?id=48579107</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=48579107</guid></item><item><title><![CDATA[New comment by HybridStatAnim8 in "GrapheneOS has been ported to Android 17"]]></title><description><![CDATA[
<p>You cant respond to any opinion because I have not provided any. Security is objective. What security someone may need can vary, yes, but that does not change how the security of a device works. You are downplaying serious issues and claiming features that nearly everyone benefits from are unnecessary.<p>Every month, vulnerabilities are published and publicly accessible. The more out of date a device becomes, the more vulnerabilities are available. This is made worse when the integrity of the operating system cannot be verified and root access is exposed. Avoiding this is not a high level threat model, that is the bare minimum.</p>
]]></description><pubDate>Thu, 18 Jun 2026 00:27:38 +0000</pubDate><link>https://news.ycombinator.com/item?id=48578922</link><dc:creator>HybridStatAnim8</dc:creator><comments>https://news.ycombinator.com/item?id=48578922</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=48578922</guid></item><item><title><![CDATA[New comment by HybridStatAnim8 in "Volkswagen started blocking GrapheneOS users"]]></title><description><![CDATA[
<p>To start, all attestation is remote. It fundamentally has to be remote, be it a server or another device.<p>GrapheneOS points out how its improved privacy and security should mean that it is accepted in a system like play integrity. But this is just to outline how flawed the logic of play integrity is. It is by no means an endorsement of play integrity. GrapheneOS wants people to know that google is lying and breaking the law, and uses its own exclusion as that evidence. Even if GrapheneOS were accepted into play integrity, it would still exclude any and all forks and self-signed builds of GOS, which is unacceptable. If companies absolutely insist on using this approach despite its flaws, they should use the generic attestation available in android, and permit using 3rd party roots of trust in some form, rather than outsourcing this verification to 3rd parties like google.<p>As for the pinned attestation approach, that is Trust On First Use, and is used to verify the integrity of a device based on the security of the devices early bootchain. The initial attestation is what future attestation is pinned to. This allows you to verify a device is the same one, it has not been downgraded, has not been tampered with, etc. This is awesome, and lets you do things like what GrapheneOS does with Auditor. But this is not used to restrict what operating systems are used. Root based attestation somewhat tries to resolve the Trust On First Use approach, but is used to arbitrarily ban operating systems in practice. It is super flimsy as any leaked keys can bypass it.<p>My only concern is your claim that GrapheneOS is for this technology when it is most certainly against it. The nuance is that pinned attestation is a different approach with different properties, and advocating for it does not mean GrapheneOS is not an ally against play integrity.<p>Auditor also functions as a proof of concept for the potential of attestation, check here for more info: <a href="https://attestation.app/about" rel="nofollow">https://attestation.app/about</a></p>
]]></description><pubDate>Thu, 18 Jun 2026 00:16:07 +0000</pubDate><link>https://news.ycombinator.com/item?id=48578840</link><dc:creator>HybridStatAnim8</dc:creator><comments>https://news.ycombinator.com/item?id=48578840</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=48578840</guid></item><item><title><![CDATA[New comment by HybridStatAnim8 in "GrapheneOS has been ported to Android 17"]]></title><description><![CDATA[
<p>Most of this is not related to the claim and is more tangential discussion about things you like that run on the linux kernel, now, there is nothing wrong with that, but I must emphasise that none of what you describe is a part of the criteria for what constitutes a linux distro. A linux distro is an operating system using the linux kernel. Android fits that criteria.<p>The policies and applications running on top of or in the linux kernel do not change its distro classification. Lacking root access is a massive step forward for privacy and security. Root access is insecure and a hacky shortcut to proper functionality.</p>
]]></description><pubDate>Wed, 17 Jun 2026 23:15:42 +0000</pubDate><link>https://news.ycombinator.com/item?id=48578337</link><dc:creator>HybridStatAnim8</dc:creator><comments>https://news.ycombinator.com/item?id=48578337</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=48578337</guid></item><item><title><![CDATA[New comment by HybridStatAnim8 in "GrapheneOS has been ported to Android 17"]]></title><description><![CDATA[
<p>MicroG requires privileged access. It also downloads and runs proprietary google code within this privileged context. MicroG additionally has very poor app compatibility and has had severe privacy issues in the past.<p>Sandboxed google play does not grant google code any kind of privileged access. It is confined to the same app sandbox and permission model as all other apps and can be installed and uninstalled like any other app.<p>Note that apps with google libraries grant google the same, unprivileged access google services gets on GrapheneOS. MicroG fails to meet the privacy, security, and usability requirements GrapheneOS has in place when it comes to google play compatibility.<p>So, you can pick MicroG, which is bundled, privileged, poorly made, has poor compatibility, and trusts an additional party...<p>Or, you can pick sandboxed google play, which is not bundled, optional, unprivileged, fully sandboxed, and does not trust additional parties. Oh, and you can uninstall and reinstall whenever.<p>It is evident which option gives the user freedom, and a choice.</p>
]]></description><pubDate>Wed, 17 Jun 2026 22:18:13 +0000</pubDate><link>https://news.ycombinator.com/item?id=48577729</link><dc:creator>HybridStatAnim8</dc:creator><comments>https://news.ycombinator.com/item?id=48577729</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=48577729</guid></item><item><title><![CDATA[New comment by HybridStatAnim8 in "Volkswagen started blocking GrapheneOS users"]]></title><description><![CDATA[
<p>GrapheneOS has 99% app compatibility with sandboxed google play. Apps do not have issues with sandboxed google play at this time.</p>
]]></description><pubDate>Wed, 17 Jun 2026 21:51:33 +0000</pubDate><link>https://news.ycombinator.com/item?id=48577406</link><dc:creator>HybridStatAnim8</dc:creator><comments>https://news.ycombinator.com/item?id=48577406</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=48577406</guid></item><item><title><![CDATA[New comment by HybridStatAnim8 in "Volkswagen started blocking GrapheneOS users"]]></title><description><![CDATA[
<p>Note that I am a GrapheneOS supporter. You seem to have a few misconceptions.<p>GrapheneOS is one of, if not the most vocal organization against the abuse of attestation mechanisms. GrapheneOS and its userbase feel the consequences of play integrity every single day.<p>Im not sure where you got the idea that all GrapheneOS wants is to be accepted by play integrity, because that is not the case. GrapheneOS has been working with regulators to get play integrity banned. Being accepted by play integrity, but nothing else changing, is not good enough for GrapheneOS. It would only be a small victory along the path of abolishing this nonsense.<p>So, no, GrapheneOS and its community are definitely against play integrity. The "signs" that they are "starting to notice" are not there. They are already fully aware of what attestation is and how it can be abused. They are definitely not ignorant on the subject.<p>You might be confusing root based attestation with pinned attestation. Root based attestation is flimsy and allows tools like play integrity to ban operating systems they do not like. Pinned attestation, on the other hand, has real security properties and cannot be abused to block certain operating systems. GrapheneOS uses pinned attestation as a part of their Auditor app, and it has other cool uses we could see in the future.</p>
]]></description><pubDate>Wed, 17 Jun 2026 21:48:07 +0000</pubDate><link>https://news.ycombinator.com/item?id=48577362</link><dc:creator>HybridStatAnim8</dc:creator><comments>https://news.ycombinator.com/item?id=48577362</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=48577362</guid></item><item><title><![CDATA[New comment by HybridStatAnim8 in "Volkswagen started blocking GrapheneOS users"]]></title><description><![CDATA[
<p>Note that Fairphone does not provide software updates for anywhere near as long as they claim, and using a modern device with 7 years of support, such as a pixel or iphone, will be far better in the long term. Fairphone is basically e-waste out of the box.</p>
]]></description><pubDate>Wed, 17 Jun 2026 21:29:16 +0000</pubDate><link>https://news.ycombinator.com/item?id=48577173</link><dc:creator>HybridStatAnim8</dc:creator><comments>https://news.ycombinator.com/item?id=48577173</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=48577173</guid></item><item><title><![CDATA[New comment by HybridStatAnim8 in "Volkswagen started blocking GrapheneOS users"]]></title><description><![CDATA[
<p>The legal definition of the OS does not matter at all when considering the difference between failing to support something, and using a tool that explicitly stops something from working that otherwise works without issue. Play integrity is a tool which does not base any of its certification decisions in privacy or security, rather leverages it for anticompetitive reasons. This is known and trivially verifiable.<p>I do know what these terms mean in a legal context. I am claiming that play integrity is an anticompetitive and monopolistic tool, of which VW decided to use. I am not claiming VW is a monopoly. What you are claiming is their right to do, is not their right at all, and is illegal.</p>
]]></description><pubDate>Wed, 17 Jun 2026 19:23:43 +0000</pubDate><link>https://news.ycombinator.com/item?id=48575473</link><dc:creator>HybridStatAnim8</dc:creator><comments>https://news.ycombinator.com/item?id=48575473</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=48575473</guid></item><item><title><![CDATA[New comment by HybridStatAnim8 in "GrapheneOS has been ported to Android 17"]]></title><description><![CDATA[
<p>GrapheneOS is designed for everyone, including average users. It does not require a high threat model, and the features it provides are not only useful to people with high threat models.<p>Contrary to popular belief, exploitation of vulnerable devices is a lot more common, and a lot easier than people pretend it is. You dont need to be targeted either, mass exploitation can, has, and will occur.<p>LineageOS does not have privacy, security, or usability comparable to GrapheneOS. LineageOS is missing many important features and falls behind android updates. GrapheneOS will be the far better choice in all 3 of these categories.<p>The features GrapheneOS provides, such as the network permission, cannot be replicated with a firewall app. The network permission properly covers all forms of network access for an app, where firewall apps do not have the ability to prevent all network communication. They are leaky.<p>The AGNSS servers and proxies are very, very tiny aspects of what GrapheneOS provides. You would be losing out on many more high impact privacy, security, and usability features.<p>Root access and an unlocked bootloader are insecure, even for low threat models. These devices are vulnerable and should not be used for any sensitive data.<p>LineageOS is not the better choice for any privacy, security, or usability usecases relative to GrapheneOS.</p>
]]></description><pubDate>Wed, 17 Jun 2026 19:15:09 +0000</pubDate><link>https://news.ycombinator.com/item?id=48575342</link><dc:creator>HybridStatAnim8</dc:creator><comments>https://news.ycombinator.com/item?id=48575342</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=48575342</guid></item><item><title><![CDATA[New comment by HybridStatAnim8 in "Volkswagen started blocking GrapheneOS users"]]></title><description><![CDATA[
<p>GrapheneOS requires a locked bootloader and supports using deveice attestation via the generic attestation functionality in the Android Open Source Project.<p>Play integrity is an anticompetitive tool that ignores this, and artificially limits itself on GrapheneOS. It is not due to any incompatibility.</p>
]]></description><pubDate>Wed, 17 Jun 2026 18:14:42 +0000</pubDate><link>https://news.ycombinator.com/item?id=48574376</link><dc:creator>HybridStatAnim8</dc:creator><comments>https://news.ycombinator.com/item?id=48574376</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=48574376</guid></item><item><title><![CDATA[New comment by HybridStatAnim8 in "Volkswagen started blocking GrapheneOS users"]]></title><description><![CDATA[
<p>GrapheneOS is based on the Android Open Source Project and retains near perfect android app compatibility. It cannot call itself android for legal reasons, but the legal definition does not affect its app compatibility.<p>Tools such as play integrity are illegal. Using anticompetitive and monopolistic tools is not the right of application developers.</p>
]]></description><pubDate>Wed, 17 Jun 2026 18:01:18 +0000</pubDate><link>https://news.ycombinator.com/item?id=48574182</link><dc:creator>HybridStatAnim8</dc:creator><comments>https://news.ycombinator.com/item?id=48574182</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=48574182</guid></item><item><title><![CDATA[New comment by HybridStatAnim8 in "Volkswagen started blocking GrapheneOS users"]]></title><description><![CDATA[
<p>The basis of your argument, that users want these developers to support another platform, does not make sense, because GrapheneOS does not require apps add explicit support for it. GrapheneOS has 99% android app compatibility.<p>The issue is not that this application isnt tested on GOS, its that an anticompetitive, illegal tool is being used to ban non-certified OSs when these apps would work perfectly otherwise.</p>
]]></description><pubDate>Wed, 17 Jun 2026 17:58:44 +0000</pubDate><link>https://news.ycombinator.com/item?id=48574153</link><dc:creator>HybridStatAnim8</dc:creator><comments>https://news.ycombinator.com/item?id=48574153</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=48574153</guid></item><item><title><![CDATA[New comment by HybridStatAnim8 in "Volkswagen started blocking GrapheneOS users"]]></title><description><![CDATA[
<p>GrapheneOS maintains 99% android app compatibility. It does not require any additional funding or expenses to support GrapheneOS, and is actually more expensive to add these anticompetitive tools responsible for banning GrapheneOS.<p>GrapheneOS is also not responsible for bugs in this app. Any bug reports coming from GOS are likely to be from the hardening toggles, which uncover bugs in the app. This is the apps fault, and these bugs still exist on other OSs. It should be resolved for the benefit of all users.</p>
]]></description><pubDate>Wed, 17 Jun 2026 17:50:07 +0000</pubDate><link>https://news.ycombinator.com/item?id=48573992</link><dc:creator>HybridStatAnim8</dc:creator><comments>https://news.ycombinator.com/item?id=48573992</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=48573992</guid></item><item><title><![CDATA[New comment by HybridStatAnim8 in "Volkswagen started blocking GrapheneOS users"]]></title><description><![CDATA[
<p>The funny thing is, nothing needs to be done to support GOS. GOS has 99% android app compatibility. The issue isnt that GOS requires changes in the app to support it, rather, the tools they are using explicitly ban non-certified OSs.<p>Dont let their boilerplate responses fool you, tools like play integrity only serve to push anticompetitive practices. The claims about not being able to support GOS are nonsense, and all they did was break existing support.</p>
]]></description><pubDate>Wed, 17 Jun 2026 17:42:51 +0000</pubDate><link>https://news.ycombinator.com/item?id=48573889</link><dc:creator>HybridStatAnim8</dc:creator><comments>https://news.ycombinator.com/item?id=48573889</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=48573889</guid></item><item><title><![CDATA[New comment by HybridStatAnim8 in "Volkswagen started blocking GrapheneOS users"]]></title><description><![CDATA[
<p>GrapheneOS has an official partnership with a large OEM (Motorola), has near perfect app compatibility, is constantly improving upon user experience, and has been well known and regarded in the privsec community and by many trusted security experts. It appears to be gaining more mainstream awareness as a result.<p>Oh, and Android 17 has been released so there is hype for that.</p>
]]></description><pubDate>Wed, 17 Jun 2026 17:35:26 +0000</pubDate><link>https://news.ycombinator.com/item?id=48573780</link><dc:creator>HybridStatAnim8</dc:creator><comments>https://news.ycombinator.com/item?id=48573780</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=48573780</guid></item><item><title><![CDATA[New comment by HybridStatAnim8 in "Volkswagen started blocking GrapheneOS users"]]></title><description><![CDATA[
<p>It is far more likely that it is due to scams and grifts that pretend to be GrapheneOS, associated with GrapheneOS, or based on GrapheneOS, rather than GrapheneOS itself. Criminals tend to be not that bright.</p>
]]></description><pubDate>Wed, 17 Jun 2026 17:31:33 +0000</pubDate><link>https://news.ycombinator.com/item?id=48573720</link><dc:creator>HybridStatAnim8</dc:creator><comments>https://news.ycombinator.com/item?id=48573720</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=48573720</guid></item><item><title><![CDATA[New comment by HybridStatAnim8 in "GrapheneOS has been ported to Android 17"]]></title><description><![CDATA[
<p>No, them supporting e/OS corroborates the claim that their goal is not privacy or security.</p>
]]></description><pubDate>Wed, 17 Jun 2026 15:49:37 +0000</pubDate><link>https://news.ycombinator.com/item?id=48572165</link><dc:creator>HybridStatAnim8</dc:creator><comments>https://news.ycombinator.com/item?id=48572165</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=48572165</guid></item><item><title><![CDATA[New comment by HybridStatAnim8 in "GrapheneOS has been ported to Android 17"]]></title><description><![CDATA[
<p>Android similarly supports, and in fact uses, "proper" Linux. Android and its forks are Linux distributions. You can use a mainline kernel in Android just fine.</p>
]]></description><pubDate>Wed, 17 Jun 2026 15:44:31 +0000</pubDate><link>https://news.ycombinator.com/item?id=48572077</link><dc:creator>HybridStatAnim8</dc:creator><comments>https://news.ycombinator.com/item?id=48572077</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=48572077</guid></item></channel></rss>