<rss version="2.0" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:atom="http://www.w3.org/2005/Atom"><channel><title>Hacker News: tholdem</title><link>https://news.ycombinator.com/user?id=tholdem</link><description>Hacker News RSS</description><docs>https://hnrss.org/</docs><generator>hnrss v2.1.1</generator><lastBuildDate>Sun, 12 Apr 2026 07:24:50 +0000</lastBuildDate><atom:link href="https://hnrss.org/user?id=tholdem" rel="self" type="application/rss+xml"></atom:link><item><title><![CDATA[New comment by tholdem in "Comparing Android Alternatives: Lineage OS, ∕E∕OS, and Graphene OS"]]></title><description><![CDATA[
<p>I am currently using 4 banking apps from 3 different banks on GrapheneOS, they all work just fine. I'm also using WhatsApp and would not use the backup feature to Google Drive even on PixelOS. Uber (haven't tried the for drivers app), and other ride hauling apps also work fine.<p>Why would I choose LineageOS instead of GrapheneOS? I can't see any benefits in using LineageOS, I only see major drawbacks.<p>Why is it always 0 or 1 with privacy? Why can't I use GrapheneOS with sandboxed Google Play Services? Seems like the best option. I can still use all the apps I want and also get privacy and security benefits. I only give Google what I want and still get to live like a normal person, without making huge compromises on security, privacy, usability and GrapheneOS has been the most stable OS I've used. More stable than the stock PixelOS.</p>
]]></description><pubDate>Tue, 18 Nov 2025 17:49:42 +0000</pubDate><link>https://news.ycombinator.com/item?id=45969617</link><dc:creator>tholdem</dc:creator><comments>https://news.ycombinator.com/item?id=45969617</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=45969617</guid></item><item><title><![CDATA[New comment by tholdem in "F-Droid and Google’s developer registration decree"]]></title><description><![CDATA[
<p>Yes, all notifications work fine with sandboxed Play Services installed. All my banking apps also work fine. I haven't really had any problems with app support or any other problems for the many years I've run GrapheneOS as my daily driver.</p>
]]></description><pubDate>Tue, 30 Sep 2025 15:21:53 +0000</pubDate><link>https://news.ycombinator.com/item?id=45426690</link><dc:creator>tholdem</dc:creator><comments>https://news.ycombinator.com/item?id=45426690</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=45426690</guid></item><item><title><![CDATA[New comment by tholdem in "Introduction to GrapheneOS"]]></title><description><![CDATA[
<p>What are these technical solutions?</p>
]]></description><pubDate>Sat, 20 Sep 2025 12:40:04 +0000</pubDate><link>https://news.ycombinator.com/item?id=45312873</link><dc:creator>tholdem</dc:creator><comments>https://news.ycombinator.com/item?id=45312873</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=45312873</guid></item><item><title><![CDATA[New comment by tholdem in "Introduction to GrapheneOS"]]></title><description><![CDATA[
<p>If you allow root, there is no need for additional privEsc exploit. Also does LineageOS actually ship security patches reliably for software and firmware? How is Magisk helping to resist attacks?</p>
]]></description><pubDate>Sat, 20 Sep 2025 12:39:41 +0000</pubDate><link>https://news.ycombinator.com/item?id=45312870</link><dc:creator>tholdem</dc:creator><comments>https://news.ycombinator.com/item?id=45312870</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=45312870</guid></item><item><title><![CDATA[New comment by tholdem in "Introduction to GrapheneOS"]]></title><description><![CDATA[
<p>If you are fine running an OS with horrible security and privacy, then LineageOS and it's forks are fine. If you want the best privacy and security, then GrapheneOS is the best option.</p>
]]></description><pubDate>Mon, 15 Sep 2025 13:42:19 +0000</pubDate><link>https://news.ycombinator.com/item?id=45249667</link><dc:creator>tholdem</dc:creator><comments>https://news.ycombinator.com/item?id=45249667</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=45249667</guid></item><item><title><![CDATA[New comment by tholdem in "Introduction to GrapheneOS"]]></title><description><![CDATA[
<p>This just doesn't work the way you think, this mentality is not just outdated, but dangerous. People who think like that are more subject to "low IQ" attacks than people who accept the fact they are subject to the same "low IQ" attacks that work on everybody. You are overly confident. You can't be 100% alert and suspicious 24/7, around the clock. At some point you are tired, your attention is elsewhere or you are just not up-to-date on the latest techniques that attackers combine with some form of social engineering.<p>Also no matter how technical you are, it's almost impossible for you to detect zero-click 0days for which you are more vulnerable to than people without root privileges. You running rooted OS actually become easier and less costly target than people without rooted OS.</p>
]]></description><pubDate>Mon, 15 Sep 2025 08:32:58 +0000</pubDate><link>https://news.ycombinator.com/item?id=45247427</link><dc:creator>tholdem</dc:creator><comments>https://news.ycombinator.com/item?id=45247427</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=45247427</guid></item><item><title><![CDATA[New comment by tholdem in "Some users have noticed settings that let Meta analyze and retain phone photos"]]></title><description><![CDATA[
<p>Maybe once the ads start showing on Whatsapp it gets easier to convince people to switch.</p>
]]></description><pubDate>Fri, 29 Aug 2025 14:43:31 +0000</pubDate><link>https://news.ycombinator.com/item?id=45064798</link><dc:creator>tholdem</dc:creator><comments>https://news.ycombinator.com/item?id=45064798</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=45064798</guid></item><item><title><![CDATA[New comment by tholdem in "Google will allow only apps from verified developers to be installed on Android"]]></title><description><![CDATA[
<p>No root is a major security feature, you have chosen an OS that prioritizes security.<p>Use some other browser if dark mode is really important to you.<p>I think the launcher is good and I can't think of anything to improve on it. I'm happy it's the default, but I'm sure you can switch to a different launcher if you want.<p>Pattern unlock is also not there because of security.</p>
]]></description><pubDate>Tue, 26 Aug 2025 15:55:11 +0000</pubDate><link>https://news.ycombinator.com/item?id=45028288</link><dc:creator>tholdem</dc:creator><comments>https://news.ycombinator.com/item?id=45028288</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=45028288</guid></item><item><title><![CDATA[New comment by tholdem in "Graphene OS: a security-enhanced Android build"]]></title><description><![CDATA[
<p>So you're saying don't use a smartphone at all, which isn't possible, or use CalyxOS, which not only suffers from the same "problems" you criticize in GrapheneOS, but is also inferior in every way when it comes to security and privacy?<p>This does not make sense at all.</p>
]]></description><pubDate>Fri, 25 Jul 2025 10:24:13 +0000</pubDate><link>https://news.ycombinator.com/item?id=44681609</link><dc:creator>tholdem</dc:creator><comments>https://news.ycombinator.com/item?id=44681609</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=44681609</guid></item><item><title><![CDATA[New comment by tholdem in "Graphene OS: a security-enhanced Android build"]]></title><description><![CDATA[
<p>Why do you think that's interesting? Google is highly respected for its security practices. Do you think Apple engineers use some special hardened iOS?</p>
]]></description><pubDate>Fri, 25 Jul 2025 10:14:31 +0000</pubDate><link>https://news.ycombinator.com/item?id=44681552</link><dc:creator>tholdem</dc:creator><comments>https://news.ycombinator.com/item?id=44681552</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=44681552</guid></item><item><title><![CDATA[New comment by tholdem in "Graphene OS: a security-enhanced Android build"]]></title><description><![CDATA[
<p>Your logic seems to fall apart here.<p>> an operating system which essentially handles all of your private data.<p>This is exactly why one should continue using GrapheneOS as it is by far the best, most secure and private option. If you do not agree with one project member about something that is not related to the technical features of the project, it does not matter, since you can not be targeted with any GOS updates. Same updates would have to go to all GOS users and as stated before, the previous project leader has a stellar reputation when it comes to their work and prior actions regarding users security and privacy.<p>> the artist being "Google" and all their controversial practices<p>You believing this is a problem, you should then be using an iPhone anyway.<p>You are worrying GOS devs might push a malicious update, even when there are no proofs of that happening? What prevents the same from happening with other projects that are already inferior in every way? You are implying people should switch to less secure options because of this one thing that also applies to all other options? It does not make any sense and seems dishonest.</p>
]]></description><pubDate>Fri, 25 Jul 2025 09:58:42 +0000</pubDate><link>https://news.ycombinator.com/item?id=44681459</link><dc:creator>tholdem</dc:creator><comments>https://news.ycombinator.com/item?id=44681459</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=44681459</guid></item><item><title><![CDATA[New comment by tholdem in "Graphene OS: a security-enhanced Android build"]]></title><description><![CDATA[
<p>You don't need to wipe the phone when updating GrapheneOS. It's as painless as on stock Pixel OS. OTAs downloaded and installed on the background, just reboot the phone after.</p>
]]></description><pubDate>Fri, 25 Jul 2025 09:28:39 +0000</pubDate><link>https://news.ycombinator.com/item?id=44681280</link><dc:creator>tholdem</dc:creator><comments>https://news.ycombinator.com/item?id=44681280</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=44681280</guid></item><item><title><![CDATA[New comment by tholdem in "GrapheneOS needs OEM partner access"]]></title><description><![CDATA[
<p>There is so much misinformation about GrapheneOS. Other hardware is not supported for very good reasons. Mainly because the most basic security features are simply not available on other hardware. Google goes out of their way to support other operating systems with proper verified boot using custom signing keys. Also Pixels have proper dedicated security module, Titan M, which I believe are missing from most, if not all other options. Also MTE support. Hardware security is important and none of the current options match Pixels.</p>
]]></description><pubDate>Thu, 12 Jun 2025 06:39:16 +0000</pubDate><link>https://news.ycombinator.com/item?id=44254817</link><dc:creator>tholdem</dc:creator><comments>https://news.ycombinator.com/item?id=44254817</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=44254817</guid></item><item><title><![CDATA[New comment by tholdem in "Washington Post's Privacy Tip: Stop Using Chrome, Delete Meta Apps (and Yandex)"]]></title><description><![CDATA[
<p>You are implying Meta and others were able to just siphon data from any website via WebRTC using their native apps, but this was not the case. They were only able to track which websites you visited if that website already embedded the company tracking. Many websites do, but not all.</p>
]]></description><pubDate>Sun, 08 Jun 2025 15:50:24 +0000</pubDate><link>https://news.ycombinator.com/item?id=44217695</link><dc:creator>tholdem</dc:creator><comments>https://news.ycombinator.com/item?id=44217695</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=44217695</guid></item><item><title><![CDATA[New comment by tholdem in "Daily driving a Linux phone, but why?"]]></title><description><![CDATA[
<p>How can you compare iOS or Android security with desktop Linux security?<p>Have you checked what it takes to achieve those 0-click root exploits on iOS or Android compared to a desktop Linux distro?<p>Not even in the same league.</p>
]]></description><pubDate>Fri, 25 Apr 2025 11:54:25 +0000</pubDate><link>https://news.ycombinator.com/item?id=43792643</link><dc:creator>tholdem</dc:creator><comments>https://news.ycombinator.com/item?id=43792643</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=43792643</guid></item><item><title><![CDATA[New comment by tholdem in "Daily driving a Linux phone, but why?"]]></title><description><![CDATA[
<p>Yes, but this was about Silverblue and how it implements some additional sandboxing, which it doesn't. SELinux is great, but maintaining it and creating configs is huge amount of work and where on AOSP, every process is strictly confined with SELinux, on Fedora, not so much. Not to mention the additional software the user installs. Not at all comparable to real Android or iOS sandboxing.</p>
]]></description><pubDate>Fri, 25 Apr 2025 07:17:00 +0000</pubDate><link>https://news.ycombinator.com/item?id=43791060</link><dc:creator>tholdem</dc:creator><comments>https://news.ycombinator.com/item?id=43791060</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=43791060</guid></item><item><title><![CDATA[New comment by tholdem in "Daily driving a Linux phone, but why?"]]></title><description><![CDATA[
<p>It may be in the future, but for now it is no different from Fedora Workstation in terms of security. Please correct me if I am wrong. AFAIK Silverblue has no additional sandboxing or any other improvements to security.</p>
]]></description><pubDate>Thu, 24 Apr 2025 17:29:54 +0000</pubDate><link>https://news.ycombinator.com/item?id=43785262</link><dc:creator>tholdem</dc:creator><comments>https://news.ycombinator.com/item?id=43785262</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=43785262</guid></item><item><title><![CDATA[New comment by tholdem in "Daily driving a Linux phone, but why?"]]></title><description><![CDATA[
<p>Sandboxing should be built in and by default, not DIY and glued on, like with apparmor and firejail.<p>"Your car does not come with a seatbelt? Seatbelt parts are easy to order online and assembled on any car, it's your fault for not using one."<p>> Also the very same npm backdoors have already hit android apps. What can sandboxing do if you backdoor a dependency of your banking app?<p>The whole point of sandboxing is that one compromised app can not compromise the whole system and other apps. Compromised dependency on my banking app on Android or iOS only compromises that banking app and nothing else.</p>
]]></description><pubDate>Thu, 24 Apr 2025 16:01:36 +0000</pubDate><link>https://news.ycombinator.com/item?id=43784306</link><dc:creator>tholdem</dc:creator><comments>https://news.ycombinator.com/item?id=43784306</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=43784306</guid></item><item><title><![CDATA[New comment by tholdem in "Apple pulls data protection tool after UK government security row"]]></title><description><![CDATA[
<p>> What concerns me more is that Apple is the only company audibly making a stand.<p>But still Apple operates in China and Google does not. This is weird to me. Google left China when the government wanted all keys to the citizens data. Apple is making a stand when it's visible and does not threaten their business too much.<p>Apple is not really in the business of protecting your data, they are just good at marketing and keeping their image.</p>
]]></description><pubDate>Fri, 21 Feb 2025 19:09:47 +0000</pubDate><link>https://news.ycombinator.com/item?id=43131589</link><dc:creator>tholdem</dc:creator><comments>https://news.ycombinator.com/item?id=43131589</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=43131589</guid></item><item><title><![CDATA[New comment by tholdem in "New speculative attacks on Apple CPUs"]]></title><description><![CDATA[
<p>No need to turn JS off. Turn on Lockdown mode which disables Javascript JIT and WASM, which might be enough</p>
]]></description><pubDate>Wed, 29 Jan 2025 14:00:23 +0000</pubDate><link>https://news.ycombinator.com/item?id=42864953</link><dc:creator>tholdem</dc:creator><comments>https://news.ycombinator.com/item?id=42864953</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=42864953</guid></item></channel></rss>