Discussion
Loading...

#Tag

Log in
  • About
  • Code of conduct
  • Privacy
  • Users
  • Instances
  • About Bonfire
joene extra boosted
joene extra
joene extra
@joeneXtra@todon.eu  ·  activity timestamp 7 days ago

❔ Vraagjes aan IT-nerds in de Lage Landen. Als ik #GrapheneOS wil gebruiken, dan heb ik een $%%&!3 #Pixel nodig. Die kan je refurbished kopen zie ik. Als ik zo naar de prijs kijk past een Pixel 7 of liefst 8 wel binnen mijn budget.

Vragen:

1. Wat is de beste plek/site voor zo'n refurbished Pixel?
2. Heb ik iets over het hoofd gezien en zijn die Pixels ook ergens anders te krijgen?

#tech #android

  • Copy link
  • Flag this post
  • Block
joene extra
joene extra
@joeneXtra@todon.eu  ·  activity timestamp 7 days ago

❔ Vraagjes aan IT-nerds in de Lage Landen. Als ik #GrapheneOS wil gebruiken, dan heb ik een $%%&!3 #Pixel nodig. Die kan je refurbished kopen zie ik. Als ik zo naar de prijs kijk past een Pixel 7 of liefst 8 wel binnen mijn budget.

Vragen:

1. Wat is de beste plek/site voor zo'n refurbished Pixel?
2. Heb ik iets over het hoofd gezien en zijn die Pixels ook ergens anders te krijgen?

#tech #android

joene extra
joene extra
@joeneXtra@todon.eu replied  ·  activity timestamp 7 days ago

❔️ Nog een aanvullende vraag. Hoe werkt #GrapheneOS met #DigiID en Nederlandse bank-apps (#Triodios in mijn geval)?

  • Copy link
  • Flag this comment
  • Block
joene extra
joene extra
@joeneXtra@todon.eu  ·  activity timestamp 7 days ago

❔ Vraagjes aan IT-nerds in de Lage Landen. Als ik #GrapheneOS wil gebruiken, dan heb ik een $%%&!3 #Pixel nodig. Die kan je refurbished kopen zie ik. Als ik zo naar de prijs kijk past een Pixel 7 of liefst 8 wel binnen mijn budget.

Vragen:

1. Wat is de beste plek/site voor zo'n refurbished Pixel?
2. Heb ik iets over het hoofd gezien en zijn die Pixels ook ergens anders te krijgen?

#tech #android

  • Copy link
  • Flag this post
  • Block
Sabrina Web :privacypride: 📎 boosted
Fabio Manganiello
Fabio Manganiello
@fabio@manganiello.eu  ·  activity timestamp last week

#CandyCrush can bring #ICE agents to your door.

ICE has bought access to some surveillance tools developed by Penlink.

If you read the description of that company on their website you’ll find an overdose of fluffy and probably AI-generated corporate jargon that doesn’t mean anything:

Penlink is a global leader in digital intelligence solutions. Our compliant and certified solutions simplify complex data, empowering public safety and organizations to make informed decisions quickly and effectively. We believe in the power of data-driven intelligence to accelerate clarity in decision-making for global security, strategic operations, and the most critical missions.

In short: they make tools to spy on people. Through their mobile phones.

And it’s not like they do any kind of rocket science. They have some boring location trackers injected in a bunch of crappy ads SDKs used by some crappy free apps on the Google and Apple stores.

Commercial location data collected through trackers voluntarily installed by people on their phones can be queried without a warrant. Or it can be sold to data brokers, who in turn can resell it to whoever they want.

The list of impacted apps found so far is publicly available here. 12,373 apps at the time of writing.

The list includes mostly games (some Candy Crush and Angry Birds releases, many card games and solitaires, gambling/casino games, sudokus, football simulators etc.).

But it also includes photo editors, weather apps, pregnancy date calculators, network speed analyzers, many VPN apps, and many apps most likely used by foreigners (there are many local Arabic, Chinese, Spanish, Italian and Indian apps in the list).

Among those that caught my eye: Vinted, Flightradar24 and IlMeteo.

My two cents, especially if you are an American citizen:

  1. Avoid apps installed through the Play/Apple stores unless you really know and trust their developers. Use #FDroid instead.

  2. If you can, use #GrapheneOS, or an #Android ROM without Play Services, or that allows you to sandbox individual apps or the Play Services themselves.

  3. It’s even better if you can sandbox or deny the Nearby Devices permissions on the Play Services, if your ROM permits it. Nearby known Wi-Fi networks can also reveal a lot about your location.

  4. If the urge of playing that random animal crossing game that someone was playing at your hairdresser’s can be contained, then please contain it.

  5. Remember that you can also install those apps on your computer at home through something like Waydroid or any Android emulator, in a sandboxed environment without much sensitive data. Without putting location trackers always with you in your pocket.

  6. If Angry Birds asks to access your location, ask yourself why a game whose purpose is to throw chickens at pigs needs to know where you are.

  7. Periodically review from your phone’s settings which apps have access to your location, and when they tried to access it last time. An app that has no apparent reason to know where you are, and repeatedly tries to access your location while you’re not using it, is usually a big red flag.

  8. Always use Tor or a VPN that you trust (like Mullvad or Proton) to browse the Web. If you have the technical skills, try and go the extra mile. Set up your own VPN with a Pihole that blocks all trackers and forwards all external traffic through your trusted VPN, and wire your mobile devices to it too. If you can self-host, then self-host as much as you can.

  9. I’d be tempted to say “go around with a dumbphone if you think that you’re at risk”, but that may make things worse. Nowadays it’s very uncommon for anyone to step out of their house without a smartphone. If ICE stops you and you show them your grandma’s dumbphone they may actually harass you even more.

This part of the story where surveillance capitalism turns into plain boring totalitarian surveillance was so predictable.

#USPol

https://archive.ph/HYbBG

Fabio's Space

Fabio's Space

Fabio's Space

Fabio's Space

Google Docs

gravy_app_list

Fabio's Space

Fabio's Space

  • Copy link
  • Flag this post
  • Block
Fabio Manganiello
Fabio Manganiello
@fabio@manganiello.eu  ·  activity timestamp last week

#CandyCrush can bring #ICE agents to your door.

ICE has bought access to some surveillance tools developed by Penlink.

If you read the description of that company on their website you’ll find an overdose of fluffy and probably AI-generated corporate jargon that doesn’t mean anything:

Penlink is a global leader in digital intelligence solutions. Our compliant and certified solutions simplify complex data, empowering public safety and organizations to make informed decisions quickly and effectively. We believe in the power of data-driven intelligence to accelerate clarity in decision-making for global security, strategic operations, and the most critical missions.

In short: they make tools to spy on people. Through their mobile phones.

And it’s not like they do any kind of rocket science. They have some boring location trackers injected in a bunch of crappy ads SDKs used by some crappy free apps on the Google and Apple stores.

Commercial location data collected through trackers voluntarily installed by people on their phones can be queried without a warrant. Or it can be sold to data brokers, who in turn can resell it to whoever they want.

The list of impacted apps found so far is publicly available here. 12,373 apps at the time of writing.

The list includes mostly games (some Candy Crush and Angry Birds releases, many card games and solitaires, gambling/casino games, sudokus, football simulators etc.).

But it also includes photo editors, weather apps, pregnancy date calculators, network speed analyzers, many VPN apps, and many apps most likely used by foreigners (there are many local Arabic, Chinese, Spanish, Italian and Indian apps in the list).

Among those that caught my eye: Vinted, Flightradar24 and IlMeteo.

My two cents, especially if you are an American citizen:

  1. Avoid apps installed through the Play/Apple stores unless you really know and trust their developers. Use #FDroid instead.

  2. If you can, use #GrapheneOS, or an #Android ROM without Play Services, or that allows you to sandbox individual apps or the Play Services themselves.

  3. It’s even better if you can sandbox or deny the Nearby Devices permissions on the Play Services, if your ROM permits it. Nearby known Wi-Fi networks can also reveal a lot about your location.

  4. If the urge of playing that random animal crossing game that someone was playing at your hairdresser’s can be contained, then please contain it.

  5. Remember that you can also install those apps on your computer at home through something like Waydroid or any Android emulator, in a sandboxed environment without much sensitive data. Without putting location trackers always with you in your pocket.

  6. If Angry Birds asks to access your location, ask yourself why a game whose purpose is to throw chickens at pigs needs to know where you are.

  7. Periodically review from your phone’s settings which apps have access to your location, and when they tried to access it last time. An app that has no apparent reason to know where you are, and repeatedly tries to access your location while you’re not using it, is usually a big red flag.

  8. Always use Tor or a VPN that you trust (like Mullvad or Proton) to browse the Web. If you have the technical skills, try and go the extra mile. Set up your own VPN with a Pihole that blocks all trackers and forwards all external traffic through your trusted VPN, and wire your mobile devices to it too. If you can self-host, then self-host as much as you can.

  9. I’d be tempted to say “go around with a dumbphone if you think that you’re at risk”, but that may make things worse. Nowadays it’s very uncommon for anyone to step out of their house without a smartphone. If ICE stops you and you show them your grandma’s dumbphone they may actually harass you even more.

This part of the story where surveillance capitalism turns into plain boring totalitarian surveillance was so predictable.

#USPol

https://archive.ph/HYbBG

Fabio's Space

Fabio's Space

Fabio's Space

Fabio's Space

Google Docs

gravy_app_list

Fabio's Space

Fabio's Space

  • Copy link
  • Flag this post
  • Block
hazelnot :yell:
hazelnot :yell:
@hazelnot@sunbeam.city  ·  activity timestamp last week

Wait, what

The official GrapheneOS account on their forums is claiming that F-Droid has been "involved in underhanded attacks on the GrapheneOS project" and that they "may choose to specifically target GrapheneOS" with malicious code injections!?

Is there any truth to this whatsoever? o.o

#grapheneos #fdroid

  • Copy link
  • Flag this post
  • Block
Joseph Nuthalapati :fbx: boosted
arthur.pizza
arthur.pizza
@art@mastodon.sdf.org  ·  activity timestamp last week

I've successfully installed #GrapheneOS on my Google Pixel 9 XL. All the Google Play stuff that I need is tucked away in a little private container and only thing on my main phone are free and open source applications.

  • Copy link
  • Flag this post
  • Block
Elena Rossini ⁂
Elena Rossini ⁂
@_elena@mastodon.social  ·  activity timestamp last week

@stefano sorry for becoming a Fedi "reply guy" offering unsolicited advice, but in case you have a Pixel phone, I would highly highly recommend GrapheneOS. There are none of these shenanigans there (you can even have Wifi and Bluetooth turned off automatically after inactivity)

Wulfy
Wulfy
@n_dimension@infosec.exchange replied  ·  activity timestamp last week

@_elena @stefano

Second that.
I got pixel just so I can run #GrapheneOS.

All the evil shit is sandboxed.

And you can have multiple profiles.
If you are going to a fascist state, it takes 1 minute to wipe your real profile and you just have only owner and "I'm harmless and hold no opinions beyond cats" profile.

Sorry, no caption provided by author
Sorry, no caption provided by author
Sorry, no caption provided by author
  • Copy link
  • Flag this comment
  • Block
arthur.pizza
arthur.pizza
@art@mastodon.sdf.org  ·  activity timestamp last week

I've successfully installed #GrapheneOS on my Google Pixel 9 XL. All the Google Play stuff that I need is tucked away in a little private container and only thing on my main phone are free and open source applications.

  • Copy link
  • Flag this post
  • Block
Jan Böhmermann 🤨 :verified:
Jan Böhmermann 🤨 :verified:
@janboehm@edi.social  ·  activity timestamp 2 weeks ago

* Hardware nicht mitgemeint.

0
0
@0@det.social replied  ·  activity timestamp 2 weeks ago

@janboehm
…abwarten, da kommt hoffentlich was…

https://www.heise.de/news/Custom-ROM-GrapheneOS-kommt-auf-Smartphones-von-grossem-Hersteller-10767072.html

#grapheneos #digitalindependence #digitalindependenceday

heise online

Custom-ROM GrapheneOS kommt auf Smartphones von großem Hersteller

Die Entwickler der sicheren Custom-ROMs GrapheneOS arbeiten mit einem großen Hersteller zusammen, um Smartphones abseits der Pixel-Geräte zu unterstützen.
  • Copy link
  • Flag this comment
  • Block
pvergain (framapiaf) boosted
Teddy / Domingo (🇨🇵/🇬🇧)
Teddy / Domingo (🇨🇵/🇬🇧)
@TeddyTheBest@framapiaf.org  ·  activity timestamp 2 weeks ago

Ce #smartphone #suisse ultra-sécurisé va t-il devenir le nouveau #GrapheneOS ? Punkt débarque avec le MC03, un smartphone fabriqué en #Allemagne qui carbure à un #OS maison où chaque donnée compte. Pendant que GrapheneOS claque la porte de la #France, les Suisses prennent le relais.
https://www.clubic.com/actualite-593509-ce-smartphone-suisse-ultra-securise-va-t-il-devenir-le-nouveau-grapheneos.html

  • Copy link
  • Flag this post
  • Block
Teddy / Domingo (🇨🇵/🇬🇧)
Teddy / Domingo (🇨🇵/🇬🇧)
@TeddyTheBest@framapiaf.org  ·  activity timestamp 2 weeks ago

Ce #smartphone #suisse ultra-sécurisé va t-il devenir le nouveau #GrapheneOS ? Punkt débarque avec le MC03, un smartphone fabriqué en #Allemagne qui carbure à un #OS maison où chaque donnée compte. Pendant que GrapheneOS claque la porte de la #France, les Suisses prennent le relais.
https://www.clubic.com/actualite-593509-ce-smartphone-suisse-ultra-securise-va-t-il-devenir-le-nouveau-grapheneos.html

  • Copy link
  • Flag this post
  • Block
Electronic Frontier Foundation
Electronic Frontier Foundation
@eff@mastodon.social  ·  activity timestamp 3 weeks ago

Tucked away deep in the Settings app on Android are all sorts of privacy and security features you may have never seen. It’s time to get to know those settings. https://ssd.eff.org/module/how-to-get-to-know-android-privacy-and-security-settings

How to: Get to Know Android Privacy and Security Settings

Open up your Android phone’s Settings app and you’ll find dozens of different options with little guidance on what those options do. Some of these settings have a serious impact on your privacy and security, altering what data gets shared automatically with apps, data brokers, and Google itself. What sorts...
hobbs
hobbs
@hobbs@dobbs.town replied  ·  activity timestamp 3 weeks ago

@eff
@traecer I was just fiddling with the duress pin in #grapheneos today!

  • Copy link
  • Flag this comment
  • Block
Joseph Nuthalapati :fbx:
Joseph Nuthalapati :fbx:
@njoseph@social.masto.host  ·  activity timestamp 3 weeks ago

#GrapheneOS installation on a Pixel phone is the easiest Android ROM I've flashed in the past 8 years. I used the WebUSB-based installation method. (Also discovered that my desktop has a USB-C port in the back, lol).

I am not a fan of web browsers turning into operating systems, but this is a good use case for WebUSB. I wonder if we can flash Debian-based operating systems images using this, directly from the official website. Removes the need for desktop apps like Balena Etcher.

#webUSB

  • Copy link
  • Flag this post
  • Block
Grégory Gutierez 🌻🎸🐧 boosted
Fabio Manganiello
Fabio Manganiello
@fabio@manganiello.eu  ·  activity timestamp 2 months ago

#Android is dead and we’d better all leave the ship before it sinks entirely.

Options to unlock bootloaders on Android devices are also narrowing down. Xiaomi removed the ability to unlock the bootloader entirely in MIUI in August (after months spent making it ridiculously difficult), same for OnePlus, Samsung did so in July, and probably Google devices will soon follow suit.

And let’s not mention the nightmare of the Play Integrity API that forces all Android developers to register through the Play Store and use Google’s signing keys, even if they don’t intend to distribute their apps through it.

Sure, officially Google has taken a step back and has pledged to provide a way for developers and power-users to bypass those restrictions. But we can all expect it to be a cumbersome and change-prone process filled with ridiculous amounts of frictions at every step - and I wouldn’t even expect such a morally bankrupt company to keep maintaining this “sideloading” option.

Google once competed with Apple for customers. But in a world where Google walks away from the biggest antitrust trial since 1998 with yet another slap on the wrist, competition is dead, and Google is taking notes from Apple about what they can legally get away with. And the EU, the biggest opposer of its anti-competitive acts, is also becoming softer with Big Tech - both because Vestager has left the job, and because being soft with trillion-dollar monopolist tech titans is seen as a sign of being “technologically competitive”.

Your best bet is to purchase a Pixel 9a now, before more manufacturers decide to block bootloaders, and immediately flash it with #GrapheneOS.

The long term plan would instead be to throw all of our efforts and energies on Linux phones. The folks at GrapheneOS are doing an amazing job and fighting against all kind of pressures, but at some point we should probably all just acknowledge that anything that is tainted with Android, or runs on a device intended only to run Android, is a liability, and we should no longer build solutions on top of hardware and software that we can no longer trust.

Sailfish, PostmarketOS, UBPorts, MeeGo or whatever comes next must succeed. No matter the cost.

  • Copy link
  • Flag this post
  • Block
Carlo Gubitosa :nonviolenza: and 1 other boosted
Pietro395 :proton: 🇮🇹
Pietro395 :proton: 🇮🇹
@pietro395@mastodon.uno  ·  activity timestamp 3 weeks ago

PosteID taglia fuori gli utenti di GrapheneOS, LineageOS, /e/OS e altri sistemi Android non certificati da Google

https://www.reddit.com/r/ItalyInformatica/s/lribDP3LPy

#grapheneos #sicurezza #spid
@sicurezza

  • Copy link
  • Flag this post
  • Block
Pietro395 :proton: 🇮🇹
Pietro395 :proton: 🇮🇹
@pietro395@mastodon.uno  ·  activity timestamp 3 weeks ago

PosteID taglia fuori gli utenti di GrapheneOS, LineageOS, /e/OS e altri sistemi Android non certificati da Google

https://www.reddit.com/r/ItalyInformatica/s/lribDP3LPy

#grapheneos #sicurezza #spid
@sicurezza

  • Copy link
  • Flag this post
  • Block
Deep Pandya
Deep Pandya
@Pandya@fosstodon.org  ·  activity timestamp 3 weeks ago

I learned from #FSFE (https://fsfe.org/activities/android/liberate.en.html#OS) that #LineageOS and #GrapheneOS are Libre and Ethical replacement to Android. However recently I found that #GNU (https://www.gnu.org/distros/common-distros.html) recognize them as non endorsable! Any idea about this discrepancy?

FSFE - Free Software Foundation Europe

Liberate Your Device - Free Your Android! - FSFE

Learn how to regain control of your data, with a free operating system and free apps
  • Copy link
  • Flag this post
  • Block
:linux: :freebsd:
:linux: :freebsd:
@unixviking@social.linux.pizza  ·  activity timestamp 4 weeks ago

So... in the end, I switched to the iPhone as my primary device after already having to use it as a secondary device alongside my Pixel 9 with GrapheneOS.

Before you stone me, let me say first and foremost that I love GrapheneOS and its almost perfect privacy features! But certain circumstances made a switch more or less necessary.

On the one hand, I don't want to constantly carry around two smartphones – especially when I don't want to lug around an extra backpack, wallet, and/or other bags, but just my keys and phone. Then there's the issue of two phone numbers.

On the other hand, I use “ID Austria,” Austria's digital government service (they can only dream of such technical achievements in Germany, muahaha!), and like my banking, it doesn't work, or only works poorly, without Play Services installed. The same goes for digital tickets for public transportation.

And finally, there's the logging of my health data with Apple Watch, as I have a heart condition, among other things, and Apple Health records all these values very well and perfectly prepares and presents all the relevant data for my doctors. In the end, my health is a little more important to me than data protection. At least I can convince myself that Apple is a little better and more trustworthy here than the data octopus Google.

And: the symbiosis between Linux and Apple now works very well. The iCloud calendar can be easily integrated into GNOME or KDE calendars, and that's what my entire daily organization revolves around. That was the most important point for me. And with Localsend, I have a perfect Airdrop alternative for data exchange, and Nextcloud also works smoothly on both platforms. So, apart from my health, I'm currently more than satisfied with how things are going!

#linux #unix #opensource #freesoftware #grapheneos #apple #privacy #health

  • Copy link
  • Flag this post
  • Block

bonfire.cafe

A space for Bonfire maintainers and contributors to communicate

bonfire.cafe: About · Code of conduct · Privacy · Users · Instances
Bonfire social · 1.0.1-beta.35 no JS en
Automatic federation enabled
Log in
  • Explore
  • About
  • Members
  • Code of Conduct