• NewOldGuard@lemmy.ml
    link
    fedilink
    English
    arrow-up
    0
    ·
    6 days ago

    I want to love this but I can’t compromise my security for this device. If y’all ever add MTE and the other features required by Graphene I’ll be the first in line

    • ExLisper@lemmy.curiana.net
      link
      fedilink
      English
      arrow-up
      0
      ·
      5 days ago

      Yeah, same for me. I’m sure I’m on top of CIA’s list of “people to hack” so no security compromises for me.

      • NewOldGuard@lemmy.ml
        link
        fedilink
        English
        arrow-up
        0
        ·
        edit-2
        5 days ago

        I get the sense this is sarcastic lol. In my opinion though, privacy without security isn’t very useful. Yes I can avoid corporate or government spying when I’m in physical control of a device like this, but what if I get arrested on some false pretenses and they use cellebrite to gain access? Or the same at an airport when traveling? If you’re any form of political dissident, activist, or a member of a marginalized group, being targeted this way is a very real possibility. And as soon as that insecure but “private” device is out of your hands, all that data is free game for the govt.

        • NuclearDolphin@lemmy.ml
          link
          fedilink
          English
          arrow-up
          0
          ·
          5 days ago

          This is why threat modeling is important.

          but what if I get arrested on some false pretenses and they use cellebrite to gain access?

          Chances are they can clone the eMMC and wait for a CVE. Or threaten or hold you until you cave. If a lawsuit is your only recourse, I would expect any constitutional barriers to be ignored in practice. Your best bet is to never end up being an explicit target, which may be more difficult for certain individuals.

          My threat model considers dragnet surveillance as the primary threat, so I’d compromise on surviving dirty maid type attacks in favor of reducing the information my device gives out.

          Obviously if your device is being actively exploited, you cannot be private. But your security requirements increase greatly if your data footprint indicates to them that you warrant targeted scrutiny.

    • Hemingways_Shotgun@lemmy.ca
      link
      fedilink
      English
      arrow-up
      0
      ·
      5 days ago

      Fair enough. But too many people think privacy and security are the same thing.

      GrapheneOS is dedicated to both privacy and security, whereas e/os (while it does have some security improvements over stock android) is much more focused on the privacy side of things.

      • Zarobi@aussie.zone
        link
        fedilink
        English
        arrow-up
        0
        ·
        5 days ago

        There is some overlap. Can’t have privacy problems if everything’s encrypted and they have no access to your data in the first place

        • iopq@lemmy.world
          link
          fedilink
          English
          arrow-up
          0
          ·
          5 days ago

          You can still have privacy issues. For example, everything’s encrypted, but you’re the only one with the exact fingerprint so every adveriser and government agency knowns who you are