logoalt Hacker News

Borealidyesterday at 3:58 PM2 repliesview on HN

Graphene doesn't position itself against spyware.

For example, a user being able to inspect and edit the files written by an app, no matter where or how those files were written, would be an anti-spyware feature: you could better observe the behavior of a closed-source application.

Grapene opposes this feature because the app security model protects the app AGAINST the device user editing or reading protected files.

Graphene's philosophy is enforcing the Android security model. The Android security model gives guarantees to the app developer about how their app can behave, even where the device's owner wishes otherwise. See: Play Integrity.


Replies

ysnpyesterday at 6:54 PM

GrapheneOS have mentioned wanting to expand the logging/intrusion detection capabilities of their Auditor app but contend with the need to include it as a system app which is against their philosophy (PoLP). It is not accurate to say they don't want to do anything about spyware.

They are also completely against Play Integrity as implemented on principle.

Iolaumyesterday at 6:31 PM

Graphene puts a HEAVY emphasis on security.

Also your argument about a user inspecting and editing application files feels like a strawman argument. For example many spyware use malicious links to infect the devices, not malicious apps.

show 1 reply