Secure Phone Series: Device Security
copperhead.co
copperhead.co
GrapheneOS is endorsed by Edward Snowden https://twitter.com/Snowden/status/1175430722733129729?s=09
And IMO, it's extremely misrepresentative, but if you could link to some displays of what you're referring to then I suppose we could debate what you mean by "toxic".
https://twitter.com/DanielMicay/status/1264528965127024644
Daniel stating he feels Brave has nefarious intentions.
https://twitter.com/DanielMicay/status/1154509303962689536
Daniel Micay attacking the Tor Project for considering use of his hardened allocator
https://lists.torproject.org/pipermail/tor-dev/2019-August/0...
And of course you don't show any context at all.
> Daniel stating he feels Brave has nefarious intentions.
The DRM is a valid issue. Brave is not impervious to all criticism.
> Daniel Micay attacking the Tor Project for considering use of his hardened allocator
That's not what happened at all. He never attacked them for that. He debunked the nonsense that Tom Ritter was posting. The Tor Project never even considered using hardened_malloc either. I suggested that Whonix use hardened_malloc and so HulaHoop (another Whonix developer) asked if this could affect web browser fingerprinting on the mailing list. No Tor Project developer made any indication that they wanted to include hardened_malloc - quite the opposite.
https://lists.torproject.org/pipermail/tor-dev/2019-August/0...
Have you even read these links or do you just want to mindlessly promote Copperhead?
Please read the contents of that link and you'll arrive at the same conclusion
I dont agree with a bunch of Micays opinions. But when it comes to technical facts, I cant argue much because he is so exact with this. But I have never seen any emotional insults from him nor any emotional manipulation.
https://www.zdnet.com/article/hackers-claim-they-can-now-jai...
You rarely hear about Android exploits, since the devices are assumed insecure, whereas when an iPhone vulnerability comes out, that's a big deal. iPhones are miles ahead of Android, Pixel is the closest and they're still far.
Case in point: You never hear about how the government couldn't open some bad guy's Android, do you?
Products that are closed to some groups are not secure against the group for which the product is open (Apple, US government et al.)
Writing about the Secure Enclave would be pointless because it's completely unrelated to the domain the article was written for. Maybe they should add a line "oh by the way, Apple does things differently" because much more than just the security chip is done differently by Apple, but that wouldn't make much sense either.
The article does have a short bit about the secure element in the phone, which serves a very similar purpose to the secure enclave, except less well-integrated because Android device manufacturers don't control all the hardware.
They state on their site (copperhead) that only 2 months after split with Daniel the rom got updated again. That is not true. I was affected by the split and there was no update that early, while Daniel continued development.
My account has been created solely to defend Graphene here btw. But this is my usual nick I use everywhere else. I am a longtime passive reader.
The Copperhead site states that they support Zero Touch Provisioning of devices.
That involves Google and Vendor infra and as far as I know this cant enable installing custom roms from inside Google roms. I might be wrong there because I didnt dig that deep into MDM provisioning. But enough that it didnt seem anywhere open source friendly.
The notifications aren't working properly: this morning my alarm didn't ring and this evening a reminder didn't fire either.
The Fdroid store is nice but it lacks a lot of well designed apps.
I don't have access to my bank app.
KeepassDX (password manager) doesn't work in the chromium forks available.
The AOSP keyboard doesn't "learn" and doesn't offer suggestions for the next word I might type. I can't change the layout. I tried another keyboard from FDroid, it didn't even have auto completion.
A lot of things aren't customizable like the ugly icons (looking at you Bromite! ;)
So for the first time my phone isn't my enemy but it's so limited that I'm not sure it's worth continuing using it.
For the first time I'm thinking going to Apple. I know their privacy stance is mostly marketing but they scare me less than Google. I don't know.
You can get access to your bank app via Aurora store, available on F-Droid. It is a front end to google play store and allows install/update of the apks. It also shows you the report on what trackers are known in each app.
Note that without google services, some app functionality that relies on it may not work, like notifications. The alarm app is bundled with AOSP so should work, weird.
Keepassdx works fine with Vanadium for me. Magickeyboard is amazing for auto type.
That being said maybe the pixel 4 builds aren't as mature. I am running on Pixel 3a and it has been smooth sailing. A phone experience I have long been waiting for.
Also the project is not as well resourced as big companies, so some bugs and rough edges are expected . Support the project financially if you want a viable open source and secure mobile os.
In term of privacy what does it imply to install the Aurora store? I didn't look much into it, I thought I would get everything with FDroid.
The AOSP clock adds an audible notification 1.5 hour before the alarm (this was silent on my regular Google Android build). If I deactivate the notification, the alarm is still triggered but I have to go into the app to deactivate it (and I'm not sure how reliable it is).
I installed the clock from SimpleMobileTools. It's reliable 80% of the times which isn't ideal for an alarm!
A lot of apps on FDroid are outdated and warned me that they were made for an older version of Android.
I would support the project financially if I stay on it, but the way I see it if I want to remain on GrapheneOS I'm going to have to code (or modify) all the apps I need.
I have 0 knowledge in mobile dev, and frankly I'm not exactly thrilled to have to spend all of my next year free time to build what I need.
I'm not exactly thrilled to go to Apple either, and at this point I think I'd rather go without a mobile phone than to go back to Google.
I need to chew on this.
I have keepassdx version 2.8.7 installed and it has magic keyboard. Go to settings > Form filling and play around with magic keyboard settings.
Yes F-Droid has some outdated apps, and it seems to by default install an older app version. You can check and usually you can upgrade to a newer version if it's in the repo. Otherwise, some apps or authors do have their own repos you can add.
https://piunikaweb.com/2019/02/05/the-demise-of-copperheados...
You get open source fanatics that will cut you down any chance they get. Nothing is ever good enough and god forbid you want to charge money for anything.
Most actually don’t know anything and cant distinguish good products from bad. They are just paranoid.
People who actually want to buy security products listen to the loud mouth fanatics so nothing can actually get made because the fanatics will ensure that only free is good. The ensure the market is dead.
Copperhead tried to make a good run for it. But in the end when you try to tame a fanatic you are going to get hurt.
And then there are mediocre-to-bad products that are suspiciously successful and get deals easily. It is like someone powerful makes sure they become widespread.
When they were still publishing their sources they were often lagging months behind with basic AOSP security updates. Still not updated to Android 11 yet, 2 months since it was launched, which, as they support Pixels, means they now have 3 monthly updates worth of device specific security patches that can't of been applied.
GrapheneOS moved to 11 in September, not so long after it was released by Google
Grapheneos has been around far longer than the commercial project. The commercial project was set up to fund the open source project however James Donaldson, the current copperhead CEO has a criminal background and tried to turn it into something completely different
I encourage you to read https://github.com/Peter-Easton/GrapheneOS-Knowledge/blob/ma... to understand what really happened
While it may not have been the point of the article it gives no reason why you should consider CopperheadOS.
This is my perspective taking the article at face value as a complete layman in Hardware and OS security who cannot provide any critic or judgement on the technical content of the article.
It's now a scam project focused on attacking GrapheneOS and harassing developers, as evident throughout this very thread with their usage of sockpuppet accounts.
https://grapheneos.org/#history
https://twitter.com/DanielMicay/status/1171170734380654597
https://renlord.com/posts/2020-03-25-copperheados-legal-thre...
You also literally linked a cease and desist letter from our lawyers telling another member of your group to stop this kind of crap.
https://mobile.twitter.com/_copperj/status/13218300688140451...
From what I gathered everyone moved on to graphene, including the original architect.
I've not seen anyone mention copperheadOS as a modern secure phone in a long time. Not trying to denigrate the post but it's somewhat strange to see them appear out of nowhere.
Also, on my barely secured, out of date firmware phone, the site doesn't work because I block js :/
Truly long for the day people at least attempt to make fallback no-js sites or at least text only static pages like some 90's ftp server for us weirdos who don't need nor want interactivity. Last I looked something like 80% of Android and 50% of apple phones were end of life and yet still used.