logoalt Hacker News

HybridStatAnim8yesterday at 8:18 PM1 replyview on HN

You would install your own build of GrapheneOS. Not the official images.

Its not advisable to run anything as root, at all. Or expose access to it in any form.

You can make userdebug builds to access a form of root that doesnt undermine the entire security model, in ADB. Afaik this lets you access apps internal directories but is not recommended for production devices.


Replies

kuschkuyesterday at 9:51 PM

> You would install your own build of GrapheneOS. Not the official images.

Awesome, so you're advising against installing GrapheneOS for anyone that wants control over their own data.

Sorry for twisting the words slightly, but that's the essence of the issue here, isn't it?

> Its not advisable to run anything as root, at all. Or expose access to it in any form.

And then you advise for exposing access to it in pretty much the same form I asked for before.

It'd be funny if it wasn't so exhausting.

Regarding the security model: So adjust the security model.

Any access that an app can have, should also be available to the user. Importantly, they should be able to access and modify any data.

The system documents/files app already has special permissions for that, there's no reason why it shouldn't have access to all files (accessible through the same unlock system as e.g. the security settings)

show 1 reply