• 0 Posts
  • 33 Comments
Joined 1 year ago
cake
Cake day: July 1st, 2023

help-circle




  • It’s not questionable at all to assume that a user rooting and installing their own OS is a security risk. That’s the entire premise of zero trust. I’m sure Graphene OS is secure and better for user privacy when configured properly. But you can’t trust that an end user will configure it properly. That’s what I am saying and have been saying since the first message. You can’t trust the user to be security minded. Ultimately, the best thing you can do as a developer or a business is support a known quantity of software and hardware configurations and that likely means only supporting OEM installed ROMs.


  • It’s not for your security. It’s for the company’s security. You’re really dense you know that. This is not about you and it’s not about Google. What I’m saying is, people suck ass. So to protect themselves from people sucking ass, they restrict access to their system to their terms. Completely fair if you ask me.

    You can go cry Google bad all you want. I might even agree Google is bad. But this is not a Google thing. It’s an IT security thing. The banks and MFA providers are security first businesses. They will make the decision that protect them first and it makes sense for them to do so. If you owned a bank, there is a high likelihood you would make similar decisions that end users don’t quite understand.

    As far as McDonald’s is concerned, who the fuck knows what their developers are doing. That app is trash anyways.



  • This has very little to do with Google. Custom OS’s in general are being restricted by these apps, not Graphene in particular. All custom OS’s and root access devices are inherently less secure, even if they are privacy focused OS’s.

    In IT this is called a zero trust. You don’t trust anything you cannot verify yourself. And a user installed OS is not something anyone can verify other than the installing user. Obviously for your own security you have your own zero trust policy if you are using something like Graphene, but these companies aren’t making it more secure for you as a user, they’re covering their asses in case there are holes in security they cannot account for.


  • Most banks restrict custom ROM and root access devices for security purposes. Same with MFA apps. I get it. From an IT security perspective, restrictions on software compatibility limit the number of failure points. Even if you find a custom OS that is more secure as an OS, it is installed through opening up your device to security risk and there is no real requirement for you to close up that security risk afterward. My company has made the same choice to restrict supported platforms for our services.

    McDonald’s app restricting the OS is probably some security decision they made because it’s more secure even when they probably don’t need it though.






  • Yes but that isn’t changed by the amount of data used. There is no cost to supply per kb supplied, only a cost to maintain the equipment that governs the speed of the connection.

    Here’s an analog example. If the city you lived in started charging you more for the water to come into your house faster as well as charging you for the amount of water you use. Obviously you should pay for the amount of a finite resource you use but the speed at which you acquired that resource should be limited only by the physics of the water transportation system.

    Data on the other hand, is not a finite resource. There is no limit to the amount of data one can acquire given endless time and energy. So the only way to bill for that becomes the speed at which you acquire the data. You pay for the data speed and that funds the infrastructure to supply that speed indefinitely. End of story. The only reason data caps exist is that they want to charge more money for you to use less bandwidth so they can sell that bandwidth to other people. When what should really happen is, they should invest in higher bandwidth capacity and sell that to their customers to return on that investment.

    Either supply me infinite speed and bill me for the amount of data used or supply me infinite data and bill me for the bandwidth. Not both.