Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

What about a custom ROM (fork) of Android, sans Google apps? Not an option for typical end-users, of course.


Disabling Verified Boot and not having Google Play Services would dramatically reduce the security posture of an Android device.

Disclaimer: I work at Google.


> not having Google Play Services would dramatically reduce the security posture of an Android device.

I understand Verified Boot, but how would removing Google Play Services damage security? It would seem to reduce the attack surface.


For one, without Google Play Services you have no Play Store. Unless you're going to prevent users from installing apps entirely, there isn't really another safe way to obtain apps. Additionally Verify Apps, SafetyNet, Safe Browsing, etc. are all part of Google Play Services. You _really_ want Verify Apps.


F-Droid, Raccoon, MicroG?


F-Droid and Racoon are ways to obtain apps. MicroG is an alternative to Google Play Services. How do these solve the other issues the commenter mentioned? Does MicroG include "Verify Apps, SafetyNet, Safe Browsing, etc."?


Excellent points; thanks.


you can keep verified boot on custom roms. play services expose you to googles nsa'd taps we'll hear about in 5y.

source: im another google engineer


https://source.android.com/security/verifiedboot/verified-bo...

How do you propose a custom rom can establish hardware root of trust without being signed by the device manufacturer?


I believe the point is that such a signature is useless since the software signed as safe is actually unsafe, while a self-signed rom at least has a chance to be safe.


this reminds me of when team-teso had their stuff on their website directly accessible over https.. so they used a self-signed cert, so that no govt or corporation could require a MITM with a valid signed cert from any trusted CA.


Probably as long as it was patched for security updates but tbpfh, trusting a random stranger on the internet for security advice is likely unwise.




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: