‹ BackHN Continuity

Thread

GrapheneOS – When an app is slow

86 points · 65 comments · speckx

  1. pjmlp · · focus · HN ↗
    Maybe the actual solution is to improve, replace the application.
    1. izacus · · focus · HN ↗
      Or maybe there's a reason why the mainline Android OEMs don't ship that allocator by default.
      1. Groxx · · focus · HN ↗
        The fairly obvious answer here is "OEMs don't care about security because very few people will pay for it, either with $ or time". Benchmaxxing sells better.
        1. izacus · · focus · HN ↗
          That's trivially provable as false.
          1. nvme0n1p1 · · focus · HN ↗
            If so, I'd love to know which OEM you're thinking of who ships an Android distro more secure than GrapheneOS.
            1. izacus · · focus · HN ↗
              Let's first start with y'all providing any proof that it was "benchmaxxing" that causes OEMs not to ship hardened allocators (and not - for example - breaking compatibility with users' software).

              And then we can move the goalposts to "more secure distro with GrapheneOS" which isn't part of the conversation until you dragged it out.

              1. pessimizer · · focus · HN ↗
                > Let's first start with y'all providing any proof

                Your trivially proving things can't involve asking other people to prove the opposite of things. You've instantly backed down.

                > And then we can move the goalposts

                Why? You haven't done anything except ask others to do things. You've moved the goalposts from trivially falsifiable, and started begging.

                1. izacus · · focus · HN ↗
                  I'm not going to play a game where you make up false shit and I do the work of disproving it while you move the goalposts with new false shit.

                  Android release notes are easy to find: <a href="https:&#x2F;&#x2F;source.android.com&#x2F;docs&#x2F;whatsnew&#x2F;release-notes" rel="nofollow">https:&#x2F;&#x2F;source.android.com&#x2F;docs&#x2F;whatsnew&#x2F;release-notes

                  So are marketing materials: <a href="https:&#x2F;&#x2F;blog.google&#x2F;products-and-platforms&#x2F;platforms&#x2F;android&#x2F;android-17-features&#x2F;" rel="nofollow">https:&#x2F;&#x2F;blog.google&#x2F;products-and-platforms&#x2F;platforms&#x2F;android...

                  and so are marketing materials: <a href="https:&#x2F;&#x2F;blog.google&#x2F;products-and-platforms&#x2F;devices&#x2F;pixel&#x2F;google-pixel-10-pro-xl&#x2F;" rel="nofollow">https:&#x2F;&#x2F;blog.google&#x2F;products-and-platforms&#x2F;devices&#x2F;pixel&#x2F;goo...

                  and each of those shows that security is pretty much a constant focus for everyone.

                  Dismissing all the security work done by other people because they didn&#x27;t jump on your feature is insane behaviour.

Open on Hacker News to reply ↗

Unofficial Hacker News client; not affiliated with Y Combinator.