Hacker Newsnew | past | comments | ask | show | jobs | submit | pyrophane's commentslogin

I have a JetKVM and could never get video to work on it despite spending a lot of time on troubleshooting. It may have just been a defective unit but I never got around to trying to RMA it.

Purely an aside but I went to the StandardNotes website and the first thing that struck me was how all over the place their AI generated product images were.

> Lock-in is the game. Users will pay. Many companies under-price their product and suffer the consequences.

Well, just yesterday the WSJ published an article [1] about bending spoons that include this detail:

> Evernote, a note-taking app acquired in 2023, was among the holdings Bending Spoons profiled in its IPO prospectus. Evernote’s revenue was 30% higher in 2025 than in 2022, and during that time average revenue per monthly active user rose 150%. What the prospectus didn’t say: Those figures meant the number of users fell 48%. Revenue rose through price increases as the customer base shrank.

So, a lot of users were not willing to pay.

1. https://www.wsj.com/finance/investing/at-bending-spoons-the-...


That's bending spoons' business model. Buy a declining business and drive it into the ground by extracting as much value as they can from the customers still dependent on it.

It's basically the broadcom model for VMware. Sadly this model is very popular these days.

I'm very happy with obsidian these days though I don't use their sync service. The self hosted livesync is pretty good though a bit quirky at times.


A bit over a year ago I got an iPad Pro with the nano-texture display and when hearing that apple was developing a folding phone I thought, man, if they put this screen on the inner display that would be amazing.

I assumed they wouldn't do it because they were marketing the nano-texture as a specialty thing for professionals and glossy screens were the popular ones, but now here we are.


We have both now on the phone. For those that don't like the nano-texture inner dualscreen they can just only use the outer glossy one

Then they'd be seriously dumb people to buy an otherwise inferior (too thick, too heavy, bad cameras, small screen) device for $2000 to just use that outer screen alone

GrapheneOS actually recommends against using Aurora and instead just using the Play Store, so this shouldn't really hurt users.

For extra privacy, you can sign into the Play Store with a Google Account that isn't tied to anything else.


Although the nice thing about Aurora Store is it allows you to install apps without a google account linked to your device, keeping Google Play Services signed-out.

Somewhere in the FAQ GOS advertises that Play Services can be used without signing in, but they also recommend the official Play Store (which requires signing in) and explicitly don't recommend Aurora (which doesn't).

Unless I'm missing something, I don't see how you can functionally use Play Services signed-out when in order to obtain those apps in the first place, you need to sign into a Google Account for Google Play.

That's personally what I used Aurora for, plus as an easy way to export APK files.


Some apps offer direct APK downloads from their websites. If Google Play Services is detected, they use it for push notifications. Otherwise, they fall back to an internal background connection. WhatsApp is an example.

You still need to supply Play Services:

GrapheneOS uses Sandboxed Google Play. LineageOS requires flashing a package like MindTheGapps. There is also microG, an open-source reimplementation of Play Services APIs.


> Google Account that isn't tied to anything else.

At the risk of being a privacy absolutist / fatalist: Google’s entire business model is surveillance. They follow you around and track your habits so you can be influenced. Given that, a Google account is always tied to something else.


I'm under no illusion that google doesn't know I own my multiple accounts. They most certainly do. I usually use the same user agent (with containers) on the same IP, after all.

But my goal is to avoid a stranger gaining access to my google services if they manage to unlock a lost device or steal my TV/streaming box that has no lock at all.

I wish Google supported a permission system per device. For example on most of my android devices all I really want is to be logged into Youtube and the play store. I most certainly do not want those devices to have access to my contacts, emails, calendar, keep, drive, payment, etc. (I don't personally use all of those things, but you might and that's what a random thief would gain access to.)


Yep, something like checkboxes on login:

   - ALL: Log me in to all Google Services
   - Calendar
   - GMail
   - YouTube
   - ...
Adding more would require to login anew.


Piggybacking on this... I create my fair share of "burner accounts" and almost always they (not just Google) connect it to my true identity. Granted I'm not using VPNs or really trying to hide the connection but it seems trivial for them to associate.


My experience has been that all the consumer privacy/security tools are varying degrees of “good” at keeping away bad actors, trackers, advertisers, and most third parties, but when it comes to the big dogs, there’s nothing you can really do to stop them. Google, Facebook, etc. just have too many data points already available to them so they can easily build a picture of you. There are simply too many services that have them running around in the background or just straight up depend on them.

All you can do is leave their ecosystem as much as you can and accept you will never be fully rid of them


> leave their ecosystem

Their tracking is baked into various apps even if you don't have an account with them. Anything with social media integrations can report back to the mothership behind your back.


yes I believe I said that in my previous comment more or less


I'm happy enough not using them however lately even government services (which I have no choice but to use) require loading a captcha from either google or cloudflare. The situation is absurd.


They have required unique phone numbers for accounts I've tried lately, or parent's phone numbers. Facebook is worse though, they are quick to ban an account/phone number.


[flagged]


No, GrapheneOS is a privacy project. The primary focus is providing usable privacy. GrapheneOS solely works on security to protect privacy.

GrapheneOS is a privacy first project. Security is improved for the sake of privacy.


Google's business model is providing you services that are excellent, while also providing advertisers access to your willing eyeballs when you use those services.

Yes, the advertising targeting is incredibly invasive, but let's not pretend they aren't providing world class Search, Email, Docs, Maps, Video (YT), etc in exchange.


GrapheneOS (the project) might recommend for or against certain things in relation to their specific objectives, but that doesn't mean all GrapheneOS users have the same objectives or need to comply with the opinions of GrapheneOS.

For instance, I use GrapheneOS because it provides better security and privacy out of the box than LineageOS, but I'm also not so paranoid that I'm going to just blindly listen to advice against using F-Droid. What I want out of my Android instance is good security defaults with no bloatware, not to stop the NSA from looking at my travel photos and what HN articles I once looked at. It's okay if my OS is great but not perfect.

So yes, I am a GrapheneOS user who is [modestly] hurt by this. Signing in with a dummy account is just another one of those things that will end up being futile in years to come when Google requires iris scans, DNA samples, and anal probes in order to get a new account. Personally, I'd prefer installing whatever software I want on whatever devices I [pretend like] I own, without telemetry or jumping through hoops.


Yes, F-Droid and its apps are great <3 They add so much security by simply not having a lot of tracking code that can be exploited and tries to hook all over your system. And they have reproducible builds which is something the commercial stores don't even bother with. This is really important for security. I don't understand that GrapheneOS advises against them.

And yeah the iris scans sound like a scare but only 2 years ago there was a constant line of zombies here in the shopping mall giving their eye scans to altman.

The masses really don't care about privacy if you give them a worthless trinket.


I've honestly never understood why F-Droid even still exists. Every time I've tried to use it (as recently as half a year ago) it's still a shitshow and never displays or updates apps correctly. Half the time an app showed up on the website that didn't show up on the phone app. The other half of the time even when I did get something installed, it would just never understand that an update existed and needed to download and update a given app. It's one of the worst pieces of software I've used in a while, and I can tolerate a good bit of jank from FOSS apps.


> never displays or updates apps correctly. Half the time an app showed up on the website that didn't show up on the phone app. The other half of the time even when I did get something installed, it would just never understand that an update existed and needed to download and update a given app

You probably "just" need to pull down while on the "Latest" or "Updates" tab, to update your repository (it will show a small banner at the top while it's doing that). It's incremental, so it may take a while if it has been some time since you last did it (and auto-updates are disabled).

The way F-Droid works is that it downloads the whole index and then the catalog, version checks, etc, all runs locally, quite similarly to some package repositories actually.

I am not claiming its intuitive, but I think that part works fine once you understand how it works.


The last time it wouldn't update an app, I could see in the app store and on the website that my app had a new version, but no matter what I did, I could not make it update the app. I don't know what I was doing "wrong", but I think if I couldn't figure it out or make it happen, there's something very wrong with either the app or how it's "supposed" to work. Neither of which is an acceptable user experience for me.


Doesn't match my experience (or anyone I know that uses F-Droid), FWIW.

We search for stuff, install it, it updates in the background. We install some of our own repos, but the bulk of our apps come from F-Droid's default repos.

Hard to reconcile your account with my experience without specifics.


My understanding is that F-Droid is hosted out of some home servers (instead of some universities like other similar package managers) so the bandwidth leaves much to be desired. But the UX is definitely a big part of the problem. I don't understand why it tends to abort downloads when I background it, and I don't understand why it doesn't show a toast that it aborted the download.

I very much prefer Obtainium these days despite the setup steps. I don't think it's a coincidence that Obtainium, Aurora, Zapstore, etc. are gaining mindshare over F-Droid, just like how Brave has explosive growth over FF.



or APKUpdater, which covers besides F-Droid as well APKMirror, Aptoide, IzzyOnDroid, APKPure, GitLab and GitHub

https://github.com/rumboalla/apkupdater

though personally I use it only for Fdroid, Gitlab and Github


Have you tried Neo Store for accessing F-Droid and other repositories? In particular, I use the IzzyOnDroid F-Droid and Guardian Project repos.


I have not, but honestly, at this point, I just don't really care anymore. I can only try and be rebuffed by a product so many times.


> Every time I've tried to use it (as recently as half a year ago) it's still a shitshow and never displays or updates apps correctly. Half the time an app showed up on the website that didn't show up on the phone app.

Sounds like an accurate recreation of the Play Store experience to me.


This is not me simping for Google, I would honestly prefer literally anyone else with an acceptable app store experience, but I can honestly say I've never had that experience with the Play Store. If there's an update, it updates. If there's an app, it appears in search. On the rare occasion an app doesn't appear and I go to the Play Store website looking for it, the reason the app didn't show up is because it's listed as incompatible with my device (usually Android version too low or too high).


Yeah, the experience isn't great and there are better alternatives but F-Droid was there before anything else existed. It's also great to just have it as an option.


The software and many parts of the project are bad, but I don't see how you can't understand its reason to exist.

You're sure you understand what it does?


> a Google Account that isn't tied to anything else.

Isn't that pretty much impossible? You need a phone number for verification, which effectively ties it to that phone number.


> > a Google Account that isn't tied to anything else.

> Isn't that pretty much impossible? You need a phone number for verification, which effectively ties it to that phone number.

I just want to follow-up on this because some people claim this is not correct because they have managed to create accounts without phone numbers.

Indeed, I think to this day, under special circumstances (like e.g. on reasonably recent Android devices) you might be able to setup a Google account without phone number.

The trick is, that in the general case, you can not keep this account online indefinitely.

I once worked out a trick to get it going and I was feeling safe because I had setup 2FA and backup codes (see https://masysma.net/37/google_how_to_create_an_account_witho...).

First thing to note: This way of account creation does not seem to work anymore.

Second thing to note: After once logging in from a different country, trying to login again REQUIRES me to provide a phone number after successfully giving username/password/2FA code. No way to use the recovery code instead...

Also, given that this account was never before connected to a phone of any kind, by definition, the addition of a phone number cannot provide additional security confirmation (it's data that simply wasn't present before and any "personal" phone number could potentially do -- of course I haven't tried, because that's the point of not linking a phone number).

I think this way it is finally proven that they only do this to harvest the data/phone numbers and any claim of enhanced security is void.

I write this after having lost the second account to the phone number required screen despite being in possession of all the credentials which were ever assigned to that account...


Same thing happens to me.


Accounts created on stock Pixels don’t require phone numbers.


that haven't been true since pixel 4. it just picks your phone in the background.

a burner sim, like a literal criminal, is the only way today.


Even with a burner sim, there is the International Mobile Equipment Identity (IMEI) number, which is tied to the phone, and is known to all apps with the android.permission.READ_PRIVILEGED_PHONE_STATE permission.


That can't be true? <https://grapheneos.org/faq#hardware-identifiers>

  As of Android 10, apps cannot obtain permission to access non-resettable hardware identifiers such as the serial number, MAC addresses, IMEIs/MEIDs, SIM card serial numbers and subscriber IDs. Only privileged apps included in the base system with READ_PRIVILEGED_PHONE_STATE whitelisted can access these hardware identifiers. Apps targeting Android 10 will receive a SecurityException and older apps will receive an empty value for compatibility. The currently enabled carrier-based messaging app for SMS/MMS/RCS is a special case that's given access to certain device identifiers including the IMEI. This is normally the GrapheneOS fork of AOSP Messaging but can be changed to another app by the user.

  Since these restrictions became standard, GrapheneOS only makes a small change to remove a legacy form of access to the serial number by legacy apps, which was still around for compatibility. It used to need more extensive changes such as disallowing access to the serial number but those restrictions are now standard.

I don't know however if sandboxed google play is such a privileged app.


I couldn't immediately find whether GrapheneOS grants READ_PRIVILEGED_PHONE_STATE to Google Play. It might very well be that the GrapheneOS sandbox spoofs a fake IMEI, and I do hope so.

In any case, my parent comment was meant for stock Pixels, as mentioned by armadyl further up in this thread.


https://grapheneos.org/usage#sandboxed-google-play

> Google Play receives absolutely no special access or privileges on GrapheneOS as opposed to bypassing the app sandbox and receiving a massive amount of highly privileged access.

It doesn't mention IMEI here, but hopefully READ_PRIVILEGED_PHONE_STATE is included in "privileged access."


There is an AppStore app, I am not sure if this is the one we are talking about? <https://github.com/GrapheneOS/AppStore/blob/main/app/src/mai...>

That one lists:

  ACCESS_NETWORK_STATE
  ENFORCE_UPDATE_OWNERSHIP
  FOREGROUND_SERVICE
  FOREGROUND_SERVICE_SPECIAL_USE
  INSTALL_PACKAGES
  INTERNET
  POST_NOTIFICATIONS
  QUERY_ALL_PACKAGES
  RECEIVE_BOOT_COMPLETED
  REQUEST_DELETE_PACKAGES
  REQUEST_INSTALL_PACKAGES
  UPDATE_PACKAGES_WITHOUT_USER_ACTION


That's grapheneos's own app, separate from the play store or play services.


True. I think this one is closer to the truth: <https://github.com/GrapheneOS/platform_packages_apps_GmsComp...>

There is no READ_PRIVILEGED_PHONE_STATE mentioned there.


That's also incorrect, because the gmscompat app is just a helper app. Play services can and does request additional permissions. Those permissions are handled by the OS under the play services app, not gmscompat. If you want RCS for instance, you must grant play services and google messages phone and ICC auth access, which isn't seen in gmscompat at all.


  > That's also incorrect, because the gmscompat app is just a helper app.
Hmm, ok. I was reasoning the helper app was needed to get around the default assumptions from Google Play Services.

  >  Those permissions are handled by the OS under the play services app
Yes, but I assume you don't mean that as that GOS makes special hard-coded provisions for the play services. GOS claims to run Play Services like any other unprivileged app, and so any additional permission it would want would have to be consented by the user and should be visible to the user. If not, then GOS wording would be quite a bit unfortunate at least.

EDIT: "GmsCompatConfig is the text-based configuration for the GrapheneOS sandboxed Google Play compatibility layer. It provides a large portion of the compatibility shims." [1] This seems to indicate that the permissions requested by Play Services are being honored with the shims from the helper app. That would alleviate the permission problem.

1. https://github.com/GrapheneOS/platform_packages_apps_GmsComp...


Google Mobile Services apps installed on GrapheneOS including Play services run as regular sandboxed apps. They receive absolutely no special access compared to other apps by installing and running them. There are the standard permission toggles for granting those but none of those are required for typical usage to provide compatibility with many apps from the Play Store depending on their services.

There are additional special permission toggles for RCS and Android Auto. The issue with RCS is mainly that they split the implementation across Google Messages and Play services. Android's standard permission model gives special access to the app selected by the user as the messaging app but Google Messages expects Play services to have special access too.

The shims defined with GmsCompatConfig are a small subset of the overall compatibility layer. It has many shims which need to actually implement the functionality such as remapping the Play Store using privileged installation APIs to the regular ones available to user installed app stores. It has to remap the APIs used by dynamite modules to ones not requiring privileged SELinux policies too. It has a mix of shims which simply stub out the functionality and many which need to handle it as a regular sandboxed app would need to do it.


Thank you for clarifying this.

The only way to install Google Mobile Services apps including the Play Store on GrapheneOS is as regular sandboxed apps. They aren't granted any of the large number of usual privileged permissions, don't run with the usual far more privileged SELinux policies, aren't used by the OS as a backend for anything and aren't otherwise allowed to do special things by the OS in the usual many ways that is granted. They're regular sandboxed apps on GrapheneOS.

That's the application software side. I would assume the IMEI and IMSI are both going out to the cell network though, and I would presume that it's trivial to tie a phone number to those with how the mobile industry generally sells subscriber data to various data brokers. The only question is how permissive those data brokers are (their major constraint is how much most people become aware of this dynamic), but when dealing with a major APT like Google I'd assume they're tuned into the best ones with songs about bona fide purposes.


Are you talking about the US here? I am hoping this would be off-limits in Europe.


Yes I am talking with a US perspective. I would hope the GDPR would prevent such things in (most of) Europe. But I also personally wouldn't assume so given that there are still the same dynamics of keeping the info flows private to avoid scrutiny, and claiming plausible "legitimate purposes" and "consent".


Play services isn't an "app", it's a highly privileged system service that has access to everything and some more.


The only way to use Play services on GrapheneOS is as a regular sandboxed app. It runs in the standard app sandbox without any of the usual privileged permissions, privileged SELinux policy and many other forms of special access. It also doesn't get used by the OS as a backend for anything. Our sandboxed Google Play compatibility layer implements this by remapping APIs to ones available to sandboxed apps and stubbing out many which aren't needed.

yes, but not on GOS.

Its possible to set up a phone with a google account without even a sim card in it and use it as a wifi only device, so Im pretty sure what your saying is wrong.


you will be asked for a phone number then.

assuming the number you get hasn't previously been assigned to a google account


I've had no end of trouble registering an account on our corporate SIMs as the phone numbers (not the actual SIM cards) had been recycled as employees leave.


So many systems cannot handle known pattern of a phone number changing. Who's decided these are imutable values? That I have only one? That it's not shared?


It still works without a SIM card, how do you explain that?


You can create an account with no phone number during Android device setup.

You can also just get a burner phone number for a few bucks.


> You can also just get a burner phone number for a few bucks.

But you have to keep paying the monthly cost, if you loose access to a phone number in your Google account it's game over for any account recovery or "let's verify it's you" it might decide to throw your way.


What's the problem then? If it happens, discard that account and make a new Aurora Store burner account.


> You can create an account with no phone number during Android device setup.

Yeah now they have IMEI and all the other device specific info anyway they might as well forego the phone number


Sometimes you just can't.

For example, the banking app I have refuses to be installed from the Play Store on GrapheneOS due to "not-certified" device, but works perfectly fine when installed by Aurora.

The check seems to be purely store-based and never enforced later.


I have similar problems installing region locked apps as someone who's fairly frequently in different regions.


This is exactly why I switched to Aurora. I couldn't even install Balatro from the Play Store.


Same. Twint (basically the Swiss Venmo) insists that my phone is not compatible with it.

But using Aurora I can install it just fine and it works flawlessly.


Do you trust the banking app installed from Aurora enough to do your online banking? I don't, and I really wish there would be a decent way to verify that the installed/provided apps are legit. For me this is the biggest downside of using GrapheneOS, which I'm otherwise extremely happy with.

(for me, the whole point of using GrapheneOS is privacy and not sending data to Google, so using the PlayStore is not an option)


Android apps are signed. Can't you verify the signature?


Can you?

I'm pretty sure if I try calling my bank or searching the website to confirm the developer's public key fingerprint, there's not going to be any answer. You have to ask Google's servers to give you the APK and trust what it gives you, either via the front-end called Aurora or the front-end called Play Store


Privacy Guides is building a database of signing keys with a verifier app:

https://github.com/privacyguides/verified-apps-android

https://github.com/privacyguides/verified-apps/

I think in general trust is established for Play Store apps by downloading the app with the Play Store on a phone with Google Certified Android. Then the app can get the signing key for storage in the database. Then this can be used to verify APKs downloaded outside the play store.


Maybe not in practice, but in theory, it works. I don't think there's a better way of handling this without relying on some centralised authority (Google) to validate the authorship of an app, which is hardly desirable.


Doesn't AppVerifier allow you to do just that?


Doesn't Aurora download the packages directly from Google?


Presumably the parent does not want to have to trust Aurora to do that


It seems wise to have at least one alternative mobile phone app store. Even if it isn't very good. If the government can tell Google to do trivial things like, for example, change the name of bodies (plural now) of water, it can turn off your app updates, trapping you on insecure versions indefinitely. This probably matters more if you live outside of the US, but if I had a plan B for an app store on my phone, I would certainly at least evaluate it.


The government didnt ask google, they changed the name on the Geographic Names Information System (GNIS), which is the official legal mapping source which other companies like Google etc use. Hence the change filtered down through software from the top official channel.


Right, the government pulled a lever, and google complied within days. If the FTC declares app stores can't provide security updates without government license, that is another lever they can pull, and google will comply.

Wether or not the most recent example is the best example, doesn't matter. What matters is when the government says "jump" in legalese, google's lawyers say "how high?"


Name changes happen all the time and I would expect Google to match what the government sources use locally. The fact that the government is capricious is no reason for me to desire Google to become an alternative naming center.


Having to have a account is absolutely a downgrade and privacy-hostile.


A Google account is a personal identifier, it is linked to your person. Therefor trying to untie it from anything else is futile.

Google states: Using a false name or incorrect information when creating a Google account is against Google's Terms of Service.


The main reason for me to use GrapheneOS would be to sever the umbilical cord to google.

I don't really see the point of using GrapheneOS instead of Stock Android if I then have to use the play store.


Better security, for once. You get (security) updates a lot faster with GrapheneOS.

Also on GrapheneOS, Play Services and Play Store come unprivileged, sandboxed like any other app. So Google is not an admin on your phone, which I would argue is one step towards "severing the umbilical cord".

Moreover, GrapheneOS doesn't have any issue with apps sideloading.

And more. There are many reasons to use GrapheneOS.


ok, fair enough.

Using the Play Store on GrapheneOS whether via sandboxed Google Play or another frontend definitely doesn't defeat any the purpose of it. You do not have to use the Play Store on GrapheneOS, but the privacy and security features it provides are not cancelled out by using it.

GrapheneOS has privacy features such as Contact Scopes and Storage Scopes which are most useful when using privacy invasive apps. Using privacy invasive apps doesn't defeat the point but protecting against those is a core part of the purpose of GrapheneOS. Our Sandboxed Google Play compatibility layer is a privacy feature itself to enable people to use those as regular sandboxed apps without invasive access to be able to run apps depending on them.


> you can sign into the Play Store with a Google Account that isn't tied to anything else.

The problem with this is that increasingly Google is insisting on having a phone number to create a Google account. Further, they are aggressively deleting old accounts that appear to be dormant.

The good old days of creating a Google account with just an email seem to be swiftly becoming a thing of the past.


I recently had to set up a new Android device for work. Since I keep all my personal accounts separate from my work accounts, I needed to create a new Google account on that phone. I ended up paying $8 for a month of the cheapest service I could find just to get a phone number so I could create that account.


> For extra privacy, you can sign into the Play Store with a Google Account that isn't tied to anything else.

I dare you try creating a Google account that isn't tied to anything else.

Nowadays you can't even create an account in desktop browser without first having to scan a qr code from a mobile device first.


Doesn’t Google make it very hard to create an account tied to nothing (no phone or alt email)?


It's the SomethingAwful model: go to the store and find the cheapest Android phone from some prepaid company for :tenbux: then use it to set up your Google account during out-of-box-setup while on the store's free public WiFi (since Google OOBE allows free account creation without a number or existing email), then toss the phone in a drawer afterwards.

"Hope ya got ten bucks!"

(I got a random 5G Moto phone for ~$10 on clearance and it was an absolute shitter of a phone full of garbage packed in malware, but after cleaning and debloating as much as I can, it's at least a nifty toy to poke at Termux or something.)


The "Twitter counter" to that is, "We've detected suspicious activity on your account. To continue, please verify your phone number."


If you create it on a stock Pixel device the phone requirement gets dropped.


It’s undoubtedly tied to the phone with is tied to the owner


People report that it works even on grapheneos with sandboxed google play. My guess there's some fingerprinting going on, not necessarily that they're tying the account to some account id.


I tried and it didn't work, it kept asking for my phone number.


Well yeah. But if you care about anonymity on that level there are ways around that (i.e. buying in cash and creating the account using public WiFi).


What? Buy a phone in cash and have it billed to what, your monero wallet? This isn’t possible in today’s world, in the west anyways. Phones are tied to people.

And “worried about anonymity in that way”… that’s the topic being discussed here.


You can buy a phone with physical cash from a store or used p2p…

As far as cell service goes well yeah there is no such thing as anonymity. Towers will always know your location as long as the radio is on and that can be correlated easily.


How is your phone tied to you? You bought it through GOogle store?


What??


...with a Google Account that isn't tied to anything else

That isn't completely possible these days. Last I checked they want an existing email address and/or a cellphone number for verification. I guess "not tied to anything else" is proportional to how much you trust them to delete either of these bits of info after they are used, and not associate them with other accounts you might have used them with in the past/future.


We don't recommend using the Play Store as a first choice for obtaining apps. Aurora Store is another way to use the Play Store as a source of apps. If someone is using sandboxed Google Play in a profile, it makes sense to use the sandboxed Play Store to install apps. Aurora Store is mainly useful as a workaround for store listings enforcing Play Integrity and we do direct people to it for that.

Aurora Store still works fine. It doesn't require the default-enabled account sharing feature. It's not Aurora Store which is getting blocked but rather account sharing. Account sharing is against Google's terms of use and is now being detected more aggressively. We've warned about this for years but it took longer than expect for them to ramp up banning it. It's likely going to continue getting stricter.


Yes but Aurora isn't only for GrapheneOS.

I use it on a phone with (unfortunately) regular google play services. If I sign into the play store, that same account will be used for all other google services on the phone too. I'm not going to do that. I just don't want a google account (nor an apple one for that matter)


> GrapheneOS actually recommends against using Aurora and instead just using the Play Store, so this shouldn't really hurt users.

Interesting, I never tried Aurora on Graphene. For me the combination of Play Store and F-Droid worked really well so far.


>For extra privacy, you can sign into the Play Store with a Google Account that isn't tied to anything else.

Like my personal phone?)

Installing Google Play service is in itself a privacy downgrade.


It DOES still hurt.

For example the eBay app. Does not allow installing from the play store on grapheneos.


There are apps I cannot install via the Play Store in GrapheneOS, only via Aurora store.


> with a Google Account that isn't tied to anything else.

How can I get this wonderful thing?


i don't even have google play serices installed, let alone the play store...


Try installing an app that requires Play Store Integrity, say, ProShot by RiseUp Games.

Braindead dev claims this is to limit the "piracy" and bug reports, nevertheless it's either Aurora or APKMirror.


So, GrapheneOS is a supposed alternative to using Google's OS and their surveillance and adware - except you're supposed to run it on Google hardware, and apparently with a Google account and connecting to Google's services.

WTF?


GrapheneOS does not include any support for using a Google account and does not require using Google apps/services. There are many inaccurate statements here about what we supposedly recommend. We do not specifically recommend using the Play Store as a source of apps in the first place. We recommend using the sandboxed Play Store for obtaining apps from the Play Store.

GrapheneOS uses Pixels because those are still the only Android devices with reasonable security including decent updates, working encryption for users without a strong passphrase and the hardware functionality usable to provide decent exploit protection. GrapheneOS is in the process of adding support for upcoming Motorola devices meeting the official requirements.


So, what I said is true: You recommend using Google's phones and Google's app store.

Maybe in the future you'll recommend other phones, so it'll be less bad, but for now - you've verified that the "inaccurate statements"


No, we do not recommend using the Play Store as a source of apps over other options such as Accrescent. We document how people can obtain apps from the Play Store via both the sandboxed Play Store and Aurora Store. We explain apps with store listings configuring to block a non-Google-certified OS can be obtained via Aurora Store but that the sandboxed Play Store is generally a better way to install apps from it. Giving people recommendations on how to use a certain source of apps is not a recommendation to use it over the options we recommend including Accrescent.

Pixels are currently the only devices providing the updates and security features listed at https://grapheneos.org/faq#future-devices. GrapheneOS has an official partnership with Motorola where their devices are being improved to meet these requirements and provide official GrapheneOS support. We're actively working on it with them. We've reported vulnerabilities, weaknesses and made feature proposals to Google for Pixels but they certainly haven't directly helped us or supported us.


"For extra privacy, you can sign into the Play Store with a Google Account that isn't tied to anything else."

lol. lamo, even.


[flagged]


GrapheneOS is focused on privacy but that must come from a secure baseline.

GrapheneOS is much more privacy focussd than any other mobile operating system. Accrescent is the end goal for a secure and private app store but it's still in alpha. GrapheneOS is also the best for degoogling (eliminating all google services) because it comes with zero Google services unlike all the other ones listed here: https://eylenburg.github.io/android_comparison.htm

How can you call other OSes more privacy focused when they haven't closed as many VPN leaks as GrapheneOS? That's like bare minimum for privacy.


The problem is that to achieve privacy through security, Graphene has to treat the user as a potentially hostile actor.

Therefore, the system needs to protect itself and other apps from the user. Which is very much contrary to software freedom.


Verified boot does indeed make this more complicated, but it's totally possible to build Graphene with your own signing key and get full control over the OS that way (i.e. https://github.com/schnatterer/rooted-graphene).

Looking at their public statements on the matter, it seems like the problem isn't exactly that they treat the user as a potentially hostile actor so much as that they treat the system UI and persistent storage as a potentially hostile actor (though I admit from a practical perspective that's nearly the same thing): https://www.reddit.com/r/GrapheneOS/comments/13264di/is_root...

I wonder how they'd feel about something like protected confirmation to enable sudo: https://source.android.com/docs/security/features/protected-...


> Which is very much contrary to software freedom

I believe you misunderstand what "software freedom" means. You can compile and install GrapheneOS yourself, and you can grant yourself admin access. This is software freedom.

Software freedom does not mean that you should run everything as an admin, always. And just in case: software freedom does NOT mean that you should remove your firewall and let everybody SSH into your server by having a blank password.


You can't grant yourself admin access with the official build. Only the Graphene devs have the ability to push changes to the OS on your phone. Yes you can fork the software and build a version with your own signing key, then wipe your phone and install your custom build and thereby take back control, but then is that really still Graphene?

I think it's fair to say that that's at least borderline anti software freedom, even if it's true they have good security reasons for doing things that way.


Thinking about possible ways they could retain the same security properties without impinging software freedom... maybe there's a way they could make the root of trust default to a signing key embedded in the device's own secure hardware? Then by default that key could sign Graphene's own signing certificate to allow them to push updates, but the user would retain the ability to revoke that signature and sign someone else's certificate instead (or their own certificate) if they decided they didn't trust Graphene anymore, or wanted to give themselves root.


I am confused, why were your messages flagged? I disagreed with you, but I didn't see a reason to flag them? Also I don't know how to flag a message, but that's another topic.

It's not flagged now. But yes, way too many people use flags as an "I disagree" button these days. I feel like that used to be very rare (even down-votes aren't supposed to be used that way) and is becoming more common, though maybe it's always been this way and I just hadn't been on HN long enough to notice the pattern until now.

Yeah people tend to downvote for "I disagree", which is... not how I believe it should be used.

> I think it's fair to say that that's at least borderline anti software freedom

Then you don't understand software freedom either.

Software freedom doesn't mean AT ALL that random projects on the Internet MUST implement the features YOU want. Never, not at all, it's not borderline, it's not up to debate.

Software freedom is about being able to use the software the way you want, as in "you get access to the sources, you modify them, build them and run them". You can do that with GrapheneOS (well except for the binary blobs situation, but that's not in GrapheneOS' hands at all). Software freedom is NOT about GrapheneOS giving you root access on official builds because you want it. And it's also NOT about GrapheneOS installing Doom on the official builds because I want it.


> Software freedom is about being able to use the software the way you want

You can't use the software in the way you want if it uses hardware backed cryptography to block you from doing so.

> you get access to the sources, you modify them, build them and run them

This is completely infeasible for 99% of the population. If you technically have a freedom but have no practical way to exercise it, it may as well not exist.

You could argue "but someone else could modify it for you, build it, and make an easy way for you to install it", and normally I'd accept that, but given that installing that modified version would require you to completely reset your phone and install the new modified OS from scratch, I think it's debatable at that point whether you'd still be running Graphene, rather than a fork. And if exercising your freedom requires you to stop running Graphene and start running something else, is it really fair to say Graphene itself supports that freedom? Like I said, borderline.

If you're still not convinced, consider what would happen if companies started using remote attestation to verify you're running the official GrapheneOS build and block forks...


> You can't use the software in the way you want if it uses hardware backed cryptography to block you from doing so.

You can use the software the way you want, from sources. If I run an open source server at home, it does not give you the right to enter my house and come reboot my server, does it?

> This is completely infeasible for 99% of the population

Sure, it isn't. Still that's what software freedom is.

> If you technically have a freedom but have no practical way to exercise it, it may as well not exist.

I disagree, I'm very happy that free software exists.

> I think it's debatable at that point whether you'd still be running Graphene

It's not: you're running a fork at that point. That's precisely how free software works.

> And if exercising your freedom requires you to stop running Graphene and start running something else, is it really fair to say Graphene itself supports that freedom?

Yes! Again that's precisely what software freedom is about! When you run GrapheneOS, you have the freedom to fork it and run it however you want. When you run Windows or macOS, you don't.

> If you're still not convinced, consider what would happen if companies started using remote attestation to verify you're running the official GrapheneOS build and block forks...

Well GrapheneOS would still be free software?!?!? It's the software from those companies that wouldn't be. I hate remote attestation as much as the next person, and typically banks absolutely suck because they love doing that kind of bullshit. But because banks suck does not mean that GrapheneOS is not free software?

Note that I am not trying to contradict you for the sake of it. I believe too few people understand how open source works, and that is a pity because it is important to understand it. When I open source some code I wrote, I make it available for people to do whatever they want with the code. I don't give them ANY RIGHT on the products I sell (even if those products are running said open source software) or on the feature I implement.

Too many people believe that because it's open source, they have a right to tell the authors what features they should implement. This is wrong. You want root access on your GrapheneOS? Go fork it. I don't want it, I am happy with GrapheneOS. If GrapheneOS gave me root access, I would fork it to remove it. And that would still be free software!


> Well GrapheneOS would still be free software?!?!? It's the software from those companies that wouldn't be.

I think I have a broader definition of software freedom than you do. In this hypothetical scenario, GrapheneOS itself may technically be "free software" in the sense that the source code is open, but it would still be cooperating in a intentional scheme to prevent you, the user, from modifying it to work the way you want. Same deal if they started selling locked hardware with their signing key hard coded so you can't install a fork. You would legally have the ability to fork the software, but technical measures would be preventing you from running it.

Granted, they're not doing that, but it's one short step away. That's why I say it's borderline anti-freedom, not that it actually is.

I don't think it makes a difference whether the means employed to make a piece of software non-free are legal (copyright law) or technical (DRM, remote attestation, hardware locks). It's still restricting your freedom.


I really want to insist on this: when someone develops software, you don't get to choose what they develop. That's just life.

If they make their software open source, you get to fork it (sometimes contribute to it) and this is already very generous. But that's all.

I say that as an open source author and maintainer, and my experience is that the vast majority of developers do NOT understand that. I have been criticised, insulted, sometimes bullied by people who wanted me to implement whatever they wanted ON TOP of providing my work for free.

You can have your own definition of "free software" that means "the developers have to agree with my personal taste", and say that "Linux is borderline not free software because I want them to officially support Zig and they don't", but it doesn't bring much. What makes Linux free software is that you can fork it.

I guess I don't understand the need to have a definition that only serves for complaining about a free project not implementing a feature you want. I get it, you wish GrapheneOS gave you root access. But it is not the choice of the people who do the work and make it available for free. But because it is free software, you can fork it and modify it yourself, and this is great.


For what it's worth this isn't just my "personal taste". I think Richard Stallman and the Free Software Foundation, at least, would agree with my definition[1]:

> Freedom 1 includes the freedom to use your changed version in place of the original. If the program is delivered in a product designed to run someone else's modified versions but refuse to run yours—a practice known as “tivoization” or “lockdown,” or (in its practitioners' perverse terminology) as “secure boot”—freedom 1 becomes an empty pretense rather than a practical reality. These binaries are not free software even if the source code they are compiled from is free.

[1]: https://www.gnu.org/philosophy/free-sw.html#make-changes:~:t...

I didn't say anything about what GrapheneOS devs must do. They don't have to do anything. I just think that some of what they are doing comes close to impinging on software freedom in the same way proprietary software does regularly (though again, Graphene doesn't quite cross that line, in my opinion).


You misunderstand what Stallman says. The quote agrees with my definition.

You can do all that with GrapheneOS today.

What you are asking for is root access on the GrapheneOS official builds. Where does Stallman say you should get it?


I'm not asking for anything, I'm telling you what they are doing, and what they are doing is going right up to (but not quite crossing) the line of blocking you from modifying the software on your phone.

To re-iterate:

> If the program is delivered in a product designed to run someone else's modified versions but refuse to run yours—a practice known [...] in its practitioners' perverse terminology as “secure boot”—freedom 1 becomes an empty pretense

GrapheneOS literally implements secure boot, using a key you do not control. So if you install GrapheneOS, the Graphene devs have the ability to push updates to the code running on your phone but you yourself do not unless you completely uninstall GrapheneOS and wipe all data on the phone.

The only thing preventing this from being actually anti-freedom rather than merely borderline anti-freedom is that if you choose to completely un-install Graphene and wipe your phone there's currently nothing that will prevent you from installing another OS built with a different signing key (aside from the inconvenience and technical difficulty of doing so). If there were, then this would be a textbook example of what the FSF explicitly calls "not free software" in that quote.


Again you don't understand Stallman's quote. Let me try:

> If the program is delivered in a product designed to run someone else's modified versions but refuse to run yours—a practice known as “tivoization” or “lockdown,” or (in its practitioners' perverse terminology) as “secure boot”—freedom 1 becomes an empty pretense

Tivoisation or lockdown or abusively calling it "secure boot" is, according to Stallman, "non free". GrapheneOS does not do that. GrapheneOS does not even own the hardware that could do tivoisation. GrapheneOS is the fork of the original project that has been updated and installed on the original device. That means that not only GrapheneOS is free, but AOSP as well!

> is that if you choose to completely un-install Graphene and wipe your phone there's currently nothing that will prevent you from installing another OS built with a different signing key

And that's exactly what Stallman calls "free". If it prevents you from doing precisely that, it's not free. But it doesn't, so it's free.

Secure boot is a security feature. One that I want. One that makes GrapheneOS more secure than, say, a Linux on mobile (or all the other Android flavours that break secure boot, like it was for /e/OS on my FairPhone 3). The whole point of GrapheneOS is that it is secure, and therefore it is designed around that. Thanks to secure boot, if an app manages to get root access and modify the system, it will be detect on the next boot, and therefore it won't persist. This is a desirable feature.

You apparently don't want that, it's your choice. You can use LineageOS, which allows it, or you can fork GrapheneOS and modify that part.

This is all free, this is all how it's supposed to work, this is all desirable. GrapheneOS is free to make the product they want, and that product doesn't allow you to have admin access.

You seem to misunderstand "owning your device". It does not mean "the software allows you to do everything you want", it means "you can install whatever you want on it". If you install something that does not give you root access (i.e. GrapheneOS), it is your choice.


I said it's borderline not-free, not actually not-free so I don't know why you just wrote 7 paragraphs arguing against something I didn't say and have explicitly and repeatedly disclaimed.

Yes, GrapheneOS is free, but it has implemented features that are designed to make it harder to exercise that freedom, namely secure boot which puts it one short step (of baking their key in hardware) away from being exactly what that paragraph describes as not free.

(And I think you are the one misunderstanding the FSF's quote. They're mocking "secure boot" as perverse terminology for what the FSF calls "tivoization" or "lockdown". They're saying those things are one in the same. I personally wouldn't go that far, as I agree with you the software is still free as long as the key used for secure boot is not baked in to the hardware, and I think the security benefits of secure boot are real and not perverse. But the FSF itself is arguing against the whole idea, at least in this article.)


> I don't know why you just wrote 7 paragraphs arguing against something I didn't say

I argue against something you keep repeating:

> GrapheneOS is free, but it has implemented features that are designed to make it harder to exercise that freedom

This is wrong. First because it does not make it harder to exercise that freedom, and second because GRAPHENE DID NOT IMPLEMENT IT IN THE FIRST PLACE.

People arguing the way you do is, IMO, one of the reasons the "free software" movement lacks credibility. You're just whining because you wish you could have root access on your system without having to install it yourself.

I'm out.


I'm confused. Are you saying Graphene doesn't implement secure boot? Or that you don't think requiring users to wipe their phone and install a custom OS build before exercising their freedom makes exercising that freedom harder?

> You're just whining because you wish you could have root access on your system

This is false, and I think it's intellectually unhealthy to use your perception of a person's motives as an excuse to avoid mentally engaging with the substance of their argument.


> Which is very much contrary to software freedom.

Yeah, the goal is privacy although the OS is completely open source.

They do improve user experience by allowing disabling emergency alerts, call recording without alerts, no mandatory camera noise in Japan, no extra warning popup from installing APKs from the web (it's the same permission in every app store iirc), increases password length to 128 digits. All the network services are open source afaict while all the other mobile operating systems listed in that android comparison connect to Google's closed source services, netowrk permission, sensors permission, storage scopes, contact scopes.

You can still easily install whatever Android app you want on GrapheneOS and you can install dangerous apps like shizuku and apps with way too many permissions. But yeah the goal is privacy so that everyday people can protect themselves as well as journalists can protect themselves. I want journalists to get the best privacy possible without having to know a ton of technical things or making many choices.


> Accrescent is the end goal for a secure and private app store but it's still in alpha

Note that nobody (new) can submit to it today; the developer console HTTP 503s and is only available to an allow-list of developers.


Accrescent has been quiet for a while, but had claimed in the past they would open the store up for new submissions again soon, it will perhaps happen by the end of the year. Its self-imposed requirements for this are to provide a better developer experience and more common app store features developers (should) expect. They recently announced they will be posting more about the progress made towards such goal, after the big announcements and releases of some months ago.

I'm more worried about the lack of a police to take apps down when it is very clear they should not be there. This is a present problem, presently solvable and that is not acknowledged despite the fact it harms the user.


They just made an announcement on their social the are gonna announce stuff more on their social.

[flagged]


No, GrapheneOS is a privacy project. The primary focus is providing usable privacy. GrapheneOS solely works on security to protect privacy.

We never said that about the SafetyNet Attestation API and that's a dead service. We've explained that we cannot provide a long term for the Play Integrity device integrity level because they can easily detect spoofing and very easily block it. The device integrity level is also gradually phasing in a requirement for hardware attestation. Apps already use the strong integrity level to enforce it.


>For example they have stated they won't try to spoof SafetyNet because "we don't lie about security features"

They said they don't want to do it because it would stop working in the future when Google move to enforcing hardware-based attestation and it is not sustainable.


[flagged]


We don't receive early access to Android releases or security bulletins from Google.

SafetyNet Attestation API was replaced by the Play Integrity API and has been shut down.

Spoofing the checks needed to pass the Play Integrity device integrity level would only be a temporary workaround. It would stop working and we'd have to keep expanding it. It's easy for them to detect spoofing and ban it. They choose to focus on it happening at scale rather than individuals doing it with rare modifications. GrapheneOS is too widely used to get away with it.

Spoofing the device integrity level will become far more impractical once it requires hardware attestation. Remote key provisioning will also make it a lot more painful to use leaked keys for bypassing root-of-trust-based hardware attestation.


As far as I'm aware, they do not get the security patches and early bulletin access from Google. They get that from an undisclosed OEM.


The OEM is Motorola. The partnership was announced earlier this year.

You are correct about them not getting early access from Google. There was a post within the last few months saying that Google no longer releases a lot of the code via git, but instead requires submitting a form and downloading the code via Google Drive. Google are actively trying to make third-party development difficult.


We are told the OEM in question is not Motorola, and it's likely some benefits of the Mototola partnership aren't yet in effect due to silly bureaucracy. Not sure there is any reason to lie about this.

Embargoed ASB patches started being used in release 2025092500, but I can't find now the message where a Motorola employee (confirmed by a community moderator, spring-onion, in a Side of Burritos interview) first reached out publicly on the GrapheneOS Discord guild about how to obtain further technical guidance than the requirements list in the website which claims to be non-exhaustive, in order to confirm such message's date. Still, GrapheneOS claims (after the partnership announcement March this year) that ASB patches are provided by (effectively) a distinct undisclosed OEM, really meaning an employee is leaking them. Maybe even the person didn't disclose the OEM they work for but they must be associated to one in order to have access to this material.


> We're nowhere near a Fable-class model IMO, but things are going to get interesting in this next year.

I'm wondering of you could clarify your thoughts on this. I've had a hard time evaluating what Fable-class actually is capable of that sets them (or really it) apart from other models in a very significant way.


Have you tried it out? I doubt there is a general accepted definition. For me it is just more capable of deep reasoning/handling complexity. Still can mess up, still does not count as strong AI - but a level above Opus and co.


Could you give me an example of a similar task you asked Fable and a different model to do where Fable did a better job?

I have a hard time getting models like GLM 5.3 to not perform on my tasks but I might be biased.


Changes in a complex codebase. Opus can do it, but needs more handholding. Making the plan with fable and let opus implement it worked out well.


That's actually not quite what I was asking for.


Most windows laptops will do something like this by default to enhance the sound. Part of what ships as "Dolby Atmos" is some EQ-ing and normalization, with the default not being flat. It is just necessary to make those tiny laptop speakers sound half decent and not crap out all the time.



Used this to get an easyeffects Dolby profile for my framework 13 pro, made the sound at least tolerable.


You can actually extract the Dolby Atmos settings and run them under either EasyEffects or natively under Pipewire without EasyEffects, using the Python script at https://github.com/antoinecellerier/speaker-tuning-to-easyef.... (Tested on my Thinkpad, works great).


> Clean Air Act (CAA) Acid Rain Program (ARP) does not apply to power generation facilities that are not connected to a public electricity grid, commonly referred to as “islanded” power generation facilities.

This of course makes no sense whatever, as whether or not a power generator is connected to the grid has nothing to do with its environmental impact.


It literally is just a cartoon villain plan. The AI companies look at something called the "Acid Rain Program" and think to themselves "Fuck that, what's a bit of acid rain going to do?". I truly cannot comprehend the mindset here as hard as I try


> truly cannot comprehend the mindset

The mindset is "if I could harvest your organs for profit I absolutely would, and I would make it illegal to protest against it"


That’s completely unfair. They would also rent the organs back to us on a subscription plan.


Step 1: steal all of the worlds IP and make a judge rule it is fair use

Step 2: declare end of the Anthropocene (defined by man made influence on earth), while simultaneously accelerating mass extinction

Step 3: ???

Step 4: Profit?


You forgot the part where they finance this all with a never-ending pile of circular IOUs.


They definitely use three exclamation points instead of that last question mark.


Do not forget loans with APR starting at 24%. Recourse of course. With the collateral taken back if payments fail.


I recommend wathching "Repo! The Genetic Opera" on this subject.


Hey man, how else I am going to afford to pay six figures for this truck spread over 84 months?


I think you nailed the mindset with the "cartoon villain".


Less Snydley Whiplash and more the pig guy from captain planet though


Hoggish Greedly if memory serves. Regardless of one's politics Captain Planet is so campy it's fun to watch MST3K-style. Remember Linka from the Soviet Union? "Imperialist pigs!"


Both of whom could happily sit together on a corporate board. It's just capitalism!


When it comes to laws, do you just look at the title of the law, or do you look at the actual statute and regulations to see what the law applies to and what it doesn’t? Does a “vehicle inspection program” meant for commercial trucks apply to your car just because the title fits?

In this case, there is a 25 year old regulation that specifies what this program applies to and what it doesn’t. https://www.ecfr.gov/current/title-40/chapter-I/subchapter-C...


Blah blah blah. Yap yap yap. It’s funny how the laws always apply until it’s a rich fucker breaking them.

You might be fine with skirting the technicalities, but the rest of us have to live here and breathe the air.


These aren’t “technicalities.” What types of activities the laws apply to is a central aspect of every regulatory regime.


They are technicalities, because the intent of the law is clean air. A carve out for temporary generators is clearly not intended to allow megawatts of permanent generation to operate outside of the regulatory umbrella and abuse of it is allowing the rich to skate by on a technicality.


> They are technicalities, because the intent of the law is clean air.

That’s not how laws work, especially the Clean Air Act. “There are no solutions. There are only tradeoffs.” (https://ozgengungor.medium.com/one-of-those-quotes-thomas-so...).

The Clean Air Act was not designed to achieve cleaner air at any cost, but instead to achieve targeted pollution control that would have the greatest value at acceptable cost. The modern structure of the act was set in place in 1970 under Nixon, and is full of legislative compromises to balance incremental benefits to air quality against burden on industry.


> The Clean Air Act was not designed to achieve cleaner air at any cost

You will notice we are not talking "at any cost". We are talking about a very specific cost to AI hyperscalers.

> full of legislative compromises to balance incremental benefits to air quality against burden on industry.

These technicalities are being exploited for the benefit of approximately 10 people, and to the detriment of everyone else.

Your talking points are old and exhausted.


> These technicalities are being exploited for the benefit of approximately 10 people

Legislative compromises aren’t “technicalities.” The exceptions are as much a part of the laws as any other part. If they didn’t exist the laws wouldn’t have passed in the first place.

> Your talking points are old and exhausted

Your talking points—treating law as just an expression of intent rather than a reticulated framework—are third world mentality.


Huh??? The intent of the law is what the entire system and in the entire world is working nowadays, I mean in the real world - aka outside of the minds of the technocultists. This is exactly what the courts are doing everywhere, upholding the intent of the law, and also why legal AI is continuously failing at it - it can't figure out the intent among all edge cases and yeah technicalities.


> The intent of the law is what the entire system and in the entire world is working nowadays

No, in first world countries we follow the letter of the law, including exceptions.


I don't know why you must underline all that "first world" thing, it doesn't make your argument stronger. Please actually verify it, instead of blindly repeating slogans. Namely the courts may start with the letter, find subsequently the letter doesn't apply 100% because things and humans, then proceed to apply the spirit of the law the way they interpret it.


The AI companies look at something called the "endless government bureaucracy" and they think to themselves "fuck that, I'm not waiting 10 years for all that bullshit, I'll just use the loophole." I truly cannot comprehend any other reaction because I would rather have my fingernails ripped out than deal with years of government bureaucracy.


Government beauracracy, which provides things like democratic oversight, environmental protection, enforcing power grid standards and interoperability, construction regulations, etc? Would you rather we just didn't have those things?


It should be mind numbingly trivial to stand up a solar farm and ram through some transmission lines in the desert, and mind numbingly hard to set up a temporary gas generator. We needed regulatory exemptions yesterday for clean energy, public transit, and EV charging.


Oh it would be if AI actually made money. Turns out all those companies cheap out and don't actually want to put down the 20 billion for a nuclear reactor- which should be trivial if they were really the future!


They have billions of dollars, they're short on TIME.

They want computers in racks now and (rightfully imo) look at yearslong approval processes with disgust. Look at Ashburn, VA - they extract loads of money from these companies, and they keep getting investments because constructing new datacenters is easy thanks to state laws.

It's not about the money here it's about the time.


> They want computers in racks now and (rightfully imo) look at yearslong approval processes with disgust.

Disgust of the rules for me but not for thee? The rest of us have to follow the rules, but not them.

How about disgust for actual pollution? They could build clean, quiet and fast if "> It's not about the money it's about the time"

It doesn't add up, like at all.


> It doesn't add up, like at all.

Yes, it does. If you want solar? You need lots of panels on lots of land far away from the DC. You need transmission lines connecting the two. You need to fight NEPA/CEQA/whatever lawsuits for each element of the plan, the local town councils of wherever the hell you're trying to build, and the worst part is that they aren't even required to give you an answer - they can drag out the approvals for years until you give up and leave.

Compare that to a gas turbine, which can be trucked in, plugged in, and running inside a few days. Yeah, I think we should take measures to limit gas turbine deployments and encourage companies to spend more of their money connecting renewables to the grid, but that means that they need to be able to do it quickly and without catering too much to local interests.

> The rest of us have to follow the rules, but not them.

The rest of us are not installing 1MW gas turbines in our backyards. Even if we were, I don't think the current administration wants to enforce environmental rules on anyone unless it's to block renewables construction.


They don't care if you have to follow the rules either. Why don't you get mad about the fact that you are forced to obey all these idiotic rules instead of somebody else finding a way around them.


All of them are good except for democratic oversight. Those other things are beneficial and cheap and easy to comply with. It's the democratic oversight of what gets built and where that is nothing more than a giveaway to worthless bureaucrats, lawyers, activists, and NIMBYs.


The alternative to democracy is wealthy guys who can buy their way into anything being done forcing their will upon the "worthless" rest of the populace, as you called them. If only billionaires weren't held up by the monsters that are activists protesting their activities and lawyers acting as a check on their legal power.

Let's be clear, democracy isn't perfect and it usually isn't fast. But to date, it's the only system that has any hope of keeping the most powerful in check. Rejecting democracy is begging for someone who doesn't care about you to tell you what's right and wrong.


I get that anyway. It's just that in democracy it's a mob of millions of idiots who don't care about me. I guess I'd rather have it be the billionaires because at least they want to build things and advance our infrastructure and technology.


You're not thinking like a techbro. My startup shouldn't have to adhere to those regulations, but everyone else should. In fact, once my startup gets established we should make even more regulations


Do you get upset when staff have to wash their hands at your local eatery?


> I would rather have my fingernails ripped out than deal with years of government bureaucracy.

These are just words. What matters are your actions. Your action is that you will cause other people to suffer pollution in order to enrich yourself. Why can't you stand up like a man and just say that that is what you want to do?

And if you say "I am doing this to benefit humanity who need even more AI so badly" - Well those are also just words.


Who is causing what here? If there is no demand for those services then the data center will sit there idle and cause no pollution. You can't consume services that cause pollution without accepting your share of the responsibility.


Employees at the companies that do this stuff know exactly what these regulations are for and are violating them quite deliberately. They don't actually think it's "government bureaucracy" whatever they tell the public.


I would rather take /them/ going through fingernail ripping government bureaucracy for 10 years over /me/ having acid raid, but hey, I'm just a egoistical and don't see the Big Picture or something.


>Big picture

Well, if you juuust let the rich get richer, something (intentionally left unspecified) will trickle down on you.


What you label "government bureaucracy" is very often environmental protections working as intended.

One AI company's "bullshit" is another citizen's "clean air and water". Since the AI companies don't care about those negative externalities, the government can act help to mitigate the damage.


Why am I still surprised to see such braindead takes on this site


Yeah, username checks out


"Cartoon villainy" is the best possible way to describe this administration. I'm more than willing to accept lots of policy differences, but so many decisions just seem tailor made to fuck over 95%+ of the public. Like how could any sane person defend this?

It remains to be seen if the administration doesn't successfully steal future elections, but the vitriol against data centers is a rare thing that has huge bipartisan support. Texas of all places largely has a competitive governor's race because Republicans have stated they're willing to vote for the Democratic candidate because she has supported a moratorium on data centers while Abbott supports them.


Most generators not connected to the grid are for emergency backup purposes. Granted, this carve out is now clearly being abused, but the original intent is quite rational.

If we enforced strict regulations on all generators without any exceptions at all, your sewage lift station might not have a backup source anymore.


It isn't just emergency generators.

Many non-emergency generators are used because there is no grid to connect to and/or the power requirements are not anticipated to be permanent. The cost of a grid connection can greatly exceed anything justified by the use case.

There are entire industries that live off of large portable generators for non-emergency purposes because it is the only way to get power where you need it.


If that is the original intent, why did that not get added into the law? Explicitly specififying that the exception only applies to emergency backup situations would have solved this, right?


Because congress passed the law in 1970 and did not expect we'd lose the ability to pass legislation that fixes minor problems with the original laws.

Since congress can't do that anymore, to maintain a functional civilization we have to turn minor loopholes in the original law into load-bearing aspects of an industrial society.


"Emergency" is a spectrum.

Would you be OK with one specific generation station temporarily emitting 3x more than legal limit (e.g., from the hours of 2pm to 6pm) if the alternative is a 5% increase in absolute probability of a multi-day regional blackout? What about a 10% increase? Where is your red line?


Isn't the US in a perpetual state of emergency?

https://en.wikipedia.org/wiki/List_of_national_emergencies_i...


My reasonable guess is that they did not want to make those case that need off-grid generation too hard to build. And never considered that anyone would build any actually significant amount of off-grid capacity. At certain threshold grid just makes economic sense. So rational actors would never do that.

Sadly AI companies are entirely irrational actors so this really was rather hard to foresee...


Yep. The loophole is not hard to close, they could restrict the exemption to standby generators which only operate (1) in the event of a grid outage, and (2) for testing purposes.

For a genuine off-grid use case (eg: very rural locations), they could add a new exemption which allows installations up to X kW capacity per site where local grid connections do not exist. Set X large enough that it won't negatively impact applications like cabins or nature retreats, but small enough that it's not useful to a large operator like a datacentre.

Of course, this all requires a functional Congress... so good luck.


Clearly codifying intent in a string of bytes is hard, especially if an alternative makes a nice sound folding into a pocket.


The law is not a set of hard coded rules. It is an agreement between humans, tied up in unspoken conventions. The principle one being, don't be a dick. The law always breaks down when it is treated as a hard and fast set of instructions that can be "hacked" by slavish adherence to precise language.


> If we enforced strict regulations on all generators without any exceptions at all, your sewage lift station might not have a backup source anymore.

No need for the FUD.

It would just mean the backup generator connected to the sewage lift station must meet emissions regulations, like in every developed country on earth.

If you’re trying to say there are simply some generators that can’t meet emissions standards, I’m going to say you just aren’t trying.


Yes, that's what we're saying. A small generator cannot meet the emissions standards of a large generator.


Some of the most effective emissions control equipment scales down very poorly. The bigger you can make the plant, the more viable these technologies become.

https://en.wikipedia.org/wiki/Wet_scrubber

https://en.wikipedia.org/wiki/Selective_catalytic_reduction

https://en.wikipedia.org/wiki/Continuous_emissions_monitorin...

(et. al.)


You’re just not trying.

There’s no reason at all that “generator” can’t be batteries rated for x hours, or a small generator that IS emissions certified.

I.e. https://www.reddit.com/r/Generator/comments/1hydy6j/recommen...


that's a very different standard.


And now we will have to add more bureaucracy and regulations to the process because of the tech bro's abuses of reasonable carveouts. More bureaucracy that future tech bros/right wingers will complain about existing even though they chose to force the matter to the point of regulation.


I think its so that like people don't need to do an EPA assessment for their home backup generator right? They are very common where I live due to the instability of the power grid.


It seems pretty much how law (specifically common law) has always worked though. If Congress thinks the law should apply to them, then Congress's job is to write a law that applies to them. The president and judicial branches are not supposed to make new laws, but rather to enforce the laws as written.

My reading of the EPA's statement here is they also wanted to mildly warn the companies that if they ever in the future want to contemplate connecting to the grid (eg. to bring down costs), they should be aware that bypassing compliance now could have expensive consequences for them later. Of course, Congress (local or federal) could also change the law in the much shorter term, so there's risk to them either way if they design without any forward thought for how to comply. On the other hand, if this inquiry to the EPA was merely requesting clarity on whether they are exempt from the reporting paperwork, but are using otherwise standard and compliant designs, then maybe the law is already working generally as intended.


Giving the benefit of the doubt to this President and his EPA that they are simply enforcing the laws as intended is foolish, irrational, and against all known evidence and their own words and policies and actions.


The effects of this will be reduced by the realization that these regulations can be changed in the future. No one will make a large capital investment if it could be shut down in a few years.


> No one will make a large capital investment if it could be shut down in a few years.

They will if they think they can bribe government to give them exemptions to the new rules or they think they can cash out and leave someone else holding the bag before that happens.


Most regulations provide a grandfather clause that exempt existing players in the game.


There is no need in law for that. And if previous regulations were enacted in bad faith, it suck to be you if you depended on them.


This program targets acid rain. It only applies to coal and diesel. No one is building off-grid coal power plants.

Diesel generators are the standard for power generation where a grid connection is not readily available and/or the power needs are temporary (e.g. emergency backups). Cheap, easy logistics, and durable. This use case has always been allowed in practice because there is no practical alternative. Many industries rely on diesel generators for reliable site power.

It doesn't apply to natural gas power plants such as those used in data center builds at all because they don't produce this type of pollution.

I fail to see the big deal. This guidance appears to clarify the language so that it matches actual practice and intent.


burning methane does produce NO and NO2 (the N2 being oxidized at temperature). that does come down with precipitation and collect in bodies of water. over time as evaporation removes the water and its replenished with acidic rain, the concentration increases arbitrarily high.

idk how much NOx a GW or two of low efficiency (20%) gas turbine units produces, how wide that plume might be, and what the envionmental impact might be. but if we employed a few people that practice doing this kind of I'm sure they could tell us with high confidence.


CAA regulations are all based on cost-benefit analysis and also seek to exclude sources that are basically too small to be worth regulating. In this case, the governing regulations have a complex set of criteria before the permitting requirements apply: https://www.ecfr.gov/current/title-40/chapter-I/subchapter-C...

These criteria were last amended in 2001, so the EPA is just applying a 25 year old regulation here.


It does make some sense. There are some semi-reasonable scenarios where not that much power is needed and you use electricity.

Still they make no sense with data centres and there should be reasonably sensible name plate capacity on it.



It makes sense when you consider that the CAA is legal under the interstate commerce clause.

We have state regulations that could solve this if they wanted to.


You are being confused by the names. A general name doesn't mean it is a general law that applies to everyone.


Ah, so only power generation facilities connected to the grid can pollute? fascinating.


At this point, they can just disband the EPA, what a bunch of crooks.


No, no, no you don't understand it's beyond the environment, it's not in an environment, it's been towed beyond the environment.


But it does have to do with whether it's interstate commerce!


Pretty insane, expect data center to be data center + coal power plant soon, why bother with generators or the pesky local grid.


Somebody mentioned that a solar panel field to power a data center requires a lot of impact assessment paper work and approvals.

Whereas natural gas generators do not.

Hence the runs on gas turbines, while solar panels are plentiful. ( Although I'd guess the consistency of power is a bigger issue. )

Running existing coal is now supposedly more expensive then putting in new wind or solar ... all else being equal.


That might be a reason, but probably more relevant is the fact that when you want solar to provide all power for a data center, you need a lot of buffering capacity (batteries). And then you also need a back up for when the sun doesn't shine... Which is probably a gas generator.

Easier to just install a gas generator then


If we didn’t have stupid regulatory bullshit and protectionism, it would be cheaper to run a data center on solar and batteries in bumfuck Nevada


AI training, not inference, seems like it would actually be a good application for a solar powered DC because you could just checkpoint and pause when it gets cloudy. It might end up worth it for the free electricity.


If you think you are building God, and every second counts, interruptions cost you way more than measly electricity.


It doesn’t make sense to do that, hardware deprecates in 5years (it used to be 3) and is currently very expensive. So by using this approach you double the average cost of hardware per unit of compute completed.

If there wasn’t such a hardware squeeze and electricity was a higher percentage of the cost, yes, it would have made sense.


They should definitely use wind power, since you could use the fans to cool the computers at the same time!

I for one would love a nice HTTP status in the form of "due to the weather being nice and calm outside, AI services are down, go outside and enjoy the day"


Imposing rules like that is what we are supposed to use religion for.


If coal doesn't pencil out economically for the grid it still likely won't pencil out economically for data centers even if you remove some of the compliance stuff.


Fair enough, I don't know if it matters short term for massive buildouts, but I'm sure whatever comes out of this is not a benefit for anyone except the owners.


A number of data centres have been proposed in Alberta, including a giant Meta one. Alberta has a derelict, obsolete power grid that can't even serve the current population, so you might wonder how that is possible.

They're coupling them with dedicated natural gas power plants. Meta finally stopped the green charade and simply dropped out of RE100, as they're all just going full speed ahead on destroying the planet.


> expect data center to be data center + coal power plant soon

Why do you think that’s likely?


Because coal is the cheapest source of electricity that isn't banned in the USA.


Are you looking at a textbook from the 1990s or something? I'm sure that was true at some point, but it hasn't been true for a long time.


It seems likely to happen again. Many US utility coal fired power plants are scheduled for retirement and will not be replaced with new coal facilities. [1]

China is building lots of new coal generation, but also lots of new solar so coal use will be reduced during daylight (not the way a coal plant wants to run, but they'll adapt)

Give it a few more years and data centers with onsite coal will look like a genius cost cutting idea. Never mind all the pollution.

[1] https://ieefa.org/resources/nowhere-go-down-us-coal-capacity...


> Give it a few more years and data centers with onsite coal will look like a genius cost cutting idea. Never mind all the pollution.

The numbers keep getting worse. Building "onsite coal" is more expensive than solar and storage, but now it needs more expensive fuel and you need to dispose of the toxic coal ash which won't be free either.


The hope is in a few more years, we'll not have a cult hell bent on accelerating the apocalypse in charge of the largest economy in the world, or are you guys planning something different?


I assume the name of this startup is meant to be pronounced like "revel" rather than "revile."


Dealers choice :)


This thing does a much better job at cleaning their nano-texture displays compared to a regular, smooth microfiber lens cleaning cloth, so there is actually a reason for it to exist.

That being said, while I haven't tested this, you can get other "suede" style microfiber cloths that I suspect are functionally the same thing as the Apple Polishing Cloth.


Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: