3

Could Apostrophy OS Be the Future of Cellphone Privacy? - Slashdot

 7 months ago
source link: https://mobile.slashdot.org/story/24/01/21/0523209/could-apostrophy-os-be-the-future-of-cellphone-privacy
Go to the source link to view the article. You can view the picture content, updated content and better typesetting reading experience. If the link is broken, please click the button below to view the snapshot at that time.
neoserver,ios ssh client

Could Apostrophy OS Be the Future of Cellphone Privacy?

Want to read Slashdot from your mobile device? Point it at m.slashdot.org and keep reading!

binspamdupenotthebestofftopicslownewsdaystalestupid freshfunnyinsightfulinterestingmaybe offtopicflamebaittrollredundantoverrated insightfulinterestinginformativefunnyunderrated descriptive typodupeerror

Sign up for the Slashdot newsletter! OR check out the new Slashdot job board to browse remote jobs or jobs in your area

Do you develop on GitHub? You can keep using GitHub but automatically sync your GitHub releases to SourceForge quickly and easily with this tool so your projects have a backup location, and get your project in front of SourceForge's nearly 30 million monthly users. It takes less than a minute. Get new users downloading your project releases today!
×

Could Apostrophy OS Be the Future of Cellphone Privacy? (stuff.co.za) 77

Posted by EditorDavid

on Sunday January 21, 2024 @07:24AM from the track-me-not dept.

"Would you pay $15 a month so Android doesn't track you and send all of that data back to Google?" asks Stuff South Africa:

A new Swiss-based privacy company thinks $15 is a fair fee for that peace of mind. "A person's data is the original digital currency," argues Apostrophy, which has created its own operating system, called Apostrophy OS.

It's based on Android — don't panic — but the version that has already been stripped of Google's intrusiveness by another privacy project called GrapheneOS, which used to be known as CopperheadOS. Launched in 2014, it which was briefly known as the Android Hardening project, before being rebranded as GrapheneOS in 2019. Apostrophy OS is "focused on empowering our users, not leveraging them," it says and is "purposely Swiss-based, so we can be champions of data sovereignty".

What it does, they say, is separate the apps from the underlying architecture of the operating system and therefore prevent apps from accessing miscellaneous personal data, especially the all-important location data so beloved of surveillance capitalism... Apostrophy OS has its own app store, but also cleverly allows users to access the Google Play Store. If you think that is defeating the point, Apostrophy argues that those apps can't get to the vitals of your digital life. Apostrophy OS has "partitioned segments prioritising application integrity and personal data privacy".

The service is free for one year with the purchase of the new MC02 phone from Swiss manufacturer Punkt, according to PC Magazine. "The phone costs $749 and is available for preorder now. It will ship at the end of January."

Additional features include a built-in VPN called Digital Nomad based on the open-source Wireguard framework to secure your activity against outside snooping, which includes "exit addresses" in the US, Germany, and Japan with the base subscription.

    • Re:

      Its possible.
    • Re:

      Indeed. But I would donate to a non-profit maintaining such a FLOSS OS.

      • Re:

        This lot may be what you are looking for - https://e.foundation/e-os/ [e.foundation]

        Nothing perfect, of course, but at least it's a large step in the right direction. FLOSS / non profit / privacy oriented / supports Android apps. Based off [doc.e.foundation] their own builds of LineageOS [lineageos.org] I understand. LineageOS is also FLOSS / non profit and Android app supporting but designed to maintain compatibility with Google so slightly more compromised on privacy.

        • Re:

          Both seem good. Been running LineageOS without google services for a while now.
          Lineage's feature, where you allow an app access to a resource (such as contact), but it only gets an empty/dummy store is absolute gold.

          Considering Murena fairphone as a replacement when my current phone dies. (ancient Nexus5, should be any time now...)
          Pinephone is a contender too.

          My ideal would be https://postmarketos.org/ [postmarketos.org] . But that's way out there.

    • Re:

      Agree.

      Of course....iPhone.

    • Re:

      Yeah, but you likely don't own it. It owns you.

  • Would you pay $15 a month so Android doesn't track you and send all of that data back to Google?

    Probably not. I only pay $17.33/month for the "Flex" Plan ($10 unlimited talk/text, $5/GB 5G data) from Ting/T-Mobile on my Pixel 5a. I obviously don't use much cell data, mostly WiFi, and not many calls/texts either -- so, basically, I don't use the phone much at all. I have my cell for for if/when I need it while away and for authentications. (I also have a landline at home, which I prefer for long(er) calls, but I don't use that one much either.)

  • The promises aren't worth the pixels they're printed on. Typically, five minutes after company looks halfway viable, someone will make an eye-watering offer for whatever they want from the company and it's done. Just, ya know, tell the users the absolute minimum you can get away with.

      • Right, because the Swiss never do anything financially suspicious
        • Re:

          > financially suspicious

          The European mindset says, "suspicion", the American mindset says, "privacy".

          Too bad the Americans are dominated by European-wannabees.

          Choice is good.

        • Swiss product ? Like crypto products from Crypto AG ? Never trust Switzerland for security and/or privacy. Switzerland is a known spy on its citizen, banking is just an exception.

      • "So it occasionally catches fire but it keeps perfect time? Sorry, been hanging out with Jack O'Niell too much..."
  • If they make a 5-5.4" version and keep a resolution of minimum full HD, I would buy it and happily pay the subscription.

  • It has already been proven that most people don't value their privacy at all and will gladly sell it for much less than 15 bucks a month. The rest of us have had this "OS" for years.

  • So all the heavy lifting was/is being done by GrapheneOS which is FOSS and Android is the actual underlying OS layer but these rentseekers come along and say that packaging some unauditable VPN service and an App Store makes it their OS that's deserving of a subscription, this has to be a joke/troll.

  • Buying this product to protect your privacy is akin to paying for YouTube Premium when you could just use Piped/Musicale and legally pay nothing for the same end product. All you're effectively paying for is for someone not to serve you unwanted additional services you can easily avoid. A second hand iPhone SE bought at a market with cash combined with a PAYG SIM (also bought with cash) is far cheaper, far more secure, and if you disable all the cloud services and use fake details when signing up for an Apple ID, is far more private too. If you use said second hand device for the full remainder of its lifecycle, you will have also pocketed enough spare cash to make up for any lost promotional deals you would have missed out on by not handing over your details to every other tom, dick and harry too.

    Even with the sandboxing it touts, this operating system does not resolve the biggest issue with Android, in that all the common apps you're likely to need (beyond what is supplied by the manufacturer) will still abuse your privacy (regardless of what it can see on the phone itself) because they're all glorified web containers for companies profiting by operating large data silos. If an app is tied to an account, whatever you're typing into those apps will still be slurped and shared with other parties. It also does not resolve the fundamental privacy issues with smartphones in general (unsecured cell protocols, cell tower analytical data being sold to unaccountable entitles, push notifications being ran through central servers in a mostly unprotected manner etc.)

    If you're concerned enough about your privacy to consider paying a subscription while also foregoing every other app you'd normally expect to use on a smartphone, consider following Naomi Brockwell's lead by migrating your phone numbers to VoIP [www.nbtv.media] instead.
    • Re:

      In addition to sandboxing they have their own app store, their own email services and mail apps, their own data services..you're paying for a google services replacement with screened apps with data stored in Switzerland with no 3rd party usage of that data, where extradition of that data is much harder. My hunch is people using this sort of phone aren't actively posting to tiktok or instagram or X and are actively trying to keep prying eyes off their location data while still having a useful data terminal.
  • While I can get a custom ROM for free, the time it takes to figure out which one to get, check compatibility with the phone, install it and so on has some monetary value. So I would be willing to pay for avoiding that hassle, but not 15/mo. Now, if they also significantly supported development (something like RHEL) of their ROM rather than pass-through open source ROM, it might be worthwhile at $15/mo.
    • Re:

      Same. The phone itself might work (good OS already and a jack? Yes please) but 15/month is a pretty steep price for....what? There doesn't appear to be any ongoing development or anything else so what are you paying for?

      If they were doing as you said and actually funding development and putting that work in then maybe (but 15/mo is still quite a steep ask.)

      Let's see if they survive and can lower the monthly rate. Somehow I doubt it.

    • You could also just get an iPhone on a payment plan for about $15/month, pay another $2 for a VPN and never install the YouTube or Facebook app.

  • Silent Circle tried this and failed miserably. There isnâ(TM)t enough of a market share to sustain a business, people donâ(TM)t care.
  • ...if all personal computers, including phones & tablets, came with no OS installed by law? When you turn on the computer, it simply asks you which (flavour of) OS you want to install (I think Raspberry PI does this?). You could choose from a list, e.g. Google's OS, device manufacturer's custom OS, & some popular 3rd party OS' that specialise in privacy, security, minimal, all the bells & whistles, social media addict, restricted use (children & employees), etc.. It installs & initiates,
    • Most people don't want to buy an engine. They want to buy a car.

      • Re:

        well your analogy fails a bit, successfully installing an engine *that is hooking up fuel,exhaust, transmission not to mention getting the##engine management" computer setup) uis a bit more complicated than booting from usb and installing your os of choice. Unless ofc you are on a system the is locked down in uefi. At any rate getting an engine into the car (if I understand correctly this is analogues to installing the os, hold on the engine is hw but os is sw, this analogy is either wrong or I''ve comple
      • Re:

        Who said anything about cars? I'm talking about device OS software. It takes a few minutes to install & configure, & can easily be turned into a simplified, consumer-friendly process. If internet connections are a bit spotty, a USB drive installer will work, no problem. It's not a technical issue, it's just that corporations don't want anyone but them to have root access in order to lock them out, control them, & create dependency.
      • Re:

        I had to buy a new engine for my car. It was $6000, installed, including new exhaust manifolds.

  • i would rather get an open hardware & open software solution that i dont have to rent, a smartphone i can buy once and i actually own it, something like the FairPhone or PinePhone and have a choice of phone software so i can pick GraphineOS or LineageOS or others
  • So wait a minute. You buy the hardware (paying upfront) and you _then_ must pay them a monthly fee to essentially hide your data/actually from prying eyes? What happens if you stop paying? Do the partitions come crashing down and suddenly the last year's worth of activity gets exposed for Google/others to see? How does this work exactly?

    It seems there already exist open-source alternatives, minus the rent-seeking and without the obligatory Adobification of cloud bullshit that nobody wanted in the first pl

    • Ah yes, âoeeveryoneâ(TM)s labor should be free but mineâ
      • Re:

        "Labor"? Are they paying someone to manually intercept the data packets before they get to google?

        • Re:

          How do you suspect their sandboxing software gets built, tested, and maintained?

          I am quite curious since we don't yet live in a post-scarcity Type II civilization.

          • Re:

            To paraphrase the GP:

            Would I subscribe to a service to keep my information private? No fucking way.

            Would I buy a product for a premium, that provably kept my information private? Quite possibly yes.

            Why? In the first model, "they" control whether your information is private or not, and to what extent, and for what period. In the second model, ** I ** do.

            That is a HUGE distinction that you are missing.

          • Re:

            Should probably ask GrapheneOS. They're probably doing most of the "labor."

  • Now, I need another operating system on top of Apostrophy OS so I'm really sure no one has access to my data. I think $14 is a fair fee for that peace of mind.
  • Unless and until people bugging your phone land in prison (and that very much includes the TLA people), this is going to continue. Do not trust your phone, there are too many bad people around than want your data. Many of them in government positions or working in high positions in large enterprises.

    • Re:

      Bugging a phone is a criminal offence (at least if done by intercepting and decoding the signals between cell base station and phone (or envy other patty of the telecom network) without a warrant), not shore about the legality of capturing the traffic on device and sendng it to a third party (ie the party doing the bugging), it probably deepens on whet country you are in, but I suspect that in most places it would be considered a crime, but might be hard to prove.
      • Re:

        1) If a vendor does it and basically coerces consent, it is not.
        2) If some TLA does it, it usually is not.

        Seriously, have you been living under a rock?

      • Laws only have as much relevance as their enforcement provides for.
    • Re:

      LineageOS for microG [microg.org] is pretty good.
      None of the Google apps, but most Android apps will sitll work anyway.

    • Re:

      Does your phone have a SIM? You don't need location on, tower based triangulation does a plenty good job.

    • The only real privacy there is is information generated within a singular mind that is never communicated in any form.
    • Re:

      Not all products are for all people.

  • They didn't do the work, they just bundled it.

    What I would do is find a phone that I could load GrapheneOS onto myself, and then I would do that.

    Rent seeking on someone else's labor is crap

  • Especially because I would have no guarantee at all it is what I will really get.

  • Paying someone to NOT do something?

    Rings a bell... isn't that called danegeld?

    Eff them.
    Recently switched from Telus because they were charging me $5/month to NOT use data.

  • $15/month never ending, is way too much. Windows charges a one time fee and support lasts for many years. That would be a better approach rather than a subscription that costs more in a year than a single Windows license.
  • 1. The question is moot in the US because your not on carrier whitelists therefore no VoLTE for you.

    2. There is a long history of security / privacy focused one trick ponies delivering none of the above and quickly going out of business.

    3. It is scummy in the extreme to rent access to something you didn't write and only superficially tweaked.

    4. They talk about privacy and yet the first thing you do.... drumroll... create an account.

  • will it work at an min level (emergency call?) with no sub or no internet to check licensing?

  • ... for something the company "promises", but you have no way of checking yourself. Why on earth would that company not secretly sell your data... or be forced to sell your data?

    BTW if you just want your software to run on a more secure system, just use text-based software and use mosh (based on SSH) to connect to your computer at home.

  • In a world where I'm doing everything I can to avoid subscription services, you can refer to the subject for my opinion.
  • This is great stuff, and a move in the right direction given what happened with Blackphone.

    No source code?
    No peer review?

    Monthly fee?

    No thanks.

  • This is just GrapheneOS wearing a mask. Why get this instead of just getting a Graphene phone?

  • The fact that they can't even pick a name and stick with it doesn't give me warm fuzzies about its stability...

  • I already use LineageOS with microg and wireguard with pihole/unbound, but would consider a paid service in the future. I switched to Proton Mail years ago and have been very satisfied paying for it. This seems like a similar good value paid service.
    • Two questions! How long will they support the phone os upgrades? Will they keep everything unlocked for people who want to flash to another Rom later on?
  • To propose any OS to replace the market contenders now, it must be formally verified like or surpassing seL4 or this is just another hipster mustache popularity contest.
  • That's all you need to know. This is a new company that nobody knows, and nobody has any reason to trust. They will, as likely as not, take your money and run, and then sell your private data anyway.

    • Re:

      Exactly this...and I see *nothing* but cons.

      For the sake of argument, let's assume that they actually will hold up their end of the bargain. Users *must* create an account in order to ensure that they pay the subscription fee, and the phone *must* enforce the termination of the "Apostrophy Services" if the subscription is terminated. Only the main website linked even addresses the "what if I don't pay the subscription" question, and they're pretty coy about what the "Apostrophy Services" are. If they're bas

  • So it is the same as volla OS, but with subscription and not available only to volla phones

    • Re:

      and e-os and probably others
      most fund their development selling their own phones, but nothing stops from instaling in other phones


Recommend

About Joyk


Aggregate valuable and interesting links.
Joyk means Joy of geeK