The problem with all these approaches is it's too easy for a website to detect you're blocking their ads and then harass or block you. A browser extension like uBlock Origin has extra code trying to defeat the anti-blocker blockers that works a lot better.
It is ridiculous that my computer is a battleground for companies trying to trick me into buying goods and services.
Yes, it's totally unacceptable. Mobile devices are definitely an area where open computing is being lost. It's even worse in iOS, where running arbitrary code within the device you've bought requires a $100/y payment or running an insecure version of the operating system and a jailbreak.
GrapheneOS seems to be the only workable, half-decent solution. But there is a lot of tradeoffs that are neede.
In terms of user-control, I don't think GrapheneOS is the best solution in the Android ecosystem. It may well be the best in terms of security, but that's a different question.
Just like Google's Android, GrapheneOS does not allow the user arbitrary filesystem access under any circumstances. This means a few things:
You cannot take full backups of your phone or otherwise take out all your data. All you can do is ask each app kindly via a backup API for the things it's willing to give you.
If you ever want to replace GrapheneOS, maybe because you've found something better or because the project stops supporting your device, you need to re-unlock the bootloader, wiping all your data.
In essence, this means that replacing Google's Android with GrapheneOS swaps out one gatekeeper for another. Your data is still not yours. The same is true for e.g. CalyxOS, which also insists on locking the bootloader (with a non-user-controlled key) and providing no arbitrary filesystem access.
This is a definite degradation compared to the previous generation of Android distros such as Lineage OS, where users kept full control of their device and their data. Is it worth giving that up in exchange for stronger security? Maybe, maybe not. All I'm saying is that GrapheneOS does not represent the optimum in terms of user control.
Interesting! I hadn't considered that perspective. I think this is because of attempts to sandbox applications between one another right, and avoiding a single application getting all data within the device. It's interesting for me because I am having discussions in https://lobste.rs/s/9ipypq/updates_full_disk_access_macos where people lament the lack of isolation between apps in desktop operating systems such as MacOS.
But it's not just apps. ADB also does not get full access. Neither does the recovery (we used to be able to do full backups via TWRP, does anybody remember that?). The only party who could get full access to your data is whoever holds the signing keys - so either Google or GrapheneOS. This may be a fine tradeoff for many people but I'm not happy about it. This is not how I run my desktop Linux and I don't think I want to run my Android like this either.
If you find a solution that works and is open I'd be interested to hear it! I've been thinking in this area, albeit not with a lot of effort hehe. I'd prefer not to have a phone at all, though these days there are so many apps that require a phone, like banking and so on.
Run Android with local root and/or unlocked bootloader, like Lineage OS. You lose some security such as defense against evil maid attacks but it's very convenient and you're fully in control
Run something like GrapheneOS, including the locked bootloader, but build and sign it yourself with your own key. If done correctly this would let you have your cake and eat it too, but it's a bit of a hassle to set up. I think a project with proper support for this would be great.
It’s possible, for example, for a DNS operator to direct requests for your on-line banking service to its own proxy, and slurp up your credentials when you log in.
Drives me nuts that it requires root access to add to the hosts. Is it a conspiracy that Google wants you to see ads so you can’t modify the hosts? I have both ad-blocking & non-ad-blocking reasons to do so, but now with a rooted device everyone acts like my device is insecure—when I would argue I’m now more secure with ad/adware/spyware/malware all blocked via hosts. But it was never about my privacy/security to take this away from me on Android.
Yeah, I'm also really pissed that a "rooted" device is frowned upon as "insecure", and some enterprisey / financial / govt apps refuse to work "for my own safety", unless I manage to hide the rooting fact from them somehow. I'm so tired of it so I'm ready to give up, and the next Android phone I'll have is probably not gonna be rooted. I guess I lost in this cat-and-mouse game against the corporations.
I used to use an ad-blocking VPN for my android device, but then I installed tailscale which is it's own VPN, and I can't have two VPNs running. So now I get ads in all my non-web-browser apps, which is.... highly annoying. I'd love it if there was some solution there, but at least so far I haven't found one.
I can swear by Pi-hole as well, it works everywhere and I haven't had any issues with it at all. I used Tailscale, but due to its client apps on iOS being a battery hog, I have switched to Wireguard. Pi-hole worked equally well on both.
nelson | 23 hours ago
The problem with all these approaches is it's too easy for a website to detect you're blocking their ads and then harass or block you. A browser extension like uBlock Origin has extra code trying to defeat the anti-blocker blockers that works a lot better.
It is ridiculous that my computer is a battleground for companies trying to trick me into buying goods and services.
SamRW | 23 hours ago
Yes, it's totally unacceptable. Mobile devices are definitely an area where open computing is being lost. It's even worse in iOS, where running arbitrary code within the device you've bought requires a $100/y payment or running an insecure version of the operating system and a jailbreak.
GrapheneOS seems to be the only workable, half-decent solution. But there is a lot of tradeoffs that are neede.
muvlon | 10 hours ago
In terms of user-control, I don't think GrapheneOS is the best solution in the Android ecosystem. It may well be the best in terms of security, but that's a different question.
Just like Google's Android, GrapheneOS does not allow the user arbitrary filesystem access under any circumstances. This means a few things:
You cannot take full backups of your phone or otherwise take out all your data. All you can do is ask each app kindly via a backup API for the things it's willing to give you.
If you ever want to replace GrapheneOS, maybe because you've found something better or because the project stops supporting your device, you need to re-unlock the bootloader, wiping all your data.
In essence, this means that replacing Google's Android with GrapheneOS swaps out one gatekeeper for another. Your data is still not yours. The same is true for e.g. CalyxOS, which also insists on locking the bootloader (with a non-user-controlled key) and providing no arbitrary filesystem access.
This is a definite degradation compared to the previous generation of Android distros such as Lineage OS, where users kept full control of their device and their data. Is it worth giving that up in exchange for stronger security? Maybe, maybe not. All I'm saying is that GrapheneOS does not represent the optimum in terms of user control.
SamRW | 2 hours ago
Interesting! I hadn't considered that perspective. I think this is because of attempts to sandbox applications between one another right, and avoiding a single application getting all data within the device. It's interesting for me because I am having discussions in https://lobste.rs/s/9ipypq/updates_full_disk_access_macos where people lament the lack of isolation between apps in desktop operating systems such as MacOS.
muvlon | 2 hours ago
But it's not just apps. ADB also does not get full access. Neither does the recovery (we used to be able to do full backups via TWRP, does anybody remember that?). The only party who could get full access to your data is whoever holds the signing keys - so either Google or GrapheneOS. This may be a fine tradeoff for many people but I'm not happy about it. This is not how I run my desktop Linux and I don't think I want to run my Android like this either.
SamRW | 2 hours ago
If you find a solution that works and is open I'd be interested to hear it! I've been thinking in this area, albeit not with a lot of effort hehe. I'd prefer not to have a phone at all, though these days there are so many apps that require a phone, like banking and so on.
muvlon | an hour ago
There are basically 2 types of solutions:
Run Android with local root and/or unlocked bootloader, like Lineage OS. You lose some security such as defense against evil maid attacks but it's very convenient and you're fully in control
Run something like GrapheneOS, including the locked bootloader, but build and sign it yourself with your own key. If done correctly this would let you have your cake and eat it too, but it's a bit of a hassle to set up. I think a project with proper support for this would be great.
edwintorok | 13 hours ago
Sometimes that breaks scrolling on the webpage, apparently some websites have code to scroll to top until the cookie banner is accepted or rejected.
jaredkrinke | 19 hours ago
Doesn’t HTTPS protect against this?
toastal | 17 hours ago
Drives me nuts that it requires root access to add to the hosts. Is it a conspiracy that Google wants you to see ads so you can’t modify the hosts? I have both ad-blocking & non-ad-blocking reasons to do so, but now with a rooted device everyone acts like my device is insecure—when I would argue I’m now more secure with ad/adware/spyware/malware all blocked via hosts. But it was never about my privacy/security to take this away from me on Android.
dimonomid | 14 hours ago
Yeah, I'm also really pissed that a "rooted" device is frowned upon as "insecure", and some enterprisey / financial / govt apps refuse to work "for my own safety", unless I manage to hide the rooting fact from them somehow. I'm so tired of it so I'm ready to give up, and the next Android phone I'll have is probably not gonna be rooted. I guess I lost in this cat-and-mouse game against the corporations.
drmorr | 16 hours ago
I used to use an ad-blocking VPN for my android device, but then I installed tailscale which is it's own VPN, and I can't have two VPNs running. So now I get ads in all my non-web-browser apps, which is.... highly annoying. I'd love it if there was some solution there, but at least so far I haven't found one.
lemon | 16 hours ago
I had this exact problem so I set up Pi-hole on an old raspberry pi I had laying around, put tailscale on it and set it up as the tailnet exit node.
frontsideair | 14 hours ago
I can swear by Pi-hole as well, it works everywhere and I haven't had any issues with it at all. I used Tailscale, but due to its client apps on iOS being a battery hog, I have switched to Wireguard. Pi-hole worked equally well on both.
drmorr | 6 hours ago
Oh. That's smart! I should do that.
xilef | 21 hours ago
I have used personalDNSfilter for a long time, with no issues, and less ads