Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Add device integrity/verification recommendations #2315

Merged
merged 1 commit into from
Nov 12, 2023

Conversation

jonaharagon
Copy link
Member

Changes proposed in this PR:

  • I have disclosed any relevant conflicts of interest in my post.
  • I agree to grant Privacy Guides a perpetual, worldwide, non-exclusive, transferable, royalty-free, irrevocable license with the right to sublicense such rights through multiple tiers of sublicensees, to reproduce, modify, display, perform, relicense, and distribute my contribution as part of this project.
  • I am the sole author of this work.
  • I agree to the Community Code of Conduct.

@privacyguides-bot
Copy link
Collaborator

This pull request has been mentioned on Privacy Guides. There might be relevant details there:

https://discuss.privacyguides.net/t/add-content-about-iverify-for-ios/14579/21

@netlify
Copy link

netlify bot commented Oct 24, 2023

Deploy Preview for privacyguides ready!

Name Link
🔨 Latest commit d5a31c8
🔍 Latest deploy log https://app.netlify.com/sites/privacyguides/deploys/6550b0791534b30008f5fa69
😎 Deploy Preview https://deploy-preview-2315.preview.privacyguides.dev
📱 Preview on mobile
Toggle QR Code...

QR Code

Use your smartphone camera to open QR code link.
Lighthouse
Lighthouse
4 paths audited
Performance: 81 (🟢 up 7 from production)
Accessibility: 91 (🔴 down 1 from production)
Best Practices: 98 (no change from production)
SEO: 88 (no change from production)
PWA: -
View the detailed breakdown and full score reports

To edit notification comments on pull requests, go to your Netlify site configuration.

@SkewedZeppelin
Copy link
Contributor

While my Hypatia may not be very effective at detecting general malware, it does offer a fairly rigorous database of known stalkerware apps thanks to the @AssoEchap project: https://github.com/AssoEchap/stalkerware-indicators

Maybe of interest.

@jonaharagon jonaharagon requested review from dngray, a team and blacklight447 and removed request for a team October 24, 2023 02:46
@jonaharagon jonaharagon added this to the v3.17 milestone Oct 24, 2023
@freddy-m freddy-m self-requested a review October 24, 2023 08:43
@dngray dngray force-pushed the jonaharagon/device-integrity branch from 84e5f04 to 240d5a0 Compare October 24, 2023 09:31
jonaharagon added a commit that referenced this pull request Oct 24, 2023
Signed-off-by: Daniel Gray <dngray@privacyguides.org>
@privacyguides-bot
Copy link
Collaborator

This pull request has been mentioned on Privacy Guides. There might be relevant details there:

https://discuss.privacyguides.net/t/help-me-i-got-a-virus-on-my-phone-what-to-do-now/14681/8

@ph00lt0
Copy link
Contributor

ph00lt0 commented Oct 30, 2023

Hypatia

Where is the discussion on this? I mean, I think this shouldn't be just pushed to the website without the forum thread. I actually do not think this is quite recommendable at all. The app is just a hash check AFAIK, the user interface is completely impossible to understand for a general user. Also, this app doesn't stop you from being infected at all, and the chance that it will notify you about it in my eyes is exceptionally low. Spyware like this can only be well detected with pattern based behaviour analysis. Once hashes of known things are out, you are far too late, and things like Google Play protect. I understand the need of this app for DivestOS as it does not have Google Play, but for others I do not see much benefit TBH.

@matchboxbananasynergy
Copy link
Contributor

As another thing to look out for - Auditor will soon be getting generic device support for their Stock OS. Should be mentioned here when that makes it in.

@jonaharagon
Copy link
Member Author

@matchboxbananasynergy what does that mean?

@privacyguides-bot
Copy link
Collaborator

This pull request has been mentioned on Privacy Guides. There might be relevant details there:

https://discuss.privacyguides.net/t/hypatia-android-anti-malware/14755/1

@matchboxbananasynergy
Copy link
Contributor

@matchboxbananasynergy what does that mean?

Currently, Auditor verifies Stock OS for supported devices, and Stock OS / GrapheneOS for Pixels.

Auditor will have generic device support where you can verify Stock OS on Android 10+ devices without them having to be explicitly supported in the code.

Copy link
Member

@freddy-m freddy-m left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Happy to approve this, it just seems a bit full on if for some reason you didn't notice the 'advanced' heading. Perhaps there should be more of warning in the introduction?

jonaharagon added a commit that referenced this pull request Nov 1, 2023
@jonaharagon jonaharagon modified the milestones: v3.17, v3.18 Nov 1, 2023
Copy link
Member

@freddy-m freddy-m left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

LGTM

Signed-off-by: Daniel Gray <dngray@privacyguides.org>
Signed-off-by: Freddy <freddy@privacyguides.org>
@dngray dngray force-pushed the jonaharagon/device-integrity branch from ce4d5c4 to d5a31c8 Compare November 12, 2023 11:01
@dngray dngray added the c:software self-hosted/decentralized software and related topics label Nov 12, 2023
@dngray dngray merged commit d5a31c8 into main Nov 12, 2023
6 of 7 checks passed
@dngray dngray deleted the jonaharagon/device-integrity branch November 12, 2023 11:01
@privacyguides-bot
Copy link
Collaborator

This pull request has been mentioned on Privacy Guides. There might be relevant details there:

https://discuss.privacyguides.net/t/v3-18/15135/1

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
c:software self-hosted/decentralized software and related topics
Projects
None yet
Development

Successfully merging this pull request may close these issues.

None yet

7 participants