Live data from Hacker News

CopperheadOS: A hardened open-source operating system based on Android

copperhead.co

61–70 of 105 posts

Re: CopperheadOS: A hardened open-source operating system based on Android

#61
post #50

How does this compare to CyanogenMod? Security is definitely important but how much should I trust this OS? Both CyanogenMod and CopperheadOS should be able to run smoothly withoug google-specific apps I believe, which is nice for some.

The problem is the vast majority of applications actually require Google services to run on Android devices. Running an Android device without GApps is pretty much pointless unless you are really using it for a very very specific purpose.

> Running an Android device without GApps is pretty much pointless unless you are really using it for a very very specific purpose.

This is an exaggeration; you can find plenty of solutions that don't require Gapps, AFAIK. However, I don't know that the typical end-user would be happy solving that problem or using imperfect workarounds. For one thing, you need some sort of GApps solution to access the Play store, AFAIK.

> the vast majority of applications actually require Google services to run

There are plenty of GApps subsitutes for people who want them; I've done some homework on it, but haven't gotten around to trying them and all of the following is "AFAIK"; it's just based on a bunch of reading.

----

These appear to be the two leading substitutes:

* TKApps: 6 editions containing varying subsets of Google Apps

http://forum.xda-developers.com/android/software/tk-gapps-t3...

http://forum.xda-developers.com/android/help/qa-tk-gapps-hel...

* MicroG Project: My impression is that this is most carefully engineered option. In addition to its full suite I think it gives you the option of installing only one component, the stripped down GMSCore, which provides substitutes for several Google Play Services APIs.

https://github.com/microg

http://forum.xda-developers.com/showthread.php?t=1715375

http://forum.xda-developers.com/android/apps-games/app-micro...

----

Also of interest:

* Blankstore: For minimal Play Store access, or maybe just the API to keep other apps happy.

https://github.com/mar-v-in/BlankStore

http://forum.xda-developers.com/showpost.php?p=29115263&...

* Fakestore: (I don't have a link, but it's the same concept as Blankstore)

* BeansTown106's Gapps: (I don't have a link, but your search engine should find it), "very complete and work quite well" per a dev of OmniROM, a leading Android fork

* GApps Browser: Google Apps sandboxed, so can login there without being logged on in web browser, for confidentiality

https://f-droid.org/repository/browse/?fdfilter=browser&fdca...

Re: CopperheadOS: A hardened open-source operating system based on Android

#62
Copperhead seems designed to protect against malicious attackers, but does it protect confidentiality against commercial tracking (another kind of attack)?

I'll add: I haven't come across another fork of Android that focuses on security so I'm rooting for these guys.

Re: CopperheadOS: A hardened open-source operating system based on Android

#63

This project seems interesting but largely impractical until a truly independent FOSS app store exists with a wide selection + security track record as good as Google Play or iTunes. I don't see how it gets there with such a narrow hardware selection.

https://f-droid.org/: Open source, the apps they list include the following: "This version is built and signed by F-Droid, and guaranteed to correspond to the source tarball below."

Re: CopperheadOS: A hardened open-source operating system based on Android

#64
post #28

Earlier quoted context omitted.

ASLR is already a part of pretty much every current operating system ( save FreeBSD-RELEASE )

ASLR is a band-aid. If you need it, your system is already insecure. It's just that the attacker may need to crash your system a few times before they get in.

All systems need it. All systems are already insecure. All desktops systems already implement it. This has been the situation for years now.

Re: CopperheadOS: A hardened open-source operating system based on Android

#65
post #50

How does this compare to CyanogenMod? Security is definitely important but how much should I trust this OS? Both CyanogenMod and CopperheadOS should be able to run smoothly withoug google-specific apps I believe, which is nice for some.

CyanogenMod's priority is not security; it prioritizes things like stability, compatibility, non-technical end-user experience, and relationships with developers. For example:[1] Rule #1 of CM is "Don't break apps". We recognize that there are nefarious apps out there, and many of our users would actually understand how to use permission controls (and the implications of using them). With our huge userbase, we have a…

And unlike Debian[1], RedHat[2], OpenSUSE[3], FreeBSD[4] they don't even have a documented list of security advisories and what update fixed them—and given the haphazard nature of CyanogenMod stable builds (including some devices receiving none for months when there are high profile security issues, yet no statement anywhere that those devices have any less security support than any other), I have little faith in the security processes of CyanogenMod. And that's before you even start to touch on the privacy aspects which his post is mostly about, as far as I can tell!

[1] https://www.debian.org/security/ [2] https://access.redhat.com/security/security-updates/#/securi... [3] https://www.suse.com/support/update/ [4] https://www.freebsd.org/security/advisories.html

Re: CopperheadOS: A hardened open-source operating system based on Android

#66
post #58
post #4

Earlier quoted context omitted.

"Devices will be supported until Google drops support from the Android Open Source Project. Google guarantees major version updates for at least two years after launch. Security updates are guaranteed for three years after launch along with 1.5 years after the last device is sold." As someone that is still using a phone from 2012, this is problematic since I have no intention of getting a new phone that often. Is the…

Cyanogenmod still supports security updates for the Galaxy S, a model released in 2010.[0] Is it still worth using a six-year-old phone? Maybe not, but if your device is lucky enough to have support it can last you a long time. [0] https://download.cyanogenmod.org/?type=nightly&device=galaxy...

That's nightly builds, which CM discourage use of.

The three most recent stable "snapshots" are from 2015-09-01 00:25:00, 2015-06-26 07:37:01, and 2014-11-12 08:14:51. Given Google has been pushing monthly security updates for a long time, I'd have massive doubts about about the status of security updates for it.

Re: CopperheadOS: A hardened open-source operating system based on Android

#68
post #58
post #4

Earlier quoted context omitted.

"Devices will be supported until Google drops support from the Android Open Source Project. Google guarantees major version updates for at least two years after launch. Security updates are guaranteed for three years after launch along with 1.5 years after the last device is sold." As someone that is still using a phone from 2012, this is problematic since I have no intention of getting a new phone that often. Is the…

Cyanogenmod still supports security updates for the Galaxy S, a model released in 2010.[0] Is it still worth using a six-year-old phone? Maybe not, but if your device is lucky enough to have support it can last you a long time. [0] https://download.cyanogenmod.org/?type=nightly&device=galaxy...

CyanogenMod doesn't have all of the source code or the keys to sign low-level firmware, so it's not possible for them to provide full security updates after vendors drop support. They only provide security updates for the Android Open Source Project components. CopperheadOS is security-oriented so it's not going to keep devices alive when it becomes impossible to provide proper security updates.

Re: CopperheadOS: A hardened open-source operating system based on Android

#69
post #50

How does this compare to CyanogenMod? Security is definitely important but how much should I trust this OS? Both CyanogenMod and CopperheadOS should be able to run smoothly withoug google-specific apps I believe, which is nice for some.

The problem is the vast majority of applications actually require Google services to run on Android devices. Running an Android device without GApps is pretty much pointless unless you are really using it for a very very specific purpose.

The vast majority of apps on the Play Store do not actually require Play Services. There are also plenty of open-source apps on F-Droid without any such dependency, and other mostly proprietary alternatives like the Amazon app store.

Re: CopperheadOS: A hardened open-source operating system based on Android

#70

Copperhead seems designed to protect against malicious attackers, but does it protect confidentiality against commercial tracking (another kind of attack)? I'll add: I haven't come across another fork of Android that focuses on security so I'm rooting for these guys.

Privacy enhancements are definitely within the scope of the project. Most of the current features are exploit mitigations though. If you look through https://copperhead.co/android/docs/technical_overview you'll see that there are a few privacy features already, and there are many in-progress. They won't be listed there until they're actually completed though.
Post reply on HN