Live data from Hacker News

CalyxOS – De-Googled Android Alternative

calyxos.org

121–130 of 496 posts

Re: CalyxOS – De-Googled Android Alternative

#121
post #93
post #76

Earlier quoted context omitted.

Yeah GrapheneOS is security over privacy, Calyx is privacy over security (and has a bit more mainstream appeal with MicroG, supporting push messaging and location services etc). GrapheneOS has also pioneered a lot of security measures, a lot of which have been added to Android proper (if you see their feature log, a lot of it says "removed because it was introduced in Android"). I wonder if that wouldn't have been th…

Don't privacy and security go hand in hand?

I see it as:

Private = not sending data out of my device unless I want it to.

Secure = resistant to someone trying to get into my device.

They do overlap a bit, to be private a device needs some base level of security. But a device can be very secure and still not be private as it's sending data out for analytics, tracking, etc.

Re: CalyxOS – De-Googled Android Alternative

#123
post #112
post #82

Earlier quoted context omitted.

Calyx has more focus on functionality and privacy rather than security. On Graphene, security is always priority #1. For example: Calyx provides MicroG. This means you can talk to Google Play services, though in a better, more privacy-conscious way. MicroG is an open implentation of Google Play Services. However, MicroG requires signature spoofing: You need to install a fake Google certificate so that it can trick of…

The microG creator goes into more detail about signature spoofing at https://github.com/microg/GmsCore/issues/1467#issuecomment-8... The concerns usually raised against that are due to the "default" patch included in their repository, which has a specific purpose. We don't use that, https://calyxos.org/about/tech/microg/ are the precautions we take to try and prevent abuse. I made it a privileged permission because t…

Yeah I agree, it's a good compromise and I definitely use MicroG despite that (though not on Calyx but Lineage for MicroG, as I don't have a Pixel phone). I think the Calyx precautions are more than adequate. And better than Lineage's.

I just wanted to highlight the difference in focus, GrapheneOS will always pick the security side when a compromise needs to be made. Another example is the "We don't lie about security features" stance about SafetyNet. Even though a GrapheneOS phone is arguably more secure than a random manufacturer-modified Android rom. I agree that signature spoofing has an unnecessarily bad name. Probably because some mainstream roms like Lineage eschewing it. Personally I think it's a great tradeoff between privacy and functionality.

Re: CalyxOS – De-Googled Android Alternative

#124
post #82
post #74

Earlier quoted context omitted.

How does CalyxOS compare to GrapheneOS?

Calyx has more focus on functionality and privacy rather than security. On Graphene, security is always priority #1. For example: Calyx provides MicroG. This means you can talk to Google Play services, though in a better, more privacy-conscious way. MicroG is an open implentation of Google Play Services. However, MicroG requires signature spoofing: You need to install a fake Google certificate so that it can trick of…

This is the trade off that I hate having to make, and I'm glad to see something like Calyx here.

I want a phone that respects my privacy and is secure, but I also want to use apps like Google Photos (my favorite app that I use more than anything, aside from Firefox), Lyft, Netflix, Slack, banking apps, airline apps, and, critically, Google Pay.

I get that using many of those apps might increase my exposure to tracking and privacy leaks, but I just want an OS behind them that I know I can trust in isolation, and that may have measures in place that at least try to mitigate some of the worst privacy abuses from the apps. (And if it can't always succeed at that, that's fine, I'll live.)

Meanwhile, my only real choices are stock Android, which I know I can't trust to protect my privacy (since Google's business model depends on that), and iOS, which will treat me like a child and not let me do what I want with my phone unless Apple approves. (I'm also really concerned about the privacy implications of Apple's plan to do client-side scanning for CSAM material, assuming that's true.)

So I just don't feel like there's anything out there right now that will let me run the apps I want, that is built in top of an OS that I feel I can trust. Calyx seems to be one of the few I've seen that looks like they're actually trying to be that.

Re: CalyxOS – De-Googled Android Alternative

#125
post #100

Only available on Pixel phones and a single Xiaomi phone.

We do want to support more devices, however not all of them meet our requirements https://calyxos.org/about/faq/device-support/#requirements-f... We're trying to find devices which do, and if not see if the requirements can be relaxed. The most important part that's missing from many phones is being able to relock the bootloader with a custom OS installed.

It would help if you'd put the supported devices right up on the front page. It saves much time for most visitors and doesn't end up in frustration if people get them on the second step.

Re: CalyxOS – De-Googled Android Alternative

#126

I’m thinking about buying a degoogled Android phone to replace my iPhone. The main things I want are: * Spotify needs to work over Bluetooth in my car * WhatsApp needs to work (preferably with push notifications) * I need the Fitbit app to work so my watch can show push notifications from my personal apps * a network-based location provider to be consumed by my personal apps (I’m working on a personal data and automa…

For you first two questions: Spotify will work with Bluetooth, and WhatsApp will have eventual notifications (real-time if the app was recently opened, up to seven hours later otherwise, at least on my device)

We're very close to getting the notification issues fixed.

We've sent some patches to microG to address them at https://github.com/microg/GmsCore/pull/1483

I'm running it on my device since a few weeks now and it has been quite reliable so far.

Re: CalyxOS – De-Googled Android Alternative

#127
post #93
post #76

Earlier quoted context omitted.

Yeah GrapheneOS is security over privacy, Calyx is privacy over security (and has a bit more mainstream appeal with MicroG, supporting push messaging and location services etc). GrapheneOS has also pioneered a lot of security measures, a lot of which have been added to Android proper (if you see their feature log, a lot of it says "removed because it was introduced in Android"). I wonder if that wouldn't have been th…

Don't privacy and security go hand in hand?

No. First, there are security measures that wreck privacy, e.g. sending all your data to some company's servers for virus scanning. Routing all your traffic through some filtering VPN provider. That kind of stuff. There are privacy measures that wreck security, e.g. not using personalized user accounts for certain things.

Security is also mostly up to definition, a secure computer system is a system that only does what it is defined to do. What this definition entails is up to the vendor, which isn't necessarily the same definition a user might want for security or privacy.

But generally, there is a large overlap between privacy and security.

Re: CalyxOS – De-Googled Android Alternative

#128

Earlier quoted context omitted.

> most of their added value is lost when running a custom rom Could you please explain?

Well, Google packages the pixel phones with their latest OS updates and pixel specific features like Gcam. By running a custom ROM you lose those. Its cameras mainly perform so well because of the big AI farms at Google.

Google Camera works just fine, entirely offline as well.

You do miss out on some other pixel-specific features (Hold for Me for example), but camera quality should be unaffected.

Re: CalyxOS – De-Googled Android Alternative

#130

Most of the de-Googled or Linux based mobile OSes have their installation restricted to Pixel phones. Why? Is there any option for old Motorola phones?

Because those are the phones that are supported in the upstream Android Open Source Project (AOSP), which these OSes are typically based on. Other phones, even ones that to a great job of publishing their sources (like Sony's), have their support living outside of AOSP. And older phones get dropped from AOSP, the original Pixel was dropped in Android 11. So, by only targeting the devices that AOSP supports these OSes can focus on the interesting part of building the OS, rather than getting bogged down with hardware support.
Post reply on HN