> microG replaces some functions of Google Play Services while maintaining much more anonymity and privacy. I've said it before and saying it again on here for those that don't know: microG breaks the security model on android and adds in package signature spoofing. It's the only way to add a fake Google Play Services without needing to pull Google blobs. This is why projects like LineageOS are against using this met…
If signature spoofing is confined to apps that I designate as spoofed (such as microg), then I'm okay with it. No security problem as far as I'm concerned. I'd like to see people make their own apps that don't rely on Google services (or faked Google services) of course, like the Linux ecosystem.
CalyxOS – De-Googled Android Alternative
241–250 of 496 posts
Re: CalyxOS – De-Googled Android Alternative
#242The thing which always makes me hesitant about these projects is that they don't receive frequent security audits and not having an expensive brand behind them makes them more at risk to being willing to trash their name at the cost of my privacy and security. I consider these to be a fairly critical part of any project which claims superior privacy and security. I think about it this way: Should I trust A. The compa…
If you're hoping market forces would keep companies competitive and secure, well, people don't have much of a choice when it comes to mobile operating systems. Free market dynamics that should correct this problem don't really come into play when a two company cartel has 99.7% of the mobile operating system market nearly split in half between them.
Re: CalyxOS – De-Googled Android Alternative
#243It is asking a lot, but this would be nice: if the developer organizations behind CalyxOS and GrapheneOS could sell new phones with software installed, sort of like System 76 for Linux laptops.
I believe CalyxOS sells a Pixel 4a preloaded with membership ( https://calyxinstitute.org/membership/calyxos ).
Re: CalyxOS – De-Googled Android Alternative
#244The thing which always makes me hesitant about these projects is that they don't receive frequent security audits and not having an expensive brand behind them makes them more at risk to being willing to trash their name at the cost of my privacy and security. I consider these to be a fairly critical part of any project which claims superior privacy and security. I think about it this way: Should I trust A. The compa…
Re: CalyxOS – De-Googled Android Alternative
#245As someone who knows quite little about Android (currently in the Apple ecosystem, but considering jumping ship): When you use these privacy-focused Android versions without Google Play, is there a consistent way to get apps from the Play store to run on there? (e.g. download the APK from somewhere and sideload it). I'd really like an OS that doesn't spy on me, but there's e.g. some goverment ID apps, transit apps an…
I use f-droid for most of my standard apps (note-taking, calendar, etc) - and since I am not using gmail, those suite of apps are useless to me. I use firefox for my browser, and use the client provided by my email provider. The worst thing is basically not having Google Maps because while fdroid does work, it is not condusive to 'just looking things up real quick'. It's more of a 90's GPS where you pull over, take 5…
If you're okay with a closed source navigation app, Magic Earth strikes a balance between Google Maps and FOSS apps such as Organic Maps. Magic Earth uses OpenStreetMap data but layers its own address search on top of it to cover addresses and landmarks that are not available on OSM.
Google Maps does work on CalyxOS and so does its most fully-featured proprietary competitor, HERE WeGo. But if you only want to use free and open source software, I understand.
> Messages are received, but my phone won't show me unless i unlock the screen - and then I get alll the notifications at once.
Is your device configured to hide notifications when locked? See "Control how notifications show on your lock screen":
Re: CalyxOS – De-Googled Android Alternative
#246The thing which always makes me hesitant about these projects is that they don't receive frequent security audits and not having an expensive brand behind them makes them more at risk to being willing to trash their name at the cost of my privacy and security. I consider these to be a fairly critical part of any project which claims superior privacy and security. I think about it this way: Should I trust A. The compa…
Re: CalyxOS – De-Googled Android Alternative
#247Earlier quoted context omitted.
Interesting setup. Do you have any resources about how efficient TrackerControl is at preventing Google to collect data from the phone various system services?
I would also like to hear more on this, a quick look at TrackerControl's readme tells me it mainly functions as a blocklist. Which (I would think) the moment you turn off tracker control to use google maps (or whatever play services app you wanted to use for a moment), said app will send a flood of queued location data that it has been collecting in the background if allowed. I suppose that setup could work if the us…
No, it works per app. I'm also a TC user, it's quite great. Per app you tell it whether it should allow talking to various motherships. You can toggle on broad categories (for a given app) or also more fine-grained. It also logs which services applications tried to contact, so I can see that Spotify that I pay for is trying to send god knows what to Facebook (and that TC blocks it).
It takes a bit of setup because a ton of apps talk to a ton of centralized services (Aurora store and Newpipe obviously need to talk to Google, for example), but after that I'm a lot less bothered by apps including the Facebook sdk or something because it'll be stopped anyhow.
I'm waiting for the day that apps/websites stop telling your phone/browser to rat on you and they start doing it server-side. Lot less gdpr trouble because nobody can check what you're doing and goodbye blocklists. But so far it seems things don't yet work that way.
Re: CalyxOS – De-Googled Android Alternative
#248Earlier quoted context omitted.
I trust people with money as their motive about as much as I'd trust a serious alcoholic to hold on to a bottle of booze for me without taking a sip. Might not be a popular opinion but it is my 2 cents to spend. Could a someone at an open source project slip in an obfuscated backdoor in some esoteric area of the OS? Of course. But the risks of being found out are so much higher, after the fact that all changes at an…
The alcoholic will definitely take a sip. ... But they are also heavily incentivized to know where your booze is, care for your booze, and make sure it doesn't get stolen or poisoned. Because if something happens to you, where are they going to get the sip?
Where else are customers going to go? All phones in stores right now run OSes from either Apple or Google. Both companies can forsake their customers' trust and people will still buy phones that run their software.
That incentive doesn't really exist in a market that's ruled by a two company mobile operating system cartel.
Re: CalyxOS – De-Googled Android Alternative
#249Earlier quoted context omitted.
Man, stuff like this is so depressing to read. Like this is supposed to be a forum for showcasing new tech, projects, etc. What's the point of having this if people in the industry are going to say, "I don't like it because it's not backed by a trillion dollar company". What will change ?
OP didn't say he doesn't like it, just pointing out the reality. But yes, the reality is depressing.
Re: CalyxOS – De-Googled Android Alternative
#250Are there any resources summarizing the differences between… - CalyxOS - Purism, Librem - microG - /e/ - LineageOS - LineageOS for microG - GrapheneOS And I’m sure many other Android open source/degooglers?
All of CalyxOS, LineageOS, LineageOS for microG, GrapheneOS and /e/ are Android distributions (based on the open-source part of Android, with some modifications and additions)
Purism (brand name) Librem 5 (model name) is an opensource smartphones that reduces black boxes to closed areas, while on most smartphones black boxes like modem share RAM access, using a brand new GNU/Linux (so not Android) smartphone OS.
microG is fundamentally simply an opensource Android app, that replaces some small parts of Google Services (which are very big unauditable closed-source Android apps), so apps requiring Google Services may have a chance to work without Google services. However microG requires a bit more permissions than a standard app, that's why there needs to be a "LineageOS for miroG" to support microG.
Now, between CalyxOS, /e/, LineageOS, and GrapheneOS:
- LineageOS targets devices support. LineageOS supports many devices officially, and provides infrastructure to support many more unofficially. They also include many features, but it doesn't feel like they have a specific orientation, and they are happy to integrate with Google apps. They are the very core of Android community original development.
- GrapheneOS is security first and foremost, no matter the cost to usability (their philosophy there does seem to evolve to open to more users recently). They do (great) security original development.
- /e/ is market first. They focus on having the best experience to the user, and try to reach as many users as possible. They have very little original development, their value is mostly in communication, and providing a "cloud" account.
- CalyxOS is targeting a good private user-experience. This goes both by having good usable defaults, and filling gaps. They have nice original developments in making Google-less more usable.