Live data from Hacker News

CalyxOS – De-Googled Android Alternative

calyxos.org

261–270 of 496 posts

Re: CalyxOS – De-Googled Android Alternative

#261

I purchased a Pixel phone to test this stuff on. I installed LineageOS and found I couldn't run some google apps. I reinstalled LineageOS with https://opengapps.org added during the install and made the mistake of transferring from my old phone which brought all the google services and everything back to the phone (mostly). I then installed CalyxOS - much easier install process than lineage. Really liked the defaults…

Don't you think it is kind of absurd that you have to buy a device from Google to degooglify it as CalyxOS does not support other devices. How difficult would it be to actually port it to a device already supported e.g. by lineage?

Re: CalyxOS – De-Googled Android Alternative

#262
post #200

Earlier quoted context omitted.

That's not really the point though is it? It's more like 'I do like it.. is it sensible to use it?' At least, that's how I read it, and how I feel about such things. I'd very much like my next phone to run Linux (i.e. be a Pinephone) though.

> I'd very much like my next phone to run Linux Why again? Android is already free and open source and Linux doesn't have good answers for the proprietary goodies

I like the level of control and ease of reproducible setup that I have on my desktop, and find my (Android) phone frustrating to use in part because it lacks it.

It's not without trying either, I've worked on and off on a terraform provider for Android - currently apps only but with some vague intention to try to manage as much of settings as possible (not much, AIUI). It's just not meant to be used like that though, of course, and I wish Linux was a viable enough option that, at least among nerds already using Linux for work if nothing else, it didn't need to be justified for use on phones.

Re: CalyxOS – De-Googled Android Alternative

#263

The thing which always makes me hesitant about these projects is that they don't receive frequent security audits and not having an expensive brand behind them makes them more at risk to being willing to trash their name at the cost of my privacy and security. I consider these to be a fairly critical part of any project which claims superior privacy and security. I think about it this way: Should I trust A. The compa…

There should be a third party independent group to conduct audits. That might solve this.

Re: CalyxOS – De-Googled Android Alternative

#264

The thing which always makes me hesitant about these projects is that they don't receive frequent security audits and not having an expensive brand behind them makes them more at risk to being willing to trash their name at the cost of my privacy and security. I consider these to be a fairly critical part of any project which claims superior privacy and security. I think about it this way: Should I trust A. The compa…

Anyone who has managed a product security program will tell you that's it's impossible for small groups to keep up with the complexity and attack surface of products like android. From a consumer perspective, going with A and trusting the company is by far the safest option.

Sorry to be a pedantic but: Two People created CopperheadOS, one of them now works on GrapheneOS. The security mitigations developed for those were incorporated upstream into Android, decreasing the attack surface.

Re: CalyxOS – De-Googled Android Alternative

#266
post #212

> microG replaces some functions of Google Play Services while maintaining much more anonymity and privacy. I've said it before and saying it again on here for those that don't know: microG breaks the security model on android and adds in package signature spoofing. It's the only way to add a fake Google Play Services without needing to pull Google blobs. This is why projects like LineageOS are against using this met…

I've said this in another comment, but I'll duplicate here: The microG creator goes into more detail about signature spoofing at https://github.com/microg/GmsCore/issues/1467#issuecomment-8... The concerns usually raised against that are due to the "default" patch included in their repository, which has a specific purpose. We don't use that, https://calyxos.org/about/tech/microg/ are the precautions we take to try an…

Making it system-only still isn't ideal. It then requires a full OS update to push updates to microg/playservices, cannot just update the app components if vulnerabilities are found in the wild.

I would like if there was stronger privacy laws or antitrust orders that force Google to open their service provider API's so people can choose alternative location/push providers, but this doesn't seem like it will exist soon.

For many users, it's going to be the best usability compromise to use minimal play services and use apps that don't send content over the push networks (signal is like this, element can be configured this way).

Re: CalyxOS – De-Googled Android Alternative

#267

How risky is it if I install this on a device that is not on the supported list?

Not recommended. Downloads are tailored to specific device models, and installing an operating system image intended for a different device model would not work and could brick your device. If your device is supported by LineageOS but not CalyxOS, LineageOS for microG is an alternative OS that might work for you:

https://lineage.microg.org

Re: CalyxOS – De-Googled Android Alternative

#268

The thing which always makes me hesitant about these projects is that they don't receive frequent security audits and not having an expensive brand behind them makes them more at risk to being willing to trash their name at the cost of my privacy and security. I consider these to be a fairly critical part of any project which claims superior privacy and security. I think about it this way: Should I trust A. The compa…

To say that trillion dollar companies are less likely to fail at security/privacy because all their decisions take into consideration the hypothesis of reputation damage seems simplistic. They also have the money to pay for damage control.

Re: CalyxOS – De-Googled Android Alternative

#269

Anybody have experience using something like this (or others like GrapheneOS) as a daily driver? I’m interested in moving away from Apple and big tech in general, but I don’t know how practical that is yet.

CalyxOS on a Pixel 5 with microG for the past month. The only two problems I've had have been that I can't install the CapitalOne app and I can't install any paid Google store apps. I have a backup Android phone (Unihertz Jelly 2) with LineageOS and Google Play Services / Play Store installed, which I haven't had any issues with at all. I don't use Google Pay, Google Assistant or Google Maps. Those three apps are my biggest pain points, but a sacrifice I'm willing to make. I do use Garmin Pay on my Garmin watch and the Google Maps web app.

Re: CalyxOS – De-Googled Android Alternative

#270

The thing which always makes me hesitant about these projects is that they don't receive frequent security audits and not having an expensive brand behind them makes them more at risk to being willing to trash their name at the cost of my privacy and security. I consider these to be a fairly critical part of any project which claims superior privacy and security. I think about it this way: Should I trust A. The compa…

> A. The company which has thousands of developers working on it and wants to avoid their brand being dirtied by failures in security and privacy.

They don’t seem to be too much concerned about failures in security and privacy… Their entire business is based on dismantling of privacy, why should they be trusted more than companies that have alternative business models?

Post reply on HN