Live data from Hacker News

CalyxOS releases test builds for Fairphone 4, OnePlus 8T, and OnePlus 9

calyxos.org

21–30 of 67 posts

Re: CalyxOS releases test builds for Fairphone 4, OnePlus 8T, and OnePlus 9

#21
post #15
post #14

Earlier quoted context omitted.

How is Calyx more privacy respecting than GrapheneOS by default? Not sure about the defaults on Calyx, but AFAIK GrapheneOS has zero connections to Google. You choose to install sandboxed Play services only if you want to.

By default, Calyx is privacy-preserving, because it doesn't connect automatically to WiFi. You choose to connect to WiFi only if you want to. Yes, I'm very exaggerating the comparison, but still. My point is that the comment I'm answering touts the sandboxed Google Play Services. You can't tout it *and* say it's privacy preserving, it's a XOR.

GrapheneOS doesn't automatically connect to Wi-Fi either unless you enable the option. It also has per-connection MAC randomization enabled by default so Wi-Fi is essentially anonymous when you use it anyway.

> you can't tout it *and say it's privacy preserving.

Why? Sandboxed Play Services has no special privileges on GrapheneOS and thus has the same level of access as any other app. How can it invade your privacy if you don't explicitly give it access to private information?

Re: CalyxOS releases test builds for Fairphone 4, OnePlus 8T, and OnePlus 9

#22

There's some sort of battle happening between the devs of Graphene and Calyx as we speak: https://twitter.com/GrapheneOS/status/1511593168667611139?s=...

This has been going on for atleast a year. There's a long video from Techlore which presents the CalyxOS side of the picture and places the blame with GrapheneOS leadership: https://www.youtube.com/watch?v=Dx7CZ-2Bajg .

It's a video pushing a whole bunch of clearly fabricated stories and libel about me. The leader of the Calyx Institute and multiple project members have also participated in this abusive behavior. They've tried to pretend as if their highly abusive behavior isn't real and is simply imagined. Techlore's video shows a series of doctored screenshots with him lying through his teeth about the history, context and content of the screenshots. He very openly gets pleasure out of directing his toxic community to harass me and teaching them to push these talking points about me being schizophrenic, crazy and delusional. You're spreading highly abusive and libellous content. The person claiming we're toxic is the one who is an abusive sociopath engaging in character assassination and running an abuse campaign against someone because they take great pleasure in abusing someone on the autism spectrum who gets extremely hurt by their behavior and this harassment campaign.

Nicolas Merrill and other Calyx Institute employees have extensive involvement in this. Nick has repeatedly tried to claim that I'm crazy and delusional. Today, Nick openly tolerated and showed his tacit support for ongoing raids on our rooms. Multiple people currently involved in massive raids on our room alternating between spamming extreme gore and libel were openly bragging about it in the Calyx room. He was there and perfectly happy to allow it. He has openly engaged with people repeatedly insulting me, harassing me and saying that I should kill myself. It's not the GrapheneOS community engaging in a misinformation / libel campaign across platforms and this highly toxic / abusive behavior.

https://twitter.com/GrapheneOS/status/1511593168667611139

I can link a whole bunch of other Twitter threads and archives about this but I currently need to deal with these ongoing raids on our room by CalyxOS.

Re: CalyxOS releases test builds for Fairphone 4, OnePlus 8T, and OnePlus 9

#23

Earlier quoted context omitted.

This has been going on for atleast a year. There's a long video from Techlore which presents the CalyxOS side of the picture and places the blame with GrapheneOS leadership: https://www.youtube.com/watch?v=Dx7CZ-2Bajg .

I don't like the video, it shows Daniel Micay as a toxic sociopathic man, while in reality he is nothing like that

It's a video pushing a whole bunch of clearly fabricated stories and libel about me. The leader of the Calyx Institute and multiple project members have also participated in this abusive behavior. They've tried to pretend as if their highly abusive behavior isn't real and is simply imagined. Techlore's video shows a series of doctored screenshots with him lying through his teeth about the history, context and content of the screenshots. He very openly gets pleasure out of directing his toxic community to harass me and teaching them to push these talking points about me being schizophrenic, crazy and delusional.

Nicolas Merrill and other Calyx Institute employees have extensive involvement in this. Nick has repeatedly tried to claim that I'm crazy and delusional. Today, Nick openly tolerated and showed his tacit support for ongoing raids on our rooms. Multiple people currently involved in massive raids on our room alternating between spamming extreme gore and libel were openly bragging about it in the Calyx room. He was there and perfectly happy to allow it. He has openly engaged with people repeatedly insulting me, harassing me and saying that I should kill myself. It's not the GrapheneOS community engaging in a misinformation / libel campaign across platforms and this highly toxic / abusive behavior.

https://twitter.com/GrapheneOS/status/1511593168667611139

I can link a whole bunch of other Twitter threads and archives about this but I currently need to deal with these ongoing raids on our room by CalyxOS.

Re: CalyxOS releases test builds for Fairphone 4, OnePlus 8T, and OnePlus 9

#24
Good to have options. For me I won't be even testing this distribution when looking at their preference for signal, tor, their own VPN and duckduckgo.

Thanks but no thanks.

For those in Europe our preference tends to be with Telegram, ProtonVPN and Qwant. Please consider this configuration profile as default in future releases for those in the European continent. Thanks.

Re: CalyxOS releases test builds for Fairphone 4, OnePlus 8T, and OnePlus 9

#25

Good to have options. For me I won't be even testing this distribution when looking at their preference for signal, tor, their own VPN and duckduckgo. Thanks but no thanks. For those in Europe our preference tends to be with Telegram, ProtonVPN and Qwant. Please consider this configuration profile as default in future releases for those in the European continent. Thanks.

As someone from Europe I would much rather have it default to Signal than to Telegram. I prefer encryption over "jurisdiction-based protection" or whatever security shell game Telegram is playing to protect my plain text messages.

Re: CalyxOS releases test builds for Fairphone 4, OnePlus 8T, and OnePlus 9

#26
post #15
post #14

Earlier quoted context omitted.

How is Calyx more privacy respecting than GrapheneOS by default? Not sure about the defaults on Calyx, but AFAIK GrapheneOS has zero connections to Google. You choose to install sandboxed Play services only if you want to.

By default, Calyx is privacy-preserving, because it doesn't connect automatically to WiFi. You choose to connect to WiFi only if you want to. Yes, I'm very exaggerating the comparison, but still. My point is that the comment I'm answering touts the sandboxed Google Play Services. You can't tout it *and* say it's privacy preserving, it's a XOR.

> By default, Calyx is privacy-preserving, because it doesn't connect automatically to WiFi. You choose to connect to WiFi only if you want to.

Going to simply interpret this as unhelpful sarcasm.

> My point is that the comment I'm answering touts the sandboxed Google Play Services.

Sandboxed Google Play isn't included in GrapheneOS. Users can choose to install apps which include Google's libraries and use the Google Play SDK. Regardless of whether people use sandboxed Google Play or microG, they're using the Google Play code inside each app using it. The whole point of sandboxed Google Play is that users can optionally choose to install Play services and the Play Store in the user/work profile(s) of their choice with it receiving ZERO additional access or privileges compared to the Google libraries / Play SDK within each app using it. GrapheneOS does not include Google Play and has no special sandbox for Google Play. It includes a compatibility layer for users to run it in the full, strictest API 32 app sandbox with all the standard GrapheneOS enhancements. It does not receive any special access or privileges. It can't do anything the Google libraries within apps can't already do themselves. The Sandboxed Google Play compatibility layer also includes the ability to redirect APIs like location services to the OS implementation. By default, location services are redirected to the OS implementation, so users don't need to give Location access to Play services. Of course, if users grant Location to apps using Google Play, they're trusting the app and all the included libraries, and any app using Google Play is using Google Play libraries.

You can see for yourself that the full featured Google Maps app completely works without Google Play, and that their Ads SDK and other libraries work without it. Their libraries can do everything that sandboxed Google Play can do on their own without it. That's the whole point. Google Play is not required to contact Google services. Apps can do that on their own, and Google's libraries within those apps are fully capable of doing it. They largely choose not to implement fallbacks for features, but in some cases they clearly do as you can see from Google Maps and the Ads SDK. Only apps using the Lite variant of the Ads SDK need Google Play services for it to work. And again, sandboxed Google Play is not included in GrapheneOS. CalyxOS includes microG as part of the OS and encourages using it through the setup wizard. That uses Google's proprietary services and code. The Play code in each app is not replaced. It has a bunch of serious privacy and security issues from not implementing all the expected security checks, in some cases because microG is ideologically against enforcing the security model for things like location services.

CalyxOS doesn't simply include microG with users encouraged to use it. They use Google services by default, with no way to turn them off. They significantly roll back the security model of the OS. They recently went almost 4 months without shipping the browser or Android security updates, including multiple vulnerabilities caught being exploited in the wild and announced as such in bulletins. How are users supposed to get privacy and security from an OS which lacks consistent security updates and has no problem rolling back or bypassing the standard OS privacy and security model? It isn't simply not a hardened OS. It's a dangerously insecure one.

Re: CalyxOS releases test builds for Fairphone 4, OnePlus 8T, and OnePlus 9

#27

Do these custom OSes preserve the native capabilities of the multiple cameras on the device? Can someone chime in with their experience?

AOSP Camera can't use them but GrapheneOS ships with a Camera app that's able to use all the cameras and a lightweight variant of HDR+. Google Camera can also be used on GrapheneOS simply by installing GSF and Google Camera. Network permission can optionally be revoked for both, and neither has special privileges. It's different on CalyxOS where using Google Camera requires giving a high level of privileges to Google Camera itself and Google services (microG).

Re: CalyxOS releases test builds for Fairphone 4, OnePlus 8T, and OnePlus 9

#28
post #2

Does anyone prefer CalyxOS over GrapheneOS or LineageOS?

It's definitely better than Lineage, since Lineage is the least private and secure out of all "degoogled" ROMs. However, it isn't as good as Graphene.

CalyxOS recently went almost 4 months without shipping Chromium (including WebView) and Android security updates. CalyxOS is not "degoogled" and uses multiple Google services by default without an opt-out. Look at their documentation. It also has privileged Google service integration enabled by default. If using Google services is considered "degoogled", what does it mean? Not having Google Play as part of the OS? They do have a reimplementation of a small subset of it using Google's services and it's specially privileged.

Re: CalyxOS releases test builds for Fairphone 4, OnePlus 8T, and OnePlus 9

#29

Do these custom OSes preserve the native capabilities of the multiple cameras on the device? Can someone chime in with their experience?

This question is weirdly worded so I want to be careful answering it. This is highly device dependent, and out of these devices I only have the 8T. Will it be the same as stock camera experience? Not unless the vendor blobs and camera frameworks are ported to these OS, which they almost never are. But camera drivers still used pulled from vendor image, just with an opensource camera app.

Status of the 8T's cameras: In the 8T's case 3 of the 4 back cameras are accessible in LineageOS (only 2mp monochrome is not), and only through Gcam or Opencamera, not the stock LineageOS app. The macro camera's access was only figured out in the past few weeks by the LOS maintainer. I use a modified version of GCam to access the other lenses. I believe Oneplus actually disabled the macro lens in their vendor rom, so this is a case where LineageOS and downstream roms from it like Calyx are adding back some functionality that was lost.

Re: CalyxOS releases test builds for Fairphone 4, OnePlus 8T, and OnePlus 9

#30

Good to have options. For me I won't be even testing this distribution when looking at their preference for signal, tor, their own VPN and duckduckgo. Thanks but no thanks. For those in Europe our preference tends to be with Telegram, ProtonVPN and Qwant. Please consider this configuration profile as default in future releases for those in the European continent. Thanks.

ProtonVPN (private, proprietary, trusted) can never be considered an alternative over Tor (open, FLOSS, untrusted).

While I'd prefer Matrix and/or XMPP over either: Telegram (single-device encryption for 1-to-1 chats only) is inherently less secure than Signal. Both require phone-number verification and thereby doxxing oneself to use.

Post reply on HN