Live data from Hacker News

CalyxOS releases test builds for Fairphone 4, OnePlus 8T, and OnePlus 9

calyxos.org

31–40 of 67 posts

Re: CalyxOS releases test builds for Fairphone 4, OnePlus 8T, and OnePlus 9

#31
post #4

One thing that bugs me to no end with Android (don't know about iOS or various tweak android builds), is that it is sooooo hard to restrict basic things. I don't want random apps to start on bootup as an almost-invisible-service, instead I don't want anything to do with that app until I explicitly start it and use it. Revoking permissions should be supereasy - like remove any and all network ability (eg camera or fla…

I would love to see all permission clearly outlined in a central location.

Could even be part of the Firewall application in CalyxOS for all I care (have run this on a Pixel 4a for a year now and very impressed with the update cycle and stability offered).

Re: CalyxOS releases test builds for Fairphone 4, OnePlus 8T, and OnePlus 9

#32
post #10
post #6

Earlier quoted context omitted.

I'd pick Graphene over Calyx on privacy and security grounds, and Lineage over Calyx on device support or tweakability grounds. Graphene is honestly ahead on the security and privacy front. MicroG requires very strong privileges and weakens the comprehensive privsep you'd otherwise have; GrapheneOS offers sandboxed play services with the standard SELinux policies for unprivileged Android software. GrapheneOS also has…

> I'd pick Graphene over Calyx on privacy and security grounds, and Lineage over Calyx on device support or tweakability grounds. I'd pick Calyx over privacy grounds not Graphene. (I totally agree that Graphene beats anyone on security grounds by miles, and depending on your threat model, security could be related to your privacy) > MicroG requires very strong privileges and weakens the comprehensive privsep you'd ot…

> I'd pick Calyx over privacy grounds not Graphene. (I totally agree that Graphene beats anyone on security grounds by miles, and depending on your threat model, security could be related to your privacy)

CalyxOS is substantially less private than GrapheneOS, not just less secure. You seem to be claiming this entirely based on CalyxOS including microG rather than the sandboxed Google Play compatibility layer. Sandboxed Google Play is not part of GrapheneOS. It doesn't ship with it, and unlike on CalyxOS, there isn't a setup wizard page encouraging you to use Google services. CalyxOS uses Google services even without microG and you can't turn it off. Your claims really don't make sense. Sandboxed Google Play compatibility layer is an optional feature users can choose to use, and it uses exactly the same sandbox used for the apps themselves including the apps people want to use with it. Those apps include Google's libraries including the Play SDK. You're relying on exactly the same sandbox for the client-side part of Play services as Play services has containing it. That's actually not entirely the full story since Play services is API 32 and always has the best available sandbox, while many apps have a lower API level and get a somewhat weaken sandbox, like API GrapheneOS has a bunch of added privacy features, not simply security features. This page is a list of features added on top of AOSP 12.1: https://grapheneos.org/features. It does not list features implemented by GrapheneOS upstream that are present in AOSP 12.1 since those are no longer features differentiating it.

Privacy depends on security, and CalyxOS recently went 4 months without shipping the Chromium and Android security updates. How is that supposed to be private? They also covered up how bad it was and wouldn't admit to how much was missing. They've consistently done that. They've covered up security vulnerabilities in their code. They denied there were leaks in their "firewall" app toggles and are still pretending as if there aren't leaks even though those were explained to them in the past and they're well aware their approach doesn't work properly.

> If we're speaking of FAKE_SIGNATURE.... No it doesn't? If implemented properly (I don't know how Calyx do it, but I know I do), only apps in firmware are allowed to use FAKE_SIGNATURE, and if you build your firmware with only microg that has FAKE_SIGNATURE, then only microg can fake signature. Also it can fake exactly one signature, which is Google's. It's probably possible to make that patch better, if some people gives us reasons it is a flaw.

Except that microG is missing security checks and the full security model, and by doing this you're directly bypassing a security check.

> Really, please tell me in which threat model does using microg hinders security, maybe we can find a fix. So far, I've never heard any.

Projects spreading libel about security researchers lose the privilege of getting vulnerabilities reported to them and patches made for them. microG has a bunch of blatantly missing security checks and based on what you're saying it should be no problem for others to find and fix those. Also, how are you going to add all kinds of cross-app signature checks, pinning and parts of the missing security model to an app ideologically opposed to some of these things?

> With regards to privacy, I take unprotected opensource software over Google trackware no matter the sandboxes you put under it. Windows has a better sandboxing model than Linux, yet I feel much better doing random apt installs, than downloading random Windows apps.

microG still uses proprietary Google services and the proprietary Google libraries are still included and being used by every app using it. People can see for themselves that Google Maps entirely works without Play services other than compass calibration, and that the Ads SDK works fine without Play services. microG is open source middleware sitting between closed source libraries and services. CalyxOS includes the privileged Google eSIM apps by default which give Google your IMEI, with no warning about that.

GrapheneOS does not use Google services by default. CalyxOS uses Google services by default with no off switch even without microG and has privileged Google services in the OS.

Re: CalyxOS releases test builds for Fairphone 4, OnePlus 8T, and OnePlus 9

#33
post #26
post #15

Earlier quoted context omitted.

By default, Calyx is privacy-preserving, because it doesn't connect automatically to WiFi. You choose to connect to WiFi only if you want to. Yes, I'm very exaggerating the comparison, but still. My point is that the comment I'm answering touts the sandboxed Google Play Services. You can't tout it *and* say it's privacy preserving, it's a XOR.

> By default, Calyx is privacy-preserving, because it doesn't connect automatically to WiFi. You choose to connect to WiFi only if you want to. Going to simply interpret this as unhelpful sarcasm. > My point is that the comment I'm answering touts the sandboxed Google Play Services. Sandboxed Google Play isn't included in GrapheneOS. Users can choose to install apps which include Google's libraries and use the Google…

> Going to simply interpret this as unhelpful sarcasm.

I think it is helpful to convey the emotion that goes through me when I read such a remark.

> It includes a compatibility layer for users to run it in the full, strictest API 32 app sandbox with all the standard GrapheneOS enhancements.

How does it handle Doze? In original Android, no app is allowed to keep a TCP connection open forever. And without that, FCM is useless. Also I believe that having Google Play Services running permanently has an impact (more on that later in this comment)

> You can see for yourself that the full featured Google Maps app completely works without Google Play, and that their Ads SDK and other libraries work without it.

That's an interesting point, thanks, I'll probably spend some time exploring those things. That Google garden does such things doesn't really surprise me.

> Only apps using the Lite variant of the Ads SDK need Google Play services for it to work.

From the description of Lite Ads SDK, it sounds like something that every app developer should want, yet it looks like Google is down-publicizing it a lot, so noone actually use it, nice workaround from Google, thanks for the info.

I see you're focusing your whole speech on Ads SDK. Does it mean only the ads SDK has this behavior?

My personal use of microg is for apps I trust (mostly opensource, or where I'm a paying customer), which work (much) better with cloud messaging. (I have to admit, I trust those apps enough to know they don't have ads, but not enough to trust they don't have ads sdk). So I do believe that for my usecase, microg gives me a much better privacy than Play Services, because most apps won't contain the infinite list of trackers Google Play Services include. But if you have proofs of otherwise, please do enlighten me, you're more knowledgable than me on SDKs.

FWIW, I have one metric (a rather stupid one, I agree) which is IMO showing that there is a huge difference: the data transferred and the battery usage. I have an order of magnitude difference in data transferred, and I get at least 3 times more battery life in suspend. Which IMO definitely highlights the fact that Google Play Services running permanently has its own privacy impacts, even when giving them minimal permissions.

> CalyxOS doesn't simply include microG with users encouraged to use it. They use Google services by default, with no way to turn them off.

"Google services" are 100MB+ proprietary code, sending god knows what to Google. CalyxOS doesn't have 100MB+ proprietary code, with microg you exactly know which data is sent. And actually if I'm not mistaken, microg doesn't do google registration or cloud messaging by default, so I don't think it does any Google connection by default? I'm not exactly sure there. I'm sure cloud messaging is disabled by default though, so no permanent connection

> They recently went almost 4 months without shipping the browser or Android security updates, including multiple vulnerabilities caught being exploited in the wild and announced as such in bulletins.

Just like the biggest (or maybe second or third, I don't really track that) corporation in the world on their flagship, while they are 50000 times smaller? But anyway, you're right: again, I said that on security grounds, I'd always pick GrapheneOS, and that the relation between privacy and security is pretty complicated, and I understand that some privacy threat models requires stronger security than trust.

---------------- Edit: Removed this part which is no longer relevant.

> They significantly roll back the security model of the OS.

I'm guessing you're speaking of microg implementation when you say "roll back the security model". I'm curious why you didn't answer to the comment where I ask to point out precisely how that roll backs the security model.

Re: CalyxOS releases test builds for Fairphone 4, OnePlus 8T, and OnePlus 9

#34

There's some sort of battle happening between the devs of Graphene and Calyx as we speak: https://twitter.com/GrapheneOS/status/1511593168667611139?s=...

Sigh, always.

The users have been banned, it's just that no mods were around at that time.

We strictly don't allow any GrapheneOS talk at all on our channels due to this drama. I don't know what else to do.

See: https://view.matrix.org/room/!aPqEsAdWuysydZNCic:matrix.org/...

Not the thing one wants to wake up to, but what can you do.

Disclosure: CalyxOS lead developer.

Re: CalyxOS releases test builds for Fairphone 4, OnePlus 8T, and OnePlus 9

#35

I have an 8T, I use Android Auto a lot when driving. Do I need to build from source or can I sideload the package with CalyxOS?

Unfortunately that is currently not supported since Android Auto is a proprietary app and needs system / OS level privileges to actually work.

Re: CalyxOS releases test builds for Fairphone 4, OnePlus 8T, and OnePlus 9

#36
post #10
post #6

Earlier quoted context omitted.

I'd pick Graphene over Calyx on privacy and security grounds, and Lineage over Calyx on device support or tweakability grounds. Graphene is honestly ahead on the security and privacy front. MicroG requires very strong privileges and weakens the comprehensive privsep you'd otherwise have; GrapheneOS offers sandboxed play services with the standard SELinux policies for unprivileged Android software. GrapheneOS also has…

> I'd pick Graphene over Calyx on privacy and security grounds, and Lineage over Calyx on device support or tweakability grounds. I'd pick Calyx over privacy grounds not Graphene. (I totally agree that Graphene beats anyone on security grounds by miles, and depending on your threat model, security could be related to your privacy) > MicroG requires very strong privileges and weakens the comprehensive privsep you'd ot…

> If we're speaking of FAKE_SIGNATURE.... No it doesn't? If implemented properly

We've always heavily restricted as well.

https://calyxos.org/docs/tech/microg-details/

> Really, please tell me in which threat model does using microg hinders security, maybe we can find a fix. So far, I've never heard any.

I keep asking the same to anyone bringing this up. We'd be happy to even submit patches to microG for any issues found and reported.

Re: CalyxOS releases test builds for Fairphone 4, OnePlus 8T, and OnePlus 9

#37
post #34

There's some sort of battle happening between the devs of Graphene and Calyx as we speak: https://twitter.com/GrapheneOS/status/1511593168667611139?s=...

Sigh, always. The users have been banned, it's just that no mods were around at that time. We strictly don't allow any GrapheneOS talk at all on our channels due to this drama. I don't know what else to do. See: https://view.matrix.org/room/!aPqEsAdWuysydZNCic:matrix.org/... Not the thing one wants to wake up to, but what can you do. Disclosure: CalyxOS lead developer.

You're claiming no mods were around when Nicolas Merrill was right there in the middle of the conversation? It's blatantly not true. Screenshot is here for everyone to see:

https://twitter.com/DanielMicay/status/1511639628637511681

You shouldn't lie about things that are so easily disproven. The main thing you disallow in your rooms are people defending GrapheneOS against your misinformation and libel. Those are the people who get quickly banned. You're frequently the ones engaging and spearheading this. You only ban people when it's not going your way and then you clean things up after the fact just as you're doing here. The fact remains that you have NOT banned the people openly involved in highly abusive behavior, and you're directly part of it yourselves too.

Nick is frequently one of the people directly involved in bullying and libel targeting me along with pushing blatant misinformation about GrapheneOS. The incredibly toxic behavior directed towards us comes from the top. Nick, you and Techlore have orchestrated this. You're directly responsible for the highly abusive behavior directed towards me and you're going to be held accountable for it whether you like it or not. You act as if you're trying to stop it but you're more focused on removing the messages of people countering vicious attacks on us than you are on stopping the abuse you've regularly engaged it and encouraged. It did not become what it is now without the direct support of the Calyx organization and CalyxOS. Everyone tied to the organization is tainted by it and it will follow them.

I have plenty more screenshots to post on Twitter if you folks would like showing extremely abusive behavior from Nick. I can show both you and him supporting the abusive behavior and raids towards us. Most of these attacks come directly from the top and are heavily based on the libel and misinformation from you, Nick and Henry. The legacy of your project will be your abusive behavior. It's how you're going to be remembered. It's not as if you're doing anything beyond marketing and misleading users beyond that.

Eventually you folks are going to pay the cost of your nasty character assassination campaign and misinformation war both to promote your project and to harm GrapheneOS. You don't even do remotely the same kind of work. From the start, all you've done is try to take advantage of an unfortunate takeover attempt on our project. The attempt at undermining us was happening even in your early days when we were helping you and telling people about your project.

This is never going to go away and your continued escalation over the past year and especially the past few months is not going to go unanswered. You think you can get away with it because all we've done is talk about what's happening. It's not going to remain that way. Any project, conference or organization where you're involved and who you work with inherits all of this baggage going forward until you make any real attempt at reversing this and repairing the harm that has been caused. It will follow you around for the rest of your life. You will always be the people who engaged in extremely abusive behavior towards someone which a dozen people in your room who you have not banned have openly said is aimed at trying to drive me to kill myself. You were openly against even banning Kiwi Farms. There is nothing more that needs to be said.

Re: CalyxOS releases test builds for Fairphone 4, OnePlus 8T, and OnePlus 9

#38
post #37
post #34

Earlier quoted context omitted.

Sigh, always. The users have been banned, it's just that no mods were around at that time. We strictly don't allow any GrapheneOS talk at all on our channels due to this drama. I don't know what else to do. See: https://view.matrix.org/room/!aPqEsAdWuysydZNCic:matrix.org/... Not the thing one wants to wake up to, but what can you do. Disclosure: CalyxOS lead developer.

You're claiming no mods were around when Nicolas Merrill was right there in the middle of the conversation? It's blatantly not true. Screenshot is here for everyone to see: https://twitter.com/DanielMicay/status/1511639628637511681 You shouldn't lie about things that are so easily disproven. The main thing you disallow in your rooms are people defending GrapheneOS against your misinformation and libel. Those are the…

Geez, it's one message, there was more after it, when no mods were around. I can't speak on behalf of Nick of course.

I woke up, saw it, and banned those people. We don't allow people to do this for any project, ever. What else can even be done, there's thousands of people on the channel, and moderation is hard and time consuming.

People on the internet say things, you can't keep attributing it to us always.

Somebody joins our channel, your channel, posts on twitter, etc - how are we responsible for what they say anywhere else, we don't control their speech.

Learn how the internet works - this has been the crux of the problem all along, you attributing things to us, and then using that as justification of your behaviour doing exactly what you're accusing us of doing. All those threats :(

HN is not the place for this conversation either.

Re: CalyxOS releases test builds for Fairphone 4, OnePlus 8T, and OnePlus 9

#39
post #7
post #3

Nice development. Just yesterday I ordered a Pixel 6 to replace my ageing Ubuntu Phone — Google's Pixel smartphones are the only ones really well supported by privacy focussed Android forks like GrapheneOS and CalyxOS (I intend to install GrapheneOS on it). Currently, this seems like a decent middle ground between being able to run apps from one of the two app stores (Apple's and Google's) when needed without sacrifi…

GrapheneOS is collaborating with a hw vendor to create a device that can run GOS and which has similar hw to current Pixel devices. https://twitter.com/GrapheneOS/status/1490518600339308544

That is amazing.

I have been a happy GOS user for years. Sadly, my Pixel 3a EOL is next month. I opted for an iPhone this time as they generally are supported for longer periods of time.

Maybe my next phone will be a phone designed for GOS :)

Re: CalyxOS releases test builds for Fairphone 4, OnePlus 8T, and OnePlus 9

#40
post #4

One thing that bugs me to no end with Android (don't know about iOS or various tweak android builds), is that it is sooooo hard to restrict basic things. I don't want random apps to start on bootup as an almost-invisible-service, instead I don't want anything to do with that app until I explicitly start it and use it. Revoking permissions should be supereasy - like remove any and all network ability (eg camera or fla…

It's not the most fluid UX ( but then again it's not something you need every day so it makes sense to have it a few levels deep), but in Android, since many versions ago, you can go to Settings - Apps - app - Allow/Disallow auto-launch, background running, etc. From the same place you can also revoke permissions, and some Android skins have views with all apps that have access to X and Y.
Post reply on HN