Earlier quoted context omitted.
Off the top of my head: Lots of banking apps don't work. RCS has only just started working. No "Find My Device" support. Permissions model is difficult to understand - even I struggle with it. Standard launcher has tiny icons which can't be adjusted. Pop on to https://discuss.grapheneos.org/ and see the struggles which users have.
> No "Find My Device" support. "Find My Device" means the location of your device is constantly sent to and stored on someone else's computer (the "cloud"), and it is something that shouldn't exist unless that someone else's computer happens to be yours.
LineageOS 23
131–140 of 188 posts
Re: LineageOS 23
#132Earlier quoted context omitted.
Ok, less so NFC, but my bank and all the governments I have to deal with have reasonably functional websites. It's clearly possible.
Where are you from? I live in Germany. I use ING and DKB as my banks. Both of the banks require a Play Integrity-checked app as their default 2FA.In the past I used Sparkasse and Commerzbank. They too required a PI-approved app. As an alternative you can order a code generator but for DKB that requires a paid debit-card. ING disables the phone app if you use a code generator. You cannot have multiple 2FA.
Re: LineageOS 23
#133Earlier quoted context omitted.
I have used both, and I can personally use my smartphone properly with both. GrapheneOS is more strict about security, making it more secure but less accessible (at the moment you can only run GrapheneOS on Pixel phones). I am happy with GrapheneOS' policy: that's exactly why I use GrapheneOS, to the point where I bought a Pixel just for GrapheneOS. Many people complain about GrapheneOS not supporting other phones. I…
There is little point in fortifying the front-door when the backdoor is wide open. The hardware itself should never be trusted when being produced by a vendor like Google and cannot be verified on the component level. Their business model completely revolves in reducing your private sphere and sell it to others. Never use google hardware if you are serious about security.
Their business model also does not involve selling data afaik, it's selling access to their adspaces [1] all over the internet including the ability to target people (based on information Google jealously hoard). They stand to lose just as much as most other OEMs if they did suspicious things in hardware just like Apple, Samsung etc.
If you're serious about security you will avoid using OEMs that have unfortunate patch gaps which leave device owners at the mercy to *known vulnerabilities* [1][2][3][4] as well as unknown threats which is fortunately one of GrapheneOS's many reasonable device support requirements.
[1] https://blog.google/products/ads-commerce/more-effective-med...
[2] https://srlabs.de/blog/android-patch-gap
[3] https://srlabs.de/blog/android-patch-gap-2020
[4] https://www.android-device-security.org/talks/
[5] https://techcommunity.microsoft.com/blog/vulnerability-manag...
Re: LineageOS 23
#134Note, GrapheneOS seems to have been able to secure partner access to Android early security releases, but this comes with the cost that the source used to make these special "01" builds is private until general availability. This might not be a tradeoff that LineageOS is willing to take; GrapheneOS has provided the option on a recommended opt-in basis. https://discuss.grapheneos.org/d/27068-grapheneos-security-p...
As far as I have heard they have not actually secured partner access for themselves, they just got someone who has access to break their NDA.
See https://discuss.grapheneos.org/d/24134-devices-lacking-stand... for a more detailed explanation.
Re: LineageOS 23
#135Somewhat related: I could never get adb in my M1 Air (Tahoe and Sonoma too) to detect any android devices. I have an OnePlus Nord CE 2 Lite 5G. Same cable and everything works fine on Ubuntu and Windows machines. The phone is not getting detected in the "System Information" either. Tried MTP, PTP, USB Debugging, OTG everything. Anyone faced this issue?
Re: LineageOS 23
#136Note, GrapheneOS seems to have been able to secure partner access to Android early security releases, but this comes with the cost that the source used to make these special "01" builds is private until general availability. This might not be a tradeoff that LineageOS is willing to take; GrapheneOS has provided the option on a recommended opt-in basis. https://discuss.grapheneos.org/d/27068-grapheneos-security-p...
Yeah, yesterday I got a pop-up post-update that explained the situation and asked me if I wanted the closed source blobs.
Re: LineageOS 23
#137Earlier quoted context omitted.
I have used both, and I can personally use my smartphone properly with both. GrapheneOS is more strict about security, making it more secure but less accessible (at the moment you can only run GrapheneOS on Pixel phones). I am happy with GrapheneOS' policy: that's exactly why I use GrapheneOS, to the point where I bought a Pixel just for GrapheneOS. Many people complain about GrapheneOS not supporting other phones. I…
There is little point in fortifying the front-door when the backdoor is wide open. The hardware itself should never be trusted when being produced by a vendor like Google and cannot be verified on the component level. Their business model completely revolves in reducing your private sphere and sell it to others. Never use google hardware if you are serious about security.
If your threat model is that you cannot trust the Pixel hardware, then you cannot trust any smartphone or computer at all, period.
Re: LineageOS 23
#138Note, GrapheneOS seems to have been able to secure partner access to Android early security releases, but this comes with the cost that the source used to make these special "01" builds is private until general availability. This might not be a tradeoff that LineageOS is willing to take; GrapheneOS has provided the option on a recommended opt-in basis. https://discuss.grapheneos.org/d/27068-grapheneos-security-p...
The bad thing in general is the dependence on Google policy for all AOSP distros. Joining those programs might long term worsen the situation. IMHO, it could be worth the fight if GrapheneOS could win their (rather legal/lobbying) battle to obtain play integrity certification by following security closely (which is a joke IMHO because EOL phones with not updates for years also get integrity). Google releasing easily…
> does not even include the keys for providing alternative web views or the ability to switch the location provider.
Trusting third parties with this is a privacy and security risk. GrapheneOS uses our Vanadium fork of Chromium for the WebView and LineageOS has their own builds of Chromium for it. We provide our own network location implementation using a semi-offline approach based on Apple's location service. We plan to add fully offline support for both Wi-Fi and cell tower network location via downloading regional databases. SUPL is essentially obsolete for GrapheneOS since all supported devices have PSDS and the network location service is already used to help accelerate GNSS when enabled, so we could just remove that instead of making our own SUPL service based on the same data.
We're making progress in fighting the Play Integrity API but governments and regulators move slowly. Courts also move slowly but we haven't brought it to a court yet and would prefer not having to do that. We would greatly prefer if Google worked it out with us and other AOSP-based operating systems but it doesn't appear there's much chance of that ever happening. It's strange since we were never hostile towards them, earned them a lot of money via hardware sales and made substantial upstream contributions.
A major Android OEM is working with us because unlike Google, they're able to see the significant benefits of working with us and selling a lot of devices based on it once they have official GrapheneOS support. Google could have worked with us and others instead of the path they're taking. They could have sold a lot more Pixels by opening up the devices more and improving them. Instead, they'll sell a lot fewer Pixels than they could have as one of the main reasons people buy them goes away. A lot of people who bought them and used the stock OS still bought them because they knew they could get first class support for another OS. They're shooting themselves in the foot. Our userbase will be buying devices from another OEM instead once they meet our requirements.
Re: LineageOS 23
#139Over recent user privacy (and security) crackdowns from Google, these OS upgrades seem to be becoming more appealing. Can anyone comment on what differs Lineage from something like GrapheneOS?
Re: LineageOS 23
#140Earlier quoted context omitted.
Ok, less so NFC, but my bank and all the governments I have to deal with have reasonably functional websites. It's clearly possible.
Where are you from? I live in Germany. I use ING and DKB as my banks. Both of the banks require a Play Integrity-checked app as their default 2FA.In the past I used Sparkasse and Commerzbank. They too required a PI-approved app. As an alternative you can order a code generator but for DKB that requires a paid debit-card. ING disables the phone app if you use a code generator. You cannot have multiple 2FA.