GrapheneOS has a security preview release channel that is opt-in but includes patches from these embargoed vulns already. Again, it's opt-in but for those with a higher threat model use-case it's nice to have.
Would this not defeat the purpose of responsible disclosure? As a bad actor I could learn of secret vulnerabilities from this channel.
These patches are available to all vendors who chose not to protect their users yet.
Releasing binary patches is allowed, this is why GOS have added the security preview channel.
Wouldn't it be a total mindfuck if it turns out that Graphene is less secure[1] than stock Pixel, and this is all part of an ANOM-style honeypot operation that has Feds hyping it up, to trick interesting targets into adopting a less-effective security posture. 1. Such as via slower 0-day responses, for instance. This is a thought experiment, I'm nor alleging that this is what it is.
Those honeypot phones clearly use marketing aimed at criminals and make all sort of false promises and clearly aren't technical and transparent projects like GrapheneOS. GrapheneOS community doesn't tolerate discussion of crime or implying you are a criminal on their official community chat rooms and forum. Doesn't make sense for it to be a project aimed at luring in criminals. Anyway, GrapheneOS ships security patch…
Well, if you're implying someone is a criminal because they don't want their phone come with the google buttplug and spyware installed....... I think you have a problem :D
That is hardly the only problem. The browser is astonishingly bad at dark mode. The launcher forces almost all icons to greyscale black and white and does not accept icon packs. I feel like I'm downgrading by my compulsion for Brave and Lawnchair, but some attention is lacking in aesthetics. (e/os has this problem to a lesser degree with the Bliss launcher.) There is no rooted ADB. Even if a giant OS TAINTED notifica…
Vanadium is pretty good but I agree there are problems I can circumvent only by using another one (Brave); I presume it's the strict tracking protection that breaks some sites. Not sure about your launcher problem, but you had to turn it on yourself? I don't experience anything like this on my phones. I miss Nova though; none of the other launchers I tried came near (last tried: uLauncher, Kvaesito, Olauncher, Lawnch…
I understand that Magisk can be applied to Graphene if the final device lock step is not applied.
I might try that if I elevate it to my daily driver.
I'm not comfortable without root. I have the absolute right to have root on my device.
I don't know why Graphene didn't just take Trebuchet.
Any info on recent ban of SafeDot by Android and GOS? Any plans to implement SafeDot as an official GOS app?
Isn't that now a native android function?
A little green dot? No, it's a small fraction of SafeDot functionality. I'm interested in audible notification when camera, mic, or gps is accessed. Currently, I cannot make it work on GOS (maybe, may phone is hacked).
On Lineage this is the default behaviour: charging only until I tap on a notification to change it.
That's the standard Android behavior for the USB gadget mode, not something specific to LineageOS, and it does not mean USB is in a charging-only mode but rather than no USB gadget functionality such as file transfer (MTP) is active. It does not mean USB peripherals and USB-C alternate mode are disabled, which certainly work in the default charging-only mode for Android's USB gadget setting. It doesn't even mean that…
Got it, that makes sense! Thanks for explaining :)
It can be more secure, but it also feels like the kind of "improvement" that's ripe for exploitation. When you put in a step where you have to ask your service provider for permission to swap the SIM, buckle up for the inevitable development of them asking for a $5, $50 or $100 "service fee" so they consider allowing it.
Couldn't they do that with physical SIM cards? On their end, record the IMEI of the first device they see connecting with a specific SIM card and then disallow connections if that SIM is used with a different IMEI.
I'm not sure if that's legal, but even if they did it, it's a lot more opaque. If they started doing it, many people would assume it to be a technical fault by the provider or the phone manufacturer, and the ensuing support calls and drama would probably cost way too much for this to be worth it in the first place. However, with eSIM, they get to redefine all the rules, since the customer has to learn how to use them from scratch anyway. And they also get access to nice, digital, software-driven workflows that can make the need to pay up apparent, as opposed to just randomly cutting service to the user.
GrapheneOS is basically the Android equivalent of iOS Lockdown mode. Considering how the threat landscape has changed, it would be nice if Google offered this itself. Or became a long-term sponsor of GrapheneOS, seeing how great a job they've been doing.
Not really. iOS in lockdown mode has multiple features disabled (or crippled, depending on how you look at it), while GrapheneOS is just..... secure by design with secure defaults. https://support.apple.com/en-us/105120 In iPhone also you cannot just turn on/off/adjust these protections one by one, it's all or nothing.
> OS in lockdown mode has multiple features disabled [...] while GrapheneOS is just...
...disabling features. Android Auto, Google Pay, enhanced GPS, SafetyNet, push notifications, support for any apps requiring device integrity, etc.
They aren't redesigning and re-implementing these features securely, they are reducing attack surface just like lockdown mode.
Nope. This is eplus in Japan, and if you try go through the website it tells you you have to use the app. It's cos a lot of shows these days don't use paper tickets, but smart tickets on your phone. It is what it is.