Live data from Hacker News

Devices with GrapheneOS support should be available in 2027

grapheneos.social

291–300 of 444 posts

Re: Devices with GrapheneOS support should be available in 2027

#291
post #123

Earlier quoted context omitted.

@fsflover: and my mobile phone provider. And my insurance. And my eletricity provider. And my housing associations customer portal. Getting doctors appointments. Mortgage. Union. National retirement savings account. Some of these may have some alternative left, but far too many you will be left out. Well, I can buy a train ticket without it, so I could still leave.

Do you mean to say that all these services require strong device integrity to function in Sweden?? In Australia, no local app that I'm aware of (banking, finance, government, medical) requires any form of device integrity - otherwise I couldn't use them. The only exception I've encountered is Google Wallet. I wonder why there would be such a difference in policy between countries, not only in government but across th…

The comment that I was replying to was suggesting (to me) to live in sweden without mobile bankid (centralized 'banking' 2FA app on smartphone). I have here listed services that require said mobile bankid. Mobile bankid works for me and others on graphene os, but would likely not work on an arbitrary linux smartphone.

Re: Devices with GrapheneOS support should be available in 2027

#292

I've never really understood why we chase Android-alikes on mobile platforms instead of trying to build on mainstream Linux. I know some folks in the nix community (nix-on-droid and other projects) have tried to bring us closer to this, but projects like Graphene seem to have a lot of traction.

> I've never really understood why we chase Android-alikes on mobile platforms instead of trying to build on mainstream Linux. Because there is no such thing as "mainstream Linux" when it comes to anything related to user-facing consumer software. Not on desktops, not on tablets, not on phones. I mean you invoked "mainstream Linux" and "Nix" in the same paragraph. That alone should clue you into why this, absolutely,…

[flagged]

Re: Devices with GrapheneOS support should be available in 2027

#293
post #138

Earlier quoted context omitted.

> All the existing apps are on Android and iOS. Graphene lets you run them. We have waydroid for that. > You can't have a bank account on a Linux phone* because they won't let you, but you can on Android including on Graphene. Unless of course it uses those stupid integrity apis to block anything that isn't stock.

Porting traditional Linux desktop distributions to Android devices is meaningless, all you get is more instability, more unsafe and more trouble. Waydroid is a bad implementation on security and compatibility, just running Android in VM is better.

[flagged]

Re: Devices with GrapheneOS support should be available in 2027

#294

I've never really understood why we chase Android-alikes on mobile platforms instead of trying to build on mainstream Linux. I know some folks in the nix community (nix-on-droid and other projects) have tried to bring us closer to this, but projects like Graphene seem to have a lot of traction.

GrapheneOS primarily exists to greatly improve privacy and security compared to the Android Open Source Project (AOSP). AOSP provides far better privacy and security than a traditional desktop Linux distribution. It has a strong mandatory app sandbox, an increasingly good permission model moving more and more towards case-by-case consent, broad use of memory safe languages throughout the OS and app ecosystem, strong MAC/MLS policies developed as part of the whole OS, modern exploit protections, verified boot with downgrade protection for the whole OS and far more. GrapheneOS starts from the already good privacy and security of AOSP and greatly improves upon it. We greatly improve the permission model, exploit protections and much more but we depend on starting from a foundation that's already decent.

Moving to a far less private and secure desktop software stack is going in the opposite direction from GrapheneOS. GrapheneOS doesn't exist to simply provide an alternative to mainstream operating systems but rather to offer much better privacy and security. We wouldn't be doing that if we were forking a desktop Linux environment and doing similar work for it. It would be nowhere close to the privacy and security of simply using an iPhone. That's a major part of why GrapheneOS is based on AOSP rather than it solely being about compatibility.

Desktop distributions are incredibly far behind on privacy/security and lack any clear path to achieving the same things. Every year, Android makes backwards incompatible privacy and security improvements as part of a new target SDK version. Android retains compatibility with legacy apps, but apps distributed through the Play Store (and other app stores to an extent) are required to move to the new target API level within around a year. This results in apps being forced to conform to a gradually improving privacy and security model. There's no such thing for desktop Linux apps but rather apps choose how much they want to participate in nascent sandboxing efforts.

GrapheneOS has near perfect compatibility apps from the Play Store via our sandboxed Google Play compatibility layer with the exception of banking and government apps. 90% of banking apps currently work on GrapheneOS because it greatly succeeds all of their security requirements and is only wrongly banned by a subset of those apps. These apps are gradually adding more anti-tampering and attestation checks for the hardware and OS, so maintaining compatibility has required us to gradually add more functionality working around it. We've also had to actively convince apps to stop banning non-Google-certified operating systems or to permit GrapheneOS and other secure options alongside doing it. A growing number of apps are choosing to stop banning using GrapheneOS due to pressure from our expanding userbase.

Android is a large Linux operating system family. It's the mainstream form of Linux on personal computers. Android users are Linux users. For privacy and security, using a monolithic kernel written in C is definitely not a good thing. Doing much better than we are today partly requires moving away from so heavily depending on the Linux kernel for security. Android does a lot of Linux kernel hardening with attack surface reduction and exploit protections which are improved by GrapheneOS, but it's not enough. The massive torrent of severe vulnerabilities being discovered in the Linux kernel is going to get worse before it gets better and will remain a problem. Adopting hardware-based virtualization for isolation of apps and OS components including drivers is an important part of our roadmap.

Re: Devices with GrapheneOS support should be available in 2027

#296

Earlier quoted context omitted.

My broker has a much more fully featured web app then it does on iOS or Android. You can do things in a browser that the phone apps will send you to a browser to do. BofA is just as good of a web app. Maybe people are just used to using their phones?

Looking down the thread I am also thinking maybe this is a Europe thing? I am usa.

https://news.ycombinator.com/item?id=49363246

Re: Devices with GrapheneOS support should be available in 2027

#297
post #138

Earlier quoted context omitted.

Porting traditional Linux desktop distributions to Android devices is meaningless, all you get is more instability, more unsafe and more trouble. Waydroid is a bad implementation on security and compatibility, just running Android in VM is better.

> Waydroid is a bad implementation on security and compatibility, just running Android in VM is better. What security problems does waydroid have that a VM wouldn't?

Waydroid disables most of the Android privacy and security model through not having functional SELinux. SELinux is not simply an additional layer of security on Android but rather deeply integrated into the OS. The app sandbox and isolation throughout the OS are heavily built on SELinux. It also heavily depends on it for kernel attack surface reduction combined with internal kernel hardening via exploit protections.

Waydroid uses an outdated fork of LineageOS running with namespaces and a compatibility layer on top of a much less private and secure base OS without similar kernel or userspace security protections. Running up-to-date AOSP in a virtual machine would at least be able to preserve the internal Android privacy and security model for apps to protect apps from each other and the OS from apps. It would also contain the overall OS within it too. Using the much less private and secure OS as the host OS with full access is quite backwards from a privacy and security perspective but would be a huge improvement.

AOSP is much more private and secure than traditional desktop Linux distributions. Moving to that software stack is inherently going to be moving much further away from competing with the privacy and security of iOS. The direction taken by GrapheneOS is to start from AOSP and greatly improve the privacy and security it provides to compete with and exceed the industry standard privacy and security provided by iPhones. That requires more than only software. Hardware and firmware security are very important too. Software security also increasingly depends on hardware-based security features such as hardware memory tagging, hardware control flow integrity protections, hardware-based virtualization and much more.

Keeping user data safe from access via encryption also depends on hardware security features for the vast majority of users not using a very strong passphrase. People take it for granted that they're going to have secure data via disk encryption with a random 6 digit PIN but that's not the case without a good secure element and OS integration with it. The approach used by desktop operating systems with TPMs is awful and makes security worse in a lot of ways rather than better. It's not at all the same thing, similarly to how what the desktop world calls secure boot is not a serious or complete implementation of it and doesn't provide nearly any useful security properties to end users unlike iOS or AOSP.

Re: Devices with GrapheneOS support should be available in 2027

#298

I've never really understood why we chase Android-alikes on mobile platforms instead of trying to build on mainstream Linux. I know some folks in the nix community (nix-on-droid and other projects) have tried to bring us closer to this, but projects like Graphene seem to have a lot of traction.

GrapheneOS primarily exists to greatly improve privacy and security compared to the Android Open Source Project (AOSP). AOSP provides far better privacy and security than a traditional desktop Linux distribution. It has a strong mandatory app sandbox, an increasingly good permission model moving more and more towards case-by-case consent, broad use of memory safe languages throughout the OS and app ecosystem, strong…

[flagged]

Re: Devices with GrapheneOS support should be available in 2027

#299

Earlier quoted context omitted.

I had to replace a credit card yesterday. Part of the default flow involves the call center sending a notification to your app. When I told them my android version was too old, it took them twenty minutes to find out they could instead send a text message. That text message sends you to a photo-and-id verification service, but that's another issue. Soon, there won't even be an alternative flow. There are a lot of pla…

Are you sure? This seems like a forum with a lot of early adopters and a lot of late adopters still use browsers, email, text messages. Like, let me guess that your credit cars isn't capitol one. Not that it should be, but that would be more "normie".

In Europe at least, most banks require IOS or Android. Even to login into the web Frontend.

Re: Devices with GrapheneOS support should be available in 2027

#300
post #120
post #36

Earlier quoted context omitted.

All the existing apps are on Android and iOS. Graphene lets you run them. You can't have a bank account on a Linux phone* because they won't let you, but you can on Android including on Graphene. * before replying snarkily that Android is Linux, please take a long walk off a short pier, thanks

Even Graphine is limited in what apps work properly compared to a normal google phone. You have to give up a lot in order to have privacy these days. A pure linux non-android phone would be great however you wouldn't have access to properly working apps and would not be able to participate in modern society.

Using BMW digital keys seem to be a problem because of the lack of google wallet support (supposed to also be an issue on Lineage).

Anyone getting BMW digital keys to work on Graphine OS?

Post reply on HN