Earlier quoted context omitted.
Are you sure? This seems like a forum with a lot of early adopters and a lot of late adopters still use browsers, email, text messages. Like, let me guess that your credit cars isn't capitol one. Not that it should be, but that would be more "normie".
In Europe at least, most banks require IOS or Android. Even to login into the web Frontend.
Devices with GrapheneOS support should be available in 2027
351–360 of 445 posts
Re: Devices with GrapheneOS support should be available in 2027
#352Earlier quoted context omitted.
> Waydroid is a bad implementation on security and compatibility, just running Android in VM is better. What security problems does waydroid have that a VM wouldn't?
Waydroid disables most of the Android privacy and security model through not having functional SELinux. SELinux is not simply an additional layer of security on Android but rather deeply integrated into the OS. The app sandbox and isolation throughout the OS are heavily built on SELinux. It also heavily depends on it for kernel attack surface reduction combined with internal kernel hardening via exploit protections.…
Re: Devices with GrapheneOS support should be available in 2027
#353When Google acquired motorola, I was excited at the possibilities. When they sold Motorola off, I thought it a deeply unfortunate move.
With this announcement though, I am now seeing it in a very positive light. Given Google's current position, if they still owned Motorola I can't see this sort of collaboration with grapheneos ever happening.
Major kudos to the graphenos team! This is a huge milestone, a huge accomplishment, and a real world validation of the incredible work that you are doing. Thank you so much for everything you have done
Re: Devices with GrapheneOS support should be available in 2027
#354Earlier quoted context omitted.
AOSP has way better security and therefore privacy than desktop linux.
[flagged]
Hardware-based security features including hardware memory tagging, a high quality secure element providing high quality interfaces for improving security, proper verified boot and more are definitely important too, but they cannot simply be bolted onto an OS. The OS needs to be built around being able to take advantage of these features.
Moving to a far less private and secure desktop software stack is going in the opposite direction from GrapheneOS. GrapheneOS doesn't exist to simply provide an alternative to mainstream operating systems but rather to offer much better privacy and security. We wouldn't be doing that if we were forking a desktop Linux environment and doing similar work for it. It would be nowhere close to the privacy and security of simply using an iPhone. That's a major part of why GrapheneOS is based on AOSP rather than it solely being about compatibility.
Desktop distributions are incredibly far behind on privacy/security and lack any clear path to achieving the same things. Every year, Android makes backwards incompatible privacy and security improvements as part of a new target SDK version. Android retains compatibility with legacy apps, but apps distributed through the Play Store (and other app stores to an extent) are required to move to the new target API level within around a year. This results in apps being forced to conform to a gradually improving privacy and security model. There's no such thing for desktop Linux apps but rather apps choose how much they want to participate in nascent sandboxing efforts.
GrapheneOS has near perfect compatibility apps from the Play Store via our sandboxed Google Play compatibility layer with the exception of banking and government apps. 90% of banking apps currently work on GrapheneOS because it greatly succeeds all of their security requirements and is only wrongly banned by a subset of those apps. These apps are gradually adding more anti-tampering and attestation checks for the hardware and OS, so maintaining compatibility has required us to gradually add more functionality working around it. We've also had to actively convince apps to stop banning non-Google-certified operating systems or to permit GrapheneOS and other secure options alongside doing it. A growing number of apps are choosing to stop banning using GrapheneOS due to pressure from our expanding userbase.
Android is a large Linux operating system family. It's the mainstream form of Linux on personal computers. Android users are Linux users. For privacy and security, using a monolithic kernel written in C is definitely not a good thing. Doing much better than we are today partly requires moving away from so heavily depending on the Linux kernel for security. Android does a lot of Linux kernel hardening with attack surface reduction and exploit protections which are improved by GrapheneOS, but it's not enough. The massive torrent of severe vulnerabilities being discovered in the Linux kernel is going to get worse before it gets better and will remain a problem. Adopting hardware-based virtualization for isolation of apps and OS components including drivers is an important part of our roadmap.
Re: Devices with GrapheneOS support should be available in 2027
#355Earlier quoted context omitted.
In Europe at least, most banks require IOS or Android. Even to login into the web Frontend.
There are quite a few people from Europe on HN saying that you can find banks not forcing the duopoly apps on you, in different countries.
However at that point you'll likely pay for the privilege.
Re: Devices with GrapheneOS support should be available in 2027
#356Earlier quoted context omitted.
AOSP security model relies on an extremely restrictive SELinux config out-of-the-box (that importantly also doesn't impede normal phone/app usage), with the kernel hardened about as much as any cutting edge Linux distro could offer from upstream, plus features that haven't been upstreamed yet (and again, completely transparently to the user).
[flagged]
Traditional desktop Linux distributions have atrocious privacy and security. The security record is very poor. The security record does speak for itself in that it has been a disaster. iOS and AOSP have massively improved upon the legacy Unix security model. A traditional desktop OS cannot properly protect users from applications, remote attacks or physical attacks such as extracting data from an After First Unlock state device. It's not only the software that's very lacking but also the hardware and firmware for the Windows and desktop Linux ecosystem. macOS has a made a lot of progress for the hardware, firmware, hardware-based security within the OS and a gradual move towards a mandatory app sandbox and other protections which have not happened in the Windows or desktop Linux world.
AOSP has an increasingly usable desktop mode and supports running traditional desktop Linux within hardware accelerated virtual machines. It's not fully ready as a desktop replacement yet but it's getting there. Android will be shipped on many laptops in the future as a replacement for ChromeOS. The desktop mode is going to be the main way it functions on those so it's going to get much better. GrapheneOS has all of this functionality. Many people are trying out the latest Android 17 desktop mode on GrapheneOS and were already using the earlier experimental mode. Major improvements to that are coming. Many people are quite happy with this even if you don't want it.
Re: Devices with GrapheneOS support should be available in 2027
#357Earlier quoted context omitted.
My broker has a much more fully featured web app then it does on iOS or Android. You can do things in a browser that the phone apps will send you to a browser to do. BofA is just as good of a web app. Maybe people are just used to using their phones?
Can you deposit checks from the webapp? That is the feature most often missing in banking webapps. It isn't something I need often, fortunately.
Re: Devices with GrapheneOS support should be available in 2027
#358Earlier quoted context omitted.
Do you mean to say that all these services require strong device integrity to function in Sweden?? In Australia, no local app that I'm aware of (banking, finance, government, medical) requires any form of device integrity - otherwise I couldn't use them. The only exception I've encountered is Google Wallet. I wonder why there would be such a difference in policy between countries, not only in government but across th…
The comment that I was replying to was suggesting (to me) to live in sweden without mobile bankid (centralized 'banking' 2FA app on smartphone). I have here listed services that require said mobile bankid. Mobile bankid works for me and others on graphene os, but would likely not work on an arbitrary linux smartphone.
Re: Devices with GrapheneOS support should be available in 2027
#359Anyone has any idea if this changes current situation with nfc payments? Currently many banking apps do not work, and google pay is just unavailable, to my understanding it was related to secure chip on phone - as graphene wasnt "stocked" android os approved by google, i dearly hope this chnages with motorola
90% of banking apps do already work on GrapheneOS:
https://privsec.dev/posts/android/banking-applications-compa...
A growing number of the apps banning using GrapheneOS are choosing to start permitting it. A small number of apps are permitting it by relaxing their Play Integrity API checks but most aren't willing to do that. A growing number of apps are implementing support for standard Android hardware attestation and permitting the GrapheneOS verified boot keys with it. We provide a page guide explain how to do that:
https://grapheneos.org/articles/attestation-compatibility-gu...
Our partnership will Motorola will help get the apps banning GrapheneOS to start permitting it through GrapheneOS becoming more mainstream and eventually being considered the stock OS on certain device variants.