Live data from Hacker News

GrapheneOS – A privacy and security-focused mobile OS with Android compatibility

grapheneos.org

111–120 of 186 posts

Re: GrapheneOS – A privacy and security-focused mobile OS with Android compatibility

#111

Earlier quoted context omitted.

I feel google is really turning into Microsoft. These are the same anti open source talking points / FUD you’d see in the early 2000s.

Who exactly is talking about anti-openness here? We're talking about which open source piece of code to reuse. Someone gave a bad argument against one company's offering. Microsoft of the 90s, which no one emulates these days and it's a wrongheaded comparison anyways, would have said that all the open options are bad to begin with. If you meant to say "anti-free software" then maybe we could have a conversation, but…

“Open source is not safer because people won’t read the source”, “having control doesn’t matter”, and trying to raise doubts about the trustworthiness of the people involved... that’s old Microsoft textbook approach.

At least MS wasn’t built on open software, unlike Google.

> And while we're at it, what's your connection if any with the company that sells Purism phones.

None at all. I’ve just heard of this project a few days ago via a DDG search.

Believe it or not, not everyone is a corporate shill.

Re: GrapheneOS – A privacy and security-focused mobile OS with Android compatibility

#112

Librem seems to have the correct way forward, reject the big mess of Android and catch up to it with completely Open pieces. https://puri.sm/products/librem-5/ They're making good progress and I can't wait to be able to update my handheld device with mainline pieces for as long as anyone who still uses one cares to update it. Currently my Samsung Android device is at Dec 2018 patchlevel and nothing I can do about it.

The big problem is the price which too high.

R&D and a small batch size are the only reasons.

Re: GrapheneOS – A privacy and security-focused mobile OS with Android compatibility

#113

Librem seems to have the correct way forward, reject the big mess of Android and catch up to it with completely Open pieces. https://puri.sm/products/librem-5/ They're making good progress and I can't wait to be able to update my handheld device with mainline pieces for as long as anyone who still uses one cares to update it. Currently my Samsung Android device is at Dec 2018 patchlevel and nothing I can do about it.

Librem 5 isn't going to be particularly security-focused: no attestation, no trusted boot, most userspace programs are written in memory unsafe languages like C, with no extra effort memory corruption mitigations. Also, Flatpak offers a permission system that's very limited compared to Android.

Attestation of what? Software security is inferior in Android (hello leaky API), hardware is untrusted in Librem sinde Day 0. Show me a TPM chip with open firmware or it's a security disaster on my board. Seccomp is a thing. Also, Flatpak is the last thing I would concider to use.

Re: GrapheneOS – A privacy and security-focused mobile OS with Android compatibility

#114
post #85

https://grapheneos.org/#roadmap is pretty interesting: > Details on the roadmap of the project will be posted on the site in the near future. In the long term, it aims to move beyond a hardened fork of the Android Open Source Project. Achieving the goals requires moving away from relying the Linux kernel as the core of the OS and foundation of the security model. It needs to move towards a microkernel-based model wit…

Strengthening the security with virtualization is something that's in the early stage of experimentation and research and will be a long-term project. Over the long term though, the goal is moving away from having the Linux kernel completely other than as the native API / ABI for apps. Projects like https://github.com/google/gvisor are very promising in that regard even if they end up playing no part in how this even…

I think if you dont have a strong opinion about it, this is exactly what they are trying to achive with Zircon/Fuchsia kernel.

A micro-kernel, with a linux virtualization layer, being abble to run Linux executables as if they were native.

My hunch is that in the long term, Google will probably use Zircon as the 'first-level' kernel, and run the android apps using some emulation layer.

Maybe it could be the answer for what you are trying to accomplish, without having to create a whole micro-kernel OS from scratch, while at the same time benefiting from whats already there.

I bet that with such a thing in place, the Linux kernel could totally go away, with only a emulation layer in place if you want to.

Re: GrapheneOS – A privacy and security-focused mobile OS with Android compatibility

#115

Earlier quoted context omitted.

The big problem is the price which too high.

R&D and a small batch size are the only reasons.

I am not blaming them for that, I understand that but I understand also customer who does not pay twice as more as for other phone.

Re: GrapheneOS – A privacy and security-focused mobile OS with Android compatibility

#116

Earlier quoted context omitted.

Who exactly is talking about anti-openness here? We're talking about which open source piece of code to reuse. Someone gave a bad argument against one company's offering. Microsoft of the 90s, which no one emulates these days and it's a wrongheaded comparison anyways, would have said that all the open options are bad to begin with. If you meant to say "anti-free software" then maybe we could have a conversation, but…

“Open source is not safer because people won’t read the source”, “having control doesn’t matter”, and trying to raise doubts about the trustworthiness of the people involved... that’s old Microsoft textbook approach. At least MS wasn’t built on open software, unlike Google. > And while we're at it, what's your connection if any with the company that sells Purism phones. None at all. I’ve just heard of this project a…

> Open source is not safer because people won’t read the source

That's not what I said. To sum it up: Open source is not really a security proposition. It eliminates problems related to negligence.

> having control doesn’t matter

In what concrete way does the Purism OS give you more control over your device than AOSP?

It really seems like you are confusing open source and free software for this entire conversation, as literally every line of code we are discussing is shared under a license that allows you to look at, modify and use as you see fit.

> None at all. I’ve just heard of this project a few days ago via a DDG search.

The depth of your consideration was already fairly easy to guess, but thanks for being honest.

> Believe it or not, not everyone is a corporate shill.

Physician, heal thyself.

Re: GrapheneOS – A privacy and security-focused mobile OS with Android compatibility

#117
post #105

Librem seems to have the correct way forward, reject the big mess of Android and catch up to it with completely Open pieces. https://puri.sm/products/librem-5/ They're making good progress and I can't wait to be able to update my handheld device with mainline pieces for as long as anyone who still uses one cares to update it. Currently my Samsung Android device is at Dec 2018 patchlevel and nothing I can do about it.

> with completely Open pieces AOSP is completely open source. Hardware and firmware is a much different story, but that applies to the device you're promoting just as much... > They're making good progress and I can't wait to be able to update my handheld device with mainline pieces for as long as anyone who still uses one cares to update it. Currently my Samsung Android device is at Dec 2018 patchlevel and nothing I…

[deleted]

Re: GrapheneOS – A privacy and security-focused mobile OS with Android compatibility

#119

Librem seems to have the correct way forward, reject the big mess of Android and catch up to it with completely Open pieces. https://puri.sm/products/librem-5/ They're making good progress and I can't wait to be able to update my handheld device with mainline pieces for as long as anyone who still uses one cares to update it. Currently my Samsung Android device is at Dec 2018 patchlevel and nothing I can do about it.

I'm really excited for it. I also have my eyes on the Pine phone project.

Re: GrapheneOS – A privacy and security-focused mobile OS with Android compatibility

#120

Librem seems to have the correct way forward, reject the big mess of Android and catch up to it with completely Open pieces. https://puri.sm/products/librem-5/ They're making good progress and I can't wait to be able to update my handheld device with mainline pieces for as long as anyone who still uses one cares to update it. Currently my Samsung Android device is at Dec 2018 patchlevel and nothing I can do about it.

Librem 5 isn't going to be particularly security-focused: no attestation, no trusted boot, most userspace programs are written in memory unsafe languages like C, with no extra effort memory corruption mitigations. Also, Flatpak offers a permission system that's very limited compared to Android.

> isn't going to be particularly security-focused: no attestation, no trusted boot

This is only true initially, presumably due to time and funding constraints. From the FAQ (https://puri.sm/faq/):

> What are your plans for tamper-proofing the Librem 5?

> We hope to have a version of PureBoot available for the Librem 5 for users who want to verify it with a Librem Key. We cannot commit to it being available at launch but it’s a goal.

A PureBoot description can be found at (https://puri.sm/posts/pureboot-the-high-security-boot-proces...).

Post reply on HN