Live data from Hacker News

GrapheneOS is the only Android OS providing full security patches

grapheneos.social

111–120 of 467 posts

Re: GrapheneOS is the only Android OS providing full security patches

#111
post #53
post #14

Obviously this situation can't go on. If neither of the two major players can make an open, secure, _simple_, easy-to-understand, bloat-free OS, then we somehow need another player. Presently (and I confess, my bias to seek non-state solutions may show here), it seems that a non-trivial part of the duopoly stems from regulatory capture insofar as the duopoly isn't merely software, but extends all the way to TSMC and…

One comment mentioned Jolla. Another currently available option is [FuriLabs]( http://furilabs.com ). It runs atop Hallium/etc but you are effectively still able to daily drive a mobile Linux shell and contribute to the ecosystem if you want to see it grow. Now with that said: so much work has gone in to Android (and by extension, Graphene) to improve on power usage/security/etc that I'm not sure I'd bother to actual…

Furilabs was just in the news here because they discontinued their device models from a few years ago, and released a new device for a big price bump with _significantly worse_ hardware.

I know I would love to give them a try, but a 720 screen is an absolute non starter for me. It would be hard for anyone to sell me on just a FullHD (1080) screen in the era of QHD (2K) being industry standard. Additionally, I believe their FAQ even admits that their already low power devices only get a few hours of battery life.

Re: GrapheneOS is the only Android OS providing full security patches

#112
post #14

Obviously this situation can't go on. If neither of the two major players can make an open, secure, _simple_, easy-to-understand, bloat-free OS, then we somehow need another player. Presently (and I confess, my bias to seek non-state solutions may show here), it seems that a non-trivial part of the duopoly stems from regulatory capture insofar as the duopoly isn't merely software, but extends all the way to TSMC and…

GNU/Linux phones exist and can be used as daily drivers, if you put enough effort in it. Sent from my Librem 5.

Re: GrapheneOS is the only Android OS providing full security patches

#114
post #88

Understaffed gift product wants 1 week cycles. OEMs want 2-4 month cycles. This is a perfect representation of the state of the software industry.

I don't think that's a fair comparison. OEMs have quite a lot of extra steps before releasing any build to the public. They have to pass xTS, the set of test suites required before getting certified by Google, possibly carrier certification, regulatory requirements and more depending on where the build will be released. There are "quicker" release channels for security fixes, but I don't think it's common for OEMs to…

Yep. And GrapheneOS's changes to the kernels of devices they ship are laughably small, 20-30 commits at most. I don't think they even do any basic CVE checks on any of the source code.

Fuzzing, actual security analysis - all those things are done by Google.

Re: GrapheneOS is the only Android OS providing full security patches

#115

[flagged]

Hacker News Guidelines [1]:

> Please don't post insinuations about astroturfing, shilling, brigading, foreign agents, and the like. It degrades discussion and is usually mistaken. If you're worried about abuse, email hn@ycombinator.com and we'll look at the data.

> Please don't comment about the voting on comments. It never does any good, and it makes boring reading.

[1] https://news.ycombinator.com/newsguidelines.html

Re: GrapheneOS is the only Android OS providing full security patches

#116
post #58

You can tell it's truly secure and private because the Cellebrite leak says they can't break it (one of very few!) and some governments assume you're a drug dealer if you use it. My next phone will run GrapheneOS.

Have a link to the source? And have they said they can’t break it, or haven’t yet? I’d imagine from a business perspective it would hardly be worth it

Re: GrapheneOS is the only Android OS providing full security patches

#117
post #38

Earlier quoted context omitted.

You're getting a lot of indirect responses. If you've ever tried to mod your android phone the answer is simple. Its google play services and hardware attestation for things like banking websites. Its really easy to make a custom rom but hard to do serious "real life" stuff; companies don't want to make it easy. To most regular users, if they cant download apps from the google play store, and they can't use venmo\cas…

This just shows that the barrier of entry of a new phone OS is more than $0. You can pay app developers to port their apps off of play services, you can pay developers to add support for your attestation keys. Considering how many billions of dollars Android makes for Google, there is a room for a return on investment for an alternate OS to enable investments into a new OS.

How much do you want to pay? Who will be paying? Big companies will probably laugh such an effort out of the room, nay, they will not even let you into the room to talk with them.

Re: GrapheneOS is the only Android OS providing full security patches

#118
So this is interesting, they release the patched binaries several months before anyone else does and several months before the source code of the patches is released?

This implies that anyone can download GrapheneOS firmware images and use binary diffing techniques to find what are still 0-day vulnerabilities on every Android other than GrapheneOS.

Useful! Thank you GrapheneOS developers.

Re: GrapheneOS is the only Android OS providing full security patches

#119

As a LineageOS user, I'd be interested in the disparity between GrapheneOS and LineageOS.

If you have a Pixel -> Graphene, if not -> Lineage.

I personally don't care about "security" all that much, my main reason for using Graphene is freedom to use my hardware in any way I wish. This means unrestricted ability to run any program on the phone from any source. Sideloading restrictions don't apply to Graphene, and it is also impossible for state actors to impose things such as client-side scanning of text messages. It's also immune to unwanted AI anti-features.

I use my own "cloud" infrastructure with my phone and I am not interested in using Google's. My Graphene device is configured to route all traffic through Wireguard tunnel and my DNS server. I also use exclusively use my own email server and "cloud" storage for all non-work related purposes. Graphene makes this easy by not leaking any information to Google.

Re: GrapheneOS is the only Android OS providing full security patches

#120
post #37

Earlier quoted context omitted.

The only thing proprietary in the early PC architecture was the BIOS. Everything else was pre-existing architecture from third parties, there was nothing to keep a lid on. Since a PC was a big box of parts anyone could manufacture one. A modern phone is much more complicated. As to why there aren’t a plethora: the market doesn’t demand it that much. The people doing it aren’t wildly successful. Perhaps that’s changin…

Even the batteries are not interchangeable on phones. You'd think all phones should have the same exact battery, that this kind of standardization is beneficial for phone manufacturers as it helps them bargain with their parts suppliers but no for whatever reason we can't have that. Edit: I am not saying just user replaceable. I mean standardized so the same cells in a 2024 phone also works on 2025...

Why, of all parts on a phone, would you expect the battery to be the one that's already good enough that it should never need to be upgraded?

"Battery capacity" is like the one thing phone manufacturers still try to improve.

Post reply on HN