Live data from Hacker News

GrapheneOS is the only Android OS providing full security patches

grapheneos.social

121–130 of 467 posts

Re: GrapheneOS is the only Android OS providing full security patches

#121

Earlier quoted context omitted.

Why not run Android directly, such as using Graphene OS. It's decades ahead in both OS architecture, developer tools, and developers compared to non Android based Linux operating systems.

Graphene uses the Google codebase, so Google is choosing its long-term development strategy and standards it will support. It's like choosing Chromium to escape Chrome.

Not the worst choices!

Re: GrapheneOS is the only Android OS providing full security patches

#122
post #116
post #58

You can tell it's truly secure and private because the Cellebrite leak says they can't break it (one of very few!) and some governments assume you're a drug dealer if you use it. My next phone will run GrapheneOS.

Have a link to the source? And have they said they can’t break it, or haven’t yet? I’d imagine from a business perspective it would hardly be worth it

There more sources if you google, but someone leaked a Cellebrite meeting.

https://www.androidauthority.com/cellebrite-leak-google-pixe...

https://arstechnica.com/gadgets/2025/10/leaker-reveals-which...

Re: GrapheneOS is the only Android OS providing full security patches

#123

https://tbot.substack.com/p/grapheneos-new-oem-partnership > GrapheneOS has officially confirmed a major new hardware partnership—one that marks the end of its long-standing Pixel exclusivity. According to the team, work with a major Android OEM began in June and is now moving toward the development of a next-generation smartphone built to meet GrapheneOS’ strict privacy and security standards.

This is excellent news. Google doesn't sell Pixels in my country for some reason. Hopefully the new phones will be easier to obtain.

Have you considered using mail forwarding, or sites like Swappa.com with forwarding built in?

Hoping this helps you get your hands on a cheap Pixel!

Re: GrapheneOS is the only Android OS providing full security patches

#124

https://tbot.substack.com/p/grapheneos-new-oem-partnership > GrapheneOS has officially confirmed a major new hardware partnership—one that marks the end of its long-standing Pixel exclusivity. According to the team, work with a major Android OEM began in June and is now moving toward the development of a next-generation smartphone built to meet GrapheneOS’ strict privacy and security standards.

This is really cool, but, longer term, what happens if Google makes android closed source? I feel this is a very real risk.

Re: GrapheneOS is the only Android OS providing full security patches

#125

Graphene has really caught my eye in the last several months, but unfortunately I couldn't find a good deal for Pixel phones (>128GB storage), used or new. That's the biggest bottleneck for adoption it seems. I just finally switched from an S10E to a S25Ultra (black friday deal brought down to $820), but not being able to use Graphene in the future hurts a bit for sure.

Goodness, friend, where were you looking? A used 256GB Pixel 8 in good condition is $320. https://swappa.com/listings/google-pixel-8?carrier=unlocked&...

One caveat--you have to be certain that you get a Pixel with an unlocked bootloader. There are a lot of Pixels (mostly sold by Verizon) that are unlocked for use with any carrier, but whose bootloaders remain locked. If you have one of these ex-Verizon phones, there is no way as of now to unlock the bootloader.

Re: GrapheneOS is the only Android OS providing full security patches

#126
post #2

> may i ask how you obtain the source? Are you registered as an OEM at Google? Same question, how does Graphene get patches?

They have partnership an OEM who provides them with sources. Currently they're only permitted to release binaries of the patches due to the embargo, this is why these patches are in the parallel stream/optional (so people unhappy with being unable to see the sources won't have them shoved down their throats). I don't have URLs at hand at the moment but all these questions have been asked many times and explained exte…

> It's quite surreal how unsafe the standard Android

Well that's untrue. I'd even venture to say that with how many OEMs there are it's insane how safe Android is. Google for one updates their devices for 7 years since Pixel 6, they can't control OEMs who might have ~10 people working on their devices.

Re: GrapheneOS is the only Android OS providing full security patches

#127

Earlier quoted context omitted.

https://eylenburg.github.io/android_comparison.htm

That comparison shows "Deblobbed? Yes" for GrapheneOS. That implies they've replaced (most of) the blobs for wifi, bluetooth, 5g chips etc. Is that actually true? It's such a big deal, and I see little to no work being done on this front. Anyone have any idea what GrapheneOS actually deblobbed?

It's nowhere near that. Pretty sure even modules are signed by Google.

Re: GrapheneOS is the only Android OS providing full security patches

#129
post #88

Understaffed gift product wants 1 week cycles. OEMs want 2-4 month cycles. This is a perfect representation of the state of the software industry.

I don't think that's a fair comparison. OEMs have quite a lot of extra steps before releasing any build to the public. They have to pass xTS, the set of test suites required before getting certified by Google, possibly carrier certification, regulatory requirements and more depending on where the build will be released. There are "quicker" release channels for security fixes, but I don't think it's common for OEMs to…

> I don't think that's a fair comparison.

Fair?

> OEMs have quite a lot of extra steps before releasing any build to the public.

AIUI updates are less stringent and burdensome than initial certification. Regardless much of the process is automated. Graphene has CI too. 3PL's taking 4 weeks to run automated tests is also absurd. There are some "manual steps" to run CTS-V but they shouldn't be weeks level burdensome either. This is the point, this is an industry problem.

The reason that the OEMs even have to deal with this 3PL test mess is for GMS certification, so again this is a policy decision that enforces a poor process. The bad properties of the process are not inherent to the problem space of validating builds against requirements. An industry problem.

> There are "quicker" release channels for security fixes, but I don't think it's common for OEMs to only ship those without any other change to the system.

Seems like a decision that is not user-centric.

> I don't think Graphene does anything of sort, they take what's already certified in the Pixel builds and uses it. Not like they could do much aside testing on the public part of xTS.

Private test suites for software are a toxic idea, it's in the same box as "SSO tax", and other such "pay for security" models. Given the software industry can't be trusted not to do this, I'm almost keen to see legislation to explicitly ban this practice.

Re: GrapheneOS is the only Android OS providing full security patches

#130

Earlier quoted context omitted.

Graphene uses the Google codebase, so Google is choosing its long-term development strategy and standards it will support. It's like choosing Chromium to escape Chrome.

Not the worst choices!

Indeed. However, in terms of the independence, better choices exist.
Post reply on HN