Live data from Hacker News

GrapheneOS is the only Android OS providing full security patches

grapheneos.social

131–140 of 467 posts

Re: GrapheneOS is the only Android OS providing full security patches

#131
post #89
post #24

Earlier quoted context omitted.

The company making a device that is licensed by the FCC has to do everything that they can to mitigate the risk of an unlicensed broadcast on their devices. https://www.fcc.gov/oet/ea/rfdevice > INTENTIONAL RADIATORS (Part 15, Subparts C through F and H) > An intentional radiator (defined in Section 15.3 (o)) is a device that intentionally generates and emits radio frequency energy by radiation or induction that may…

> The company making a device that is licensed by the FCC has to do everything that they can to mitigate the risk of an unlicensed broadcast on their devices. Where do you see this in the rules? The only thing I see that even comes close is the following sentence: "Manufacturers and importers should use good engineering judgment before they market and sell these products, to minimize possible interference" Maybe it's…

SDR for listening does not require a license. For transmission, depending on the power and frequency may require a broadcast license.

https://www.reddit.com/r/RTLSDR/comments/dx5sln/do_developer...

Depending on the power of the walkie talkie, it may require a license.

https://www.rcscommunications.com/which-two-way-radios-requi...

> MURS (Multi-Use Radio Service) – Two-way radios programmed to operate within the MURS (Multi-Use Radio Service) are not required to be licensed. They transmit at 2 watts or less and only operate on pre-set frequencies between 151 -154 MHz in the VHF band. MURS radios have a general lack of privacy, a limited coverage area, and frequent channel interference.

> ...

> GMRS (General Mobile Radio Service) – The General Mobile Radio Service (GMRS) is another of the most popular and numerous licenses the FCC granted. GMRS licenses allow for radios to transmit up to 50 watts. GMRS licenses also allow for hand-held, mobile, and repeater devices. The GMRS spectrum has 22 channels that it shares with FRS and an additional 8 repeater channels that are exclusive to GMRS.

> Virtually Every Other Land Mobile Radio (LMR) Device – Virtually all two-way radios beyond the models mentioned above are subject to FCC licensing. In fact, any device that transmits at 4 watts or higher requires coordination (and, thereby, licensing) by the FCC.

---

The Flipper is licensed to operate with a particular set of power and frequency ranges. https://flipperzero.one/compliance

For the SDR it is licensed to operate between 304.5 - 321.95; 433.075 - 434.775; and 915.0 - 927.95 MHZ range in the US.

Note that none of those are the cellphone frequency bands.

---

https://prplfoundation.org/yes-the-fcc-might-ban-your-operat...

which quotes 2.1033 Application for grant of certification. Paragraph 4(i):

> For devices including modular transmitters which are software defined radios and use software to control the radio or other parameters subject to the Commission’s rules, the description must include details of the equipment’s capabilities for software modification and upgradeability, including all frequency bands, power levels, modulation types, or other modes of operation for which the device is designed to operate, whether or not the device will be initially marketed with all modes enabled. The description must state which parties will be authorized to make software changes (e.g., the grantee, wireless service providers, other authorized parties) and the software controls that are provided to prevent unauthorized parties from enabling different modes of operation. Manufacturers must describe the methods used in the device to secure the software in their application for equipment authorization and must include a high level operational description or flow diagram of the software that controls the radio frequency operating parameters. The applicant must provide an attestation that only permissible modes of operation may be selected by a user.

and 2.1042 Certified modular transmitters. Paragraph (8)(e)

> Manufacturers of any radio including certified modular transmitters which includes a software defined radio must take steps to ensure that only software that has been approved with a particular radio can be loaded into that radio. The software must not allow the installers or end-user to operate the transmitter with operating frequencies, output power, modulation types or other radio frequency parameters outside those that were approved. Manufacturers may use means including, but not limited to the use of a private network that allows only authenticated users to download software, electronic signatures in software or coding in hardware that is decoded by software to verify that new software can be legally loaded into a device to meet these requirements.

Re: GrapheneOS is the only Android OS providing full security patches

#132

https://tbot.substack.com/p/grapheneos-new-oem-partnership > GrapheneOS has officially confirmed a major new hardware partnership—one that marks the end of its long-standing Pixel exclusivity. According to the team, work with a major Android OEM began in June and is now moving toward the development of a next-generation smartphone built to meet GrapheneOS’ strict privacy and security standards.

I wonder if a real OEM supports graphene if that would solve device attestation for things like banking apps.

Re: GrapheneOS is the only Android OS providing full security patches

#133

Earlier quoted context omitted.

> I'm not knowledgeable enough -- what would it take to escape the Apple/Google duopoly? At this point? Reliable emulation that can run 99% of Android apps, to provide a bridge until the platform is interesting enough for people to develop for it "natively". I think the easiest way to do that would be to run Android in a VM.

Why not run Android directly, such as using Graphene OS. It's decades ahead in both OS architecture, developer tools, and developers compared to non Android based Linux operating systems.

Graphene OS exists because Google lets it. You can't rely on competitors that can only exist in this manner

Re: GrapheneOS is the only Android OS providing full security patches

#134

https://tbot.substack.com/p/grapheneos-new-oem-partnership > GrapheneOS has officially confirmed a major new hardware partnership—one that marks the end of its long-standing Pixel exclusivity. According to the team, work with a major Android OEM began in June and is now moving toward the development of a next-generation smartphone built to meet GrapheneOS’ strict privacy and security standards.

This is really cool, but, longer term, what happens if Google makes android closed source? I feel this is a very real risk.

They won't because they literally control the mobile market by having Android open source.

Re: GrapheneOS is the only Android OS providing full security patches

#135

Earlier quoted context omitted.

This just shows that the barrier of entry of a new phone OS is more than $0. You can pay app developers to port their apps off of play services, you can pay developers to add support for your attestation keys. Considering how many billions of dollars Android makes for Google, there is a room for a return on investment for an alternate OS to enable investments into a new OS.

How much do you want to pay? Who will be paying? Big companies will probably laugh such an effort out of the room, nay, they will not even let you into the room to talk with them.

$10 million dollars per app. The creator of the new OS will pay. If you offer enough cash they will stop laughing.

Re: GrapheneOS is the only Android OS providing full security patches

#136
post #90
post #60

Earlier quoted context omitted.

Any one of us here could learn the skills to design a smartphone. It won't necessarily be good, but I remember that years ago, someone made one with a touchscreen hat and GSM hat atop a Raspberry Pi, rubber-banded to a power bank. I'm sure any one of us HN users could do this. And it worked. Quality only goes up from there. The problem is it won't run any apps, so you'll need to carry this open-source secure phone in…

Or use everything via the web browser; but yes, I think apps are the main reason we can't just have a generic Linux phone OS on an open hardware platform

Apps make or break operating systems and app stores. Just ask Microsoft (Windows Phone) or Huawei (HarmonyOs). IIRC amazon was paying devs to publish to their app store or something like that.

Thankfully, some apps have both web and native mobile versions but for a modern digital life, the critical apps are sadly not on both versions.

Re: GrapheneOS is the only Android OS providing full security patches

#137

Earlier quoted context omitted.

Has the OEM in question been revealed yet? Likely not one of the major OEMs because they all lock their bootloaders. I'm crossing my fingers it's Fairphone but that's because I love my FP5. The GrapheneOS devs have been pretty harsh towards Fairphone because of their slow updates.

The most likely contenders are OnePlus, Motorola, and HMD. > "It is a big enough OEM that there is good chance you may have owned a device from them in the past." I think this takes Nothing out of contention.

What about HTC, LG? Heck, Blackberry rising from the ashes?

I'd love for it to be Framework.

Re: GrapheneOS is the only Android OS providing full security patches

#139
post #61

Earlier quoted context omitted.

In the ARM world, there isn't even a standard way to boot, and there are no standard hardware interfaces - except maybe the interrupt controller, since it's part of the CPU and only ARM designs the CPUs. On any PC, you can still use BIOS/UEFI services to get a basic framebuffer and keyboard input. You cannot do that on embedded ARM devices - you need to get several layers into the graphics stack to have a framebuffer…

I worked with ARM boards, I know a bit about it. Booting into Linux is never hard, it's all about using uboot, sometimes with tiny patches on top. I think it's actually even easier with android phones, as you don't have access to the low level bootloader, you just use fastboot stuff. Having basic framebuffer in BIOS/UEFI is neat for toy OSes, but not very relevant for something practical. You gotta need proper driver…

Booting into a mainline Linux kernel on your average junk-level SBC with all the hardware working (without simply sticking to an Android-like downstream/proprietary BSP) is quite hard, and that's what you need in order to make a phone usable as a daily driver. That's really the root issue; mobile phones are built as embedded devices, with no consideration for running a generic OS kernel. This isn't even an Android issue, OpenMoko was the same deal. If anything, Android was the first mobile platform to even loosely approach any kind of PC-like openness.

Re: GrapheneOS is the only Android OS providing full security patches

#140

Earlier quoted context omitted.

Why not run Android directly, such as using Graphene OS. It's decades ahead in both OS architecture, developer tools, and developers compared to non Android based Linux operating systems.

Graphene uses the Google codebase, so Google is choosing its long-term development strategy and standards it will support. It's like choosing Chromium to escape Chrome.

The same can be said about the Linux codebase. Tomorrow Linus could private his branch and stop supporting public releases. If AOSP goes closed source then people can fork it and continue to maintain it.
Post reply on HN