Also, https://postmarketos.org/ is a good project too.
GrapheneOS – A privacy and security-focused mobile OS with Android compatibility
141–150 of 186 posts
Re: GrapheneOS – A privacy and security-focused mobile OS with Android compatibility
#142Earlier quoted context omitted.
That sounds reasonable, but here we are with Android's endless security disaster and all their apps written in not-Java from the beginning. The most cancerous aspects of Android are by design, that you cannot control network exfiltration from apps, you cannot update or modify the OS pieces at will, and the apps are monetizing everything you do and everything they can find against you. Librem will answer these.
> that you cannot control network exfiltration from apps GrapheneOS has a Network permission toggle, which is one of the features already restored from the past work on the project. There are many other privacy and security features that still need to be ported to the latest release, although a lot of them have become standard features especially in Android Q. https://gist.github.com/thestinger/e4bb344dcc545d2ee00dcc…
Privacy is security!
Re: GrapheneOS – A privacy and security-focused mobile OS with Android compatibility
#143Earlier quoted context omitted.
> with completely Open pieces AOSP is completely open source. Hardware and firmware is a much different story, but that applies to the device you're promoting just as much... > They're making good progress and I can't wait to be able to update my handheld device with mainline pieces for as long as anyone who still uses one cares to update it. Currently my Samsung Android device is at Dec 2018 patchlevel and nothing I…
> AOSP is completely open source. This is only true in the most technical way possible. Yes, AOSP is open source -- but none of the standard applications on any stock version of Android use AOSP anymore. The calendar and other applications are all proprietary. The AOSP versions feel like they stopped being developed in 2010 -- which coincidentally is when Google started developing proprietary replacements. I use Line…
Interesting, I did not know that. What are the reasons for this? Military application? Are these laws subject to change?
I always thought that there is no way to separate the CPU from the baseband/communications PU.
Re: GrapheneOS – A privacy and security-focused mobile OS with Android compatibility
#144Earlier quoted context omitted.
Have you tried a pure AOSP + F-Droid on Nexus/Pixel or Xperia? It's quite good. The only major drawback are closed drivers. But the userland is nice, open and polished. My worry with Librem and all those initiatives is that rebuilding an ecosystem like F-Droid takes a lot of effort and time.
A Pixel running stock AOSP with F-droid and Chromium is the bleeding edge of what's possible with open source. There's no better UI/UX in existence and the tragedy of it all is that outside of Android developers and software engineers most people never get to experience it at all. The reality is that Librem is unnecessary because we have F-droid. There's nothing wrong with F-droid and as time goes on more mainstream…
GrapheneOS is sadly only available on Pixel devices.
Re: GrapheneOS – A privacy and security-focused mobile OS with Android compatibility
#145Earlier quoted context omitted.
Not the entire industry, as many companies have thankfully moved on from plain old C, or at very least reduced its use quite considerably. BSD/Linux derived FOSS is still the C stronghold. The Morris worm was in 1988, since then C has collected enough CVEs due to memory corruption issues to consider its use bad practice. Something that even Apple, Google and Microsoft security reports now advise against, and with Goo…
> BSD/Linux derived FOSS is still the C stronghold. Oh that's ok then, it's not like that accounts for most of the world's server and embedded infrastructure, open or otherwise...
And regarding embedded space, AUTOSAR now requires C++14.
I think there are enough computers with wheels to deem it relevant.
Re: GrapheneOS – A privacy and security-focused mobile OS with Android compatibility
#146Earlier quoted context omitted.
I agree, hardware is a primary concern. I am not meaning to paint those who work on AOSP or third-party ROMs in a bad light. The work they do is terrific and great for the community. I also do not mean to dismiss any of the fantastic work that Graphene brings to the Android community. I am simply stating that the biggest difference between Librem and Android is that there are more hurdles to jump through to provide a…
Librem 5 is not open hardware. I also don't understand why you're comparing hardware to an operating system that's perfectly capable of running on top of it with the strengths and weaknesses of the hardware underneath it. You make it sound like AOSP or GrapheneOS wouldn't run on it. I don't think it would make a very good hardware target due to having so many security regressions from the status quo but it could cert…
Could you write more on the state of open hardware, and perhaps point me to open-hardware endeavours that have the slightest chance of success?
I understand that it is an very expensive undertaking to deliver a hardware mashine that is based on an open architecture from the CPU to the actual communication/data storage devices (logical design, actual layout, photolithography, assembly). Since patents on older circuitry must be all expired by now, it must be the lack of money that is the actual stopper for truly open systems.
Re: GrapheneOS – A privacy and security-focused mobile OS with Android compatibility
#147A very condensed version of the messy CopperheadOS implosion is: https://en.wikipedia.org/wiki/CopperheadOS#History It's good that the tech person is moving on, but Android doesn't seem a great starting point if privacy&security are the top priorities (as opposed to remaining captive in the Android camp, with some belief that you're a bit more secure than default).
The Android Open Source Project is the only viable starting point. I don't know what else you would suggest. It has solid privacy and security as a baseline already, unlike other mobile or desktop Linux-based operating systems. There's also a huge amount of public security research targeting it for both offensive and defensive work. Moving to the desktop Linux stack would drastically set back both privacy and securit…
Stop spreading FUD. In this conversation we are talking about phones filled with bloatware that spies on the user in every instant and you nitpick about memory safety in the kernel.
Re: GrapheneOS – A privacy and security-focused mobile OS with Android compatibility
#148Earlier quoted context omitted.
> with completely Open pieces AOSP is completely open source. Hardware and firmware is a much different story, but that applies to the device you're promoting just as much... > They're making good progress and I can't wait to be able to update my handheld device with mainline pieces for as long as anyone who still uses one cares to update it. Currently my Samsung Android device is at Dec 2018 patchlevel and nothing I…
> AOSP is completely open source. This is only true in the most technical way possible. Yes, AOSP is open source -- but none of the standard applications on any stock version of Android use AOSP anymore. The calendar and other applications are all proprietary. The AOSP versions feel like they stopped being developed in 2010 -- which coincidentally is when Google started developing proprietary replacements. I use Line…
I want a real Linux in a phone as much as anyone. In fact, I have stuck to the Maemo N770-N9 saga as much as I could.
But I am also realistic. Developing a new secure Linux distribution for phones and, most importantly, a healthy ecosystem with useful applications will take a lot of time and effort.
In the meanwhile, as discussed in other threads here, using AOSP on a Pixel (or even better, GrapheneOS) is a really good solution. It's remarkable how few people use it in comparison to the benefits it brings into the table, and given it's quite easy to migrate to it with the appropriate hardware (hopefully device-independent ROMs make this less restrictive).
If standard applications in AOSP are lagging behind, then it'd be probably worthy to spin off an effort to replicate all proprietary functionality. An equivalent to MicroG.
That said, I've never missed anything major. For me, Firefox/Chromium, K-9, Conversations/Signal, OsmAnd and Termux provide a great userland experience.
Re: GrapheneOS – A privacy and security-focused mobile OS with Android compatibility
#149What does it matter if you are still running proprietary software with direct memory and CPU access on your network, camera, ... Android can give you privacy and enough security for most people. This can't add much more as long as its running on the same devices. This is a great effort and I support it, but let's not imagine this will make our phones that much more secure.
Open source is a development model and doesn't have magical privacy and security properties. An iPhone is going to remain the best overall option for privacy and security for the near future, especially for users that aren't very technical. That's not really in spite of it being almost entirely proprietary but rather that's something quite orthogonal to it. GrapheneOS aims to provide a much more private and secure op…
This is misleading.
> A maliciously inserted backdoor designed to be stealthy would be indistinguishable from those
This is a false equivalence. In most closed source systems the vendor does not need to put efforts into designing a stealthy backdoor.
It just adds tons of code that spy on the user and call it features. The amount of homecalling done by android, ios and windows is staggering.
Not to mention the ability to push an update that can contain a backdoor on a specific, targeted device without the users being aware of it.
Re: GrapheneOS – A privacy and security-focused mobile OS with Android compatibility
#150Librem seems to have the correct way forward, reject the big mess of Android and catch up to it with completely Open pieces. https://puri.sm/products/librem-5/ They're making good progress and I can't wait to be able to update my handheld device with mainline pieces for as long as anyone who still uses one cares to update it. Currently my Samsung Android device is at Dec 2018 patchlevel and nothing I can do about it.
I hope Librem remains viable. As someone who needs some specific apps for work, I won't be able to switch for practical considerations unless those services work well enough on the device. For example, Slack. I could carry a second device for personal use, but am unlikely to.
- Decent hardware available at competitive price
-- While I could make do with some degraded performance for a truly open phone concept, most people would not, especially if price point is similar to, or higher, than established closed platform brands
- Must have apps available - needed for wide acceptance
-- My personal examples of must have apps:
-- BankID (Swedish e-id, needed for banks, taxes, government sites, payments)
-- Swish - Swedish app for personal micro transactions
-- Public transportation apps (tickets/timetable)
-- Bank application
-- Signal
Without these apps, a open platform phone would be next to useless to me. And I am a big proponent of open platforms.
And looking at how reluctant BankID were to even support older version android phones, I am not optimistic to them adding a completely new platform to support.
I know people who were forced to upgrade from "old" phones because BankID no longer supported their Android version, and phones would not get newer Android version.