Live data from Hacker News

GrapheneOS is the only Android OS providing full security patches

grapheneos.social

151–160 of 467 posts

Re: GrapheneOS is the only Android OS providing full security patches

#151

Earlier quoted context omitted.

$10 million dollars per app. The creator of the new OS will pay. If you offer enough cash they will stop laughing.

Have you ever tried to pay a bank to do something for you ? Trying to get some scale, you're hypothesizing about giving 10 millions to HSBC to make business with your startup, when they're throwing away 500+ millions every year just to cover their money laundering. https://www.investopedia.com/stock-analysis/2013/investing-n... And we're discussing doing this for basically every major banks.

But what what I'm asking for is only a small amount of engineering time to add 1 line to their gradle and change 1 line in their app's code. This isn't a deal spanning many engineering years doing on going work and having to measure how effective things are. It's a small change plus the overhead of making a deal and getting through the beurocracy.

Re: GrapheneOS is the only Android OS providing full security patches

#152

Earlier quoted context omitted.

I don't think that's a fair comparison. OEMs have quite a lot of extra steps before releasing any build to the public. They have to pass xTS, the set of test suites required before getting certified by Google, possibly carrier certification, regulatory requirements and more depending on where the build will be released. There are "quicker" release channels for security fixes, but I don't think it's common for OEMs to…

Yep. And GrapheneOS's changes to the kernels of devices they ship are laughably small, 20-30 commits at most. I don't think they even do any basic CVE checks on any of the source code. Fuzzing, actual security analysis - all those things are done by Google.

isn't that by design? for GKIs i mean

Re: GrapheneOS is the only Android OS providing full security patches

#153
post #2

> may i ask how you obtain the source? Are you registered as an OEM at Google? Same question, how does Graphene get patches?

Yes. They've parterned with an OEM. In fact, they are making an official GOS phone with that OEM.

afaict it's more like "making sure 's next flagship supports graphene"

Re: GrapheneOS is the only Android OS providing full security patches

#154
post #116
post #58

You can tell it's truly secure and private because the Cellebrite leak says they can't break it (one of very few!) and some governments assume you're a drug dealer if you use it. My next phone will run GrapheneOS.

Have a link to the source? And have they said they can’t break it, or haven’t yet? I’d imagine from a business perspective it would hardly be worth it

https://discuss.grapheneos.org/d/14344-cellebrite-premium-ju...

Re: GrapheneOS is the only Android OS providing full security patches

#155

which pixel model is best for grephene? I strongly prefer long battery life. will other phones be supported? why only pixel?

The OS is not very relevant to the Pixel. Compare the Pixels you like that are new (GrapheneOS drops support as models become older flagships, I think for security reasons) and get that one. IIRC, currently only Pixel is allowed, because the bootloader can be opened without rooting the device.

https://grapheneos.org/faq#device-support

Re: GrapheneOS is the only Android OS providing full security patches

#156

Earlier quoted context omitted.

Oh that's one of the best news in the smartphone world in a long time. It's impossible to escape the Apple/Google duopoly but at least GrapheneOS makes the most out of Android regarding privacy. I still wish we could get some kind of low resource, stable and mature Android clone instead of Google needlessly increasing complexity but this will over time break app compatibility (Google will make sure of it) Edit: I do…

I'm not knowledgeable enough -- what would it take to escape the Apple/Google duopoly? I'm imagining a future where you buy a smartphone and when you do the first configuration, it asks you which services provider you want to use. Google and Apple are probably at the top of the list, but at the bottom there is "custom..." where you can specify the IP or host.domain of your own self-hosted setup. Then, when you downlo…

There are some good stuff on the software side that people mention, but a big one is the driver support. We would need device makers to upstream support so there is less worrying about reverse engineering or needing to run modified ROMs based on old builds. Or just publish specs on the hardware that is enough for implementation. Sure, you can buy a specific phone and run a de-googled android or linux, but that only really works for the hobbyist who wants to spend time doing this. Which makes it difficult to create a market that encourages developers of software to port their software or write new software. With out being able to broadly support devices, most people are gonna be better off running Google's android.

Re: GrapheneOS is the only Android OS providing full security patches

#157

https://tbot.substack.com/p/grapheneos-new-oem-partnership > GrapheneOS has officially confirmed a major new hardware partnership—one that marks the end of its long-standing Pixel exclusivity. According to the team, work with a major Android OEM began in June and is now moving toward the development of a next-generation smartphone built to meet GrapheneOS’ strict privacy and security standards.

I wonder if a real OEM supports graphene if that would solve device attestation for things like banking apps.

[deleted]

Re: GrapheneOS is the only Android OS providing full security patches

#158

Earlier quoted context omitted.

They won't because they literally control the mobile market by having Android open source.

Now that their market is established, I don't think open-source is a requirement anymore. They would of course share with hardware vendors strategically.

True. All the big OEMs are in too deep with Android now, there's no going back. They could easily make it code share under NDA instead of open source.

Re: GrapheneOS is the only Android OS providing full security patches

#159

Earlier quoted context omitted.

I'm not knowledgeable enough -- what would it take to escape the Apple/Google duopoly? I'm imagining a future where you buy a smartphone and when you do the first configuration, it asks you which services provider you want to use. Google and Apple are probably at the top of the list, but at the bottom there is "custom..." where you can specify the IP or host.domain of your own self-hosted setup. Then, when you downlo…

> I'm not knowledgeable enough -- what would it take to escape the Apple/Google duopoly? At this point? Reliable emulation that can run 99% of Android apps, to provide a bridge until the platform is interesting enough for people to develop for it "natively". I think the easiest way to do that would be to run Android in a VM.

Has no one mentioned not using a smartphone as an option?

Re: GrapheneOS is the only Android OS providing full security patches

#160

Earlier quoted context omitted.

Have you ever tried to pay a bank to do something for you ? Trying to get some scale, you're hypothesizing about giving 10 millions to HSBC to make business with your startup, when they're throwing away 500+ millions every year just to cover their money laundering. https://www.investopedia.com/stock-analysis/2013/investing-n... And we're discussing doing this for basically every major banks.

But what what I'm asking for is only a small amount of engineering time to add 1 line to their gradle and change 1 line in their app's code. This isn't a deal spanning many engineering years doing on going work and having to measure how effective things are. It's a small change plus the overhead of making a deal and getting through the beurocracy.

The issue is to have them do anything at all.

I see it akin to the proverbial "not getting out of bed for less than XXXXX". You're getting out of bed every day, for free. But having someone make you do it for a specific reason will be an exponentially harder proposition.

> 1 line in their app

Aren't you asking them to maintain compatibility outside of Play Services and be on available on your platform ? That's a whole project, including their (or their contracting shop's) validating the whole new stack from a security and technical perspective, and a legal and business check on what that actually means to them.

Perhaps we can look at it from a darker perspective: if a random guy came to the bank to ask them support for their parralel phone ecosystem, the bank would at least want to know what they're getting into and what's in it for them. Especially if they're offered 10 millions for allegedly one line of code.

Post reply on HN