Live data from Hacker News

GrapheneOS is the only Android OS providing full security patches

grapheneos.social

161–170 of 467 posts

Re: GrapheneOS is the only Android OS providing full security patches

#161

Earlier quoted context omitted.

I'm not knowledgeable enough -- what would it take to escape the Apple/Google duopoly? I'm imagining a future where you buy a smartphone and when you do the first configuration, it asks you which services provider you want to use. Google and Apple are probably at the top of the list, but at the bottom there is "custom..." where you can specify the IP or host.domain of your own self-hosted setup. Then, when you downlo…

> I'm not knowledgeable enough -- what would it take to escape the Apple/Google duopoly? At this point? Reliable emulation that can run 99% of Android apps, to provide a bridge until the platform is interesting enough for people to develop for it "natively". I think the easiest way to do that would be to run Android in a VM.

Well if you rely on running Android apps, you still rely on Android.

Actually, if you rely on the app, you really on the Android SDK which is not open source.

Now if you could run AOSP but your own apps built with an open source SDK, that would be a different story. Some people seem to really want to do that with PWAs. I personnally tend to hate webapps, but I have to admit that they can be open source.

Re: GrapheneOS is the only Android OS providing full security patches

#162

Earlier quoted context omitted.

> I'm not knowledgeable enough -- what would it take to escape the Apple/Google duopoly? At this point? Reliable emulation that can run 99% of Android apps, to provide a bridge until the platform is interesting enough for people to develop for it "natively". I think the easiest way to do that would be to run Android in a VM.

Has no one mentioned not using a smartphone as an option?

How do you run WhatsApp or Signal without a smartphone? Pretty hard.

If your answer is "don't use them", then you're not living in a country where the vast majority of communications are done on WhatsApp or Signal, good for you I guess.

Re: GrapheneOS is the only Android OS providing full security patches

#163

Earlier quoted context omitted.

> So why would a company, in this new environment, invest resources in making their hardware compatible with competing software environments? Because that's what customers want to buy. People are paying premium iPhone prices for hardware with mediocre specs and then the hardware sells out when someone like Purism or Fairphone actually makes an open one. How many sales would you get if you did the same thing on a phon…

Some of the funnest work, if you could get it, was swapping ssds out of laptops coming through customs for high value targets.

Which is another reason we need to strip this hardware attestation stuff out of the hardware. It either needs to use exclusively keys the user loaded into the device themselves or the keys aren't on the device whatsoever and then the "high value targets" verify the contents of the drive from a known-clean machine once they get it back from the adversarial foreign officials before putting it back into service. Or better yet, keep a separate laptop on each side of the border and then sync the data over the internet instead of losing physical control over the device at an adversarial border.

Plenty of adversarial countries have a competent security service. A foreign government can compromise the corporation's root signing key for the devices through technical attacks and through bribery, espionage, physical intrusion, etc. And they're not going to tell you that they have before using it against your high value targets, so how do you protect them? By not relying on systems with a single point of compromise.

Re: GrapheneOS is the only Android OS providing full security patches

#164

Earlier quoted context omitted.

The most likely contenders are OnePlus, Motorola, and HMD. > "It is a big enough OEM that there is good chance you may have owned a device from them in the past." I think this takes Nothing out of contention.

What about HTC, LG? Heck, Blackberry rising from the ashes? I'd love for it to be Framework.

Those are no longer big these days so no. Also, they're not going to restart a whole product category just for grapheneos.

As OnePlus is kinda dead and taken over by oppo, I'm guessing Sony. They have some similar collaboration in the past like with Jolla. My Sony XA2 was one of the few models that could run sailfish.

Re: GrapheneOS is the only Android OS providing full security patches

#165

https://tbot.substack.com/p/grapheneos-new-oem-partnership > GrapheneOS has officially confirmed a major new hardware partnership—one that marks the end of its long-standing Pixel exclusivity. According to the team, work with a major Android OEM began in June and is now moving toward the development of a next-generation smartphone built to meet GrapheneOS’ strict privacy and security standards.

Oh that's one of the best news in the smartphone world in a long time. It's impossible to escape the Apple/Google duopoly but at least GrapheneOS makes the most out of Android regarding privacy. I still wish we could get some kind of low resource, stable and mature Android clone instead of Google needlessly increasing complexity but this will over time break app compatibility (Google will make sure of it) Edit: I do…

Totally agree. Pixel devices are probably still the best Android offering, but I originally got into the ecosystem because it was less confined and that appears to be changing. While I'm likely not representative of most consumers, I would love it if I could choose both the right device and right software for my particular needs .

Re: GrapheneOS is the only Android OS providing full security patches

#166

Earlier quoted context omitted.

Now that their market is established, I don't think open-source is a requirement anymore. They would of course share with hardware vendors strategically.

True. All the big OEMs are in too deep with Android now, there's no going back. They could easily make it code share under NDA instead of open source.

Huawei proved that they can move away from Android... unfortunately they did not go for a hard fork of AOSP but for a proprietary, new OS.

Re: GrapheneOS is the only Android OS providing full security patches

#167

https://tbot.substack.com/p/grapheneos-new-oem-partnership > GrapheneOS has officially confirmed a major new hardware partnership—one that marks the end of its long-standing Pixel exclusivity. According to the team, work with a major Android OEM began in June and is now moving toward the development of a next-generation smartphone built to meet GrapheneOS’ strict privacy and security standards.

This is really cool, but, longer term, what happens if Google makes android closed source? I feel this is a very real risk.

Not sure if the big manufacturers would want to depend on a proprietary Google OS. Samsung does make a lot of changes to the OS, for instance.

Re: GrapheneOS is the only Android OS providing full security patches

#168
post #12

Earlier quoted context omitted.

They have different goals: GrapheneOS wants to make a FOSS Android with the security model that makes it hard for any bad party to break into the phone. LineageOS wants to make a FOSS Android that respects user's privacy first and foremost - it implements security as best as it can but the level of security protections differs on different supported devices. Good news is that if you have a boot passphrase, it's secur…

that is simply wrong. GrapheneOS is both in terms of security and privacy the best but currently only supports pixel phones. LineageOS is trying to support as many devices as possible still with lot of google connections and missing security updates. >Good news is that if you have a boot passphrase, it's security is somewhat close to GrapheneOS its not anywhere close https://grapheneos.org/features

I am overwhelmed by the specificity of your demonstrated knowledge on this topic.

Re: GrapheneOS is the only Android OS providing full security patches

#169

Earlier quoted context omitted.

What about HTC, LG? Heck, Blackberry rising from the ashes? I'd love for it to be Framework.

Those are no longer big these days so no. Also, they're not going to restart a whole product category just for grapheneos. As OnePlus is kinda dead and taken over by oppo, I'm guessing Sony. They have some similar collaboration in the past like with Jolla. My Sony XA2 was one of the few models that could run sailfish.

> Also, they're not going to restart a whole product category just for grapheneos.

I don't think that there is any need to restart a new category. Just make your new phones good enough for GrapheneOS.

GrapheneOS has close to half a million users, I think it's worth doing some adjustments.

Re: GrapheneOS is the only Android OS providing full security patches

#170

Earlier quoted context omitted.

But what what I'm asking for is only a small amount of engineering time to add 1 line to their gradle and change 1 line in their app's code. This isn't a deal spanning many engineering years doing on going work and having to measure how effective things are. It's a small change plus the overhead of making a deal and getting through the beurocracy.

The issue is to have them do anything at all. I see it akin to the proverbial "not getting out of bed for less than XXXXX". You're getting out of bed every day, for free. But having someone make you do it for a specific reason will be an exponentially harder proposition. > 1 line in their app Aren't you asking them to maintain compatibility outside of Play Services and be on available on your platform ? That's a whol…

>not getting out of bed for less than XXXXX

I just made up the figure. Perhaps 10 billion dollars is more enticing. Perhaps you have to purchase the company outright and then dictate they add support. My point is that it's not impossible to get the apps people need to work on an alternate Android OS. It is a matter of funding conpatibility. You can find a niche audience of people to start out with to make a competitive OS for them. And then overtime expand that audience more and more.

>Aren't you asking them to maintain compatibility

Typically the complaints about banks is that they use the Play Integrity library which doesn't trust other operating systems. So the ask is to support the Android API for integrity and to trust the key of the OS provider. This would be done via a new library to make integration easier and more foolproof.

Post reply on HN