Live data from Hacker News

GrapheneOS is the only Android OS providing full security patches

grapheneos.social

191–200 of 467 posts

Re: GrapheneOS is the only Android OS providing full security patches

#191

Earlier quoted context omitted.

The issue is to have them do anything at all. I see it akin to the proverbial "not getting out of bed for less than XXXXX". You're getting out of bed every day, for free. But having someone make you do it for a specific reason will be an exponentially harder proposition. > 1 line in their app Aren't you asking them to maintain compatibility outside of Play Services and be on available on your platform ? That's a whol…

>not getting out of bed for less than XXXXX I just made up the figure. Perhaps 10 billion dollars is more enticing. Perhaps you have to purchase the company outright and then dictate they add support. My point is that it's not impossible to get the apps people need to work on an alternate Android OS. It is a matter of funding conpatibility. You can find a niche audience of people to start out with to make a competiti…

> It is a matter of funding conpatibility.

Key clients requesting support for the alternative OS will be a way faster route IMHO. The same way nobody bribed banks to support android, they saw the market share and potential and decided by themselves it was a worth doing. Which is why it came so late.

I understand you're offering a way to get around the chicken and egg problem, I'm saying dealing with the supply part is crazy hard. Somewhat paying users to buy into your ecosystem despite the lack of support could be a better use of money (I'm thinking about Meta subsidizing Occulus until it got some traction, and I assume it's still in the red after so many years)

> the Android API

People loosely explain the lack of technical challenge, but from the institution's POV you're asking them to expand their trust from Google, a US company which will be solely responsible if anything critical happens...to potentially each single phone maker, whoever happens to be selling the device to your clients ?

If Google didn't exist that's what they'd do. But Play Services is a thing. The more I think about the less I see an incentive for any established player to do that move until customers are actively clamoring for it. There's just no upside otherwise.

Re: GrapheneOS is the only Android OS providing full security patches

#192

Earlier quoted context omitted.

Graphene uses the Google codebase, so Google is choosing its long-term development strategy and standards it will support. It's like choosing Chromium to escape Chrome.

The same can be said about the Linux codebase. Tomorrow Linus could private his branch and stop supporting public releases. If AOSP goes closed source then people can fork it and continue to maintain it.

Linux doesn’t really rely on Linus for coding anymore…

Re: GrapheneOS is the only Android OS providing full security patches

#193

Earlier quoted context omitted.

I'm not knowledgeable enough -- what would it take to escape the Apple/Google duopoly? I'm imagining a future where you buy a smartphone and when you do the first configuration, it asks you which services provider you want to use. Google and Apple are probably at the top of the list, but at the bottom there is "custom..." where you can specify the IP or host.domain of your own self-hosted setup. Then, when you downlo…

You can escape the duopoly by using a GNI/Linux phone, Librem 5 or Pinephone, but don't expect any support from Google or Apple for them. I'm using the former as a daily driver.

I would not trust any of these. They are a security disaster, lacking even basic features for securing your device against tampering and hacking.

There is a reason GrapheneOS is number one and a reason why they only run on Pixels (for now).

Re: GrapheneOS is the only Android OS providing full security patches

#194
post #167

Earlier quoted context omitted.

This is really cool, but, longer term, what happens if Google makes android closed source? I feel this is a very real risk.

Not sure if the big manufacturers would want to depend on a proprietary Google OS. Samsung does make a lot of changes to the OS, for instance.

"Not sure if the big manufacturers"

thats the thing, they would supply android os to these major manufacturer, but for the rest??? need vetted applications

Re: GrapheneOS is the only Android OS providing full security patches

#195
post #166

Earlier quoted context omitted.

True. All the big OEMs are in too deep with Android now, there's no going back. They could easily make it code share under NDA instead of open source.

Huawei proved that they can move away from Android... unfortunately they did not go for a hard fork of AOSP but for a proprietary, new OS.

"they can move away from Android"

nah, it still android

Re: GrapheneOS is the only Android OS providing full security patches

#196

Earlier quoted context omitted.

You can escape the duopoly by using a GNI/Linux phone, Librem 5 or Pinephone, but don't expect any support from Google or Apple for them. I'm using the former as a daily driver.

I would not trust any of these. They are a security disaster, lacking even basic features for securing your device against tampering and hacking. There is a reason GrapheneOS is number one and a reason why they only run on Pixels (for now).

Depends on your threat model, but yes.

Re: GrapheneOS is the only Android OS providing full security patches

#197
post #167

Earlier quoted context omitted.

This is really cool, but, longer term, what happens if Google makes android closed source? I feel this is a very real risk.

Not sure if the big manufacturers would want to depend on a proprietary Google OS. Samsung does make a lot of changes to the OS, for instance.

What's the alternative? I doubt even someone as big as Samsung will be willing or able to develop their own alternative OS (atleast one that can actually grab marketshare enough that critical apps get ported), and I can't imagine them wanting to hitch their wagon to the Linux alternatives.

Re: GrapheneOS is the only Android OS providing full security patches

#198

Earlier quoted context omitted.

Oh that's one of the best news in the smartphone world in a long time. It's impossible to escape the Apple/Google duopoly but at least GrapheneOS makes the most out of Android regarding privacy. I still wish we could get some kind of low resource, stable and mature Android clone instead of Google needlessly increasing complexity but this will over time break app compatibility (Google will make sure of it) Edit: I do…

I have been trying to come off of google and cloud by building — quite slowly — my own nas server which has 2 nodes in two geographic regions where I am building certain services like cloud storage and backup, webhosting etc. But I think there are a few key things that need to be community driven to really get rid of this duoply. 0. A privacy first approach would be something like this: `You+App --Read/Write-> f_priv…

I don't understand your syntax:

    `You+App --Read/Write-> f_private(your_data) 
Does this mean a server where third parties can send code to run on your data, but cannot respond to them?

Re: GrapheneOS is the only Android OS providing full security patches

#199

Earlier quoted context omitted.

Yes, but keep in mind individual apps like Signal need to run in the background at all times if you want to receive timely notifications on Graphene, because they cannot rely on the Google backend for that. If you have enough such apps, you may well find that battery life is shorter than on the stock OS.

This is true if you opt not to install Google Play Services.

Good point, I chose not to on my main "Owner" profile to be fully Google-free. I have the sandboxed Play Services on a separate profile I hardly ever use for testing purposes.

Re: GrapheneOS is the only Android OS providing full security patches

#200

Earlier quoted context omitted.

Graphene uses the Google codebase, so Google is choosing its long-term development strategy and standards it will support. It's like choosing Chromium to escape Chrome.

The same can be said about the Linux codebase. Tomorrow Linus could private his branch and stop supporting public releases. If AOSP goes closed source then people can fork it and continue to maintain it.

The Linux kernel cannot be relicensed. Linus does not hold copyright to most code.
Post reply on HN