I use CalyxOs without any Google Apps (camera app blocked via firewall). I find GrapheneOS horrible. If I want to get away from Google, I don't want to run Google Apps in the sandbox either
Care to elaborate more on how you find GrapheneOS "terrible"?
Reclaiming Mobile Privacy with GrapheneOS
21–30 of 80 posts
Re: Reclaiming Mobile Privacy with GrapheneOS
#22Quoted post unavailable.
Re: Reclaiming Mobile Privacy with GrapheneOS
#23Re: Reclaiming Mobile Privacy with GrapheneOS
#24Quoted post unavailable.
Re: Reclaiming Mobile Privacy with GrapheneOS
#25I love GrapheneOS. Before trying it one should consider that unlike some "sister" projects, it does not support signature spoofing, so if you need SafetyNet or something similar, you will likely be out of luck. On one hand I like the no spoofing position the devs took, on the other hand my banking app.
Re: Reclaiming Mobile Privacy with GrapheneOS
#26I had to switch back to iOS. My smartphone is my primary camera and I missed lots of important shots because the Graphene camera was so slow to double click launch from locked (on a flagship pixel $LATEST pro max whatever). I really miss syncthing.
Re: Reclaiming Mobile Privacy with GrapheneOS
#27I love GrapheneOS. Before trying it one should consider that unlike some "sister" projects, it does not support signature spoofing, so if you need SafetyNet or something similar, you will likely be out of luck. On one hand I like the no spoofing position the devs took, on the other hand my banking app.
You should read https://grapheneos.org/usage#banking-apps and https://grapheneos.org/articles/attestation-compatibility-gu.... GrapheneOS has full hardware-based attestation support and we use it ourselves in a much more secure way than this weak anti-fraud approach. The long-term solution is convincing major apps wanting to deploy this to allowlist GrapheneOS via hardware attestation.
We currently choose not to ship patches spoofing the traditional software-based SafetyNet attestation / Play Integrity API attestation. The reason for this is because we don't really want to ship a set of hacks which will stop working when they improve it and will permanently stop working when a service starts checking for strong verification. Having users start depending on Google Pay NFC payments working and then having it go away would be a problem for a production quality OS in a way that it wouldn't for a hobbyist project where expectations are different. We don't want to essentially commit to providing something we know is impossible to keep providing due to hardware attestation.
You can only spoof the weak basic verification, and whether it passed strong verification is always there in the result. It's only a matter of time before those services require it. It's based on when they're ready to start phasing out support for devices launched with Android 7.x and earlier along with a few phones that shipped with broken verified boot / attestation support even after it was required such as OnePlus. They can require it only for certain features if they want. Android 10+ is needed for security updates, so if they truly do care about security, nearly 100% of devices launched with Android 7.x and earlier are irrelevant now since only a small portion got upgraded to Android 10 (almost none beyond it) and those are now losing security support. Android 10 will be losing security support soon.
We may reconsider and ship spoofing for the legacy software-based attestation (known as non-strong verification by those APIs) if not shipping it becomes an adoption issue due to others shipping it. It doesn't mean we think it's a good idea but we'd rather have people using a more secure OS than a highly insecure one often without proper security patches and a fake patch level displayed...
Re: Reclaiming Mobile Privacy with GrapheneOS
#28Quoted post unavailable.
The background story of the project is quite sad, so it sort of makes sense that he is very defensive of it. (The project got some monetary support initially from a company, which later tried to hijack the whole open-source project (going by copperhead os nowadays, I believe). Fortunately thanks to Micay the original was unharmed (he revoked private keys, big kudos!), but they do throw shade at GrapheneOS promoting t…
Re: Reclaiming Mobile Privacy with GrapheneOS
#29I've used GrapheneOS for a while now and have been impressed by it. I'd recommend it to all those who value privacy and security. Battery life is way better now as well.
Any comparisons to project /e/ or clyxOs?
GrapheneOS provides our sandboxed Google Play compatibility layer allowing using the Google Play apps as regular apps in the full standard app sandbox with no special access or privileges. We've made them work like any other apps, with absolutely no ability to do something a regular user installed app can't do. You also don't need to grant them permissions to use 95% of functionality and can revoke our added Sensors toggle (Network COULD be revoked and you can use GSF + Google Camera + Google Photos with Network revoked from each but most of Play services exists to provide Google services so it would somewhat defeat the purpose, but it's possible).
Re: Reclaiming Mobile Privacy with GrapheneOS
#30I've used GrapheneOS for a while now and have been impressed by it. I'd recommend it to all those who value privacy and security. Battery life is way better now as well.
Any comparisons to project /e/ or clyxOs?
Calyx supports Pixel3 and Fairphone, but otherwise looks pretty similar. According to GOS's main developer's comments in this thread, Calyx:
- doesn't have features like https://grapheneos.org/features#storage-scopes.
- doesn't have the Play sandbox
- "isn't a hardened OS and isn't at all comparable to GrapheneOS. They recently didn't even ship half the baseline Android security patches for 2 months, let alone providing much better patching and substantially hardening the privacy and security of the OS"
My opinion is biased since I'm a GOS user, and I have a very positive opinion of the project, so take this with a pinch of salt.