https://tbot.substack.com/p/grapheneos-new-oem-partnership > GrapheneOS has officially confirmed a major new hardware partnership—one that marks the end of its long-standing Pixel exclusivity. According to the team, work with a major Android OEM began in June and is now moving toward the development of a next-generation smartphone built to meet GrapheneOS’ strict privacy and security standards.
GrapheneOS is the only Android OS providing full security patches
221–230 of 467 posts
Re: GrapheneOS is the only Android OS providing full security patches
#222https://tbot.substack.com/p/grapheneos-new-oem-partnership > GrapheneOS has officially confirmed a major new hardware partnership—one that marks the end of its long-standing Pixel exclusivity. According to the team, work with a major Android OEM began in June and is now moving toward the development of a next-generation smartphone built to meet GrapheneOS’ strict privacy and security standards.
Re: GrapheneOS is the only Android OS providing full security patches
#223https://tbot.substack.com/p/grapheneos-new-oem-partnership > GrapheneOS has officially confirmed a major new hardware partnership—one that marks the end of its long-standing Pixel exclusivity. According to the team, work with a major Android OEM began in June and is now moving toward the development of a next-generation smartphone built to meet GrapheneOS’ strict privacy and security standards.
Oh that's one of the best news in the smartphone world in a long time. It's impossible to escape the Apple/Google duopoly but at least GrapheneOS makes the most out of Android regarding privacy. I still wish we could get some kind of low resource, stable and mature Android clone instead of Google needlessly increasing complexity but this will over time break app compatibility (Google will make sure of it) Edit: I do…
This is why I can’t do GrapheneOS. Pixel devices do not suit my needs (& aren’t available). 2 of the big appeals for my going Android was 1) device options 2) ability to customize (appearance, apps from other sources, root access). Google has basically done everything to prevent #2 & GrapheneOS prevents #1. …This is why I also have a Linux phone to just leave these restrictions.
Re: GrapheneOS is the only Android OS providing full security patches
#224Earlier quoted context omitted.
Has the OEM in question been revealed yet? Likely not one of the major OEMs because they all lock their bootloaders. I'm crossing my fingers it's Fairphone but that's because I love my FP5. The GrapheneOS devs have been pretty harsh towards Fairphone because of their slow updates.
The most likely contenders are OnePlus, Motorola, and HMD. > "It is a big enough OEM that there is good chance you may have owned a device from them in the past." I think this takes Nothing out of contention.
Re: GrapheneOS is the only Android OS providing full security patches
#225Earlier quoted context omitted.
The issue is to have them do anything at all. I see it akin to the proverbial "not getting out of bed for less than XXXXX". You're getting out of bed every day, for free. But having someone make you do it for a specific reason will be an exponentially harder proposition. > 1 line in their app Aren't you asking them to maintain compatibility outside of Play Services and be on available on your platform ? That's a whol…
>not getting out of bed for less than XXXXX I just made up the figure. Perhaps 10 billion dollars is more enticing. Perhaps you have to purchase the company outright and then dictate they add support. My point is that it's not impossible to get the apps people need to work on an alternate Android OS. It is a matter of funding conpatibility. You can find a niche audience of people to start out with to make a competiti…
Re: GrapheneOS is the only Android OS providing full security patches
#226As a LineageOS user, I'd be interested in the disparity between GrapheneOS and LineageOS.
If you have a Pixel -> Graphene, if not -> Lineage. I personally don't care about "security" all that much, my main reason for using Graphene is freedom to use my hardware in any way I wish. This means unrestricted ability to run any program on the phone from any source. Sideloading restrictions don't apply to Graphene, and it is also impossible for state actors to impose things such as client-side scanning of text m…
Re: GrapheneOS is the only Android OS providing full security patches
#227The GrapheneOS obsession with picking a fight with everyone else is the most unfortunate part of the project.
Re: GrapheneOS is the only Android OS providing full security patches
#228Earlier quoted context omitted.
This is really cool, but, longer term, what happens if Google makes android closed source? I feel this is a very real risk.
They won't because they literally control the mobile market by having Android open source.
Re: GrapheneOS is the only Android OS providing full security patches
#229Re: GrapheneOS is the only Android OS providing full security patches
#230Earlier quoted context omitted.
I don't think that's a fair comparison. OEMs have quite a lot of extra steps before releasing any build to the public. They have to pass xTS, the set of test suites required before getting certified by Google, possibly carrier certification, regulatory requirements and more depending on where the build will be released. There are "quicker" release channels for security fixes, but I don't think it's common for OEMs to…
> I don't think that's a fair comparison. Fair? > OEMs have quite a lot of extra steps before releasing any build to the public. AIUI updates are less stringent and burdensome than initial certification. Regardless much of the process is automated. Graphene has CI too. 3PL's taking 4 weeks to run automated tests is also absurd. There are some "manual steps" to run CTS-V but they shouldn't be weeks level burdensome ei…
That's true having dealt with some of it, nonetheless I haven't found that much of a difference due to having to use 3PL.
There's more manual steps on top of CTSV for camera and GMS, but that's all there is to it.
The only real difference I've seen is on Google's side to actually say "ok" before it getting approved.
Carriers and regulations are better on that side, but assume you have a security fix in the modem, for some carriers you're supposed (emphasis here) to redo it...
> Seems like a decision that is not user-centric.
I can see how having two release channels one solely for security and a bigger one might be a burden on some. But you hardly want to only fix security issues when you have a real bugfix you want to also release, so it makes sense to me the channels have to be merged.
> Private test suites for software are a toxic idea
To be fair on android side they're quite fine. One is specifically for GMS compliance, one for camera verification, and one for security patches verification.
The latter is janky and not as updated as you'd think, so unless you really forget to apply patches it'll pass.
With that said, the amount of people running those test suites not for certification can probably be counted on a single hand, I think that's the least of the problems.