Live data from Hacker News

GrapheneOS is the only Android OS providing full security patches

grapheneos.social

231–240 of 467 posts

Re: GrapheneOS is the only Android OS providing full security patches

#231
post #58

You can tell it's truly secure and private because the Cellebrite leak says they can't break it (one of very few!) and some governments assume you're a drug dealer if you use it. My next phone will run GrapheneOS.

It could also just mean they haven't bothered try

I would imagine it's a very high priority if you have powerful targets. They're not gonna be running an off-the-shelf android phone.

Re: GrapheneOS is the only Android OS providing full security patches

#232

Earlier quoted context omitted.

I'm not knowledgeable enough -- what would it take to escape the Apple/Google duopoly? I'm imagining a future where you buy a smartphone and when you do the first configuration, it asks you which services provider you want to use. Google and Apple are probably at the top of the list, but at the bottom there is "custom..." where you can specify the IP or host.domain of your own self-hosted setup. Then, when you downlo…

> I'm not knowledgeable enough -- what would it take to escape the Apple/Google duopoly? At this point? Reliable emulation that can run 99% of Android apps, to provide a bridge until the platform is interesting enough for people to develop for it "natively". I think the easiest way to do that would be to run Android in a VM.

> I think the easiest way to do that would be to run Android in a VM.

The problem is the critical payment and government ID apps that will never run in an Android VM because they intentionally break without hardware attestation.

Re: GrapheneOS is the only Android OS providing full security patches

#233

https://tbot.substack.com/p/grapheneos-new-oem-partnership > GrapheneOS has officially confirmed a major new hardware partnership—one that marks the end of its long-standing Pixel exclusivity. According to the team, work with a major Android OEM began in June and is now moving toward the development of a next-generation smartphone built to meet GrapheneOS’ strict privacy and security standards.

I wonder if a real OEM supports graphene if that would solve device attestation for things like banking apps.

Non-Google attestation is still a bad thing.

I'd much rather GrapheneOS continue to get popular enough that banking apps are forced to support phones without attestation.

Re: GrapheneOS is the only Android OS providing full security patches

#234

https://tbot.substack.com/p/grapheneos-new-oem-partnership > GrapheneOS has officially confirmed a major new hardware partnership—one that marks the end of its long-standing Pixel exclusivity. According to the team, work with a major Android OEM began in June and is now moving toward the development of a next-generation smartphone built to meet GrapheneOS’ strict privacy and security standards.

I wonder if a real OEM supports graphene if that would solve device attestation for things like banking apps.

I'm writing this on a grapheneos pixel 5. I have the app for very-large-USbank and a few others. With 'exploit protection compatibility toggle' enabled they works fine. In what regard this applies to device attestation I couldn't say.

Re: GrapheneOS is the only Android OS providing full security patches

#235

Earlier quoted context omitted.

I don't think that's a fair comparison. OEMs have quite a lot of extra steps before releasing any build to the public. They have to pass xTS, the set of test suites required before getting certified by Google, possibly carrier certification, regulatory requirements and more depending on where the build will be released. There are "quicker" release channels for security fixes, but I don't think it's common for OEMs to…

Yep. And GrapheneOS's changes to the kernels of devices they ship are laughably small, 20-30 commits at most. I don't think they even do any basic CVE checks on any of the source code. Fuzzing, actual security analysis - all those things are done by Google.

Their contributions upstream go way back, I think someone could misread this comment that they've not contributed, and that would be an unfortunate misunderstanding.

Re: GrapheneOS is the only Android OS providing full security patches

#236
post #162

Earlier quoted context omitted.

Has no one mentioned not using a smartphone as an option?

How do you run WhatsApp or Signal without a smartphone? Pretty hard. If your answer is "don't use them", then you're not living in a country where the vast majority of communications are done on WhatsApp or Signal, good for you I guess.

Signal can be used without a phone using signal-cli. You can sign up with it and either attach your account to signal-desktop or keep using signal-cli

Re: GrapheneOS is the only Android OS providing full security patches

#237

Earlier quoted context omitted.

I would not trust any of these. They are a security disaster, lacking even basic features for securing your device against tampering and hacking. There is a reason GrapheneOS is number one and a reason why they only run on Pixels (for now).

Depends on your threat model, but yes.

[flagged]

Re: GrapheneOS is the only Android OS providing full security patches

#238

https://tbot.substack.com/p/grapheneos-new-oem-partnership > GrapheneOS has officially confirmed a major new hardware partnership—one that marks the end of its long-standing Pixel exclusivity. According to the team, work with a major Android OEM began in June and is now moving toward the development of a next-generation smartphone built to meet GrapheneOS’ strict privacy and security standards.

I wonder if a real OEM supports graphene if that would solve device attestation for things like banking apps.

[dead]

Re: GrapheneOS is the only Android OS providing full security patches

#239

The GrapheneOS obsession with picking a fight with everyone else is the most unfortunate part of the project.

“The reasonable man adapts himself to the world: the unreasonable one persists in trying to adapt the world to himself. Therefore all progress depends on the unreasonable man.”

[flagged]

Re: GrapheneOS is the only Android OS providing full security patches

#240
post #85
post #58

You can tell it's truly secure and private because the Cellebrite leak says they can't break it (one of very few!) and some governments assume you're a drug dealer if you use it. My next phone will run GrapheneOS.

Does the Celebrite leak say out can break recent iOS?

[flagged]
Post reply on HN