You can tell it's truly secure and private because the Cellebrite leak says they can't break it (one of very few!) and some governments assume you're a drug dealer if you use it. My next phone will run GrapheneOS.
It could also just mean they haven't bothered try
GrapheneOS is the only Android OS providing full security patches
231–240 of 467 posts
Re: GrapheneOS is the only Android OS providing full security patches
#232Earlier quoted context omitted.
I'm not knowledgeable enough -- what would it take to escape the Apple/Google duopoly? I'm imagining a future where you buy a smartphone and when you do the first configuration, it asks you which services provider you want to use. Google and Apple are probably at the top of the list, but at the bottom there is "custom..." where you can specify the IP or host.domain of your own self-hosted setup. Then, when you downlo…
> I'm not knowledgeable enough -- what would it take to escape the Apple/Google duopoly? At this point? Reliable emulation that can run 99% of Android apps, to provide a bridge until the platform is interesting enough for people to develop for it "natively". I think the easiest way to do that would be to run Android in a VM.
The problem is the critical payment and government ID apps that will never run in an Android VM because they intentionally break without hardware attestation.
Re: GrapheneOS is the only Android OS providing full security patches
#233https://tbot.substack.com/p/grapheneos-new-oem-partnership > GrapheneOS has officially confirmed a major new hardware partnership—one that marks the end of its long-standing Pixel exclusivity. According to the team, work with a major Android OEM began in June and is now moving toward the development of a next-generation smartphone built to meet GrapheneOS’ strict privacy and security standards.
I wonder if a real OEM supports graphene if that would solve device attestation for things like banking apps.
I'd much rather GrapheneOS continue to get popular enough that banking apps are forced to support phones without attestation.
Re: GrapheneOS is the only Android OS providing full security patches
#234https://tbot.substack.com/p/grapheneos-new-oem-partnership > GrapheneOS has officially confirmed a major new hardware partnership—one that marks the end of its long-standing Pixel exclusivity. According to the team, work with a major Android OEM began in June and is now moving toward the development of a next-generation smartphone built to meet GrapheneOS’ strict privacy and security standards.
I wonder if a real OEM supports graphene if that would solve device attestation for things like banking apps.
Re: GrapheneOS is the only Android OS providing full security patches
#235Earlier quoted context omitted.
I don't think that's a fair comparison. OEMs have quite a lot of extra steps before releasing any build to the public. They have to pass xTS, the set of test suites required before getting certified by Google, possibly carrier certification, regulatory requirements and more depending on where the build will be released. There are "quicker" release channels for security fixes, but I don't think it's common for OEMs to…
Yep. And GrapheneOS's changes to the kernels of devices they ship are laughably small, 20-30 commits at most. I don't think they even do any basic CVE checks on any of the source code. Fuzzing, actual security analysis - all those things are done by Google.
Re: GrapheneOS is the only Android OS providing full security patches
#236Earlier quoted context omitted.
Has no one mentioned not using a smartphone as an option?
How do you run WhatsApp or Signal without a smartphone? Pretty hard. If your answer is "don't use them", then you're not living in a country where the vast majority of communications are done on WhatsApp or Signal, good for you I guess.
Re: GrapheneOS is the only Android OS providing full security patches
#237Earlier quoted context omitted.
I would not trust any of these. They are a security disaster, lacking even basic features for securing your device against tampering and hacking. There is a reason GrapheneOS is number one and a reason why they only run on Pixels (for now).
Depends on your threat model, but yes.
Re: GrapheneOS is the only Android OS providing full security patches
#238https://tbot.substack.com/p/grapheneos-new-oem-partnership > GrapheneOS has officially confirmed a major new hardware partnership—one that marks the end of its long-standing Pixel exclusivity. According to the team, work with a major Android OEM began in June and is now moving toward the development of a next-generation smartphone built to meet GrapheneOS’ strict privacy and security standards.
I wonder if a real OEM supports graphene if that would solve device attestation for things like banking apps.
Re: GrapheneOS is the only Android OS providing full security patches
#239The GrapheneOS obsession with picking a fight with everyone else is the most unfortunate part of the project.
“The reasonable man adapts himself to the world: the unreasonable one persists in trying to adapt the world to himself. Therefore all progress depends on the unreasonable man.”