Live data from Hacker News

GrapheneOS is the only Android OS providing full security patches

grapheneos.social

321–330 of 467 posts

Re: GrapheneOS is the only Android OS providing full security patches

#321

Earlier quoted context omitted.

I believe you can root GrapheneOS. It just breaks the security model, so it's not recommended to do so.

Ah, you're right: https://github.com/schnatterer/rooted-graphene I stand corrected. Still, as you say, less point in it since it breaks their security model.

> I stand corrected. Still, as you say, less point in it since it breaks their security model.

It breaks the entire point of the security model on ALL android devices. It isnt recommended on any Android distribution. It doesnt matter if its LOS or GOS

Re: GrapheneOS is the only Android OS providing full security patches

#322
post #58

You can tell it's truly secure and private because the Cellebrite leak says they can't break it (one of very few!) and some governments assume you're a drug dealer if you use it. My next phone will run GrapheneOS.

It could also just mean they haven't bothered try

Considering they mention it on their marketing materials, they definitely did bother

Re: GrapheneOS is the only Android OS providing full security patches

#323

Earlier quoted context omitted.

I guess antitrust is the keyword here. Something that is considerably weakened in today's USA.

I continue to be of the opinion that many of our economic problems could be improved with more competition. (Depending on your definition of "problem" of course. The current state of affairs is fantastically profitable some.)

Oh for sure. Why are movies scattered all over oblivion? Because there's no simple marketplace for licensing movies, it's a closed market that requires doing lots of behind-the-scenes deals. Healthcare? Only specific providers can make medical equipment, tons of red tape, opaque billing structures, insurance locked out in weird ways, etc.

To understand how healthy a market is, ask 'how easily could a brand new startup innovate in this area'. If the answer is 'not easy at all' - then that thing is going to be expensive, rent seeking, and actively distorting incentives to make itself more money.

Re: GrapheneOS is the only Android OS providing full security patches

#324

Earlier quoted context omitted.

> I'm not knowledgeable enough -- what would it take to escape the Apple/Google duopoly? At this point? Reliable emulation that can run 99% of Android apps, to provide a bridge until the platform is interesting enough for people to develop for it "natively". I think the easiest way to do that would be to run Android in a VM.

> I think the easiest way to do that would be to run Android in a VM. The problem is the critical payment and government ID apps that will never run in an Android VM because they intentionally break without hardware attestation.

Yep, otherwise, VM is effectively one of the better ( and maybe even safer ) way of trying to escape the established ecosystem.

Re: GrapheneOS is the only Android OS providing full security patches

#325
post #288

Earlier quoted context omitted.

> but still I'd like to choose my hardware and software separately interoperating via standards This is why I can’t do GrapheneOS. Pixel devices do not suit my needs (& aren’t available). 2 of the big appeals for my going Android was 1) device options 2) ability to customize (appearance, apps from other sources, root access). Google has basically done everything to prevent #2 & GrapheneOS prevents #1. …This is why I…

What kind of Linux phone setup do you have, and what kind of experience has it been? I want to make the leap sometime, but not quite there yet.

I have an Xperia with Sailfish OS. The Android app support ironically ends up what makes it usable, but the new patch isn’t released with kernel support that actually makes the IO work properly. Its own app selection is pretty small. It would be cool if all desktop Linux didn’t need an entirely new skin to work at this form factor, else I could get what I needed. I also use Nix to smooth over some of the repository shortcomings.

Re: GrapheneOS is the only Android OS providing full security patches

#326

Earlier quoted context omitted.

It could also just mean they haven't bothered try

Considering they mention it on their marketing materials, they definitely did bother

Marketing is known to lede a lot of bullshit. Celebrite saying "We tried our stuff and it didn't work" is very likely more about obscurity than focused effort. Unless you know that celebrite has been specifically hired to break into a GrapheneOS device and put as much effort into it as they do into standard Android and iOS and failed, it means nothing. It's like the old thing about MacOS 9 being more secure than Windows.

Re: GrapheneOS is the only Android OS providing full security patches

#327
post #101

Great, so this means that the only way to get an Android release that's up-to-date on security patches is a binary-only distro - either Google Pixel, or the GrapheneOS preview channel. Just wonderful. Google should know better than this, shame on the other OEMs that forced this mess.

If it's any consolation, preview builds are reproducible at the point that the embargo ends. A bit better than the definition of binary that we're used to.

https://discuss.grapheneos.org/d/27068-grapheneos-security-p...

Re: GrapheneOS is the only Android OS providing full security patches

#328

Earlier quoted context omitted.

Isn't there an emulator that can run Android apps inside any Linux distro?

No. There are a few that claim to, but none of them are actually any good. Waydroid, for instance, requires that your kernel is compiled in basically "Android mode" (e.g. binder enabled).

> Waydroid, for instance, requires that your kernel is compiled in basically "Android mode" (e.g. binder enabled).

Waydroid needs you to have a single kernel module, which is in mainline Linux and just happens to be disabled in many desktop builds. That hardly makes it an "Android mode" kernel, and I certainly see no reason why it should make the system no good.

Re: GrapheneOS is the only Android OS providing full security patches

#329
post #113

I notice my battery life is much better switching to graphine from the stock google rom.

Yes, but keep in mind individual apps like Signal need to run in the background at all times if you want to receive timely notifications on Graphene, because they cannot rely on the Google backend for that. If you have enough such apps, you may well find that battery life is shorter than on the stock OS.

https://unifiedpush.org/ fixes this for a number of apps. Self-hostable.

Battery life is still better than stock in my case, and it's just as reliable as sandboxed Play. Highly recommend.

Re: GrapheneOS is the only Android OS providing full security patches

#330

Earlier quoted context omitted.

Ah, you're right: https://github.com/schnatterer/rooted-graphene I stand corrected. Still, as you say, less point in it since it breaks their security model.

> I stand corrected. Still, as you say, less point in it since it breaks their security model. It breaks the entire point of the security model on ALL android devices. It isnt recommended on any Android distribution. It doesnt matter if its LOS or GOS

Honestly don't care for the idea of a system secured from its owner. If I wanted to use iOS, I would.
Post reply on HN