Earlier quoted context omitted.
I had to replace a credit card yesterday. Part of the default flow involves the call center sending a notification to your app. When I told them my android version was too old, it took them twenty minutes to find out they could instead send a text message. That text message sends you to a photo-and-id verification service, but that's another issue. Soon, there won't even be an alternative flow. There are a lot of pla…
Are you sure? This seems like a forum with a lot of early adopters and a lot of late adopters still use browsers, email, text messages. Like, let me guess that your credit cars isn't capitol one. Not that it should be, but that would be more "normie".
Devices with GrapheneOS support should be available in 2027
391–400 of 444 posts
Re: Devices with GrapheneOS support should be available in 2027
#392Let me know when you're trying to eliminate having a Google or Apple account to do anything instead of making it less intolerable/invasive to have one.
Re: Devices with GrapheneOS support should be available in 2027
#393I've never really understood why we chase Android-alikes on mobile platforms instead of trying to build on mainstream Linux. I know some folks in the nix community (nix-on-droid and other projects) have tried to bring us closer to this, but projects like Graphene seem to have a lot of traction.
Your point is valid for every flavor of Android except GrapheneOS. GrapheneOS’ security model makes that of desktop Linux look like a joke. This is an objective analysis based on x86 security, GrapheneOS hardening (including isolation and hardened mem allocator), Pixel hardware security.
Re: Devices with GrapheneOS support should be available in 2027
#394Earlier quoted context omitted.
Your point is valid for every flavor of Android except GrapheneOS. GrapheneOS’ security model makes that of desktop Linux look like a joke. This is an objective analysis based on x86 security, GrapheneOS hardening (including isolation and hardened mem allocator), Pixel hardware security.
Even AOSP has selinux enabled by default with very comprehensive and scoped policies. That, along with app isolation and permission system, already leaves desktop Linux far, far in the dust on security.
It has much better adoption of modern exploit protections and far better testing with sanitizers for both the kernel and userspace. It enables us to do even better because most of the memory corruption bugs caught by MTE are resolved. We do still need to resolve more, but it would be far more impractical for us to do it on the desktop.
Android uses SELinux for both whole system MAC and MLS policies with deep OS integration. It uses it for a massive amount of kernel attack surface reduction with allowlists for socket protocols, devices, ioctl commands and other functionality. It's far different from the traditional targeted approach used by desktops or even rare use of whole system SELinux for desktops/servers. It's nearly a completely different thing in practice. The OS has it deeply integrated in userspace for enforcement beyond in the kernel and it's developed around it. It's the main basis for the app sandbox and a lot of other isolation in the OS. OS processes are specifically split up and have IPC set up in a way that they can be contained well with it.
The mandatory app sandbox with yearly backwards incompatible privacy and security improvements as part of new target SDK versions is the most important difference. It's the basis for GrapheneOS being able to do much better. Having the infrastructure it already has available means we can add our features such as Contact Scopes, Storage Scopes and our Sensors toggle on top. We plan to add a lot more, but there are also the yearly improvements we get in the baseline such as how Camera, Microphone and Location have supported one-time grants for years, can only be used while apps are in use once granted (with Location have an extra layer of background opt-in) and precise vs. coarse location.
Re: Devices with GrapheneOS support should be available in 2027
#395Earlier quoted context omitted.
All the existing apps are on Android and iOS. Graphene lets you run them. You can't have a bank account on a Linux phone* because they won't let you, but you can on Android including on Graphene. * before replying snarkily that Android is Linux, please take a long walk off a short pier, thanks
[flagged]
https://privsec.dev/posts/android/banking-applications-compa...
Re: Devices with GrapheneOS support should be available in 2027
#396Earlier quoted context omitted.
I knew it would be their higher end devices but I really wish they would have put it on their lower end as well. I have a Moto G running LineageOS and it's my favorite phone ever. The ability to have my 800GB of music synced to a sdcard is something I'm loath to give up.
I had Motorola Moto Gs all from the first generation to the fifth or sixth, cheap and worked great, had everything one could wish for in a daily smartphone. But eventually they too started growing in size, and so I got an iPhone 12 Mini instead, that I still use to this day. I'm currently hoping I'll find something released in 2025+ that is the same size as the Mini or the old Moto Gs, but they are nowhere to be foun…
Re: Devices with GrapheneOS support should be available in 2027
#397I've never really understood why we chase Android-alikes on mobile platforms instead of trying to build on mainstream Linux. I know some folks in the nix community (nix-on-droid and other projects) have tried to bring us closer to this, but projects like Graphene seem to have a lot of traction.
GOS is broadly compatible with most phone use cases out of the box--chat, mail, browsing. A Google Play profile lets me use almost all apps (including my bank apps, but I understand that's not true for everyone). In principle I agree about a Linux phone, but the gaps are much greater. I am also sympathetic to the GOS team's arguments that sandboxing on Android is better, and important on a device that allows control…
We provided a much more detailed reply at https://news.ycombinator.com/item?id=49364220.
Re: Devices with GrapheneOS support should be available in 2027
#398I've never really understood why we chase Android-alikes on mobile platforms instead of trying to build on mainstream Linux. I know some folks in the nix community (nix-on-droid and other projects) have tried to bring us closer to this, but projects like Graphene seem to have a lot of traction.
Like others have said, it comes down to apps mostly. But there is also the fact that Google and others have spent more than a decade optimizing the OS for appliances. Android was built from the ground up for mobile devices and handles things like background apps, notifications, and charging as expected on a phone. All of this could be ported or rebuilt, but the work has already been done for Android and billions of d…
Re: Devices with GrapheneOS support should be available in 2027
#399I've never really understood why we chase Android-alikes on mobile platforms instead of trying to build on mainstream Linux. I know some folks in the nix community (nix-on-droid and other projects) have tried to bring us closer to this, but projects like Graphene seem to have a lot of traction.
One word: ecosystem. Phones are useless bricks without an ecosystem. This is why we only have 2 operating systems for portable devices when we used to have more than twice the amount.
Re: Devices with GrapheneOS support should be available in 2027
#400I bought the Moto signature a month ago , I already assumed it prolly won't support graphene, since some of the previous replies on X indicate that the graphene team requires full hardware compliance with their requirements, and the Signature apparently is not compliant yet. Anyway I ended up buying a really good smartphone.. just not a graphene supported haha :( Also this is really great collab from moto & graphene…
They didn't "ban" them, but they did enable some attestation feature that effectively "bans" anything that isn't Google Android. Which still makes you wonder why Volkswagen is so keen on alienating what little is left of their customer base with completely stupid security theater.