Live data from Hacker News

GrapheneOS is the only Android OS providing full security patches

grapheneos.social

401–410 of 467 posts

Re: GrapheneOS is the only Android OS providing full security patches

#401
post #12

Earlier quoted context omitted.

They have different goals: GrapheneOS wants to make a FOSS Android with the security model that makes it hard for any bad party to break into the phone. LineageOS wants to make a FOSS Android that respects user's privacy first and foremost - it implements security as best as it can but the level of security protections differs on different supported devices. Good news is that if you have a boot passphrase, it's secur…

that is simply wrong. GrapheneOS is both in terms of security and privacy the best but currently only supports pixel phones. LineageOS is trying to support as many devices as possible still with lot of google connections and missing security updates. >Good news is that if you have a boot passphrase, it's security is somewhat close to GrapheneOS its not anywhere close https://grapheneos.org/features

This is the correct response. I use both GrapheneOS and LineageOS. But LineageOS focus is on delivering newer versions of Android to many phones abandoned by their OEM. GOS exclusively focuses on security and privacy. If you want a reasonably secure phone but don't want Google or Apple inside your device, your best bet is GOS.

Re: GrapheneOS is the only Android OS providing full security patches

#402

Earlier quoted context omitted.

Oh that's one of the best news in the smartphone world in a long time. It's impossible to escape the Apple/Google duopoly but at least GrapheneOS makes the most out of Android regarding privacy. I still wish we could get some kind of low resource, stable and mature Android clone instead of Google needlessly increasing complexity but this will over time break app compatibility (Google will make sure of it) Edit: I do…

Pixel phones currently have the additional benefit of a full Debian OS running via AVP. This is (imo) on par with or better than having Termux on a rooted device. It's still fairly off-the radar which makes it a really good time to be exploring it's uses.

I agree, it has been lots of fun testing around in the KVM. Recently a GrapheneOS update even included the Button to attach to the "screen" of the VM. It also has GPU passthrough iirc?

When i have more freetime during the holidays i will test further. I especially want to try how it works when i combine stuff like steam + fex + Proton or run other GPU stuff

Re: GrapheneOS is the only Android OS providing full security patches

#403
post #363

Earlier quoted context omitted.

It doesn't seem to be the entire project, just one dev (afaik) that's quite outspoken and does make accusations that they don't always seem to back with evidence. Also insofar as the actual "product" remains completely untouched by any spats it shouldn't be a dealbreaker for anyone wanting to use GOS, but of course it isn't ideal to have any drama attached.

You're making libelous claims without evidence while falsely claiming that I'm doing it. This typically goes along with baseless claims that I'm insane, delusional, schizophrenic, etc. with links to extraordinarily dishonest content filled with obvious fabrications from a couple serial harassers. One of those serial harassers has an identity verified Kiwi Farms account and was the one who involved them in targeting m…

Rossman only ever commented on kiwi farms on a thread about himself. You are lying again, confirming the words of the parent comment.

And deserved criticism is not harassment.

Re: GrapheneOS is the only Android OS providing full security patches

#404
post #376
post #301

Earlier quoted context omitted.

Equally lets not forget that china sees this as a key strategic necessity for a forced reunification attempt on taiwan, both for national security and the ability to produce chips solo. Two things can be true. They can have great engineers and government money. Theyre not mutually exclusive.

Governments all over the world try to support their economies. It's not just a Chinese thing. How much does the western world invest in LLMs? But for some reason, we only call it "cheating" when China does it and is more successful than us.

What an outburst lol. I didnt call it cheating. Its just as worth noting as when it happens elsewhere. Perhaps you should stop reading what isnt there.

Re: GrapheneOS is the only Android OS providing full security patches

#405

Earlier quoted context omitted.

> Any one of us here could learn the skills to design a smartphone. Unless you're Fabrice Bellard who literally created a 4G softmodem - no. It takes a whole lot of people (or, again, one genius Fabrice Bellard clone) to design a smartphone. You'll need AT THE VERY LEAST: 1) a SoC that has reasonably open device drivers and specifications - without that, all attempts are moot 2) a hardware engineer to deal with the P…

or you could slap a GSM shield on a Raspberry Pi.

As I wrote: that's a MVP, not something you can sell to anyone less nerdy than Richard Stallman, and it's based off of the work of a lot of the people I just spent 58 minutes to think of and write down.

Re: GrapheneOS is the only Android OS providing full security patches

#406

The GrapheneOS obsession with picking a fight with everyone else is the most unfortunate part of the project.

That is also my feeling, at least from a part of the GrapheneOS community. I have seen them despising and bullying /e/OS, Debian, F-Droid, the Linux kernel... Too bad for this project, that is amazing, to have such toxic folks.

Open source communities should help each other, and work together, not fight.

Re: GrapheneOS is the only Android OS providing full security patches

#407

Earlier quoted context omitted.

> I think the easiest way to do that would be to run Android in a VM. The problem is the critical payment and government ID apps that will never run in an Android VM because they intentionally break without hardware attestation.

Isn't this spoofable with root access?

The private key used for attestation is stored in the secure element hardware, which runs its own OS, completely inaccessible to the main hardware's OS, even with root.

Some apps don't actually check the attestation signatures, so they could be spoofed for now, but if spoofing became common, apps would just get strict about checking attestation.

Re: GrapheneOS is the only Android OS providing full security patches

#408

Earlier quoted context omitted.

Not having root prevents me from taking proper backups that include app data, it prevents me from using Aegis to import TOTP codes from Authy. I get that on some abstract level it is more "secure" from any malicious software that might find its way onto the device, but the practical upshot is largely obstructing the user from using the system. Have you ever had to work on a locked-down machine at an office? I don't n…

> Not having root prevents me from taking proper backups that include app data You can handle this better without root. GrapheneOS includes SeedVault per default for example. > Have you ever had to work on a locked-down machine at an office? Fortunately I'm the admin at work :) > I don't need Google or Graphene to play IT department for me. GrapheneOS is security+privacy first and "enabling root" compromises on this.…

As I'm sure you're aware, SeedVault won't backup app data if the app authors have opted out of it. Again, this is an example of a system serving masters other than the device's owner.

Re: GrapheneOS is the only Android OS providing full security patches

#409

Earlier quoted context omitted.

> I'm not knowledgeable enough -- what would it take to escape the Apple/Google duopoly? At this point? Reliable emulation that can run 99% of Android apps, to provide a bridge until the platform is interesting enough for people to develop for it "natively". I think the easiest way to do that would be to run Android in a VM.

Has no one mentioned not using a smartphone as an option?

Doesn't really make sense in a conversation about security (the HN post was referencing security).

Traditional desktop OSes (Windows, MacOS, traditional Linux distros) are just at an entirely different level than modern mobile OSes (Android OSes, iOS) and ChromeOS. They also often run on less secure hardware, especially compared to a Pixel.

Re: GrapheneOS is the only Android OS providing full security patches

#410

Earlier quoted context omitted.

[flagged]

No, it doesn't. It obeys Google's long-term development strategy for the OS. Google and privacy are absolutely incompatible. See: https://news.ycombinator.com/item?id=29502439

Google has implemented lots of privacy and security features in AOSP over time. The app sandbox and permission model has evolved a lot, in a good direction. The codebase is also modernized with the increasing adoption of memory safe code. At least Google seemes to have a thought out development strategy to enhance security and privacy, contrary to the projects you mentioned elsewhere in this Hacker News thread.

Also, what you link doesnt prove what you think it does. Manifest V3 is a very good thing for privacy and security. It restricts and controls the access of extensions much more. With MV2 you have much less control over your data.

Post reply on HN