Live data from Hacker News

GrapheneOS is the only Android OS providing full security patches

grapheneos.social

411–420 of 467 posts

Re: GrapheneOS is the only Android OS providing full security patches

#411
post #404
post #376

Earlier quoted context omitted.

Governments all over the world try to support their economies. It's not just a Chinese thing. How much does the western world invest in LLMs? But for some reason, we only call it "cheating" when China does it and is more successful than us.

What an outburst lol. I didnt call it cheating. Its just as worth noting as when it happens elsewhere. Perhaps you should stop reading what isnt there.

Where did I say you called it cheating? From where I stand, you're reading what isn't there.

Re: GrapheneOS is the only Android OS providing full security patches

#412
post #377

Earlier quoted context omitted.

"You don't need to connect to the Internet at all". How is that an answer to someone saying that they don't see how they can stay connected without having a smartphone?

Well honestly that's part of the flip phone lifestyle, if someone doesn't want to call me, that's fine, they can send me an email. We don't have to bring Google or Apple into this relationship, it's a choice people make because the prefer texting and being available to everyone they ever met 24/7

> We don't have to bring Google or Apple into this relationship, it's a choice people make because the prefer texting and being available to everyone they ever met 24/7

You're changing the discussion now.

The original point is this: Given that people want to be able to text with their friends in what is perceived as a normal way, how can they do it without a smartphone?

If you change the rules ("Given that people are fine being disconnected"), of course it changes everything.

Re: GrapheneOS is the only Android OS providing full security patches

#413

Earlier quoted context omitted.

I would not trust any of these. They are a security disaster, lacking even basic features for securing your device against tampering and hacking. There is a reason GrapheneOS is number one and a reason why they only run on Pixels (for now).

> security disaster, lacking even basic features for securing your device against tampering and hacking Indeed the GrapheneOS community is known for attacking the GNU/Linux mobile with false claims, https://news.ycombinator.com/item?id=45562484 . Security is a meaningless word without defining a threat model. Try to defend your GrapheneOS against Google, especially these two problems: https://news.ycombinator.com/ite…

GrapheneOS doesnt really proactively attack GNU/Linux. What happens is that there are posts on the internet about GrapheneOS or mentioning GrapheneOS in which or under which completely wrong comparisons between GrapheneOS and GNU/Linux get posted. It makes sense that you care to clarify or correct if you spot people are talking about your project and are (intentionally or unintentionally) spreading wrong information about it by making comparisons based on misconceptions or falsehoods.

The thing you link about restricting network traffic doesnt make much sense. GrapheneOS has a proper network permission which other OSes dont have. The outbound traffic restrictions to certain destinations which are being referred to are just a bad approach. You can send the traffic to one server and just process it there and send out to other servers.

You also say :

> Also, if I explicitly don't trust Google with anything, GOS is extraordinarily insecure for me until a new vendor

If thats the case, dont opt for GNU/Linux either given the large code contributions made by Google. Also avoid any software built with LLVM, written in Go, written in Flutter, using Angular, ...

The two "problems" you link arent really huge security issues. How is GrapheneOS having access to the embargoed patches and being able to ship them a security issue? Also the planned sideloading restrictions dont even apply to GrapheneOS. It would only apply to certified OS that license Google Mobile Services. Also, that isnt even a security issue. Its a freedom issue.

Re: GrapheneOS is the only Android OS providing full security patches

#414
post #288

Earlier quoted context omitted.

What kind of Linux phone setup do you have, and what kind of experience has it been? I want to make the leap sometime, but not quite there yet.

I have an Xperia with Sailfish OS. The Android app support ironically ends up what makes it usable, but the new patch isn’t released with kernel support that actually makes the IO work properly. Its own app selection is pretty small. It would be cool if all desktop Linux didn’t need an entirely new skin to work at this form factor, else I could get what I needed. I also use Nix to smooth over some of the repository s…

Sailfish OS just takes the wrong approach, to be honest. It makes more sense to have the more secure OS at the host (Android) and the less secure as a guest for compatability (traditional Linux distro). Its also problematic that the app compatability delivered via the Anseood support uses an outdated Android version etc.

Re: GrapheneOS is the only Android OS providing full security patches

#415
post #406

The GrapheneOS obsession with picking a fight with everyone else is the most unfortunate part of the project.

That is also my feeling, at least from a part of the GrapheneOS community. I have seen them despising and bullying /e/OS, Debian, F-Droid, the Linux kernel... Too bad for this project, that is amazing, to have such toxic folks. Open source communities should help each other, and work together, not fight.

You can't equate actions from a part of the community with actions by the project. If you would see any bigotry by a GrapheneOS community member, please report it to the moderators. Bullying, toxcity and misinfo are not allowed. Action will be taken.

I havent noticed a lot of that in the community myself, in which im very active. Its exceptional in my eyes. Common though is technical criticism on other projects when people ask advice about it or want a comparison with alternative. Also common is people being fed up by harassment by other projects.

The founder of /e/OS repeatdely attacks GrapheneOS in random internet threads that are only mention GrapheneOS. This contrast with the approach of GrapheneOS where they will only do a comparison with /e/OS in reponse to posts where both are mentioned and compared by others. Or, in reponse of wrong comparisons in the media or harassment (personal attacks etc.) stemming from them.

F-Droid does also have some maintainers that engaged in personal attacks against the GOS founder. And anyway what do you expect the project to do if people ask whether to get apps from Play Store or F-Droid? Pretend there is no technical security difference? If people ask questions, the project and community try to inform.

There is big conflict with Debian or Linux kernel at all. They also dont mismarket themselves or spread misinfo about GrapheneOS. They are concerned though that both heavily used projects lack a security focus.

Re: GrapheneOS is the only Android OS providing full security patches

#416

Earlier quoted context omitted.

No, it doesn't. It obeys Google's long-term development strategy for the OS. Google and privacy are absolutely incompatible. See: https://news.ycombinator.com/item?id=29502439

Google has implemented lots of privacy and security features in AOSP over time. The app sandbox and permission model has evolved a lot, in a good direction. The codebase is also modernized with the increasing adoption of memory safe code. At least Google seemes to have a thought out development strategy to enhance security and privacy, contrary to the projects you mentioned elsewhere in this Hacker News thread. Also,…

Every reasonable, independent organization confirms that Manifest V3 is the end of privacy for Chrom(ium) users, e.g.,

https://news.ycombinator.com/item?id=29502439

https://news.ycombinator.com/item?id=41871873

https://news.ycombinator.com/item?id=44543660

> It restricts and controls the access of extensions much more.

You mean, it restricts users even more and gives to websites the freedom to track you? I won't engage in further discussion with you, you're just trolling.

Re: GrapheneOS is the only Android OS providing full security patches

#417
post #363

Earlier quoted context omitted.

You're making libelous claims without evidence while falsely claiming that I'm doing it. This typically goes along with baseless claims that I'm insane, delusional, schizophrenic, etc. with links to extraordinarily dishonest content filled with obvious fabrications from a couple serial harassers. One of those serial harassers has an identity verified Kiwi Farms account and was the one who involved them in targeting m…

Rossman only ever commented on kiwi farms on a thread about himself. You are lying again, confirming the words of the parent comment. And deserved criticism is not harassment.

People in that thread mention a GrapheneOS project member together with the worst of bigotry, slurs and death wishes. And Rossman just decides to keep replying and talking in that thread. Like its worth engaging with these people and they deserve attention.

Re: GrapheneOS is the only Android OS providing full security patches

#418
post #92

Earlier quoted context omitted.

> I'm not knowledgeable enough -- what would it take to escape the Apple/Google duopoly? At this point? Reliable emulation that can run 99% of Android apps, to provide a bridge until the platform is interesting enough for people to develop for it "natively". I think the easiest way to do that would be to run Android in a VM.

Similar to how Valve is managing the transition from Windows to Linux.

it'd be cool if they made Steam Phone.. it could be to Steam Deck as iPhone was to iPod Touch.

Re: GrapheneOS is the only Android OS providing full security patches

#420
post #304

There are millions if not billions of older devices. What we need is an OS that support those.

That would become a meaningless effort security wise as time goes on. The drivers and firmware will become outdated. OS updates are necessary but not sufficient. I get the e-waste / enviromental argument, and I think its very warranted to criticize OEMs for not providing long support times in the past. Apple and Google do this well in recent years, luckily.
Post reply on HN