Live data from Hacker News

Devices with GrapheneOS support should be available in 2027

grapheneos.social

421–430 of 444 posts

Re: Devices with GrapheneOS support should be available in 2027

#421
post #420

Earlier quoted context omitted.

It's fair to say they banned GrapheneOS but they didn't only ban GrapheneOS. It's very rare for apps to specifically ban GrapheneOS but Revolut uses an SDK which tried to do it. We worked around it and Revolut works on GrapheneOS since January 2025 but not for lack of trying to ban it by an SDK they use and it sometimes blocks our users.

[flagged]

> I appreciate the truth more than narratives

It is the truth.

> Volkswagen did not ban you.

They banned GrapheneOS and other non-Google certified operating systems.

> Volkswagen probably don't even know that you exist.

They're aware of the existence of GrapheneOS. They've received immense pushback for banning it. They have customer support templates for responding to GrapheneOS user complaints.

> because like this it's just storytelling

Revolut shipped a check for ro.build.user being set to the string "grapheneos" resulting in using the app being blocked. They also banned the yellow verified boot state at the same time but quite notably did not ban the orange verified boot state. This was our release working around it to get the app working again:

https://grapheneos.org/releases#2025012600

We know what happened and what we had to do to work around it. It's verifiable that this was shipped by Revolut.

> I know of course that uncompromisingly maintaining something that challenges the status quo needs stories to keep the drive alive.

It's you who is pushing a false narrative.

> Idk man I think you people need grounding. That, or I just need to stop seeing the humanity in you, start seeing you as a software vending machine and applaud your (hate to say it, but) delusions, as those lead to you working harder for stuff that is useful to me.

You're not welcome to contact us again after this.

Re: Devices with GrapheneOS support should be available in 2027

#422
post #420

Earlier quoted context omitted.

[flagged]

> I appreciate the truth more than narratives It is the truth. > Volkswagen did not ban you. They banned GrapheneOS and other non-Google certified operating systems. > Volkswagen probably don't even know that you exist. They're aware of the existence of GrapheneOS. They've received immense pushback for banning it. They have customer support templates for responding to GrapheneOS user complaints. > because like this i…

[flagged]

Re: Devices with GrapheneOS support should be available in 2027

#423
post #370

Earlier quoted context omitted.

> We would prefer the Play Integrity API being banned by regulators but this is good enough for now. Unfortunately, the EU is currently developing their age-verification-app, and it mandates hardware attestation[1], and it seems that their reference implement those requirements using Play Integrity[2]. [1]: https://news.ycombinator.com/item?id=49148128 [2]: https://github.com/eu-digital-identity-wallet/av-doc-technic…

Our growing userbase and Motorola partnership will give us a lot of sway to get apps to allow GrapheneOS. We can't realistically convince banks, governments and other companies to stop requiring attestation. We can realistically convince most apps to allow GrapheneOS via hardware attestation since it supports doing it via the standard Android key attestation API. We cannot realistically convince apps to not adopt att…

> https://grapheneos.org/articles/attestation-compatibility-gu... is our guide for app developers on permitting GrapheneOS via hardware attestation.

It's not a very good guide, frankly. It's basically a wall of text without clear instructions on what to do, besides "look at the examples Google gave". And even looking at Google's examples, there are no examples or explanations that tell me how to download the list of allowed signatures, and what should I do with the Json schema.

Re: Devices with GrapheneOS support should be available in 2027

#424

Earlier quoted context omitted.

Waydroid disables most of the Android privacy and security model through not having functional SELinux. SELinux is not simply an additional layer of security on Android but rather deeply integrated into the OS. The app sandbox and isolation throughout the OS are heavily built on SELinux. It also heavily depends on it for kernel attack surface reduction combined with internal kernel hardening via exploit protections.…

> The approach used by desktop operating systems with TPMs is awful and makes security worse in a lot of ways rather than better. It's not at all the same thing, similarly to how what the desktop world calls secure boot is not a serious or complete implementation of it and doesn't provide nearly any useful security properties to end users unlike iOS or AOSP. Interesting. Could you elaborate? I always thought that Sec…

The standard UEFI Secure Boot used with traditional Windows and traditional desktop Linux is an incomplete and insecure implementation of secure boot. It doesn't verify the vast majority of the OS, nearly always lacks an unbroken chain of trust from the hardware, does not verify all of the firmware and lacks downgrade protection for both most of the firmware and the OS. In the typical setup, it trusts an enormous number of keys and software. It barely provides any useful security properties.

Secure boot was widely used as a term prior to the UEFI usage of the term including many much more meaningful implementations. The term verified boot refers to the same concept but avoids it being confused with solely verifying a late stage bootloader and OS kernel from UEFI firmware.

Re: Devices with GrapheneOS support should be available in 2027

#426

Earlier quoted context omitted.

No, it doesn't come anywhere close to the privacy or security provided by AOSP. You could be dividing up your projects into highly sandboxed environments on Android too. It has support for running multiple hardware accelerated virtual machines running desktop Linux and it wouldn't be that hard to support creating those with NixOS and other distributions instead of only the standard the Debian images provided by Andro…

Yes, it does, at least for my threat model. AOSP (with Google Play Services, which are needed to do much useful) mean that a whole lot of closed source system binaries are running with full access to all my data and constantly phoning home to Google.

>at least for my threat model

That is fine but obviously we are talking about threat model in comparison to each other.

>Google Play Services, which are needed

They are "needed" if you want to use other closed source apps that rely on play service feature. If you don't want/use closed source apps there is no reason to use Google play services at all, that's why they are optional.

>running with full access to all my data

GrapheneOS sandboxes play services specifically to run with user permission instead of system and can be used in a completely different isolated profile for your other private user data.

NixOS by itself does nothing to increase security outside of the supply chain. There is for example no default application sandboxing, Mandatory access control or hardened memory allocation (software or hardware). Just to name the most basic security feature.

https://grapheneos.org/features

Re: Devices with GrapheneOS support should be available in 2027

#427
Honest question, because I'm not part of that scene (yet) at all:

I seem to remember that I have read mentions of GrapheneOS for years now, but does this news mean it has been practically vaporware the whole time? Google making Android a walled garden just as bad as iOS shows how important projects like this and its siblings are. I'm impatiently waiting for more Jolla phones to become available, but something like GrapheneOS might be a viable alternative.

Re: Devices with GrapheneOS support should be available in 2027

#428

Specific devices: >At the time of writing, within ~12 months, in 2027, the 2027 Signature, Razr fold, and Razr flip will meet the hardware security requirements and should have official GrapheneOS support. Motorola is currently porting GrapheneOS to their devices. https://news.ycombinator.com/item?id=49038982

I knew it would be their higher end devices but I really wish they would have put it on their lower end as well. I have a Moto G running LineageOS and it's my favorite phone ever. The ability to have my 800GB of music synced to a sdcard is something I'm loath to give up.

[deleted]

Re: Devices with GrapheneOS support should be available in 2027

#429
I wonder how Google will react if more and more mobile phones with GrapheneOS appear on the market. I suspect they will block further adoption by throwing up all kinds of hurdles.

They could make more parts of Android closed source, even critical ones without which you cannot realistically build an Android phone. It could, however, trigger anti-trust lawsuits, but my guess is they're willing to risk that. I mean, worst-case they only have to rollback to what they already had and maybe pay a fine.

Re: Devices with GrapheneOS support should be available in 2027

#430

This is very exciting. I have been an iPhone user for the last 8 years. I am entirely in Apple's ecosystem. I would legitimately change my phone (+watch +headphones) for a vertical foldable (like razr) phone running graphene OS. I don't think Apple is releasing a vertical foldable or even a modern smaller phone. One can only hope.

To get you started on switching the ecosystem, which is a pain. Here's some of what I landed on while moving from iOS to GrapheneOS.

Ente Photos

NotesNook

Signal (I use Molly but it's only on Android)

Bitwarden

Proton

Post reply on HN