Live data from Hacker News

CalyxOS – De-Googled Android Alternative

calyxos.org

441–450 of 496 posts

Re: CalyxOS – De-Googled Android Alternative

#441
post #395

Earlier quoted context omitted.

Please look at the comments being replied to from that user in this thread. They're spreading misinformation about GrapheneOS in order to promote CalyxOS. This isn't something isolated but rather than community is highly hostile towards our project and has been heavily involved in harassment of our developers, raids on our community and coordinated spreading of misinformation. Every time GrapheneOS or CalyxOS is ment…

> has been heavily involved in harassment of our developers, raids on our community and coordinated spreading of misinformation I'd be interested to see how you draw this conclusion. I have been in the CalyxOS rooms for quite a long time and have never seen anything of the sort. In fact, when GrapheneOS is mentioned, users are told to change the topic.

People can see for themselves the misinformation being regularly spread about GrapheneOS by the CalyxOS community whenever either CalyxOS or GrapheneOS is brought up. The raids on our channels are a well known fact and those people are openly welcomed in the CalyxOS rooms, even those who have publicly told me to kill myself on multiple occasions. Nick himself has been heavily involved in this behavior. I don't think someone who is involved in the community perpetrating these attacks is a good source on what has been happening. He justifies his support for these people by saying they have an open channel with free speech.

> In fact, when GrapheneOS is mentioned, users are told to change the topic.

Yes, people get banned when they defend GrapheneOS from attacks. Nothing is done when they spread misinformation about it as long as they don't do it too blatantly. Action is quickly taken if someone there tries to counter it.

Re: CalyxOS – De-Googled Android Alternative

#442
post #318

Earlier quoted context omitted.

Yes, they do, and GrapheneOS is heavily focused on both. The purpose of the project and what it provides is being heavily misrepresented by the comment above. GrapheneOS treats bypasses of privacy features as security vulnerabilities. It offers substantial privacy advantages of CalyxOS and doesn't come with the privacy drawbacks it introduces. See https://news.ycombinator.com/item?id=28095033 (above) for a more in-de…

Disclaimer: strcat is the GrapheneOS developer.

Disclaimer: tentacleuno is a member of a community engaged in harassment and bullying.

GrapheneOS has a development team with a dozen developers and several of those are having their work funded. It's not a single person project. Please stop spreading your malicious talking points.

Re: CalyxOS – De-Googled Android Alternative

#443
post #323
post #82

Earlier quoted context omitted.

Calyx has more focus on functionality and privacy rather than security. On Graphene, security is always priority #1. For example: Calyx provides MicroG. This means you can talk to Google Play services, though in a better, more privacy-conscious way. MicroG is an open implentation of Google Play Services. However, MicroG requires signature spoofing: You need to install a fake Google certificate so that it can trick of…

> Calyx has more focus on functionality and privacy rather than security. That's not true. GrapheneOS is heavily focused on privacy and offers much better privacy than CalyxOS. See https://grapheneos.org/features for the privacy and security features offered beyond AOSP. Unlike CalyxOS, we aren't listing AOSP features as our own. CalyxOS has a leaky firewall which apps can bypass and a leaky VPN tethering implementat…

> CalyxOS has a leaky firewall which apps can bypass and a leaky VPN tethering implementation.

We're working on fixing the one bypass. I don't know what you mean by leaky VPN tethering implementation.

We have a patch (from LineageOS) that allows tethered devices to connect over the VPN. By default in AOSP a tethered device ignores the VPN.

Wouldn't this be the opposite of leaky? It prevents leaks, especially when you have always-on VPN enabled.

> GrapheneOS has a Network toggle without those leaks and prefers the approach of fine-grained VPNs rather than using the same tunnel for everything.

We evaluated the network toggle and found it to cause crashes in apps when the permission got taken away from them unexpectedly, which is why we've gone with the solely network-level implementation.

We also do not have anything that'd make you think 'use the same tunnel for everything'. Multiple users work just fine, and in fact we now have a built-in work profile feature which lets you run another VPN in that (since that's how Android works) out of the box.

> CalyxOS includes a lot more proprietary services (Google, WhatsApp, etc.)

We do not include any proprietary services. We have microG which is open source, and the WhatsApp integration is done in open source code in the Dialer, it does not rely on anything proprietary.

In fact, you're the one who's brought up your play services approach which involves running the proprietary binary. Don't you see the irony?

Re: CalyxOS – De-Googled Android Alternative

#444

The trouble I have with AOSP of all flavors isn't lack of Google Services, it's lack of access to the app store. I can do fine without Google Services, but I occasionally need an app that's just not available on F-Droid, and Google is doing their level best to make it harder to get APKs any other way. You used to be able to download them from the store; no longer possible. They've announced some other package format,…

You can access and download apps from Google Play Store with Aurora Store. https://gitlab.com/AuroraOSS/AuroraStore#aurora-store-a-goog... > Google is doing their level best to make it harder to get APKs any other way. You used to be able to download them from the store; no longer possible. They are making it easier with Android 12 by letting third-party stores do automatic updates without user interaction, not harde…

I had no idea about Aurora Store, this changes things for me. Thanks!

Re: CalyxOS – De-Googled Android Alternative

#445
post #436
post #321

Earlier quoted context omitted.

GrapheneOS doesn't ship integration of proprietary services like CalyxOS, whether that's WhatsApp or Google services. GrapheneOS does have https://grapheneos.org/usage#sandboxed-play-services providing a way to use Play services in a sandbox with zero special privileges. This doesn't provide Play with any access beyond what it has in the client libraries within apps using it. Many of those client libraries aren't sim…

I did not want to get into this, but you're simply spread falsehoods. > GrapheneOS doesn't ship integration of proprietary services like CalyxOS, whether that's WhatsApp or Google services. We do not ship anything proprietary. We ship microG, which is "A free-as-in-freedom re-implementation of Google’s proprietary Android user space apps and libraries." - see https://microg.org/ We ship an integration with WhatsApp i…

> I did not want to get into this, but you're simply spread falsehoods.

I'm not spreading any falsehoods.

> We do not ship anything proprietary.

You ship integration of proprietary services including Google services and WhatsApp. You provide them with privileged integration unavailable to other apps.

> We ship microG, which is "A free-as-in-freedom re-implementation of Google’s proprietary Android user space apps and libraries." - see https://microg.org/

i.e. an implementation of proprietary Google services.

> We ship an integration with WhatsApp in the Dialer, which is entirely open source code. It is based on the existing contacts mechanism (anyone who has WhatsApp or Signal on any Android will see entries for those in the Contacts app - that is what we expose to the Dialer to make it easy to use those to make end-to-end encrypted calls.

i.e. integration of proprietary services into the OS in a way that isn't available to other apps.

> In fact, you're the one who's promoting your approach of being able to run the proprietary Play Services - and yet you say you don't ship integration of proprietary services. Which is it?

GrapheneOS does not include any form of Play services and has no support for the OS using it. If a user installs Play services, the OS detects it and intercepts the attempts it makes to use privileged APIs and instead returns placeholder data.

With microG, the Play services code is still present in each app using it. microG is an additional trusted party, not implementing the same level of transport security or other security checks and does not avoid trusting the Play services code to exactly the same extent.

> You can't ship Play Services legally anyway.

Not actually true. Do you claim that stuff like firmware cannot be shipped too?

> Aurora Store does not get unattended installation permission, it never has. It can only update installed apps, which is what Google is allowing in Android 12.

No, they're allowing it in a more secure, restricted way rather than what is implemented in CalyxOS. Look at the list of requirements for an unattended app update via the Android 12 API.

> F-Droid Privileged Extension is extended, and both that and F-Droid have received security audits in the past which haven't found issues - and the Privileged Extension itself hasn't changed much since then. We're very careful about making any changes there.

Shallow security audits in the past is meaningless. F-Droid is an API 25 app (Android 7.1) with a a metadata signing system with the same weaknesses as Android's deprecated v1 signature scheme and massive attack surface. It bypasses the standard OS security model for determining sources of apps rather than respecting it. This is incompatible with the expected the security model for unattended app updates in Android 12.

> It is one thing to give constructive criticism to projects, it's another to attack them directly based on falsehoods.

I'm not doing that. Rather, that is what you folks have been doing at every opportunity in these threads. I've only posted here to defend us from malicious misinformation being spread by you folks. You're engaging in that yourself and can't claim to be uninvolved.

Re: CalyxOS – De-Googled Android Alternative

#446
post #445
post #436

Earlier quoted context omitted.

I did not want to get into this, but you're simply spread falsehoods. > GrapheneOS doesn't ship integration of proprietary services like CalyxOS, whether that's WhatsApp or Google services. We do not ship anything proprietary. We ship microG, which is "A free-as-in-freedom re-implementation of Google’s proprietary Android user space apps and libraries." - see https://microg.org/ We ship an integration with WhatsApp i…

> I did not want to get into this, but you're simply spread falsehoods. I'm not spreading any falsehoods. > We do not ship anything proprietary. You ship integration of proprietary services including Google services and WhatsApp. You provide them with privileged integration unavailable to other apps. > We ship microG, which is "A free-as-in-freedom re-implementation of Google’s proprietary Android user space apps and…

I'm really tired of this.

> GrapheneOS does not include any form of Play services and has no support for the OS using it. If a user installs Play services, the OS detects it and intercepts the attempts it makes to use privileged APIs and instead returns placeholder data.

Isn't that shipping an integration for a proprietary service?

How can you claim that we're the ones shipping proprietary service integrations when we ship an open source implementation, and you're the ones shipping an integration for the proprietary implementation.

I'm done here, there's no point arguing with you, you don't see reason.

> Not actually true. Do you claim that stuff like firmware cannot be shipped too?

There is precedent here, https://phandroid.com/2009/09/25/cyanogen-gets-cd-from-googl...

It's the sole reason why there exists the concept of flashing gapps are installing other custom ROMs, and that cannot be supported without verified boot.

The other way is what you're doing, which is impressive, not questioning the code / implementation, just the way you're trying to present it here.

Re: CalyxOS – De-Googled Android Alternative

#447

Earlier quoted context omitted.

There's no point in using LineageOS after they dropped PrivacyGuard instead of expanding it. You start going down this road and suddenly you'll have a phone that doesn't pass SafetyNet anymore. You have to use 3rd-party applications and probably a ROM made by a random internet user not affiliated with LineageOS because they drop support for devices all the time. The phone manufacturers bribe ROM developers to do that…

Privacy Guard) I was the one who purposely removed it. I spent days ( if not weeks ) trying to get it working properly ( read, it never worked properly and causes many issues we still have tickets for ) futhermore Google basically rewrote the full stack once again, while introducing the, now publicly available in 12, permission hub that somehow gave a better view of permissions and easy access to remove them. We know…

Thank you for your (sadly to often undeappreciated but still immensly useful to many people) work.

Re: CalyxOS – De-Googled Android Alternative

#448

Earlier quoted context omitted.

From memory, I think LineageOS 17 took roughly 8-12 hours for an initial build and 3.5 hours for subsequent (ccache) builds on an Intel i5-3570K and spinning hard drive. That's not including the initial git clone. The idea might seem daunting, but assuming midrange hardware and a decent net connection, it's very much doable in under a day without resorting to cloud services.

How would it scale with the number of cores? 3950x should make relatively short work of it, or wouldn't it?

I would expect it to scale pretty well, at least until you reach the limits of your disk and buffer RAM.

The build process supports the -j option just like make. You can use -j N+1 if you want to keep all your cores busy, or -j N-1 to keep your machine more responsive during the build, or nice and -j 1 if you're in no hurry and your machine has more important tasks. (Actually, I think reasonable defaults for these might already be part of the build scripts, but it has been a while since I looked.)

Re: CalyxOS – De-Googled Android Alternative

#449

Earlier quoted context omitted.

Could you explain why you would build in the cloud? Based on a sibling comment, it sounds like it might be because it’s crazy resource-intensive? I’ve honestly not heard of cloud building before. Is it common for large projects like operating systems?

Yes, building AOSP requires a fairly powerful machine (at least to do it quickly): https://source.android.com/setup/build/requirements . It's definitely possible to do on a local machine with decent specs though.

By my reading, my not-really-a-gaming-desktop could do it in 3 hours, that doesn't seem bad at all.

Now granted, those were heavyweight specs when Android came out in 2007, but I'd figure about half of us probably have a similar box sitting around today, and the other half would just need to beef one up with some additional RAM.

Re: CalyxOS – De-Googled Android Alternative

#450

I’m thinking about buying a degoogled Android phone to replace my iPhone. The main things I want are: * Spotify needs to work over Bluetooth in my car * WhatsApp needs to work (preferably with push notifications) * I need the Fitbit app to work so my watch can show push notifications from my personal apps * a network-based location provider to be consumed by my personal apps (I’m working on a personal data and automa…

I don't use WhatsApp, but I bridge my other chat apps through the Matrix client Element.

It appears that WhatsApp does have a bridge for Matrix, though I've not used it.

https://matrix.org/docs/projects/bridge/mautrix-whatsapp

Post reply on HN