Live data from Hacker News

GrapheneOS – A privacy and security-focused mobile OS with Android compatibility

grapheneos.org

51–60 of 186 posts

Re: GrapheneOS – A privacy and security-focused mobile OS with Android compatibility

#51
post #45

Earlier quoted context omitted.

That sounds reasonable, but here we are with Android's endless security disaster and all their apps written in not-Java from the beginning. The most cancerous aspects of Android are by design, that you cannot control network exfiltration from apps, you cannot update or modify the OS pieces at will, and the apps are monetizing everything you do and everything they can find against you. Librem will answer these.

Large majority of Android security exploits are in C and C++ written drivers, hence why with each release the amount of freedom with native code gets further locked down. Android Q has another round of such measures. https://android-developers.googleblog.com/2019/05/queue-hard...

Those may be security exploits, but the real malware is what gets installed through Google Play.

Re: GrapheneOS – A privacy and security-focused mobile OS with Android compatibility

#52
post #43

Earlier quoted context omitted.

While with each Android interaction, Google locks down the amount of C and C++ code that gets exposed to outside world. https://android-developers.googleblog.com/2019/05/queue-hard... As such I have a very hard time believing that Librem with be as secure as modern Android.

There is security, and then there is freedom. You can have the most secure system in the world -- but if there are state sponsored, or company back back doors it means nothing. In FOSS initiatives spent ages building fee and and open software, combating proprietary systems and software that they had no control over. All that would be loss just to give it up now that we have moved from PCs to phones.... I for one want…

What freedom does PureOS offer that AOSP without Google services lacks?

Re: GrapheneOS – A privacy and security-focused mobile OS with Android compatibility

#53
post #51
post #45

Earlier quoted context omitted.

Large majority of Android security exploits are in C and C++ written drivers, hence why with each release the amount of freedom with native code gets further locked down. Android Q has another round of such measures. https://android-developers.googleblog.com/2019/05/queue-hard...

Those may be security exploits, but the real malware is what gets installed through Google Play.

Hence a Play Store free alternative like GrapheneOS.

Re: GrapheneOS – A privacy and security-focused mobile OS with Android compatibility

#54

It supports the Google Pixel range of phones only so far. So in order to get that is more secure and more independent from Google I have to buy a Google phone?

Exactly my question. I have seen a bunch of these OSs, all useless because there is no build for my phone and no described path for making one. I would love to get the T-Mobile spyware off my phone. What do i do?

Unfortunately all you can really do is pick up a different phone. Luckily finding an old unlocked Nexus 5 or OnePlus One on ebay is pretty easy and relatively cheap.

Re: GrapheneOS – A privacy and security-focused mobile OS with Android compatibility

#55
post #36
post #31

Also, https://postmarketos.org/ is a good project too.

PostmarketOS seems the most promising effort for a truly open and affordable handheld OS with mainline kernel and other good practices. And there's also a useful incremental path for evolution, that starts with a familiar GNU/Linux and moves gradually towards handheld tweaks (UI, power, devices, apps). It's important to be upfront that PostmarketOS is not yet viable as a daily driver, or people will feel they wasted…

PostmarketOS reminds me a lot about the approach Openmoko (https://en.wikipedia.org/wiki/Openmoko) took way back over a decade ago, except that they did have to build the hardware as well.

Re: GrapheneOS – A privacy and security-focused mobile OS with Android compatibility

#56
I can see what the focus is, but I couldn't find a page that clearly spelled out differences with AOSP. I realize that's a missing target, but as a potential user it's interesting to know how it's going to be different than stock Android (beyond what the "focus" is).

Re: GrapheneOS – A privacy and security-focused mobile OS with Android compatibility

#57
post #51
post #45

Earlier quoted context omitted.

Large majority of Android security exploits are in C and C++ written drivers, hence why with each release the amount of freedom with native code gets further locked down. Android Q has another round of such measures. https://android-developers.googleblog.com/2019/05/queue-hard...

Those may be security exploits, but the real malware is what gets installed through Google Play.

Nothing can be done to prevent stupid users to install everything that shines.

Even HNers do curl | sh without thinking twice about it.

Re: GrapheneOS – A privacy and security-focused mobile OS with Android compatibility

#58
post #48

Earlier quoted context omitted.

Exactly my question. I have seen a bunch of these OSs, all useless because there is no build for my phone and no described path for making one. I would love to get the T-Mobile spyware off my phone. What do i do?

If you have a phone with T-Mobile spyware then it almost certainly also has a locked bootloader with no official unlock method. What are you expecting people developing alternate OSes to do about that? The obvious way to get a phone not running T-Mobile spyware is to not buy a phone from T-Mobile. Not trying to be snarky here, I have one of these phones too. Though if you happen to have a T-Mobile Oneplus phone like…

To clarify, some of the phones you can buy directly from T-Mobile can also be bought "unlocked" in the open market.

In general, if you want any hope of unlocking your phone (either for use on other carriers or unlocking the bootloader) then you should NOT buy from the carriers' online or brick & mortar stores.

Re: GrapheneOS – A privacy and security-focused mobile OS with Android compatibility

#60

It supports the Google Pixel range of phones only so far. So in order to get that is more secure and more independent from Google I have to buy a Google phone?

There are not that many phone manufacturers that even allow you to change the trust anchor (which makes any of this even remotely possible). For example, Samsung uses e-fuses to burn in their signing key, rewriting recovery will permanently trip their attestation (Knox); other manufacturers use similar practices. Pixels are one of the only currently available phones with user-controlled trusted boot in mind.

Oneplus phones too.
Post reply on HN