Live data from Hacker News

GrapheneOS has been ported to Android 17

discuss.grapheneos.org

531–540 of 653 posts

Re: GrapheneOS has been ported to Android 17

#531

I took the plunge into GrapheneOS a week ago. I picked up a new Pixel10 Pro and never even tried the stock OS (except to unlock the boot loader). I've got almost everything working the way I want. There were a few non-essential banking apps that won't install. The most annoying problem I had is when I tried to install Strava, which I cannot get working. The app installs, but it will not let me sign in. I guess I need…

The most hilarious is McDonald's app - it refuses to work without Play Integrity check. I wonder what braindamaged reasoning is behind this. Do they want to position themselves as a bank or something?

What would anyone use an app to order food from McDonald's? Just walk into the restaurant, pay cash, and walk out with the food.

Re: GrapheneOS has been ported to Android 17

#532
post #484

Earlier quoted context omitted.

them supporting e/OS suggests otherwise

No, them supporting e/OS corroborates the claim that their goal is not privacy or security.

What do they need to support to convince you? Providing all hardware features required by GrapheneOS is not feasible for a small company.

Re: GrapheneOS has been ported to Android 17

#533

That's exactpy why I get Google Pixel phones. Support expires? Upgrade to custom ROM Ads? Upgrade to custom ROM Want to use it as server? Upgrade to custom ROM. If I would use Apple iPhone, these old phones would be trash very soon.

The iPhone 11 was released almost 7 years ago and is still supported by the latest iOS.

For context, that would put it at the same release as Pixel 3 or Pixel 4. Those devices stopped receiving updates in 2022-2023.

Re: GrapheneOS has been ported to Android 17

#534

Earlier quoted context omitted.

No, them supporting e/OS corroborates the claim that their goal is not privacy or security.

What do they need to support to convince you? Providing all hardware features required by GrapheneOS is not feasible for a small company.

Fairphone doesn't design or make their smartphones. The devices are designed and made by a large ODM. It's entirely feasible to use a modern SoC with current generation security features and provide proper updates. Their ODM isn't doing it to cut costs.

Fairphone quickly stops providing Linux kernel updates and has months of delay for Android userspace backports along with driver/firmware backports. The delay for yearly updates typically starts at a year and gets longer as devices get older and they've always skipped the quarterly updates.

Using a modern SoC, properly configuring it, using proper signing keys (Fairphone has repeatedly used publicly available sample private keys) and providing proper updates is most of what's needed to meet the requirements. That's entirely doable by the few OEMs designing their devices in-house such as Motorola Mobility. Samsung and Google along with many of the ODMs making devices for Nothing, Fairphone, etc.

https://discuss.grapheneos.org/d/24134-devices-lacking-stand...

Re: GrapheneOS has been ported to Android 17

#535
post #405
post #291

Earlier quoted context omitted.

Huh, it works just fine in the UK. Wonder if they have different builds (or completely different apps) for different regions. Or maybe it's the GrapheneOS compatibility layer that makes it work? Not sure.

Play Integrity has several levels. GrapheneOS MEETS_BASIC_INTEGRITY, which I believe only requires a locked bootloader and no superuser. There's also been some discussion of spoofing MEETS_DEVICE_INTEGRITY, since before Android 13 it didn't rely on a TPM, and many apps don't want to lock out older devices, but it's been decided against it [0]. [0] https://github.com/GrapheneOS/os-issue-tracker/issues/1986

I saw on the GrapheneOS forums that some people had managed to get it working, but I was unable to do so.

My bootloader is locked, because I re-locked it after installing GrapheneOS. The app runs, but refuses to let me log in. I even tried (temporarily) using a browser to login, and let the browser switch to the app in the process. Nada.

It's ridiculous that Google bills their "DEVICE INTEGRITY" initiative as a security feature, when GrapheneOS, which is a more secure platform, cannot use it.

Re: GrapheneOS has been ported to Android 17

#536

I took the plunge into GrapheneOS a week ago. I picked up a new Pixel10 Pro and never even tried the stock OS (except to unlock the boot loader). I've got almost everything working the way I want. There were a few non-essential banking apps that won't install. The most annoying problem I had is when I tried to install Strava, which I cannot get working. The app installs, but it will not let me sign in. I guess I need…

I run Strava on my Pixel 10 Pro Fold running GrapheneOS. IIRC you need to have Google Play Store installed (with zero permissions, preferably) to make Strava work.

Both Google Play Store and Google Play Services are installed, with minimal permissions. Strava still does not work.

Re: GrapheneOS has been ported to Android 17

#537
post #199

GrapheneOS would be so much more interesting if there was an official supported way for rooting it. That's the only reason I haven't switched to it on my several devices (all rooted)

If you value freedom to do what you want on your devices, then you may want to consider Librem 5 instead. It runs a desktop Debian derivative with full root access.

You have the ability to do what you want on your device. Root access in AOSP is just used as a hacky shortcut to achieving specific functionality. To do it properly while maintaining the security model would be to build it into the OS itself. The same concept applies to desktop platforms and the Librem 5. This isn't related to freedom.

That device, and the Debian derivative it runs, are not private or secure.

Re: GrapheneOS has been ported to Android 17

#538

I took the plunge into GrapheneOS a week ago. I picked up a new Pixel10 Pro and never even tried the stock OS (except to unlock the boot loader). I've got almost everything working the way I want. There were a few non-essential banking apps that won't install. The most annoying problem I had is when I tried to install Strava, which I cannot get working. The app installs, but it will not let me sign in. I guess I need…

I know a friend is using Strava on his Pixel 10 running graphene so there should be a way

There should be a way, but I have not yet found it, and I've spent some time on this. I've installed/uninstalled Strava about a dozen times, rebooted each time, tried various permissions, but stood my ground on some of the permissions. Should I give Strava access to my photos and my microphone? I'll never go that far.

Re: GrapheneOS has been ported to Android 17

#539
post #484

Earlier quoted context omitted.

I don't think that fairphone is interested in privsec so it will never be supported.

them supporting e/OS suggests otherwise

/e/ is the direct opposite of a privacy or security focused OS. It doesn't provide bare minimum standard privacy and security patches while setting an inaccurate Android security patch level. It lags many months behind on patches even on devices where they're the least behind. It's typically years behind on kernel, driver, firmware and major OS updates. It doesn't keep the standard privacy and security protections intact and lagging behind on OS updates means not having the current ones. It sends user data to OpenAI and other third parties without consent.

https://community.e.foundation/t/voice-to-text-feature-using...

https://codeberg.org/divested-mobile/divestos-website/raw/co...

https://discuss.grapheneos.org/d/24134-devices-lacking-stand...

/e/ and Murena have repeatedly claimed providing strong privacy and security mainly benefits criminals and claim devices doing it are mainly used by criminals. Here's one example of many:

https://grapheneos.social/deck/@GrapheneOS/11635397373214317...

An iPhone is a hardened device with drastically better privacy and security than an /e/ device. It would fall under the claims from /e/ and Murena about hardened devices.

Re: GrapheneOS has been ported to Android 17

#540
post #487

Earlier quoted context omitted.

It seems to me that /e/ is opposed to privacy and security. https://xcancel.com/GrapheneOS/status/2066908368560656652#m

It's interesting how you are able to conclude that. e/OS is clearly a step up from default Android

/e/ has drastically worse privacy and security from the Android Open Source Project or especially and iPhone. It's not a step up from standard AOSP. It lags many months behind on many High/Critical severity patches, years behind on overall patches and rolls back the privacy/security in a bunch of ways. It includes many invasive services.

It has many default enabled highly privileged Google services including downloading Google Play executables such as droidguard and running those with similar privileged access as they have on a Google Mobile Services OS anyway.

Post reply on HN