Live data from Hacker News

GrapheneOS has been ported to Android 17

discuss.grapheneos.org

541–550 of 653 posts

Re: GrapheneOS has been ported to Android 17

#541
post #405
post #291

Earlier quoted context omitted.

Huh, it works just fine in the UK. Wonder if they have different builds (or completely different apps) for different regions. Or maybe it's the GrapheneOS compatibility layer that makes it work? Not sure.

Play Integrity has several levels. GrapheneOS MEETS_BASIC_INTEGRITY, which I believe only requires a locked bootloader and no superuser. There's also been some discussion of spoofing MEETS_DEVICE_INTEGRITY, since before Android 13 it didn't rely on a TPM, and many apps don't want to lock out older devices, but it's been decided against it [0]. [0] https://github.com/GrapheneOS/os-issue-tracker/issues/1986

Hmmmm.... Actually you can have an unlocked bootloader for the basic integrity level.[0]

[0] https://developer.android.com/google/play/integrity/verdicts

Re: GrapheneOS has been ported to Android 17

#542
post #529

Earlier quoted context omitted.

Are you saying that GraphebneOS running on Google Pixels has no proprietary blobs apart from the firmware?

No, but all of the kernel drivers are open source and always were. The closed source userspace libraries such as the Mali GPU library aren't a barrier to porting to a new kernel version which is what was said above. We could move to 6.12 ourselves but we choose to wait for them for much broader testing which is happening with Android 17 QPR2.

Is there a list of the drivers and closed libraries somewhere?

Re: GrapheneOS has been ported to Android 17

#543

Been toying with the idea for a long time, but I'm concerned about US financial institution apps and multiple countries specific apps (local transport, finance, medical and governmental), whose apks do no exist, as well as (crucial for me, as a heavy international traveler) google voice. For a lot such I now need to use a combo of Google playstore, for US account tied apps, and Aurora for non US apps.

You will find that a lot of banks and other companies have old fashioned websites that open work better (and more privately) than apps. Even Google Voice should be usable through its website. However what is usually recommended by the Graphene community is to call or text via Signal instead.

Re: GrapheneOS has been ported to Android 17

#544
post #20

Earlier quoted context omitted.

Ha! Me too! Exact same. Bought a Pixel 10. Intended to do the default Android for a while. But it was filled with ads for “Wicked” which had me looking at my phone with a sneer on my face I couldn't erase - as if someone had smeared feces all over it and threw it on my bed. So I jumped straight to GrapheneOS, which was way easier and less extreme than I had been warned. So beautifully minimal, with no crap. Now my ph…

iOS is also going into this direction, just open the AppStore, it’s all the cheapest most horrible apps. Temu (shop like you don't give a s* about the planet), addictive AI Waifu’s (who needs human interaction anyway), clean your stuff but fake-time-wasting style (it's free dopamine!), search option’s first hit is often scammy (ie search for MS Authenticator). I feel that Steve ("If you want pr0n get an Android") wou…

You should read https://discuss.grapheneos.org/d/24134-devices-lacking-stand... about /e/ and also look at what they say about devices with strong privacy and security including but not limited to https://grapheneos.social/deck/@GrapheneOS/11635397373214317....

Re: GrapheneOS has been ported to Android 17

#545
post #450
post #446

Earlier quoted context omitted.

Freedom to get a stroke from an incomplete toy OS? Snark aside, desktop Linux userspace (or gnu Linux, call it how you want) is nowhere near production ready. And even for the more general point, giving out root willy-nilly is not more freedom. It's more like letting your child play on the 5th floor of a half-constructed building that's about to be exploded. Your kid can enjoy their time just as much in the safe fore…

Not everything needs to be "production ready". And giving out root willy-nilly is freedom. It's my device, I should get to decide how I want to use it and not have artificial restrictions put on my be by someone else. If I want to rm -rf /, I should be able to do just that.

You can, but maybe don't make it an easy to accidentally invoke default.

Like even `rm` added a flag to not do that without explicitly asking.

Also, there are plenty of immutable OSs now among Linux distros, are they also limiting your freedom?

Re: GrapheneOS has been ported to Android 17

#546
post #474

Sadly not an option as long they don't support Fairphones

Fairphones are far from meeting the security requirements to run GrapheneOS and have chosen an incompatible path. It won't be available for their devices.

https://discuss.grapheneos.org/d/24134-devices-lacking-stand...

https://grapheneos.social/@GrapheneOS/116353973732143171

Re: GrapheneOS has been ported to Android 17

#547
post #186

I have always wondered what this OS looks like. They have an incredibly detailed website with zero screenshots.

It looks very plain (black background, monochrome icons, very few apps included). You can customize all that if you want. I personally quite like the default appearance, but I am also the kind of person who uses the default GNOME or KDE theme on Linux and does not bother with custom themes or anything beyond daily Bing wallpapers.

Re: GrapheneOS has been ported to Android 17

#548
post #529

Earlier quoted context omitted.

No, but all of the kernel drivers are open source and always were. The closed source userspace libraries such as the Mali GPU library aren't a barrier to porting to a new kernel version which is what was said above. We could move to 6.12 ourselves but we choose to wait for them for much broader testing which is happening with Android 17 QPR2.

Is there a list of the drivers and closed libraries somewhere?

The kernel drivers are all published in the GrapheneOS kernel repositories. A subset of the libraries/services in the vendor partition used with those drivers are closed source.

Pixels were headed towards all of the device support code for the OS being open source along with open sourcing large portions of the firmware including for the TEE (Trusty OS) and secure element (OpenTitan). It was ended after the launch of Android 16. It's a major factor in why GrapheneOS is going to be focused on future Motorola Mobility devices. You can still see a large portion of the Pixel userspace driver libraries and services in the AOSP source tree but they stopped pushing new releases for a lot of it.

Re: GrapheneOS has been ported to Android 17

#549

Earlier quoted context omitted.

If you value freedom to do what you want on your devices, then you may want to consider Librem 5 instead. It runs a desktop Debian derivative with full root access.

You have the ability to do what you want on your device. Root access in AOSP is just used as a hacky shortcut to achieving specific functionality. To do it properly while maintaining the security model would be to build it into the OS itself. The same concept applies to desktop platforms and the Librem 5. This isn't related to freedom. That device, and the Debian derivative it runs, are not private or secure.

What do you mean when you say "not private"? Are you accusing the company of sending private data to their servers, as Google and Apple do?

Freedom of computing on Librem 5 doesn't end with the root account. It also allows to natively run any desktop software and develop it in any language, without reliance on Google's decision on how one must use the phone, how your OS must evolve and when you may get your updates. Or install a completely different OS from different developers, because there is no reliance on anything proprietary at all.

How you can call a device with a ton of opaque binary blobs more private and secure without mentioning this fact is beyond me. I do not call Librem 5 more secure. But its security depends on what I choose to run on it. And I only run trusted software, so it can be secure.

Post reply on HN