Live data from Hacker News

GrapheneOS has been ported to Android 17

discuss.grapheneos.org

581–590 of 653 posts

Re: GrapheneOS has been ported to Android 17

#581
post #454

Earlier quoted context omitted.

> How can you be free when you're not private or secure? Are you serious? Have you even seen the state of modern operating systems compared to the operating systems of the 80s and 90s? I've had way more fun and learnt lot more about computers messing around with OSes that let you did whatever the hell you wanted to. Modern OSes have sacrificed a lot in that name of security. As for privacy, that's a completely separa…

You can't have privacy without security.

Privacy is when nobody is looking, whether that's because they cannot look or because there's nobody that looks.

Security is the former: actively denying someone or something the ability to look in a situation where they are trying. GrapheneOS does that by encouraging a locked bootloader (preventing physical attacks) and letting you deny sensor access (preventing malicious apps from accessing unnecessary info), for example. I think we agree so far?

But you can also have privacy by just not installing apps that violate your privacy. Such a device could be as open as any Linux laptop where you log in with root:root. It lets you do whatever you want and access whatever you want. It's yours through and through. That's freedom without security, which may or may not have privacy depending on who you let look: if you leave it unattended at a hacker conference or have sshd with password login enabled, yeah that won't stay private for very long. But that's your choice right? You can just not invite anyone in or, in this example, bring it to someone who would do something malicious

An official GrapheneOS release has a lot of features baked in against actively malicious actors (be it apps or people at border checks), but users need to work within the boundaries and limitations of the sandpit that's provided to them. They're not granted much freedom, and that limits what privacy measures you can enact. Making a backup of /data, modifying firewall or traffic routing rules, signature spoofing to substitute an untrusted app with a trusted implementation, intercepting and faking Android API responses... a lot of things are off-limits: you don't have the freedom to shape the environment to suit your needs, for example to create privacy or security

The axes (privacy, freedom, security) all influence each other, but they are still separate enough that you can have one or two without the other. I can see what you mean if you say that your threat actors are skilled exploit developers and you can't have privacy without also thwarting these constant attempts. (Paranoid as that may sound, I'm sure it's true for some people.) Most people would gain more privacy from doing something about the pervasive adtech than about exploit developers they're not likely to run into. For them, LineageOS could be more private and provide more freedom while being less secure in some ways (e.g. they need to watch out which processes they grant access, for example something claiming to be backup software that turns out to be ransomware) and more secure in others (e.g. data availability by getting to make backups)

Re: GrapheneOS has been ported to Android 17

#582
post #221
post #20

Earlier quoted context omitted.

Ha! Me too! Exact same. Bought a Pixel 10. Intended to do the default Android for a while. But it was filled with ads for “Wicked” which had me looking at my phone with a sneer on my face I couldn't erase - as if someone had smeared feces all over it and threw it on my bed. So I jumped straight to GrapheneOS, which was way easier and less extreme than I had been warned. So beautifully minimal, with no crap. Now my ph…

> it was filled with ads You bought a phone from an advertising company?

All factory operating systems come with ads and bloat and spyware, Apple/Samsung included. Google remains the lesser of all other evils because at least to date, they offer an open source OS, bootloader unlocking, and root. A community driven mobile OS is absolutely where we should go, but for now and the foreseeable future you can call a Lyft, deposit a check (in America), and do other mainstream tasks on AOSP flavors without Google/Apple/Samsung having to know anything about it. It's never been easier to make the user friendly choice too: https://grapheneos.org/install/web

Re: GrapheneOS has been ported to Android 17

#583
post #578

Earlier quoted context omitted.

How can you be free when you're not private or secure? Grapheneos is fully open source and comes with 0 Google services. >so called "security" Grapheneos is widely recognized as one of the most secure operating systems.

> Grapheneos is fully open source and comes with 0 Google services. And calls the open source microG a threat while encouraging people to install google mobile services, conveniently provided from their preinstalled app store, which most people will need for at least some of the apps they need in daily life, so everyone ends up with GMS installed in their main profile. A real bastion of freedom and choice.

MicroG requires privileged access. It also downloads and runs proprietary google code within this privileged context. MicroG additionally has very poor app compatibility and has had severe privacy issues in the past.

Sandboxed google play does not grant google code any kind of privileged access. It is confined to the same app sandbox and permission model as all other apps and can be installed and uninstalled like any other app.

Note that apps with google libraries grant google the same, unprivileged access google services gets on GrapheneOS. MicroG fails to meet the privacy, security, and usability requirements GrapheneOS has in place when it comes to google play compatibility.

So, you can pick MicroG, which is bundled, privileged, poorly made, has poor compatibility, and trusts an additional party...

Or, you can pick sandboxed google play, which is not bundled, optional, unprivileged, fully sandboxed, and does not trust additional parties. Oh, and you can uninstall and reinstall whenever.

It is evident which option gives the user freedom, and a choice.

Re: GrapheneOS has been ported to Android 17

#584

Earlier quoted context omitted.

> Yeah RCS always has been an embrace extend extinguish thing. The carriers were super pissed to lose their SMS revenue to WhatsApp and iMessage so they came up with this shit to be an active partner in the loop again, and they can bill for it again. Consumers didn't fall for that and it died off. I strongly disagree with this negative characterization. RCS was a replacement protocol for the extremely outdated SMS an…

RCS is not modern. E2EE is only an addon and it's not open. As others have mentioned it's not even available with interoperation. And it was really invented by carriers for exactly that purpose: To regain SMS/MMS revenue. But at this point here in Europe SMS usage between people had vanished anyway (except for spam and poor 2FA implementations) And the social problems are not a technology problem, it's more a result…

> RCS is not modern.

False. RCS is a replacement for SMS and MMS, and it is far more modern than those. RCS is the most modern game in town.

> As others have mentioned it's not even available with interoperation.

Others might have "mentioned" this, but it is false. RCS is interoperabile. It is supported both in Android and iOS by different applications. That covers the two mobile operating systems that constitute nearly the entire mobile market.

> And it was really invented by carriers for exactly that purpose: To regain SMS/MMS revenue.

I don't think that's true since they didn't charge for RCS. But even if it's true: that doesn't mean RCS is bad. RCS is like HTTP+HTML, but for messaging. Saying that RCS is bad is like demanding that all browsers should be proprietary without supporting anything resembling a web standard. Which would be crazy.

> But at this point here in Europe SMS usage between people had vanished anyway

That's irrelevant because RCS is still important in the US.

> And the social problems are not a technology problem,

They absolutely are (also) a technology problem. If people can't properly interact with each other in group chat because one side falls back to MMS and all pictures are ultra low resolution, then that's annoying for everyone. Of course people would say the problem is with Android rather than with iMessage refusing for many years to adopt RCS, which hugely boosted Apple's market share among young people in the US.

> Without blue bubbles there'll be something else that kids will be bullied for.

False. They weren't bullied for blue bubbles. They were "bullied" because green bubble people had bad compatibility problems. Why? Because of lack of RCS.

> And Google didn't try to convince Apple to do this out of the goodness of their heart.

That's an absurd statement. Google was obviously not happy that Apple was (as they even confirmed in internal emails) actively using incompatibility to increase their US market share. Apple was basically acting like Internet Explorer vs Netscape.

> Like I said most of the protocol (except the E2EE) is open but the implementation is not.

It's still an open protocol. Not everything must be open source. Proprietary apps like WhatsApp use neither an open protocol nor are they open source.

> It gives google even more control.

Even more? Proprietary protocols like iMessage or WhatsApp have far more control.

> You also won't be able to use it on a PC without a google account which is a big dealbreaker compared to Whatsapp and Signal.

That's an absurd comparison because you can't use WhatsApp or Signal without an WhatsApp or Signal account either. Not even on phones.

> iMessage isn't a thing here in Europe anyway

That's irrelevant. Open standards are good even if non-open things dominate in some area.

> (neither is SMS/MMS).

Also irrelevant. RCS is an open protocol that is vastly superior to SMS and MMS and not a closed and proprietary system like WhatsApp or iMessage. This makes it a great system, similar to HTTP and HTML.

Re: GrapheneOS has been ported to Android 17

#585
post #579

Earlier quoted context omitted.

I wouldn't be particularly surprised if they're hiding the spec / charging pointless $$$ to reduce access, but I was under the impression that it would be available, like RCS's spec itself. e.g.: the RCS v3 page: https://www.gsma.com/solutions-and-impact/technologies/netwo... ^ which links to the E2EE v1 spec: https://www.gsma.com/solutions-and-impact/technologies/netwo... ("download" is a direct link to a pdf file)…

Ah when I last checked the E2EE was only in practice implemented by Google and invented by them. It looks like this might have been opened up, unless this is an earlier version somehow? And interconnect traffic to e.g. iMessage was not E2EE. I have to look up on this again as the last time I looked at it was during late corona (2022? 2023?) when there was a local talk to adopt RCS (which failed) But the problem remai…

yea, from my understanding Google has had E2EE when messaging itself for a couple years or so now, mirroring how iMessage encrypts messages to itself. iMessage is even very similar (maybe identical) to MLS, and Google Messages might be as well but I don't know the details. but neither encrypts when sending to the other, nor any other client/server/etc, because there is no agreed-and-implemented spec last I looked (a few months ago).

they have, however, been touting the security improvements that RCS brings ever since work first started on it. which is so misleading that it's outright malicious imo.

Google Messages and iMessage AFAIK send RCS messages to each other just fine, but it's not encrypted. yet. ever, IMO, until the moment it's rolled out.

Re: GrapheneOS has been ported to Android 17

#586
post #575

Earlier quoted context omitted.

Android similarly supports, and in fact uses, "proper" Linux. Android and its forks are Linux distributions. You can use a mainline kernel in Android just fine.

Nah, Android is not a really a proper Linux system that 'supports' Linux software within any reasonable definition of the word; not anymore at least Root nowadays gets you very little: software like wavemon that worked great on Android 4.4 no longer runs because selinux or whatever restrictions block nearly everything from working that isn't going through the Android API channels. Accessing external storage from Linu…

Most of this is not related to the claim and is more tangential discussion about things you like that run on the linux kernel, now, there is nothing wrong with that, but I must emphasise that none of what you describe is a part of the criteria for what constitutes a linux distro. A linux distro is an operating system using the linux kernel. Android fits that criteria.

The policies and applications running on top of or in the linux kernel do not change its distro classification. Lacking root access is a massive step forward for privacy and security. Root access is insecure and a hacky shortcut to proper functionality.

Re: GrapheneOS has been ported to Android 17

#587
post #97

Earlier quoted context omitted.

A lot of developers are lured into building in a dependency on Google services, so yes you'll need microG or, as GrapheneOS prefers, the original Google code running on your device for those apps to function. Or patch the app, like Langis does for Signal (not necessary for it to function without Google in this case, but it removes its calling out to Google's apps and services for those who don't want that). If you're…

GrapheneOS is designed for everyone, including average users. It does not require a high threat model, and the features it provides are not only useful to people with high threat models. Contrary to popular belief, exploitation of vulnerable devices is a lot more common, and a lot easier than people pretend it is. You dont need to be targeted either, mass exploitation can, has, and will occur. LineageOS does not have…

> Contrary to popular belief

Extraordinary claims require extraordinary evidence. Got any?

The rest of the comment consists of even vaguer statements about how it's better in every way and then (circularly) drawing the conclusion that it's always the right choice because it's better in every way. I have no idea how to respond to these opinions than either writing a book that goes into every subtopic you're touching on, or just concluding "ok that's your opinion". Maybe consider that others may disagree by having different values and priorities than you, and so it's not strictly always the best option

Re: GrapheneOS has been ported to Android 17

#588
post #12

I've been running GrapheneOS for 7 months now and I'm not going back. When I bought my Pixel 10 last year, I wasn't actually planning on trying Graphene for a while....until I noticed Google had force bundled a 'Wicked For Good' movie promo theme with the latest security update.

What are you using for cell service? Been wanting to switch to GOS for years, but I've also been really uninterested in having to find a new service provider (currently using fi).

Re: GrapheneOS has been ported to Android 17

#589
post #578

Earlier quoted context omitted.

> Grapheneos is fully open source and comes with 0 Google services. And calls the open source microG a threat while encouraging people to install google mobile services, conveniently provided from their preinstalled app store, which most people will need for at least some of the apps they need in daily life, so everyone ends up with GMS installed in their main profile. A real bastion of freedom and choice.

MicroG requires privileged access. It also downloads and runs proprietary google code within this privileged context. MicroG additionally has very poor app compatibility and has had severe privacy issues in the past. Sandboxed google play does not grant google code any kind of privileged access. It is confined to the same app sandbox and permission model as all other apps and can be installed and uninstalled like any…

Thanks, but there's no way anybody here hasn't already heard all of that. GrapheneOS' statements are inevitably reposted to every thread and subthread that touches on the topic.

Yes, I knew it's in a sandbox at the time of writing my comment above; no, that doesn't make it a privacy paradise compared to microG.

The sandbox still needs internet access for a lot of GMS' functions and lots of apps send information into it. For example, Signal will actively reach out for notification bundling, so Google gets to know who runs Signal, what IP address they're on, with who else they share that address as they go to school and work, build a social graph... So while the sandbox is definitely very useful and I'm glad it exists as open source software that other Android distributions can be inspired by, it doesn't definitively solve fundamental problems with running unwanted software on your device

Do you know what privileged context means? As in, what access this grants concretely? I tried to look it up once, ended up in Android source code trees, and left more confused than I went in. It looked like it gets no extra file access at all, which is strange right? What does privileged mean if not that? I tried su'ing to the user ID of GMS and this confirmed that the GMS user can't access other apps' data folders. So I'm no longer sure what to even make of this wording. Is it maybe about syscall hardening that isn't applied to privileged apps or so, so like exploit protection rather than normal permissions? The benefit of that would be protecting from exploits that Google could send. Do we think they'd legit do that, short of receiving an NSL that compels them?

Rather than running the unwanted proprietary (but necessary) software wholesale and attempt to sandbox it, I'd much rather substitute as much as possible with open code (where we know what it does) and have a much smaller set of proprietary components that need to be kept around in a sandbox and active only when necessary. For example, microG will replace Gmaps with Mapbox, reducing how much data is sent out about you to Google (they don't get to see which city you are probably in while using the map in Too Good To Go, for example).

It seems fairly obvious to me that less data sharing plus less proprietary code (that needs to be sandboxed) is better than letting Google go wild and installing their apps as-is with self-updating functionality (in said sandbox). What threat would sandboxed microG pose that sandboxed GMS doesn't? Is there any logic to GrapheneOS not wanting to build upon microG to get the remaining proprietary parts properly sandboxed, rather than starting over from scratch?

Re: GrapheneOS has been ported to Android 17

#590
post #575

Earlier quoted context omitted.

Nah, Android is not a really a proper Linux system that 'supports' Linux software within any reasonable definition of the word; not anymore at least Root nowadays gets you very little: software like wavemon that worked great on Android 4.4 no longer runs because selinux or whatever restrictions block nearly everything from working that isn't going through the Android API channels. Accessing external storage from Linu…

Most of this is not related to the claim and is more tangential discussion about things you like that run on the linux kernel, now, there is nothing wrong with that, but I must emphasise that none of what you describe is a part of the criteria for what constitutes a linux distro. A linux distro is an operating system using the linux kernel. Android fits that criteria. The policies and applications running on top of o…

Sure, we can have different opinions on what makes a useful Linux distribution. Either way, you can't install Ubuntu Touch on just any phone. That Volla supports that alongside their AOSP derivative gives you more options on how to use the device; it's worth pointing out to potential buyers as a bonus on top of running Android only
Post reply on HN