Live data from Hacker News

GrapheneOS – Break Free from Google and Apple

blog.tomaszdunia.pl

831–840 of 967 posts

Re: GrapheneOS – Break Free from Google and Apple

#831

And once you are on GrapheneOS, break free from your proprietary watch ecosystem and switch to GadgetBridge ( https://gadgetbridge.org/ ) I run a Thinkpad with NixOS and KDE, a Pixel 9 with GrapheneOS, and an Amazfit watch paired with GadgetBridge on my phone. It's a testament to the hard work of the FOSS maintainers of these projects, and the spirit of open source, that everything works flawlessly together without a…

Alternatively, consider PineTime, which even offers a choice of the OS it runs: https://pine64.org/documentation/PineTime/

Also there's AsteroidOS which is a wrist sized linux for your watch, and looks fantastic! - https://www.youtube.com/watch?v=U6FiQz0yACc

Re: GrapheneOS – Break Free from Google and Apple

#832
post #694

Earlier quoted context omitted.

Just like Linux can mean "the Linux kernel" or "a Linux distribution" in "common use of the terms", Android can mean "a device that can legally be advertised using the Android trademark" or "whatever looks like Android to people". Now when someone says "Break free from Android... by installing Android?", either they are having fun by using the two different meanings in the same sentence, or they are confused and genu…

You're vigorously defending a poorly thought out title by inventing irrelevant contexts and falsely accusing multiple people of being wrong because they claimed such uncontroversial things like "AOSP is Android". Sure, if we want to be strictly correct then AOSP is not Android, but rather the name of a Google project that distributes the source code of Android - but that's not how the term is commonly used in these d…

> Sure, if we want to be strictly correct then AOSP is not Android, but rather the name of a Google project that distributes the source code of Android

Thank you.

I do find it ironic that you could not understand what I mean given that you're the kind of people who say "GNU/Linux".

Re: GrapheneOS – Break Free from Google and Apple

#833
post #589

Am I the only one who finds monospace font barely readable for articles? Good for code, bad for longer forms of text.

No, I also click away articles in that font style if it's not exceptionally interesting or relevant to me In this case, reader mode fixes it (your browser probably has a button built in)

I always forget about it, thanks for the tip.

Re: GrapheneOS – Break Free from Google and Apple

#834
post #645
post #69

Earlier quoted context omitted.

privacy != security. And sandboxed Google Play services serve both goals -- it runs the service as a regular android service, not an exceptional one that has a bunch of extra permissions. So you can allow/restrict it as you seem fit, while not "getting behind" on features/apps that mandate it.

GrapheneOS provides major privacy enhancements including Contact Scopes, Storage Scopes, Sensors toggle, per-connection Wi-Fi privacy via per-connection DHCP state + MAC randomization and far more. It's a privacy project and privacy depends on security so it heavily focuses on protecting against exploitation of privacy and security vulnerabilities too. Privacy and security are not separate things from each other but…

I won't argue with you on the project-related part of it, you obviously know best there :) Thank you for all the work!

But how would you "rate" for example desktop "GNU/Linux" with this in mind? Quite clearly privacy is important here and none of the major components leak/store unnecessary personal data. But the security story is quite sad, everything runs as the same user so a random `npm install` can just do whatever it wants with my browser caches, ssh keys, etc. I would say that GNU/Linux is privacy-friendly, but has terrible security. Would you not agree here? How does this fit with the "privacy and security are not separate things" part? Genuinely curious about your opinion here, not arguing for the sake of it, they are just not as closely connected in my mind. For example Google has a good track record of having safe practices regarding data storage -- but privacy is not their strong suit/hard to define what it means for a company to begin with.

Re: GrapheneOS – Break Free from Google and Apple

#835
post #232

Earlier quoted context omitted.

As far as I remember, last time I needed to use Google play on a shared phone I could just create a random Google address (I mean, completely invented name, etc.) and it allowed me to do anything, just as my normal Android. I am too lazy to test, but did this change? Can't you just make a "fake" account and continue with your life? The phone company knows where you are, the bank knows what you purchase. Compared to t…

No, they will either immediately or shortly thereafter require you to link a phone number, etc

You can create a Google account without adding a phone number, that's still possible currently. To do this you need to make it within an app, for example Google Play Store or YouTube, not on the websites. You also need to use a trusted IP, so you shouldn't use a VPN. To avoid handing out your home WiFi IP, you can use a public WiFi point or use cellular which cycles IPs more quickly.

Re: GrapheneOS – Break Free from Google and Apple

#836
post #219

Earlier quoted context omitted.

You may be surprised to realise that you actually don't understand the difference between AOSP and Android :-). See https://news.ycombinator.com/item?id=47047167

You're vastly exaggerating that difference. It's ridiculous to say it's incorrect that GOS is not Android based.

> It's ridiculous to say it's incorrect that GOS is not Android based.

I totally agree, but that's not what I'm saying, is it?

Someone said:

> "Break Free from Android and iOS" looks inside - Android

I answered that there is actually a nuance that is relevant in the context of this article. Ignoring that nuance to make the article sound stupid is simply unfair.

Re: GrapheneOS – Break Free from Google and Apple

#837
post #651

Earlier quoted context omitted.

There's a massive open source app ecosystem for Android which is far larger than the subset available in F-Droid. Open source does not imply private or trustworthy. Completely trusting applications with access to all your data with no insight in to what they're accessing or sending to services means you wouldn't know if your privacy is being violating anyway.

The (desktop) Linux security model is different. You trust the distro maintainers in the same way you trust the GOS devs, and instead of "app sandboxing" you use user accounts, containers or VMs to protect personal information. The Android security model makes sense in the context of laypeople using mostly commercial malware on the stock OS however.

> The (desktop) Linux security model is different

In that it doesn't really exist. Sure, linux has all the capabilities to do it properly, but defaults matter in security so the way it currently works, basically every program has access to everything actually important (personal files, photos, ssh keys, etc). It just can't upgrade your GPU driver.

Re: GrapheneOS – Break Free from Google and Apple

#838

Been using this for about a year on a p9 pro. It works very well. I hear the google tap to pay does not work, but I've never tried it. However Vipps with their tap to pay works fine. BankID works but not with biometric login, which some things require IIRC. And for some reason DnB private works fine, but you are not allowed in on the corp app. It's mind boggingly stupid that they lock down apps like this, when you ca…

> I can use my bank on some linux distro, Yes, I've been doing that since 2009 on Ubuntu and Debian but there are several caveats. One of those banks has its own TOTP device and they won't replace it when the battery dies. It's almost 20 years old now. Then it's the fingerprint sensor on my phone. The other banks authenticate accesses and many operations with either their app + fingerprint (all of them) or SMS (some…

It's not really a requirement of a Pixel device. It just happens to be the case that Pixel devices currently are the only devices meeting the hardware requirements listed in the FAQ: https://grapheneos.org/faq#future-devices. The hardware requirements don't contain exoctic things but non-Google and non-Apple companies until now just fail to deliver on the security front. It's also not that GrapheneOS catered these requirements to fit to Google and Google only. They are actively working with an OEM partner since June 2025 to help them meet the hardeware requirements for a subset of their future devices. So they are even willing to assist companies to meet the requirements if they have the ambition to do so. The OEM is not yet disclosed, the launch of the device will be somewhere in 2027.

Re: GrapheneOS – Break Free from Google and Apple

#839
post #791
post #712

Earlier quoted context omitted.

> I fear "Android" will continue to be understood as a word for either variant Well, "Android" generally means either variant. I run GrapheneOS and I call it Android. If someone asks, I say I run Android, not GrapheneOS. Actually in terms of experience, it is Android to me. But in a context where we oppose GrapheneOS to Android, then I think it's important to be clear. GrapheneOS belongs to the family of OSes that ar…

I take that point, that's a useful thing to do. Not sure that many people even in threads like these will get it unless explained (at which point you might as well word around it) but on a close forum or chat this is definitely a useful approach

I am honestly getting tired of people complaining about the fact that there is a less ambiguous way to name things. Those projects are more and more converging into saying "AOSP-based" (but that's evolving, interesting how language works!). GrapheneOS always says AOSP-based. The English wikipedia page of LineageOS says AOSP-based. In the past we used to call them custom ROMs, but the naming has evolved.

Of course, it is only relevant when it is relevant.

You can join a discussion about cars, where people talk about their Honda or Opel or Fiat, and when they ask you what you drive, you say "a car". And when they say "no but... which brand", you can go on and explain to them that they don't know how to use language, that "a car" is the common way to talk about those vehicles and that nobody in the world cares about a brand, even though you just witnessed a discussion where those people did care about the brand. Sure, you can do that.

But don't expect to have an enjoyable social interaction this way. And don't tell me "but you started it!": I answered to a comment that was making the article sound ridiculous by proudly conflating the two concepts.

Re: GrapheneOS – Break Free from Google and Apple

#840

Earlier quoted context omitted.

GrapheneOS requirement of Pixel devices is a dependency on Google too. They are currently working with an OEM to release a non-Pixel GrapheneOS phone in the future.

as long as it is not fairphone. I am out. I don't want to have to choose between privacy and sustainability.

It won't be Fairphone. Fairphone is very far removed from the hardware requirements listed here https://grapheneos.org/faq#future-devices They don't seme to take security seriously at the moment, so the chance is low they are going to make the huge leap needed to meet the requirements. Fairphone heavily markets their sustainability but it's very relative. Fairphone doesn't give proper software support. They don't properly keep up with Android updates and also stop giving updates much more quickly than Google (8 years since Pixel 8) and iPhone. Giving proper software support is also part of what makes a device usable for a longer period of time and hence reduces the need to purchases a new device which has an environmental and climate impact. With regards to the hardware longetivity, Google has good repair programs for their Pixels. It's more difficult and less supported to do repairs yourself but it's certainly possible to repair your device.
Post reply on HN