7 ms·
I'd pick Graphene over Calyx on privacy and security grounds, and Lineage over Calyx on device support or tweakability grounds. Graphene is honestly ahead on t
by Seirdy 5y ago
I'd pick Graphene over Calyx on privacy and security grounds, and Lineage over Calyx on device support or tweakability grounds.
Graphene is honestly ahead on the security and privacy front. MicroG requires very strong privileges and weakens the comprehensive privsep you'd otherwise have; GrapheneOS offers sandboxed play services with the standard SELinux policies for unprivileged Android software.
GrapheneOS also has hardened_malloc, which seems to have the best design for malloc hardening out of any alternatives I'm aware of.
On the userspace side, Graphene uses several of its own apps. One is Vanadium for its webview and browser; it's a hardened fork of Chromium. Check the patchset; it's got a bunch of security improvements and cross-pollenates with Bromite. The most interesting feature they've been working on is per-site JIT toggles.
The list goes on. Few other OSes come close.
Now, if you want to tinker with your phone at the expense of security, Lineage is actually a great option. It has a big community of tweakers and ricers who root their phones and come up with some cool experiments. It also supports a wider variety of devices, including devices abandoned by their manufacturers. Don't expect security updates, though.
- colordrops 5y agoIsn't graphene a huge target for black hats and three letter agencies? I guess no more so than lineage.
- lberrymage 5y agoThere is no evidence to suggest this. GrapheneOS has multiple systemic privacy and security improvements over the stock OS (e.g. hardened_malloc, toggleable network permission, exec spawning), so it's a much harder target to develop a working exploit for when compared to devices running the stock OS.
- phh 5y ago> I'd pick Graphene over Calyx on privacy and security grounds, and Lineage over Calyx on device support or tweakability grounds. I'd pick Calyx over privacy grounds not Graphene. (I totally agree that Graphene beats anyone on security grounds by miles, and depending on your threat model, security could be related to your privacy) > MicroG requires very strong privileges and weakens the comprehensive privsep you'd otherwise have If we're speaking of FAKE_SIGNATURE.... No it doesn't? If implemented properly (I don't know how Calyx do it, but I know I do), only apps in firmware are allowed to use FAKE_SIGNATURE, and if you build your firmware with only microg that has FAKE_SIGNATURE, then only microg can fake signature. Also it can fake exactly one signature, which is Google's. It's probably possible to make that patch better, if some people gives us reasons it is a flaw. Really, please tell me in which threat model does using microg hinders security, maybe we can find a fix. So far, I've never heard any. > GrapheneOS offers sandboxed play services with the standard SELinux policies for unprivileged Android software. With regards to privacy, I take unprotected opensource software over Google trackware no matter the sandboxes you put under it. Windows has a better sandboxing model than Linux, yet I feel much better doing random apt installs, than downloading random Windows apps.
- tholdem 5y agoHow is Calyx more privacy respecting than GrapheneOS by default? Not sure about the defaults on Calyx, but AFAIK GrapheneOS has zero connections to Google. You choose to install sandboxed Play services only if you want to.
- phh 5y agoBy default, Calyx is privacy-preserving, because it doesn't connect automatically to WiFi. You choose to connect to WiFi only if you want to. Yes, I'm very exaggerating the comparison, but still. My point is that the comment I'm answering touts the sandboxed Google Play Services. You can't tout it *and* say it's privacy preserving, it's a XOR.
- lberrymage 5y agoGrapheneOS doesn't automatically connect to Wi-Fi either unless you enable the option. It also has per-connection MAC randomization enabled by default so Wi-Fi is essentially anonymous when you use it anyway. > you can't tout it *and say it's privacy preserving. Why? Sandboxed Play Services has no special privileges on GrapheneOS and thus has the same level of access as any other app. How can it invade your privacy if you don't explicitly give it access to private information?
- strcat 5y ago> By default, Calyx is privacy-preserving, because it doesn't connect automatically to WiFi. You choose to connect to WiFi only if you want to. Going to simply interpret this as unhelpful sarcasm. > My point is that the comment I'm answering touts the sandboxed Google Play Services. Sandboxed Google Play isn't included in GrapheneOS. Users can choose to install apps which include Google's libraries and use the Google Play SDK. Regardless of whether people use sandboxed Google Play or microG, they're using the Google Play code inside each app using it. The whole point of sandboxed Google Play is that users can optionally choose to install Play services and the Play Store in the user/work profile(s) of their choice with it receiving ZERO additional access or privileges compared to the Google libraries / Play SDK within each app using it. GrapheneOS does not include Google Play and has no special sandbox for Google Play. It includes a compatibility layer for users to run it in the full, strictest API 32 app sandbox with all the standard GrapheneOS enhancements. It does not receive any special access or privileges. It can't do anything the Google libraries within apps can't already do themselves. The Sandboxed Google Play compatibility layer also includes the ability to redirect APIs like location services to the OS implementation. By default, location services are redirected to the OS implementation, so users don't need to give Location access to Play services. Of course, if users grant Location to apps using Google Play, they're trusting the app and all the included libraries, and any app using Google Play is using Google Play libraries. You can see for yourself that the full featured Google Maps app completely works without Google Play, and that their Ads SDK and other libraries work without it. Their libraries can do everything that sandboxed Google Play can do on their own without it. That's the whole point. Google Play is not required to contact Google services. Apps can do that on their own, and Google's libraries within those apps are fully capable of doing it. They largely choose not to implement fallbacks for features, but in some cases they clearly do as you can see from Google Maps and the Ads SDK. Only apps using the Lite variant of the Ads SDK need Google Play services for it to work. And again, sandboxed Google Play is not included in GrapheneOS. CalyxOS includes microG as part of the OS and encourages using it through the setup wizard. That uses Google's proprietary services and code. The Play code in each app is not replaced. It has a bunch of serious privacy and security issues from not implementing all the expected security checks, in some cases because microG is ideologically against enforcing the security model for things like location services. CalyxOS doesn't simply include microG with users encouraged to use it. They use Google services by default, with no way to turn them off. They significantly roll back the security model of the OS. They recently went almost 4 months without shipping the browser or Android security updates, including multiple vulnerabilities caught being exploited in the wild and announced as such in bulletins. How are users supposed to get privacy and security from an OS which lacks consistent security updates and has no problem rolling back or bypassing the standard OS privacy and security model? It isn't simply not a hardened OS. It's a dangerously insecure one.
- joecool1029 5y ago>Don't expect security updates, though. For the binary blobs, but for the opensource components all supported builds are current on monthly android security patches. (well, in review for probably a few days on April: https://review.lineageos.org/q/topic:R_asb_2022-04 https://review.lineageos.org/q/topic:R_asb_2022-04 ) LineageOS maintainers also pull android servicing branch back to cm14.1 tree too if you wanted to try your hand at building on a previously supported device.