5 ms·
/e/OS falls significantly behind the other alternative Android systems with regards to privacy and security. Please see this independent comparison table: http
by _rdvw 3y ago
/e/OS falls significantly behind the other alternative Android systems with regards to privacy and security.
Please see this independent comparison table: https://eylenburg.github.io/android_comparison.htm https://eylenburg.github.io/android_comparison.htm
And additionally the reviews by Kuketz: https://www.kuketz-blog.de/android-grapheneos-calyxos-und-co-unter-der-lupe-custom-roms-teil1/ https://www.kuketz-blog.de/android-grapheneos-calyxos-und-co...
See also my table that shows historical release dates for monthly Android Security Bulletins: https://divestos.org/misc/a-dates.txt https://divestos.org/misc/a-dates.txt
and the Chromium (WebView): https://divestos.org/misc/ch-dates.txt https://divestos.org/misc/ch-dates.txt
- notyoutube 3y agoI'm using microg's lineage, and something I was wondering when choosing a rom was, how secure are all those roms in terms of supply chain/developpers. There are many, with no big reassuring name behind, and it's hard to trust that what looks like a random rom from the internet is not just a full trojan horse. It would be nice to have just the one or two options, with app store and some kind of official entities backing (say, states, or universities, or distros).
- geraldhh 3y agoafaik microg is developed by a german guy with a grant from the goverment. can't get more legit than that in the android ecosystem :D
- commoner 3y agoI'm having a great experience using microG, which lets me selectively enable and disable cloud messaging for every app that attempts to use Google Play Services. microG does not implement the ads and tracking (Google Analytics) APIs of Google Play Services. microG also lets me use Mozilla Location Services to replace Google Location Services, which obtains a location much faster than GPS alone. With microG being free and open source, I trust it much more than the proprietary Google Play Services, even with sandboxing applied. It's weird that the article doesn't mention microG even once, since it's what /e/ uses instead of the Google Play Services client.
- geraldhh 3y ago> It's weird that the article doesn't mention microG even once true seems like the whole aftermarket android ecosystem hinges on the functionality of this, mostly unrecognized, component
- izacus 3y agoIt's safe to assume that there's very little-to-none supply chain protection. It's mostly all single people or tiny groups of people releasing this.
- notyoutube 3y agoSad to hear. It feels like the EU could fund some entity to manage, develop and distribute such a degoogled android with only a very small fraction of its other spendings, and that would help a lot with reducing google/apple's hold on the european market… A cheap deal.
- izacus 3y agoAndroid is a Google project through and through, so I'm not sure if basing the result would actually be "reducing google hold on european market". For that you'd have to actually have a product that isn't developed by one of those corps.
- notyoutube 3y agoI mean, it would be a step in a better direction, wouldn't it? One might start with something like aosp/lineage and potentially fork from there if needs be, or ask of companies to support this alternative rom, etc.
- greentea23 3y agoDegoogling is a misnomer imo. It's not about not using anything from Google or Apple at all. They both contribute to Linux, clang/llvm and other core open software tooling after all. It's about not using unaudited closed source code which cannot be proven to be secure or private, as well as getting away from the online services Google/Apple bake into their operating systems that spy on and tell on users as a requirement to boot the device at all. There's also some cool features that are blocked by both. Since AOSP is open source and the API is easy to target by 3rd party app stores, it's perfectly legitimate to use it as a starting point. There may come a day where Google stops releasing it in such a usable way though, and a more complete fork will be necessary to maintain OS sovereignty.
- kaba0 3y agoGrapheneOS is by far the most secure option. Unfortunately, it’s only for pixels (as the former “director” (in my opinion rightly) claims that there is not much point to “extreme” security if the hardware itself is already vulnerable, and most android phones have very shitty hardware security)
- 4ggr0 3y ago> not much point to “extreme” security if the hardware itself is already vulnerable What I don't get about this is that a lot of people who install custom ROMs do so, to ungoogle their devices, and just plainly get rid of Google. So why exactly is Google deemed to be a safe hardware vendor?
- eptcyka 3y agoThey have a secure boot chain and they allow users to use their own signing keys. Samsung for instance also has verified boot, but doesn't allow users to use their own keys. Thus, the boot process is as secure using GrapheneOS as it would be using stock Android, but this just isn't the case for any other device manufacturer.
- 4ggr0 3y agoYeah but that's still SW, if we talk about HW then using Google-HW to get rid of Google seems a bit weird. I know that Google is not manufacturing these parts, but they're probably not open-source either. I don't care that deeply about privacy/security, just being a bit devils-advocat-y.
- smallerfish 3y agoIt depends on why you want to de-google. Running Android means that you're plugged into their ad-analytics data collection. Firmware layers are extremely unlikely to be reporting personalized analytics into that engine. On the other hand if you're trying to avoid an oppressive state, you probably want to avoid any potential for a sub-poena to a big corp yielding information on you; in which case considering fully open firmware makes much more sense.
- 3abiton 3y agoThere are no real answers to this, taking trust out of the equation, the only way to be sure is to inspect the source code and build it yourself. On a side note, it's always possible to hook dns to a remote piehole setup, and monitor connections. Aside from the security issues related to roms, there are still the binary blobs from OEMs.
- maratc 3y ago> It would be nice to have just the one or two options, with app store and some kind of official entities backing I won't doubt that you know that iPhone is a thing.
- nicman23 3y agodont know how up to date it is but you can use android auto without gapps https://github.com/sn-00-x/aa4mg https://github.com/sn-00-x/aa4mg
- crossroadsguy 3y agoMaybe yes. But then look at the list of supported devices and you’d see why. Graphene is barely supported. It just supports Pixels/Google. What privacy is that which is not accessible?
- _rdvw 3y agoMy DivestOS supports decade+ old devices and provides monthly security updates for seven versions of Android, no other project does this. GrapheneOS has good reason to only support Pixel devices, they consistently do the right thing with regards to relocking, verified boot, CFI/SCS support, strongbox support, and even now MTE support. Many other devices fail to support these, eg: https://divestos.org/pages/faq#kernelCFI https://divestos.org/pages/faq#kernelCFI Even the FP4 shown in the article is fundamentally broken and trusts the AOSP public test-keys for verified boot: https://divestos.org/pages/faq#deviceBootloader https://divestos.org/pages/faq#deviceBootloader
- crossroadsguy 3y agoFor me bank and finance apps are very important and they all stop working without Google services. One of the reasons I am stuck on iOS. Not to me mention with every patch and release there's a risk of doing the whole flashing/setup again. Also, if there's a need for service some OEMs just refuse to even entertain you if there's another ROM installed.