3 ms·
Custom ROMs have had just about enough of being Android's second-class citizens
- Sayrus 2y agoSince the link is a bit hidden within the article, here is the relevant thread on Graphene's Mastodon instance: https://grapheneos.social/@GrapheneOS/112878067304840664 https://grapheneos.social/@GrapheneOS/112878067304840664
- yunohn 2y agoI learned nothing from that thread tbh - felt like they were continuously parroting the same thing without explaining any real details.
- Zak 2y agoWhat comes preloaded on Android phones isn't simply the Android Open Source Project (hereafter AOSP), but Android plus Google Mobile Services (hereafter "Google Android") and whatever customizations the manufacturer adds. One of the features of Google Android is a remote attestation service to prove to apps that the OS has not been modified. Google makes this available to its OEM partners whose operating systems meet certain security standards, called CTS, but not to open source projects like GrapheneOS. On older devices, the remote attestation feature can be software-only, and that's easily faked. Newer devices support hardware-based attestation, which is not. A significant number of third-party apps refuse to run on devices that do not attestation, something Google makes no attempt to discourage. If you recall an uproar from the tech world when Microsoft was trying to push something called "trusted computing", this is the same kind of thing. In the Mastodon thread, GrapheneOS asserts that many OEM Android ROMs do not actually meet CTS security standards while GrapheneOS does. GrapheneOS supports the hardware-based attestation mechanism so that devices can prove they are running unmodified GrapheneOS, but apps using Google's attestation service will not accept that. GrapheneOS wants Google's mechanism opened to third parties provided they meet the same security standards.
- warkdarrior 2y agoShouldn't GrapheneOS work to convince those third party apps not to use Google's OS attestation?
- Zak 2y agoGrapheneOS already does that, and provides code and documentation for anyone who wants to use attestation and support GrahpeneOS but with Google being the OS and SDK vendor, app developers usually take the path of least resistance. One might describe that situation as Google using market power to exclude competitors, which is illegal. https://grapheneos.org/articles/attestation-compatibility-guide https://grapheneos.org/articles/attestation-compatibility-gu...
- TheCoelacanth 2y agoThey are doing that too. Shockingly, it's actually possible to do multiple things at once.
- 486sx33 2y agoYou could probably make the case that googles retarded “open source” android isn’t at all, violates the GPL and, separately, initiate an anti trust lawsuit purely on the way that play store API killed blackberry
- KetoManx64 2y agoIt is though, you can build AOSP without any of the Google Play store services and it will work just fine. Download some apps from F-droid and you will have a fully functional modern smartphone. I'm running a LineageOS based ROM on the phone I'm typing this out on with no Google Apps or services installed. Newpipe for YouTube, Waze for maps, MicroG for open source implementatiom of Google Services APIs. Works great
- TheCoelacanth 2y agoFully functional except for some key functionality like NFC payments which generally requires hardware attestation.