26 ms·
Graphene OS: a security-enhanced Android build
- VladVladikoff 1y agoThis is almost enough to make an Apple fanboy switch to android. Maybe I’ll get a second phone just to try it out. Which model would be best?
- BLKNSLVR 1y agoIf it's just for trying out, then go for the cheapest second hand Pixel that's still supported by GrapheneOS and still has a battery that can hold charge for as long as you need it to for testing. I bought a second hand Pixel 7a for my recent migration. Battery isn't great, but it's good enough to get me through a day.
- strcat 1y agoBattery life improved a lot with the 9th gen Pixels other than the Pixel 9a due to the dramatically more efficient cellular radio. Set it to "4G" or the GrapheneOS added "4G only" as the cellular network mode and you should save a lot of battery life compared to having 5G enabled all the time. Battery life heavily depends on the apps, network and overall configuration. It's easy to end up with bad battery life with lots of apps doing their own push, etc. GrapheneOS users tend to avoid using Google services when possible and this has a battery life cost when using apps like Signal with their own push systems. In the case of Signal, Molly is a fork with UnifiedPush support that's more efficient but it requires running a server to convert FCM to UnifiedPush since Signal doesn't support it.
- mbananasynergy 1y agoAnything 8th gen and later would be best, as those models support MTE which is a huge security feature not present on 6th or 7th gen hardware. Our recommended devices can be found here: https://grapheneos.org/faq#recommended-devices https://grapheneos.org/faq#recommended-devices
- deleted 1y ago[deleted]
- ranger_danger 1y agoMaybe my tinfoil hat is on too tight, but I always thought it was interesting that Graphene OS places so much blind trust in a proprietary black box security chip from Google that they pinky-promised to open source but never did.
- deleted 1y ago[deleted]
- sigmar 1y agoAre you referring to the titan M2? why do you describe Graphene OS putting "so much blind trust in" it? I don't think they put much trust in it besides using it for storing keys and for their "Auditor" app
- deleted 1y ago[deleted]
- fooqux 1y ago> I don't think they put much trust in it besides using it for storing keys Ummm. Was this sarcasm that went over my head? Because if not, I have a hard time thinking of anything that requires as much trust as your private key storage.
- bjackman 1y agoIf you think the org that produced the hardware might have backdoored it, architecting your software to avoid the TPM or whatever is dumb. Targeting Google HW at all is an unavoidable act of complete trust so you might as well use the HW properly. Also, why would Google bother backdooring their special HW when 99.999% of its users are anyway gonna be running a totally Google-controlled proprietary SW stack?
- perching_aix 1y ago> Targeting Google HW at all is an unavoidable act of complete trust Doesn't the existence of FHE downgrade that to just "complete practical trust" at least? Not that I know of it being employed, but that it could be, and that it may be worth shouting out exactly cause of how niche and impractical it is.
- waltercool 1y ago[dead]
- z3c0 1y agoI think Graphene gets posted here yearly. Having tested a variety of ROMs dedicated to different elements of security, I can attest that Graphene allows the most "normal" phone usage compared to many others. The biggest factor is the sandboxed Google Play Services, which allow you to use a lot of apps that you wouldn't be able to otherwise. I've used Lineage without MicroG, as a comparison, and that's becoming more-and-more unusable every day some lousy Android developer tethers their company's app to some feature exclusive to Play Services.
- ranger_danger 1y agounfortunately it doesn't support google pay, which is a dealbreaker for me
- DANmode 1y agoPhone-wallet case.
- mbananasynergy 1y agoGoogle Pay is not available on any alternative OS due to Google blocking it. It's unfortunately their choice, rather than a lack of support on our end. Depending on where you are in the world, there might be other NFC payment options for you. In the EEA and UK, Curve pay works. Paypal made their own solution and is rolling it out, starting with Germany. Both work with GrapheneOS. Many banks also have their own solutions.
- nicman23 1y agoyeah but lineageos with μg is quite good.
- SchwKatze 1y agoMy only problem with Graphene is the ridiculous low number of supported devices, i know I know, security reasons and so on. But I would accept an lower security hardened version but at least have Graphene instead of Google's junk
- metalman 1y agohttps://calyxos.org/ https://calyxos.org/ does a few other devices, seems aimed strait at true privacy
- mbananasynergy 1y agoGrapheneOS community manager here. I would recommend checking out https://eylenburg.github.io/android_comparison.htm https://eylenburg.github.io/android_comparison.htm for a third-party comparison of these projects. They're not really similar. CalyxOS downgrades security compared to the Android Open Source Project, often falls significantly behind on standard Android privacy and security patches as is the case right now (they still haven't ported to Android 16 which is required to have the latest patches) and doesn't provide similar privacy or security features. Features like Contact Scopes, Storage Scopes and our Sensors permission toggle are some of the privacy features includes in GrapheneOS. Privacy necessitates security. The security provided by GrapheneOS is in order to be able to protect privacy.
- spaqin 1y agoAccording to the link you provided, it does seem to be ahead of stock Android (assuming AOSP) and LineageOS, disproving your point that it's falling behind. The point of the OP is not that it would be better than your solution anyway; rather, if you have a device unsupported by GrapheneOS, Calyx would be better than nothing.
- rfoo 1y ago> Calyx would be better than nothing. Depends on your threat model. If Google, low-effort scam apps or being profiled by apps are your only adversary, then that's true. If random threats on Internet or APTs pwning your phone, or being forensic-proof are part of your threat model, then Calyx is strictly worse than stock.
- perching_aix 1y agoThat project background reads suspicious as all hell, but then the thing does do what it says on the tin from all the news I see, so go figure.
- mbananasynergy 1y agoHi, GrapheneOS community manager here. There are some corrections that we have contacted the author about regarding the history of the project. They initially e-mailed us to ask a few questions but seems to have maybe misunderstood something. For clarity, GrapheneOS is the continuation of CopperheadOS, not a new project that spun off from it. As an example, it can be seen that our repositories and legacy bugtrackers are ours: -https://github.com/GrapheneOS/platform_manifest/forks?include=active&page=3&period=&sort_by=last_updated https://github.com/GrapheneOS/platform_manifest/forks?includ... -https://github.com/GrapheneOS/platform_bionic/forks?include=active&page=1&period=&sort_by=last_updated https://github.com/GrapheneOS/platform_bionic/forks?include=... -https://github.com/GrapheneOS-Archive/legacy_bugtracker/issues?q=is%3Aissue%20state%3Aclosed&page=34 https://github.com/GrapheneOS-Archive/legacy_bugtracker/issu... It's a direct continuation, but was renamed to GrapheneOS post the failed takeover attempt. GrapheneOS has persevered and is all the stronger for it. Over a decade now. :)
- onli 1y agoThat is not correct, or at best a very questionable interpretation. Graphene is a continuation of the open source side of copperhead, but the copperhead project continued to exist even though the Graphene dev sabotaged it by deleting the cryptographic keys. Copperhead is the continuation of copperhead is my reading, Graphene is just also a continuation in a different project. Why lie about something so easy to disprove by a bit of research? There were a bunch of articles about this back then, even wikipedia states it clearly.
- other8026 1y agoDid you look at the links? > Fuzion24 / platform_manifest Created 10 years ago Updated 10 years ago
- usuallymatt 1y agoI was tempted to use this but when I looked into the team behind it there seemed to be some issues as exposed by Louis Rossman here: https://youtu.be/Dl1x1Dy-ej4 https://youtu.be/Dl1x1Dy-ej4. Instead, I installed CalyxOS and have been using it over a year now and I'm very happy with it. Check it out.
- deleted 1y ago[deleted]
- Scrubbed4426 1y agoThis a video where he openly bullies someone, live streams their private messages where they're getting upset with him bullying them and repeatedly, blatantly lies about them including falsely claiming they're insane, etc. Rossman lied about stopping using GrapheneOS and has continued using it after that point. The video was made to direct harassment towards the project and founder after the project refused to work with Rossman. He has done similar things to others, labeling them as insane and delusional.
- bernoufakis 1y ago> This a video where he openly bullies someone, live streams their private messages where they're getting upset with him bullying them and repeatedly, blatantly lies about them including falsely claiming they're insane, etc. That is the most disingeneous take on the video. The claim this kind of commenters that freely carry water for the toxic GOS (ex-?) lead developer is the exact reason why Rossmann made the video. The evidence is all there for the public to see. Daniel does not get to essentially harass people he disagrees with after they have been asked to not contact them, threaten them to "publicly expose them" and get away scott free. Being a genius at cyber security or autistic does not give one a free pass to treat other like garbage. > The video was made to direct harassment towards the project and founder after the project refused to work with Rossman. The video was made to expose the harassment of the project founder toward Rossmann, when the former contacted him out of the blue with frivolous accusations after they parted way a year earlier due to un-reconciliable disagreements. > He has done similar things to others, labeling them as insane and delusional. No evidence provided, as usual.
- aussieguy1234 1y agoThe one thing that prevents me from switching my Pixel over is the lack of support for emergency services to see your location if you call the emergency number. I know this because I called twice while having GrapheneOS installed. I do some watersports and always take my phone with me, so letting emergency services see my location is good for my safety in case I ever got into trouble on the water. I also have a PLB, but I like to have two devices for redundancy, as is best practice.
- cromka 1y agoThis should be higher up.
- strcat 1y agoGrapheneOS supports E911. It doesn't have Google's proprietary Emergency Location Services implemented as part of Google Play services which some countries depend on. We plan to implement the same standard it does for regions without support for a variant of E911: https://github.com/GrapheneOS/os-issue-tracker/issues/1174 https://github.com/GrapheneOS/os-issue-tracker/issues/1174
- aussieguy1234 1y agoIt the Australian emergency number (000). Not sure if they're using the Google Play services implementation of Emergency Location Services.
- strcat 1y agoIt sounds like you're in a region not supporting E911 but rather depending on Google's proprietary Emergency Location Service. We plan to make our own implementation of what that provides: https://github.com/GrapheneOS/os-issue-tracker/issues/1174 https://github.com/GrapheneOS/os-issue-tracker/issues/1174 GrapheneOS supports E911 and has our own network location implementation you can enable which gets used by it. Unlike Google's implementation, our network location is based on location position estimation similarly to iOS. Unlike iOS, we'll be providing full offline support for it.
- mjbale116 1y agoWhile a big proponent of this, to my mind, it seems a bit counterintuitive to place your trust in a community who will probably cannot be held into account once some bad actor slips into their ranks, creates a bad patch and empties my bank account.
- gruez 1y ago>counterintuitive to place your trust in a community who will probably cannot be held into account once some bad actor slips into their ranks Open source software is everywhere. Do you think Microsoft or Redhat going to be held to account if they accidentally added some backdoored OSS code? Moreover all of the development happens in the open and you can build it yourself. I'm not sure what the alternative is. Just trust Apple has their shit together with iOS?
- rtkwe 1y agoYou say the same thing about Linux? This feels like old open source FUD, the only case I know of off hand is the xz util backdoor and that was found and patched before the malicious patch had made it into the main distribution channels.
- mbananasynergy 1y agoHi there. GrapheneOS community manager here. It's important to note that GrapheneOS is not some niche barely-used project. It has existed since 2014 and is used by multiple hundreds of thousands of people at this point. There are also many eyes on the project through people forking it to make their own products, people maintaining their own builds etc. GrapheneOS is also reproducible in addition being open source. On our side, we are very particular about accepting outside contributions if they don't need meet our standards, and code is heavily reviewed within our team before being merged. I'd also recommend giving https://grapheneos.org/faq#audit https://grapheneos.org/faq#audit a read through. All in all, your concern, while valid, isn't something that's likely to happen precisely because we're very aware of situations where it has (see xz) and are therefore very vigilant. The kind of thing you're worried about isn't likely to come from a big project like GrapheneOS that has many eyes on it, but rather something small that's used everywhere and barely has a couple of devs working on it, if that (again, see xz).
- throwaway-0001 1y agoThe main missing feature is password under duress that would open a different “user”. So even if you’re forced to give away your password they won’t get to the real account (some hidden profile or similar). At least hidden profiles would be good enough for basic protection. They have this which wipes your device, but you can get killed under duress. https://discuss.grapheneos.org/d/14722-using-duress-password-example https://discuss.grapheneos.org/d/14722-using-duress-password...
- OsrsNeedsf2P 1y agoI've seen this be requested for years from various mod users. Is it too difficult to implement or something?
- throwaway-0001 1y agoThey say a hidden profile is not secure enough so not worth implementing. I rather have this hidden profile that would stop 99% of criminals than what they have now. I think their approach to this project is to deliver real security at the cost of features.
- mbananasynergy 1y agoGrapheneOS community manager here. The problem with something like this is that it cannot be reasonably hidden when it would be exposed by someone using basic tools. Our Duress PIN/Password feature doesn't make any attempts to mask itself, precisely because we think doing that only gives people a false sense of security. We think there's a good chance a motivated adversary is going to be familiar with GrapheneOS and its features, and the more mainstream it becomes, the more this can mean "your abusive significant other" rather than someone at the border. The moment people know this feature exists, it can become dangerous even if you don't use it. You can be threatened to unlock, and even if you do, the adversary can choose to not believe you since they can think you're just hiding it. That puts you in a dangerous situation where they think you can provide something that's literally not there. It's a very difficult problem to solve, and we don't think that proposal can solve it.
- ChrisArchitect 1y agoRelated: Cops say criminals use a Google Pixel with GrapheneOS – I say that's freedom https://news.ycombinator.com/item?id=44658908 https://news.ycombinator.com/item?id=44658908 Cops in [Spain] think everyone using a Google Pixel must be a drug dealer https://news.ycombinator.com/item?id=44473694 https://news.ycombinator.com/item?id=44473694 ICEBlock, an iOS Exclusive https://news.ycombinator.com/item?id=44672521 https://news.ycombinator.com/item?id=44672521
- minimalist 1y agoLast I heard, Google discontinued publishing device trees and driver binaries for Pixel devices with their recent changes to their stewardship of the AOSP [0]. Was it something definitive or are they merely delayed? If the practice is being discontinued, what would be the reason why? Doesn't publishing these artifacts create a business case for customer demand for the Pixel devices? Or is there some cost that outweighs the benefits? Is it maintainer overhead? I didn't bring this up when it was a news story last month because there was a lot of cynicism in the thread, but I am genuinely curious. I am really grateful for both GrapheneOS and Google for creating a phone platform that Just Works for the essential stuff and that I can reasonably recommend to non-technical people! [0]: https://news.ycombinator.com/item?id=44259921 https://news.ycombinator.com/item?id=44259921
- NewJazz 1y agoI heard unsubstantiated rumors that it was somehow antitrust-related. If they are selling off their device business (again), then it makes sense that the device drivers would not be part of AOSP...
- strcat 1y ago> If they are selling off their device business Android and Chrome are potentially going to be split from Google: https://www.nytimes.com/2024/11/20/technology/google-search-chrome-doj.html https://www.nytimes.com/2024/11/20/technology/google-search-... (https://archive.ph/egRL4 https://archive.ph/egRL4) Pixels are no longer the Android reference devices. An Android company ending up with the OS, Google Play and Google's OEM partners wouldn't need Pixels. That's a possible reason for the change. However, the simplest explanation is that they're continuing to take cost cutting to an extreme where it negatively impacts their long term revenue far more than the money it saves. A lot of Pixels were sold due to first class support for using other operating systems including it not voiding the warranty.
- strcat 1y agoAndroid 16 no longer provides device trees for Pixels as part of the Android Open Source Project. It's important to note it doesn't provide those for any other devices. There are no other OEMs providing similar AOSP support. A few OEMs publish more basic device trees for older Android versions. This was Pixels losing one of their advantages compared to non-Pixels but it was never one of our hardware requirements, which are listed at https://grapheneos.org/faq#future-devices https://grapheneos.org/faq#future-devices. It isn't part of why Pixels are the only devices meeting our requirements. We're working with a major Android OEM to change that though, hopefully for 2026 or at least 2027. GrapheneOS typically ports to new yearly Android releases in a couple days and tends to have it reach the Stable channel in under 2 weeks. We completed our initial port to Android 16 in a similar time period after the release on 2025-06-10. However, we then had to reimplement device support in a similar way to how we would support a non-Pixel device. Our initial production release based on Android 16 was published on June 30th. As usual, we had to spend around a week making a series of releases fixing regressions reported by users. It reached our Stable channel on July 8th. Since our port to Android 16 took significantly longer than usual, we backported most of the Android 16 firmware, all of the kernel drivers and parts of the userspace device support to our now obsolete Android 15 QPR2 branch and did a few more releases based on Android 15 QPR2 where we were able to provide the full 2025-06-05 patch level which also turned out to be the full 2025-07-05 patch level due to no vulnerability fixes in the July 2025 Android Security Bulletin or Pixel Update Bulletin. This was an unusual approach and not generally a reasonable way of doing things. We were able to do it successfully. It won't be nearly as much of an issue going forward since we dealt with building the new automation we needed. Our port to Android 16 QPR1, Android 16 QPR2, Android 16 QPR3, Android 17, etc. shouldn't be nearly as difficult and we should get back to our typical porting time for major releases.
- h4kunamata 1y agoIt is insane the amount of "news" about GOS that somehow get things wrong. It cannot be coincidence but misinformation on purpose. On Twitter, GOS team have to often reply with the actual correct information, it is insane man. Reading some comments here regarding hidden profile, security through obscurity doesn't and will never work. Add to that the fact that GOS is well known now, those people think that if they were forced to give their phone away, they won't have to disclose the hidden profile??? Newbies!! I don't wonder why GOS team never bothered to prioritise this. I have been using GOS for a few years now, it is perfect, full control over everything, the teams support is like no other and full transparency about everything, the release notes are like no other. I really hope this project will never die.
- throwaway-0001 1y agoI know you talking about my hidden profile. But let say you have a banking account you don’t want people to find out. Currently you can only keep it on the main profile or any other secondary, which are easily visible. With my approach you can minimise 99% of the risks for most users. And even so, you can have 2 hidden profiles. So you can always show the decoy hidden profile.
- bugsMarathon88 1y agoGraphene is a fantastic operating system for Pixel devices. Simple, reliable and with plenty of security and privacy features to make you feel warm and fuzzy. System updates are automatic, actual phone functionality is flawless, perhaps the only complaint to be had is the quality of camera, which probably lacks proprietary drivers. Signal works fairly well - even without abusive Google Services installed, making this a perfect daily mobile driver. Much gratitude to the developers of this project.
- gf000 1y agoDidn't try it in a long while, but I remember being able to run the proprietary pixel camera app just fine.
- mbananasynergy 1y agoGrapheneOS does not degrade the camera quality at all. The quality will depend on the app being used. If you use Pixel Camera on GrapheneOS, you'd be getting the experience you'd get on stock OS using that same app. Similar for our built-in camera app.
- jrexilius 1y agoI just installed Graphene on a new pixel. I've only used it for two days, but I got that same feeling of "finding buried treasure in your backyard" I got when I first installed Linux in 1999. I can't believe this amazing software is free in all senses of the word. It is a TON of work and they got so much right. The security and usability settings give all the grainular control I've known was possible and wanted for a long time. I see some core team on this thread, so just wanted to say THANK YOU! Awesome job! Keep fighting for the users! I'm totally the wrong person to offer recommendations on mobile, but so far it works very well for me, but then, I use almost no third party apps, and none of them are Play store only. My only complaint is the hardware (outside of their control).
- 1024core 1y agoWhere do you get the apps from? Google's App Store?
- robmusial 1y agoF-Droid app store. https://f-droid.org https://f-droid.org
- morserer 1y agoAurora Store on F-Droid is a FOSS frontend for the Google Play Store that is a seamless drop-in. Requires no Play Services, nor an account.
- bboygravity 1y agoBut than the apps you download (your banking app) require play services right? So then what's the point of having a Play Store without Google Play services?
- ThePowerOfFuet 1y agoMany apps claim to require Play Services, but all my (several) bank apps work perfectly on GrapheneOS. No notifications because they rely on Google, but that is more feature than bug in my books. Signal brings its own notifications, so they work perfectly. The only app which was broken to the point of unusability was Too Good To Go, which demands that you pick locations on a map which relies on Play Services; the manual city entry is broken. I use Google Maps only in Firefox Focus, but I've heard that builds of Google Maps up to about a year or so ago didn't rely on Play Services, and with Aurora Store you can manually enter a build number to install. tl;dr: 10/10, fabulous experience.
- b8 1y agoI'd install Graphene OS in a heartbeat on my Pixel if they'd add support for Google call screening and feature like Hold for me. Thise features are why I bought my pixel and it's too much of an inconvenience to go without them now. Spam calls have went down significantly and has saved me a lot of time.
- aesh2Xa1 1y agoI believe spam detection in the Google Phone app does work on GrapheneOS. For spam, install their sandboxed Google Play, and then install Google's Phone and Speech Recognition & Synthesis apps. For SMS/MMS/RCS spam, you'd use an app supporting blocking (e.g., Google Messages). I imagine that Hold For Me works if you also install the Google app and whatever other dependencies.
- largbae 1y agoThe most fun feature of GrapheneOS is the ability to look at the logs of any app at any time from the App Info page.
- unlikelyusernam 1y agowow I had no idea that feature was even there. Thanks for the heads up :)
- Sytten 1y agoBeen using it for the past two years and supporting the project. I personally love it but you do have to tinker a bit once in a while so I would hesitate to put it in the hands of my parents (though I bought them pixel just in case). Google Pay not working is mildly annoying (hoping to get PayPal or Curve eventually). Android Auto works but I didnt yet try to make voice commands work. Some app behave weird if you block access to the sensors (though it is nice to be able to do it). Sandboxed google play works great for the most part.
- hft 1y agoMy workaround for using both NFC payments and Graphene OS is wearing a Google Pixel Watch (1). All other Google Wallet features besides NFC payments should work. [1] https://discuss.grapheneos.org/d/475-wallet-google-pay/4 https://discuss.grapheneos.org/d/475-wallet-google-pay/4
- microtonal 1y agoSadly that solution does not work everywhere. In a lot of countries, Google Pay cards are added by the bank's app and it's on the bank to support rolling out cards on WearOS as well. A lot of banks in my country only support putting a card in Wallet on phones, but not WearOS watches (not sure if it is laziness on their part or whether security of WearOS watches is not deemed acceptable in general due to the lack of secure elements, shorter/no PINs, etc.).
- icar 1y agoCurve NFC payments work for me.
- deleted 1y ago[deleted]
- rdescartes 1y agoWhy firefox in andriod is "more vulnerable to exploitation" ?
- worldsavior 1y agohttps://grapheneos.org/usage#web-browsing https://grapheneos.org/usage#web-browsing
- ndriscoll 1y agoDoes Vanadium include the necessary APIs for uBlock Origin? Otherwise this seems like having a long explanation of how secure the windows are with titanium frames and bulletproof glass while the front door is wide open.
- worldsavior 1y agouBlock origin won't save you from exploits in Firefox. The only way it would've might save you is if you disabled first-party JS, which you might as well just disable in the browser itself. Chromium still is the superior browser in terms of security and Firefox is way behind. Adding an extension so you _might_ have less security exploits in the foundation is a wrong tactic and should be avoided.
- ndriscoll 1y agoReal world threats generally aren't exploiting process memory errors or whatever. Unless they're in the shadier parts of the web, users are unlikely to encounter such things even when they might exist. Spyware and adware threats on the other hand are ubiquitous and highly likely to be encountered by nearly everyone. A web browser that doesn't mitigate that is simply not fit for purpose. It's a table stakes security requirement.
- worldsavior 1y agoCurrently all the browsers are with ads by default. Not ideal but certainly most don't encounter spyware through ads, unless they're in some spam sites.
- Night_Thastus 1y agoI've been interested in Graphene OS, but being limited to just the Pixel phones is kind of lame. Have a Galaxy A55 I'd have liked to try it with.
- tonydav 1y agoI've been using graphene since 2 weeks. It's been great. I'm only missing 1 feature: auto call recording.
- morserer 1y agoNot automatic, but the GrapheneOS dialer supports call recording out of the box. During a call, drag your buttons and they will scroll. The call recorder is the 7th button.
- mbananasynergy 1y agoWe recently made it so that the call recording option is not hidden away. If there are 7 options, it's RTT that will be the last one now, and we've made the scroll bar always be visible to make it clearer to people that they can scroll there.
- ajb 1y agoIt's interesting that the only devices complying with the security requirements are Google's. I wonder if Google actually has an internal version of Android that's more security-focussed. Given that critical engineers' personal devices being hacked should be a security threat that's on Google's radar, it's possible.
- bernoufakis 1y agoAccording to the developers, beside the AOSP software itself, there seems to also be hardware requirements that only the Pixel satisfies. https://grapheneos.org/faq#future-devices https://grapheneos.org/faq#future-devices As a large company, they are probably targeted through their devices and since they have the means, it does make sense that the Pixel devices have high security standards compared to other OEMs.
- tholdem 1y agoWhy do you think that's interesting? Google is highly respected for its security practices. Do you think Apple engineers use some special hardened iOS?
- strcat 1y agoOur hardware requirements are listed at https://grapheneos.org/faq#future-devices https://grapheneos.org/faq#future-devices. There are a small subset of other devices with at least nearly all of the security features we require. However, those devices either don't allow using another OS or cripple security for it. There's no other device providing the listed security features and allowing us to support it. Pixels are also the only devices properly keeping up with current Android OS and security updates. We need ongoing firmware and driver updates. There are other devices offering support for a similar time period, but not actually providing close to the same thing during that time period. Most OEMs do the bare minimum for security. The security features they provide are the ones provided for them by AOSP, the SoC vendor, etc. They provide delayed and quite incomplete security patches. Android downplays the fact that it has OS releases every month. There's a new monthly, quarterly or yearly release each month. The monthly Android Security Bulletin patches are a separate thing providing backports of a subset of the security patches (most High and Critical severity AOSP patches) to older initial yearly releases (the initial releases of Android 13, 14, 15 and 16). There are also a huge amount of SoC and other hardware-related security patches with a small subset included in the Android Security Bulletin. Most OEMs struggle to provide these backports and vendor patches on time for a reasonable time period. Non-Pixel OEMs eventually update to a new initial yearly release, usually quite late, then rely on the backports to it for a year or more. Full Android security patches mean shipping the latest stable releases, which have been through significant public testing beforehand for quarterly/yearly releases and are not actually bleeding edge. Quarterly releases are as large as yearly ones but awareness of them existing is low. Android 16 QPR1 currently in Beta has more user-facing changes than Android 16. We're working with a major Android OEM towards some of their future devices meeting our requirements and providing official GrapheneOS support. It will be their regular devices but meeting our requirements currently only Pixels do. Hopefully available in 2026 or 2027. There's no reason other devices can't provide comparable or better security than Pixels, but it's not easy or cheap.
- sebtron 1y agoI have used LineageOS [0] for a few years on my old phone, and last year I got a Pixel 4 and I am using Graphene on it. Both systems work well and I am really glad they exist; Graphene gets extra points for its extremely easy installation process. Unfortunately it seems Graphene is already phasing out support for the Pixel 4 [1], so I'll have to switch back to Lineage at some point. The only technical limitation I have encountered using these ROMs is related to GPS: my position is often lost and I need at least multiple minutes to gain it back (or sometimes it never comes back, depending on where I am). This is likely related to not using Google's location services, even though I have turned on all settings like using WiFi / bluetooth to improve the location accuracy. I tried every advice I found online, without luck. Somehow the issue is a bit worse on Graphene, as my position is lost every time I close the Maps app, but it may be related to the phone and not the OS. [0] https://lineageos.org/ https://lineageos.org/ [1] https://grapheneos.org/faq#supported-devices https://grapheneos.org/faq#supported-devices
- ThePowerOfFuet 1y ago>The only technical limitation I have encountered using these ROMs is related to GPS: my position is often lost and I need at least multiple minutes to gain it back (or sometimes it never comes back, depending on where I am). This is likely related to not using Google's location services, even though I have turned on all settings like using WiFi / bluetooth to improve the location accuracy. I tried every advice I found online, without luck. Somehow the issue is a bit worse on Graphene, as my position is lost every time I close the Maps app, but it may be related to the phone and not the OS. Pixel 8 works amazingly with Graphene's new network location feature. Position fixes are SO MUCH FASTER. It is truly a gamechanger. First it was Wi-Fi only, but they just released cellular location as well. They provide a proxy to Apple's location services.
- jech 1y ago>>The only technical limitation I have encountered using these ROMs is related to GPS: my position is often lost > Graphene's new network location feature I believe it uses https://beacondb.net/ https://beacondb.net/, which is starting to have fairly decent coverage, at least in large parts of Europe. You can contribute to BeaconDB even if you have an ordinary Google phone by installing https://github.com/mjaakko/NeoStumbler https://github.com/mjaakko/NeoStumbler. I use LineageOS myself (because Graphene no longer supports my Pixel 5), and unfortunately it doesn't do network location out of the box. You can get network location on LineageOS by installing MicroG, but it's currently somewhat flaky.
- matheusmoreira 1y agoIt's a shame that Android as a whole is trending towards hardware remote attestation. It's pretty much guaranteed that app developers will eventually start writing their apps so that they refuse to run on anything that doesn't pass Google Play Integrity. Being unable to run WhatsApp or bank apps on GrapheneOS will render it useless as a smartphone operating system. It might not be happening right now but the threat of it looms eternal. My bank could flip a switch somewhere and suddenly my phone becomes useless for the purpose of accessing my bank account. The Google Pixel requirement also makes me sad. I understand that they have solid reasons why. The problem is Google is incapable of selling their phones worldwide. It's really embarrassing for Google and unfortunate for me.
- icar 1y agoHardware attestation and Google Play Integrity are two different things, and the former solves the monopolistic practices of the latter.
- matheusmoreira 1y agoNot at all. They are one and the same. Both of those things will literally destroy the computer freedom we enjoy today. GrapheneOS can attest to the device's security. The question is whether the app developers will trust such an attestation. Will they put money, time and effort into evaluating and trusting GrapheneOS? Of course not. They will just decide to trust nobody except Google and Apple. This is the future. We'll be discriminated against. Can't even log into an account from an "unauthorized device". Their servers will just refuse to talk to our phones if they can't cryptographically verify that we have not "tampered with" them. We'll be refused service straight up unless our computers are straight up owned by corporations. This so called "integrity checking" is meant to protect the corporations from us, not the other way around. It's so we can't do things like hack our way around their "policies".
- mbananasynergy 1y agoWell, there are examples such as Yuh and Swissquote which are using Play Integrity API and also using hardware attestation to specifically allow GrapheneOS. The latter is in the process of implementing what's needed right now. We also expect Google's Play Integrity API to inevitably be ruled as anti-competitive, which it is.
- sandreas 1y agoHappy long term user, great project. Here is a list of Open Source Apps, I use to replace Google stuff: Aurora Store - Anonymized frontend for Playstore F-Droid - Open Source App Store Obtainium - App Store for other sources (e.g. github) Organic Maps - Open Source navigation (not as good as proprietary ones though) SherpaTTS - Text to speech for Organic Maps PDF Doc Scanner - Little Trickster, Open Source document scanner Binary Eye - Barcode reader K9 Mail / FairMail - Mail client LocalSend - Cross Platform File Transfer Syncthing Fork - Catfriend1 Syncthing fork to sync files VLC Media Player - media player KOReader - ebook reader Voice - Paul Woitaschek, local audiobook player AudioBookShelf - Remote audiobook player Immich - image backup Fossify File Manager - file manager Substreamer / DSub - Audio streamer for navidrome self hosted server OpenCamera - Open Source camera app I wish I had this list from the start... Hope it helps someone :-)
- pedro_caetano 1y agoWorth mentioning that Fossify also has an amazing Contacts and Calendar app (using both right now on Android 15). https://www.fossify.org/apps/ https://www.fossify.org/apps/ Fossify is a FOSS project with a handful of volunteers and they do take donations: https://www.fossify.org/donate/ https://www.fossify.org/donate/
- jraph 1y ago> Organic Maps - Open Source navigation (not as good as proprietary ones though) Note that a community fork done by some core contributors was just spawned: CoMaps [1] > K9 Mail / FairMail - Mail client And now there's Thunderbird, which is branded version of K9 Mail IIUC (I don't know if there's any reason to switch from K9 Mail to Thunderbird for existing users) [1] https://f-droid.org/en/packages/app.comaps.fdroid/ https://f-droid.org/en/packages/app.comaps.fdroid/
- Liquix 1y agoDoes the fork solve the issue with inputting addresses? Organic Maps will happily route to the correct street, but falls over when entering a standard format address (i.e. XXX Streetname Ave)
- user070223 1y agoA question for strcat / other Graphene developers: Can you clarify what can one expect from legacy extended support. Will old devices get any more updates? how long, how often, is it just security patches etc.. Thanks for you hard work!
- Andromxda 1y agoNot a dev, but legacy extended support means that there are no more feature updates, i.e., no new Android versions or QPRs, only AOSP security backports. Obviously there aren't any firmware patches either, as these devices are unsupported by the manufacturer, who is responsible for delivering any changes to the firmware. https://grapheneos.org/faq#device-support:~:text=The%20following%20devices%20are,secure%20current%20generation%20devices https://grapheneos.org/faq#device-support:~:text=The%20follo....
- nvdr 1y agoBig thank you to the GrapheneOS team! I have been running it for a week now on my 9pro and the user / app sandboxing is great. If there's a way to donate with cryptocurrency or help contribute, let me know!
- kupfer 1y agoCheck https://grapheneos.org/donate https://grapheneos.org/donate
- BLKNSLVR 1y agoThe article mentions the lack of a swipe keyboard, which is an issue for me. There is an option though: Heliboard with a custom swipe configuration applied (which is apparently sourced from Google, I'm not sure how "grey" that is). It definitely works as a swipe keyboard, but it's just not as good as GBoard. I will persist, however. I hope that it's learning at least...
- senorqa 1y agoMy personal favorite feature of GrapheneOS is that we can toggle the network access permission. In the past, I'd have to root my phone just to be able to install a firewall to do the same. Big props to GrapheneOS!
- gtsop 1y agoAs a long time GOS user I just want to remind what a joy it is to see my very old phone outlive flagships due to the lack of bloatware. I upgrade phones just for a single reason: it has been physically hit so hard over the years that it stops being physically functional.
- lrvick 1y agoGrapheneOS (like all modern AOSP based ROMS) can literally not function with just the open source code. It requires hundreds of binary blobs from the vendor partition of a stock Android ROM, many of which have root access and have not been audited by anyone, including Google, who often lacks source code for them. Beyond that, the GraheneOS team still controls a single signing keychain for all phones in the wild, which we have to assume is still controlled by Daniel Micay (strcat) as it has not rotated as far as I can tell since he mostly stepped away from public view. He is without question a brilliant security engineer, but we can't ignore his very public Terry-Davis-esqe history of mental illness. Making -anyone- a single point of failure for a ROM frequently recommended for journalists and dissidents is a bad plan, and especially not someone very prone to believing wild conspiracy theories. I can't recommend GrapheneOS for any high risk use cases until: 1. they are able to find a device they can run 100% open source code on with no binary blobs 2. The ROM can be full source bootstrapped to mitigate trusting trust attacks. 3. The ROM builds 100% deterministically and is reproduced and signed by multiple team members publicly 4. Threshold signing or a quorum managed enclave issues the final signature only if multiple team members give it signed approvals of a hash to sign. Until at least those points are covered, the centralized trust model of GrapheneOS is a liability and the central keyholder is at high risk of being targeted for manipulation or coercion. Honestly there is no good solution to these problems right now, and as a security and privacy researcher my best advice today to potentially targeted individuals is don't carry a phone at all, or if you must carry one, keep it in airplane mode whenever possible and do not do anything sensitive on it. Consider QubesOS or AirgapOS for such things. If you are fine with centralized control of a phone, and fine with binary blobs controlled by random corpos having God access to your device, but would prefer to eliminate as much proprietary corpotech bullshit as possible, then I would suggest considering CalyxOS which is at least run by a former LineageOS maintainer with a great reputation.
- tholdem 1y agoSo you're saying don't use a smartphone at all, which isn't possible, or use CalyxOS, which not only suffers from the same "problems" you criticize in GrapheneOS, but is also inferior in every way when it comes to security and privacy? This does not make sense at all.
- torium 1y ago> ""will never again be closely tied to any particular sponsor or company"". Work on GrapheneOS is supported by a Canada-based foundation created in 2023; there appears to be almost no public information available regarding this organization, though.
- morserer 1y agoThe company you're discussing is... GrapheneOS itself. > GrapheneOS Foundation was created as a non-profit organization in Canada in March 2023 to handle the intake and distribution of donations. [1] > GrapheneOS Foundation has been incorporated as a federal non-profit organization in Canada. It will be used to receive donations to pay developers and pay for infrastructure. It will also help to shield developers from attacks through the legal systems across various countries. [2] [1]: https://grapheneos.org/history/ https://grapheneos.org/history/ [2]: https://x.com/GrapheneOS/status/1638648643363258369 https://x.com/GrapheneOS/status/1638648643363258369
- torium 1y agoDoes anybody else here see as problematic that this OS supports mostly Pixel, a Google phone? Over and again people on HN make the following argument: "Google is a company that makes most of its revenue from ads and surveillance. Therefore, you should always assume that Google is spying on you". But somehow when it comes to Pixel people give it a pass? Prediction: If Pixel isn't already hardwired to phone home and report on your activities, it will slowly become so over time, as Google realizes its interest. You know, as it happened with Android, Chrome, and everything else that Google touches.
- _vere 1y agoThis is just conspiratorial fearmongering based on vibes. If pixels somehow phoned home on a hardware level, do you think we wouldn't be able to tell? Do you think we wouldn't see it in our network logs? GrapheneOS supports pixels because they are currently the only devices that fulfill their list of requirements, like an actually usable secure element, hardware memory tagging, etc. They have said and continue to reiterate that they would support other devices that fulfill their requirements and seem to be currently looking into working with OEMs to move away from pixels in the long term. Just saying "you claim to degoogle phones yet the phone you use is a GOOGLE pixel, suspicious" is baseless nonsense.
- bitpush 1y ago+1. It is kinda sad that folks seem to have lost critical thinking or even just some plain perspective on things. They hear their favorite influencer spout something, and they parrot it everywhere. Google bad, hurr durr.
- maelito 1y agoI want Graphene OS on a non-Google compact smartphone. Not "pixel compact", but the size of an iPhone mini.
- maelito 1y agoMy main complain by far to LineageOS is the necessity to wipe everything for major releases on my S10. That's not possible every year. What about Graphene ? Can I get 5 years of updates without needing to wipe the phone ?
- tholdem 1y agoYou don't need to wipe the phone when updating GrapheneOS. It's as painless as on stock Pixel OS. OTAs downloaded and installed on the background, just reboot the phone after.
- timschumi 1y ago> My main complain by far to LineageOS is the necessity to wipe everything for major releases on my S10. That's not possible every year. Are you sure that you are not just misinterpreting the upgrade instructions? For the S10 a mandatory wipe-on-upgrade has last been the case when upgrading from versions _older than LineageOS 21.0_. During the time where LineageOS 20 was the current version there was no requirement to wipe listed at all, so presumably it didn't exist then.
- maelito 1y ago> For the S10 a mandatory wipe-on-upgrade has last been the case when upgrading from versions _older than LineageOS 21.0_. Ah, that might be it. My current version is 21. > If your device is running LineageOS version older than 21.0, wipe your data partition (this is usually named “Wipe”, “Format”, or “Factory reset”) . https://wiki.lineageos.org/devices/beyond0lte/upgrade/ https://wiki.lineageos.org/devices/beyond0lte/upgrade/ Yes ! Thank you, I can upgrade to 22 without wiping.
- maelito 1y agoJust did the update. Thank you again.
- Andromxda 1y agoYes, GrapheneOS has always offered OTA updates via the System Updater app. https://grapheneos.org/usage#updates https://grapheneos.org/usage#updates It's set up to download and install updates automatically by default. Alternatively, you can install a signed update package via adb sideload. https://grapheneos.org/usage#updates-sideloading https://grapheneos.org/usage#updates-sideloading Both the update client and the backend are open source, just like the rest of the system: https://github.com/GrapheneOS/platform_packages_apps_Updater https://github.com/GrapheneOS/platform_packages_apps_Updater https://github.com/GrapheneOS/releases.grapheneos.org https://github.com/GrapheneOS/releases.grapheneos.org
- lollobomb 1y agoI am a long time GrapheneOS user, amazing project. One thing that is not clear to me is the support for NFC payments. Las time I checked, NFC payments on Graohene didn't work at all, but I am reading on this thread that some users do manage to pay via NFC? Did Iget this right? Mind explaining how? I do not use banking apps (I only use banks that allow me to log in via browser using a 2FA which is not a proprietary app, like a FIDO key or other physical dongle), but do I get it right that Revolut would allow me to pay via NFC in this case? Is this something geo-dependent?
- prophesi 1y agoThe issue isn't with NFC. It's passing the Play Integrity check that app developers optionally can use to prevent devices that don't pass the check from running their app, or remove parts of its functionality. IIRC I don't think any custom ROM's can pass the check. So you might be able to pay via NFC with a banking app if they don't implement the Play Integrity API. For Graphene's thoughts on the matter (2024): https://grapheneos.org/articles/attestation-compatibility-guide https://grapheneos.org/articles/attestation-compatibility-gu...
- deleted 1y ago[deleted]
- lollobomb 1y agoYes, I know the issue, but my question was more: is Revolut one of such banking apps?
- _lvbh 1y agoYes https://discuss.privacyguides.net/t/revolut-is-blocking-new-logins-from-android-distributions-that-arent-certified-by-google-incl-grapheneos/23024 https://discuss.privacyguides.net/t/revolut-is-blocking-new-...
- lollobomb 1y agoOK, and then these HN users who report being able to pay via NFC with Revolut on Graphene OS are lying? Sorry, I am confused :|
- ovalanche 1y agoTrue privacy is such a rare commodity these days. It’s a breath of fresh forest air to enter an OS unwatched, allowing your mind to be free. Not to get too deep, but contemporary philosophy posits that our phones have become extensions of our brains (not only theoretically, but literally! See e.g. Andy Clark and David Chalmers, “The Extended Mind,” 1998). Our devices have access to profound parts of our lives— our habits, friends, desires, notes, thoughts… With something this fundamental, it’s vital to have privacy. Thank you, Graphene team, for all the hard work you do.
- preisschild 1y agoI love GrapheneOS. The only "issue" I had is that you are actually responsible for your own device, including taking backups. Unfortunately my home server, which I was using for backups, was flooded and before I replaced it my phone died and I lost a lot of data...
- no-reply 1y agoyou can always store encrypted backups to cloud storage
- preisschild 1y agoTrue, but unfortunately Proton Drive, which I use for "cloud" storage, does not supported the storage API that GrapheneOS' SeedVault supports for backups
- fmajid 1y agoI am (very slowly) migrating from iOS to GrapheneOS, for the same reasons as OP (privacy, Apple's increasingly user-hostile and developer-exploitative policies). Apart from migrations concerns, which are not GrapheneOS' fault, the main shortcoming I see is the lack of proper backup/restore, e.g. when switching phones. There is Seedvault, but I've found it unreliable.
- sjw987 1y agoPerhaps a newbie question, but since there's a lot of Graphene users here I thought it'd be best to get a human answer. I have an old Pixel 5 which I stopped using because Google dropped Google Pay (tap to pay) on it. I moved to a new device (Pixel 9) for daily usage but still have the 5 laying around (due to low resale value). At the time I moved, Pixel 5 was about 1.5 years (November 2023) beyond Android security updates. I still love the form factor (more than the bigger 9 I use now) and it has much more life left in it. I'd quite like to use this as a backup device for basic utility (camera, phone, SMS, basic read-only web use) and to take with me for runs and travelling. Would installing GrapheneOS on this device likely make it more secure? Do Graphene releases work the same on all devices, or is it sort of device-by-device basis?
- backscratches 1y agoYes it will make it more secure (and faster!), but it is already receiving only bare EOL updates, but will definitely give it some life extension. See: https://grapheneos.org/faq#supported-devices https://grapheneos.org/faq#supported-devices
- fmajid 1y agoYou won't get the full set of security measures (those require newer Google Tensor chipsets with ARM Memory Tagging Extensions, so Pixel 8 and later), but it's still going to be far more secure than any Android or even iPhone. Regarding NFC payments, the apps themselves refuse to run on non-vanilla OSes due to spurious security concerns and Google's maneuvers behind the scenes, but there are reports that Curve Pay works, at least in the UK.
- sjw987 1y agoThat shouldn't be much of an issue. I didn't plan on NFC payments going forward. If I use the web minimally and toggle the internet off when not in use, that should be pretty secure, right?
- 1y ago
- Funes- 1y agoIf I need to buy a phone made by Google to get away from Google, I'm just not doing it. /e/ doesn't support my current smartphone, either, and postmarketOS is not functional. At this rate, I think we're better off going back to dumbphones.
- CommenterPerson 1y agoThank you. I have the same worry. I'm not a developer, how could one tell there isn't some built in backdoor in the hardware? There was another HN posting on Graphene and asked the same question there with no answer.
- strcat 1y agoThe same thing could be said about any hardware. Pixels receive by far the most privacy and security research of any devices. They're by far the most secure Android devices and the only ones providing competitive security with iPhones. They're the only devices with even a reasonable level of security combined with proper alternate OS support. Our hardware requirements are listed at https://grapheneos.org/faq#future-devices https://grapheneos.org/faq#future-devices. These are very reasonable requirements for industry standard security features, standard updates and the ability for GrapheneOS to use those standard security features. There are other devices with all the major features listed there but not the ability for GrapheneOS to use all of them. Updates are a major issue for all non-Pixel Android devices including the ones advertising lengthy support. GrapheneOS is working with a major Android OEM towards their future devices providing the expected hardware-based security features and updates, unlike their current devices. The purpose of GrapheneOS is not specifically avoiding Google but if you want hardware from another large tech company to use with GrapheneOS, you'll have that option. The initial goal for these devices is providing a similar level of security and long term support to what we already have with Pixels. In the longer term, we want to have add hardware-based security features unavailable on Pixels or iPhones along with hardening below the OS layer. For now, Pixels are the only viable option for us to use. We're actively working on changing that but we're not going to simply greatly lower our standards and support devices where we can't adequately protect users. There's no evidence of any backdoor and it's contradicted by how exploits are developed and used. There is plenty of evidence that other devices lack comparable security. https://discuss.grapheneos.org/d/14344-cellebrite-premium-july-2024-documentation https://discuss.grapheneos.org/d/14344-cellebrite-premium-ju... shows an example where only the Pixel 6 and later / iPhone 12 and later have brute force protection which holds up against the most sophisticated company developing forensic data extraction tools. We have access to more recent documentation showing the same thing. Why do governments buy exploit tools from NSO, Cellebrite, etc. and develop their own if they supposedly have backdoors in devices? Why would using a device from Samsung or Sony protect against it if they did?
- tclover 1y agoWhat if all this hype about GrapheneOS was actually deliberately invented by the CIA so that everyone who has something to hide would install a beacon with a backdoor on themselves? adjusts tinfoil hat
- AstroBen 1y agoI'm secretly hoping my iPhone will spontaneously explode so I can justify buying a pixel for this
- eleitl 1y agoI've been rocking it on mobile for a while, and went for a tablet (LineageOS there previously) this month. The only real option for privacy and security which isn't swiss cheese.
- flntzr 1y agoI'd like to switch phones soonish and was looking at the fairphone 6 with /e/OS but feel deterred by its mid range specs which would probably limit its longevity. I would like to get away from google. Is waiting for the new pixel and then putting grapheneOS on it a good way forward? Seems weird to pick a google device to get away from that company. Has anyone else done the same? Alternatively, there is the iPhone but I do like fdroid and the more open nature of android.
- bernoufakis 1y ago> I'd like to switch phones soonish and was looking at the fairphone 6 with /e/OS but feel deterred by its mid range specs which would probably limit its longevity. I would like to get away from google. > Is waiting for the new pixel and then putting grapheneOS on it a good way forward? Seems weird to pick a google device to get away from that company. > Has anyone else done the same? I did end up going for a Pixel + GOS. Although it is conterintuitive to use a Google device to get away from Google, according to GOS developers themselves, the Pixel series were the only devices that met their strict requirements for security. From personal experience, been using it for almost 3 years now, and it gives you 95% of the benefits of Android while giving you back control over your phone, and being generally more secure. Just stay out of the radar of the leadership, they can be a bit abrasive, for the lack of a better expression.
- flntzr 1y agoThank you for the warning. Is the camera with GrapheneOS as good as the stock android one? I get to use my wife's iPhone camera sometimes and it frequently shocks me how good and responsive it is. But I'm coming from a OnePlus 8 Pro, which never had a great camera in the first place.
- bernoufakis 1y agoI suck at taking pictures. It's definitely good enough, but worst case you can install the stock Google Camera app and disable network permission to limit snooping.
- greenie_beans 1y agosome things about the UX in this is so bad, which i love because it discourages me from using the phone more. every time i end a phone call i struggle hanging it up. i don't know how to go forward in the browser because the swipe always makes me go back, even when i swipe forward. it's using the ugly material ui components from google. it's great! all of the privacy and security parts of the UX are good, though.
- strcat 1y ago> some things about the UX in this is so bad, which i love because it discourages me from using the phone more. every time i end a phone call i struggle hanging it up. i don't know how to go forward in the browser because the swipe always makes me go back, even when i swipe forward. it's using the ugly material ui components from google. it's great! Android has a standard system back navigation gesture based on the previous system back button. Apps integrate support for it. Chromium disables their back/forward gestures when using the modern gesture navigation in the OS. It would have made sense to have a forward gesture but Android never had that as something apps had to implement so it would only work in a small subset of apps and would be generally unavailable, which would be confusing. Phone app has a button for ending the call. It's our fork of AOSP Dialer with minor changes including UI improvements. Calculator, Clock, Contacts, Gallery, Keyboard, Messaging and Phone are AOSP apps which we need to overhaul or replace. These look and function the same way Google's apps used to but are outdated. They're the open source projects which were abandoned beyond security patches after they forked them off into their own proprietary Google apps. Gallery and Keyboard will likely be replaced while the rest will be overhauled. We know these apps have a bad UI but our focus has been on the core OS instead of apps people can replace. We're beginning to do more work overhauling these.
- greenie_beans 1y agovery interesting. thank you for all of that information and the work you do. maybe one day i can contribute to the UX without being an HN cynic!
- eskuero 1y agoI have been using GrapheneOS en my pixel for almost a year and quite satisfied. The docs for compilation are neat so I'm running my own build with my own signatures and my own repository of their AppStore for my third party apps that I also build from source. I run only those apps on the main profile and then keep a private space (set to autokill on lock) for proprietary apps that require Play Services.
- 1vuio0pswjnm7 1y agoDoes GrapheneOS firewall provide port forwarding or is Netguard required
- ciferkey 1y agoReally feel a similar sentiment to a lot of others in the comments! I'm enjoying the recommendations other shared here. I _think_ this follows the rules of conduct for HN but let me know, I recently brained dumped about the following on my blog about the general experience setting up GrapheneOS: https://blog.matthewbrunelle.com/i-picked-a-really-weird-time-to-try-out-grapheneos/ https://blog.matthewbrunelle.com/i-picked-a-really-weird-tim...
- emulio 1y agoI wish to use Graphene OS, but I can't force myself to buy a Pixel Phone, I don't like the design.
- DavideNL 1y agoNote that the author of the article has now added "corrections" : Corrections/elaborations on some points : https://lwn.net/Articles/1031454/ https://lwn.net/Articles/1031454/ Source: https://grapheneos.social/@GrapheneOS/114914602970489632 https://grapheneos.social/@GrapheneOS/114914602970489632 > Our community manager has provided a response to the recent LWN article on GrapheneOS with important corrections and context. The article had significant inaccuracies about the history of GrapheneOS, our organization and the details of what we provide. [.................]
- lollobomb 1y agoThe submission is a bit old but let me try anyway since I see some user claiming to be Graphene community manager here. Let me first reiterate that GOS is an amazing project and that I am super grateful for your work. That said, I think the #1 missing feature is the lack of a robust backup solution. Las time I checked, there was an ongoing discussion about shipping an ad-hoc backup system for GOS. ANy uodate on this? Thanks!
- joemazerino 1y agoGrapheneOS "had" to reply to this article because they weren't happy with it's portrayal of events and LWN refused to edit a live article. Par for the course with GrapheneOS. They always seem to take a good thing said about them and not be satisfied. https://x.com/GrapheneOS/status/1948811620047536316 https://x.com/GrapheneOS/status/1948811620047536316