4 ms·
I've always found it strange that GrapheneOS only runs on Google hardware. Can anyone explain this choice?
by megaloblasto 1y ago
I've always found it strange that GrapheneOS only runs on Google hardware. Can anyone explain this choice?
- keerthiko 1y agomost of the explanation from the horse's mouth will be found here: https://grapheneos.org/faq#device-support https://grapheneos.org/faq#device-support
- megaloblasto 1y agoThanks > These devices meet the stringent privacy and security standards and have substantial upstream and downstream hardening specific to the devices It still seems strange. A big part of GrapheneOS is to provide a safeguard from Googles data hoarding, yet it works primarily on Google phones.
- fdsfdsfdsaasd 1y agoYes, a situation that Google is steadily fixing.
- warkdarrior 1y agoConspiracy theory time: GrapheneOS is a skunkworks project from Google, to sell more Pixel hardware.
- subscribed 1y agoConsidering last years development and quite open Google hostility? No. GoS have provided a lot of patches upstream, Some of which were even applied. Despite that they wouldn't get early access to A16 just because. Access EVERY vendor promising to preinstall privileged Google services has. Allegedly Google security team was very happy about that idea, but got vetoed by management.
- rfoo 1y ago> It still seems strange. A big part of GrapheneOS is to provide a safeguard from Googles data hoarding, yet it works primarily on Google phones. That's the most confusing part. IMO GrapheneOS is not mainly about "provide a safeguard from Googles data hoarding", instead this is more like a side quest. GrapheneOS is about creating a mobile OS that is more secure against advanced threats [0] than anything else, including stock Pixel OS and iOS. [0] Currently my rule of thumb is, anyone who can find and write exploits for new memory corruption bugs for the wanted attack surface, or who can buy such capability, qualifies as advanced threat. Hence Cellebrite qualifies as a borderline "advanced threat".
- kelnos 1y agoThat doesn't seem odd to me. Google's data hoarding is done in software, not hardware. Remove Google's add-on software and you have a more or less blank slate to work with. I don't see why we'd expect any different.
- zahllos 1y agoThis is the answer. Google play services and related privileged components are the non-open source blob hoarding data, along with whatever backend services you use from Google. These components are part of the stock android image that comes on the device that's replaced entirely by GrapheneOS. Naturally if you continue to use Google services then the data hoarding continues.
- AlgebraFox 1y agoThey've clearly explained here. I'm not sure how many people would keep asking the same question without even doing a simple web search. https://grapheneos.org/faq#future-devices https://grapheneos.org/faq#future-devices
- megaloblasto 1y agoSomeone clearly replied with the same link. I'm not sure how many people would keep replying the same thing without even doing a simple thread search.
- garciansmith 1y agoThey posted within a minute of each other, so likely did not see the the response and were typing theirs as the other got posted.
- tcfhgj 1y agonot sure if it is an explanation or a justification
- raziel2p 1y agowhat's the difference?
- sandreas 1y agoAFAIK the Pixel devices are the only ones that reliably allow bootloader unlocking / re-locking, that is required to perform custom os installs. There are others e.g. Motorola ones or Fairphone, that also allow this but it's a good idea to focus on a specific set of devices keeping maintenance as low as possible and security focus as high as possible. There are alternatives like /eOS/ or CalyxOS supporting more devices and I experienced exactly this "no longer supported" issue with my Xiaomi A2, which suddenly disappeared from the list of supported devices (see https://calyxos.org/news/2021/03/29/mi-a2-ten-firmware/ https://calyxos.org/news/2021/03/29/mi-a2-ten-firmware/).
- strcat 1y agoPixels are the most secure Android devices and the only ones meeting the hardware security requirements for GrapheneOS at this time. GrapheneOS is working with a major Android OEM towards their future devices meeting these requirements. Neither /e/ or CalyxOS is a hardened OS. They provide much weaker protection against these attacks than the stock Pixel OS or especially an iPhone. They're weakening privacy and security substantially including lagging many months and even years behind on standard security patches. CalyxOS has not shipped the June 2025-06-05 patch level or later. /e/ is regularly many months behind on OS and browser security patches along with very often being a year or more behind on kernel updates and firmware/driver updates. See https://discuss.grapheneos.org/d/24134-devices-lacking-standard-privacysecurity-patches-and-protections-arent-private https://discuss.grapheneos.org/d/24134-devices-lacking-stand... with in-depth information about /e/ on Fairphone devices with links to multiple articles from third party security researchers covering it and other information. Those non--Pixel devices do not provide a secure base either.
- octo888 1y agoCurious if you've already read the comprehensive FAQ entry and are trying to imply something?
- megaloblasto 1y agoKind of. I don't use grapheneOS and I'd like to, but de-googling your phone by buying a Google phone seems a bit sketchy. I don't want to take away from a privacy focused project. I'm super thankful for this option and I can't stand android or iPhone. But in the back of my mind I wonder if I'm being tricked.
- SirHumphrey 1y agoAs for why graphene uses graphene uses pixels - their FAQ does a good job explaining. As for why google keeps the bootloader opened and maintains (until recently) good enough device-tree support- I would guess mostly historical reasons? Before becoming as mainstream as they are now nexus and pixel phones used to be in part android development devices and certain creature comforts stuck. This seems to be souring though, so some of the people there may be in talks with an OEM for a graphene os specific device[1]. [1]: https://discuss.grapheneos.org/d/23886-partnership-between-grapheneos-oem-and-end-of-the-play-integrity-api-saga https://discuss.grapheneos.org/d/23886-partnership-between-g...
- megaloblasto 1y agoThis is great info. Thanks.
- fsflover 1y agoI agree with you, it's a dangerous and suspicious choice, https://news.ycombinator.com/item?id=45100831 https://news.ycombinator.com/item?id=45100831
- octo888 1y agoI'm suspicious of your comment. You got beef or had a run in with the people who run the project...?
- fsflover 1y agoI don't have and never had any connection to GrapheneOS developers, positive or negative, online or offline, nor am I working for any of their competitors. I only have the philosophical disagreement with their decisions explained in my link above.
- subscribed 1y agoOkay, I'll bite - what phone GOS should run on? Remember the context is having a *secure* handset in hand.
- matheusmoreira 1y agoHe's not wrong from a computer freedom perspective. GrapheneOS is actively hostile to things like complete root access. It blows a hole in the security model. It's also very much enabled by the exact same sort of user hostile cryptography that corporations use to lock down their devices. Things like hardware attestation which protects apps from us. We can't easily do things like MITM an app to reverse engineer it. I still it's superior to any stock Android OS but the risks associated with giving up freedom for security must be considered. The ideal is to have security while simultaneously maintaining our power as the owners of the machine.
- strcat 1y agoGrapheneOS only supports devices where users can have full control over the OS and replace it. Choosing to use GrapheneOS is fully optional and people who don't want a strong security model can use something else. Not clear how GrapheneOS in any way hurts people's freedom by giving them a highly private and secure OS option for devices which meet our requirements. We're working with an OEM on towards more devices meeting our requirements which will support using other operating systems too. If you want another OS, you can use one. If you want to modify GrapheneOS in any way you want, that's fully supported. We provide easy to follow build instructions. You can make a userdebug build with ro.adb.secure=1 if you want root access at the cost of security.
- other8026 1y agoPixels are the only devices that are out right now that meet the project's requirements. The project is in talks with a major OEM to have some of their devices meet GrapheneOS's requirements and have official support for GrapheneOS. Assuming all continues to go well, the project has said they expect those devices to be out in 1-2 years.