16 ms·
Before buying a smartphone I tried to find an inexpensive model that supports open source OS, but I couldn't. What open OS support is ether expensive Pixels, or
by codedokode 11mo ago
Before buying a smartphone I tried to find an inexpensive model that supports open source OS, but I couldn't. What open OS support is ether expensive Pixels, or outdated models.
The solution, I think, would be a regulation that forbids manufacturers of any chip or device CPU from making obstacles to reprogramming the device (using fuses, digital signatures, encryption etc). So if you buy a device with CPU and writable memory, you should be able to load your own program and manufacturer may not use technical measures to stop you. The goal of regulation would be preventing of creating digital waste, vendor locks and allow reusing the hardware.
Of course, features like theft prevention won't work, so the user should be able to waive this right.
- kragen 11mo agoWe just had a thread about this on https://news.ycombinator.com/item?id=45740383 https://news.ycombinator.com/item?id=45740383.
- maxloh 11mo agoMost vendors (at some level) allow flashing custom distributions, as long as you didn't buy that device from carrier: https://github.com/zenfyrdev/bootloader-unlock-wall-of-shame/ https://github.com/zenfyrdev/bootloader-unlock-wall-of-shame... You will lose DRM-based apps (e.g. Netflix), Payment apps, and bank apps though.
- xyzal 11mo agoNot in markets without significant Huawei and Xiaomi presence. Local banks (Czech Republic) are not using integrity APIs to keep being usable for most clients.
- Xelbair 11mo agoThat small little caveat already makes it a non-option
- nvdr 11mo agoMost DRM / banking apps work fine for me through the browser and you can add them to your home screen. Android / Samsung Pay will stop working, but if you have a Garmin watch, you can still pay with that.
- fcpk 11mo agoBut this is changing. Already in multiple countries(and soon possibly EU wide) there will be only play integrity(strong verdicts) to enforce availability of many services(if not using ios, which is the same locked in syndrome). Yes some banks still allow classic clunky 2FA(sms, card readers, sometimes SIM generators) but it'll all eventually go away in favor of "locked and favored" os unless legislation fights against it.
- maxloh 11mo agoOnly for now. Google did push the Web Environment Integrity API, which is basically "Play Integrity API for Chrome," that helps websites check if the OS, browser, or installed extensions are "safe". Fortunately, they backed off and decided to abandon the proposal after massive backlash. But we don't know when we will see a 2.0 version of that.
- heavyset_go 11mo agoEven phones from Motorola require you to literally ask permission to unlock your bootloader via a form on their website, which they then unlock remotely or you enter some generated code. Other manufacturers do the same, where you have to wait a period of like 45 days before being able to unlock, and then have to ask permission on their website to unlock your bootloader.
- munchlax 11mo agoAnd good lock unlocking anything over 5 years old because the updated website doesn't support what you've got. Been there, it sucks.
- codedokode 11mo agoTo be fair, for "anything over 5 years old" you can probably find a privilege escalation exploit.
- wiz21c 11mo agothe question is not "being able to", the question is "being able to with a reasonable effort". wandering the web to find an exploit is way beyond my spare time.
- VagabundoP 11mo agoThat might get you root but not a bootloader unlock.
- kube-system 11mo agoThere are privilege escalation CVEs in bootloader code too. I remember unlocking some very early locked bootloaders this way in the early days of android.
- VagabundoP 11mo agoSo much rarer now. Its getting more and more locked down unfortunately.
- safety1st 11mo agoThis is the place where I think lawmakers needs to be involved. Bearing in mind that laws aren't engineering specs, being able to pay for things and use a bank are about as close to fundamental rights as anything is for participants in society. If you have to buy a second device to use Netflix, so be it, but we need laws that guarantee people can make digital payments without Apple or Google's permission. There are societies today (I live in one) where some businesses are starting to accept payment only through a banking or payment app, no cash, no card, nothing else. And these apps will only function in the very narrow circumstances of "I bought a device which runs software from one of two American tech monopolies and follow all their frequently changing rules for using various software that's unrelated to the payment I need to make." This limitation is mostly in place due to the banks believing it will make things more secure. Security is important, but not important enough that you get to start denying innocent people the ability to make payments or exile them from the banking system because they had some kind of dispute with Apple or Google. Governments need to step in with access mandates here, otherwise this problem WILL come to a jurisdiction near you sooner or later.
- AnthonyMouse 11mo ago> Security is important The argument that this is actually a security benefit is a farce. It doesn't do anything. If the device is compromised then it's going to capture your password and send it to the attacker without attempting any attestation. So the only time the attestation is attempted is when the device isn't compromised.
- kevincox 11mo agoYes, if it was a measure of device security they would revoke attestation of devices that are behind on security updates. But no, a 5 year old device that never got security updates is A-OK according to Google but a completely up to date custom ROM is not. It's clearly not about real security. It is about control. You follow the rules and get Google's blessing or no SafetyNet for you. These rules include things like ensuring that the user can't access their own data without the controlling app's permission.
- LogicHound 11mo agoBank apps work fine (at least UK ones) on Graphene OS installed via the play store.
- codedokode 11mo agoI wouldn't want the bank to access my phone, so it doesn't matter that the app doesn't work, and in a weird case where you urgently need to transfer your money to scammers while not being at home, you can use bank's web app.
- VagabundoP 11mo agoBanks are all moving to MFA through an app, which then needs play protect, which then maybe need TWRP/Magisk.
- thomc 11mo agoThere are at least a couple of banks or credit card companies in the UK now that only offer mobile apps, as well as those now using push MFA with their apps for every large purchase. Recently I needed to install an app from the UK government to prove my identity via camera to renew my driving license, and that doesn't work in GrapheneOS either. I can do it in person (for now) but there is an extra fee.
- codedokode 11mo agoAll the banks I use, have a web app, although it can be somewhat limited, but I don't need any advanced functions anyway. > as well as those now using push MFA with their apps for every large purchase. Our banks use SMS OTP (not required for mobile app) for all operations - I assume otherwise the amount of fraud would be exorbitant. > Recently I needed to install an app from the UK government to prove my identity via camera to renew my driving license, and that doesn't work in GrapheneOS either. I can do it in person (for now) but there is an extra fee. Interesting that the government relies on a proprietary, foreign platform.
- array_key_first 11mo agoAndroid and said manufacturers purposefully do everything in their power to make this as awful as possible. For example, you can't relock the bootloader on any device except pixels. Why? No reason. Just fuck you, I guess. That's a huge security hole that they're creating, intentionally. What's going on is they are hoping that if you do use other software that you get malware or get scammed. They are literally, actually, undermining their own device's security just to send a message. These people are psychotic.
- willtemperley 11mo agoLooks like GrapheneOS will be available on another "major Android OEM” soon [1]. Regulation should prevent Google from subsidising manufacturers to use Android. Arguably the recent antitrust legislation [2] applies in this case because they're effectively paying manufacturers to place that horrendous and impossible to remove search bar on the home screen. [1] https://www.androidauthority.com/graphene-os-major-android-oem-partnership-3606853/ https://www.androidauthority.com/graphene-os-major-android-o... [2] https://www.justice.gov/opa/pr/department-justice-wins-significant-remedies-against-google https://www.justice.gov/opa/pr/department-justice-wins-signi...
- VagabundoP 11mo agoI just wish they had two sizes, a pocket version please. I have small Trumpian hands.
- kevincox 11mo agoGrapheneOS is in some ways not an open OS. The official builds don't provide root access. So for example apps are able to hold your data hostage from you. I get that this is in the name of security hardening. And you can make a build that has limited root access and is officially supported. But GrapheneOS isn't the end-all solution to computing freedom. Although hopefully on those devices you will be able to install custom OSes (root capable build of Graphene or otherwise).
- zb3 11mo agoRaw root access isn't what I'd want apps to have.. it's that the Android permission system deliberately limits what the user can consent to, the rest is for "system apps" and to install those you need to unlock bootloader and start the whole "journey" while saying goodbye to banking apps. Implementing a more flexible permission model + sandbox would probably involve too much work for them. Hopefully AVF might make things a little better if we'd be able to run Android VMs on Android - so you'd be able to run a rooted VM inside GrapheneOS.. but this depends on Google keeping Android open source, yet QPR1 was not released.
- theK 11mo agoDid you check the stuff murena has on offer? Most if not all of their phones come with an unlockable bootloader and the OS they come with isn't that bad to start with either.
- microtonal 11mo agoThey are pretty bad when it comes to security: https://eylenburg.github.io/android_comparison.htm https://eylenburg.github.io/android_comparison.htm
- theK 11mo agoHmm... that looks like a pretty skewed comparison. It's as if somebody took the security features that make Graphene stand apart and compared everything else to them. No contention that Graphene is safe, but categorizing other OSes as "pretty bad when it comes to security" because they don't copy Graphene is a bit of a stretch.
- strcat 11mo agoEylenburg's site is focused on privacy and security for the comparisons. GrapheneOS is the only privacy and security hardened OS included in the Android-based OS comparison. None of the other operating systems listed in that comparison keep up with Android privacy/security patches or provide significant OS level privacy or security improvements. Many GrapheneOS features aren't listed by the table or are grouped in huge generic categories such as "Hardened system components". An example of a major privacy feature not listed by the table is closing the leaks in Android's standard VPN lockdown mode. GrapheneOS fixes all 5 of the known outbound leaks in VPN lockdown mode, CalyxOS partially fixes 1 of them and the others don't touch this since that's not their focus. It's a privacy and security focused site comparing an OS focused on improving those in the OS layer to ones which mostly aren't. Operating systems lagging far behind on privacy and security patches are definitely quite bad when it comes to security. For example, the official releases of /e/ for the Pixel 7 are still based on Android 13 and do not include any of the Pixel kernel, driver of firmware patches released from October 2023 and later. Eylenburg's table doesn't put much emphasis on this since it's contained within a couple rows which do not adequately communicate how delayed the updates are and how much that matters. In addition to the official Android and OEM privacy/security patches, there are also major privacy and security improvements in each major Android release. Android also doesn't backport most Moderate and Low severity patches which are no longer given CVE assignments. Most privacy patches are considered Moderate or Low severity if at all. Many privacy improvements also aren't considered to be bug fixes since they're improvements to the intended design of the system. Only bug fixes considered to have a High or Critical severity security impact are backported. The comparison table could cover a bunch of standard Android privacy/security improvements to emphasize the importance of keeping up with the only actual LTS branch.
- N-Krause 11mo agoAll the Fairphone Versions support e/OS/ as far as I know. I have the Fairphone 5 with the current e/OS/ version completely un-googled. But you also have the option to allow partial google-fication in e/OS/ so you don't miss out on most of the features and paid-apps you had.
- constantcrying 11mo ago>The solution, I think, would be a regulation that forbids manufacturers of any chip or device CPU from making obstacles to reprogramming the device (using fuses, digital signatures, encryption etc). Why would you make essential security features illegal? Do you want to fly on a plane where the flight control software was maybe overwritten? >So if you buy a device with CPU and writable memory, you should be able to load your own program and manufacturer may not use technical measures to stop you. The problem is Google and Apple locking down their Operating System, this is not a technical limitation on hardware.
- surajrmal 11mo agoSecurity only works if you can control what software is trustworthy. If some software has been proven to be untrustworthy, it is worthwhile to prevent all software that the producer has ever made from working at scale. Adding some nominal process and fee to make it too expensive to create a lot of accounts prevents them from creating hundreds of alternative aliases. There is a lot of precedence for why this is a good idea and works. I think if there was another company involved with performing the audit which folks trusted it might now seem so scary.
- anonymous908213 11mo agoDo you understand that you are advocating for a world in which two corporations are the sole determinator of the livelihood of all mobile software developers? A career in software development should not be at the complete mercy of Apple and Google, or I suppose if you had your way Microsoft for PC gatekeeping as well.
- codedokode 11mo ago> Do you want to fly on a plane where the flight control software was maybe overwritten? I don't understand it. Whoever owns the place can replace any part of it, including computers. So being able to overwrite software doesn't change it. Furthermore, plane computers are not a consumer hardware. You could make a better example with patched car software. > The problem is Google and Apple locking down their Operating System, this is not a technical limitation on hardware. The initial ROM bootloader contains hard-coded signature which prevents you from replacing Apple/Google software.
- thastings 11mo agoDroidian[0] currently supports a relatively new Motorola phone[1]. A Snapdragon 8+ gen 1 device, so the performance isn't bad, and most features seem to work, including Waydroid. I've noticed incoming phone calls causing a glitch where the call can't be answered, but other than that, daily drivable. Just like a PinePhone, only more powerful. In my region it can be had for ~€250 brand new. [0] https://droidian.org/ https://droidian.org/ [1] https://www.notebookcheck.net/Lenovo-ThinkPhone-by-Motorola-in-review-Business-smartphone-with-IP-certification.700348.0.html https://www.notebookcheck.net/Lenovo-ThinkPhone-by-Motorola-...
- wraptile 11mo agoEvery few years or so we collectively rediscover that general computing devices should be general and repeat the same mistake every time new format is released. We're all a bunch of reactive losers and that will never change it seems.
- pjmlp 11mo agoMany of those devices are closed exactly due to regulations.
- egorfine 11mo ago> a regulation that forbids manufacturers of any chip or device CPU from making obstacles to reprogramming the device Except regulations are now moving in the opposite direction: to mandate device locking.
- andrepd 11mo ago> Before buying a smartphone I tried to find an inexpensive model that supports open source OS, but I couldn't. What open OS support is ether expensive Pixels, or outdated models. You can buy a refurbished Pixel 5 for less than 200$. Great screen, great camera, 5G, the works. It's definitely not an "outdated" device, and it runs Graphene or Lineage with minimal hassle.
- gf000 11mo agoYou can get a new Pixel 8 for ~500$, I would say that has a very decent price to value, and will be supported for longer.
- edm0nd 11mo agoyou can also snag refurb'd Pixel 7s for $170 off eBay atm
- grepex 11mo agoI snagged a Pixel 8A for around 200 on ebay.
- codedokode 11mo agoIt's hard to find. Pixel 8 costs $670 here, and the cheapest Pixel is 9a for $470. At this price, it is overpriced. Pixel 8 has 8 GB RAM, Samsung A16 with 8 GB costs just $230. It's almost 3 times cheaper. And Samsung supports 2 SIM cards, unlike Pixel, so you can have, for example, one SIM for Internet and another for calls.
- Andromxda 11mo agoUsed or refurbished devices are typically much cheaper. It's what I would recommend. You can also use 2 SIMs on a Pixel by using an eSIM.
- gf000 11mo agoAs mentioned, second-hand is also an option. But my price was actually from Hungary with world-record VAT included, so not sure if you really couldn't find/order it for around that price. Also, the basic premise is that you can buy a decent Pixel phone for an affordable price, not that it has the very best price/value out of any device. I would also wager that the Pixel 8 has massively better cameras than a Samsung A16, so not apples to oranges.
- deng 11mo agoNot sure what exactly you mean with "open source OS" and if Lineage counts as one in your book: it supports quite a few cheap and also fairly recent Motorola phones, which are also easy to unlock: https://wiki.lineageos.org/devices/#motorola https://wiki.lineageos.org/devices/#motorola For family, I just got a used Edge 30 Neo for ~100$ and put LineageOS on it, and it works like a charm. Phones like the Moto g84 go for even less and still can be bought new for a decent price. Xiaomi would be even cheaper, but I would highly discourage getting one because the unlock process is plain ridiculous nowadays. And as others have already noted, if you don't mind getting a phone that's a few years old, a used Pixel 5 is not expensive (still happily using a Pixel 4a and don't see why I would need to upgrade).
- edm0nd 11mo agofyi you can buy refurb'd pixel 7's off eBay for like ~$170 great for playing around with or if you want to install something like GrapheneOS.
- Andromxda 11mo agoThe Pixel 8 and 8a aren't that expensive either. And keep in mind that they are supported until 2030 and 2031 respectively. [1] They not only receive security updates for 7 years, instead of the 5 years for previous Pixel generations, but also have stronger hardware security, by implementing the ARM memory tagging extension. [2] [1] https://grapheneos.org/faq#device-lifetime https://grapheneos.org/faq#device-lifetime [2] https://grapheneos.org/faq#recommended-devices https://grapheneos.org/faq#recommended-devices