30 ms·
GrapheneOS – Break Free from Google and Apple
- to3k 8mo ago[flagged]
- deleted 8mo ago[deleted]
- villgax 8mo agoUnless govts make web a primary citizen of information dissemination and acceptance, it will be only apple/google on the sim card linked access
- ordainedclicks 8mo agoOne of the only big downsides I've noticed with GrapheneOS is that several banking apps don't work with it at all thanks to being tied to Google's verification ecosystem. Luckily I have hardware 2FA keys from my bank so I can authenticate using that. It also slightly decreases the suck-factor from whenever the phone decides to fly off down a drain. This may not be the case for you, so do your research on what you need for daily living.
- stinos 8mo agoAuthor is installing Google Play Services it seems, wouldn't that work around this? In any case, for me this also sort of defeats the purpose: I'd rather break free from Google and Apple, not just (stock) Android and iOS.
- UnreachableCode 8mo agoNo, because most banking apps call upon the Google Play Integrity API, which GrapheneOS doesn't (or can't?) use. There's a decent list kicking around of which ones work (Monzo, for instance). https://privsec.dev/posts/android/banking-applications-compatibility-with-grapheneos/ https://privsec.dev/posts/android/banking-applications-compa...
- tranq_cassowary 8mo agoIt's more common in banking apps than in other apps to implement Play Integrity but it's cetainly not "most banks" that do it. It's still only a small subset. Sucks of course if it's your bank.
- UnreachableCode 8mo agoMaybe not in your region, but here in the UK I think the majority of high street banks do not function on GrapheneOS.
- palata 8mo ago> this also sort of defeats the purpose Not really. On GrapheneOS, the Play Services/Play Store run as sandboxed apps, i.e. they are not system apps like on Android. They just run like a normal, unprivileged app. That's a lot better than on Android. > I'd rather break free from Google and Apple, not just (stock) Android and iOS If you want to break free, you don't have to install the Play Services / Play Store on GrapheneOS, just like you don't have to install microG on LineageOS. There is a misconception that microG is better than sandboxed Play, but I disagree. With microG, your apps still connect to the Google servers, so you're not "breaking free".
- microtonal 8mo agoWith microG, your apps still connect to the Google servers, so you're not "breaking free". Moreover, some OSes (e.g. /e/OS) give certain Google apps higher privileges than other apps even with microG, install Android Auto and it's still game over. GrapheneOS does not have this issue because as you say, Google apps/services get sandboxed. Obligatory link: https://eylenburg.github.io/android_comparison.htm https://eylenburg.github.io/android_comparison.htm
- adezxc 8mo agoYup, also Google Pay doesn't work, though there are other providers which work fine (Curve Pay I think works in all of EU), but it just made me carry my wallet everywhere and I understood I don't mind that at all.
- microtonal 8mo agoI still have my Apple Watch configured, so I'm just doing the NFC payments with that :).
- kaopor 8mo agoSince all of comments are about NFC payments, this should be higher. Can confirm Curve Pay works (pixel 9a) at least with one Greek bank and Revilut. Not affiliated in any way with them and don't know this service is actually works just Yeah I'm amazed too.
- zhouzhao 8mo agoOf course that is highly depdendet on the bank used, but so far none of my banking apps didn't work! If you are using a rather popular banking app, chances are high that it has been discussed in the GrapheneOS forum. Anyway, with google play services installed, mine have worked out of the box.
- dgxyz 8mo agoDoes anyone know if HSBC's UK app works on it? I've seen inconsistent reports that it does and doesn't. Edit: ignore this - there's a list elsewhere in this thread!
- mentalgear 8mo ago"Banking Applications Compatibility with GrapheneOS" https://privsec.dev/posts/android/banking-applications-compatibility-with-grapheneos/ https://privsec.dev/posts/android/banking-applications-compa...
- rcMgD2BwE72F 8mo agoI contacted my bank, insisting that GrapheneOS is one of the most secure OS on the market and therefore should be supported if they actually care about users' security (it's actually far more secure than all the old, far less secure but Google-approved devices out there). They acknowledged an fixed their app, one of the most popular in France. Still missing Android Pay but that's due to Android Pay being closed. I wish banks would do something and support NFC payment systems that don't require the device to be controlled by Google (how can we be okay with this?!)
- jackhalford 8mo agoI’m interested which french bank is this?
- palata 8mo ago> I wish banks would do something and support NFC payment systems that don't require the device to be controlled by Google There are countries where it's possible to pay everywhere with the banking app scanning a QR code. No need for NFC :-).
- stephenr 8mo agoI use qr based payments regularly where I live, and in my home country I use nfc payments (watch/phone/card) essentially always, when we visit. NFC is by far more convenient and reliable.
- palata 8mo agoI can't say about "convenient" because I don't use it, but I have been using QR codes for years and I haven't had a single issue. I don't know anyone who has. QR codes are reliable.
- stephenr 8mo agoIt's regularly unreliable here, because it's reliant on a bank app which in turn is reliant on an internet connection, and banks here are kind of shit. It's pretty common here that people will be told they need to turn off an otherwise working Wifi connection when facing problems because bank apps will often just not work properly on wifi. But as I said, even without that, the convenience level is ridiculously different. It's arguably quicker to open your wallet and use a debit card with an NFC chip than it is to use QR codes, before we even talk about the convenience of watch/phone payments using NFC.
- joebe89 8mo agoWhat about the small matter of having to purchase a Google phone in the first place?
- palata 8mo agoI see it as a necessity, because the Google phone is the only one worth it if you care about security. The problem is not GrapheneOS, but rather that phone manufacturers other than Google don't care. Now if there were millions of GrapheneOS users, it would start becoming interesting for other phone manufacturers to care. My point being that I buy Pixel in order to give more weight to GrapheneOS, in the hope that other manufacturers will eventually realise that.
- backscratches 8mo agoMost anti-google move: buy a second hand pixel, they receive no revenue on the device which is (assumed) already highly subsidized by google so that they can profit off users' data, then you use their subsidized hardware without running their spyware OS. Google only loses money in this scenario, it is a great protest.
- Aachen 8mo agoHave you seen those prices? I don't think the devices need subsidising at all. How else could competitors, who aren't selling off your data, offer it for cheaper?
- backscratches 8mo agocompetitors also sell off your data, via uninstallable google spyware in most cases!
- Aachen 8mo agoThat depends on (1) which one you pick and (2) whether you keep the stock OS Given that there exist vendors like Fairphone/Murena that sell lower-performant hardware at much lower price points, it seems to me that the expensive but decent hardware (like Google's flagship) might be priced appropriately as well Other competitors (that do track you, like Samsung) have similar price points for their high-end hardware and are again much cheaper for slower hardware. If selling data is so essential, they wouldn't allow removing the tracking. (Samsung may be a bad example because they removed it last summer, but root popularity has been diminishing since early android days anyway so I can't imagine it's a big factor for them)
- tonylemesmer 8mo agoyep - tried GrapheneOS for the first time today and my banking app detected that the phone was jailbroken.
- microtonal 8mo agoDid you relock the bootloader and disable OEM unlocking as part of the GrapheneOS onboarding?
- lpcvoid 8mo agoBeen using GOS since roughly 2020. I refuse to use a Phone without GOS on it. It's been amazing.
- palata 8mo agoI am really hoping that other phone manufacturers will eventually realise that and start making phones that can be supported by GOS.
- strcat 8mo agoGrapheneOS was contacted by one of the largest Android OEMs in June 2025 and we're actively working with them. They're going to be announcing our partnership in March 2026 and the phones meeting our requirements with official GrapheneOS support are scheduled for 2027.
- palata 8mo agoMarch? Wow that it huge! Congrats!
- strcat 8mo agoYes, March 2026 is when the first announcement from the OEM will be which is when people will find out which OEM it is. A fair bit into 2027 is when the devices supporting GrapheneOS will be launched. It was theoretically possible for it to happen for 2026 but not very realistic and the hardware wasn't quite there yet.
- palata 8mo agoIn my opinion (which is worth what it is worth), 2027 is perfectly fine (my Pixel should live a lot longer than that anyway). What I find huge is that it is concretely happening! It will show recognition for GrapheneOS, and it will be great to have an alternative to the Google Pixels. Also, people looking at GrapheneOS want technical excellence, so better not rush it :-).
- franczesko 8mo agoWhy only pixel phones are supported?
- lpcvoid 8mo agoBecause google actually cares about hardware and software security. Read the FAQ: https://grapheneos.org/faq#supported-devices https://grapheneos.org/faq#supported-devices
- zhouzhao 8mo ago>Because google actually cares about hardware and software security. That statement might not have aged so well, especially consindering googles attempt to lock out apps from their devices, If the developers do not comply with being oficially registered.
- lowdude 8mo agoThere is a difference between security and privacy or freedom of use. Locking down the device to only allow a subset of apps that Google has some control over (by requiring developers to register) is a measure that can increase security, even though it obviously takes some control away from the end-user. The fact that the play store is not exactly known for exceptionally high standards w.r.t. malware, or that there are lots of valid concerns that come along with a company controlling who is allowed to supply apps for the device is a different topic.
- izacus 8mo agoDon't mix security and freedom. They're commonly opposed to each other.
- palata 8mo agoThis is true, I don't get the downvotes.
- tranq_cassowary 8mo ago
- h4x0rr 8mo ago"Break Free from Android and iOS" looks inside - Android
- mft_ 8mo agoIt should probably be "break free from Google and Apple"?
- to3k 8mo agoYou are right! I will change the title :)
- g947o 8mo agoAs long as it is based on AOSP, it is at the mercy of Google to release source code and updates. Given recent trends, I wouldn't be surprised if Google stops shipping Android source completely.
- mvanbaak 8mo agohow will it help you to break free from apple if it only supports pixel phones?
- mft_ 8mo agoOne reason that people use Apple phones is they are seen as a less privacy-invasive option than Android/Google. So it would follow that a valid privacy-respecting third option would potentially help Apple customers as well as Google customers.
- timbit42 8mo agoThey are working on making their own phone hardware.
- goodpoint 8mo ago...on a google phone.
- 8mo ago
- Myzel394 8mo agoI've been using GrapheneOS for about 3 years now. For the most part, it works very well. I don't have any issues with banking apps, nor any other closed source apps. I'm using two profiles both with sandboxed Google play installed. I'm logged in into my private Google account on the work profile. However, there was one case that lead me to thinking about ditching grapheneos to this day. I installed Uber on my phone and I was able to successfully create an account and use it. When it came to booking a ride, the app crashed and I had to log in again. Once I did that, I was told that my account has been suspended for violating the terms of services. All I did to that point was creating an account and booking a ride. I was able to resolve the issue luckily after a few days and going back and fourth a couple of times with the Uber support, however, the risk of getting banned on any such platform is still risky, and thus I'm not sure if grapheneos is usable if you need to use such services.
- peanut_merchant 8mo agoI regularly use Uber on Graphene OS and have had no issues.
- rcMgD2BwE72F 8mo agoThat's clearly a Uber problem. I'm also a GrapheneOS and used Uber once -- it worked.
- HunOL 8mo agoIt's clearly end user problem who is not able to book a ride. Root cause is on Uber side.
- ThePowerOfFuet 8mo ago>there was one case that lead me to thinking about ditching grapheneos to this day Your aim is misplaced: ditch Uber, not GrapheneOS.
- budududuroiu 8mo agoI'm a new GrapheneOS user and stopped using Uber as altogether. Taxis aren't that bad where I'm at, and cheaper than Uber
- mentalgear 8mo agoThis is especially interesting in regard to the recent HN dicussion on spyware by for-profit intel firms having access to Whatsapp, Telegram, Signal, etc. (https://news.ycombinator.com/item?id=47033976 https://news.ycombinator.com/item?id=47033976) through OS-level no-click hijacks. I wonder how secure GrapheneOS is in that regard, and what the other contenders are?
- cartoonworld 8mo agoGrapheneOS have hardened_malloc which is a huge advantage, I think. It makes the weird machines problem much harder. I would say be very careful, because you can still get previews of images, or old and weird media formats that could be exploitable, and android/GrapheneOS doesn't have the same sorts of policy as say Apple with the iMessage blast door. They control safari, etc. Android's attack surface seems pretty jagged. For example there is only one webrender engine on iOS, where you can run anything you like on Android/GrapheneOS.
- tranq_cassowary 8mo agoChromium is the only web engine present on a fresh install. If a user doesn't install a browser with another engine, the attack surface doesn't get increased. Chromium/Blink is more secure than Safari/Webkit overall so I don't really think this is an argument in favour of iOS. iOS for sure does some good things though and is better than Android in some areas.
- subscribed 8mo agoHard to say how it fares against those specific attacks but some of the vulnerabilities that will go out in the mid-2026 on the mainstream handsets are already patched: https://grapheneos.org/releases#2026021200 https://grapheneos.org/releases#2026021200 (it's not magic. All big vendors have these details, just choose to take their sweet time to patch them. GOS has partnered with a major OEM vendor who provides them with access) Other than the specific patches above, there's a list of generic GOS features: https://grapheneos.org/features#exploit-protection https://grapheneos.org/features#exploit-protection All in all you're probably much safer.
- ramon156 8mo agoDoes anyone have a good grasp of the differences between GOS and /e/OS? I'm buying a Fairphone soon and was wondering what both are like
- SockThief 8mo agoConsider this (by Graphene OS): https://discuss.grapheneos.org/d/24134-devices-lacking-standard-privacysecurity-patches-and-protections-arent-private https://discuss.grapheneos.org/d/24134-devices-lacking-stand... /e/OS community talking about it: https://community.e.foundation/t/article-from-grapheneos-about-e-os/72203 https://community.e.foundation/t/article-from-grapheneos-abo... And then maybe this: https://eylenburg.github.io/android_comparison.htm https://eylenburg.github.io/android_comparison.htm Hope that helps.
- realusername 8mo agoI like GrapheneOS but they fail to understand in this post that the #1 security concern an android user face is the lack of privacy. Sure they have hardened everything but realistically, that's not the main threat for your average user. Their top contribution to android is the sandboxed Google Play, by far.
- gf000 8mo agoprivacy != security. And sandboxed Google Play services serve both goals -- it runs the service as a regular android service, not an exceptional one that has a bunch of extra permissions. So you can allow/restrict it as you seem fit, while not "getting behind" on features/apps that mandate it.
- realusername 8mo agoI disagree, privacy is an essential part of security, if there's no privacy, then there's no security. That's also why I don't keep anything important on my phone as I don't trust what's going on there despite having all the secure features that you would want.
- dizhn 8mo agoGrapheneOS is Android isn't it? Same binary blob issues and such? Or is that not an issue on Pixel devices?
- palata 8mo agoIt is not. GrapheneOS is AOSP-based. But yeah, same binary blob issues for firmwares, but Linux on Mobile has the same issues.
- dizhn 8mo agoIt's not very important but what are you referring to with "it is not" ? AOSP is Android (it's in the name) so I don't get it. Are you talking about blobs re Pixel devices?
- palata 8mo agoNo, I really meant that AOSP is not Android. Android builds on top of AOSP. I elaborated here: https://news.ycombinator.com/item?id=47047167 https://news.ycombinator.com/item?id=47047167
- dizhn 8mo agoWell. I do get your point and I am aware of the situation and how Google pivoted away from a truly open source OS by systematically moving components like the keyboard to separate closed source apps. The fact remains though that it's Android Open Source Project where all Android systems are based on. It's become sort of a GNU/Linux kind of distinction where the "certified" Android is AOSP + Google. Though the situation is not that clear because there are other Android based phones that do not contain the Google layer but are still Android.
- palata 8mo ago> Though the situation is not that clear because there are other Android based phones that do not contain the Google layer but are still Android. Which ones? I'm pretty sure that being "Android" means that you are certified by Google. You cannot sell an Android device if it's not certified by Google. > It's become sort of a GNU/Linux kind of distinction where the "certified" Android is AOSP + Google It depends on the context. If someone asks you "are you using Windows or Linux?", answering "I'm using GNU/Linux" is a way to show that you are that kind of people. But if someone asks you what userland you are using, then suddenly it makes sense to make a distinction between GNU and, say, busybox. When someone asks me if I have and iPhone or Android, I say Android (even though I am running GrapheneOS). But when we're talking specifically about an alternative to Android that builds upon AOSP, then I think it makes sense to make a distinction. There is a whole (niche) market of AOSP-based alternatives to Android, that users choose specifically because they are not Android. When we talk about that, it makes sense to use the right words.
- 6jQhWNYh 8mo agoIt's a shame only Pixel phones are supported. I have PWM sensitivity and Pixel phones are notoriously bad for this, my eyes hurt when I look at one for more than 30mn. Due to the lack of good, secure alternative, I have had to give up on privacy in exchange for manufacturer updates.
- sudonem 8mo agoThe Pixel limitations has been my main concern as well. The good news is that they are actively working on developing their own hardware. The bad news is that it’s been delayed. But I’m watching closely. https://www.galaxus.at/en/page/grapheneos-postpones-pixel-alternative-to-2027-41106 https://www.galaxus.at/en/page/grapheneos-postpones-pixel-al...
- 6jQhWNYh 8mo agoInteresting article. Let's now hope for a reasonable price, even though it will be challenging for their team. It would be a shame if the target audience is limited to overpaid nerds like most of HN.
- wolvoleo 8mo agoThat article speculates the OEM is Samsung but I find that very hard to believe. Samsung is totally beholden to Google. The discontinued their own DeX and Tizen smartwatch OS for Google alternatives and as for their "AI" features most of them actually come from Google. Google would not allow this and they're way too entangled with Samsung.
- lejalv 8mo ago> when I look at one for more than 30mn That limitation might be doing you a favor, as these things go... Even if Pixels hadn't PWM a larger screen (or, dare I say, a book) will be an improvement for longer reading sessions.
- backscratches 8mo agoSeconded. Really hope the new Graphene device does not have terrible PWM. Battery benefit to OLED is great but not if I can't look at my phone.
- xvilka 8mo agoThey should get the same level of financing (donations) as Tor project at least. Some big organization like Open Technology Fund or NLnet should give them yearly grants.
- olejorgenb 8mo ago900+ donors on github (https://grapheneos.org/donate#github https://grapheneos.org/donate#github) is not *too* bad, but likely not enough to cover a full salary.
- choeger 8mo agoWhat about device attestation? Will you be able to run banking apps and Netflix et. al.? For me the biggest concern is that while you may be able to use and run your own device, you will be locked out of most propietary services. Much like how more and more websites simply don't work with Firefox anymore.
- lawn 8mo agoAll Swedish banking apps I've tried works great. Including BankID, swish, Sparbanken, Nordea, LF, Revolut and more. I've had less issues than with CalyxOS for example, where more apps broke.
- buzzwords 8mo agoThis might be one of those things were if there is big enough user base, companies will start to take it seriously.
- strcat 8mo agoNearly all non-banking apps work with very few exceptions. A large majority of banking apps work. A growing number of banking apps were adding checks for Google certification but now a growing number of those are explicitly allowing GrapheneOS via the Android hardware-based attestation system it supports which can be used to verify the hardware, OS and app with an alternate OS or non-Google-certified hardware if it adds the hardware support for it.
- xnacly 8mo agoWell i do use banking and netflix on graphene os on my pixel 8a and everything works perfectly
- ThePowerOfFuet 8mo agoNetflix and almost all banking apps work fine. https://grapheneos.org/articles/attestation-compatibility-guide https://grapheneos.org/articles/attestation-compatibility-gu... https://privsec.dev/posts/android/banking-applications-compatibility-with-grapheneos/ https://privsec.dev/posts/android/banking-applications-compa...
- haunter 8mo agoBreak free from Android... by installing Android? I'm not sure it's really breaking free when the first task to do is intall Google Play Services so your banking app works. Sounds like we can't actually breaking free from Android and iOS. Maybe with Linux like the Fedora Atomic for mobile devices? https://github.com/pocketblue/pocketblue https://github.com/pocketblue/pocketblue Or PostmarketOS? https://postmarketos.org/ https://postmarketos.org/ Even then banking would probably only work through the browser... Sad state of the world really.
- to3k 8mo agoI tried Ubuntu Touch and Droidian https://blog.tomaszdunia.pl/ubuntu-touch-eng/ https://blog.tomaszdunia.pl/ubuntu-touch-eng/ https://blog.tomaszdunia.pl/droidian-eng/ https://blog.tomaszdunia.pl/droidian-eng/
- arein3 8mo agoAnd the 50% of banking apps still wont work because it wants an android signed by google. And no tap to pay. Hopefully the new EU banking system will work on Graphene and Ill switch back
- wisplike 8mo ago[dead]
- Maken 8mo agoThe new payment networks are not an independent app. They are a protocol your banking app has to implement, so unless your bank supports non-Google phones you are out of luck (not my case, thankfully).
- lejalv 8mo agoI would put the focus on having capable web-banking. I never install the banking app on my phone. I must also be getting old, because I don't get the big fuss about NFC payments. Firstly, I'd never use them if they go through Google/Apple. But even when/if they don't, it's not a big deal to use a card, isn't it (if you hate cash)?
- rubymamis 8mo agoWe need Linux OSes and phones to catch up to really break free from this duopoly. Only when there is enough traction, essential infrastructure like banks will start supporting Oses like that. It's a chicken and egg kind of problem.
- gf000 8mo agoAndroid is a Linux OS and is eons ahead anything that would sit on top of "GNU/Linux" userspace. Why start from scratch?
- galangalalgol 8mo agoYeah, just need to decide where to start the fork. The larger problem is radio firmware. FCC regs were the initial excuse, for wifi and Bluetooth too, but we need to open up the source for all of these and allocate money for enforcement if we are truly worried people are going to start adding wifi channels etc. Open firmware phone radios would let you do things like truly turning off the radio when wifi was present, no gps ping even.
- palata 8mo agoThe good news being that the work made by Linux on Mobile projects regarding the radio firmware benefits AOSP projects, and inversely, right?
- pelzatessa 8mo agoI think that the main problem is that android has a lot of weird modifications that are not consistent with the rest of linux distros. The user data is suddenly in /data instead of /home, theres no package manager, no systemd (for better or worse), and there's hella lotta security gotchas, for example call recording is impossible without root as far as I know. I'm not saying that Android is not hackable, but it's a different type of hackability than desktop linux, you have to learn it all over again and in my opinion it's much harder to master than desktop linux. I've been on ubports for 3 years and while it also has some weird caveats like read only rootfs, no working package manager (due to read-only fs. however ubports has pretty cool support for lxc containers where you can use apt). Due to chronic lack of time I haven't been able to sit down on my phone to play with it a bit (for example id like to install waydroid), but it seems a lot easier than android. For example, while there isn't an app for call recording, some guy worked around it by writing a systemd user service as a workaround[1]. This is exactly the type of thing I'm thinking about when talking "linux phone". For me as a linux user, the difference if ubports was a human, I'd think that perhaps they were sick, whereas if android was a human, i'd shoot them in the face :) [1] https://forums.ubports.com/post/75157 https://forums.ubports.com/post/75157
- absqueued 8mo agoHow is it a break from google/appple if the only supported devices are Pixels? I can't use my sony or other vendors hardware at all. Are there valid reasons to only support pixels?
- gf000 8mo agoThey are the only Android phones that have the proper security primitives to build a secure OS on top.
- jsheard 8mo agoAlso, they are working on bringing a non-Pixel alternative to market: https://www.androidauthority.com/graphene-os-major-android-oem-partnership-3606853/ https://www.androidauthority.com/graphene-os-major-android-o...
- strcat 8mo agoPixels are the only devices providing the required updates and security features. These requirements are listed here: https://grapheneos.org/faq#future-devices https://grapheneos.org/faq#future-devices GrapheneOS is partnered with a major Android OEM working on improving their future devices to meet our requirements. The first devices with official GrapheneOS support from them are planned for 2027. It takes time and resources to make reasonably secure devices. Future generations can improve further including adding hardware-based privacy/security protections unavailable on Pixels.
- daoboy 8mo agoMany are complaining about banking app compatability, but I've never felt compelled to use anything other than my browser for banking. What's the big deal with the banking apps? Am missing out on some huge advantage here?
- dgan 8mo agoSome banks force you to validate transfers on your phone; unfortunately its not the user who decides
- rationalist 8mo agoDepositing checks by taking a picture of them.
- Aachen 8mo agoIf I knew what a cheque even looks like, that might be a benefit
- rationalist 8mo agoI don't think that comes across how you intend.
- Aachen 8mo agoThat being?
- voxadam 8mo agoWhile I admire GrapheneOS and its goals, I feel that until we free the proprietary baseband processors and their RTOS from the grips of Qualcomm and friends it's a pyrrhic victory, at best.
- palata 8mo agoWhen there isn't a perfect solution, the next best thing is... the next best thing :-).
- deleted 8mo ago[deleted]
- darkwater 8mo agoUnless the next best thing makes you think you are already achieving the "perfect solution" for what you think you care about, but in truth does not. I'm not a mobile phone security expert but my feeling is that in the case of GrapheneOS - which target is probably high-profile people at risk of state actors et similia attacks - a zero-day in the closed source firmware from Qualcomm will probably screw you anyway. I understand that you are anyway reducing the attack surface (now they need to target the modem firmware specifically), I understand the concept of security in depth and I also understand that by using GrapheneOS you are already placing mitigations for many other known and unknown attack vectors. But still...
- cartoonworld 8mo agofyi a Cell Site Simulator can masquerade as the legitimate telco operator and push type 0 messages to the handset. What that means is they can push malicious settings and configurations (Definitely) and probably malicious firmware to the handset at will. They don't need to code this, they buy the software packages from the usual suspects. Adversary simply needs to put a drt box or a hailstorm or what-not close enough to the handset to do the work. The baseband can do a lot, it has dma (if I recall correctly) and can almost certainly screen look, and extract information from some but not all base bands. This varies. GrapheneOS cannot really influence this, but hardened_malloc could conceivably help. What would be great is a bench firmware re-flash, but I don't want to do this every single day.
- thisislife2 8mo agoGrapheneOS' approach is to focus more on security than privacy, because they believe increased security leads to increased privacy. Unfortunately, that means their hardware requirements pretty much limit the hardware that you can run it on (currently only the Pixel phone range). Worse, it also means they stop supporting a device when it reaches End-Of-Life as software security updates stop for it (see How long can GrapheneOS support my device for? - https://grapheneos.org/faq#device-lifetime https://grapheneos.org/faq#device-lifetime ). Sad though - GrapheneOS on Sony Open Devices ( https://developer.sony.com/open-source/aosp-on-xperia-open-devices https://developer.sony.com/open-source/aosp-on-xperia-open-d... ) would have been nice.
- stephenr 8mo agoI'm not sure I fully understand this. Why are GrapheneOS releases dependant on Google releases?
- palata 8mo agoThey are dependent on the AOSP releases (which Google develops) and on the manufacturer updates (and because GrapheneOS runs on Pixels, then it goes back to Google again).
- stephenr 8mo agoI can understand relying on an OEM to provide hardware support for a given model - but I'm finding it hard to understand why they're unable to continue supporting a release just because the upstream removes support for something. I'm not even really sure what you mean by "manufacturer updates". The more I hear about this project, the less is sounds like an alternative OS and more it sounds like a thin skin around whatever shit Google throws out, to be honest.
- palata 8mo ago> why they're unable to continue supporting a release just because the upstream removes support for something. If you have an EOL Pixel and a new major version of Android is released, Google will not port this new version of Android (and therefore AOSP) to it. So GrapheneOS would have to do it. GrapheneOS just say they don't have the resources to do that, so they follow the Google releases. Could you keep an EOL Pixel without receiving updates? Sure. But then it's not supported anymore, it's just outdated, insecure software. > I'm not even really sure what you mean by "manufacturer updates". There are the AOSP updates (which bring new features, but importantly in our case bring security fixes) that come from Google, but your phone is more than that. There is a bunch of hardware running in your phone and a bunch of firmwares exposing it. Say your camera, or your wifi module, etc. If there is a security issue in the firmware of the camera, then it won't be fixed in the AOSP codebase. You need the camera manufacturer to fix it and release a firmware, pass it to the phone manufacturer who will then deploy it on your phone. Google split both of those concepts years ago in order to deploy Android updates faster and make everybody more secure, because manufacturers had a tendency to lag a lot. Some still do but the situation generally improved, I think. Anyway, you need to receive those security updates from your manufacturer because they are independent from Google. > the less is sounds like an alternative OS and more it sounds like a thin skin around whatever shit Google throws out, to be honest. If you think that AOSP is shit, then sure. I mean, if you think that the Linux kernel is shit, maybe you don't want to run a Linux distribution. I personally think that AOSP is pretty great, and vastly superior to Linux on mobile (among other because it has a much better security model). I am not a big fan of Google being root on my phone (with Android and system apps like Play Services), which is something that GrapheneOS fixes (by making Play Services run like any other, unprivileged app). GrapheneOS is also adding privacy features, be it by proxying your location requests (so that they go through the GrapheneOS servers instead of directly to Google) or by adding features like "scopes", where you can choose exactly which contact you share with an app, for instance, or refuse Internet access to an app without breaking it (GrapheneOS will just make the app believe that it has the permission to access the internet but there is just no connection right now). And of course GrapheneOS hardens the system in terms of security (e.g. with a hardened malloc or memory tagging stuff that Apple recently introduced as well). So yeah, it is relatively thin, because AOSP is a huge codebase. But it doesn't mean that it's worthless: this skin makes it more secure, more private, and for me more enjoyable than Android.
- tcfhgj 8mo agoBreak free from Google and Apple by buying a phone from Google /s
- backscratches 8mo agoI commented elsewhere but GrapheneOS on Pixels actively siphon resources from Google and is arguably a good protest against google. They subsidize Pixel hardware (to incentivize users to adopt their spyware OS), you (buying used obviously) take their subsidized hardware and do not repay them by using their spyware, replacing it with Graphene. Only google loses. Their hardware is technically very good otherwise (in fact no other hardware fits the strict graphene security requirements).
- imcritic 8mo agoHow about they start supporting more devices instead?
- backscratches 8mo agoGood news they are making their own devices. But until then pixels are technically the most secure android devices and graphene would not be as robust on other devices.
- ysnp 8mo agoSmall correction, GrapheneOS are not making them. They are partnering with an existing large OEM to ensure one or a number of future flagship devices meets their security, privacy and support requirements.
- mathfailure 8mo agoNo, there are no such news yet, only hearsay.
- strcat 8mo ago
- lambdaone 8mo agoIt's a sign of how far we've come that this article says "Break Free from Google and Apple", not "Break Free from Google, Apple and Microsoft".
- nusl 8mo agoPeople seem to fondly remember the Microsoft phones. If they made them now though, I can't really imagine what sort of Copilot-filled abomination they would be.
- guerrilla 8mo agoYeah that's not actually good. As much as I'd never use anything from Microsoft, having less diversity is not a step in the right direction.
- Tepix 8mo agoI heard that Windows on phones is about to make a return later this year, thanks to NexPhone.
- axegon_ 8mo agoFor some (and other not-so) obvious reasons I switched to Graphene a few weeks ago. For years I've been pushing towards de-cloudifying my digital life and there were several reasons for it: On one hand it was the constant content subscription which gave me 0 guarantees that what I am interested in will still be available the next morning, even though I've paid for it, and the other was, you guessed it, the idiotic LLMs everywhere and subsequently the complete annihilation of security practices by giving a probabilistic model unrestricted access to all of your data. First things, first, kudos to the GrapheneOS team for making it this easy to install and the surprisingly rapid support for new devices. Sure, there are features which I otherwise liked in the stock android that came with Pixel phones(swipe typing is something I very much enjoyed) but all in all, I can't say I miss much from it otherwise. I've slimmed down my list of apps to basic functionalities backed by self-hosted services (nextcloud, immich, jellifin, etc. along with a VPN I maintain myself) and I honestly don't miss much from the stock Android. I want to point out that for a very long time I worked for a company that developed games for mobile devices and while the data we collected was mostly anonymous(*unless you logged in with facebook and by implications we had your facebook id) and it was never even utilized all that much beyond bad attempts at maximizing sales(not effectively anyway cause the people in charge were as incompetent as they could get), I can say that we collected ungodly amounts of data: most of the cloud bills were storage for that specific reason. While we did not have bad intentions and had to operate under strict GDPR regulations, this was a large company that was constantly monitored. Small companies can fly under the radar and get away with not abiding by the rules and laws and commonly they are not even aware what the repercussions could be. Similarly, the US and Asia-based giants can simply shrug it off and toss a few billions in fines. Make no mistake, no company is looking for your best interest and with that in mind, I couldn't recommend GrapheneOS (and self-hosting everything) enough, assuming you know what you are doing.
- 8K832d7tNmiQ 8mo agoCheck out FUTO Keyboard, It has swipe-typing feature.
- linux_modder 8mo agoFUTO has many issues, beyond licensing like it's lack of privacy features.
- mnmatin 8mo agoWallet Apps and Tap-to-pay do not work. Even got banned from PayPal. Android needs an architectural change from the ground up.
- dopidopHN2 8mo agoI'm happy with grapheneOS as a daily driver. Can you elaborate on being banned from paypal so I don't do the same ?
- ozlikethewizard 8mo agoI mean you're not degoogling yourself if you put all your transactions through a google server. Cash if possible, card if not. (Also it is possible to do these things if you root your phone, but caries its own risks and I wouldn't recommend. Ending your dependency on third party processors is probably the best outcome)
- Tepix 8mo agoIf you don't use the paypal app, you should be fine, right?
- aniviacat 8mo agoI use the PayPal app with Tap-to-pay on GrapheneOS and I haven't been banned. But of course that's entirely up to how their algorithm happens to feel about you.
- user3939382 8mo agoWhat you want is a solar 6502 with lots of memory and GMRS mesh
- deafpolygon 8mo agoGrapheneOS is like using Firefox. Works on most sites, but those few things just don’t. Maybe it’s a dealbreaker for some. And they’re dependent on Google.
- ementally 8mo agoShould be noted that in order for OEM unlocking toggle to work, you need to turn on WiFi and connect to the internet.
- Aachen 8mo agoHuh, and here I thought Google was one of the few manufacturers left that simply support it on their hardware. So it depends on some cloud service being alive. Do you know if it's the same for Fairphone or Shiftphone? Or is there another manufacturer that doesn't require this? I've recently bought a new phone so it's not relevant for me anymore but when I next go looking, it can factor into it. As it was, I had Google marked in my spreadsheet as the most accessible unlock method together with brands like Oneplus and Fairphone
- chenxiaolong 8mo agoIt's probably worth pointing out that the online process is one time and it installs a token that permanently lets the setting be toggled offline afterwards. This persists across factory resets and flashing any OS. I wrote more details about it works under the hood here: https://news.ycombinator.com/item?id=35856171 https://news.ycombinator.com/item?id=35856171
- Aachen 8mo agoEpic level comment! Very interesting to read about in this technical detail, thanks for taking the time to write it up.
- bergheim 8mo agoBeen using this for about a year on a p9 pro. It works very well. I hear the google tap to pay does not work, but I've never tried it. However Vipps with their tap to pay works fine. BankID works but not with biometric login, which some things require IIRC. And for some reason DnB private works fine, but you are not allowed in on the corp app. It's mind boggingly stupid that they lock down apps like this, when you can just open the thing in a website anyway. I can use my bank on some linux distro, crazy that they trust me since it is not Windows - the truly secure OS! Knew about those things before I started, so all in all I'm pretty happy. I'd recommend NOT using different users for different things (I started with banking etc in one profile, that ended up being a huge PITA and according to their docs it is mostly security theater anyway). Happy tinkering!
- iamgrootali 8mo ago[flagged]
- vages 8mo agoThanks for the Norwegian perspective. I agree that the locking down is truly stupid. For what it’s worth, the reasoning for locking down mobile apps is allegedly that mobile users are a less technologically competent demographic than desktop users. I do not think so myself, given the difficulty in trying Graphene vs. Desktop Linux.
- malfist 8mo agoThose people who root their phone and install alternate OSes sure are less technologically competent than someone with a browser and a laptop
- UqWBcuFx6NV4r 8mo ago“Installing alternate OSs” is juicy bait for “tech enthusiasts” who know just enough to be effectively worse off than someone with a browser, yes, and at its core is this holier than thou attitude.
- 8mo ago
- sandreas 8mo agoI personally tend to own two Phones. One all-day carry GrapheneOS device (Pixel 8) and an older WiFi and at home only iPhone for all payment and ensurance stuff. This is inconvenient in some ways, but at least it is sort of privacy as good as it gets while still being able to run official apps when I need them at home. To de-google the phone, I use F-Droid as primary App store, Aurora as fallback for non-f-droid Apps and as a last resort Obtainium to install Apps that are not in these stores. The only google App I really "need" (kind of) is the Camera App, which is sandboxed via GrapheneOS Storage Spaces and without Network permission (why would a camera need internet?). To backup my phone, I use the integrated GrapheneOS Solution (seedvault!?) for storage and apps, immich for Photos and MyPhoneExplorer for Contacts. Sometimes it is a bit hard to find good apps for specific purposes, so for everyone interested, here is a list of Apps that I personally use or have used. Newpipe - Youtube Client Audiobookshelf - Audiobooks Voice (PaulWoitaschek) - Local Audiobook Player Substreamer - Music DSub - Music (alternative) VLC - Video-Player Organic Maps - Google Maps alternative (not as good) PDF Doc Scanner - Open Source Document Scanner Wireguard - VPN Immich - Photo Backup / Viewer LocalSend - File Transfer K9 Mail / FairMail - Email Client KOReader - Ebooks Binary Eye - QRCodes and Barcodes Pure Todo - Self hosted PWA PHP Todo List Signal - Messenger Open Camera - Open Source Camera App
- nickorlow 8mo agoGrayjay is another good YouTube (and other streaming platform) client made by the company that owns Immich
- sandreas 8mo agoUh this looks nice. Thank you.
- 72deluxe 8mo agoI like Organic Maps because it isn't full of the social things. Every time I open Google Maps it shows that card at the bottom with "what's popular in your area", full of pictures of people's breakfasts and other nonsense. Organic Maps is free of this noise. Also, the desktop client on Linux is quite useful. Alternatives for Windows etc. are Cruiser Maps, a Java application (and also available as an Android app).
- palantird 8mo ago> "Perplexity - I switched to Gemini, but I confirm it works" Oh the irony.
- raincole 8mo agoWhere is it? I had a really hard time finding the irony.
- rcMgD2BwE72F 8mo agoIf they switch mostly for privacy reason, then starting using Gemini might be counter productive as Google might learn far more about the end-user than if they just did some basic search on any other Android devices. To enable Gemini, one was to accept some crazy T&C and accept that Google collects an incredible amount of personal data. I prefer to use intermediaries like Kagi Assistant, thanks to the strict privacy conditions of the API and the mixing of queries from thousands of users.
- raincole 8mo agoI mean... yes? But I really don't think there is any 'irony' here. The author clearly stated: > It’s thanks to them that we even have the option of at least partially freeing ourselves from Google (Android) and Apple (iOS) partially. And I do think they successfully did this. Asking Gemini questions when you really have something to ask is very different from integrating your whole digital life with Google.
- HunOL 8mo agoIt's not breaking free from Google, but pretending it does not affect you. You are still at mercy of app developers and Google which may introduce some changes that will affect you. Additionally you never know what will work or stop working.
- _heimdall 8mo agoThat's pretty unavoidable at that level unless you are able and willing to build your own phone hardware, OS, and all the apps you need.
- timbit42 8mo agoThey are working with a partner to create their one phone hardware.
- Tepix 8mo agoIf something truly unacceptable happens, you still have a while to switch to something else, in the meantime you will still have a working system.
- wseqyrku 8mo agoIt's weird that here on HN some people are trying to break free from Google and Apple and on the other side some people are married to Gemini, and both look like to be the majority at times.
- codethief 8mo agoI've used GrapheneOS on a Pixel 3a, 5, 8 and 10 Pro so far and it's worked really well. I couldn't imagine going back. The only things I'm missing (which don't exist in other OS'es either): - Being able to configure contact scopes in such a way that the app in question only gets access to the phone numbers of the contacts belonging to the label I specified, e.g. "WhatsApp", nothing more. Yes, one can of course add contacts' phone numbers to the contact scopes "by hand" but 1) there is a limit on the number of contacts/phone numbers configured this way, and 2) AFAIK there is no way to back up that list. - Being able to install browser extensions in Vanadium. - Being able to configure multiple VPNs at once, e.g. for Tailscale, ad filtering, blocking HackerNews during times when I should be doing something more productive :) etc., especially since the Vanadium browser doesn't support extensions (see above). I was hoping that the Rethink app might implement something like this (https://github.com/celzero/rethink-app/issues/1047 https://github.com/celzero/rethink-app/issues/1047) but it doesn't look like it's coming and it'd probably be much better to do this at the OS level.
- paul_h 8mo agoNote to self: look for second hand unlocked Pixel 10 pro!
- blahaj 8mo agoYou can use labels for contact scope.
- codethief 8mo agoYou might want to read my comment again. :) If you use labels, the app will have full access to the associated contacts, not just to their names & phone numbers.
- rkagerer 8mo agoI'm annoyed at everyone who shares my name, phone number and any other details with Meta. I never consented to it. The behavior of their app slurping up your contacts database is despicable. This doesn't answer your question, but in case it helps for others out there: it's possible to use WhatsApp with no access whatsoever to your contacts and I used it that way for years. Connecting with people is slightly jankier but it still works.
- bohdokas 8mo agoHah, just talked with my colleague, his feedback is that it’s too raw to be used daily
- rationalist 8mo agoYou might want to reconsider trusting your colleague's technical opinions.
- Aachen 8mo agoIf you're tech-literate enough to find the bootloader unlock, I find that a strange statement. Could $colleague be anymore specific?
- PlatoIsADisease 8mo agoAnyone like GrapheneOS better? Like it has some features? Or is it a locked down version of Android?
- MattTheRealOne 8mo agoI love the ability to block apps from accessing the network. There is no reason apps like the keyboard, camera, or other offline apps and games need access to the internet.
- bo1024 8mo agoWhat is the smallest phone that Graphene will run on? I would love to switch but these massive pixel phones are a no go for me.
- Aachen 8mo agoMaybe an old Pixel with an old version of GrapheneOS, but at that point you're losing most of the security benefits and, depending on your goals, you may be better served with a small phone running a different OS
- ysnp 8mo agoFrom a quick look online it may be the Pixel 8 https://www.gsmarena.com/google_pixel_8-12546.php https://www.gsmarena.com/google_pixel_8-12546.php at 150.5 x 70.8 x 8.9 mm based on recommended devices.
- kevin_thibedeau 8mo ago> Break free from Google and Apple Step 1: Buy a Google phone
- timbit42 8mo agoThey are working with a partner to get their own phone hardware.
- haskman 8mo agoAnd once you are on GrapheneOS, break free from your proprietary watch ecosystem and switch to GadgetBridge (https://gadgetbridge.org/ https://gadgetbridge.org/) I run a Thinkpad with NixOS and KDE, a Pixel 9 with GrapheneOS, and an Amazfit watch paired with GadgetBridge on my phone. It's a testament to the hard work of the FOSS maintainers of these projects, and the spirit of open source, that everything works flawlessly together without any cloud service sucking up my data. For example, I can control youtube and music playback on my laptop with my watch because KDE Connect syncs my laptop and my phone, and gadgetbridge syncs the phone and the watch. The breezy weather app on my phone can automatically push its data to gadgetbridge which in turn pushes the data to the watch. And so on. So many little things, developed independently, working like a single well oiled machine.
- BLKNSLVR 8mo agoI didn't need anything more on my to-do list, but this is intriguing.
- haskman 8mo agoSetting up GadgetBridge is very easy since it's just an android app. No flashing firmware etc. However, not all gadgets are equally supported, and you should check the support status of your device - https://gadgetbridge.org/gadgets/ https://gadgetbridge.org/gadgets/ (I bought my watch only after checking that page for compatibility).
- p-e-w 8mo ago> And once you are on GrapheneOS, break free from your proprietary watch ecosystem and switch to GadgetBridge Then switch back to Google/Apple after half a year when you discover that you can’t run - your banking app - any government app - the app required to access large sports events - the pandemic tracking app without which you can’t enter an airport - various other random apps because they ALL detect that you’re running on a phone with an unlocked bootloader and will flat out refuse to start. And for many of those, there is no legal alternative. (The extent of this varies depending on where you live, of course.)
- thomassmith65 8mo agoFull control over app permissions GrapheneOS allows for full control over what permissions each application can have. For example, in conventional Android forks, every application by default has granted Network (internet access) and Sensors [...] permissions. Has anyone ever wondered if all apps on a phone need Internet access? Well, Apple made privacy a major selling point, so I'm sure you can do this on iOS, too. /s https://news.ycombinator.com/item?id=40667147 https://news.ycombinator.com/item?id=40667147
- thisislife2 8mo agoApple's OSes do not include an Application Firewall that allows you to control which app can access the internet. Graphene OS does.
- trvhar 8mo agoBreaking free from Google by using a Google phone with a Google designed processor
- timbit42 8mo agoThey are working with a partner to get their own phone hardware, hopefully by next year.
- yamapikarya 8mo agois it worth to buy google pixel just for installing grapheneos? in my country, it is kinda pricey and of course it cannot install bank apps because almost all of them are must non root phone.
- riedel 8mo agoBreak free from Google by buying their hardware and be dependant on them to actively support the device. Things are absurd at this stage. I guess there is different motivations behind mobile OSes.
- ysnp 8mo ago"Break free from Google," is not GrapheneOS's motivation, just so people are aware. That is the blog writer's motivation.
- JCattheATM 8mo agoIt's very annoying that they restrict themselves to Pixels. I get they can't guarantee all the security features they want on other phones, but even a subset of those security features and the other advantages like the lack of cruft would make it very attractive to be able to run on other phones.
- ysnp 8mo agoI can understand the frustration, but it wouldn't be right to say they 'restrict themselves to Pixels'. They believe strongly in a standard for privacy/security of people's personal devices, and unfortunately only Pixels are close to meeting those standards. It's not even like Pixels are their ideal device. I feel the frustration should be targeted at OEMs that don't meet very reasonable requirements like minimum 5 years of monthly (timely) security updates.
- JCattheATM 8mo ago> I can understand the frustration It's not frustration, just disapproval. > but it wouldn't be right to say they 'restrict themselves to Pixels'. It's absolutely right to say that. You justify why in your next sentence. > They believe strongly in a standard for privacy/security of people's personal devices, and unfortunately only Pixels are close to meeting those standards. That doesn't prohibit them from releasing a version that runs on other phones, even if it's missing a few (and it would only be very few) features. Most of the graphene users are not using it because of those features. > I feel the frustration should be targeted at OEMs that don't meet very reasonable requirements like minimum 5 years of monthly (timely) security updates. Again, though, no frustration; I wouldn't run graphene even if I could as I have my own setup I'm quite happy with. Just disapproval at an arbitrarily high standard that isn't doing the good they think it is, and ultimately, actually does more harm in not making their product accessible to the hundreds of thousands of people it would benefit.
- timbit42 8mo agoThey are working with a partner to get their own phone hardware, hopefully by next year.
- StilesCrisis 8mo agoI can't take this seriously when their mission statement is to "break free from Google and Apple" and their entire output is a fork of a Google repo. If you're based on AOSP, the project is still 100% reliant on Google! It seems extremely cynical to me to depend on the work of a thousand-man team to build your OS, then patch out a couple of lines and claim you've broken free from them. Without Google, none of this project could exist.
- niam 8mo agoYou'd be pleased to hear, then, that "break free from Google and Apple" is not Graphene's mission statement, because this is a blog.
- saroi235409 8mo agoi don't understand your issue - using grapheneos does allow you to break free from google in the sense that you have an android OS that works well, is secure and private, and gives you the choice to use google or not. if you choose to use play store/services, they run as sandboxed, unprivileged applications like every other app. on samsung/stock pixels etc, play services is a privileged component of the os and you can't avoid this. grapheneos gives you the freedom to break free from it in this sense. soon enough grapheneos will be available on non-pixel devices, but if you really have, say, a philosophical problem with using google devices, get a used 2nd hand pixel. or wait til the oem partnership announcement.
- haskman 8mo agoBeen running GrapheneOS for a while on a Pixel 9, and extremely happy with it! Apart from the usual perks of the FOSS ecosystem, there are a few things specific to GrapheneOS that are not immediately apparent but have turned out to work very well - 1. The Pixel camera app works, including all modes and settings. A camera that takes good photos was absolutely a requirement for me, and the FOSS camera apps are not quite as good yet. 2. I don't have Google Photos and the pixel camera app tries to launch google photos when you want to review the picture you just took. But there is a FOSS app called GPhotosShim that uses the same namespace as google photos and thus fools the camera into launching that app instead. Once launched, it just launches whatever media management app you actually have configured, so it's seamless. 3. Android Auto works! 4. Android QuickShare works! 5. NFC tags / Yubikey integration works! 6. Screencasting works! 7. Sensor access and internet access can be disabled for apps by default (and I do).
- mctt 8mo ago8. External storage works. This is the only mobile OS I've found that has stable support for an External SSD. I bought a second hand Pixel 7 to test this and an exFat SanDisk Extreme Portable 2TB works with reads/writes perfectly.
- kakacik 8mo agoA quick question from potential buyer of next generation of pixel phones, since samsung keeps disappointing hard with their top line - is there any difference in quality between default photo app and what graphene os bundles with? Pixel are supposed to be very good in photography, part hardware and part software, and my concern would be degradation of that software part. With small kids, there is nothing more important on phone for me than photos/video quality these days (apart from never going into apple ecosystem, I am just incompatible with that company' philosophy). Or its just about slapping some commercial photo app (like I heard from other photographers is often done on apple to get most out of it, but forgot the name of the app) and not caring about this?
- randusername 8mo agoHow are the cameras on the latest devices running GrapheneOS? My last Android experience was the Oneplus One and the experience left me with the feeling that cameras are just too proprietary to work well once you go tinkering with custom ROMs and camera apps. I'm not a photographer or anything, I just want to quickly point and shoot and get on with whatever I'm doing without thinking too hard.
- ForHackernews 8mo agoGrapheneOS only works on Pixel devices so it only targets a very limited set of Android camera hardware.
- gf000 8mo agoYou can run the proprietary Pixel camera software on GrapheneOS just fine (properly sandboxed).
- strcat 8mo agoGrapheneOS has the same camera features and quality as the stock Pixel OS within the same apps. You can use Pixel Camera on GrapheneOS even without sandboxed Google Play in the same profile if you want the full feature set. If you want extremely good cameras, the Pixel 10 Pro and Pixel 10 Pro XL are the best choices. Those provide the highest quality image sensors among the available supported devices and the Pro mode in Pixel Camera. See https://www.dxomark.com/smartphones/ https://www.dxomark.com/smartphones/ for how those compare to other devices. Our own Camera app will be heavily overhauled to narrow the gap more with the Pixel Camera app but you can already use that especially if you care a lot about this.
- gargan 8mo agoBreak free from Google by paying money to Google for a Pixel phone? Even with a used Pixel, you're helping prop up their used market value which helps Google
- rufw91 8mo agoHas anyone tried monitoring traffic from this ROM and see whether their claim of having minimal analytics and booseted privacy is true?
- ysnp 8mo agohttps://www.kuketz-blog.de/grapheneos-der-goldstandard-unter-den-android-roms-custom-roms-teil7/ https://www.kuketz-blog.de/grapheneos-der-goldstandard-unter...
- agile-gift0262 8mo agoI've been using it for more than 2 years, and I can't think of ever going back to a stock OS. I had to send my phone for a screen repair, in the meantime I picked up my old Samsung, and the sheer amount of apps I didn't want, notifications and dark patterns to tricking me into handing over my data made me anxious. I couldn't finish setting the phone up and drove to my parent's home to pick up their old, remotely nerfed by Google, Pixel 4a so I could install GrapheneOS into it and use it while I waited for my repaired Pixel 8.
- netbioserror 8mo agoSame. Not only has using it been no trouble, but having a barebones core app selection, a few picks from F-Droid, and using the browser for the rest makes my phone feel refreshingly under my control. It lasts for 3-4 days of low usage to boot, when nothing is phoning home constantly.
- iugtmkbdfil834 8mo ago~6 months here. In my case, it became almost a full daily driver ( putting corporate spyware on it would kinda defeat the purpose ). It is by no means perfect, but I can recommend it ( and I could not do the same with other phones that should have been better on paper -- linux phones like pinephone or purism ).
- deleted 8mo ago[deleted]
- jokethrowaway 8mo agoI really don't want to give Google money so the Pixel is off for me until GrapheneOS supports something else. For now I consider smartphones as disposable toys that can't be trusted with anything sensitive and use a computer for privacy. I also don't like the idea of running Android, I still hope for a real linux phone at some point.
- timbit42 8mo agoYou could buy a used Pixel. Also, they are working with a partner to get their own phone hardware, hopefully by next year.
- tranq_cassowary 8mo agoPhones, to just give one example, at least have fine-grained run-time permission controls while on Linux apps can just access anything the user can, except if you use something like Flatpak which gives you sandboxing but the quality of that sandboxing is still worse than Android 4.4 KitKat. How can you protect your sensitive info without such permission controls that gate access to your personal data? Note that this is just one example, there are also other problems with traditional desktop OSes and a large portion of desktop hardware.
- RRRA 8mo agoUntil these OS also start putting forward something like WebOS that tried to get phones back to on open web, there is no breaking the binary format and Appstore monopoly. I wish Europe would have forced that 10 years ago since the US is beyond saving.
- gf000 8mo agoWhat binary format?? Go read facebook's "source code", is that any more open than a random apk? If anything, apks decompile quite well.
- Aachen 8mo agoSo long as browsers allow you to open the developer tools and inspect memory etc., they're more open than remote attestation of a stock android or ios device Decompiling apps only works if you can get the app. I don't understand GP's problem with the apk format either, but you do need to break terms of service to get the files if you don't have a phone with Google services installed. Whether that's ethical or legal is up for debate
- drnick1 8mo ago> but you do need to break terms of service to get the files if you don't have a phone with Google services installed Why would I care? It's not like what Big Tech does is ethical or legal. You need to fight fire with fire.
- SahAssar 8mo agoWas WebOS really that much about openness? Are you not thinking of FirefoxOS/B2G?
- strcat 8mo agoThere's a huge open source app ecosystem for Android and it has the best support of any major platform for well integrated web applications. There are a bunch of alternatives for getting apps including getting them directly from the developers which has been automated without needing an app store. The linked post talks about using Obtainium for getting apps more directly from developers when possible.
- pickleglitch 8mo agoI had to replace my old phone a few months back and I went with a used Pixel 8 pro from Backmarket specifically so I could try GrapheneOS. I'll never go back if I can help it. I love this OS.
- arbirk 8mo agoIf Apple partners with Starlink, this is my next mobile OS
- OptionX 8mo ago"Break free from Google" All supported devices are exclusively Pixels.
- timbit42 8mo agoThey are working with a partner to get their own phone hardware, hopefully by next year.
- hk1337 8mo agoDo they just not have ANY screenshots of the OS anywhere on the web site
- deleted 8mo ago[deleted]
- matthewkayin 8mo agoIt looks about the same as stock android.
- OuterVale 8mo agoIt is just Android. If you're familiar with the usual Material styling of Android, you're familiar with what Graphene looks like.
- cbeach 8mo agoIf they'd put a screenshot, that would then have been immediately clear to casual visitors. My initial assumption was "this is gonna look like a typical OSS product, and not as polished as iOS or Android". A single screenshot would have dispelled that notion.
- m00dy 8mo agoIf you are using social media, you might get a shadowban, just because you needed to unlock your bootloader to install this OS. the OS is great, but too risky in certain situations.
- Aachen 8mo agoTry a social media that is not antisocial. HN, Mastodon, Tildes, various forums... lots of communities and tech content are available in browsers or via open source apps I'm not aware of any that bans you when not using an allowlisted OS, so maybe it was something else that caused this shadowban, or (more likely) that's just my bubble
- saroi235409 8mo agoi use social media and have never gotten a shadowban. to the contrary grapheneos actually is very effective against apps like reddit shadowbanning you - if you get banned outright on reddit, for example, you can create a new profile in private space and reddit will not be able to detect that you're ban evading. if you get banned from the profile u use in the app in private space, again, if you just delete private space and recreate it, download the reddit app again, it will be unable to detect that you're evading the ban. i previously tried doing this on other os's and reddit detected the ban evasion. don't ask me how i know. (just correcting this misinfo)
- m00dy 8mo agoyou're correcting nothing, my business revolves around evading these kind of checks especially on mobile apps. TikTok, for example, it is very aggressive. If you have something different than stock ROM, your reach will be greatly diminished. There's a little bit information here [0]. [0]:https://discuss.grapheneos.org/d/18118-play-integrity-meets-device-integrity/2 https://discuss.grapheneos.org/d/18118-play-integrity-meets-...
- edbaskerville 8mo agoSwitched to this from Apple a year and a half ago. Works for most things. Unexpectedly, replacement apps lack polish. Also, RCS works very inconsistently (been without it for months), seems to be Google's fault. There may be workarounds, but I haven't had the energy to try the more complicated suggestions. I am probably going to switch back to a used old iPhone for "phone appliance" tasks, but keep around the Pixel for other things. My main takeaway from the experience is that iMessage is an even bigger weapon than I thought.
- empyrrhicist 8mo agoThe RCS issue is why I switched back to iPhone, reluctantly. If anything, iOS seems buggier and less reliable, but I know (and am related to) a lot of people who insist on using iMessage/RCS, and I can't be missing messages.
- microtonal 8mo agoAre you in the US? I get the impression that iMessage and RCS are only big there. Almost nobody uses them here in Europe. (It's mostly WhatsApp where I live and Signal is slowly getting more popular.) As an aside, from the latest release notes: Sandboxed Google Play compatibility layer: add toggle for granting Play services access to ICC auth in order to support RCS with carriers requiring it for RCS in Google Messages including T-Mobile (see RCS usage guide) https://grapheneos.org/releases#2026021200 https://grapheneos.org/releases#2026021200 https://grapheneos.org/usage#rcs https://grapheneos.org/usage#rcs
- drnick1 8mo ago> Also, RCS works very inconsistently (been without it for months), seems to be Google's fault. The best thing would be to switch to Signal (Molly) for texting.
- bialamusic 8mo agoCombine it with OnemanBSD to be really FREE. Lookhere: https://www.youtube.com/watch?v=2wHaoQhXOYY https://www.youtube.com/watch?v=2wHaoQhXOYY
- Creator71 8mo ago[dead]
- ghrl 8mo ago"Break free from Google" and buy a Pixel phone from them to do so. But unironically Pixels are currently some of the best actually open phones. They do not lock down or require shady practices for unlocking the bootloader (although they do require a network check once that happens automatically, but it will permanently allow unlocking the bootloader if successful once. Pixels are very easy to restore and almost un-brickable, allow bypassing the boot screen warning by pressing the power button twice, actually allow relocking the bootloader and don't void your warranty unlocking it, don't have a shady one-time fuse like Samsung phones do with Knox, etc.
- deleted 8mo ago[deleted]
- hydrogen7800 8mo agoI've wanted to try this on my old Pixel 5, but it has the dreaded screen/motherboard failure. It appears there is no solution for that short of replacing the screen/mobo, which i've already done once after cracking it.
- microtonal 8mo agoPixels are really great despite being from Google. I hope they will continue to make them unlockable/relockable. As you say they are also surprisingly hard to brick. Here is someone trying to break it intentionally during the GrapheneOS install: https://www.youtube.com/watch?v=ik0AiO0WtuU https://www.youtube.com/watch?v=ik0AiO0WtuU If you don't like giving money to Google, plenty of companies offer refurbished Pixel phones.
- neelc 8mo agoIn the US, many refurbished Pixel phones are Verizon variants which disallow OEM unlocking. When was in college and had Sprint this was a nightmare since then I wanted root for unlimited hotspot (Sprint made it easy that way), but most refurbished Pixels were Verizon variants. And I couldn't just use OnePlus because they were only designed GSM networks or later Verizon CDMA-less. Then, new Pixels were unaffordable for me, but parents insisted on using Sprint. I ended up getting a Pixel 3 off Mercari (which I still own) just to keep root. Now, I can afford a Pixel 10 Pro new (which I am right now), alongside spare Pixel 9 and OnePlus 13R units. But even then (a) my income is lower than when I worked at Microsoft and (b) The OnePlus was from a trade-in deal.
- Cider9986 8mo agoOne thing that is a game changer on GrapheneOS is the network toggle for apps. Turn off network access for your keyboard, camera app, calculator, files, etc.
- Aachen 8mo agoDefinitely one of the best features to have this in the native UI, though it's also possible in other ways If anyone wants this without GrapheneOS: https://f-droid.org/packages/dev.ukanth.ufirewall https://f-droid.org/packages/dev.ukanth.ufirewall If anyone wants this without GrapheneOS and without root: https://f-droid.org/packages/net.kollnig.missioncontrol.fdroid https://f-droid.org/packages/net.kollnig.missioncontrol.fdro...
- tranq_cassowary 8mo agoThat's not at all a similar approach so it doesn't quality as "if anyone wants *this*). The GrapheneOS feature pretends the network is down and local host is also inaccessible. This is good for compatability (apps generally take into account that a network can be down) and too avoid apps knowing you are using the feature.
- SirMaster 8mo agoHow does this break free from Google? Isn't the Android that Google themselves writes and maintains the upstream of Graphene? Are they going to disconnect completely from upstream Android or something?
- dangus 8mo agoThe article directly answers your questions, specifically in the “what is GrapheneOS?” section. For the end user, breaking free from Google means exiting from Google’s services surveillance system wherever possible. It doesn’t mean complete elimination of the use of source code written by Google employees. GrapheneOS is really the most private option of all viable daily drivable smartphone operating systems available, because your only other options generally involve Apple and Google services dependency. You can use GrapheneOS and never send any user information to Google, that’s how you “break free.”
- johnnyballgame 8mo agoSome privacy settings for GrapheneOS: https://inteltechniques.com/blog/2026/01/05/grapheneos-2026-settings/ https://inteltechniques.com/blog/2026/01/05/grapheneos-2026-...
- lanfeust6 8mo agoI use this and lineage, but in a few years time this could be moot if Google decides to completely lock down devices. That leaves commercial options like Fairphone
- strcat 8mo agoFairphone is far from meeting the update and security requirements for GrapheneOS. It isn't a viable platform for a hardened OS to use and isn't likely to ever become one due to security being very far from a priority for them. GrapheneOS has a partnership with one of the largest Android OEMs. They're going to be announcing it in March 2026. Devices meeting all of the update and security requirements from them with official GrapheneOS support are planned for 2027. We don't expect future Pixels to prevent installing GrapheneOS but we'll be fine if they do. We'd still like to keep supporting new Pixels but they'll become a secondary option in the future since there will be devices with official support.
- lanfeust6 8mo agoThat OEM has yet to be named. It would be nice to see it happen, but it's yet to materialize. > It isn't a viable platform for a hardened OS Breaking from google/Apple doesn't in itself require a hardened OS, as we see in LineageOS.
- strcat 8mo agoOur OEM partner is announcing the partnership in March 2026. It's an active partnership with work under way for devices launching in 2027.
- zer0zzz 8mo agoWhy is it that Google find my doesn’t work? I can’t get it running on my pixel, seems like a known issue.
- kopirgan 8mo agoThere's several AOSP based ROMs in forums like xda. Mostly developed by enthusiasts. Recall using one years ago on my Samsung device with happy results. That was long before banking apps etc. Wondering what's the difference with this? Extra security?
- tranq_cassowary 8mo agoThis is a production grade OS, it's made by professionals, it's not hobbyist. It keeps up with updates of upstream Android and Linux kernel. It has a ton of good security and privacy features.
- Gud 8mo agoIs there a great phone with high end specs this runs on? Currently have an iPhone 16 pro, and probably my next phone will be something like this. I need to be able to share photos easily with my wife, typically I’ve been using airdrop.
- aniviacat 8mo agoYou can use GrapheneOS with the Google Pixel lineup, or in particular the Pixel 10 Pro XL [1]. GrapheneOS supports Android's Quick Share, which (on the Pixel 10 family) is compatible with AirDrop [2]. [1] https://grapheneos.org/faq#supported-devices https://grapheneos.org/faq#supported-devices [2] https://blog.google/products-and-platforms/platforms/android/quick-share-airdrop/ https://blog.google/products-and-platforms/platforms/android...
- Gud 8mo agoWhat if I don't want to give money to Google at all?
- aniviacat 8mo agoThen GrapheneOS is currently not an option, however they are working with another OEM to have non-Google phones available with GrapheneOS by next year [1]. [1] https://grapheneos.social/@GrapheneOS/115987006592879172 https://grapheneos.social/@GrapheneOS/115987006592879172
- Gud 8mo agoOk that is great news, thanks for sharing.
- the_arun 8mo agoMy observation is - It is the ecosystem that is sticky not just the OS.
- empyrrhicist 8mo agoYou can install Google Apps as a regular set of user apps rather than a system-level admin monstrosity, and it mostly works - Play Store included. Whether or not that defeats the purpose is an exercise left to the reader.
- Aachen 8mo agoYou're not the first to notice! It's called the network effect
- Ajedi32 8mo agoThe list of open source apps in this article was very informative and something you can benefit from even if you don't use GrapheneOS. Many of the apps listed I hadn't heard of.
- mrcwinn 8mo agoI really doubt they have an issue tracking you despite all this added effort.
- timbit42 8mo agoDon't let perfect be the enemy of good.
- kittbuilds 8mo ago[dead]
- neelc 8mo agoAbout his comment: > Unfortunately, I must recommend Windows 10/11 here, because then you don’t have to mess around with any drivers; it’s the simplest option. When I worked at Microsoft but ran FreeBSD at home, I often used my work Windows laptop to install custom ROMs. This is because FreeBSD was finicky with adb. Now I run Fedora and the Android drivers are pre-installed. I installed GrapheneOS on both a Pixel 10 Pro (main) and Pixel 9 (spare) that way. On Windows, I've had more trouble with Android drivers than I did on non-Windows.
- OsrsNeedsf2P 8mo agoThis has been my experience with Windows too. Airpods connect out of the box on Linux, but on Windows they would stop pairing every couple minutes until I fixed some drivers
- canu7 8mo agoYou can even install GrapheneOS from another GrapheneOS Vanadium browser. No computer required.
- danielmartins 8mo agoI had a Pixel 6a with Graphene OS for a year before the phone started to glitch and eventually die. It ran pretty hot; sometimes it was hard to even hold the phone in my hands without burning myself. I could not get a replacement as I bought the phone in a foreign country (Google doesn’t sell Pixels here in Brazil). So as much as I love the idea of running a more private phone, I found the hardware extremely fragile and poorly designed, so I will not buy from them again anytime soon.
- gib444 8mo agoYeah Pixels are poor quality. Mine developed the common pink vertical line display issue after 18 months The flag ship should not be more than $500
- drnick1 8mo ago> The flag ship should not be more than $500 Which is (almost) the case during sales. The P10 was on sale for $599 not long ago, and you could buy a 9a for little more than $300. That is extremely good value compared to any iThing repoted your every move to Apple.
- deleted 8mo ago[deleted]
- gib444 8mo ago$600 to last 18 months? Disagree
- sfRattan 8mo ago> I had a Pixel 6a with Graphene OS for a year before the phone started to glitch and eventually die. It ran pretty hot; sometimes it was hard to even hold the phone in my hands without burning myself. This sounds like your phone may have been one of the Pixel 6a models with a defective battery[1]. It was a major problem for which Google pushed out an update that nerfed the battery life. There is a tool online where you can check if your particular 6a was one with a battery from the bad production batch[2]. But that unfortunately doesn't help if you are in Brazil where, as you say, Pixels aren't officially sold and import/export controls tend to make tech warranties useless in practice. [1] https://www.lifewire.com/pixel-6a-battery-overheating-warning-11780242 https://www.lifewire.com/pixel-6a-battery-overheating-warnin... [2] https://support.google.com/pixelphone/answer/16340779?hl=en https://support.google.com/pixelphone/answer/16340779?hl=en
- SoKamil 8mo agoAm I the only one who finds monospace font barely readable for articles? Good for code, bad for longer forms of text.
- nisten 8mo agoI switch from iPhone to a pixel 9 fold, and installed graphene after 2 weeks on stock android. Look, it's better than stock android overall, UI much more simplified even though it gives you a lot more security control, battery feels slightly longer, but there are drawbacks, i.e. twitter/x wouldn't install, neither would my bank's app. However from time to time I go to use iOS on the iphone and it just feels like better software, with better ergonomics overall, the combination of the xnu kernel plus the design and feel of the..buttons.. on iOS is still years ahead in my opinion. So keep that in mind if you're switching away from apple to it, as android still feels like decade plus old software. Now for the upsides.. there's a built in terminal and debian vm you can install and run your agentic AI tools (claude code,opencode etc) in a portable sandboxed environment which you just don't get onios. You can even fire up a graphical xfce session albeit that takes quite a bit of work to get it to go. As for the tablet form factor of the phone itself when unfolded, i found it amazing the first few weeks and then later found myself rarely using it. Overall I'm going to stick with itand will never go back to stock android, but am quite annoyed at how much better it could actually be.
- strcat 8mo agoYou can bypass Play Store restrictions on app installs by using Aurora Store. There's a high chance your banking app can be used but it may require toggling the per-app exploit protection compatibility mode. Most banking apps work on GrapheneOS. X is one of extremely few apps disallowing using a non-Google-certified OS but it only partially disallows it in their store listing which can be worked around and for regular password login. Login is still possible to X via a passkey or Google login. X should stop doing that but they're quite understaffed and did this as a misguided anti-spam measure.
- linux_modder 8mo agoAurora store is a horrible placeabo. Not only is it using other folks anonymized accounts, which violates several privacy laws internationally it also still has the Google libraries in their apks like everything else. You are not gaining any privacy or security using Aurora Store or F Droid for that matter but are indeed opening up more attack surface in the supply chain that ends at your device.
- NoSalt 8mo agoThe main problem with the Pixel phones, along with most Android phones these days, is the lack of a μSD card slot and a 3.5mm headphone jack. When I recently had to purchase a new phone, I had to go with a Motorolo G, as it had both of those features.
- tranq_cassowary 8mo agoThere are some problems with this, often if a microSD card is used the storage on that SD card isn't encrypted because of the portability goal of it. It would be a bad fit for the project. As per the headphone jack, the headphone jack is much less durable than a USB-C port and has less use cases. Two USB-C ports on a phone would be nice however. For audio with audio devices not accepting digital audio in you would need to add an adaptor with a DAC in between but this is mostly good for audio quality given that those DACs often have better quality than the ones built into the phones. This is my opinion though, you may have different needs.
- shadowgovt 8mo agoAfter reading this blog post, going to grapheneos's site, and browsing a half-dozen or so pages that I thought might show me what it looked like... I cannot find a single image of it. GrapheneOS team, I'm begging you... Hire or recruit one person with advertising or copy-for-public-consumption experience. Just one.
- Aachen 8mo agoAnswered 2h ago before your comment: https://news.ycombinator.com/item?id=47047720 https://news.ycombinator.com/item?id=47047720 Saving a click, it looks like any bare Android without vendor customisations. You just get extra settings like turning off network per app I don't disagree that some screenshots might be good marketing
- danans 8mo ago> For me, it works like this: on the Owner user, because that’s the name of the main account created automatically with the system, I installed the Google Play Store along with Google Play services and GmsCompatConfig Many people here might recoil at this: to go through the trouble of de-Googling your phone and then just install Google Play services and the Play Store, but the important part is that it is a choice they could make. Pixels are arguably the best option for software choice among mainstream phones (and iPhones are the worst), but both are a huge regression of choice compared to traditional personal computing platforms.
- ethagnawl 8mo agoI've found using separate accounts for Non-Play (default) and Play (exception/escape hatch) to be a very happy medium.
- MattTheRealOne 8mo agoI use and appreciate GrapheneOS due to it being one of, if not the best, option we currently have. That said, I do not like how much the project depends on Google. - GrapheneOS is based on Android, which is solely developed by Google. - GrapheneOS only supports Google Pixel devices. Thankfully, they are working on partnering with a different manufacturer, but details are still very limited. - They recommend using the Google Play Store (requires a Google account) to get apps and recommend against using F-Droid. - Their Vanadium web browser is based on Chromium, which is controlled by Google. It also does not have an ad blocker or support extensions. They recommend against using Firefox. Firefox, and Safari to a more limited extent, are the only web browsers keeping Google from having complete control over web standards and the way we can access the internet. This is not a criticism of the GrapheneOS project or developers. I understand that security is the biggest priority of GrapheneOS and I understand that Google is often good at security. They are following the goals of the project. It is more directed towards the GrapheneOS community that often blindly recommends GrapheneOS as the only option and treats any alternative as inferior and not to be considered. Most users do not need security at all costs. Especially among the free and open source enthusiast community, freedom and user control are often prioritized. There should be more awareness and discussion about what the user wants and whether that actually aligns with the security-first goals of GrapheneOS.
- deleted 8mo ago[deleted]
- niam 8mo ago> It also does not have an ad blocker It does have a network-level ad blocker. What it doesn't have is a blocker which modifies/injects Javascript into pages, which iiuc is the main reason that the blocker doesn't help with ads on YouTube much, or pages which employ similar techniques. > They recommend against using Firefox. To clarify: they recommend against Firefox Mobile because it didn't support site isolation until last month's v147 updates. I don't know if the goalpost has moved since, but in any case: there's nothing on Graphene that would prevent you from using Firefox.
- strcat 8mo ago
- darepublic 8mo agoSo you were happy in your orchard/garden but then plenti arrived offering the forbidden fruit; android. This is the slippery slope that led us here, open rebellion against the tech patriarchy
- thomastjeffery 8mo agoAs great as GrapheneOS has been, I'm still tempted to switch to LineageOS. Sure, it would be objectively less secure, but at least then I might be able to disable the obnoxious "automatically disabled 3 unused background apps" notifications. The biggest problem with security culture is its obsessive hyperfocus on security. Any change that could possibly be less secure (even in extremely exclusive circumstances) must be wrong. Even if it improves accessibility, it must be rejected out of hand. GrapheneOS promises to liberate us from the enshittification of Google's anticompetitive moat; but it focuses that effort exclusively on security. Everything else that was enshittified gets carefully preserved as-is in the name of "security". All I want is a mobile computer that does what I tell it to. Why is that constantly treated as an unreasonable fantasy?
- tranq_cassowary 8mo ago> Even if it improves accessibility, it must be rejected out of hand GrapheneOS has many exploit mitigations and those that would break compatability with too much apps are opt-in instead of opt-out. They also have per app toggles so you can decide to use them per app. So they certainly don't sacrifice accessibility for the highest level of security. > GrapheneOS promises to liberate us from the enshittification of Google's anticompetitive moat This isn't something GrapheneOS promises anywhere on their website. They aim to offer a secure and private OS with good compatability with Android apps. > but it focuses that effort exclusively on security. They focus on privacy and usability as well. Security is actually only focused on because the privacy features aren't enforceable without security. > Why is that constantly treated as an unreasonable fantasy? Because tinkering, hackability and unrestricted freedom aren't the purposes for which GrapheneOS was made.
- thomastjeffery 8mo agoIt's good enough for you, and therefore it can't get any better. Interrupting the user with pointless notifications is not security. Removing the ability to disable those notifications is only a security feature if the user wants then in the first place! The problem here is more than the lack of interest in making a system that is both secure and usable. It's the outright rejection of usability as a goal.
- zackify 8mo agoAs a long time iOS user, I now mainly run Graphene + GadgetBridge with a helio strap. Pretty nice and private setup. My running watch is from a chinese company that I do not trust, so I lock down the permissions quite far. I like that Graphene lets me control the network permission and have offline maps that cannot report anything external. Overall the most annoying thing is not being able to iMessage... I moved who I could over to signal. Also the battery life is amazing because I keept restricting apps from background usage and the defaults already do a good job of that
- cbeach 8mo agoThe article is a wall of text with not a single screenshot. And I couldn't easily find a link to a page that summarised GrapheneOS with some images so I could see how polished it looked. This is one of the reasons why OSS fails to gain mainstream appeal (as much as I want it to)
- strcat 8mo agoGrapheneOS is based on the latest release of the Android Open Source Project (AOSP) which is Android 16 QPR2. It looks nearly the same as the stock Pixel OS also based on the same AOSP release. The main UI differences are user-facing portions of the many privacy and security features added by GrapheneOS. There are minor differences such as the stock Pixel OS having a few different fonts than AOSP. The main thing to show would be the UI for features such as Contact Scopes, Storage Scopes, per-app exploit protection controls, etc. It looks like the stock Pixel OS without the Google app/service integration not present in AOSP with added privacy and security controls. There are many useful videos about GrapheneOS here: https://www.youtube.com/@sideofburritos/videos https://www.youtube.com/@sideofburritos/videos Any of the videos older than December 2025 will be prior to Android 16 QPR2 so the overall UI will be outdated. That's part of why we don't focus on screenshots or videos because many would need to get updated every 4 months. We'd mainly be using them for our own features which often improve more frequently than that.
- deleted 8mo ago[deleted]
- charles_f 8mo agoGraphene is very attractive, the two things that prevent me from going are a) using your phone as a credit card, I'm too attached to that now. b) work profile does not work with rooted phones
- ElectronBadger 8mo agoI've been using /e/OS for years. Since 2025 I'm on Pixel 9A and GOS. It's excellent. Everything I need works great. Updates are so frequent. Attention to details regarded to security is amazing. My favorite mobile OS.
- apazzolini 8mo agoI wish there were a good iPhone Mini sized phone I could install GrapheneOS on.
- timbit42 8mo agoThey are working with a partner to provide their own hardware to run GrapheneOS on. Maybe they will have more than one model.
- hereme888 8mo agoCitibank app does not work in GrapheneOS
- glhaynes 8mo agoThis is so well-written with obvious care! Answers so much of what I've been wanting to know, as someone who's thinking about taking this plunge.
- mitanjan 8mo agoGoogle is so much engrained in our lives that we can't really break free. You can't just don't use youtube and for that you need a google account.These projects are nice and good for tinkering, but can't use this as a dialy driver.
- mrtesthah 8mo agoWhy do I need a Google account for Youtube? It seems I can watch nearly any video I want without logging in. Moreover there are anonymity proxies like Invidious.
- aniviacat 8mo agoAs someone who doesn't have a Google account, I can use YouTube just fine on my GrapheneOS phone using apps like NewPipe.
- strcat 8mo agoGrapheneOS is very usable as a daily driver. Nearly every Android app can be used on it and there's a huge ecosystem of open source Android apps. You should read the whole linked article which explains in depth how someone new to using it set up their device. They chose a certain way of doing it to balance their priorities. Only a tiny portion of apps can't be used on GrapheneOS which are mostly a subset of around 15% of banking apps which ban using a non-Google-certified OS in a way we can't easily work around. Most banking apps do work and extremely very other apps are unavailable. Google apps and services aren't used by GrapheneOS by default but can be installed as regular sandboxed apps. You don't need a Google account to use YouTube and can use it via the browser, NewPipe or several other alternatives rather than their app. The linked article covers someone's first experience with it with a lot of detail. They're using it as their daily driver with mainly open source apps and separate profiles with mainstream apps they still need. They're using those with much better privacy protections including having sandboxed Google Play in those profiles for using mainstream apps rather than regular highly privileged Google Play heavily integrated into the OS and not running with the standard app sandbox or privileges.
- drnick1 8mo agoLike others have said, you can use Youtube without Google account. Moreover, you can give Google the middle finger by using uBlock Origin or viewing though a third party client like VacuumTube. Also don't forget the shorts filter recently featured on HN to remove those annoying portrait format videos.
- acd 8mo agoI want to break free - Queen :) Lyrics https://genius.com/Queen-i-want-to-break-free-lyrics https://genius.com/Queen-i-want-to-break-free-lyrics
- mbix77 8mo agoSwitched a couple of weeks ago and works perfectly. I also found so many better apps that dont steal your data for basic stuff like weather, notes, messaging,...
- notorandit 8mo agoGrapheneOS needs at least the modem blob provided by the OEM. It runs as root, it has full network control. Same could go for other "drivers" like wifi+bluetooth. Privacy is more a dream than a real thing.
- timbit42 8mo agoThey are working on getting their own hardware.
- strcat 8mo agoNo, that's a misconception. GrapheneOS has only ever supported devices where the cellular radio is isolated from the OS and unprivileged. It does not have access to memory it hasn't been permitted to access by GrapheneOS. Wi-Fi, Bluetooth, NFC, UWB, etc. are isolated components too. Our hardware requirements are listed in our FAQ and require proper isolation for radios: https://grapheneos.org/faq#future-devices https://grapheneos.org/faq#future-devices 8th, 9th and 10th gen Pixels provide our full set of requirements with 7 years of support from launch. 6th and 7th gen Pixels are missing the ARMv9 security features including the extremely important hardware memory tagging (MTE) feature we heavily use to protect against exploitation. Even the first devices we supported back in 2014 including the Nexus 5 had isolation for the cellular radio but similar isolation for Wi-Fi/Bluetooth started with the Nexus 5X.
- kittbuilds 8mo ago[dead]
- deleted 8mo ago[deleted]
- linsomniac 8mo agoFYI: Google Fi + GrapheneOS doesn't work. My son recently tried setting up GrapheneOS and got everything working but couldn't get connected to Google Fi to work, even with a SIM card.
- tranq_cassowary 8mo agoIt works but you need to install the Google Fi app from the Google Play Store.
- owlcompliance 8mo agoI need to try this out.
- gigatexal 8mo agoA lot like Linux zealots people say a lot of things along these lines: “It’s perfect. I love it. It works great. No complaints” and then go on to list 100 rough edges that mainstream phone OS users never have any issues with. It’s funny.
- 1vuio0pswjnm7 8mo ago"Break free from Google ..." by purchasing Google hardware and using [software "based on"] Google software Is it really "breaking free" from a company if the method of "breaking free" requires continued cooperation from the company This is not to suggest using a modified version of Android isn't useful. This comment is not about GrapheneOS. (But there will be HN replies that will try to redirect focus to it anyway.) This comment is about claiming it's possible to "break free" from something while still remaining inextricably tied to it In addition to using a custom ROM, there are methods of stopping the Pixel's attempts to "phone home" to the company that work even with the version of Android pre-installed by the company intact. However if a method requires software, e.g., drivers, or is "based on" software controlled by the company, then ultimately the company holds the cards. IMHO, this is not what it means to "break free" Perhaps the most reliable method of stopping these connections to the company is one that does not rely on cooperation by the company. This is because if the company decides to stop cooperating, the method still works
- timbit42 8mo agoThey are working with a partner to create their own hardware to run GrapheneOS on.
- Refreeze5224 8mo agoYour "perfect" is a massive enemy of the "good" that is GrapheneOS compared to using stock Android.
- H8crilA 8mo agoDoes anyone have an answer to the problem of an OS for a laptop? I'm thinking about strong security here, less so about privacy (which is doable, for example via a Linux distribution).
- tranq_cassowary 8mo agoChromeOS (most secure OS), MacOS (most secure firmware and still much more secure OS compared to non-ChromeOS competitors)
- anotherevan 8mo agoThe biggest hold-back for me is that, here in Australia, Google Wallet (aka Google Pay) is the only way you can do tap credit card payments that I know of. Can't with Paypal. Not with any banking apps that I know of. It's just so damned convenient. And the recording of transactions on the phone saves me having to collect paper receipts.
- seanw444 8mo agoIf you want to fight back‚ let convenience take the back seat.
- LowLevelKernel 8mo agoLet’s just say, it took a while for the Stingray to get in while moving at 70mph. But it got in when it’s 0mph
- QuiEgo 8mo agoThis is the phone version of saying “the power utility is an evil awful monopoly that treats me like shit, so I’m gonna get solar and batteries and go off grid.” It’s cool it’s possible, but it’s not practical for most people.
- tranq_cassowary 8mo agoWhat do you think the major practical downsides are? Maybe you are not aware of how many things perfectly work or how easy some workaround are, so I am wondering.
- QuiEgo 7mo agoThe average person uses Chrome with no ad-blocker on and has never opened a terminal emulator. HN wildly sways to a tech-aware audience. I think most people would read the simple instructions provided by the author and immediately be overwhelmed and confused - "what's a bootloader, why do I need to care about unlocking it, is this going to break my phone?!"
- OldMatey 8mo agoBreak free from Google*. As long as you buy a Google phone. I really want to use it, but the Pixel only requirement is a deal breaker
- timbit42 8mo agoThey are working with a partner to get their own phone hardware. You could also buy a used Pixel.
- deleted 8mo ago[deleted]
- kwanbix 8mo agoYou have to understand that this is yo replace your os on your phone. No phone is designed for that to happen. If you find it difficult, try to do it on an iphone.
- Arifcodes 8mo ago[dead]
- sfRattan 8mo agoIf you're willing to invest in a smartwatch principally as a secure payment appliance, tap-to-pay with Garmin Pay works when configured on Graphene OS, and most Garmin Smartwatches will happily stay in airplane mode for months once configured. AFAICT, Garmin Pay works like Apple Pay, meaning (unlike Google Pay) no network connection is required.
- Arifcodes 8mo ago[dead]
- deleted 8mo ago[deleted]
- h4kunamata 8mo agoI've been using GOS for 3years give or take on a Pixel 7 PRO. Yes, GOS also stops you from buying new phone every year and personally, I am hopping Pixel 10 PRO is worth the upgrade, doubt it. In Australia, everything works, from banking to gov services, they do not block or have limited function. CommBank App supports NFC payment via its app for example. Dual profiles is silly and utterly unnecessary. List of my open-source applications: - Aurora Store: Should be avoided, it like F-Droid have broken security in place. You have a high risk of installing crappy on your phone via those stores. That is why I still use Google Play and download apk once here in there from GitHub project. - Organic Maps: Dead project, a lot of things have happened and that is why CoMaps was created/forked. It is a beautiful and mega lightweight offline GPS map with tons of features. CoMaps replaced Earth Magic that got completely destroyed to greedy, and Sygic which I have an old lifetime premium license which now is somewhat limited unless you pay for premium plus :) OP didn't mentioned but GOS + Android Auto works like a dream wirelessly, GOS provided is Google-free dependency version and it just works.
- anonzzzies 8mo agoWe need an Euroepean vendor or organ or consortium taking up Android or Graphene or whatever and stamping a cert on phones allowed to run bank apps, after which banks (etc) have to support those phones. And/Or having to offer all functionality in the app(s) also in mobile web, but having users who want to use that requiring an OTP (or so) hardware token. I would be in favour of having the latter no matter what; no I can do this with my bank, but it doesn't offer the same as the mobile app and the site is not mobile optimised either.
- irenetusuq 8mo ago[dead]
- vermaden 8mo ago> Break free from Google Looks inside. Only Google phones are supported. Curtain drops ...
- karlosvomacka 8mo agoUsing Brave (Chromium based software) is a strange choice from privacy oriented person imo...
- Copernicron 8mo agoI've found that your experience with GrapheneOS greatly depends on which country you're in and which mobile provider you use. I'm on Freedom Mobile in Canada and I had enough issues that I went back to stock. RCS didn't work at all, and my phone would regularly lose the cellular connection to the point I had to reboot the phone and reset the cellular network settings. I didn't feel like I could trust it in an emergency situation so I reverted. There are also times I'm out of cell coverage and having satellite SOS would be invaluable. Some of these issues are known and some are just features the project won't support. Last I heard they aren't going to support satellite messaging at all.
- ireflect 7mo agoI’m with Freedom Mobile in Vancouver, currently using a rather old iPhone. My next phone will probably run GOS. I have issues with Freedom on my iPhone too. Poor signal, or else “good” signal but poor data backhaul. Are you pretty sure your issues went away after going back to stock Android? Or is it possible it’s just Freedom Mobile’s general issues?
- Copernicron 7mo agoRCS works perfectly on stock and I haven't had any random drops of the cell network since I switched back. I'm not saying it's bug-free, but those particular issues disappeared with stock compared to GOS. It could also be because I'm on a Pixel 10 Pro and they just haven't worked out all the issues yet. I plan to try again in a few months.
- TrailingArbutus 7mo agohad been using GrapheneOS for a while now, feels goated and keeps things alive from back when rooting was so common in cyanogen days. we are at a stage where the big corps are too hard to push against :(