4 ms·
There's absolutely no reason to use /e/ when GrapheneOS exists. https://eylenburg.github.io/android_comparison.htm https://eylenburg.github.io/android_comparis
by lpcvoid 7mo ago
There's absolutely no reason to use /e/ when GrapheneOS exists.
https://eylenburg.github.io/android_comparison.htm https://eylenburg.github.io/android_comparison.htm
- preisschild 7mo agoAnd even if GOS doesn't support your device (due to minimum security requirements) why not use upstream LineageOS?
- przmk 7mo agoBecause upstream LineageOS doesn't support microg out of the box. You can install it but it needs signature spoofing to pass Google's SafetyNet garbage. Bonus point for some roms that allow you to relock the bootloader after the install (iodéOS, CalyxOS).
- wolvoleo 7mo agoLineageos supports signature spoofing for microG these days! It did take them a long time to come around but they did in the end.
- ForHackernews 7mo ago/e/OS also supports locked bootloaders for devices that have official builds (a smaller subset than the ones with community builds)
- greentea23 7mo agoThere is a version that makes only the changes to include microg, has OTA updates too: https://lineage.microg.org/ https://lineage.microg.org/
- FireInsight 7mo agoUnless you own some obscure phone that is not supported by GOS, Calyx or Iode, but is by /e/... Not sure how many of those exist...
- miroljub 7mo agoBut GrapheneOS doesn't exist. It works only on a few devices created by Google, so their claim of being degoogled is a bit funny.
- flexagoon 7mo ago> their claim of being degoogled is a bit funny. I don't think they use this term anywhere. It also now works on Motorola devices, it's on my HN feed literally right above this post.
- szmarczak 7mo agoI have no idea where you got this information - the HN post is about partnership. It does not work on Motorola devices, at least not yet [1]. [1] https://grapheneos.org/releases https://grapheneos.org/releases
- krige 7mo agoIt doesn't "now work"; it may work on a future Motorola device that doesn't exist yet.
- wolvoleo 7mo agoIt doesn't yet work on Motorola devices. It is going to become available on selected Motorola devices at some point in the future.
- miroljub 7mo ago> It also now works on Motorola devices, it's on my HN feed literally right above this post. Did you read the article you mentioned? There's not yet a single non-Google device that can run GrapheneOS.
- _ache_ 7mo agoI must agree, you are right, GOS is only on Pixel phones. But we have to keep in mind that /e/ has a lot of problems, the only one solved is sending data to Google. The security aspect of the OS is problematic and some key elements of a privacy seem questioning (AI integration, commercial collaborations, ...). Fix: IA => AI typo and various English errors.
- mrbn100ful 7mo agoNot everything have to be perfect. For some user, /e/ is more approachable (Friendly and colorful UI) I could not get my mother to use GrapheneOS, /e/ is a lot simpler. Still miles better than to use a Default ROM from most OEM.
- ploum 7mo agoExactly! If you can use GrapheneOS, good for you but what /e/OS offers is: - Usable Android with your usual Android app (banking, etc) - No data sent to Google by default - Easier interface with nearly no bloatware - Available easily on many smartphones, including older ones - Extending the life of some smartphones The price to pay is: - Some Murena cloud bloatware - Android security patches are sometimes delayed - Security is not on par with GrapheneOS If your main concern is protecting your privacy from Google and extending the life of your smartphone without breaking a sweat, /e/OS is probably the best option. If your main concern is protecting against state actors attacks or very specific threats, then GrapheneOS might be better. /e/OS works really great for non-techie users. I’ve done it in my family.
- microtonal 7mo agoI have phones with both, but I don't necessarily agree that /e/OS is easier. E.g. things like doing or restoring in-app purchases often do not work, even when logging in through microG. Want that nice backup option that Signal is now offering? Well, good luck, you cannot purchase it on /e/OS (at least I couldn't). In general when it comes to compatibility, my experience is that GrapheneOS is better because it can use real Google Play Services, albeit sandboxed. I think you can use the Play Store on /e/OS as well, but it's going to have higher privileges. No data sent to Google by default Not true. /e/OS does send data to Google by default: https://www.kuketz-blog.de/e-datenschutzfreundlich-bedeutet-nicht-zwangslaeufig-sicher-custom-roms-teil6/ https://www.kuketz-blog.de/e-datenschutzfreundlich-bedeutet-... They also use Google for assisted GPS when you use it, eSIM provisioning, widevine provisioning. Last time I checked, microG on /e/OS also downloads a Google binary blob for SafetyNet. Besides analytics, if you install Google Apps (e.g. for Android Auto), many of them get higher privileges on /e/OS. The price to pay is: I would also add installing F-Droid apps (if you use App Lounge) through 'CleanAPK', without wanting to reveal why this is necessary or who owns/maintains CleanAPK. They do quite a lot of fishy stuff. It may be incompetence, but yeah... If your main concern is protecting against state actors attacks or very specific threats This always sounds like systems like GrapheneOS are for paranoid people. But this is basically you if you ever go to a demonstration (e.g. in the US) or cross borders of certain countries (e.g. of the US), sadly things like Cellebrite have become very common. Then suddenly layered protection, not running years behind in security patches, a duress pin, or rebooting after not unlocking for a few minutes to get back to BFU aren't so bad. (IANAL, figure out yourself which of these are legal and not destruction of evidence.)
- wolvoleo 7mo agoThere is when you have a phone that isn't a pixel.
- nosioptar 7mo agoGraphene doesnt even support all usable pixels. My pixel 3a isn't supported, but is by eos, lineage, and mobian (if you don't need volte).
- lpcvoid 7mo agoYour phone is too old, it doesn't get any security updates anymore since years now. Idk why you even still use it?
- nosioptar 7mo agoMy phone isnt too old, it still gets updates on Lineageos. I've got no reason to replace it.
- akimbostrawman 7mo agoIt gets Android OS feature updates not security/firmware updates. GOS aims to be the most secure OS possible without compromise so they aren't supporting devices without them. Pixel 3a only offered 3 years of security updates. Current GOS supported devices support up to 7 years.
- deleted 7mo ago[deleted]
- StingyJelly 7mo agoEven on non-pixel devices, unless you really want to use the /e/ "ecosystem, there are probably better options like LineageOS for microG iodéOS. (/e/ used to be heavily based on an outdated version of LineageOS for microG. I'm not sure what the current state is after I settled on second-hand pixel with graphene)
- Vinnl 7mo agoiodé is available for my device as well, but it looked fairly similar to /e/OS to me (and the latter has an official partnership with my phone's manufacturer). What makes it a better option - should I switch?
- StingyJelly 7mo agoWhen I looked into it, /e/ constantly used to be many months late with security updates. LineageOS for microg and iodé were much quicker (~ 1 month max which is still not that great).
- Vinnl 7mo agoHmm, possibly I'm looking in the wrong place, but as far as I can remember, I've been getting new /e/OS versions about every month, and looking at the release notes [1], they usually seem to include the latest "Android security patches", which I assume is what's relevant - unless there's something else that should also be included? [1] https://gitlab.e.foundation/e/os/releases/-/releases https://gitlab.e.foundation/e/os/releases/-/releases
- StingyJelly 7mo agoYes, seems like they got it down to ~2 weeks, goo! Good to know, that should be on par with Lineageos.
- dirasieb 7mo agois "/e/ supports my phone while graphene only supports google pixels" not a good reason?
- Rumengol 7mo agoThere absolutely is when your concern is not only moving away from Google but also using sustainable hardware like Fairphone, which GrapheneOS doesn't support afaik.
- bornfreddy 7mo agoAs someone who switched from FP4 with /e/OS to GrapheneOS - absolutely not true. My reason for switching was a bug where the phone calls didn't display the caller number. So I switched to GOS in hope it would be better... and it is, but not in all areas. For example their insistence on not supporting MicroG leads to poor UX, because let's face it, you can't trust Google services, even sandboxed, to not syphon tons of data into the cloud. MicroG was easybto use for privacy. They also seem to be very opinionated about (not) using a firewall for privacy, like NetGuard, instead recommending some weird alternatives like DNS firewalls. And don't get me started on their icons - I don't mind ugly-ish icons, but they are taking the ugliness to a whole new level. GrapheneOS is not a bad OS, but it is very opinionated, and they (heavily) prioritize security over privacy. When I turn FP4 on, I still like it way better than GOS. Still, I like seeing who is calling, so I'm not going back... Ymmv.
- ysnp 7mo agoI am not a project member so I cannot speak for GrapheneOS, but maybe I can help clear up some misunderstandings. >insistence on not supporting MicroG leads to poor UX, The problem they are trying to solve is apps not working without the presence of Google Mobile Services or Google Play. They don't want to compromise by having a component with high privileges integrated in their image that involves security issues like signature spoofing. MicroG will send less data to Google partly because it is simply an incomplete implementation of the features offered by GMS (sanboxed-google-play appp compatibility is quite a bit higher), partly because the access is more granular or there are choices offered for services like location (GrapheneOS provides non-Google location services and community support on only installing and enabling the parts you need for specific app features to work). UX is not adversely affected, but if you want to use a privileged app bypassing security checks and sending data to Google anyway then you have the freedom to compile microG with it integrated if you would like. >They also seem to be very opinionated about (not) using a firewall for privacy, like NetGuard, instead recommending some weird alternatives like DNS firewalls GrapheneOS tries to implement or end encourage sustainable approaches to privacy and security, and this partially means approaches that don't break if the adversary knows what you are doing. Egress/outbound traffic filtering is fundamentally unworkable. Apps do not have to connect to known privacy a invasive third party domains to violate your privacy or expose your data to extra parties, they can simply send anything they want to their own servers and do anything they like with the data. From my understanding this is why GrapheneOS do not want to encourage the approach of blocking apps from connecting to certain domains/addresses. Instead they tackle the problem at its source by providing a direct AND indirect network access toggle which cuts off an apps access to the outernet without letting the app know (pretends the network is down). This makes it non trivial for apps to exfiltrate data and as a side effect can provide benefits like data conservation (for capped plans). >instead recommending some weird alternatives like DNS firewalls. DNS based solutions are offered (not promoted) if you want more control over your DNS query resolvers or you want to improve your quality of experience by blocking advertisements and malvertising domains. >they (heavily) prioritize security over privacy. Can you point out another OS project with real privacy features like a network permission, sensors data access permission, contact access scopes, storage access scopes, per connection MAC randomisation and so on? https://eylenburg.github.io/android_comparison.htm https://eylenburg.github.io/android_comparison.htm They have even more plans for privacy like location scopes, anti-fingerprinting for Vanadium browser and maybe AnonymisedDNSCrypt/Oblivious DNS and probably more they haven't mentioned. If you suggest some more on their issue tracker they may get back to it when they have the resources.