6 ms·
GrapheneOS is focused on privacy but that must come from a secure baseline. GrapheneOS is much more privacy focussd than any other mobile operating system. Acc
by Cider9986 1mo ago
GrapheneOS is focused on privacy but that must come from a secure baseline.
GrapheneOS is much more privacy focussd than any other mobile operating system. Accrescent is the end goal for a secure and private app store but it's still in alpha. GrapheneOS is also the best for degoogling (eliminating all google services) because it comes with zero Google services unlike all the other ones listed here: https://eylenburg.github.io/android_comparison.htm https://eylenburg.github.io/android_comparison.htm
How can you call other OSes more privacy focused when they haven't closed as many VPN leaks as GrapheneOS? That's like bare minimum for privacy.
- dingaling 1mo agoThe problem is that to achieve privacy through security, Graphene has to treat the user as a potentially hostile actor. Therefore, the system needs to protect itself and other apps from the user. Which is very much contrary to software freedom.
- Cider9986 1mo ago> Which is very much contrary to software freedom. Yeah, the goal is privacy although the OS is completely open source. They do improve user experience by allowing disabling emergency alerts, call recording without alerts, no mandatory camera noise in Japan, no extra warning popup from installing APKs from the web (it's the same permission in every app store iirc), increases password length to 128 digits. All the network services are open source afaict while all the other mobile operating systems listed in that android comparison connect to Google's closed source services, netowrk permission, sensors permission, storage scopes, contact scopes. You can still easily install whatever Android app you want on GrapheneOS and you can install dangerous apps like shizuku and apps with way too many permissions. But yeah the goal is privacy so that everyday people can protect themselves as well as journalists can protect themselves. I want journalists to get the best privacy possible without having to know a ton of technical things or making many choices.
- Ajedi32 1mo agoVerified boot does indeed make this more complicated, but it's totally possible to build Graphene with your own signing key and get full control over the OS that way (i.e. https://github.com/schnatterer/rooted-graphene https://github.com/schnatterer/rooted-graphene). Looking at their public statements on the matter, it seems like the problem isn't exactly that they treat the user as a potentially hostile actor so much as that they treat the system UI and persistent storage as a potentially hostile actor (though I admit from a practical perspective that's nearly the same thing): https://www.reddit.com/r/GrapheneOS/comments/13264di/is_root_possible_with_grapheneos/ji54e19/ https://www.reddit.com/r/GrapheneOS/comments/13264di/is_root... I wonder how they'd feel about something like protected confirmation to enable sudo: https://source.android.com/docs/security/features/protected-confirmation https://source.android.com/docs/security/features/protected-...
- palata 1mo ago> Which is very much contrary to software freedom I believe you misunderstand what "software freedom" means. You can compile and install GrapheneOS yourself, and you can grant yourself admin access. This is software freedom. Software freedom does not mean that you should run everything as an admin, always. And just in case: software freedom does NOT mean that you should remove your firewall and let everybody SSH into your server by having a blank password.
- Ajedi32 1mo agoYou can't grant yourself admin access with the official build. Only the Graphene devs have the ability to push changes to the OS on your phone. Yes you can fork the software and build a version with your own signing key, then wipe your phone and install your custom build and thereby take back control, but then is that really still Graphene? I think it's fair to say that that's at least borderline anti software freedom, even if it's true they have good security reasons for doing things that way.
- Ajedi32 1mo agoThinking about possible ways they could retain the same security properties without impinging software freedom... maybe there's a way they could make the root of trust default to a signing key embedded in the device's own secure hardware? Then by default that key could sign Graphene's own signing certificate to allow them to push updates, but the user would retain the ability to revoke that signature and sign someone else's certificate instead (or their own certificate) if they decided they didn't trust Graphene anymore, or wanted to give themselves root.
- lol768 1mo ago> Accrescent is the end goal for a secure and private app store but it's still in alpha Note that nobody (new) can submit to it today; the developer console HTTP 503s and is only available to an allow-list of developers.
- phasephantasm 1mo agoAccrescent has been quiet for a while, but had claimed in the past they would open the store up for new submissions again soon, it will perhaps happen by the end of the year. Its self-imposed requirements for this are to provide a better developer experience and more common app store features developers (should) expect. They recently announced they will be posting more about the progress made towards such goal, after the big announcements and releases of some months ago. I'm more worried about the lack of a police to take apps down when it is very clear they should not be there. This is a present problem, presently solvable and that is not acknowledged despite the fact it harms the user.
- Cider9986 1mo agoThey just made an announcement on their social the are gonna announce stuff more on their social.
- welwala 1mo ago[flagged]
- SXX 1mo ago[flagged]
- ysnp 1mo agoAs far as I'm aware, they do not get the security patches and early bulletin access from Google. They get that from an undisclosed OEM.
- MattTheRealOne 1mo agoThe OEM is Motorola. The partnership was announced earlier this year. You are correct about them not getting early access from Google. There was a post within the last few months saying that Google no longer releases a lot of the code via git, but instead requires submitting a form and downloading the code via Google Drive. Google are actively trying to make third-party development difficult.
- phasephantasm 1mo agoWe are told the OEM in question is not Motorola, and it's likely some benefits of the Mototola partnership aren't yet in effect due to silly bureaucracy. Not sure there is any reason to lie about this. Embargoed ASB patches started being used in release 2025092500, but I can't find now the message where a Motorola employee (confirmed by a community moderator, spring-onion, in a Side of Burritos interview) first reached out publicly on the GrapheneOS Discord guild about how to obtain further technical guidance than the requirements list in the website which claims to be non-exhaustive, in order to confirm such message's date. Still, GrapheneOS claims (after the partnership announcement March this year) that ASB patches are provided by (effectively) a distinct undisclosed OEM, really meaning an employee is leaking them. Maybe even the person didn't disclose the OEM they work for but they must be associated to one in order to have access to this material.