35 ms·
AOSP eng here; I don't interact with Graphene or any of their folks at all; I'm just a distant observer like most folks here. Still, I can't help but think th
by moonshot5 26d ago
AOSP eng here;
I don't interact with Graphene or any of their folks at all; I'm just a distant observer like most folks here.
Still, I can't help but think that Graphene seems to want to complain about everything and anything that doesn't fit their niche use case. (As much as it seems beloved here, people that flash custom Android OSs are the very definition of niche users.)
My personal attitude to Graphene seems to get a bit more negative with each one of these "rants" and I doubt I'd go far out of my way to help them, even if I had exposure to them.
- WarmWash 26d agoWhen you are a minority you have to be incredibly loud for any chance to sway things your way. Not saying whether it's a good thing or a bad thing, but just the nature of reality.
- riedel 26d ago[flagged]
- iamnothere 26d agoSecurity shouldn’t be a niche use case. There’s a constant trickle of CVEs, and spyware vendors are known to abuse these exploits in their software. All this on devices that are reachable in the US through a text or MMS, sent to an easily located 10 digit number that isn’t easily changed. These are devices that people now use for all kinds of sensitive tasks! Security should be the number one priority, frankly. Graphene has shown that this is possible, and they have tried multiple times to get Google to integrate their work.
- Iolaum 26d agoEven in the EU spyware use is prevalent (and i 'd guess everywhere else in the world). There have been many scandals of government authorized commercial spyware been deployed against journalists. Is it really that niche a mobile OS that tries to not be exploitable by them?
- Borealid 26d ago[flagged]
- Iolaum 26d agoGraphene puts a HEAVY emphasis on security. Also your argument about a user inspecting and editing application files feels like a strawman argument. For example many spyware use malicious links to infect the devices, not malicious apps.
- Borealid 25d agoLet's say I want to secure my system against an app developer deciding to delete my data stored in their app. To do that, I wish to store a copy of all the files the app has written to my filesystem, and put that copy outside the app's control. This is explicitly to contain data the app's developer does not WANT me to be able to keep. A. Is my being unable to do this "more secure"? If so, why is the specific threat I described to my data integrity - an app developer deleting my data - invalid? B. Does GrapheneOS support this protection, ensuring the device owner is secure against the app developer, or do they instead secure the app developer against the user?
- Iolaum 25d agoLet's say you are a Graphene OS user. Why are you even using such an app? Also you are misrepresenting the threat model. The problem is not an app deleting it's own legitimate data. P.S. On GrapheneOS you can block apps from getting Internet access to limit their bad ideas.
- Borealid 25d agoI do not feel you addressed my point at all. I want to install an app now, and protect against its developer doing a rugpull on my local files later. I do not want to need to review each new app version in advance as I install it. This is clearly a legitimate case where what the Android security model says I should be permitted to do makes me less secure against an attack by the app developer.
- embedding-shape 26d ago> that Graphene seems to want to complain about everything and anything that doesn't fit their niche use case What would you want them to complain about instead? Of course they'll complain about that, just like Googlers will complain about things affecting their stock price, no one is surprised that people care about stuff they're personally involved in, it makes a lot of sense. Now if these complaints weren't accurate, then I'd walk with you and feel a bit more negative with each piece. But the ones I've looked into, have been spot on, so who cares if it's for their specific niche? I expect them to care about their niche, that's why those people all work together in that organization in the first place.
- mmooss 26d ago[flagged]
- microtonal 26d agoI'm not an AOSP engineer, but that was my thought reading GOS's comments: Why be negative toward the people who you want help from? What help though? Google has closed off AOSP and only does source code drops twice a year. Google has embargoed security patches for three months and only provides them to OEMs of Google-certified Android phones, not other AOSP-based projects. Google stopped providing git trees of kernel sources and instead requires projects to submit a request for a Google drive link for each kernel version that takes up to weeks to process. Google is shutting out open Android systems through Play Integrity. Google is not helping anymore, over the last 1-2 years they have tried everything to sabotage AOSP-based projects. The only reason that they are not fully closing AOSP is probably because 1.) they would get in hot water with regulators; and 2.) AOSP will probably get forked.
- edent 26d agoPerhaps they complain because that's literally the only way to get Google to take notice? Let's be real, AOSP doesn't exist any more. Google have closed down nearly everything. All the development happens in private, you've stopped addressing bugs raised by the public, the source of patches are only infrequently released, device trees are gone. Wouldn't you complain?
- microtonal 26d agoAll the development happens in private, you've stopped addressing bugs raised by the public, the source of patches are only infrequently released, device trees are gone. To emphasize this point a bit more: only "QPR0" (major release) and QPR3 are released as part of AOSP. QPR1 and QPR3 are not released at all anymore, but contain fixes for vulnerabilities that are not marked high/critical (so don't end up in ASB). It is not clear to me whether OEMs get access to QPR1 and QPR3, but Google are not only witholding features, but also a set of security fixes. Besides that, they are torpedoing other systems through Play Integrity. IMO it would be best if AOSP was spun off from Google into its own org that actually cares about developing an open source system for others (both open source systems like GrapheneOS/Lineage and commercial vendors like Samsung) and that would have an attestation system that is open to vendors that have good device security.
- delichon 26d agoThis doesn't read as a rant to me, but as calm and factual, regarding a genuine security regression that merits public attention. What is your interest in mischaracterizing it?
- Cider9986 26d agoYou might not like their style of speech, at least they care about their users. Maybe Google uses nice flowery language that makes the reader feel nice—IDC—actions speak louder than words. Stock Pixel is an awful experience. So many useless notifications, popups, ads, privacy not by default. Company: "We care about your privacy" meanwhile 1400 corporations they share data with GrapheneOS: "There's zero telemetry in GrapheneOS" The more you read the more you realize they are nearly always correct.
- gib444 26d ago[flagged]
- Cider9986 26d ago> If they happen to overlap, that's a happy coincidence. I can't know what the developers of any OS are actually thinking, but based their actions, GrapheneOS does more for their users than any other OS. Therefore I assume that doing good things for users equals care for users. It's probably stupid to try to guess about care.
- yaro330 26d ago> Stock Pixel is an awful experience. So many useless notifications, popups, ads, privacy not by default. Huh? What pixel are you on? You only get notifications from stuff you install after the initial setup is done. And even then you can outright mute applications, completely.
- certify7128 26d agoThankfully the project doesn't care about your personal attitude. That "niche use case" literally saves lives in countries where saying the wrong thing can put you to death. Since when is calling something out a rant?
- LMYahooTFY 26d ago[flagged]
- rustcleaner 26d agoIn a world where economics makes security hardly a secondary concern, a situation exploited by both the intelligence and surveillance broker sectors, dogmatic sanctimony for high security is a feature and not a bug.
- timschmidt 26d ago> As much as it seems beloved here, people that flash custom Android OSs are the very definition of niche users. Hmm... Let's try reframing this: "as much as it seems beloved here, people that install their own operating systems on PCs are the very definition of niche users" I'm absolutely certain that's how IBM felt before the clones. But the ability to install what they wanted on a defacto standard platform is what launched the computing revolution. I think we'd still be living in a sterile monopolistic environment with $10k compilers otherwise. Folks installing their own ROMs on phones are only niche because they've been pushed out at every opportunity using locked bootloaders, embedded security processors, factory installed secret keys, etc. Despite all that, there's still thriving communities developing and using custom ROMs on their phones. That demonstrates more than niche demand.
- yaro330 26d ago> Hmm... Let's try reframing this: "as much as it seems beloved here, people that install their own operating systems on PCs are the very definition of niche users" I mean yeah, 99% of people never installed an OS and never will, what's your point here?
- timschmidt 26d ago> 99% of people never installed an OS and never will, what's your point here? That the 1% who do build visicalc, Linux, the internet, Google, and every application and innovation that happens outside the corporate wall. The entire ecosystem everyone else ends up using. And that calling that niche is ridiculous, shortsighted, and shooting oneself as a platform owner in the foot.
- yaro330 25d agoWhat are you talking about? You're making zero sense. I've been in the niche of modifying and installing my own ROMs, then to kernels, and now doing the same things commercially. It is a niche, it always was. There was never a mass community of users, the most installs you used to see on any given AOSP based project is maybe 20-30K for the most popular devices like Redmis, Pocos or Google Nexus phones. It's still a niche, and things that users do and used to do to their phones are fundamentally incompatible with Android's security model. Root access, magisk, xposed, overall zero or near zero security validation from the security perspective on all ROMs but Graphene (maybe some others, I haven't followed the sphere for a while).
- striking 26d agoIf they're just some "niche use case" then why would Motorola partner with them? The way they see it, > By combining GrapheneOS’s pioneering engineering with Motorola’s decades of security expertise, real‑world user insights, and Lenovo’s ThinkShield solutions, the collaboration will advance a new generation of privacy and security technologies. In the coming months, Motorola and the GrapheneOS Foundation will continue to collaborate on joint research, software enhancements, and new security capabilities, with more details and solutions to roll out as the partnership evolves. https://motorolanews.com/motorola-three-new-b2b-solutions-at-mwc-2026/ https://motorolanews.com/motorola-three-new-b2b-solutions-at...
- bitpush 26d agoMotorola is not a big Android phone maker.
- striking 26d agoI think that's a worthwhile point to consider but it's only relevant if we move the goalposts from "GrapheneOS is only used by Android ROM enthusiasts" to "GrapheneOS is only supported by one small Android phone manufacturer". To be frank, though, I don't see any of this line of reasoning as relevant; it's just appeals to greater authorities on either end. If AOSP is only for manufacturers there's really no reason for it to be open source in the first place. And then folks who care about actually improving security end-to-end outside of whatever's convenient to implement by those beholden to the quarterly profit metrics are up a creek. Personally, if this whole GrapheneOS/Motorola thing doesn't improve the state of the ecosystem I'm going back to Apple or whatever other manufacturer makes it clear they take security seriously.
- mirashii 26d agoThey’re the second largest manufacturer of Android smartphones in the US, and 10% of the global market. Seems a bit unreasonable to dismiss them out of hand on that basis.
- eptcyka 26d agoNeither is google.
- amaccuish 26d ago[flagged]
- matheusmoreira 26d agoI've never seen them call it "evil". I've seen them debunk CalyxOS security claims as well as criticism of GrapheneOS, and they usually provide some serious reasoning and technical information when they do it. They know what they're talking about. Don't take it personally. I'm a huge fan of Linux, and GrapheneOS routinely comes here and calls it a huge security liability. And they are right.
- drewfax 26d agoSo other projects are not supposed to critize Google? Graphene's focus is on security and they complain about lack of security in your products. Seems valid to me. Also security and using non-Google OS are not niche usecases. I'm not sure how you are working on Android, the most popular OS while claiming security is a niche usecase. In fact, I have less confidence in security of your work.
- MostlyStable 26d ago[flagged]
- matheusmoreira 26d ago[flagged]
- freedomben 26d ago[flagged]
- matheusmoreira 26d ago[flagged]
- MostlyStable 26d ago[flagged]
- eptcyka 26d ago[flagged]
- eptcyka 26d ago[flagged]
- fph 26d ago[flagged]
- stefan_ 26d ago"I don't know anything but I don't like Graphene" Well we know Google isn't enabling MTE, while LLM-enabled exploits are multiplying rapidly. Maybe you need to get back to work?
- matheusmoreira 26d agoThey are good enough to have their own Cellebrite column. If they complain about something, you should probably listen.
- rustcleaner 26d ago... and my opinion becomes more positive with each rant. We'll have to agree to disagree. The only reason I buy Pixels for myself and my family members is because of GrapheneOS, otherwise it would be used out of date hardware for LineageOS or some kind of Linux phone. I am thankful that they are attempting to diversify with Motorola, being entirely Pixel dependent has been a project vulnerability; anytime Google decided to lock down the boot loader, it would have been curtains for the project.
- ysnp 26d agoCould you please explain why supporting MTE/potentially EMTE in production as a goal represents a niche use case? Isn't mitigating memory corruption issues a mainstream ideal? How else would you propose to do it?
- drnick1 26d agoMaybe if Google did not shove their spyware down people's throats and actually allowed users control of their phones, there wouldn't be a need for projects like Graphene and Lineage. Until then, complaints are more than justified.
- 1shooner 26d ago> people that flash custom Android OSs are the very definition of niche users. This is a mischaracterization. The niche isn't Android hobbyists, it's people with what should be a basic expectation for privacy. I wouldn't flash GOS or any other OS if I could safely avoid it.
- Phelinofist 26d ago> I doubt I'd go far out of my way to help them, even if I had exposure to them. Too busy crippling sideloading I guess
- yaro330 26d ago[flagged]
- preisschild 25d agoTbf with all the information that has come to light since then Rossmann and FUTO were also not behaving correctly and it was fair from him to deny coming onto their show (where they have also invited fascists before)
- yaro330 25d ago[flagged]
- deleted 25d ago[deleted]