4 ms·
> they also compare the security to the "Android Open Source Project" as if it's a real thing It is very much a real thing. You can build AOSP from sources and
by palata 1mo ago
> they also compare the security to the "Android Open Source Project" as if it's a real thing
It is very much a real thing. You can build AOSP from sources and install it on a phone. Many Android devices run that (e.g. drone controllers).
> Is certainly much better than my Samsung flagship
Oh yeah, that's for sure. To share my experience, in terms of updates for me it has been GrapheneOS >>> Stock Android > /e/OS. I was running LineageOS/Cyanogen a decade ago but I don't remember and it was a different time anyway.
- grapheneos 1mo agoFairphone's updates are definitely much worse than recent Samsung flagships. It's the other way around to an extreme. Samsung does monthly security patches for their flagships and includes a large subset of security preview patches. It's not as good as GrapheneOS security preview releases but they're ahead of the Android security bulletins. Fairphone is 1-2 months behind the Android security bulletins which are themselves 2-4 months behind the security preview patches. Fairphone takes a year to port to a new OS version shortly after launch and then ends up taking increasingly more time.
- realusername 1mo agoNo you can't, AOSP doesn't even include a functional keyboard not a functional call manager nowadays. And I'm not even talking about the firmware side of things Sure that might be enough for very basic hardware like your drone controller example but not a phone
- palata 1mo agoWell then you install apps.
- realusername 29d agoYou are just reinventing LineageOS here basically, patching the defects of AOSP to make it work on real phones
- palata 29d agoI am really not sure what you are trying to say. GrapheneOS is AOSP + stuff. LineageOS is AOSP + stuff. Certified Google Android is AOSP + stuff. What comes from AOSP goes into GrapheneOS, LineageOS and Certified Google Android. So obviously it makes sense to compare them.
- realusername 28d agoIt doesn't because AOSP itself is unusable on a modern phone. It's just a low level technical building block nowadays and everybody is chosing the parts they want. Comparing your OS to AOSP itself made sense in 2016, it doesn't anymore in 2026. It make sense to compare the OS between each other, what you can actually install and use on the phone.
- palata 28d agoDo we agree that the Android security model is baked into AOSP? Or would you say that the Play Services bring the security model to Google-certified Android, GrapheneOS implements its own security model from scratch, and LineageOS as well? Assuming they share a big part of the security model, how would it "not make sense" to compare them? If AOSP is the baseline, saying that /e/OS is often weakening the security model and GrapheneOS is hardening it is a way to compare them. That makes complete sense to me.
- realusername 27d ago> Or would you say that the Play Services bring the security model to Google-certified Android, GrapheneOS implements its own security model from scratch, and LineageOS as well? Yes I would say that most of the security decisions are not baked into AOSP and every rom brings their own decisions.
- microtonal 27d agoThat's really a weird position, since the SELinux-based app sandbox is in AOSP.
- microtonal 28d agoGrapheneOS >>> Stock Android > /e/OS There are many vendors that are even worse than /e/OS in terms of updates. This is one of several reasons why Play Integrity is a farce, it has very little to do with security when vendors can be months late with critical vulnerabilities and still get to pass Play Integrity. Basically anything that is not GrapheneOS, Pixel, or Samsung is in a deplorable state (Samsung not only rolls out security patches during the embargo period, they also do QPR2s).
- palata 28d agoI agree. I was just saying "in my experience". /e/OS and LineageOS support so many phones that it can change a lot.