Remix.run Logo
lordofgibbons 17 hours ago

Given that Google has said they'll be delaying source code release for Android to every X months intervals (iirc), how is GrapheneOS planning to handle security updates? Will they just be Google's binary blobs?

zeech 16 hours ago | parent | next [-]

Graphene already uses binary blobs (though one can disable them if they want). Info at [0].

[0] https://discuss.grapheneos.org/d/27068-grapheneos-security-p...

khimaros 16 hours ago | parent [-]

this isn't quite right. the blobs are produced by GrapheneOS and are reproducible once the source code embargo lifts.

zeech 15 hours ago | parent [-]

Whoops, nice catch - comment edited.

Aachen 7 hours ago | parent | prev | next [-]

Isn't that about feature releases? My understanding was that security patches are separate from this

edit: looked up the announcement https://www.androidauthority.com/google-android-development-... but it doesn't even mention the word security. I don't know enough about the manufacturer side of things to say whether this means there's also no security updates while they work on new features

izacus 11 hours ago | parent | prev [-]

Motorola is a partner that has access to Android source sooner.