Remix.run Logo
tfrancisl 3 hours ago

I've never really understood why we chase Android-alikes on mobile platforms instead of trying to build on mainstream Linux. I know some folks in the nix community (nix-on-droid and other projects) have tried to bring us closer to this, but projects like Graphene seem to have a lot of traction.

godelski a minute ago | parent | next [-]

Seems like it's the same problem as chromium. Is it better to get off the Google controlled ecosystem? Yes. Is it easier to leverage the Google controlled ecosystem? Also yes.

People will tell you that chromium is "more up to date" as if Google wasn't the one setting the standards, making it impossible for anyone else to be similarly complete. Seems like we have a very similar problem here...

inigyou 3 hours ago | parent | prev | next [-]

All the existing apps are on Android and iOS. Graphene lets you run them. You can't have a bank account on a Linux phone* because they won't let you, but you can on Android including on Graphene.

* before replying snarkily that Android is Linux, please take a long walk off a short pier, thanks

yjftsjthsd-h 2 hours ago | parent | next [-]

> All the existing apps are on Android and iOS. Graphene lets you run them.

We have waydroid for that.

> You can't have a bank account on a Linux phone* because they won't let you, but you can on Android including on Graphene.

Unless of course it uses those stupid integrity apis to block anything that isn't stock.

pteraspidomorph 2 hours ago | parent | next [-]

Graphene passes basic integrity, so most of them work. There is a list here:

https://privsec.dev/posts/android/banking-applications-compa...

imkac 2 hours ago | parent | prev [-]

Porting traditional Linux desktop distributions to Android devices is meaningless, all you get is more instability, more unsafe and more trouble. Waydroid is a bad implementation on security and compatibility, just running Android in VM is better.

yjftsjthsd-h an hour ago | parent [-]

> Waydroid is a bad implementation on security and compatibility, just running Android in VM is better.

What security problems does waydroid have that a VM wouldn't?

tfrancisl 3 hours ago | parent | prev | next [-]

What's stopping me from using a browser to log in to my bank? Assuming my bank is one of the ones that requires you to lock down sideloading (they aren't, but i know many are).

owaislone 2 hours ago | parent | next [-]

Nothing is stopping you. You're free to use a desktop web app that either doesn't work or is terribly slow or has limited features on a mobile web browser. I'd love it if all apps were PWAs but that is not the case.

georgeecollins 2 hours ago | parent | next [-]

My broker has a much more fully featured web app then it does on iOS or Android. You can do things in a browser that the phone apps will send you to a browser to do. BofA is just as good of a web app. Maybe people are just used to using their phones?

limagnolia 18 minutes ago | parent | next [-]

Can you deposit checks from the webapp? That is the feature most often missing in banking webapps. It isn't something I need often, fortunately.

georgeecollins 42 minutes ago | parent | prev [-]

Looking down the thread I am also thinking maybe this is a Europe thing? I am usa.

thesuitonym an hour ago | parent | prev | next [-]

That's not terribly compelling. Android and iOS banking apps also don't work, are terribly slow, and have limited features.

mikestew an hour ago | parent | prev [-]

Eh? The bank apps I’ve seen appear to be webviews wrapping their mobile site. Much to my chagrin, I’ll add.

terribleperson 2 hours ago | parent | prev | next [-]

I had to replace a credit card yesterday. Part of the default flow involves the call center sending a notification to your app. When I told them my android version was too old, it took them twenty minutes to find out they could instead send a text message. That text message sends you to a photo-and-id verification service, but that's another issue.

Soon, there won't even be an alternative flow. There are a lot of places where there already isn't.

georgeecollins 2 hours ago | parent [-]

Are you sure? This seems like a forum with a lot of early adopters and a lot of late adopters still use browsers, email, text messages. Like, let me guess that your credit cars isn't capitol one. Not that it should be, but that would be more "normie".

cesarb 30 minutes ago | parent | prev | next [-]

> What's stopping me from using a browser to log in to my bank?

The "security module" they require you to install on your computer. In the past, when browsers had plugins, this was a browser plugin; nowadays, it's an always-on service (running as root) which exposes a local HTTP server which the bank site connects to to validate your computer. For an example from a major bank in this country (the same "security module" is used by several banks in this country), https://seg.bb.com.br/home.html is the diagnostic page for that "security module" (the FAQ page there has links to the installers).

Yeroc 3 hours ago | parent | prev | next [-]

The websites don't have feature parity with the apps these days. Things like being able to deposit a cheque aren't available among other things.

lopis an hour ago | parent | next [-]

Some older banks do have more features in their website than their app. It's usually the ones with the worse, most outdated UIs and almost useless mobile apps. After years of using several mobile-first neo-banks, I switched to a traditional bank and boy, was I not ready for the trip back in time.

encom 37 minutes ago | parent | prev [-]

>deposit a cheque

That would be inconvenient if this was 1985.

Alpha3031 3 hours ago | parent | prev | next [-]

Some banks are app only and/or build MFA functionality into their apps.

thesuitonym an hour ago | parent | next [-]

That would be a hell naw from me.

wseqyrku 35 minutes ago | parent | prev [-]

You know the web is also bits and bytes right? Someone who has a say should fix it so banks can do whatever they need right in the browser.

inigyou 3 hours ago | parent | prev | next [-]

The 2FA code you need to get from the phone app to log in on a desktop. It isn't 2005 any more.

Aachen 2 hours ago | parent | next [-]

Apparently I live in 2005 then? I do 2FA with the same chip+pin method that I use to pay in the store. Works in any browser

patall 2 hours ago | parent [-]

Maybe that is possible in Germany. It is impossible here in Sweden.

Or in other words: of course you can have mobile bankid without a smartphone, just use a tablet computer ;)

patall 2 hours ago | parent | next [-]

@fsflover: and my mobile phone provider. And my insurance. And my eletricity provider. And my housing associations customer portal. Getting doctors appointments. Mortgage. Union. National retirement savings account. Some of these may have some alternative left, but far too many you will be left out.

Well, I can buy a train ticket without it, so I could still leave.

epihelix 23 minutes ago | parent [-]

Do you mean to say that all these services require strong device integrity to function in Sweden?? In Australia, no local app that I'm aware of (banking, finance, government, medical) requires any form of device integrity - otherwise I couldn't use them. The only exception I've encountered is Google Wallet.

I wonder why there would be such a difference in policy between countries, not only in government but across the private sector? This doesn't make any sense to me. If anything, I'd expect Sweden to have a more sensible, left wing attitude than Oz.

fsflover 2 hours ago | parent | prev [-]

Looks like it is possible in Sweden: https://news.ycombinator.com/item?id=47562094

Consider switching your bank to one not forcing you into American megacorps.

stvltvs 2 hours ago | parent | prev | next [-]

Highly location dependent. This is more true in Europe than in America.

tcfhgj 2 hours ago | parent | prev | next [-]

my bank (and others) doesn't require the 2f to be a smartphone

jonathanstrange 2 hours ago | parent | prev [-]

Right, 2FA. My bank wants me to log in to my phone app and then sends an SMS to the same phone to confirm the app transaction. It's super-secure.

saidinesh5 3 hours ago | parent | prev | next [-]

The bank website typically needs the app to enable two factor authentication in a lot of places.

For eg. There's no browser based alternative to make UPI payments that i know of.

dotancohen an hour ago | parent [-]

How about for clients with no smartphones?

gf000 35 minutes ago | parent | prev | next [-]

Well, it's kinda hard to scan a QR code displayed on your screen when the camera is attached to its back (semi-joking)

TFNA an hour ago | parent | prev | next [-]

In many countries, all major local banks require their phone app as the second factor to log in to the browser version of their online banking. Sometimes functionality is removed from the browser version and made available only in the phone app.

drnick1 an hour ago | parent | next [-]

"Many" is doing a lot of work here. A more accurate statement would be that some banks in some countries require invasive apps, but fortunately it isn't the case everywhere (yet).

renehsz a few seconds ago | parent [-]

This is a huge problem in EU countries!

The relevant regulations are Commission Delegated Regulation (EU) 2018/389 and the earlier Directive (EU) 2015/2366.

While these laws are deliberately vague when it comes to specific technologies, they do require at least two independent factors from different categories, such as knowledge (password) and possession (phone).

That, in and of itself, wouldn't be a problem. The way most banks implement it, however, is by giving you two choices:

1. You use their mobile app (which likely requires device attestation and Google Play Services, so won't work on a plain LineageOS install)

2. You use their CardTAN device, which is extremely inconvenient to always carry around.

Sure, we nerds might argue they should just let us use our Yubikeys or regular old TOTP, but pretty much no bank implements that. (Why? Your guess is as good as mine.)

Personally, I had to buy a second stock Samsung phone just for banking apps. And yes, there are still alternatives (only very very few though), but no, none of them are convenient, for various unrelated reasons.

I wouldn't be surprised if this continues to spread to the US too, under the sneaky disguise of "security".

dotancohen an hour ago | parent | prev | next [-]

And what do people without a smartphone use?

renehsz 29 minutes ago | parent [-]

A hardware-based CardTAN device, which is super inconvenient. Or else they can't do any online banking at all.

crying in EU :(

DANmode an hour ago | parent | prev [-]

Name five.

catlikesshrimp an hour ago | parent [-]

BAC in Central Americal https://www.baccredomatic.com

justsomehnguy 2 hours ago | parent | prev [-]

The bank itself. They want to see where are you, what you do and snoop on anything they can about you. Having a spywa^W sorry, bank app is the best way to do that.

Source: my bank which recently 'upgraded' a browser version to a glorified SPA which even renders as a vertical oriented app on a landscape 4K monitor.

thesuitonym an hour ago | parent [-]

Sounds like it's time for a new bank.

dethos 8 minutes ago | parent | prev | next [-]

> Graphene lets you run them.

It seems not all of them, and that things will only get worse if recent news comes true.

t1234s 2 hours ago | parent | prev | next [-]

Even Graphine is limited in what apps work properly compared to a normal google phone. You have to give up a lot in order to have privacy these days.

A pure linux non-android phone would be great however you wouldn't have access to properly working apps and would not be able to participate in modern society.

m4xp an hour ago | parent | next [-]

Not true, if you install play services you can run 99.9% of apps, i can even run all the italian apps from yhe goverment. You are still using google but its running as user service and you can even revoke most of the permissions including location.

unethical_ban an hour ago | parent | prev [-]

Running their sandboxed Play, I can run everything. The only thing I notice in the US is some banking apps (stupidly, idiotically, moronically) force 2FA on every login instead of trusting biometric entirely like they do on stock OS.

sehw an hour ago | parent | prev | next [-]

I use my web browser to access my bank and tell banks that require apps to go fuck themselves.

wseqyrku 43 minutes ago | parent | prev | next [-]

I can't care less about "apps". Web is already powerful enough to do all sort of stuff on device.

That said, I think wasi containers support for a mobile OS would be a game changer.

(^ Here's a startup idea if you're looking out for one. I for one throw out all my devices from the balcony to get this)

trueno 6 minutes ago | parent [-]

yea i straight up am not downloading apps anymore if i can help it. virtually zero companies put apps out to provide a better experience, they just do it to get telemetry data. which is why all these banking apps are just their website in some wrapper lol

megous 2 hours ago | parent | prev | next [-]

Banks care very little about actual security. Some force you either to SMS codes, or to their app on a hopelessly broken platform based on shoving many untrusted spying apps onto one device and hoping some SW will be able to keep them apart.

Almost none support strong dedicated HW authenticators or second factors. Not even as an option to those who care.

Anyway it's always possible to just reverse their web api and use it directly. 2FA that consists of copying some code from SMS is no barrier, especially not on the Linux phone that you fully control.

jambalaya8 2 hours ago | parent | prev | next [-]

yeah, people suggesting Android is Linux are as annoying as people saying Digital Unix/Tru64 was OSF/1, or MacOS/OSX is now Darwin or OSF/1 or Gnu Hurd itself.

xnickb 2 hours ago | parent | prev | next [-]

Some (European) banks/healthcare apps block GOS and require stock android. Just saying

protimewaster 2 hours ago | parent | next [-]

I wonder if practices will change any of there's ever a device that ships with GOS. Right now, many companies are happy to shrug off GOS, because they don't support "modified devices".

If any of the Motorola devices have GOS as a pre-installed option, now the companies don't have the excuse that the device is modified.

I'm guessing the companies will continue to be difficult, but it'll be amusing to watch, at least.

drnick1 an hour ago | parent | prev | next [-]

What is the point of apps for these things in particular? I understand that some banks require an app for 2FA, but I don't see why anyone would want some invasive healthcare app on their phone.

gunalx 2 hours ago | parent | prev [-]

Yep. Had to change banks because of my old one suddenly dropping grapheme support by adding stupid attestation mechanics.

They surely must have gotten feedback from me and others because the next update it worked again. But I and probably others where already a lost customer.

throwaway_94383 2 hours ago | parent | prev [-]

most banking apps don't run on graphene

DANmode an hour ago | parent [-]

Stop parroting this. It’s not true.

Diminishingly few apps do not work, and it’s down to them.

dethos 5 minutes ago | parent | prev | next [-]

Yes, there's SailfishOS, there's Ubuntu Touch, and a couple more. It would be nice if one of them could gain traction so people can have a third choice.

drnick1 39 minutes ago | parent | prev | next [-]

Like others have said, it comes down to apps mostly. But there is also the fact that Google and others have spent more than a decade optimizing the OS for appliances. Android was built from the ground up for mobile devices and handles things like background apps, notifications, and charging as expected on a phone. All of this could be ported or rebuilt, but the work has already been done for Android and billions of devices prove that it works.

QwenGlazer9000 3 hours ago | parent | prev | next [-]

Everyone else mentioned the app support which is true, but for graphene specifically, they do not like desktop Linux at all because they don't like its security. They would much rather build on AOSP than desktop linux.

Gigachad 3 hours ago | parent | prev | next [-]

Because you need app support. Not even Microsoft could pull that off.

jorvi 3 hours ago | parent | next [-]

You mean Microsoft proactively kept shooting devs in the kneecaps?

Leaving phones behind on old incompatible OS versions 2 times in 3 years and switching app frameworks 3 times in 4 years does not a good app developer experience make.

Piled on top of that, Google became actively hostile to 3rd party developers building support for YouTube (and Gmail and Gmaps, but those had workarounds / alternatives).

Yokolos 2 hours ago | parent [-]

What a colossal disaster. I was a huge Windows Phone fan, so their yearly missteps were quite painful to watch. I was especially annoyed when my first gen WP wasn't going to get an upgrade to WP8. My HTC 7 Pro is still my favourite phone I've ever owned, but after that I finally gave up and switched to Android.

nextaccountic 3 hours ago | parent | prev | next [-]

What about running the whole Android infrastructure, but on top of a non-Android Linux distro? And this, on top of a Android kernel (otherwise you won't have the drivers yo uneed)

The advantage being, we can manage packages using a regular Linux distro

saidinesh5 2 hours ago | parent | next [-]

A lot of "non Android Linux distributions" like sailfish os actually use a lot of Android infrastructure to keep working.

Drivers doesn't just mean the kernel. It's the user space binary blobs and services that need to talk to the kernel to enable the hardware.

Other than that there's waydroid, alien dalvik etc.. that run another Android instance in a container.

The thing is a lot of Android applications use safety net/other methods to make sure they only run on. "Approved"/stock hardware.

tfrancisl 3 hours ago | parent | prev | next [-]

This is exactly where my head goes. There's nothing special about this hardware other than its small form factor. Sure, some desktop apps would likely want a different skin, but thats hardly limiting.

realusername 2 hours ago | parent | prev [-]

You can't because a lot of apps check that the phone is controlled by Google with Play Integrity.

Google thought about this, don't worry. They learned their lesson after CyanogenMod tried to compete by offering an alternative. Non-Google Android are now dead except in China.

arxari an hour ago | parent | next [-]

Well for me I use Lineage without even MicroG and everything I need works - yes even banking

imthatsteve 2 hours ago | parent | prev [-]

CyanogenMod became LineageOS and its still going strong, im typing this on an unofficial lineageOS build right now.

puzzlingcaptcha 3 hours ago | parent | prev | next [-]

App support, stable ABI, uniform UI/UX, hardware vendor cooperation...

tfrancisl 3 hours ago | parent | prev | next [-]

I dont think app support is all that important. Most apps are garbage as they are ime, so rebuilding from scratch, or using existing software that runs fine on linux, would keep me happy.

tcfhgj 2 hours ago | parent | prev | next [-]

Microsoft could, but abandoned just as they gained traction in Europe

sunaookami 2 hours ago | parent [-]

I miss my Windows Phone...

inigyou 3 hours ago | parent | prev | next [-]

Doesn't windows run android apps natively now?

dzikimarian 2 hours ago | parent [-]

It doesn't. There was a plan, but Microsoft abandoned it.

AstralSerenity 2 hours ago | parent [-]

They did end up releasing Windows Subsystem for Android via the Windows Insider Program, which was enough for the OSS community to take it over after it was abandoned. It still exists and has worked quite well for my use case: https://github.com/MustardChef/WSABuilds

deaton an hour ago | parent | prev [-]

Microsoft can barely pull off their flagship desktop operating system, so that doesn't say much.

florianherrengt 11 minutes ago | parent | prev | next [-]

I have a Pinephone Pro. It's nowhere near usable as a daily driver.

compass_copium 3 hours ago | parent | prev | next [-]

GOS is broadly compatible with most phone use cases out of the box--chat, mail, browsing. A Google Play profile lets me use almost all apps (including my bank apps, but I understand that's not true for everyone).

In principle I agree about a Linux phone, but the gaps are much greater. I am also sympathetic to the GOS team's arguments that sandboxing on Android is better, and important on a device that allows control of essentially my whole life (2FA apps etc.)

dzonga 2 hours ago | parent | prev | next [-]

once Huawei was forbidden from using Android - that's when people ie western markets & the world at large should've shifted. look at HarmonyOS.

in China - there's no google apps available on their 'android' versions.

their platforms are already performant and fluid - so people should build on that.

RobotToaster 2 hours ago | parent [-]

It's a shame that the newest version of harmonyOS isn't open source.

throwIeoeor 2 hours ago | parent | prev | next [-]

Because Android is miles ahead in terms of security, permission management, app separation, power management, privacy...

Linux crowd can not even agree on compositor, and if systemd or sudo is a good idea.

thesuitonym an hour ago | parent | next [-]

> Linux crowd can not even agree on compositor, and if systemd or sudo is a good idea.

This is actually a feature.

bigfishrunning an hour ago | parent | prev [-]

Why should Linux users have to agree? run what you want, it's your computer.

otekengineering 2 hours ago | parent | prev | next [-]

i recently put debian (mobian) on a pixel 3a and it's pretty solid, though i haven't tried it out as daily driver yet.

claude code makes stuff like that super accessible to do in your spare time. another example is installing debian on a synology 918+, there's no way i would've had the grit to do that without ai. it's open season for any gadget that's got a debug uart port.

gf000 37 minutes ago | parent | prev | next [-]

Because it's a mobile platform and "GNU+Linux" is laughably terrible in this space.

It's almost like Android has put millions of expert dev hours into making it the most used OS in the world. Like GNU+linux on laptops only works the way it does because of android-upstreamed battery saver kernel features.

But a mobile is also people's most used devices with all of their data, bank accounts etc there - it has to be safe. And GNU+linux has not even a single thought about security, while android just has it worked out (every app runs as its own user, so it's even built on standard UNIX security).

A mobile OS also has to race to suspend and for that it needs cooperation from "apps" -- desktop apps just run, they don't care about anything besides SIGKILL. That's not a workable model on a mobile and android solves it.

And I say all that as someone who runs linux everywhere I can and I absolutely love it. It's imo the best kernel out there -- but the userspace is not where it should be and if anything, the correct question would be what can we take from Android and add to GNU+Linux. (And nix is fantastic, but it's a packaging solution, I don't really see how it comes into question here. I can run nix on my android phone just fine by the way)

matheusmoreira 2 hours ago | parent | prev | next [-]

Because without Android I can't run WhatsApp and my bank's app on my phone, which promptly reduces it to a paperweight. I wish it wasn't so, but reality refuses to cooperate, so let's just be happy that we've got GrapheneOS which is so good it has its own column in Cellebrite's support matrix.

owaislone 2 hours ago | parent | prev | next [-]

Apps. We'd love a completely different OS and it is viable on desktop because web almost does everything but on mobile you're basically locked out of very essential functionality like banking, transit, messaging etc. The compatibility layers aren't good enough (yet) to offer a seamless experience.

gunalx 2 hours ago | parent [-]

Also almost any native desktop app forced to mobile has broken ux.

DANmode an hour ago | parent | prev | next [-]

Your point is valid for every flavor of Android except GrapheneOS.

GrapheneOS’ security model makes that of desktop Linux look like a joke.

This is an objective analysis based on x86 security, GrapheneOS hardening (including isolation and hardened mem allocator), Pixel hardware security.

Cider9986 3 hours ago | parent | prev | next [-]

AOSP has way better security and therefore privacy than desktop linux.

arxari an hour ago | parent | next [-]

This is something that no Linux phone enthusiast seems to understand.

Also if we use atomic distros with flatpaks and whatnot that mimic Android security the end user basically ends up having to essentially use Termux (but busybox or something similar) on their Linux phone as well

drnick1 an hour ago | parent | prev [-]

Stop repeating this nonsense, AOSP isn't any more "private" than Linux. AOSP is only more "secure" because, on some devices like Pixels, it exploits hardware features typically not found on general purpose computers. By default, Android also limits user control and takes root away. That may be a sensible design for an appliance, but it isn't something we should want on desktops.

deaton an hour ago | parent | prev | next [-]

Because the Android Runtime (ART) is very necessary to run APKs, and APKs are the only non-iOS standard for packaging mobile apps that is supported enough to be viable. Without it, you might get some open source apps to run on a linux phone, but you won't have banking apps, clash of clans, or a million other things people really would like to have on their phones.

geremiiah 3 hours ago | parent | prev | next [-]

I don't either. Don't we have free market capitalism? Why don't I have a Linux phone? And why do I need to worry that my government and banking apps won't work if I get a Linux phone?

rcxdude 3 hours ago | parent | next [-]

Because in a free market you can't compel someone to support your niche platform, nor even compel someone to create the niche platform you want. The market for a Linux phone is tiny because there's almost no reason for the average phone user to prefer it over android.

fsflover 2 hours ago | parent [-]

> you can't compel someone to support your niche platform

You mean, a browser?

post-it 2 hours ago | parent | prev | next [-]

Because you don't have capital.

gf000 16 minutes ago | parent [-]

well, apparently not even Microsoft had enough capital.

It's almost like the free market only works when we have well-defined and regulated markets. This has been known by Adam Smith and quite logical, yet people expect Google and Apple giga-corporations with monopolies to somehow abide by the laws of selling grains on the market.

attila-lendvai 2 hours ago | parent | prev | next [-]

no, we don't, far from it.

(which doesn't mean there's not a lot farther from here).

realusername 2 hours ago | parent | prev [-]

> Don't we have free market capitalism?

Not in the mobile world no, it's not a free market by any means

kotaKat 2 hours ago | parent | prev | next [-]

All we had to do was build PWAs instead of native apps and instead all we did was build PWAs into bad browser wrappers.

cosmic_cheese 37 minutes ago | parent [-]

I don’t see PWAs becoming dominant so long as web development stubbornly retains its highly atomized “bring your own everything” philosophy. At the very minimum, there needs to exists a community-accepted web UI framework with a similar level of “batteries included”-ness in terms of scope and depth as that of SwiftUI/Compose, or preferably that of UIKit.

The existence of such a framework would make the various tradeoffs with going web-only sting less and make that the advantageous route, not just the cost-cutting route that it’s seen as now (and why those bad browser wrappers continue to proliferate).

StrLght 3 hours ago | parent | prev [-]

AOSP is Linux.

If by "mainstream" Linux you mean something like postmarketOS, I'd suggest you look up reviews or give it a try yourself. A few months ago, people were reporting a hard time placing a call, taking a photo, etc.