| ▲ | moonshot5 4 days ago |
| [flagged] |
|
| ▲ | embedding-shape 4 days ago | parent | next [-] |
| > that Graphene seems to want to complain about everything and anything that doesn't fit their niche use case What would you want them to complain about instead? Of course they'll complain about that, just like Googlers will complain about things affecting their stock price, no one is surprised that people care about stuff they're personally involved in, it makes a lot of sense. Now if these complaints weren't accurate, then I'd walk with you and feel a bit more negative with each piece. But the ones I've looked into, have been spot on, so who cares if it's for their specific niche? I expect them to care about their niche, that's why those people all work together in that organization in the first place. |
|
| ▲ | timschmidt 4 days ago | parent | prev | next [-] |
| > As much as it seems beloved here, people that flash custom Android OSs are the very definition of niche users. Hmm... Let's try reframing this: "as much as it seems beloved here, people that install their own operating systems on PCs are the very definition of niche users" I'm absolutely certain that's how IBM felt before the clones. But the ability to install what they wanted on a defacto standard platform is what launched the computing revolution. I think we'd still be living in a sterile monopolistic environment with $10k compilers otherwise. Folks installing their own ROMs on phones are only niche because they've been pushed out at every opportunity using locked bootloaders, embedded security processors, factory installed secret keys, etc. Despite all that, there's still thriving communities developing and using custom ROMs on their phones. That demonstrates more than niche demand. |
| |
| ▲ | yaro330 4 days ago | parent [-] | | > Hmm... Let's try reframing this: "as much as it seems beloved here, people that install their own operating systems on PCs are the very definition of niche users" I mean yeah, 99% of people never installed an OS and never will, what's your point here? | | |
| ▲ | timschmidt 4 days ago | parent [-] | | > 99% of people never installed an OS and never will, what's your point here? That the 1% who do build visicalc, Linux, the internet, Google, and every application and innovation that happens outside the corporate wall. The entire ecosystem everyone else ends up using. And that calling that niche is ridiculous, shortsighted, and shooting oneself as a platform owner in the foot. | | |
| ▲ | yaro330 4 days ago | parent [-] | | What are you talking about? You're making zero sense. I've been in the niche of modifying and installing my own ROMs, then to kernels, and now doing the same things commercially. It is a niche, it always was. There was never a mass community of users, the most installs you used to see on any given AOSP based project is maybe 20-30K for the most popular devices like Redmis, Pocos or Google Nexus phones. It's still a niche, and things that users do and used to do to their phones are fundamentally incompatible with Android's security model. Root access, magisk, xposed, overall zero or near zero security validation from the security perspective on all ROMs but Graphene (maybe some others, I haven't followed the sphere for a while). | | |
| ▲ | timschmidt 4 days ago | parent [-] | | > It is a niche, it always was. Again, only because the platforms are locked down and there is no single standardized target for universally bootable ROMs in the way a Linux ISO can boot on any PC. Kinda sounds like you might be younger and didn't live through the 8bit micro -> PC transition. Standardization of the platform led to a cambrian explosion. https://en.wikipedia.org/wiki/Influence_of_the_IBM_PC_on_the... | | |
| ▲ | yaro330 3 days ago | parent [-] | | > Again, only because the platforms are locked down and there is no single standardized target for universally bootable ROMs in the way a Linux ISO can boot on any PC. Couple of things here. Android was never that open to begin with. There were always (and still going) issues with the kernel sources being withheld indefinitely, AOSP side changes are almost never released at all, iirc only Google released anything. Bootloaders were always an issue, not all manufacturers had unlockable (or easily unlockable) bootloaders. Ironically, Google were always the spearhead of the standartization in the Android world. Project Treble and stuff resulted in the fact that almost any Android device released these days can run a generic Android image, it's not gonna be as functional as the original Android, but it's something. Yes, I am on the younger side, that's why I know how it was in the Android world. Nobody is interested in reinstalling OS-es on their phones because the amount of effort to create an Android ISO that's as usable as what's preinstalled is truly gigantic. Android flavours are heavily customized for the needs of the OEM, and for the hardware that they're gonna run on. It's a niche, always was and always will be. A niche powered by a few large players like LOS or GOS, that actually get paid somehow or heavily work for the idea, and an army of teenage unpaid maintainers, who quit the maintainership as soon as they get a properly paying job that takes most of their time (me). | | |
| ▲ | timschmidt 3 days ago | parent [-] | | > Nobody is interested in reinstalling OS-es on their phones because the amount of effort to create an Android ISO that's as usable as what's preinstalled is truly gigantic. You've restated my thesis. > Yes, I am on the younger side I could tell. | | |
| ▲ | yaro330 3 days ago | parent [-] | | It's pretty clear that you have an extremely limited exposure to the custom Android development space, since you never rebutted any of the points I brought up. Custom android was never easy and never will be. And it's fundamentally incompatible with the concept of having a truly secure env on your device (same as in the PC space, ironically enough). | | |
| ▲ | timschmidt 3 days ago | parent [-] | | Son, I've been building and installing custom roms since the HTC Dream, was involved in OpenMoko, and have owned nearly every open or Linux-running phone of the last 30 years back to the Sharp Zaurus and iPaqs. Your custom rom experience sits wholly within a larger category of computer systems experience about which I've been speaking. The sort of fragmentation you describe is a symptom, not a foregone conclusion. |
|
|
|
|
|
|
|
|
|
| ▲ | edent 4 days ago | parent | prev | next [-] |
| Perhaps they complain because that's literally the only way to get Google to take notice? Let's be real, AOSP doesn't exist any more. Google have closed down nearly everything. All the development happens in private, you've stopped addressing bugs raised by the public, the source of patches are only infrequently released, device trees are gone. Wouldn't you complain? |
| |
| ▲ | microtonal 4 days ago | parent [-] | | All the development happens in private, you've stopped addressing bugs raised by the public, the source of patches are only infrequently released, device trees are gone. To emphasize this point a bit more: only "QPR0" (major release) and QPR3 are released as part of AOSP. QPR1 and QPR3 are not released at all anymore, but contain fixes for vulnerabilities that are not marked high/critical (so don't end up in ASB). It is not clear to me whether OEMs get access to QPR1 and QPR3, but Google are not only witholding features, but also a set of security fixes. Besides that, they are torpedoing other systems through Play Integrity. IMO it would be best if AOSP was spun off from Google into its own org that actually cares about developing an open source system for others (both open source systems like GrapheneOS/Lineage and commercial vendors like Samsung) and that would have an attestation system that is open to vendors that have good device security. |
|
|
| ▲ | striking 4 days ago | parent | prev | next [-] |
| If they're just some "niche use case" then why would Motorola partner with them? The way they see it, > By combining GrapheneOS’s pioneering engineering with Motorola’s decades of security expertise, real‑world user insights, and Lenovo’s ThinkShield solutions, the collaboration will advance a new generation of privacy and security technologies. In the coming months, Motorola and the GrapheneOS Foundation will continue to collaborate on joint research, software enhancements, and new security capabilities, with more details and solutions to roll out as the partnership evolves. https://motorolanews.com/motorola-three-new-b2b-solutions-at... |
| |
| ▲ | bitpush 4 days ago | parent [-] | | [flagged] | | |
| ▲ | mirashii 4 days ago | parent | next [-] | | They’re the second largest manufacturer of Android smartphones in the US, and 10% of the global market. Seems a bit unreasonable to dismiss them out of hand on that basis. | |
| ▲ | striking 4 days ago | parent | prev | next [-] | | I think that's a worthwhile point to consider but it's only relevant if we move the goalposts from "GrapheneOS is only used by Android ROM enthusiasts" to "GrapheneOS is only supported by one small Android phone manufacturer". To be frank, though, I don't see any of this line of reasoning as relevant; it's just appeals to greater authorities on either end. If AOSP is only for manufacturers there's really no reason for it to be open source in the first place. And then folks who care about actually improving security end-to-end outside of whatever's convenient to implement by those beholden to the quarterly profit metrics are up a creek. Personally, if this whole GrapheneOS/Motorola thing doesn't improve the state of the ecosystem I'm going back to Apple or whatever other manufacturer makes it clear they take security seriously. | |
| ▲ | eptcyka 4 days ago | parent | prev [-] | | Neither is google. |
|
|
|
| ▲ | Cider9986 4 days ago | parent | prev | next [-] |
| You might not like their style of speech, at least they care about their users. Maybe Google uses nice flowery language that makes the reader feel nice—IDC—actions speak louder than words. Stock Pixel is an awful experience. So many useless notifications, popups, ads, privacy not by default. Company: "We care about your privacy" meanwhile 1400 corporations they share data with GrapheneOS: "There's zero telemetry in GrapheneOS" The more you read the more you realize they are nearly always correct. |
| |
| ▲ | yaro330 4 days ago | parent | next [-] | | > Stock Pixel is an awful experience. So many useless notifications, popups, ads, privacy not by default. Huh? What pixel are you on? You only get notifications from stuff you install after the initial setup is done. And even then you can outright mute applications, completely. | | |
| ▲ | Cider9986 4 days ago | parent [-] | | I was on stock recent pixel A17 for a few hours before flashing GrapheneOS. They took over the power button for Gemini, there's gemini in Messages, there's 50 apps you don't need. Yeah you can disable notifications but it was constantly giving tips and tricks and other bullshit. The OS feels super bloated compared to GrapheneOS. | | |
| ▲ | yaro330 4 days ago | parent [-] | | I hate the power button change myself, but 1. It was turned into the Assistant button by default for many years now. 2. Can be switched back easily in settings. > there's 50 apps you don't need
Where are you getting your pixels? Mine came with all the essentials, I don't remember disabling anything in particular. No game demos, no preloaded meta cancer, just the normal google suite. > The OS feels super bloated compared to GrapheneOS. When was that ever not the case? When was a stock OS lighter than a custom flavour on any phone? You can't ship Android in the state that custom OS-es do, you won't pass the certification to get Google's goodies like OTA service and preinstalled play store. Don't quite get the Gemini argument either. You're buying a Gemini phone that touts AI everywhere on its promotional page. What do you expect? |
|
| |
| ▲ | gib444 4 days ago | parent | prev [-] | | [flagged] | | |
| ▲ | Cider9986 4 days ago | parent [-] | | > If they happen to overlap, that's a happy coincidence. I can't know what the developers of any OS are actually thinking, but based their actions, GrapheneOS does more for their users than any other OS. Therefore I assume that doing good things for users equals care for users. It's probably stupid to try to guess about care. | | |
|
|
|
| ▲ | Iolaum 4 days ago | parent | prev | next [-] |
| Even in the EU spyware use is prevalent (and i 'd guess everywhere else in the world). There have been many scandals of government authorized commercial spyware been deployed against journalists. Is it really that niche a mobile OS that tries to not be exploitable by them? |
| |
| ▲ | Borealid 4 days ago | parent [-] | | [flagged] | | |
| ▲ | ysnp 4 days ago | parent | next [-] | | GrapheneOS have mentioned wanting to expand the logging/intrusion detection capabilities of their Auditor app but contend with the need to include it as a system app which is against their philosophy (PoLP). It is not accurate to say they don't want to do anything about spyware. They are also completely against Play Integrity as implemented on principle. | |
| ▲ | Iolaum 4 days ago | parent | prev [-] | | Graphene puts a HEAVY emphasis on security. Also your argument about a user inspecting and editing application files feels like a strawman argument. For example many spyware use malicious links to infect the devices, not malicious apps. | | |
| ▲ | Borealid 4 days ago | parent [-] | | [flagged] | | |
| ▲ | Iolaum 4 days ago | parent [-] | | Let's say you are a Graphene OS user. Why are you even using such an app? Also you are misrepresenting the threat model. The problem is not an app deleting it's own legitimate data. P.S. On GrapheneOS you can block apps from getting Internet access to limit their bad ideas. | | |
|
|
|
|
|
| ▲ | WarmWash 4 days ago | parent | prev | next [-] |
| When you are a minority you have to be incredibly loud for any chance to sway things your way. Not saying whether it's a good thing or a bad thing, but just the nature of reality. |
| |
|
| ▲ | drewfax 4 days ago | parent | prev | next [-] |
| So other projects are not supposed to critize Google? Graphene's focus is on security and they complain about lack of security in your products. Seems valid to me. Also security and using non-Google OS are not niche usecases. I'm not sure how you are working on Android, the most popular OS while claiming security is a niche usecase. In fact, I have less confidence in security of your work. |
| |
| ▲ | MostlyStable 4 days ago | parent [-] | | [flagged] | | |
| ▲ | matheusmoreira 4 days ago | parent | next [-] | | [flagged] | | |
| ▲ | eptcyka 4 days ago | parent | next [-] | | I am sympathetic to GrapheneOS, but I have also worked with them and they are not easy to work with. Google is in no way required to take on criticism from OSS community- GPL and MIT do not actually require the rights holder to not be an asshole. In such a social dynamic, one will find greater success using language that appeases instead of repels the asshole. | |
| ▲ | freedomben 4 days ago | parent | prev [-] | | [flagged] | | |
| |
| ▲ | fph 4 days ago | parent | prev [-] | | [flagged] |
|
|
|
| ▲ | certify7128 4 days ago | parent | prev | next [-] |
| Thankfully the project doesn't care about your personal attitude. That "niche use case" literally saves lives in countries where saying the wrong thing can put you to death. Since when is calling something out a rant? |
| |
| ▲ | LMYahooTFY 4 days ago | parent [-] | | [flagged] | | |
| ▲ | rustcleaner 4 days ago | parent [-] | | In a world where economics makes security hardly a secondary concern, a situation exploited by both the intelligence and surveillance broker sectors, dogmatic sanctimony for high security is a feature and not a bug. |
|
|
|
| ▲ | delichon 4 days ago | parent | prev | next [-] |
| This doesn't read as a rant to me, but as calm and factual, regarding a genuine security regression that merits public attention. What is your interest in mischaracterizing it? |
|
| ▲ | ysnp 4 days ago | parent | prev | next [-] |
| Could you please explain why supporting MTE/potentially EMTE in production as a goal represents a niche use case? Isn't mitigating memory corruption issues a mainstream ideal? How else would you propose to do it? |
|
| ▲ | 1shooner 4 days ago | parent | prev | next [-] |
| > people that flash custom Android OSs are the very definition of niche users. This is a mischaracterization. The niche isn't Android hobbyists, it's people with what should be a basic expectation for privacy. I wouldn't flash GOS or any other OS if I could safely avoid it. |
|
| ▲ | matheusmoreira 4 days ago | parent | prev | next [-] |
| They are good enough to have their own Cellebrite column. If they complain about something, you should probably listen. |
|
| ▲ | drnick1 4 days ago | parent | prev | next [-] |
| Maybe if Google did not shove their spyware down people's throats and actually allowed users control of their phones, there wouldn't be a need for projects like Graphene and Lineage. Until then, complaints are more than justified. |
|
| ▲ | stefan_ 4 days ago | parent | prev | next [-] |
| "I don't know anything but I don't like Graphene" Well we know Google isn't enabling MTE, while LLM-enabled exploits are multiplying rapidly. Maybe you need to get back to work? |
|
| ▲ | iamnothere 4 days ago | parent | prev | next [-] |
| Security shouldn’t be a niche use case. There’s a constant trickle of CVEs, and spyware vendors are known to abuse these exploits in their software. All this on devices that are reachable in the US through a text or MMS, sent to an easily located 10 digit number that isn’t easily changed. These are devices that people now use for all kinds of sensitive tasks! Security should be the number one priority, frankly. Graphene has shown that this is possible, and they have tried multiple times to get Google to integrate their work. |
|
| ▲ | Phelinofist 4 days ago | parent | prev | next [-] |
| > I doubt I'd go far out of my way to help them, even if I had exposure to them. Too busy crippling sideloading I guess |
|
| ▲ | rustcleaner 4 days ago | parent | prev | next [-] |
| ... and my opinion becomes more positive with each rant. We'll have to agree to disagree. The only reason I buy Pixels for myself and my family members is because of GrapheneOS, otherwise it would be used out of date hardware for LineageOS or some kind of Linux phone. I am thankful that they are attempting to diversify with Motorola, being entirely Pixel dependent has been a project vulnerability; anytime Google decided to lock down the boot loader, it would have been curtains for the project. |
|
| ▲ | 3 days ago | parent | prev | next [-] |
| [deleted] |
|
| ▲ | amaccuish 4 days ago | parent | prev | next [-] |
| [flagged] |
| |
| ▲ | matheusmoreira 4 days ago | parent [-] | | I've never seen them call it "evil". I've seen them debunk CalyxOS security claims as well as criticism of GrapheneOS, and they usually provide some serious reasoning and technical information when they do it. They know what they're talking about. Don't take it personally. I'm a huge fan of Linux, and GrapheneOS routinely comes here and calls it a huge security liability. And they are right. |
|
|
| ▲ | yaro330 4 days ago | parent | prev | next [-] |
| [flagged] |
| |
| ▲ | preisschild 3 days ago | parent [-] | | Tbf with all the information that has come to light since then Rossmann and FUTO were also not behaving correctly and it was fair from him to deny coming onto their show (where they have also invited fascists before) | | |
|
|
| ▲ | mmooss 4 days ago | parent | prev [-] |
| [flagged] |
| |
| ▲ | microtonal 4 days ago | parent [-] | | I'm not an AOSP engineer, but that was my thought reading GOS's comments: Why be negative toward the people who you want help from? What help though? Google has closed off AOSP and only does source code drops twice a year. Google has embargoed security patches for three months and only provides them to OEMs of Google-certified Android phones, not other AOSP-based projects. Google stopped providing git trees of kernel sources and instead requires projects to submit a request for a Google drive link for each kernel version that takes up to weeks to process. Google is shutting out open Android systems through Play Integrity. Google is not helping anymore, over the last 1-2 years they have tried everything to sabotage AOSP-based projects. The only reason that they are not fully closing AOSP is probably because 1.) they would get in hot water with regulators; and 2.) AOSP will probably get forked. |
|