5 ms·
I use grapheneOS, it's the reason I bought a pixel but not for nefarious reasons but rather I don't like how much control Google has (it's ironic I had to buy a
by MurkyLabs 1y ago
I use grapheneOS, it's the reason I bought a pixel but not for nefarious reasons but rather I don't like how much control Google has (it's ironic I had to buy a google phone) on android phones even from other manufacturers and the targeted marketing and information that I would be giving out. I also don't like that Android implimented the feature where you couldn't access the Android>Data folder for 'security reasons' and have to plug it into a computer to access any of those sub folders, it's my phone let me do what I want with it. Graphene lets me access any of those folders without issue
- nicman23 1y agothe fact that they refuse to consider other phones ie fairphone or nothing phones that have the bootloader relockable is the reason that i do not use graphene. it seems like a great os but i am not giving google money to get away from google.
- dmix 1y agoYou're welcome to donate money to them so they can hire developers who can support multiple phones.
- nicman23 1y agothey flat out said they would not
- subscribed 1y agoThey _can_ if it makes sense: https://grapheneos.org/faq#future-devices https://grapheneos.org/faq#future-devices
- StrLght 1y agoThey don't refuse other manufacturers, it's quite the opposite -- GrapheneOS provides list of requirements for future device support. AFAIK Fairphone and Nothing don't fit more than a few requirements from this list. https://grapheneos.org/faq#future-devices https://grapheneos.org/faq#future-devices
- subscribed 1y agoFairphone is dangerously insecure. Nothing phone is not much better. It's not only the design of the hardware, but also patches for vulnerabilities and delivering updates for several years. You're suggesting it's ideological (which is completely untrue), while the fact is: pixels are at the very moment the only Android hardware secure enough to even care about hardening: https://grapheneos.org/faq#future-devices https://grapheneos.org/faq#future-devices (there's little sense in securing the OS if the hardware doesn't allow disconnecting the USB or there is no secure element throttling PIN attempts, right?)
- evrimoztamur 1y agoSource on Fairphone being insecure? I'm moving to Android app development and considered it for repairability/mission factors.
- subscribed 1y agoFrom what I found they're brilliant on repairability, but not so much on security, which is a bummer :( Couple of pieces on hardware: - Fairphone does not include a secure element making brute-forcing PIN trivial - Fairphone 4 used TEST KEYS for verified boot: https://forum.fairphone.com/t/bootloader-avb-keys-used-in-roms-for-fairphone-3-4/83448/4 https://forum.fairphone.com/t/bootloader-avb-keys-used-in-ro... The above alone shows insecurity by design. I cannot find any of Fairphone technical documentation that would provide details on their implementation of the TEE/HSM. As of now I believe it's only Pixel's Titan and Samsung's KNOX that provide a discrete secure element on Android devices. Android project recommends secure element to process sensitive data: https://source.android.com/docs/security/best-practices/hardware https://source.android.com/docs/security/best-practices/hard... What it's supposed to provide: https://developer.android.com/privacy-and-security/keystore https://developer.android.com/privacy-and-security/keystore On vendor: Drivers, firmware patches, OS upgrades are a necessity, not an option: most security and privacy updates are not backported. Vendor can't just wait for AOSP to deliver all the patches. Vendor must show a track record providing updates to their hardware - After a lengthy two-year delay, the phone got a taste of Android 12 in February 2023, with Android 13 arriving relatively quickly in October 2023. For Android 14, Fairphone promised to roll out the update in H2, 2024, almost a year after Google released it. Now, with less than two months left in the year, the company is postponing the update's release to 2025. -- https://www.androidpolice.com/fairphone-4-long-delayed-android-14-update-further-delayed/ https://www.androidpolice.com/fairphone-4-long-delayed-andro... - their Security Bulletin patches are consistently 1-2 months behind - Fairphone 5 is still on Android 14 (since Jul 2024). Android 15 has been released in September 2024. Year and a half later AOSP is on Android 16. - Fairphone 6 is still on Android 15 - Fairphone 5 and 6 latest security patches are from June 2025: https://support.fairphone.com/hc/en-us/articles/24463713641234-The-Fairphone-Gen-6-Release-Notes https://support.fairphone.com/hc/en-us/articles/244637136412... For comparison GrapheneOS had eight releases in July alone (GrapheneOS had a full A16 release on 30th of June for all supported devices). Security patches are usually released within one-three days (or earlier, from the tree, without waiting for being published in the bundle) GOS Release for Pixel 9 was ready three days after the device launch. Exploitability matrix as per Cellebrite: https://discuss.privacyguides.net/t/updated-cellebrite-iphone-support-matrix-leak/19578/25 https://discuss.privacyguides.net/t/updated-cellebrite-iphon... That supports the claim the hardware + OS holds.
- subscribed 1y agoOh, I forgot to add and can't edit my comment, so: they are talking with another OEM about the potential alternative hardware for the future GOS. I hope it's something good. But in reality it's probably Samsung which is the only other vendor bothered enough to add a basic secure element. Maybe they will upgrade it?
- umbra07 1y agoDo you have a source for this?
- subscribed 1y agoSamsung devices have basically everything except hardware memory tagging, afair (which is allegedly being added now?), and it looks like it's possible to both OEM unlock and relock the bootloader? Also looks like they improved security even further, hopefully exceeding Pixels: https://semiconductor.samsung.com/news-events/news/best-in-class-data-security-chip-solution-for-mobile/ https://semiconductor.samsung.com/news-events/news/best-in-c... In general I'm quite sure dev any hardware that meets these requirements would be considered: https://grapheneos.org/faq#future-devices https://grapheneos.org/faq#future-devices Re: OEM: https://grapheneos.social/@GrapheneOS/114722432094158776 https://grapheneos.social/@GrapheneOS/114722432094158776 > We have talks with a large Android OEM ongoing and they're doing initial work towards supporting GrapheneOS. We hope there will be another device we can support in 2026 or 2027 based on this. Qualcomm releasing MTE support this year is key and appears to be happening. https://grapheneos.social/@GrapheneOS/114729018035689722 https://grapheneos.social/@GrapheneOS/114729018035689722 > The initial devices built for us by an OEM are going to be their regular devices improved to meet our security and support time requirements. We aren't going to have much influence over the initial hardware. If GrapheneOS on these devices is highly successful, then we can make the business case that it makes sense to have custom hardware and firmware beyond meeting our minimum requirements. Our minimum requirements cannot require more than what we have on current devices. A.K.A: the minimum requirements are current requirements (currenly only met by Pixels) Also older one: https://xcancel.com/GrapheneOS/status/1490518600339308544?cxt=HHwWgICyhaOxsa8pAAAA https://xcancel.com/GrapheneOS/status/1490518600339308544?cx... I, for one, am excited. I like my Pixels because they can run GOS (and my Pixel 9 Pro XL has a great camera), but I'd love to have a choice.
- christophilus 1y agoSwappa is your friend. A used pixel doesn’t directly give Google money.
- nicman23 1y agothat is true but i know how people treat their phones ..
- theandrewbailey 1y ago> I don't like how much control Google has (it's ironic I had to buy a google phone) on android phones even from other manufacturers and the targeted marketing and information that I would be giving out. To a normie non-tech person, buying a several hundred dollar Google phone, only to delete Google from it sounds stupid, like you've set your money on fire. Yes, I recently bought a Pixel and immediately installed GrapheneOS.
- bdqioxnfkeof 1y agoIt's crazy that you care about privacy and buy a Google phone.
- microtonal 1y agoNot sure what you are saying. In the Android space, only Pixels have a good secure element and Samsung has an acceptable secure element. Of those only Pixel allows unlocking the phone without blowing an eFuse. So, Pixel is currently the only phone that allows installing an alternative OS and provides a secure element. Most phones without a separate secure element do not protect against brute-force PIN attacks, etc. As is often said, the most secure phones are: Pixel with GrapheneOS > iPhone >> Pixel with PixelOS >>>>>> anything else