39 comments

[ 1.4 ms ] story [ 65.2 ms ] thread
> may i ask how you obtain the source? Are you registered as an OEM at Google?

Same question, how does Graphene get patches?

https://tbot.substack.com/p/grapheneos-new-oem-partnership

> GrapheneOS has officially confirmed a major new hardware partnership—one that marks the end of its long-standing Pixel exclusivity. According to the team, work with a major Android OEM began in June and is now moving toward the development of a next-generation smartphone built to meet GrapheneOS’ strict privacy and security standards.

Why was it that in the early PC days, IBM was unable to keep a lid on 'IBM compatible', allowing for the PC interoperability explosion, yet today, almost every phone has closed drivers, closed and locked bootloaders, and almost complete corporate control over our devices? Why are there not yet a plethora of phones on the market that allow anyone to install their OS of choice?
Well, back in the day many of the people making buying decisions were tech enthusiasts who like the idea of upgradeability, etc. Computers were quite expensive, and people didn't want to waste money on a box which can only do one thing.

Besides that, "app store" was just not feasible with tech of the day.

When vast majority of customers do not care, you can ship a locked down device.

You can buy a hackable phone, but it's a niche

Obviously this situation can't go on.

If neither of the two major players can make an open, secure, _simple_, easy-to-understand, bloat-free OS, then we somehow need another player.

Presently (and I confess, my bias to seek non-state solutions may show here), it seems that a non-trivial part of the duopoly stems from regulatory capture insofar as the duopoly isn't merely software, but extends all the way to TSMC and Qualcomm, whose operations seem to be completely subject to state dictates, both economic/regulatory and of the darker surveillance/statecraft variety (and of those, presumably some are classified).

I'm reminded of the server market 20ish years ago, where, although there were more than two players, the array of simple, flexible linux distros that are dominant today were somewhere between poorly documented and unavailable. I remember my university still running windows servers in ~2008 or so.

What do we need to do to achieve the same evolution that the last 2-3 decades of server OS's have seen? Is there presently a mobile linux OS that's worth jumping on? Is there simple hardware to go with it?

Graphene has really caught my eye in the last several months, but unfortunately I couldn't find a good deal for Pixel phones (>128GB storage), used or new. That's the biggest bottleneck for adoption it seems. I just finally switched from an S10E to a S25Ultra (black friday deal brought down to $820), but not being able to use Graphene in the future hurts a bit for sure.
Samsung Androids are not safe? Big surprise there! /s
GrapheneOS goes even further by allowing you to opt in to pre-embargo security releases, bypassing the vulnerable window between vendor disclosure and OEM patches. Awesome!
... maybe, but it also drops support pretty fast, and not supported on most phones :-(
You can tell it's truly secure and private because the Cellebrite leak says they can't break it (one of very few!) and some governments assume you're a drug dealer if you use it. My next phone will run GrapheneOS.
Understaffed gift product wants 1 week cycles.

OEMs want 2-4 month cycles.

This is a perfect representation of the state of the software industry.

The problem with custom android ROM is that the kernel is built with proprietary drivers, and porting them to other custom android is really hard
GrapheneOS doesn't have any proprietary kernel drivers. There aren't any for the supported devices. Firmware and a subset of userspace driver libraries such as the Mali GPU driver library are what's proprietary.
Great, so this means that the only way to get an Android release that's up-to-date on security patches is a binary-only distro - either Google Pixel, or the GrapheneOS preview channel.

Just wonderful. Google should know better than this, shame on the other OEMs that forced this mess.

I notice my battery life is much better switching to graphine from the stock google rom.
So this is interesting, they release the patched binaries several months before anyone else does and several months before the source code of the patches is released?

This implies that anyone can download GrapheneOS firmware images and use binary diffing techniques to find what are still 0-day vulnerabilities on every Android other than GrapheneOS.

Useful! Thank you GrapheneOS developers.

You can extend your thanks to Google, as what you said is also easily done with Google's own updates.
which pixel model is best for grephene? I strongly prefer long battery life.

will other phones be supported? why only pixel?

damn, an upgrade path from my pixel 5.
The GrapheneOS obsession with picking a fight with everyone else is the most unfortunate part of the project.
The attacks on GrapheneOS from Copperhead and their supporters including within other projects were not a fight we picked. You're pushing a false narrative in support of years of libel, bullying and harassment towards us. Your project's team has regularly engaged in very underhanded attacks on ours despite us never doing anything to you. We have archives of it.

Here's an example of what you support by the founder of Murena and /e/ who you support linking to libel and harassment on a neo-nazi conspiracy site (check out the site for yourself):

https://archive.is/SWXPJ https://archive.is/n4yTO

The video that's linked there is an extraordinarily dishonest character assassination video filled with very blatantly false claims. The person who posted the video is unsurprisingly friends with a bunch of neo-nazis. Copperhead failed in their attempt at filing a baseless lawsuit against us and is on track to pay years of our legal fees.

A typical approach you folks take is linking to Kiwi Farms adjacent harassment content based on fabricated stories and spin targeting myself and the rest of our team. One of the two main people orchestrating harassment towards us has an identity verified Kiwi Farms account and was the one who involved them in targeting me (kiwifarms . st/members/larossmann.132201/).

That is also my feeling, at least from a part of the GrapheneOS community. I have seen them despising and bullying /e/OS, Debian, F-Droid, the Linux kernel... Too bad for this project, that is amazing, to have such toxic folks.

Open source communities should help each other, and work together, not fight.

AI can't work if the OS isn't secure... lol... I'm doomed.
I absolutely loved my Moto X with the walnut back. I switched to an iPhone when it stopped getting security patches.

It was built back when Google owned Motorola, before they sold off everything but the patent suite. And was intended to be their flagship phone - which the Pixel later became. Looking at the GrapheneOS FAQ, it doesn't look like I have a prayer of installing it on such an old device as it doesn't have the needed security hardware. Is there a lightweight Android install available?

i like graphite its nice and blcack and conductive
Although I don't use it I will be supporting the project. I'm quite proud of what they've achieved so far.
who is the android oem they are partnering with
Not yet disclosed. We know its a top 10 Android OEM though that cares about security for their future devices!
Is this supposed to be a joke? The best security of GrapheneOS is useless to people who don't own Don't-be-evil-hardware.
It is sadly not a joke. Its sad that OEMs outside Google and Apple currently dont make hardware and firmware with reasonable security.