‹ BackHN Continuity

Thread

Android 17 is the first since 3.x to add new APIs without releasing to the AOSP

1180 points · 723 comments · theanonymousone

  1. ahmd-sh · · focus · HN ↗
    i despise where Google is going with this. it's a duopoly in the smartphone OS space and we need (for lack of a better analogy, spare the technicals) open-source distros like we have with Linux on desktop.

    Graphene is reaching that status for me every day and i'm looking forward to switching to it as my daily driver.

    1. pojntfx · · focus · HN ↗
      GrapheneOS is pretty neat, <a href="https:&#x2F;&#x2F;postmarketos.org&#x2F;" rel="nofollow">https:&#x2F;&#x2F;postmarketos.org&#x2F; is also pretty damn polished out of the box these days. I&#x27;d argue the &quot;mobile desktop Linux systems&quot; are actually a bit more polished than Graphene, esp. when it comes to default apps (no AOSP abandonware dialer, contacts etc. apps to fight with, it&#x27;s all just maintained, responsive GNOME&#x2F;KDE apps)
      1. spijdar · · focus · HN ↗
        I want to believe this, but it&#x27;s hard for me to take this at face value. It&#x27;s been about 4 years since I&#x27;ve run pmOS, so my experience IS very out of date, but I also have a hard time believing that the experience has radically changed in the meantime.

        The short is that yes the GNOME&#x2F;KDE apps do often look more impressive, but they suffer the same sort of malaise which seems to have infected Linux desktops sometime since Eternal September, and between the sporadic crashing and &quot;this doesn&#x27;t feel right&quot;, it&#x27;s really hard for me to accept &quot;It&#x27;s more polished than AOSP!&quot;.

        pmOS&#x27;s installation page opening with a warning:

           Make sure you read state of postmarketOS before installing postmarketOS. 
        
        Which leads to a page that opens with:

          The goal is to make postmarketOS usable for everyone, but we are not there yet. Usability and most importantly stability issues need to be worked out first. If you are looking for an OS that is as usable as iOS or Android, this project is currently not for you.
        
        Does not do a lot to dissuade my skepticism. I know you said the apps specifically, but even there, it&#x27;s like... I dunno.
        1. grapheneos · · focus · HN ↗
          GrapheneOS provides drastically better usability, robustness, overall functional and app compatibility. Privacy and security are also drastically better in AOSP and especially GrapheneOS than that desktop Linux software stack ported to mobile.

          All of the default apps in GrapheneOS are being rapidly overhauled or replaced. It wasn&#x27;t a priority due to the incredibly good open source app ecosystem with many existing alternatives available. There isn&#x27;t a similarly large and high quality open source mobile app ecosystem available for what&#x27;s being promoted.

      2. cobertos · · focus · HN ↗
        I tried getting it to run on a Pixel 3a and struggled for hours, eventually gave up (albeit I tried running it with Wayland and Niri which seems less tried-and-true).
        1. brnt · · focus · HN ↗
          I recently installed pmos on two 3a&#x27;s and it was as simple as a Lineage image. Works well too!
        2. grapheneos · · focus · HN ↗
          GrapheneOS provides drastically better usability, robustness, overall functional and app compatibility. Privacy and security are also drastically better in AOSP and especially GrapheneOS than that desktop Linux software stack ported to mobile.

          All of the default apps in GrapheneOS are being rapidly overhauled or replaced. It wasn&#x27;t a priority due to the incredibly good open source app ecosystem with many existing alternatives available. There isn&#x27;t a similarly large and high quality open source mobile app ecosystem available for what&#x27;s being promoted.

          Pixel 3a will lack firmware updates regardless of what you put on it. Having serious unpatched vulnerabilities for radios and other firmware is considered acceptable for desktop operating systems but definitely not by us.

      3. MrDrMcCoy · · focus · HN ↗
        PMOS doesn&#x27;t run with full support and performance on any decent hardware. Would love to be proven wrong.
        1. grapheneos · · focus · HN ↗
          GrapheneOS provides drastically better usability, robustness, overall functional and app compatibility. Privacy and security are also drastically better in AOSP and especially GrapheneOS than that desktop Linux software stack ported to mobile.

          All of the default apps in GrapheneOS are being rapidly overhauled or replaced. It wasn&#x27;t a priority due to the incredibly good open source app ecosystem with many existing alternatives available. There isn&#x27;t a similarly large and high quality open source mobile app ecosystem available for what&#x27;s being promoted.

      4. fungi · · focus · HN ↗
        2nd vote for postmarket. have put it on an old tablet i pulled out of ewaste and it is excellent.

        there is clearly no future for android for anyone wanting an open and spyware free platform. its time to invest out efforts elsewhere.

        1. grapheneos · · focus · HN ↗
          GrapheneOS provides drastically better usability, robustness, overall functional and app compatibility. Privacy and security are also drastically better in AOSP and especially GrapheneOS than that desktop Linux software stack ported to mobile.

          All of the default apps in GrapheneOS are being rapidly overhauled or replaced. It wasn&#x27;t a priority due to the incredibly good open source app ecosystem with many existing alternatives available. There isn&#x27;t a similarly large and high quality open source mobile app ecosystem available for what&#x27;s being promoted.

      5. grapheneos · · focus · HN ↗
        GrapheneOS provides drastically better usability, robustness, overall functional and app compatibility. Privacy and security are also drastically better in AOSP and especially GrapheneOS than that desktop Linux software stack ported to mobile.

        All of the default apps in GrapheneOS are being rapidly overhauled or replaced. It wasn&#x27;t a priority due to the incredibly good open source app ecosystem with many existing alternatives available. There isn&#x27;t a similarly high quality open source mobile app ecosystem available there.

        1. NetMageSCW · · focus · HN ↗
          “rapidly” - how long has it been?
          1. grapheneos · · focus · HN ↗
            We hired 3 experienced app developers a few months ago. That&#x27;s now our app development team working on overhauling these apps. They&#x27;ve already replaced the entire Messaging app user interface with a new modern Compose UI. Messaging v13 is currently in the Alpha channel and v14 is on the way with a bunch of additional fixes needed for it to reach Beta and Stable. Multiple other apps including Contacts are well into the same overhaul process.
    2. kenhwang · · focus · HN ↗
      I just wish Graphene had better support for non-Google hardware.
      1. armadyl · · focus · HN ↗
        More like OEMs need to take security more seriously and add in the capable hardware and commit to firmware updates long term.
        1. dessimus · · focus · HN ↗
          Unless there is a real market advantage to it, they won&#x27;t. Consumers prove over and over again they are willing to trade security to save a few dollars. Furthermore, why commit to providing hardware and software support for a device to last 5+ years, when ~25% of Americans report damaging their device each year[0]. Most of a device&#x27;s population will have been replaced in 3 years.

          [0]: <a href="https:&#x2F;&#x2F;www.claimsjournal.com&#x2F;news&#x2F;national&#x2F;2024&#x2F;03&#x2F;15&#x2F;322486.htm" rel="nofollow">https:&#x2F;&#x2F;www.claimsjournal.com&#x2F;news&#x2F;national&#x2F;2024&#x2F;03&#x2F;15&#x2F;32248...

          1. armadyl · · focus · HN ↗
            Yeah unfortunately this is the case. Privacy and security in general are things most average consumers don’t necessarily care for, and especially don’t care for when it provides inconveniences. Even in more tech enthusiast crowds you see this reflected most obviously in people wanting to use Firefox over any Chromium variant of a browser.

            Not to mention to reach GOS’ requirements the cost of the phone would have to significantly increase which I imagine only hurts Android phones even more for no real gain since GOS users are minuscule overall.

            And the long term support is definitely not the norm yeah. It’s pretty much just Apple and Google doing it for their own devices. Motorola will be a newcomer to this concept with GOS. But we can only wait and see if they actually stick to it, given their track record prior to the collaboration.

            Google probably got away with it cause they made the chips and security chips themselves. I read something like Tensor costing $70 vs. a Qualcomm chip with MTE costing $250.

            But even with of all this, it wouldn’t make sense for GOS to spend it’s limited resources developing for a less secure platform when appropriate target devices exist (they mentioned something to this effect a few days ago on reddit too): <a href="https:&#x2F;&#x2F;www.reddit.com&#x2F;r&#x2F;GrapheneOS&#x2F;comments&#x2F;1wifsiq&#x2F;comment&#x2F;paac5gz&#x2F;" rel="nofollow">https:&#x2F;&#x2F;www.reddit.com&#x2F;r&#x2F;GrapheneOS&#x2F;comments&#x2F;1wifsiq&#x2F;comment...

      2. vkaku · · focus · HN ↗
        Those Razr phone updates need to start landing sooner ....
      3. subscribed · · focus · HN ↗
        They can&#x27;t due to the shortcomings of the hardware (why develop a hardened os to the grossly insecure hardware) or the vendor (no&#x2F;slow updates, etc).

        Anyone is free to fork, add the desired hardware support and flash.

        (that&#x27;s aside of some Moto flagships in 2027)

        1. tcfhgj · · focus · HN ↗
          they can, but don&#x27;t want to
          1. subscribed · · focus · HN ↗
            OK, I&#x27;m confused, explain how they can deliver comparable security on a hardware that does not offer the same capabilities, from a vendor who doesn&#x27;t provide patches.

            You say they can. How?

            1. tredre3 · · focus · HN ↗
              The hardware capability that GrapheneOS loves to use as a shield to deny support for other devices is the ability to use custom AVB keys. Without custom keys you can&#x27;t relock the bootloader after installing a custom OS on most phones. The consequences of having an unlocked bootloader are that you are susceptible to an evil maid attack.

              This is a real threat, but the reality is that the average person is more likely to be hacked&#x2F;spied on from the software side, which Graphene would protect you from as effectively as it does on Pixel.

              1. subscribed · · focus · HN ↗
                So you&#x27;re saying that being unable to prove the provenance of the image (whether it&#x27;s original or not), becoming immediately exposed to downgrade attack, to someone injecting malware to &#x2F;sys and you being unable to detect it.... That&#x27;s not a big deal?

                :)

                Well, go for it, fork and &quot;provide support&quot; to the hardware hostile to non-stock OS, be a hero :)

                1. tcfhgj · · focus · HN ↗
                  hostile to non-tock OS - where are you getting this from?
                  1. subscribed · · focus · HN ↗
                    If the bootloader cannot be unlocked, relocked, or doesn&#x27;t provide timely updates to firmware&#x2F;hardware, it&#x27;s hostile.

                    The rest is not (might be lazy, insecure or just silly but not hostile)

                    It&#x27;s surprising some vendors still don&#x27;t support unlocking and&#x2F;or relocking.

                    1. tcfhgj · · focus · HN ↗
                      smartphones aside pixel like Fairphone do explicitly allow alternative OS, definitely cannot pretend they are hostile
                      1. subscribed · · focus · HN ↗
                        Fairphone?

                        Delayed patches (they don&#x27;t keep up with AOSP), missing secure element (makes disk encryption key cracking trivial in comparison).

                        Fairphone 6&#x2F;6+ (the latest), is based on..... It&#x27;s pretty hard to find the Android version it&#x27;s based on... Got it. They ship phones based on Android 16 half of the year after the release of 17 (9 since public beta).

                        Many security patches are NOT backported to 16, which makes Fairphone insecure by design.

                        They allow relocking the bootloader, which is nice, If they also support custom AVB keys, I&#x27;d say this is a fine example of the example of the vendor that is not hostile, just not good enough.

                        I wouldn&#x27;t say they&#x27;re hostile - Samsung is hostile for example.

                        So, what&#x27;s your angle here? Do you want me to go through every vendor you bring up or what?

                        1. tcfhgj · · focus · HN ↗
                          I didn&#x27;t insinuate hostility of every vendor except Google.
                          1. subscribed · · focus · HN ↗
                            You&#x27;re not engaging with my words but you&#x27;re instead twisting them. I&#x27;ll stop wasting my time on you.
                            1. tcfhgj · · focus · HN ↗
                              I am pretty sure I understood quite well.

                              &gt; Well, go for it, fork and &quot;provide support&quot; to the hardware hostile to non-stock OS, be a hero :)

                              1. subscribed · · focus · HN ↗
                                No, you&#x27;re maliciously extending my words about some vendors to all vendors.

                                In the comment about issues with software and hardware, that somehow is being painted as GrapheneOS fault, I mentioned (among other things) hardware hostile to non-stock OS.

                                I didn&#x27;t say it&#x27;s Nothing, I didn&#x27;t name them.

                                You brought them up, so I addressed that, explained why I don&#x27;t consider Nothing hostile but just vulnerable by default and inadequate. I even provided an example of the vendor I actually consider hostile (Samsung).

                                So if you understood quite well, you&#x27;re trolling now and not discussing in the good faith.

                                The alternative is you didn&#x27;t understand and thought I consider ALL vendors as hostile, which is putting claims in my mouth, which would be fine if you asked, but you keep discussing with strawman.

                                So please go bother someone else; this is the second time you&#x27;re doing that and I wasted enough time on that.

              2. skorp01 · · focus · HN ↗
                You have a fundamental misunderstanding of what AVB is used for.

                Fully supporting and using AVB grants protection against persistence of *all* kinds. If an attacker gains privilege escalation through a remote attack, persistence become much easier if the system is not cryptographically verified every time the device boots.

                Keystore and Attestation also rely on the bootloader being locked. If the hardware root of trust reports the device as untrusted, there is a broken chain of trust for biometrics, encrypted app data that uses the hardware keystore, and any form of attestation checks (like AOSP&#x27;s Hardware Attestion API) will report the device as untrusted.

                Going back to the first point, if it is possible to modify the system and gain persistence, there is also the possibility of modifying the kernel, which would allow an attacker to rewrite or patch the kernel, rendering AOSP&#x27;s sandbox useless.

                This would also make it more vulnerable to downgrade attacks because rollback protection is tied to a locked bootloader and AVB.

                This could all be accomplished through remote exploitation. The &quot;software side&quot; you speak of is built atop AVB as a minimum requirement to assure that the software you&#x27;re running is unmodified and intact.

    3. b112 · · focus · HN ↗
      If Google doesn&#x27;t smarten up, it will no longer be in control of Android.

      Oracle was a mighty powerhouse when it bought MySQL, StarOffice, and more. It lost defacto control of all of them, due to its stupidity. In the world of open source, the tighter you hold on, the less likely you&#x27;ll retain control.

      And yet, here we are, with Google playing games.

      Google, a note: there are far more relying upon Android than you, and now there are forced alternative stores in the mix. If Samsung and everyone else said &quot;sorry Google&#x27;, or even a large majority, you&#x27;re out. Gone. Nada.

      They can now fork, and force old Android to have their new fancy pants &#x27;Play&#x27; store too.

      Google is also getting more and more pushy with Chrome. What if everyone depending upon that backend, shrugs and says &quot;Sorry Google, we&#x27;re hard-forking Chrome and we&#x27;ll all maintain it&quot;.

      1. anonzzzies · · focus · HN ↗
        &gt; Oracle was a mighty powerhouse

        It definitly still is. We run Postgres when we host our banking &#x2F; financial stuff, but when we talk with banks and say that, they demand Oracle not that &#x27;open source amateur stuff&#x27;. We have a version of our software for Oracle (and MSSQL) as well so no biggy, but still, we always try if we know it&#x27;s not a complete immediate kill (which it will be if we put it in our documentation as only option). Oracle is still everywhere at the big guys.

        1. mrlonglong · · focus · HN ↗
          Are they still forbidding benchmarking the Oracle database in their T&amp;Cs? I laugh. Such litigious losers.

          Postgres ftw. Long may it eat their lunch.

        2. LooseMarmoset · · focus · HN ↗
          as someone who is associated with “the big guys”, I can tell you this is changing.

          Our Oracle license licensing went up so dramatically that the team I work with is moving some very large databases to postgres from Oracle because it doesn’t make financial sense anymore.

          now, if we could only stop eating at the trough of Broadcom…

          1. anonzzzies · · focus · HN ↗
            I hope so, I see some changes; far less than many seem to think here though.
        3. cyberax · · focus · HN ↗
          I&#x27;m advising a startup doing software for banks, and the overall attitude of their clients is: &quot;We want to get away from the #&amp;I$*@&amp;^#$ Oracle, but we&#x27;re stuck for now&quot;.

          Oracle used to be a must-have because it was one of the few products that could handle transactions on a scale of a bank, with all the requirements for backups, redundancy, etc.

          A fun anecdote. Back in 2000, I was present at negotiations (as a note-taker) where database vendors were bidding for a project for a factory control system. Vendors submitted benchmark results for various DB sizes up to 40Gb, and Oracle&#x27;s rep hautingly said something like: &quot;Our minimal size for benchmarks is 80Gb, so here are our results for that size&quot;.

          And this was a _lot_ for that time. Now? It&#x27;s so ridiculously tiny that you can host it on a smartwatch. So why would you pay Oracle?

          1. anonzzzies · · focus · HN ↗
            Agreed, I had the same talks around 2000 but at the time it was still very much mssql&#x2F;db2&#x2F;oracle for &#x27;real companies&#x27;. Yet i&#x27;m still surprised how much pushback we get, especially in Asian countries (India) but we do get it, a lot. And we have conversations with financial partners in the US as they advice our VCs; those calls go the same way &#x27;ah, you are using that hipster open source stuff, yeah we don&#x27;t do that here&#x27;.
            1. cyberax · · focus · HN ↗
              Hint: a lot of time, the real answer is &quot;kickbacks&quot;. Find a commercial Postgres provider (EnterpriseDB) and partner with them.
      2. linuxftw · · focus · HN ↗
        Google&#x27;s Android customers are phone OEMs. The major ones seem to like how things are going. Until Samsung and whomever start the OpenHandset Foundation or some such and fork Android, there&#x27;s never going to be the Mariadb of Android.
      3. tredre3 · · focus · HN ↗
        &gt; it will no longer be in control of Android

        Who will step up to maintain it? Keep in mind that it has to be somebody that every other OEM trust. In other words it would likely have to be an alliance of manufacturers. And they&#x27;d inevitably treat OEMs outside the alliance poorly and we&#x27;d be back to the current situation, but worse.

      4. murderfs · · focus · HN ↗
        &gt; If Samsung and everyone else said &quot;sorry Google&#x27;, or even a large majority, you&#x27;re out. Gone. Nada.

        The OEMs are incapable of writing a competent operating system, and don&#x27;t particularly care to.

        &gt; Google is also getting more and more pushy with Chrome. What if everyone depending upon that backend, shrugs and says &quot;Sorry Google, we&#x27;re hard-forking Chrome and we&#x27;ll all maintain it&quot;.

        With what maintainers?

        <a href="https:&#x2F;&#x2F;chrome-commit-tracker.arthursonzogni.com&#x2F;organizations&#x2F;commits?repositories=blink,chromium,v8&amp;organizations=all&amp;grouping=quarterly&amp;colors=organizations&amp;kind=both&amp;metric=commit&amp;chart=line&amp;dates=2016-01-02,2026-09-18" rel="nofollow">https:&#x2F;&#x2F;chrome-commit-tracker.arthursonzogni.com&#x2F;organizatio...

      5. wvenable · · focus · HN ↗
        I don&#x27;t think so. Google&#x27;s customers are phone OEMs and as long as they are happy, things will continue as is. The precedents here are Microsoft with Windows and maybe Apple with iOS.

        Anything Oracle doesn&#x27;t have much relevance. They were not really interested in growing any marketshare of those products for anyone.

      6. qlte · · focus · HN ↗
        Google and Samsung have a closer relationship than ever these days, with cross-branded Google features even featured in advertisements for the last couple Galaxy models which would have been unthinkable back in 2012 or so.

        They have their private own agreements with Google to secure whatever access they need to maintain their OneUI fork and are not the one making any public complaints. Samsung did have a love&#x2F;hate relationship with Google that was openly simmering with resentment during the early years of Android but those days are long past.

        Samsung already includes their own Galaxy store alongside the Play Store on all their devices, and have for 10+ years. But during that time have actually moved the opposite direction from your hypothetical fork scenario and both companies clearly view their current relationship as mutually beneficial.

        Even though GrapheneOS and Samsung both maintain their own Android fork their views on AOSP&#x2F;Google are not aligned.

      7. surajrmal · · focus · HN ↗
        The scale of engineering to compete with Android is an order of magnitude or two larger than that necessary to compete with those other products you mentioned. Not to mention the challenges of getting the developer market to follow you to your fork. It seems like any phone vendor even capable of giving it a go is okay with the current arrangement. Chinese firms can definitely do it and I guess Huawei has, but that&#x27;s not entirely relevant to Western markets.
    4. austinthetaco · · focus · HN ↗
      i so desperately wish we were still in the days of manufacturers making their own OS. It&#x27;s why I moved to iphone: when the hardware company makes the software and vice-versa the integration is much better and less error-prone&#x2F;bloated. It never made sense to me for android to be shoehorned into thousands of devices, instead of a fork being made and for thorough OS rework to happen to support the device.
      1. qlte · · focus · HN ↗
        That is definitely not how I remember the feature phone era. The OS was an afterthought seemingly whipped together a couple months before the device hit the shelves and nothing was ever consistent even across recent models from the same manufacturer.

        Back then the primary goal was checkboxes for the carrier to advertise and UI&#x2F;UX was a distant second priority at most. Sometimes an advertised feature would just flat out be unusable (such as MP3 players), but good luck waiting for any kind of update because by then those developers had already been reassigned to the next handset model they promised to carriers.

        Also, Samsung extensively customizes their OneUI fork of Android, with its own UI look and feel that evolves independently from Android based on their own priorities. Plus Samsung&#x27;s Android maintains hundreds of features that either don&#x27;t exist at all on AOSP&#x2F;Pixels or later get folded into mainline Android.

        (Including the little known killer app suite &quot;Good Lock&quot; available on Samsung&#x27;s Galaxy store which gives power users an almost obscene amount of additional niche options and customizations that would give UX minimalist designers at Google or Apple a heart attack)

        But despite how different Pixel vs. OneUI look and feel, I can use the exact same apps whether on a Pixel or Galaxy or $100 trash phone. Interoperability is very easy to take for granted and Android app ecosystem is (still) paradise compared to the lowest common denominator J2ME &quot;app&quot; era of the 2000s.

    5. aftbit · · focus · HN ↗
      Graphene has been my daily driver for the past year or so. The only thing I miss is the ability to do contactless payments. Otherwise, it&#x27;s been awesome. I don&#x27;t run any games nor do I care about any of the AI features. YMMV.
      1. dlahoda · · focus · HN ↗
        for some people contactless payments are essential for their lifes
        1. eppp · · focus · HN ↗
          That seems a little excessive.
        2. aftbit · · focus · HN ↗
          Those people will never be able to use Graphene or any other privacy-preserving smartphone. They&#x27;ll be stuck with Apple or approved Android. At least that&#x27;s how it looks today.

          Or they can get a Garmin watch with contactless payment, or do what I do - stick a credit card in their phone case.

      2. edent · · focus · HN ↗
        Contactless payments do work on Graphene - but only with the Curve app. It also requires the card-holder to be from the UK or EU.
        1. aftbit · · focus · HN ↗
          Alas I&#x27;m from the US so that doesn&#x27;t help me.
        2. velocity3230 · · focus · HN ↗
          Not &quot;only&quot; the Curve app. Some banks provide NFC payments directly from their own app.
    6. [deleted] · · focus · HN ↗

      [deleted]

Open on Hacker News to reply ↗

Unofficial Hacker News client; not affiliated with Y Combinator.