‹ BackHN Continuity

Thread

There's a high chance of devices being sold with GrapheneOS preinstalled in 2027

322 points · 144 comments · Cider9986

  1. codedokode · · focus · HN ↗
    The problem with those free OS is that they usually work on top models which cost like 4 ordinary smartphones. It is experimental software that doesn't work perfectly, and it makes no sense to pay that much for it. So with high prices they are push away potential users.

    Also, I would like no DRM, no serial id, no support for device verification, no trusted environments, re-programmable IMEI, no locked bootloaders, no proprietary code and no telemetry in any form or shape.

    1. nunobrito · · focus · HN ↗
      This android distribution is very suspicious because of a lot of bad architectural decisions (that is one of them) and their famous refusal to disclose funding sources which go beyond common logic for open source projects.

      There are other Android distributions that run on practically any Android phone you have, look for LineageOS. Even your phone is not explicitly listed as supported, using Claude is easy nowadays to adjust the distro to run on your phone perfectly.

      1. pona-a · · focus · HN ↗
        Utter nonsense. GrapheneOS relies on explicit hardware features like MTE, TPM, and secure boot, for its threat model. Most phones don't even have that hardware, fewer still publish enough info to use it (see Samsung). You can debate if GOS is necessary for your personal needs, but the reason they are so picky is they don't want people assuming Graphene security on subpar ports.
        1. nunobrito · · focus · HN ↗
          Excuses. None of that is a reason to force users into high-profile hardware that is not audited and makes anyone buying them an automatic Person Of Interest.

          Furthermore, sound cryptography isn't dependending on specific hardware to function, with that kind of reasoning we'd never get encrypted communications anywhere. So stop inventing excuses and for once in life look deep into how they are financed, which apparently is OK to be as opaque as possible as to whom is paying them so much money.

          1. pona-a · · focus · HN ↗
            GrapheneOS is not a cryptography project, like a secure messenger would be. It's goal is practical security, which does depend on practical considerations: without MTE, similar memory security would cost an unreasonable performance penalty, without TPM conventional authentication methods like PIN-code and fingerprint would be vulnerable to bruteforce, without secure boot users would not be able to verify if their phone was physically tampered with in a brief window they were away from it... And if you have closed-source radio chips running their own untrusted software loaded over the air, integrated in such a way they can independently wiretap you, like most phones have, you'd already failed at protecting the user before you start.

            Furthermore, Android's ecosystem is structured in a way even the most basic software security concerns, like not running a comically out of date kernel, depend on the vendor's blessing, and sadly most manufacturers, including very desirable ones like Fairphone, hadn't been keeping up with such duties. Porting new kernels to old hardware is an extremely inefficient time-consuming endeavor that will take up most of volunteer time to non-satisfactory results; I can testify to that as a former member of the Ubuntu Touch project, and our standards of security were comically lax.

            Again, you CAN lower your standards of security and go for the lesser evil: many people run Lineage or Ubuntu Touch despite known gaps in their security models. But to make that choice, you have to be honest about what you're compromising. If you shut your eyes and plug your ears pretending everything is fine, you'll end up with someone killed because they listened to your uncritical advise.

            Also, I struggle to see how it's GrapheneOS's fault choosing the most secure hardware on the consumer market because it might be deemed suspicious to own it. GOS could have chosen the most popular budget Samsung (ignoring the aforementioned security issues) and it would have the same effect. Besides Pixels aren't an obscure unusual hackerphone made in small quantities, shipped from out of the country; it's among the most popular phone brands, advertised from huge billboards I pass on my bus route to university. If they chose something like the PinePhone like Genode, this point would be somewhat defensible.

            Finally, what's up with the repeated conspiratorial insinuations about financing? I admit I hadn't looked deeply into this question, even as a one-time small donor, but what are you expecting to find? Is it serious concern about the financial health of a project, or an attempt to manufacture a hysteria around some controversial donor, similar to the Tor Project?

            1. nunobrito · · focus · HN ↗
              You can downvote my posts as much as you want with your cronies.

              It won't change reality, doesn't matter how many paragraphs you write. The fact is that all that security is useless when using hardware that is compromised from the start. And I will repeat this again: any NSA supplier does bug their hardware and they do this for decades until finally admitting, just need to take a look on the NSA museum.

              Stop promoting suspiciously funded Android distributions that run on even more suspicious hardware by groups that routinely promote state-sponsored tools on their social media.

              1. Dezvous · · focus · HN ↗
                Source: trust me bro
    2. ponector · · focus · HN ↗
      You can buy new Pixel 7 quite cheap and install grapheneOS there.
      1. [deleted] · · focus · HN ↗

        [deleted]

Open on Hacker News to reply ↗

Unofficial Hacker News client; not affiliated with Y Combinator.