RU version is available. Content is displayed in original English for accuracy.
Advertisement
Advertisement
⚡ Community Insights
Discussion Sentiment
64% Positive
Analyzed from 4531 words in the discussion.
Trending Topics
#android#phone#apps#linux#google#graphene#don#security#app#grapheneos

Discussion (199 Comments)Read Original on HackerNews
Let this sink in. Google, this small tech company (correct me if I'm wrong), is peddling source code via tarballs on google drive.
Something the head of the Android ecosystem, Sameer Samat could be proud of on his CV: https://www.linkedin.com/in/sameersamat
https://killedbygoogle.com/
This is not the way.
What is the context for this? It's not clear to me from the linked social media post.
The Android kernel source code is in git: https://android.googlesource.com/kernel/common/
Plus there's a lot of other Android source hosted on Google's git servers: https://android.googlesource.com/
>At the time of writing, within ~12 months, in 2027, the 2027 Signature, Razr fold, and Razr flip will meet the hardware security requirements and should have official GrapheneOS support. Motorola is currently porting GrapheneOS to their devices.
https://news.ycombinator.com/item?id=49038982
I have a Moto G running LineageOS and it's my favorite phone ever. The ability to have my 800GB of music synced to a sdcard is something I'm loath to give up.
* before replying snarkily that Android is Linux, please take a long walk off a short pier, thanks
That said, I think wasi containers support for a mobile OS would be a game changer.
We have waydroid for that.
> You can't have a bank account on a Linux phone* because they won't let you, but you can on Android including on Graphene.
Unless of course it uses those stupid integrity apis to block anything that isn't stock.
https://privsec.dev/posts/android/banking-applications-compa...
The "security module" they require you to install on your computer. In the past, when browsers had plugins, this was a browser plugin; nowadays, it's an always-on service (running as root) which exposes a local HTTP server which the bank site connects to to validate your computer. For an example from a major bank in this country (the same "security module" is used by several banks in this country), https://seg.bb.com.br/home.html is the diagnostic page for that "security module" (the FAQ page there has links to the installers).
Soon, there won't even be an alternative flow. There are a lot of places where there already isn't.
For eg. There's no browser based alternative to make UPI payments that i know of.
Source: my bank which recently 'upgraded' a browser version to a glorified SPA which even renders as a vertical oriented app on a landscape 4K monitor.
A pure linux non-android phone would be great however you wouldn't have access to properly working apps and would not be able to participate in modern society.
Almost none support strong dedicated HW authenticators or second factors. Not even as an option to those who care.
Anyway it's always possible to just reverse their web api and use it directly. 2FA that consists of copying some code from SMS is no barrier, especially not on the Linux phone that you fully control.
If any of the Motorola devices have GOS as a pre-installed option, now the companies don't have the excuse that the device is modified.
I'm guessing the companies will continue to be difficult, but it'll be amusing to watch, at least.
They surely must have gotten feedback from me and others because the next update it worked again. But I and probably others where already a lost customer.
Diminishingly few apps do not work, and it’s down to them.
It's almost like Android has put millions of expert dev hours into making it the most used OS in the world. Like GNU+linux on laptops only works the way it does because of android-upstreamed battery saver kernel features.
But a mobile is also people's most used devices with all of their data, bank accounts etc there - it has to be safe. And GNU+linux has not even a single thought about security, while android just has it worked out (every app runs as its own user, so it's even built on standard UNIX security).
A mobile OS also has to race to suspend and for that it needs cooperation from "apps" -- desktop apps just run, they don't care about anything besides SIGKILL. That's not a workable model on a mobile and android solves it.
And I say all that as someone who runs linux everywhere I can and I absolutely love it. It's imo the best kernel out there -- but the userspace is not where it should be and if anything, the correct question would be what can we take from Android and add to GNU+Linux. (And nix is fantastic, but it's a packaging solution, I don't really see how it comes into question here. I can run nix on my android phone just fine by the way)
In principle I agree about a Linux phone, but the gaps are much greater. I am also sympathetic to the GOS team's arguments that sandboxing on Android is better, and important on a device that allows control of essentially my whole life (2FA apps etc.)
Leaving phones behind on old incompatible OS versions 2 times in 3 years and switching app frameworks 3 times in 4 years does not a good app developer experience make.
Piled on top of that, Google became actively hostile to 3rd party developers building support for YouTube (and Gmail and Gmaps, but those had workarounds / alternatives).
The advantage being, we can manage packages using a regular Linux distro
Drivers doesn't just mean the kernel. It's the user space binary blobs and services that need to talk to the kernel to enable the hardware.
Other than that there's waydroid, alien dalvik etc.. that run another Android instance in a container.
The thing is a lot of Android applications use safety net/other methods to make sure they only run on. "Approved"/stock hardware.
Google thought about this, don't worry. They learned their lesson after CyanogenMod tried to compete by offering an alternative. Non-Google Android are now dead except in China.
in China - there's no google apps available on their 'android' versions.
their platforms are already performant and fluid - so people should build on that.
claude code makes stuff like that super accessible to do in your spare time. another example is installing debian on a synology 918+, there's no way i would've had the grit to do that without ai. it's open season for any gadget that's got a debug uart port.
Linux crowd can not even agree on compositor, and if systemd or sudo is a good idea.
This is actually a feature.
GrapheneOS’ security model makes that of desktop Linux look like a joke.
This is an objective analysis based on x86 security, GrapheneOS hardening (including isolation and hardened mem allocator), Pixel hardware security.
Also if we use atomic distros with flatpaks and whatnot that mimic Android security the end user basically ends up having to essentially use Termux (but busybox or something similar) on their Linux phone as well
The existence of such a framework would make the various tradeoffs with going web-only sting less and make that the advantageous route, not just the cost-cutting route that it’s seen as now (and why those bad browser wrappers continue to proliferate).
You mean, a browser?
(which doesn't mean there's not a lot farther from here).
Not in the mobile world no, it's not a free market by any means
If by "mainstream" Linux you mean something like postmarketOS, I'd suggest you look up reviews or give it a try yourself. A few months ago, people were reporting a hard time placing a call, taking a photo, etc.
Out of nowhere, it received (along with other older phones) updates up to Android 16.
I wouldn't be surprised if the "sudden" update was just a side effect of Motorola preparing for Graphene to be released on these older phones.
https://x.com/GrapheneOS/status/2058730195041812839
https://x.com/GrapheneOS/status/2064124713501163912
https://www.androidauthority.com/lenovo-thinkphone-hands-on-...
Anyway I ended up buying a really good smartphone.. just not a graphene supported haha :(
Also this is really great collab from moto & graphene as more vendors will officially recognize Graphene as legit OS (legel/OEM is different concept). I heard month ago Volkswagen banned graphene, hopefully we we will see moving things in opposite direction...
Why would anyone want a car app? Is being tracked by the car's telematics unit (cellular modem) not enough?
Which still makes you wonder why Volkswagen is so keen on alienating what little is left of their customer base with completely stupid security theater.
The whole idea of buying something is giving people money for their (assumed correct) judgement, which then leads to desired artifacts downstream.
edit: they have X but didn't post it there https://x.com/GrapheneOS
Banking apps (e.g. Revolut) block GrapheneOS actively and many other apps too.
But it will be interesting times once they are out!
I'm not selecting which phone I buy on whether the stock OS comes with lockscreen shortcuts. At best, a software requirement someone might use as a deciding factor is OS support and bootloader unlock. The real differences are in hardware: size, battery life, chipset speed, RAM or other local model enablers, picture quality (this part also depends on good software to be fair), included accessories, satellite connectivity hardware, headphone jack, gimmicks like UWB or FM radio support, whether it's a flip/fold phone, storage space / sdcard support... all hardware differences
Having looked at some low-end Motorolas recently, this is accurate (albeit an understatement!)
Sure would be nice to have phones that can be rooted, or OS replaced. I've been hopeful this would perhaps enable that, but I fret my excitement may be premature.
This somewhat indicates to me it will be available when the Motorolas release which should be on their regular release patterns. That's been May for the 2025 and 2026 Razrs.
Maybe this will lighten the price on the Pixel 10's though...
Thanks, but no thanks. I'll keep using Lineage on any cheap smartphone under the sun.
Who maintains the kernel+driver trees used by the LineageOS port you're using? And what's the modem's security like?
Furthermore, when the hardware is cheap then it is also cheap to upgrade/move often. Which is not the case for those pixel/motorola/nsa luxury devices that only a few people in the globe can acquire.
Not sure that is exactly correct yet but guessing not long til it would be. Bleh.
Completely random public example: https://github.com/BuSung-dev/Root-My-Galaxy-Payloads/pull/1... (where GLM 5.2 is credited with the port) (Check out the other PRs in that repo for other similar examples)
This is a known adversary and highly skilled opponent org who has even attacked senators in charge of their appropriations. I find anything they say or do to be highly suspect and default guilt until cleared.
And backdoor isn't the same as mathematical vulnerabilities. I can easily see them pushing an encryption that would give them 10 or 20 bits complexity reduction.
So no, I don't trust AES either.
He is adamant that the state could not read his phone but all he has is their assurance that they could not read his phone. Of course they'll say they couldn't read it if they are after his contacts and network rather than after him.
(You could equally say that I am a deep state shill who is trying to discourage people from GrapheneOS. That is also possible, but I'd really prefer something like LinuxFromScratch for phones.)
From what a friend working in a state police cyber crime office says, "Cellebrite can't currently, unless its a Graphene OS user that's far behind on updates"
They also said iOS is equally safe unless you're an update or two behind.
Strange you're being flagged since it's easy to find many other people on the graphene forums reporting the same (unresolved) problem.
Doesn't mean it's guaranteed to be limited to graphene in scope, but definitely seems to be a prevalent issue for some yet-to-be-determined reason.
Possibly related, does anybody know if graphene is vulnerable to Pegasus?
I had the opposite experience. I was pleasantly surprised by the battery life you can get when your phone isn't full of shitware apps and even when you do install shitware, the OS helps you confine it.
https://discuss.grapheneos.org