475
submitted 4 days ago* (last edited 4 days ago) by inari@piefed.zip to c/android@lemmy.world
you are viewing a single comment's thread
view the rest of the comments
[-] Resonosity@lemmy.dbzer0.com 7 points 3 days ago

I don't understand why the GrapheneOS Foundation can't keep maintaining GOS on Pixel devices, while also collaborating with other manufacturers than just Motorola (which is a $77,000,000,000 multi-national corporation) towards more decentralized hardware that can serve their needs while also having the ability to be manufactured by multiple vendors in a white label way.

Relying on Google or Motorola for everything will eventually lead to the same issues, which is platform lock out. I have no confidence that the Motorola deal will fix everything forever.

I refuse to believe that the most secure OS can't be installed on the most OSH.

[-] TrollAccount69@lemmy.ml 1 points 2 days ago* (last edited 2 days ago)

It sounds like you don’t understand what the pixel phones are, what graphene is and what open source is.

The pixel phones used to be a reference implementation for an Android handset. A while ago Google decided to try to actually compete in the market and that meant designing hardware people would actually pick over a Samsung or whatever based on the numbers. So they put a chip in the new phone that doesn’t do emte because it makes everything slower.

Graphenes goal is to be the most secure phone os. That means they’re not competing against other Android based software packages, but against ios. It’s a tough row to hoe because whereas apple can develop hardware support for emte and software support across all first party apps and even offer it to developers in a very well documented framework then announce it in a big flashy press conference with the kicker that you can buy the system next month, graphene has to make it a granular switch system that will cause hangs, slowdown and crashes on even the aosp system apps.

Open source hardware doesn’t mean securable hardware. It’s easy to make open source platforms that are fundamentally insecure with no possible software path to remediation.

Now if you want to install some parts of graphene on unsupported devices there’s a fork out there, but it’s pretty stupid to do that since you’re giving up all the security of graphene and gaining all the roadblocks it puts in the way of doing insecure things with apps.

E: spelling

[-] Resonosity@lemmy.dbzer0.com 1 points 1 day ago

Can OSH be secured hardware? Is there a fundamental contradiction there?

I suppose if schematics for chips are available to the public, then it would be easy enough for a trained bad actor to follow those schematics and identify hardware vulnerabilities that they could attack.

Does this mean that the product GOS Foundation provides necessarily has to be closed source? Open source and privacy can never coexist?

[-] TrollAccount69@lemmy.ml 2 points 1 day ago

It is possible for open source hardware to be securable hardware. Of course, someone has to design it, manufacture it and distribute it and eventually it will be unsecurable because new vulnerabilities and capabilities are developed every day, so that someone will have to design, manufacture and distribute a successor and the old hardware will have to be deprecated.

All that costs money and the people who care about security are a super small group so graphene chooses hardware that is “accidentally” securable. The reference implementation pixel phones are a great example. Google doesn’t care about security or graphene. But they built a phone intended to do the hard work of putting all the possible parts together so that other manufacturers could look and see how they could do an Android phone with some feature (or even some better feature) without having to spend a bunch of cash doing it from scratch. It just so happens that Google included relockable (this is different and more important for security than unlockable) bootloaders, a processor with memory tagging support and a big pile of documentation in case you want to use those features.

Then Google indicated that it was gonna stop doing everyone else’s work for them. There are a bunch of reasons for this and I’m not gonna go into them but I will summarize some analysis: you should make it a priority to move away from Android devices eventually depending on your citizenship and stop relying on the securability of a computer system of any type. Doing everyone’s work for them was why the pixel phones were such a good target for graphene, they had the features and the documentation. Now that Google isn’t making reference implementations anymore, they don’t intend to have every feature (notably security features) or give out docs.

So the graphene people switched to Motorola. The new Motorola phone that’s expected to run graphene wasn’t designed for it, it just so happens to have the features and the company agreed to give them the documentation required. It’s “accidentally” securable.

That’s how graphene works. There isn’t an alternative for them. They don’t have the money, capital or expertise to design and release a phone specifically for security and there isn’t a market for that product they could endeavor to sell to and get a loan against the promise of.

I want to make sure we’re on the same page: graphene is open source. There are open source projects that prioritize security. Security and privacy are different things.

[-] HCSOThrowaway@lemmy.world 0 points 2 days ago* (last edited 2 days ago)

I don’t understand

It sounds like you don’t understand - TrollAccount69

Username accurate.

[-] TrollAccount69@lemmy.ml 1 points 2 days ago
[-] HCSOThrowaway@lemmy.world 1 points 1 day ago

Thanks. I wanted to focus on the part you missed for some reason.

[-] TrollAccount69@lemmy.ml 1 points 1 day ago* (last edited 1 day ago)

I didn’t miss it, I was trying to use it as a rhetorical tool to help the commenter recognize that material conditions keep the things they seem to think are how it ought to be from happening.

“You think it’s one way but it’s the other.” To steal a phrase from a show. I wanted to use that as a hook to keep the readers interest through what is a pretty dry topic.

E: grammar

[-] Luffy879@lemmy.ml -1 points 3 days ago

can't keep maintaining GOS on Pixel devices

Where did you get this? It was never said that they can't maintain it. Google just isn't releasing the firmware and reverse engeneering every piece of it is a nightmare and at that point you might as well make your own brand.

collaborating with other manufacturers than just Motorola

towards more decentralized hardware that can serve their needs while also having the ability to be manufactured by multiple vendors in a white label way.

Because graphene isn't a project that developes phones? Also, Youre still relying on snapdragon and other manufacturers to make key components of your phones.

I refuse to believe that the most secure OS can't be installed on the most OSH.

Time to change your mind I guess:

First of all, OSS dosent mean runs on everything.

  1. Even if someone tried to port graphene to other hardware, they would have to remove key software from the port, like memory tagging, hardened malloc, etc. Which defeats the purpose of using Graphene over any other OS.

  2. OS also dosent mean secure, or even good. Just look at the insane amount of open source software wrappers and snakes.

[-] Resonosity@lemmy.dbzer0.com -2 points 2 days ago* (last edited 2 days ago)

Where did you get this?

Did you read the rest of the sentence? I said I refuse to believe they can't maintain Pixel GOS while also simultaneously doing research & development on finding a non-corporate, non-Google, non-Motorola hardware solution. Many people are saying that GOS can't do both. I refuse to believe that. GOS Foundation could set aside resources internally to figure shit out, if they wanted to. I don't see any reason they don't have the ability to do that.

Because graphene isn't a project that developes phones?

I understand that. But corporate lock out by Google and I predict also Motorola will mean that GOS will perpetually need to jump from sinking ship to sinking ship. Having control of the hardware that doesn't come from a corporation means that they can develop their most secure OS without worrying about an expiration date on the hardware. I'm not saying I want GOS to make their own chips and phones. I'm saying I want GOS to partner with at least one OSH manufacturer like Pine64, Jolla, Purism, Fairphone, F(x)tec, SHIFT, Volla, Liberux, etc. so THEY can work on the hardware while aiming to meet GOS' requirements.

Time to change your mind I guess

I'm sorry, but privacy isn't freedom. GOS isn't the most perfect solution for all of time. I'm advocating for GOS to think about their future given a world of capitalism which seeks to destroy all our freedoms in the name of profit.

Even if someone tried to port graphene to other hardware

Existing hardware isn't sufficient. THAT IS WHY I'M ADVOCATING FOR GOS TO PARTNER WITH OTHERS SO THAT EVENTUALLY THEY CAN MAKE THE SWITCH AWAY FROM GOOGLE/MOTOROLA WHILE MAINTAINING ALL FUNCTIONALITY OF GOS.

[-] Auli@lemmy.ca 1 points 2 days ago

You do known it's not some big organization right? Have you donated millions to the project to help this along?

[-] Resonosity@lemmy.dbzer0.com 1 points 2 days ago

I'm not really a programmer so I couldn't really help in that capacity. I could donate but I also should donate to all of the other FOSS software that I use. What would be the best use of my money?

[-] Mcdolan@lemmy.world 0 points 2 days ago

Better to donate to none so you don't hurt any feelings..

[-] Resonosity@lemmy.dbzer0.com 2 points 1 day ago

Thanks for being no help!

[-] chiliedogg@lemmy.world 1 points 2 days ago

Somebody's got to make the phones. You're not going to find a bunch of modders who can manufacture millions of devices, so there's gonna be corporate involvement somewhere along the line. Now that Google is no longer sharing the Pixel firmware, GrapheneOS is working directly with a manufacturer that will.

[-] crypt0cler1c@infosec.pub -2 points 3 days ago

You refuse to believe? So you are either willfully ignorant or consciously delusional.

Instead of crying on lemme why don't you go educate yourself...

this post was submitted on 18 Sep 2026
475 points (99.2% liked)

Android

34731 readers
116 users here now

DROID DOES

Welcome to the Android community on Lemmy. Here you can participate in amazing discussions and events relating to all things Android.

The rules for posting and commenting, besides the rules defined here for lemmy.world, are as follows:

Rules


1. All posts must be relevant to Android devices/operating system.


2. Posts cannot be illegal or NSFW material.


3. No spam, self promotion, or upvote farming. Sources engaging in these behavior will be added to the Blacklist.


4. Non-whitelisted bots will be banned.


5. Engage respectfully: Harassment, flamebaiting, bad faith engagement, or agenda posting will result in your posts being removed. Excessive violations will result in temporary or permanent ban, depending on severity.


6. Memes are not allowed to be posts, but are allowed in the comments.


7. Posts from clickbait sources are heavily discouraged. Please de-clickbait titles if it needs to be submitted.


8. Submission statements of any length composed of your own thoughts inside the post text field are mandatory for any microblog posts, and are optional but recommended for article/image/video posts.


Community Resources:


founded 3 years ago
MODERATORS