319
submitted 3 weeks ago by schizoidman@lemmy.zip to c/android@lemdro.id
all 40 comments
sorted by: hot top new old
[-] Turret3857@infosec.pub 110 points 2 weeks ago* (last edited 2 weeks ago)

i dont want to sound like a dick but they really should've just forked the LineageOS apps that are maintained like they did with seedvault. this feels like theyre reinventing the wheel, or NIH

[-] Ludicrous0251@piefed.zip 45 points 2 weeks ago

Would be great if those two could play nicely. Lineage features with GOS security would be the bees knees.

[-] Goodlucksil@lemmy.dbzer0.com 1 points 2 weeks ago

I think Calyx OS would strike that balance

[-] Turret3857@infosec.pub 5 points 2 weeks ago

As a Calyx user, only kinda. A lot of the hardening done in GOS is missing from Calyx. Likewise, a lot of features in COS (firewall rules per connection type per app for instance) are missing from GOS.

[-] possiblylinux127@lemmy.zip 84 points 2 weeks ago* (last edited 2 weeks ago)

They could just... work with the community and use preexisting community apps

That is not how they role I guess

[-] bl4kers@beehaw.org 33 points 2 weeks ago

The maintainers are very picky and cynical about privacy & security. For better or for worse

[-] MonkderVierte@lemmy.zip 9 points 2 weeks ago

Not-invented-here syndrome?

[-] TrollAccount69@lemmy.ml 14 points 2 weeks ago

When you have a unique goal and set of constraints that are not shared by most users and are actually opposed to the interests of most users and developers it’s not a good idea to try to add them into an existing general purpose project.

Part of the memory tagging support of graphene for example is that the applications need to actually support it too. You can force them to deal with it, but that causes instability and crashes.

Shouldn’t all applications support memory tagging? Well that would be nice but it makes everything slower and only a few schizoid weirdos want it. Clearly the better option is to rewrite the basic system apps that everyone expects to support all the optional security features graphene requires.

Bear in mind graphenes security competition is ios. The system applications in ios all got rewritten to support emte when apple rolled out os level support for it combined with concurrent releases of new hardware with silicon support.

They’re playing a different game than the aosp community.

[-] bilb@lemmy.ml 2 points 2 weeks ago

You are correct, TrollAccount.

[-] woelkchen@lemmy.world 1 points 2 weeks ago

They could just add optional support upstream behind a compilation flag.

[-] TrollAccount69@lemmy.ml 3 points 2 weeks ago

Maybe.

I think graphene is so far removed from aosp in terms of goals and strategy that would be a pretty big commitment of resources.

If you haven’t ever done upstreaming in an open source project, there’s a pretty big support commitment involved if the thing your work could be part of has insider scope than your own project.

Which is pretty much the exact situation graphene is in.

And if the graphene people are serious about security then giving aosp their (just my own hypothetical) emte enabled apps runs a good chance of providing a false sense of security to the users of those apps when not on graphene.

This isn’t hypothetical btw, I had to dig through datasheets to prove that the old pixels don’t have emte to some random commenter a week or so ago even though just the most cursory understanding of arm mte versions and release schedules would make that obvious.

The point isn’t to say people are stupid or that person was stupid, but that often people will assume the best even when it opens them up to a huge blind spot. One of the best security (and safety) practices is to make your secure component incompatible with insecure ones. That way it’s impossible for someone to point to the thick low awg nema 5-20 extension cord without acknowledging the cheater plug they used to get it into a two prong outlet with no wide neutral.

[-] aReallyCrunchyLeaf@lemmy.ml 42 points 3 weeks ago

Hopefully we can get a calendar app!!

Cheers to the GOS team, doing the lord's work truly.

[-] iturnedintoanewt@lemmy.world 6 points 2 weeks ago

Etar isn't half bad. But yeah I wouldn't complain if they improve the landscape.

[-] yestalgia@lemmy.world 9 points 2 weeks ago

Calendula is FOSS and very good. I liked it so much I donated.

[-] pizzaschaartje@lemmy.world 2 points 2 weeks ago

I really liked the UI and UX of Google Calendar and I am amazed at how Calendula offers a near identical experience. Really amazing work!

[-] Steve@communick.news 15 points 3 weeks ago* (last edited 2 weeks ago)

It's a big ask, but might that include the browser?
They could contribute dev time to the Servo browser project.

[-] nebby@piefed.blahaj.zone 24 points 2 weeks ago
[-] Steve@communick.news 20 points 2 weeks ago

That's just Chromium with some removed "features", not a whole new app.

[-] peskypry@lemmy.ml 9 points 2 weeks ago

Well they can't do everything, can they?

[-] Azzu@leminal.space 4 points 2 weeks ago

Apparently, they plan to.

[-] Steve@communick.news 1 points 2 weeks ago

On a long enough timeline they can

[-] chemicalwonka@discuss.tchncs.de 12 points 3 weeks ago
[-] Endymion_Mallorn@kbin.melroy.org 3 points 2 weeks ago

Excellent. Does it run on the basic Tracfone devices? otherwise, they need to get on the road to compatibility.

GrapheneOS is very picky about what phones are supported, which is why up to now only certain pixels are supported, as well as Motorola phones in the future.

[-] victorz@lemmy.world 1 points 2 weeks ago

I guess Motorola phone will be my next phone.

[-] brokenwing@discuss.tchncs.de 1 points 6 days ago

Have you seen the new one? Will be more expensive than Pixels and the design is atrocious at best. Motorola Signature 27 Debuts With 200MP Periscope Camera and Snapdragon ...

[-] victorz@lemmy.world 1 points 6 days ago

6.8" is way too big for me. If that's the only one available, I'm good.

[-] nforminvasion@lemmy.world 2 points 2 weeks ago

It's only the new $1000+ flagships

[-] victorz@lemmy.world 1 points 2 weeks ago

Alright, nice

[-] jlow@slrpnk.net -2 points 2 weeks ago

From recent posts on the Fediverse I'm afraid their slopping these apps ...

[-] lka1988@lemmy.dbzer0.com 6 points 2 weeks ago
[-] wholookshere@lemmy.blahaj.zone 4 points 2 weeks ago

In the announcement threaded, they replied they us AI code analysis and code review tools to review security.

[-] lka1988@lemmy.dbzer0.com 12 points 2 weeks ago

It still goes through a human before it's pushed to the repo. That's very different thing than "slop". Slopcode is generating the actual app code via claude or whatever and shipping it as-is.

[-] GreenKnight23@lemmy.world 12 points 2 weeks ago

I hate AI, absolutely. without question.

however, code reviews and security reviews are in the top 5 acceptable uses for an LLM.

why? because I can't be bothered to read the newbies 10k lines of changes for a CSS rule change.

do I review the review? absolutely! does it make any changes to the code? absolutely NOT.

[-] TrollAccount69@lemmy.ml 9 points 2 weeks ago

Another thing to keep in mind is ai is what people are going to be using to try to find vulnerabilities in the software so using it to beat them to the punch is just good development practices.

this post was submitted on 09 Sep 2026
319 points (99.4% liked)

Android

22158 readers
131 users here now

The new home of /r/Android on Lemmy and the Fediverse!

Android news, reviews, tips, and discussions about rooting, tutorials, and apps.

🔗Universal Link: !android@lemdro.id


💡Content Philosophy:

Content which benefits the community (news, rumours, and discussions) is generally allowed and is valued over content which benefits only the individual (technical questions, help buying/selling, rants, self-promotion, etc.) which will be removed if it's in violation of the rules.


Support, technical, or app related questions belong in: !askandroid@lemdro.id

For fresh communities, lemmy apps, and instance updates: !lemdroid@lemdro.id

💬Matrix Chat

💬Telegram channels / chats

📰Our communities below


Rules

  1. Stay on topic: All posts should be related to the Android OS or ecosystem.

  2. No support questions, recommendation requests, rants, or bug reports: Posts must benefit the community rather than the individual. Please post to !askandroid@lemdro.id.

  3. Describe images/videos, no memes: Please include a text description when sharing images or videos. Post memes to !androidmemes@lemdro.id.

  4. No self-promotion spam: Active community members can post their apps if they answer any questions in the comments. Please do not post links to your own website, YouTube, blog content, or communities.

  5. No reposts or rehosted content: Share only the original source of an article, unless it's not available in English or requires logging in (like Twitter). Avoid reposting the same topic from other sources.

  6. No editorializing titles: You can add the author or website's name if helpful, but keep article titles unchanged.

  7. No piracy or unverified APKs: Do not share links or direct people to pirated content or unverified APKs, which may contain malicious code.

  8. No unauthorized polls, bots, or giveaways: Do not create polls, use bots, or organize giveaways without first contacting mods for approval.

  9. No offensive or low-effort content: Don't post offensive or unhelpful content. Keep it civil and friendly!

  10. No affiliate links: Posting affiliate links is not allowed.

Quick Links

Our Communities

Lemmy App List

Chat and More


founded 3 years ago
MODERATORS