Review: Copperhead OS
adventuresinoss.com
adventuresinoss.com
Personally I use CopperheadOS as my daily driver because it stays continually ahead of Google (and groups like AOKP, LineageOS etc) in terms of Android hardening. It goes well beyond just not having Google Play services.
See their details on their approach and design: https://copperhead.co/android/docs/technical_overview
They make continued patches to Android as part of a security and privacy first approach. Many of their patches get upstreamed by google months later (if at all) but CopperheadOS users get them right away.
Google has their engineering efforts focused mostly on new features and compatibility. They are happy to let firms like CopperheadOS be further ahead in security research and take their patches where it does not break compatibility.
It really depends on what you want to optimize for. Security/privacy or being able to run all the latest games and social media apps and the consequences that come with them.
(1) https://www.theregister.co.uk/2017/12/22/grsecurity_defamati...
1. They're a surveillance company that has more actual and potential earnings the more they know about their customers. They get good margins when their customers lack privacy with devices locked into Google by default.
2. They don't care about users' safety since make billions off Android platform but wont even patch vulnerabilities quickly. They have enough money to design a server UNIX from scratch plus a full-custom CPU plus mitigations from code injection at CPU level with all that leaving them with a few billion in revenue left out of Android alone. They just don't care since they're a public company about squeezing out every ounce of profit.
So, their incentives ensure they will leave the devices insecure. Someone will have to make their own versions that are secure like Copperhead and separation kernels before them (eg OK Labs) did. Alternatively, convince Google to offer a paid, secure option for their own internal use if nothing else with them recovering costs by eating up the cryptophone market's revenues.
So, Google securing Android would cost them a lot of money for fixing the customers' problems that dont affect Google. Then, it might cost them piles of money later in lost ad revenue when now-private services make customers black boxes of sorts.
I think there's a lot of middle ground to explore but surveillance or public companies don't usually go for it. Offering a paid, surveillance-off version of each ad service is one of those. You will rarely see that as simple as it is to do.
A few days ago I was thinking about a new smartphone and because my main problem with my current android is the outdated kernel and driver setup, I was searching for smartphone with open source drivers. Wikipedia tells us since the start of the Smartphone era about 22 phones had open source drivers (with the exception of the proprietary baseband firmware):
https://en.wikipedia.org/wiki/List_of_open-source_mobile_pho...
Doesn't look like something where you can select the hardware specifications you prefer. So I feel a little lost.
In general, I like Android but for my taste the Google services are too intrusive. Uploading my data before I had a chance to deactivate it is just unacceptable. Asking me every day to add photos to Maps sucks too. I can accept giving some of my information to Google to improve the product, but lately Google feels like the data mooch on my smartphone...
If you don't want Steam, don't use games that require it. If you don't want Google services like Google's Maps widget or its push messaging service or its game leaderboard, use apps that use another data source for maps and another persistent connection for push messages and another leaderboard service.
F-Droid and Amazon's App Store are filled entirely with apps that don't (can't) use Google's services, yet many on HN blindly continue to claim that this is not possible.
AOSP may not be as fully featured as it could be, but it's clearly quite possible to use Android without Google.
Making people implement their own services proved to be problematic, because most developers didn't care enough to optimize their services for low memory and battery usage, resulting in terrible battery life on Android devices. Since Android must compete against iOS, a central system had to be established to reach similar battery life.
That's kind of a cop-out though. It certainly could exist without Google's involvement if the location provider were a pluggable module within AOSP. microG does this - my phone supports the fused location API using Mozilla's location database instead of Google's. (There are other modules too, like a local database of cell towers if you're willing to dedicate some storage to it.)
Push notifications and Google login sure, but some of what's in the Play Services APIs should really be in AOSP, IMO.
EDIT: For that matter, you could even have the push provider available as a module too, even though Google's push service is the only one currently available.
But in general, I don't get what your expectation is, that Google will spend millions developing an OS and then give it to competition or deliberately provide worse user experience than their main competitor?
Also how do I turn off location tracking by Google, constantly asking me to upload pictures, write a review, answer questions ect
Does anyone know how to disable this?
As far as I know google can't link me to any data that maps sends.
Spotify works fine, along with a half dozen other apps.
Signal can a bit of a pain, as it complains about not having a google api backend, which I think is for contacts. Again, the pain is worth it. And there are open source contact alternatives.
I can't get apps that I paid for, for that I would have to sign in with Yalp, which I haven't bothered with. The freedom is so much better.
Everything else works, banking apps, Firefox, Dropbox, etc.
I'm using a Sony Xperia Z2. The battery is AMAZING! I really wish a largish company would pick this idea up, and start selling phones without google. Sony? The freedom and privacy is worth a lot in my opinion.
So yes, you can remove Google completely from your smartphone, but then many things are getting much more complicated. So I don't want to remove Google completely from my phone. I just want to have easy options to turn things off I do not like.
I just wish Google would respect their users wishes a little more and would keep developing their services in a direction which would embrace community contributions to the eco system.
This is not how things work in reality. People/corporations don't do what you want just because you're wishing it. If you are unwilling to tolerate a little bit of discomfort why should they tolerate the risk of changing their practices which have been proven to work? By continuing to buy Android devices, despite your complaints, you are, in fact, providing them with the opposite incentive.
You can switch off all the nags in there.
It's mostly not functionality missing to pass the CTS, but just broken untested AOSP-only code (that is replaced by Google closed source code in Google builds).
Now I'm running UBPorts in my Nexus 5 https://ubports.com/
Edit: if you are downvoting this comment, please explain why at least. It improves the conversation. Thank you.
The best place to keep you updated about Halium is their Telegram group https://t.me/halium
Hello Google employee here! I suspect we don't all have the same opinion but I can share my own since you asked. Note that I work in Cloud so I work in an area far far away from this stuff and opinions are obviously my own.
Frankly the headline makes me a little bit sad because of course I would like to make things which people are happy about. On the other hand, I also realize that it's not easy to make a product which fits every single person's use case, and in this case I suspect most this level of privacy is overkill for most people, and it's wonderful that there is something for those who want that extra privacy and security.
I also think it's awesome these people contribute security patches to AOSP!
> I mean they probably have no problem giving the personal data to Google, but at the same time many of them are probably open source proponents and would support a world where the Google services would be entirely optional to Android.
I like to think I'm a proponent of open source as I try to contribute but to be honest I don't actually think it really matters for Android to be independent of Google services because as far as I can tell, most people like Android with Google services?
Is there a reason that removing Google services would be better for the users? I can understand from a philosophical or ideological standpoint why it would be better but not really from a product point of view since I think I can confidently say 99% of Android users do not care or even know that it is open source..
I don't think our team is releasing software to let others start their own cloud service if I understand you correctly. Are you thinking of something like what GitLab does? If so our team isn't doing that sorry!
I guess I'm not an open source proponent but just whatever you would call the above?
What would you consider to be an open source proponent? Someone who believes all source code should be open source?
> That's you prerogative, but you completely miss the point of the discussion if you ask why should users want to be independent from proprietary services
Well don't just leave me hanging.. what is the point of the discussion? Please do enlighten me.
> Sure, 99% don't want that and would click any colored and shiny button if it promises them a free Justin Bieber ringtone, but this is not the topic of the thread.
Isn't it? I mean the comment was literally asking for an opinion which I gave. I'm not sure I understand why this is off topic? Most businesses would be unbelievably successful if their product appealed to 99% of people.
So back to how this relates to an Android being tied to Google Play: you as the user don't have ultimate control over your device. And that means you don't fully own your device.
That's my perception of the main issues with control from Apple and Google. Lots of great software and hardware being produced, but we need to have more power over the operation of our gadgets.
People like Google services, but they're less enthusiastic about Google's data collection practices. My father, who is now retired from a career in semiconductor manufacturing and programming, was unaware of Google's practice of monitor users' credit cards [0] and was visibly uncomfortable when he was made aware of it. Google's terms of service were effectively changed in a manner that harmed him, but he has no recourse.
Google services are frequently useful, but let's not pretend that there are other good choices. Google offers their apps for free, and has immediate access to approximately one billion Android devices by mandating an app's inclusion. That's an impossibly high barrier for all but the largest companies.
[0]: http://www.latimes.com/business/technology/la-fi-tn-google-a...
That's exactly why it should be independent of Google services–it makes it too easy to make changes to benefit those who use Google services and harm those who don't in the name of "but it's great for most people…"
Yeah but what about people who aren't most people? Are you saying they don't matter? That doesn't sound very open source.
Actually, I think removing Google services by default is not what we have in mind here. So we are okay that most users like Android as it is. Well, I think many of them just don't know which information Google collects and if they would learn about, some would not want to share that information either, but that is something everyone has to care for themselfs.
We just want the options to opt-out of every Google service easily and use alternatives (without having to flash custom roms) and to have up-to-date kernels and drivers. So having closed source drivers actually reduces the security (missing updates after a few month) and life time aspects of the product (the device). With the Android market domination Google has, it could easily force the hardware manufacturers to produce devices with open source drivers.
The Copperhead guys should get a copy of http://www.dummies.com/education/economics/how-to-determine-...
You should provide some actual claims about the problems you had with the hardware rather than just complaining.
I have one issue however that I thought I'd put out there from a customer service standpoint. If you buy a phone from them, you pay what seems to me like a nice premium (Pixel XL $1,269.00; though it's hard to find a good comparison point), and it comes with a service plan. Copperhead (as I understand) takes stock AOSP and (among other things) swaps out some of the default applications. Notably, the SMS application is something called Silence (silence.im).
Here's the issue. I've had a problem or two with Silence, and I contacted their customer support. They suggested trying other SMS apps to see if that solved my problem, which is in itself fine. However, at that point they closed the issue, because they claim that they're not responsible for 3rd party apps, even ones that they bundle and (I presume) update with system upgrades. The reason given is that they don't control the source for those, unlike the OS. I don't accept this at all. I paid a good premium (unless I'm mistaken) for the phone, I expect a _working phone_. This, these days, includes a functioning SMS client. How they go about making that happen is _their_ responsibility. They can work with me to find a suitable replacement, they can submit a pull request or a bug report, etc. But I argue they should consider the issue open until it's fixed or I decide it doesn't matter.
Anyway, not a big deal, I worked around it. Perhaps if I pressed enough they would have been okay with me returning the thing on these grounds, but it's nowhere near worth it. I just disagree with their philosophy on this issue. I understand it must be _really_ hard to deal with all this as such a small operation. But then they should put this point in big bold letters when you buy it, or something. ¯\_(ツ)_/¯
That, coupled with the fact that Pixel devices are way more expensive than Nexus used to be limits its usefulness.
Supported devices: https://wiki.lineageos.org/devices/
It turns out many apps from the Play Store don't actually have a hard dependency on Play Services. Example: Slack works, except for notifications and (IIRC) receiving calls, which is good enough if you don't need to be reachable all the time.
I run LineageOS v13 now (Galaxy Nexus), and before that Cyanogenmod back to v7 (maybe v6 not sure) and have never had Gapps installed, its been F-Droid all the way. I guess that means I can't appreciate the improved battery life or speed..
There's a project now to include anbox to run Android apps http://news.softpedia.com/news/ubuntu-phones-will-soon-run-a...
I do use lineageOS myself and am generally very content with it but I am always a bit concerned when I see that the data usage of OS components (which are thrown together as one "app" in the settings) is more than a few MB. The system must do more than just checking for updates. Unfortunately, you can't prevent system components from accessing the internet if you don't intend rooting your phone.
This already exists for businesses with Samsung Knox / Android for Business. No it's not a full OS but it fits all of their needs and separates data. Having one OS in a "vm" on a phone sounds horrible UX wise.
[0] https://forum.xda-developers.com/android/apps-games/closed-b...
I had to use a profile for my banking app to isolate it from all my personal apps, instead. But it seems that Google doesn't' even care that much about the multi-profile functionality, as it seems to crash quite often and has other issues. I imagine they don't put it through a lot of Q&A with each new Android release.
Even so, having to change between profiles often just to get that kind of isolation is quite frustrating.
I believe most android people are doing this with users.
Since Android is now up to the task of docker (kernel 3.10+), it would be very nice to see apps sandboxed with permissions exposed via networked APIs.
Then it is impossible for an app (sans exploit) to access private data, and simple for the OS to route certain apps to certain data sets (ie, fake contacts for apps that shouldn't need your damn contact to begin with).
CyanogenMod accomplished some of this through various methods, but they were detectable. If you build it this way, it should be entirely undetectable.
The sandbox doesn't do the isolation that docker can. It uses user isolation like I mentioned. The difference is that Binder is Java on top of the kernel, while docker is isolating from the kernel itself.
Without access to the service, it is impossible, sans-kernel-exploit, to escape the permissions jail, or even tell if you are in a permissions jail if someone gives your app fake contact information by routing it to a different service.
Docker isn't perfect. It had a serious CVE recently. I'm certainly not saying it is absolutely better. I'm just saying that I think they are fundamentally different and that process level isolation is superior to user level isolation.
Without strong controls about what they can do, we are always at the whim of what they might do. Google feels like a fairly bipolar company from the outside, because they present two faces depending on who they are dealing with, end-users or companies looking to advertise.
As an end-user, Google knowing all the little details about everything I do and many places I go (because analytics JS, G+ button inclusion, etc) is disconcerting. For a company looking to advertise, them not doing this all of a sudden would be disconcerting, and they would probably look to some other company that is doing so. It isn't just Google. Facebook knows a startlingly large amount about you too.
I'm increasingly convinced this is one of those places where the market is failing us because the negative externalities are mostly hidden. Those are good places for targeted regulation. I wouldn't be entirely appeased, but a law about the ability to review all information collected about you from a company and strong controls about the access, sale and use of this information would go a long way towards making me less worried about Google (or whoever) changing quite a bit in the next decade and selling off the information.[1]
Because think about it, how far away are Google, Facebook and the umpteen other ad agencies with complex profiles of you from usurping the credit bureaus?
1: Maybe what we need is an interesting billionaire to buy a lot of personal information on all the U.S. politicians from one of the less public agencies and publish it. I'm sure we would get a law passed in record time.
But do you honestly see an outcome where information is not collected at all? Because I don't, so as I see it we need to put the correct incentives in place to not only make it less likely but to handle when it inevitably does.
Maybe a fine up to $X per account leaked with a soft cap (but absolutely no less than $1 or $2 per account) is levied. Losing 1 million accounts would hurt, so companies would make real decisions about what and when to collect data for liability reasons, and protect it better in many cases when they did.
Instead of having companies own data (Google/Facebook), all data resides in public databases. This would work for services that do not need sensitive data and can be anonymized, such as what videos do I watch, what words I type/search, etc.
This would help both privacy (I know what data is being recorded) and help small competitors thrive.
Well, it's a question of what one is willing to pay. Me, I'm willing to pay actual U. S. dollars to Apple to get that same functionality without giving up (and perhaps I'm naive here) privacy. Personally, I like that well-defined transaction. The transaction that has taken place between yourself (and to some degree, me) and Google is much more fuzzy. Today Google does this with your data, but tomorrow? You call it "adjusting the service", I call it "getting more creepy". No right or wrong, you're happy, I'm happy, but from my POV there is a vast gulf in the price paid for the two competing services.
The instant Apple starts doing Googly stuff, I'll dump them for the real thing. But I'll betcha Apple is quite aware of this.
[1] https://github.com/yeriomin/YalpStore
[2] https://f-droid.org/packages/com.github.yeriomin.yalpstore/
Turn it back on, sure, until the next time you want an APK that's not listed in F-Droid. Seems like a bad idea. How about writing to your favorite app developers and asking them to list on F-Droid instead of sideloading?
Thank you, I'm staying with default Android and continuing to read what I am prompted for. He could've just opted out of most data collection, no, he had to skip it without even reading it like a 60 year old office worker at a insurance company.
I believe Google finally introduced a way to deem other app stores as trusted on your phone, but given this is just a block on the manual installation feature, I would consider the trusted sources checkbox to be more "anticompetition focused" than "security focused".
It's free and the prime one is affordable.
Just try it out.
[1] https://android.googlesource.com/platform/packages/apps/Laun...
F-droid link: https://f-droid.org/en/packages/com.benny.openlauncher/ Google play: https://play.google.com/store/apps/details?id=com.benny.open...
They show a Nexus 5 on the landing page for CopperheadOS. Why not show a supported device?
I mean, come on! Ship a patch/update, already!
1) That replaced a bootlooped ~1.4 year old Nexus 5X. Wasn't going to spend big bucks after that burn and while waiting for the Pixel 2 or Samsung whatever, or Apple's new line, to drop in a month or two.
And now, with all the crap going on with all those various new models...
I've griped about this, before, but damn it, they deserve the criticism. And the only time they make positive changes seems to be when the public image and pressure get bad enough. (And things get worse again, as soon as that pressure relents -- or gets distracted.)
(I'm not affiliated with the project, I just use it as my primary phone OS.)
[1] https://copperhead.co/android/docs/install#supported-devices
https://www.merriam-webster.com/dictionary/copperhead
The first known use of the word "copperhead" was in 1775, well before the US civil war.