Supporting initiatives like the Librem phone is also moving up in my list of priorities, once I get enough money to spare at least.
Supporting initiatives like the Librem phone is also moving up in my list of priorities, once I get enough money to spare at least.
My Blackberry Q10 served me well for years but the battery is starting to go and the OS + apps are no longer supported. I can actually say I've skipped Android/iOS entirely.
Still Android, but you keep the HW Kepboard and the batterylife and build on it is insane. Not nearly as clean as stock or the Key2, but much more freedom respecting.
I just got mine and it is significantly buggier, crashier, and slower than expected. The USB C port is also of low quality. It is overall worse quality than expected.
It's coming along fine though and in a few years that might be true! For now, a great device for tinkering and contributing back.
Source: I've used the Outlook app before my phone was enrolled with my company so I noticed the differences :).
We're using some Xiaomi devices we purchased, and I'm currently seething. I can't root without 'unlocking', which is a process that requires me to activate a Mi Account, which then requires my email and a SIM (?!), and 'find my device' (location) to even allow installation of apps via USB. To unlock the computers I bought, so I can use the root account, to install an alternate.
Seems the prison walls are just set far enough away that we don't notice.
tl;dr, in order to get some privacy, I'm being asked to associate my IMEI, my IMSI, my email, and my location.
Mere tamper-evidence - having a "bootloader unlocked" warning on boot - isn't obvious enough for a new user who has just bought the phone for the first time. So all manufacturers have added time locks and anti-fraud detection for bootloader unlocking. The time lock in particular is the best way to cut down this effect during the early sales process after which time it's hard to catch up in review score. But a time lock can only be implemented securely via a remote server out of the user's hands.
Xiaomi getting the telemetry is a cherry on top, but it's not originally nefarious - or at least - it's less nefarious than the problem it's intending to solve
The "we're protecting people from themselves" argument seems spurious.
Because it isn't the argument at all? The goal is to protect your reputation from having malware and ad laced versions of your latest hardware flooding the market (and hitting the news). Users are just a secondary concern.
In a way, it’s to protect naive users. And it still allows you to root the phone - go through this idiocy once and then never worry about it again.
adb shell pm uninstall -k --user 0 com.[miui,android,xiaomi].<appname>
Have you investigated if xiaomi.eu firmwares successfully curtail those connections?You can also grab a used device with a confirmed unlocked bootloader. You usually have to ask a seller, and some won't know the answer, but you can provide the steps for them to determine this.
I really have enjoyed the LineageOS and it's been great to have a phone that isn't as dumb as a flip phone but doesn't have all the bloatware and spying of other devices. The security around the bootloader is my biggest concern.
https://www.reddit.com/r/LineageOS/comments/ev9c4v/is_androi...
FBE is only secure when the system partitions have dm-verity enforced and verity is only enforced when the bootloader is locked.
FDE is a bit more resilient with an unlocked bootloader since there is less data left unencrypted.
However in either scenario without a locked bootloader and verity it is trivial for an attacker to insert malicious code that can then run once your device is unlocked and send off your files.
(I believe this is an example of an evil maid attack, although that name for it is somewhat new to me.)
A locked bootloader would prevent such code from being installed, or at least refuse to run it.
If you're in a position that your chain of custody is broken, just wipe, revert the device to stock signed binaries, confirm by locking the boot loader again, then unlock and re-flash your custom binaries.
Or am I missing something here?
The Play store and what it gives you is incredibly hard to live without, unless you really just want to use your phone for texting, browsing, and calling. If you're a minimalist, then great. If you're accustomed to what a smartphone can do, not so great.
The alternative app stores are full of unimpressive, small scale apps. Dozens of calculators and little games, but no maps apps (of worth), no yelps, no IMDb (which I use often), no Sheets or Photos, the list is huge. I'm sorry but these apps make a smartphone worthwhile.
To avoid such a spartan experience, I ended up just installing microG (an open source replacement for Google's Play Services) and Aurora (a replacement Play store client, which allows me to install most apps from the Play store).
The problem is that most modern apps require a mammoth cloud backend, which costs big money to run, which means you're going to need a huge company running it. You'll never find big scale apps like this on F-droid.
I use them all the time for tracking expenses, tracking information for myself, creating forms and responses, etc.
And let me tell you, I almost never have to open up the playstore except for updating my banking apps, because f-droid has a much better selection of apps anyway.
For example, NewPipe is a much superior alternative to the official youtube app and it even works perfectly fine without a youtube account. I don't have to ever worry about having my google account deleted because NewPipe backs up my subscriptions to xml.
I can only recommend this approach of "degoogling" but still having the ability to fall back in case it is really needed. But so far microG has been great, they even implemented the Covid Exposure Notification framework very quickly.
OSMAnd
>no yelps, no IMDb
What do these apps provide that the mobile sites don't?
In particular, I seem to recall if you landed on Yelp, a lot of content was "here's 150 pictures, but you can only see 3 on the browser."
There are many other uses for a car than commuting to work ;)
And you don't think this is related to Google Play Services constantly running in the background, searching for networks, location, open & installed apps, and OS metrics, per the linked article?
Reading through r/BlackBerry, it seems my KeyOne is only useable because I've disabled Google Play Services - otherwise it would be dramatically slower with much worse battery life.
you may have gotten that wrong
'google play services' is software package (app) that sits between the os (android) and the (other) apps. it provides a lot of middleware like maps and push-notifications. it has grown in power to the point that an android phone without them is pretty much pointless, hence micro-g tries to substitute.
text is insecure but thats not my threat model
Phones still have a lot of compute and sensor hardware that standalone apps can make use of. Heck, my Galaxy S3 can be a desktop replacement with MHL-out and USB or Bluetooth interfaces. And a lot of patience.
Other than that you’ll get low volume low end devices at high end or higher prices due to lack of economy of scale.
What most consumers actually want and I’ll put in that list also many many people that say they want a “Linux Phone” but in reality will go back to their iPhone/Android after a week is quite different than what a tiny niche is willing and capable of dealing with.
I used Android from day one till the LG Nexus and I switched to an iPhone after having to spend yet another weekend compiling a kernel to update my phone.
Most people want a device that “just works”.
Overall I would be good money on the fact that the percentage of people that say they want to be able to hack their phone freely and will actually do so is very slim because again Android gives you 90% if not more of that freedom already and some devices even can boot other OSes.
Sure things like the blobs on the baseband are still closed but that will always be the case no one realistically is expecting a high end 100% open source phone, and if you are keep dreaming.
And yes while having a phone that just works and one that is open isn’t mutually exclusive in principal but it is in practice especially once you account for economics.
Like it or not securing an open system is harder, and companies don’t like investing time and money developing features hardly anyone will use.
But what I mean is most of the system isn't really open like that. Configuration, application data and stuff like that is mostly managed by the system and you can't access or change that data without major hacks. Termux feels like a second-class citizen because most of the ecosystem isn't built with something like it in mind (in contrast to the "CLI-by-default" experience on other Linux systems). There's also a few (non-embedded) system components like the backup system (which, if I'm not mistaken, is provided by the Google Services Framework) which you can't easily replace.
Of course, when it comes to security this is not something you should give to anyone who doesn't know to protect themselves using it. And I assume it wouldn't be a financial success either, I just guessed this is what people mean when they say they don't like Android because it's too restrictive.
Unlike on the desktop, most important phone apps aren't so large and complicated that they couldn't be ported to or reimplemented on a new platform with a realistic amount of effort. You could offer a significantly better developer experience than either of the dominant platforms today, which would be essential to supporting the apps users expect to find available on any mobile platform today but also potentially attracting some unique and better apps over the longer term.
From the user's side, they'd be genuinely in control of their own device. There could be real security, stability and privacy benefits as a result, and you could do away with a lot of the things that annoy users of current mobile platforms.
As ever, the problem is how to bootstrap a two-sided market. It would probably have to be extremely easy for developers to port their existing Android apps. You might also have to convince one of the major phone manufacturers who can make good hardware at competitive prices to support your platform as an option, or possibly make it easy to install it as a replacement on existing phones. But with the right promotional strategy even these things don't seem totally out of the question. It's a huge potential market, on a scale where one or more well-capitalised big players in the industry could potentially take an interest.
As much as FOSS crowd loves to hate Microsoft, better get the facts right.
https://www.cbc.ca/news/business/stephen-elop-to-get-25-5m-f...
How many major phones can you buy with AOSP installed by default today?
How much development gets done on AOSP that isn't at least heavily influenced by the direction Google takes?
Does AOSP provide comprehensive privacy and security options for users but still freely connect with other devices and services using open standards?
Obviously if you're going to be Linux-based and if we're assuming some degree of compatibility with Android APIs to make porting apps easy then there is going to be common ground with AOSP, but I don't think that makes it the only or necessarily the best option.
Heck how many people do you think install SailFish on their phones? You can buy pretty decent Android phones with AOSP and even SailFishOS builds yet people aren’t taking advantage of that in any particular manner.
If almost no one uses it, even amongst those who claim they want that freedom why will build a business model around it?
I want a mobile OS that gives me complete control over my personal data.
The issue is that whilst people want it there is never a good enough “reason” for that other than I want it, Maemo doesn’t give you more freedom than what AOSP does already at least not on the software level, you can degoogle and Android phone completely and do w/e you want with it. However people don’t seem to be doing that, and those who do often do that for academic purposes rather than to have their own personalized daily driver.
Even more so often the wishes of many people when it comes to customization doesn’t even require a rooted phone and a customized AOSP ROM, if you look at what people customize on their desktop which is often limited to their desktop environment and their workflow can be done on stock Android using alternative launchers and other apps.
Wanting for an Android competitor for the sake of having competition is fine, but it won’t look much different or it won’t be much of a competitor.
The other problem is that you have to choose between hardware quality and customization, because hardware is locked down and there isn't enough economic air left in the room for a third player to be able to invest enough to compete.
As for not looking much different from Android, the key difference would be where the control lies, and what the mindset is around control. You should have a robust code signing and containerization/permissions system, but those should be in the hands of users. With Android every single app installs with permission to portscan every network you connect it to. You will have an app store, but the user will come first, not the ad network.
I liked my Nokia N900 and kept up for a while with attempts to keep its Maemo going after Nokia abandoned it. However, a decade later Maemo has bitrotted and its dev community has dwindled away. Nowadays the Phosh interface (i.e. the Librem phone, or Mobian running on the PinePhone) is seen as the most promising Free Software choice in the long term. Sailfish OS is also actively maintained, but its UI layer is closed source.
App distribution was also better on both platforms. Maemo used apt under the hood, and Preware[1] was phenomenal. These days the two vendors that own 99.4% of the mobile OS market[2] don't want to let you install apps unless they can get a 30% cut.
[1] https://webos-internals.org/wiki/Application:Preware
[2] https://www.statista.com/statistics/266572/market-share-held...
They both allow free apps.
[1]: https://fxtec.com/
[2]: https://browser.geekbench.com/v5/cpu/compare/4573446?baselin...
I have an Pixel2 and was thinking I'd get an iPhone next, but I'm really turned off by Apple's behaviour lately. I also don't want to send more money to Google.
I'm willing to accept that it may not be as polished as the big players, but how would you say it compares to other high-end Android phones?
And if you've tried running linux on it is it usable with reliable call quality?
Taking a serious look