E Foundation – deGoogled unGoogled smartphone OS and online services
e.foundation
e.foundation
Here's some reading that covers the basic points though:
https://intangiblesheep.neocities.org/rants/eelo.html
https://web.archive.org/web/20191224031946/https://ewwlo.xyz...
They should definitely embrace the Telegram FOSS fork [1] and OSMAnd~ [2] (which is a superb offline navigation tool btw) and remove all Apps that require the Android 10 firebase hockey-based notifications. [5] and [6]
A lot of apps use this for convenience and because it was _required_ since AOSP 10 but there are ways to work around that requirement with a high priority notification.
I would additionally recommend to use AppWarden [3] and Blokada [4], because both are amazing additions for an Android device.
Firefox for Android, though, is still a nightmare with all the telemetry. The old TOR Browser 9.5 series is based on old Firefox pre-quantum, 10 is based on Firefox post-quantum.
The issue with current Firefox and TOR Browser is that Mozilla decided to include the Adjust-, Firebase- and LeanPlum-SDK which introduce now more user tracking than ever before. You'll even sometimes see different A/B UIs based on your browsing behavior (not kidding) and geolocation, and of course this happens more often with Orbot being used as a Proxy.
(You can verify this via AppWarden if you don't trust me)
[1] https://github.com/Telegram-FOSS-Team/Telegram-FOSS
[2] https://github.com/osmandapp/OsmAnd
[3] https://gitlab.com/AuroraOSS/AppWarden/
[4] https://github.com/blokadaorg
[5] https://github.com/Telegram-FOSS-Team/Telegram-FOSS/blob/mas...
[6] https://developer.android.com/guide/components/activities/ba...
Besides, some of their practices like redirecting every blocklist through their own mirror (blokada.org/mirror) and in some cases through their URL shortener (go.blokada.org), makes me think they're not really as private as they claim to be.
Also, Blokada leaks DNS connections over TCP and doesn't let you set your own DoH resolver.
None of these are problems with Nebulo which is also recommended by https://PrivacyTools.io/providers/dns/ over Blokada.
https://git.frostnerd.com/PublicAndroidApps/smokescreen
https://play.google.com/store/apps/details?id=com.frostnerd....
https://gitlab.torproject.org/tpo/applications/fenix/-/issue...
I witnessed at least the Leanplum SDK taking action, and I thought I broke the App tbh. After a restart of the phone and clearing all caches via the Settings App I could verify that it happened a second time.
But I have no idea whether it was a "chrome://" Page with an externally included JS - or triggered by the underlying SDK directly. In Firefox pre-quantum (pre fenix 9.5), the Extensions Page included Google Analytics for a while, so I was assuming that my installation process of uBlock Origin and uMatrix triggered it somehow down the line.
I decided to roll back to TOR 9.5 after it happened the second time on the same day and now I'm building my own Browser (Tholian Stealth) anyways... so I didn't decide to investigate further than a casual look at the codebase where LeanPlum still seems to be littered all over the place. [1]
[1] https://gitlab.torproject.org/search?utf8=%E2%9C%93&search=l...
Those are all completely stubbed out in Tor Browser Android. I helped with some work on that a few years back.
[1] https://f-droid.org/en/packages/org.mozilla.fennec_fdroid/
/e/ “believes” in open source. Less along the lines of “concerns itself with every philosophical checkbox”.
IMO you and the author are filling in the blanks as you wish, landing in the realm of no true Scotsman.
Freedom to create as one would > flocks of sheep.
Personal emotional religion must take a backseat to suggesting folks discuss or use their time otherwise.
I don't think this is a fight that's sustainable - a giant graveyard of Android privacy forks shows that. In the end, the major contributor to this OS is and will remain Google.
In that respect, Purism's PureOS seems like a more sustainable effort.
I have a very high respect for all the work that's been done on the various GNU/Linux mobile distributions, but it's still so far away from Android wrt usability...
I agree there is something weird about fighting Google with Android, but still it makes perfect sense.
From a business or engineering PoV, you want best features for the fastest MVP. Android gives you just that. Actually it goes way beyond, /e/ didn't do much of engineering, they mostly re-used what's done by the Android FLOSS community. (Honestly I don't really like /e/ because they basically don't give anything back to the community but well).
If /e/ is ever successful, they can hire many engineers to actually fork Android to have their own. That's what Android did for Linux in the first place anyway! Most OEMs have a lot of changes to their Android, even though they keep using Google apps, and they are just fine. I'm pretty sure that Samsung have an order of magnitude more changes in Android than LineageOS (which /e/ is a pretty direct fork of), and they maintain it just fine.
This is where I ended up after countless hours of research looking for security/privacy.
Has anyone found sources for this?
Micay, of GrapheneOS and original creator of CopperheadOS, is not some random. They have pushed AOSP security ahead and have made many upstream contributions over the years.
Micay originated the Android Hardening Project, I believe it was called, and is the brains behind what was CopperheadOS, and now the superior GrapheneOS.
He was also a pretty instrumental Rust developer.
That was indeed a losing battle because Google has far more resources to add features ans beat CyanogenMod.
On the other hand, a de googlized and privacy focused platform provides something that Google can never provide.
There’s also a change in the environment surrounding all Of this. Thanks to the weaponization of Android by the American government, every country and company in the world is looking for a De GoogliZed alternative.
CopperheadOS did not die. https://copperhead.co/android
/e/ mostly uses LineageOS code without providing attribution. They have a fair fight ahead of them and the Android FLOSS community benefits from this internal competition.
Android is not designed for the community to be hacking on it. While these projects occasionally appear they don't last because of the incredible amount of work required to maintain them. You're much better off finding a normal Linux distro/phone pair that can make phone calls etc.
It has become a lot easier thanks to Project Treble.
As far as I could see in your GitHub project wiki, most devices tend to have a few glitches (probably due to issues in the hardware abstraction layer from the manufacturers side?): https://github.com/phhusson/treble_experimentations/wiki
I could see some that look mostly flawless, like Samsung Galaxy Tab 8.0 2019. It'd be good to have a curated list of preferred devices. Buying Android devices with ROMs in mind is quite frequent, and your generic ROMs are a huge leap ahead!
Doesn't the DRM stop working once the bootloader is unlocked? That'd be a big concern since most streaming apps would refuse to install or work in that case.
What other such changes is Google pushing into Android that discourages unlocking the bootloader / rooting?
So first point about the DRM itself: - Google here is "benevolent". Devices are allowed to keep working Widevine L1 working after bootloader unlock (without needing relock), and it does work just fine on Pixels. - Some devices clears their key after bootloader unlock, so unlocking means you'll never get Widevine L1 - Some devices have the key tied to being locked, to relocking will work - Some devices doesn't have restrictions, but have poorly written drivers that need to be hacked around to allow to work on unlocked bootloader
And then, there is the extra issue of what streaming apps decide to give you. For instance Netflix will not use Widevine L1 even if it works unless your device is whitelisted. So if you flash a "simple" alternative ROM on a Pixel 5, you still would get only 480p. The ROM needs to lie, and tell it is the original Pixel's ROM. (Also Netflix won't be listed from PlayStore unless the ROM lies and says the app that yes the bootloader is locked)
In my opinion, the biggest vendor lock-in about bootloader unlocking is that you'll loose all your data when unlocking, with no way to properly backup your data on stock ROM.
What makes you interested in it?
PureOS has to try and reimplement an entire mobile app ecosystem just to get to parity with existing competitors.
SailfishOS has this, and doesn't do tracking.
PureOS and Purism One implement some FOSS techniques and rebrand them. I believe Nextcloud does this as well. Not sure why projects don't clearly mention what they're based upon, especially when its a lot like original.
I don't know if all of these would work in e.foundation, but presumably at least some would run.
Custom AOSP apps can be supported via Anbox on upstream linux.
The telemedecine app is a big one I think about. I don't know what I would have done if I hadn't had a modern iOS or Android device when the pandemic hit in March, and my doctor appointments suddenly moved to this remote system.
What I seek in a phone is control over my privacy, not necessarily a vegan FOSS system.
What that means is things like:
- Fine-grained control of permissions to apps (e.g. access to rear camera only, access to only city-level accuracy of locations, access to read from only directories I specify)
- For apps that insist on having permissions to things like location and wi-fi scans to use them, the ability to make the app think it got said permissions, but receives fake data. And no, Android's mock location feature doesn't work, because apps can check if the feature is enabled or not
- The ability to fake IMEI, phone number, contact list, installed apps, and other identifying data
- Ability to generate fake IMU, proximity, temperature, barometer, and all other sensor data that could conceivably be used for fingerprinting
I think the effort is very good. The result is excellent and it's really addressing a much bigger audience that PureOS.
I think they legally can't call it "Android" in this case so it's not really their fault that they aren't mentioning this.
The officially stated reason (I'm paraphrasing) was because it allows for fudging the signatures of apps and services on the OS, and this breaks the security model.
[0] https://docs.google.com/spreadsheets/u/0/d/1bx6RvTCEGn5zA06l...
Ungoogling is a fine step but the whole thing needs to be rebuilt:
- Sharing Contacts: Should be illegal and removed as an option. Apps shouldn't be able to trick/coerce/incentivise people to harvest and sell other people's private information. When people give out their phone numbers and addresses they do it with some expectation of care, not with the intention of having it immedietly uploaded to Flappy Bird. The most that should be allowed is perhaps some sort of hash of contacts to be able to bootstrap some friend graph, but that's it.
- Sharing Files: There should be a single general default "file manager" app that acts as the intermediary between your files, and other apps, giving them only the files they need for the specific task at hand. Permission for the filemanagers themselves can be given with multiple ALL CAPS permission warnings not to do it.
- Camera/Mic/Location: Trusted intermediate app should capture and provide the data needed for the task at hand. At the absolute minimum, permissions should default to only recording while the app is open (like android location now). Persistent background recording should only be allowed after multiple ALL CAPS stern warnings and suggestion to reject unless absolutely necessary.
- SMS/etc: Have intermediate trusted apps select and share the specific messages you need to share for the task at hand.
In short, data access should be handled by few, trusted, vetted, intermediary apps, with heavily gated permissions for those apps themsevles; and sharing other people's private contact information should be illegal.
I'm curious how this will change when the entire populate has more tech knowledge in general. A few decades, and everybody on the planet will have grown up with computers, and a couple more past that and everyone will have always had a smart phone.
I'm not super hopeful though. Security and Privacy are always a tradeoff with convenience. And if I've learned anything during my revolutions on this planet, it's that we humans really love convenience. I'd say this will keep getting worse until we get a massive data breach... but we've already had a few of those and aside from it being on the news and maybe a congressional hearing, nothing changes. So I think it will keep getting worse until we find out what the market will bear. And I'm morbidly curious what that will be, even as I scream into the wind attempting to prevent it.
Additionally it seems like you could design proper super warnings that get adhered to. Do you know of any interesting examples of really severe/gated warnings that are consistently ignored? If you try to visit a website with a bad certificate, for example, it's almost impossible to get to it.
True. That, however leads down the walled-garden path. Which honestly might be our best bet, but I'm not comfortable with that thought. In order for the walled garden to work, you have to trust the gardener, and I don't trust any of the current ones.
DVB as in the Digital Video Broadcasting standard? I'm surprised Android has a specific permission for this.
The only thing I'm not really fond of, is that the apps come from an opaque source (https://info.cleanapk.org/). I also found no information on how those apps are signed, and how this is checked. Upon asking them, someone pointed me to a git commit where an outdated public key of F-Droid was used.
See also https://community.e.foundation/t/microg-what-you-need-to-kno...
I think part of their approach is also to sell refurbished phones (or, in partnership with Fairphone, new ones) with /e/ preinstalled, lowering the barrier to entry. There might be more, but I'm not too familiar with them.
I hope they can make a go of it, but I think it'll take adoption by a deep-pocketed sponsor (Samsung? Huawei? The German government?) before it would be polished enough to be a real contender for non-technical users.
But I do think the idea of an Android fork that maintains some compatibility with existing apps is more likely to find success than something like Sailfish OS, that's entirely distinct.
- Occasional "X app stopped unexpectedly" messages.
- Font sizing is really weird on the built-in email app (a K9 Mail reskin)
- System webview sometimes (maybe once a week?) starts rendering blank white pages until I reboot the phone.
Edit: and Google Maps. The built-in mapping software doesn't have good enough traffic estimation.
Does it force you to have data on the cloud? Or can you get by without using the cloud?
Simply put: I don't want anyone having my data anywhere apart from me and my device.
Unlike Google or Apple, you're not required to create a cloud account just to use your own device.
... asking for a friend ...
I obviously use my own nextcloud.
Some mircrog stuff is enabled by default, which means it does allow apps to talk to Google for eg. push messages. It's not much work to disable, though.
If you truly don't want that postmarketOS and a number of Linux distros work on some older phones and the pinephone now.
People are not dumb because they're not specialized in the same field as us.
And like the color of the Ford T, you will have the choice of your phone as long as it's a Pixel ;)
What apps are you writing for yourself on Graphene?
Have you considered being a maintainer for one of the companion apps/Graphene itself on a device? The project could really use you.
I would also recommend Shelter for a work profile for non-open source apps, which one can install on one of the Play Store clones such as Aurora.
GrapheneOS does do some privacy oriented work, but it's far more focused on hardening.
I look forward to examining /e/ and CalyxOS since their focus is more heavily on privacy. For my use cases, I'm less worried about hardening than privacy.
Also, it's a lot of work to keep Android both up-to-date and de-Googled. I started patching GrapheneOS and realized I did not have the bandwidth to maintain the patchset. And still had no good answer for SUPL. Hopefully CalyxOS and /e/ have maintainers with the bandwidth.
Do it carefully, though.
About second article which is not even published anymore. - Since when collecting money by crowdfunding makes a company bad? - It is a lie that /e/ doesn't do anything new. Check here: https://doc.e.foundation/faq#is-e-lineageos--microg - the ROM still falls back to google’s DNS : This have been fixed many months ago. - th/e/y don’t accept negative feedback : I have been in /e/ chat and there is so much negative feedback there and no one gets kicked out, I wonder what he did to get kicked out.
Seriously, this all looks like someone who doesn't like privacy trying to scare people away. Admit it no one is going to use a hard to install or hard to use OS. /e/ is the best option if you want your grandmother to have some privacy while still being able to use android apps.
My experience was terrible battery life, slow to update operating system, overall lack of attention.
E Foundation strikes me as quite similar, I have high hopes for privacy in the mobile space but unless someone really can fund that indefinitely, I don't see updates going out for a $600 smart phone (499 euros) for the lifetime a phone should have.
[1]: https://www.silentcircle.com/products-and-solutions/silent-p...
If you don't have a 'droid device supported by GrapheneOS or CalyxOS, have a look at DivestOS for something more original, and privacy and security focused, without cloud "services."