NitroPhone – Pixel 4a phone with GrapheneOS
nitrokey.com
nitrokey.com
Currently Graphene does not support Network Location Providers. So, apps won't be able to get location when you are indoors and location lookups would be slow.
Also there is some strange conflict between Graphene and Calyx, for some reason unknown to me Graphene guys consider Calyx as "malicious project" (see https://github.com/GrapheneOS/os-issue-tracker/issues/632#is...). At the same time they use SeedVault which is developed by Calyx. I guess they need to add some notes on this into their FAQ.
So, while I think that Graphene has a lot of good properties (e.g. sandboxed Play Services are MUCH better than microg) and is somehow superior to Calyx, I won't recommend Graphene to a regular user who is privacy concerned but doesn't want to trade too much for privacy. For such people CalyxOS (probably a self-build) looks like a better option.
After seeing it a few times, it really makes me uneasy to use GrapheneOS. Heck, I switched back to LineageOS because of this behavior.
In the Linux phone community, we all have our preferences (I use Mobian and am a Mobian Dev), but we are very cooperative and friendly to one another. For example, I go out of my way to make sure all of my projects work on other OSes/DEs, and I am just as welcome in the PostmarketOS developer community as I am in the Mobian community as I am in the Mobile Fedora community. I personally consider quite a few of the pmOS devs to be my friend, as well as the Fedora devs I work with.
I've never heard anything akin to " malicious organization/project that's involved in spreading misinformation about GrapheneOS and harassing our developers" and if I were I'd have no problem with going around smacking some of my friends ( some I've known since ~2014 ) that work on the project.
Nowadays most of custom ROM developers are chill and there's really nothing like the old "wars", everyone is "friend" with other projects. The issues arise with these people that you called "evangelists", and I couldn't agree more. It seems like a cult. And it's always on these "super" security/privacy oriented projects.
Thank you for all the work you have contributed to.
> I've never heard anything akin to " malicious organization/project that's involved in spreading misinformation about GrapheneOS and harassing our developers" and if I were I'd have no problem with going around smacking some of my friends ( some I've known since ~2014 ) that work on the project.
That matches what I have seen with Mainline Linux devs. We all have our preferences, but we all have common goals in mind and want to help each other.
https://github.com/Peter-Easton/GrapheneOS-Knowledge/issues/...
1 - https://sethforprivacy.com/posts/community-drama-and-mobile-...
- https://news.ycombinator.com/item?id=28095033 (Log in to HN and enable "showdead" in your HN profile to see all comments)
- https://news.ycombinator.com/item?id=28095108
At that time, I wasn't entirely sure what was going on, but I did some more research and found this:
- https://github.com/AOSPAlliance/README/commit/cbd2a95cba7c2a...
- https://web.archive.org/web/20210403012439/https://freenode....
This kind of behavior is limiting the success of GrapheneOS, and there needs to be a Linus-style intervention (https://news.ycombinator.com/item?id=18000698) to get the project back on good terms with the rest of the Android ROM community.
Mentioning a project breaking the security model of the project they're kang'ing is disparaging?
Have a good day, there.
It's common for CalyxOS folks to claim to be a proponent / user of GrapheneOS or member of our community in order to spread misinformation about it or act badly in order to make the project look bad. You saying that doesn't make it true. It has become quite extreme:
https://github.com/bromite/bromite/discussions/1186
> https://github.com/AOSPAlliance
AOSP Alliance is simply CalyxOS and they made a unilateral decision to kick us out of the organization after we brought up the misinformation and harassment they've engaged in towards GrapheneOS. They invented completely false claims and their highly dishonest and malicious behavior towards us including this incident where cdesai (lead developer of CalyxOS) churned out lies about and unilaterally kicked us out of a 'collaborative' project without consulting anyone else is a clear example of their behavior.
> This kind of behavior is limiting the success of GrapheneOS, and there needs to be a Linus-style intervention (https://news.ycombinator.com/item?id=18000698) to get the project back on good terms with the rest of the Android ROM community.
That's what needs to happen with CalyxOS and their relentless, vicious attacks on GrapheneOS including here, and including you spreading them on their behalf. They've engaged in substantial bullying and harassment targeting me in particular and we have ample evidence of that including the screenshots / logs where the leader of the organization (Nick) engages in vicious bullying targeting me for my depression and attempting to gaslight me repeatedly over a period of months. He very explicitly pretended to be a friend, as did cdesai, on order to get in a position where they could cause more harm to us and myself in particular.
- https://news.ycombinator.com/item?id=28099846
- https://news.ycombinator.com/item?id=28101158
- https://news.ycombinator.com/item?id=28101118
(Log in to HN and enable "showdead" in your profile to view them.)
Branding people who disagree with you as "malicious" and "spreading misinformation", and accusing them of being affiliates of other projects, will earn GrapheneOS more opposition than support. I support just about any FOSS project, but I will never endorse the type of hostility that's being shown here.
Please reconsider the way you communicate publicly. HN and other forums are full of potential GrapheneOS users, and toning down the abrasiveness would only serve to improve the adoption of GrapheneOS.
Which is honestly surprised me.
Never had such an extremely solid android rom.
But Anuprita and a bunch of other manchildren trying to save from misinformation by flak-ing James (the business guy) lets them look bad.
Imo this is a case of asperger + frustration.
This is completely untrue and is you trying to spin your regular persistent attacks on us into us doing something wrong. We aren't spreading any misinformation about LineageOS. AOSP can use mainline Linux kernels and traditional Linux distributions often use Android kernels so there's another an example of muddying the waters.
> After seeing it a few times, it really makes me uneasy to use GrapheneOS. Heck, I switched back to LineageOS because of this behavior.
It's you engaging in this behavior.
> In the Linux phone community, we all have our preferences (I use Mobian and am a Mobian Dev), but we are very cooperative and friendly to one another. For example, I go out of my way to make sure all of my projects work on other OSes/DEs, and I am just as welcome in the PostmarketOS developer community as I am in the Mobian community as I am in the Mobile Fedora community. I personally consider quite a few of the pmOS devs to be my friend, as well as the Fedora devs I work with.
You're acknowledging right here that you're a developer in those projects and here you are acting maliciously towards GrapheneOS with falsified claims about it. That's pretty unfortunate. It's pretty sad that you folks show up whenever it's mentioned to attack it. We'll be contacting those projects about your behavior here and elsewhere. We do not consider it to be those projects doing something wrong and expect that the others involved in them don't want you spreading FUD about GrapheneOS and starting a conflict with it.
I'm surprised to be honest.
I dont know how Graphene OS has anything to do with your judgement of the developers behavior. He is quiet a reasonable person ,helps people out a lot. Anyone who comes to the matrix room with genuine interest knows that. There are of course trouble-makers who get themselves banned and then go around the internet spreading ill-will.
I dont know of anyone who was blocked because they just made technical arguments about linux phones and got blocked. It always comes down to someone shilling some linux phone, calling it more secure and distracting everyone in the room with weird conspiratorial messages. So if you know of a situation where you or anyone you know were merely making technical points about linux phones/mainline linux in some argument about some aspect of those projects and someone blocked you or accosted you please tell us here. We take care that we act in a civil manner in the room and try to have fruitful rational discussions and do not tolerate hot-blooded-loud mouthed "evangelists"
- You seemed to make an account specifically to respond to me. Is there a reason you did that?
- I debated if i wanted to call out specific instances or not, but many of them are personal ones and I didn't want to dox anyone. Based on the replies I have gotten, it seems unnecessary to do it now.
What? GPS works fine indoors.
Not in all the cases. In my particular house GPS (and all the others, Galileo, Glonass, etc) doesn't work. It may find a sattelite or two but never gets a fix, even when I stay close to a window.
That's not super surprising. NLPs will come through either Google Play Services or MicroG, and Only in MicroG do you get a choice of them.
Location lookups still shouldn't be too bad, as from what I have seen, the Modem will still keep either an AGPS or GPS lock, so toggling the location icon really only toggles whether the information is presented to apps.
I guess if I was inside a big brick/concrete building then it might not work? It seemed to work fine in my brick apartment. Anyway if I am indoors then I probably don't need GPS anyway since I am not traveling and hopefully know where I am already.
Many apps won't start when location is not available. E.g. Tinder. I guess usually people use Tinder while staying indoors.
This lets you choose non-Google network location providers (which can even be fully offline), and would be a good choice if you don't need the parts of microG that communicate with Google's servers.
Having said that, if you're already on an OS with microG pre-installed (such as CalyxOS), you can also keep the parts of microG that communicate with Google's servers disabled to achieve the same effect.
Unfortunately I don't yet have an expertise so I can explain why.
> Well, while I like a lot of things about Graphene, at the moment there is at least one aspect of it which makes it somehow unusable (see https://github.com/GrapheneOS/os-issue-tracker/issues/24)
This seems like an extremely minor thing to nitpick over...
> Currently Graphene does not support Network Location Providers. So, apps won't be able to get location when you are indoors and location lookups would be slow.
It doesn't bundle them in the OS and the OS doesn't trust third party providers. It doesn't mean that network location providers can't be used. They can still be used by apps and provided by apps to other apps such as how it works with the Play services location APIs. We also aren't going to be sending real time location information to that kind of network service, especially if it's a proprietary service from Apple/Google/Mozilla rather than something we can self-host. We don't particularly want to host a server receiving that kind of sensitive data though. We want a robust and secure local implementation respecting the OS security model for location providers. We'll need to set up generating databases for different regions, signing them and hosting them on a server. A new client needs to be developed for this.
> At the same time they use SeedVault which is developed by Calyx. I guess they need to add some notes on this into their FAQ.
GrapheneOS came up with the overall design/concept of SeedVault and it was implemented by a member of our community long before CalyxOS existed. They started funding development work on it but they didn't create it and it isn't inherently their project. We fully intend to fund development on improving backups and will be splitting away from what SeedVault has become for various reasons including their actions against us. The developer they're funding to work on SeedVault is NOT hostile towards us but their involvement is concerning to us nonetheless.
> So, while I think that Graphene has a lot of good properties (e.g. sandboxed Play Services are MUCH better than microg) and is somehow superior to Calyx
https://grapheneos.org/features explains what it provides.
> I won't recommend Graphene to a regular user who is privacy concerned but doesn't want to trade too much for privacy
It has much broader app compatibility, so what are you trading away for better privacy and security? Is this entirely about the OS itself not feeding your location to Mozilla to get back a location estimate based on their proprietary Wi-Fi data and the openly available cellular data? The cellular data would be put to much better use by via regional databases distributed from a first party server, with a first party location service locally consuming them while respecting the security model for this.
> For such people CalyxOS (probably a self-build) looks like a better option.
All simply because we don't do include a network location service? Really?
> Also there is some strange conflict between Graphene and Calyx, for some reason unknown to me Graphene guys consider Calyx as "malicious project" (see https://github.com/GrapheneOS/os-issue-tracker/issues/632#is...).
It comes down to the CalyxOS project and community spreading misinformation and attacks on GrapheneOS and GrapheneOS developers across platforms along with engaging in substantial harassment. Our project members have been regularly impersonated by clearly fake sockpuppet accounts too, which were then used to engage in ridiculous false flag attacks such as https://github.com/bromite/bromite/discussions/1186 and the Monero incident brought up below although with the spin that we did something wrong when we were impersonated. It has become ridiculous, with this misinformation spread whenever GrapheneOS is brought up and with our developers subjected to substantial bullying and harassment.
You're a member of the CalyxOS community doing exactly the kind of thing that has led to this situation, including what you did on our issue tracker. It may seem small, but you started a whole pile on from the usual suspects lying about it here and you're representing CalyxOS whether you like it or not. They welcome you in their community, as they do others, and encourage you to attack us. Nick himself has directly engaged in vicious bullying and harassment.
I'm not sure why but even with PS installed "Network" location provider never returns anything.
> It doesn't bundle them in the OS and the OS doesn't trust third party providers.
A user-installable package may be a good option?
> We want a robust and secure local implementation respecting the OS security model for location providers. We'll need to set up generating databases for different regions, signing them and hosting them on a server. A new client needs to be developed for this.
Maybe you are not aware, but isn't "GSM location provider" doing exactly that?
> It comes down to the CalyxOS project and community spreading misinformation and attacks on GrapheneOS
I guess you should create some kind of a FAQ entry explaning your relationships with Calyx and other distros. For a random person who just tries to find a good solution for their needs all these in-house dramas are pretty obscure and demotivating.
> You're a member of the CalyxOS community doing exactly the kind of thing that has led to this situation,
You've mistaken me with someone. I'm a passerby. Something is wrong with your perception. As I said before, I have same traits (I'm an Asperger and I had some depression-alike problems) though I've learnt to keep these traits more or less under control. Maybe it's a good idea to seek an advice.
> including what you did on our issue tracker
I posted a comment saying "there is also DejaVu location provider which is used by Calyx". I don't know why you think I did somehting wrong, I'm sorry if this bothered you SO much.
> They welcome you in their community, as they do others, and encourage you to attack us.
I'm not attacking you anyhow, I think that your project is very good and in many aspects superior to other projects, though as an end user I found it somehow inconvenient because of the NLP issue. Moreover I'm really impressed by your work on sandboxed PS. Nothing more.
How did you come to this conclusion? I've seen a number of accusations such as these from yourself, and am wondering where they seem to come from. Normally, you seem to be mistaken.
https://github.com/GrapheneOS/os-issue-tracker/issues/24 is the feature request for this and the other one was closed as a duplicate in favor of it.
I was searching for this information but it wasn't immediately available on their site.
Of course once support runs out it's another matter.
3 years from the date of release is horrible. My iPhone 6S is coming up on 6 years of OS updates and will get at least 1 more with iOS 15.
That being said it would be nice if they could provide support until a CPU-level vulnerability is found. (Or is there a decent chance that they wouldn't be informed?)
On the upside I believe that the Pixel 5 has a Google-"made" SoC so that excuse is gone now. I would love to see a nice long promise of updates. The amount of eWaste generated by a phone every 2 years is awful.
For context Apple promises 5 years from the last sale and in practice supports devices even longer https://support.apple.com/en-gb/HT201624
I don't think Google can change anything about this really. Qualcomm is the only non vertically integrated vendor of SoCs with the wanted features and quality Google needs (apple is vertically integrated). They don't have any buying power towards Qualcomm. In the hardware business, they are a niche provider. 2% market share in North America, world wide even less.
Seems like Graphene only provides legacy support once Google drops support.
So its Graphene for non technical people. And in a few weeks they'll propably slap their own Fdroid Repo on top for any vendor apps.
I cant actually say if that is a good thing or not.
At least if they install vanilla Graphene, you can use attestation to verify that the os is signed by the official GOS key.
Pixel 4a on Amazon Germany is 399€. I recently bought an unused one for 300€ and needed about less than an hour to slap Graphene on top including doing attestation before and after install and storing the output.
So they crudely calculated want 230€/PersonHour. I guess the real person gets somewhere under 100€/h and the rest is put in to business reserve.
I havent seen any option to remove Mics. That would require to remove the display which is glued and fragile with an over 10% chance of killing it. Pixel displays are from 70€-150€ a piece.
> Open source allows verifying absence of backdoors.
Are all drivers and firmware open-source?
- VoLTE and SMS over LTE is a proprietary library.
- WiFi calling is a proprietary library.
- the Vendor partition is entirely proprietary, and at least for the Pixel, is different depending on if you use the AOSP version or the stock Google Version.
- For the Pixel 3a, you cannot even POST the phone without adding a proprietary library! I would be shocked if it's different for the Pixel 4.
I know for a fact that you cannot even boot a Pixel 3a without adding proprietary libraries.
If the reader is curious, feel free to look here and try it for yourself:
https://wiki.lineageos.org/extracting_blobs_from_zips.html
https://grapheneos.org/build#extracting-vendor-files-for-pix...
In my opinion, if Nitrokey was at all serious about making this 100% open source and secure, they would help mainline the kernel for it.
Edit: https://social.nitrokey.com/@nitrokey/106861801899442589
Its not 100% open source.
- option to have mics de-soldered
- graphene installation is done for you
A further oddity is that the "Buy" page has vector imagery instead of photographs of the actual device.
The only trick is that you have to make sure that your individual hardware is OEM-unlockable. The easiest way to do that is to buy a new device from the Google store; otherwise, you need to get the seller of a used device to check, or to just try your luck.
[1] The Pixel 3 will soon by end-of-support by Google, and then by GrapheneOS. But I had a Pixel 3, and I wanted to try GrapheneOS a while before I invested in a Pixel 4a or 5a for it. (So far, everything is solid, and I hope to stay with GrapheneOS until I can justify a Librem 5 or similar.)
this being said, my personal viewpoint is that a phone is the last device in the world where I would consider to do any kind of banking activity.
I made the switch to GrapheneOS recently and its been quite pleasant overall, relative to expectations.
Everything else just works, barring notifications for some apps and things that are obviously Google-oriented (e.g. google camera). Also, location is seriously degraded, because it actually _only_ works with GNSS, as far as I can tell.
I've been making the switch to sites pinned to home screen for things that aren't useful offline (banking, weather) and that's been working well, but largely unnecessary. I just really don't trust Android apps generally.
Yes, there are. In order to log into Revolut web UI you need to confirm your login through their app.
There are many other examples but so far I didn't find any single banking app which doesn't work on MicroG.
From what I've heard russian Sberbank doesn't work without safetynet though.
What's not working: apps using strict SafetyNet checks, in-app purchases (on MicroG), GPlay license checks (on MicroG). And rest assured, location services will be a real pain in your ass on Graphene (and sometimes DejaVu may deadlock on Calyx, better turn it off completely and replace with "GSM Location" Unified NLP backend).
Nitrokey is the world-leading company in open source security hardware. Nitrokey develops IT security hardware for data encryption, key management and user authentication. The company has been founded in Berlin, Germany in 2015 and can already count ten thousands of users including numerous well-known international enterprises from various industries.
> Our sandboxed PlayStore is also incomplete
Is there any detailed documentation about this chip?
It's notable that GrapheneOS only currently supports the Google Pixel 4 and 5.
e.g. Peter Easton wrote a short piece here https://github.com/Peter-Easton/GrapheneOS-Knowledge/blob/ma...
Conversely, what indication is there that Titan M is more likely than any other chip on any of your devices to be backdoored?
How do you suggest we prove this negative?
Just buy a Pixel and install yourself, cut the middleman.
Well, with backdoored HSM module tracking is the least of your problems.
This is an odd phrasing since a cryptographic hardware key does allow tracking (in a different way), so the fact it's different seems hardly relevant. For example a compromised Titan M could open you up completely to MITM of any network connections your device makes.
It could also allow any entities that already have some limited access to your device (i.e. an app restricted via OS perms) to gain broader access to sensitive data on your device.
If you need protection against malicious states or corporations specifically targeting you, this isn't good enough for the reasons you point out.
If you just want to avoid google tracking you via their various services to show you ads, this is probably sufficient.
I just thought the phrasing was a bit odd and absolutist, and somewhat misleading. I'd generally put a reasonable amount of trust in a Titan M personally - the risk factor compared to Play Services is minuscule - but I still want to be aware of the mechanisms of risk. Implying it's non-existent doesn't help anyone.
https://arstechnica.com/tech-policy/2021/06/fbi-sold-phones-...
Nitrokeys: Smartcards + MCU and rather shitty GUI software for controlling them, compatible with standard crypto tools like gpg-card. Gen < 3 is missing the hardware button that Yubi has. The HSM model has a fancy smartcard. The Start is a triple GnuPGCard with usb.
The Pro can be used for attestation with HEADS firmware.
The Nitropad is just a refurbished x230 with coreboot and heads. Kinda pricey for my taste.
The open-source nature of a lot of their offerings is a big selling point though, you're right. I overlooked that
There are many different treat models and I believe that most of the people just want to get their privacy back.