Google shifting to “upstream first” Linux kernel approach for Android features
phoronix.com
phoronix.com
1. There are many features that we feel very valuable to our OS, so we will implement them and ship our OS without blocking on upstream approval and acceptance. 2. Maintaining these patches is expensive. We will try to upstream as much as possible. 3. Most of our patches have been upstreamed and most new kernel requirements are lower priority, we should prefer to upstream first to reduce the cost to migrate our OS from the original implementations to the upstreamed implementations.
At no point does it seem that the decision was "wrong". Obviously carrying a bunch of patches has downsides but at the earlier points in the OS lifecycle getting the features was probably much more valuable than the downsides were harmful.
Most Android devices these days have bootloaders that cannot be unlocked, preventing device owners from installing custom kernel images onto their devices. And even if you have a phone where that isn't true, Google's SafetyNet will prevent you from using many crucial applications, like your bank's Android app, on that handset.
It's an awful situation for people who would rather install software provided by a third party onto their hardware (due to not trusting the device manufacturer enough to only include software in their best interest, which is a very reasonable stance in my book), but I don't think there's a way out any more.
Worst comes to worst you can decompile it and take out the checks, but it is admittedly a huge hassle.
Right now at least, there's no hardware attestation on many devices so you can just install Magisk and hide the fact you're rooted pretty easily from SafetyNet and still pass.
How long do you think it will be before a country requires that all smartphones support this? And how long before it is a requirement for laptops too?
If you do not trust the OEM, replacing its ROM with GrapheneOS / CalyxOS / LineageOS isn't going to help much anyway.
One right answer to this is fully open-source (hardware and software) phones like the PINE64 and Librem, among others.
[citation needed]
I'm finding the majority of devices to be unlockable as long as you don't buy your device from a carrier.
Carrier locked devices are not typically the norm but in the US.
And if you truly cared about software freedom, you wouldn't be buying carrier locked devices in the first place.
I really wish people would stop griping about losing security features when you flip the one switch that ensures the security of the system. Unlocking the bootloader means it is now possible to modify system files. Of course Safetynet is going to fail. The point of Safetynet is to ensure the system hasn't been tampered with.
However, despite all of your doom and gloom posturing without actual examples, I've yet to actually use a single app (and I use several banking and root detecting apps like remote features for my car) that will prevent me from continuing to use the app if rooted. It just pops up and says "We see you're using a rooted device, this is not recommended." I click "OK" and proceed as normal.
The alternative is to use Apple and whelp, that'll never happen... since I actually do care about software freedom.
That's pretty much drinking the DRM koolaid. You can have both, verified boot and freedom. All it takes is a mechanism to replace the manufacturer's trust root with an owner-supplied one. The process would wipe anything secured by the trusted components (including keys securing the user data) but that should be fine since you can make a backup.
The only thing that wouldn't work is software that wants to ensure that the user has no control over the system - DRM or "the user is too dumb to be trusted with their own device" security theater.
Not the user with a CS degree that knows what they are doing.
And even if everyone were to install malware. There are other ways to secure banking. E.g. by providing an external token with a display. This is how hardware crypto wallets and some PIN generators for in-browser banking work. Or they could ask the owner to upload the attestation pubkey to their website, then the bank could still check if it's really their app that's running (as confirmed by the boot trust chain). I'm not sure how fingerprint scanners are tied into secure boot, maybe they could be used to verify user intent too.
Except the app is remote-controlled by a malicious “display driver” that waits for the user to do all this authentication set-up, transfers the money away, “are you sure”s it, then prevents the user from seeing any of the on-phone scam warnings until it's too late to reverse the transaction.
Freedom to do what you want with the device you purchased is a right that is not to be infringed upon, especially not for the reason "the users might hurt themselves".
Setting up a technically nontrivial flow to unlock the bootloader (e.g. connect the device to a machine with an SSH client, approve SSH connection request with scary message, SSH to the phone, execute a shell script that tells you that you shouldn't unlock this unless you know what you're doing, and after confirmation the script unlocks the bootloader) is more than enough of a deterrent for the vast majority of non-technical users.
The remainder are acceptable casualties - people who refuse to read warning labels are going to have other bad things happen to them anyway (drinking poisons, injuring themselves while working with power-tools) as a result of their foolishness, and the solution to that is not to take away the power-tools from the whole population, but to train them to read and follow warning labels in the first place.
Those technically skilled users who want to unlock their bootloaders (and, you know, do what they want with the devices they paid for) should not have to pay for the stupidity of a small minority of foolish people who refuse to read warning messages.
The consumer has the right to buy from companies that sell products that actually fit their purposes, like I don't know, a computer, instead of trying to replace the firmware in a toaster.
As such, your comments in this discussion, and this one in particular, do not appear to be in good faith.
Hence why radios are kind of locked down to makers that could make use of illegal radio frequencies, some of which could even be damaging to human health.
My faith is that not everything with a CPU has to be open to install Linux on it.
This irks me. Not everyone has such choice about what to buy.
Not an excuse anymore. Motorola has universal devices that work on all carriers. Including the most difficult ones in the US, Verizon and AT&T. The unlocked Motorola devices are also often cheaper than getting a device through a carrier.
There is always a choice. There are multiple devices at given price point.
Taking credit to buy a mobile is not a wise choice ever.
Googles own devices not only allow you to unlock the bootloader, but to relock it with your own signing keys. So your statement is just wierd - if you care, vote with your wallet and don't complain how "most devices" don't give you feature you're not ready to pay for.
And does it let you pass SafetyNet and run most of the apps. AFAIK it's not so re-lockable bootloader is useless.
This isn't always possible or realistic. The cheapest Pixel phone is worth 2+ median monthly salaries in my location.
All other devices are subsidized to be just an advertising platform for their producer. Real prices of devices are those that you consider "premium".
I believe that the ability of a device owner to exercise the same level of control over it as the company that manufactured it is a matter of consumer rights, not features.
OP's comment is accurate because Pixels are not "most Android phones". You also don't know whether or not OP already owns a Pixel, so I'd say it's "weird" to tell them not to complain without knowing whether or not they have already voted with their wallet.
Avoiding Google/FB/Amazon/Microsoft or whatever your megacorp of choice is is becoming increasingly hard, and it absolutely deserves being talked about. As do any other things in which our choices and freedoms continue to be snuffed out, and that point should be able to stand alone, without being weighed against things like "Vote with your wallet" or "But in Y thing we have more freedoms now! Why does X matter?" These conversations are also worth having, but they shouldn't entirely replace the a call for alternative paths.
The poster wasn't just complaining about "most phones" but claiming there was no solution.
It seems perfectly reasonable to point out that there is a solution that works at both the individual and global levels. If you want to control your own android devices, there are several good options and if more people start making those choices then the overall situation will also improve.
If you believe something else is being snuffed out, it would help to mention what it is so people can help you. Because making that statement without context doesn't really stand alone, it's also just noise.
And in the case of vendors who haven't...?
You say that such complaints are just noise to Google because they have already acted on these complaints (ie, Pixel bootloaders are unlocked). On that, I think you and I agree re: pointless complaining.
I'm asking, why not continue to complain in an effort to push vendors with locked bootloaders to unlock them? Specific vendors are irrelevant, I'm just curious if you do/don't think people should complain to them, as well.
My comment is not about specific vendors and their actions. My comment is only about wondering when, in your mind, is a valid time for people to complain; a philosophical question. That's why the question is broad - is it OK for people to complain about vendors who have yet to take action?
Your comment just now suggests that, yes, contrary to your post complaining about complainers, you likely think it's fine to complain to/about vendors who haven't taken action you'd like to see taken.
Edit: Your logic in the last paragraph doesn't follow to me, as I was responding to a specific complaint. So that's another reason I can't really give an answer to the question.
1. Anti-user mechanisms (SafetyNet) annoy users.
2. Even though SafetyNet may not be as annoying as something like UAC, it still has deep reaching effects[1] since now the standards are proprietary and nobody can make an actual good UI alternative to the garbage dog-slow banking app.
The irony is your stale rhetoric only applies the other way: Users who were saved by "risk analysis" and firewall type systems don't know they were saved and don't care.
1. I assume this attestation is checked on the app's server - I assume Google signs their attestation that your device is "good" and this is verifiable by the server of the banking app. Otherwise the in app checks could just be nopped.
If other manufacturers decide to ignore the reference... well, that’s bad, and worthy of criticism, but it's at least good that the reference is open!
> And even if you have a phone where that isn't true, Google's SafetyNet will prevent you from using many crucial applications, like your bank's Android app, on that handset.
There is still MagiskHide, though it often requires a bunch of trial and error to get it working. In addition, there are still banks with apps that allow you to install them on rooted devices (N26 in Germany is such a bank).
[0] https://www.xda-developers.com/magisk-development-continues-...
You can still buy phones with bootloader which can be unlocked, such as sony[1], but I agree that most doesn't have this option.
The fact that google's proprietary services are necessary for most proprietary applications to work doesn't mean that there isn't a value in a phone running kernel which is closer to an upstream. When you run a custom operating system based on linux kernel, you are less likely to run the proprietary google services anyway.
[1] https://developer.sony.com/develop/open-devices/get-started/...
These new policies allow more "cross pollination" between mainline linux and the fork used by android. Waydroid running smoothly on an unmodified kernel is a result of this.
Waydroid is important "for practical software freedom" because it allows pinephone and librem-5 to run android apps.
I don't think that installing your bank's app is a good idea. First, banks are interested in collecting as much data about their customers as possible so the app will be used as a spyware. Second, installing an app eliminates second factor for authorization - now if your phone gets hacked, the criminals will be able to steal all your savings.
It is better to use only bank's website from desktop computer and use a phone only as a second factor to confirm transactions.
There's nothing about "freedom" in this post, it's all about developer's convenience. It's easier to keep local changes and push them later if the upstream is not changing much. If your upstream is a moving target, doing anything but upstream-first is only making it worse for yourself in the long run.
Nothing to add regarding bootloader locking and safetynet on top. I don't want multiple phones (I actually don't want one), but I was forced to to install my banking app 2nd factor app. I cannot root it, I cannot remove GA, safetynet prevents me to reflash it with something else, even though I theoretically can.
The best part is that at some point you can choose between:
- old/vulnerable/unpatchable android with safetynet => banking apps will be happy to work with it
or
- new fixed android which is safer, but won't pass safetynet
Yeah.. "safety".
I've seen other banks here _charging_ for the hardware OTP dongle separately. The yearly price of the dongle was more expensive than simply getting another crap phone and installing the app.
Whenever you estimate something bad to be inevitable like this, please consider the many terrible inevitable things in the past. Those in the past thought they were inevitable, but they weren't.
- everyday violence on a much higher level than today
- inability to correct mistakes of government in the long run (voting, free speech)
- lack of power of women
- vulnerability to many diseases
- protection of law
I think any one of these is composed of many traditions that when I think about them seem almost impossible to come about, in the same way that an evolved animal seems remarkable: how did that ever happen? They do happen! People worked hard and incrementally to make them happen.
Estimating them to be inevitable I think can be a discouragement to that hard work.
The reason Google appears to be doing this is not software freedom, but enabling longer software updates. Google themselves cannot provide anything remotely competitive to iOS updates if Qualcomm or other SoC vendors effectively keep their proprietary Android builds hostage. Getting stuff mainlined and unshackling Android kernels from vendor shenanigans is a very, very important step. The Google Pixel 6 is the first time in a long while an Android phone excites me, just by virtue of Google's credible 5 years of update promise.
To your point: practical software freedom has been very, very hard on Android from the start. Smartphones are complex devices, and the custom kernels they run have barely been successfully reproduced anywhere else. You can find a small handful of old devices that you can get up and running in a somewhat acceptable state, but you have to restrict yourself to hard to use old stuff to get anything workable at all.
While more software freedom is not really a goal of this project, this does potentially have side effects of more software freedom down the line. Similarly, Google's Project Treble has not delivered everything people wanted, but does allow people to run say (a buggy version of) Ubuntu Touch on a fair number of Android phones [0]. In the Android ecosystem, you have to count your blessings. (And hey, it's not iOS or Windows Phone either!)
[0]: https://forum.xda-developers.com/t/gsi-arm64-a-ab-ubuntu-tou...
Really, I don't get why Google with all its financial and legal power hasn't made sure from the beginning that all manufacturers should open source their kernel code, datasheets etc. - this would have prevented so much e-waste...
> this would have prevented so much e-waste...
E-waste is effectively profit for the device manufacturer. Discarded phones mean that the whole portable computer that is still more powerful than what we had in universities 20 years ago has become worthless and needs to be bought again. It's created an income stream for the manufacturers -- and that's why they're not incentivised to fix these problems. I'm using a OnePlus 5 -- officially EOL and Obsolete! -- with modern LineageOS Rom and it flies. Of course, "official" apps don't like that at all (which is downright stupid of its own reasons), but I have got around that.
I'm sure OnePlus would rather that I threw the thing away and bought another shiny model to get Android 11. Frankly, I'll use it until it breaks and hope that the FairPhone people have caught up by then...
People will never reliably spell it right, so you have to wonder whether it's a great choice of name for an OS.
I checked the other day and it's still true.
I still have yet to see even the most remotely reliable source that indicates Fuschia is actually going to replace Android.
Reminds me of when people were so absolutely sure that Android and ChromeOS were going to be merged.
Never happened.
I really wish people would stop repeating hare brained tech blog gossip and speculation as confirmed roadmaps.
https://android-review.googlesource.com/q/fuchsia
Also in case you missed, Android apps now run on ChromeOS.
In case you had problems comprehending it the first time, ChromeOS and Android were not *merged.*
The rumor has been around since 2015.
https://www.theverge.com/2015/10/29/9639950/google-combining...
Running ones' apps on another OS is not merging the two.
The ChromeOS/Android merger claims are still unsubstantiated. Pretty sure you'd find a fair number of AOSP/Android commits in the ChromeOS repos.
Still not convinced there's any actual evidence of Fuchsia replacing Android here.
"RFC-0082: Runnning unmodified Linux programs on Fuchsia"
https://fuchsia.dev/fuchsia-src/contribute/governance/rfcs/0...
And also, Fuchsia's license is more permissive than Android's.
Meanwhile, Fuchsia is actually slowly testing the waters in production.
https://techlog360.com/fuchsia-os-on-first-generation-nest-h...
It is no accident that Project Treble follows a similar architecture to Fuchsia drivers.
Fuchsia's license being more permissive than Android is exactly the end goal.
It might not come tomorrow, but it will come.
These commits don't show that they're replacing Linux with Fuchsia, they show that they haven't killed Fuchsia.
"RFC-0082: Runnning unmodified Linux programs on Fuchsia"
https://fuchsia.dev/fuchsia-src/contribute/governance/rfcs/0...
Let’s come back in at least 8 years or a decade and we will see if ‘Fuchsia’ actually replaces Android and even ChromeOS then.
I won’t be surprised if they do, given that is where they are heading.