GrapheneOS: The private and secure mobile OS
grapheneos.org
grapheneos.org
For those who are considering it though, its worth noting that the community has a very... Confrontational style of correcting others though.
Not a dealbreaker, but a nuisance. It can feel like being back in grade 8 again with the class know it all.
Still, I am a happy GrapheneOS user, I just hope the OS doesn't suffer from this situation. Also, those Pine64 offerings are becoming more attractive with every update.
I didn't know Sony had an "Open Devices" program, so thanks for bringing it to my attention. Apart from the price of their phones, I think that makes Sony a strong competitor to Google for people who value privacy over security and want a really good phone (spec-wise) that can flash a custom ROM out of the box.
This is wrong. The OP is wrong, and you provided a partial explanation with additional wrong information.
GrapheneOS has minimum device criteria, and currently only Pixel devices meet that. All the other commentary is nonsense.
Or do you mean Sony's latest device releases? The open firmware program is only for the midrange devices like the Xperia 10 and XA series before that, and of course it depends on having a maintainer. And new devices take time.
Jolla has both free and paid Sailfish OS license for some Sony open devices phones - https://shop.jolla.com/ ...
Its the only smart phone that can guarantee the radio is off when you put it in airplane mode.
The PinePhone can't?
You do have options:
1. Do you want to buy a third-party device like a NitroPhone? If you can afford to purchase a phone in the first place, then purchase a used phone to try flashing GrapehenOS. You can buy multiple used devices for the cost of such a device, and then you can familiarize yourself with the flashing procedure.
2. Have a friend help you. There are probably events in your town that you could find on Facebook, Reddit, or Meetup (e.g., OS install parties are a thing).
3. Wait for the official project to begin selling their hardware: https://twitter.com/grapheneos/status/1490518600339308544
Seriously though, pick up a Pixel 6, flash it at home via Web-USB.
My only qualm is that the Google bootloader doesn't show a QR code on boot to verify the kernel image being loaded, instead it simply shows a big yellow warning saying the OS is unsupported with no way of verifying if it's the GrapheneOS image you loaded or one the maid loaded while you were AFK.
I have hated android not meeting my own personal watermark in respecting open dev and privacy forward user design at its core. This project, although not core and on the fringe, gives me a small glimmer of hope in a dark smart phone world! Been a stable daily driver for like six months now.
Once upon a time it at least showed part of a hash or somesuch ostensibly uniquely identifying the OS, such that it would change if an Evil Maid flashed a new one.
I honestly don't know why we can't have a system to visualise the signed image source as the default. Put any public key you want in the firmware, show a 32-64 bit fingerprint of the loaded key as an abstract pattern and only boot an image signed with that key. Manufacturer doesn't get any special treatment.
Fairphone at least shows a hash on boot as well as the scary yellow text when relocked. Calyx is available, don't know about graphene.
Many people have tried to pay me to make them a custom ROM based on GrapheneOS but with their name and reskinning notepads and encrypted chat apps. They'll claim it's for privacy-focused businesses of course.
I would be interested, they all seem nice.
On the other hand, Calyx does actually include an app store with the base ROM. This is important if you are setting devices up for other people who need to be able to reproduce the steps you have taken. In such a case, even though I could set up Graphene myself, I would probably suggest Calyx. However I know that graphene are (were?) Working on a store of their own at some point, so when that is released my opinion may change.
Both are very usable in my opinion.
AviD's rule of usability applies here, IMO. Doesn't GrapheneOS's approach have worse third-party app support than CalyxOS's approach? I can see that leading to people trying GrapheneOS and then saying "none of my apps work on this more secure version of Android, so I'll just stick with stock Android from now on."
If people start from a device they own, then they can actually fight the other battles. Install facebook in a work profile for now but try and get some friends to move to xmpp. Install uber if and only if you're stuck and public transport has stopped for the night (and uninstall it after). Or any other compromise between complete submission and full device ownership.
Graphene as a project doesn't really seem aligned with this idea. Calyx and /e/ are a bit better.
A phone that my partner owns that I can actually realistically ask her to use is better than one that is secure against an attack that isn't even in my threat model and is a complete non starter.
Wait, do they actually do this too, or is this a hypothetical you made up for the example? Or did you mean Snapchat instead of TikTok, which I know does actually do that?
This isn't even correct anymore. "Sandboxed Play services" is essentially just play services but with the ability to uninstall it, and deny it permissions.
Graphene's approach is not inherently untenable: using the play store can be done via a separated profile - which is probably good opsec anyhow.
An alternative approach (which I believe the Graphene team are aware of, but don't necessary encourage) is to use F-Droid or the Aurora store. I believe there are some important shortcomings with this approach though.
In regards to 3rd party stores, I wouldn't use this approach for any kind of corporate or professional application, but if you're an end user there might be a case that this is preferable (suppose privacy is a much greater concern than security). I think that would be case by case though.
In the case of F-Droid, the apps need to be built using F-droid's build system, and is signed using F-Droids own keys[1], rather than the devs signing themselves. Not awful, but definitely not good.
So, regarding the 'too hard, gave up' problem you mentioned, I think you're right that its an important consideration, but disagree that Graphene's approach is "strictly" worse third party support.
I know the Aurora Store works fine for installing apps from the Play Store. My concern is more so whether those apps all work right after they're installed.
They have their own store now, https://github.com/GrapheneOS/Apps/releases.
Currently, it lists only graphene apps like Secure Camera, graphene PDF vewier, Auditor, Sandboxed Play services. Also, it only works for Android 12 and above, not only on GrapahenOS but other OS like Calyx, Lineage and it forks etc.
They are planning to add other graphene apps too, like Vandaium* etc. Non-graphene apps (like apps available on f-droid), I don't think they will be added. This store seems to be only for Graphene Apps.
https://github.com/bromite/bromite/issues/2141
https://lulz.com/the-grapheneos-controversy-ztxotgwx-280962/
https://libreddit.pussthecat.org/r/PrivacyGuides/comments/ql...