Show HN: DivestOS – Long-term support for end-of-life Android devices
divestos.org
divestos.org
The biggest issue for long term cell phone support is, even if we get an OS with a 10-year security update timeline like Rocky Linux, will the phone itself be able to make calls on whatever cellular networks exist 10 years from now? I have a number of 3G phones I bought as recently as 2018 which became paperweights in 2021 when all of the cellular telcos in the United States stopped supporting 3G, forcing me to update to a 5G phone. Is 5G going to still work in 10 years? Or are the telcos going to continue to convert perfectly good phones in to landfill?
As someone who has a 15-year-old laptop which is still a perfectly good Linux server (its screen went out two years ago, but it was a perfectly good desktop computer until then), it’s annoying seeing phones I bought less than six years ago be useless on today’s cellular networks.
An os that will let an old device live on as a wifi only device is sorely needed.
But unless I'm mistaken, if a device only has 3G, and you want to travel with it away from WiFi, you can't even get 3G data on the device, as they shut off the 3G networks in the USA. Best you're gonna find in some rural areas may be 2G or 2.5G.
The planned obsolescence of today's mobile phones makes me sad.
However, in case of mobiles, things are particularly awful because it is often not trivial to install and maintain an OS other than the one supplied by the manfucturer.
It's incredible how much electronic waste and security issues are generated by lazy manufacturers who do not mainline drivers into the Linux kernel.
The problem with long term support for Android devices is absolutely short security update windows, i.e. short term support for Android devices. Pixel comprises a tiny fraction of Android devices sold in the US, and a miniscule fraction worldwide.
Anyway I got a Pixel 5 and now use T-Mobile’s instead of AT&T’s network (via Ting, since I use little mobile data and that gives me a phone with a low-bandwidth data plan for $15 a month + tax), since T-Mobile is better about supporting legacy phones and protocols.
In terms of the “waste of spectrum” argument, I think it’s better for the earth to “waste” some spectrum than waste millions of perfectly good phones. One takes up landfill, the other doesn’t. But, to each their own.
Now they have a phone whitelist restricted to (mostly) mainstream brands...
What's the reasoning behind doing this?
Your laptop may be good, but it will probably only support some ancient insecure slow WiFi profiles.
Distributions start to drop old hardware. And there are always new CPU and other chip security bugs discovered, how do you get fixes for that into your system?
I'm fairly certain that some phone models out there are probably better in this regard, especially if you can swap out the battery, the components are of decent quality and they're built in a rugged way. Also, somehow the idea of repairing your phone has gone out of the window, since you can just buy a new one.
> Your laptop may be good, but it will probably only support some ancient insecure slow WiFi profiles.
For many, slow Wi-Fi is acceptable. Same with a dated and slow CPU/RAM, which many will still consider better than their devices becoming e-waste. If the OS wasn't so locked down, many would enjoy having a stand-in for a Raspberry Pi for all I care, since the small form factor of a phone would lend itself nicely to DIY hacking, especially because of included camera and networking. Even if the hardware is lacking, that doesn't mean that we shouldn't or couldn't support the software for longer amounts of time.
Your point about the hardware itself and what it supports becoming insecure is a good one, but there's no guarantee that the amount of time for something like that to happen would be much shorter than any improved OS EOL period. Of course, if it's some non-critical functionality that's insecure, it might as well be turned off in software, like older versions of TLS in web servers.
> Distributions start to drop old hardware. And there are always new CPU and other chip security bugs discovered, how do you get fixes for that into your system?
We could cross that bridge when we actually get to it, and try to figure out the things that are easier to do first and foremost: notably software support. If something like Ubuntu LTS has an EOL of 5 years and AlmaLinux has security updates for 10, I don't see why Android versions should be any different, unless governed by a profit oriented corporation.
Aside from that, it's surprising that 3G can just be tossed away like that on a national level, since the amounts of e-waste this would generate is kind of staggering, even more odd is the fact that in many places 2G is still in operation. I guess at least that is a bit of a silver lining, if the claims were to be true (citation is needed, but it sounds like a sane argument): https://en.wikipedia.org/wiki/3G#Decline_and_decommissions
> Technology that depends on 3G for usage will soon become inoperable in many places. For example, the European Union plans to ensure that member countries maintain 2G networks as a fallback[citation needed], so 3G devices that are backwards compatible with 2G frequencies can continue to be used.
5 years of updates is still a short time. We only have one planet...
> The biggest issue for long term cell phone support is, even if we get an OS with a 10-year security update timeline like Rocky Linux, will the phone itself be able to make calls on whatever cellular networks exist 10 years from now?
I don't think this is the biggest issue : operators usually maintain a certain type of carrier for at least 20-30 years (in France, we are only talking about shutting down 2G - which still raises a lot of issue because of the many IoT devices using GSM...)
The biggest issues are IMO
- lack of parts to repair old phones
- no possibility to manage bootloader keys / relock the bootloader (not even mentioning devices with locked bootloaders)
- "stable-api-nonsense" ideology and no BIOS/UEFI/ACPI for smartphone => no way to have "one firmware to rule them all"With an Android bootloader UEFI app on top to mimic what Android wants on top...
UEFI alone isn’t exactly useful when you need per device kernels (and associated modules). It’s just one slice of the problem.
Highlights include:
- Mull (https://gitlab.com/divested-mobile/mull-fenix), a privacy-focused fork of Firefox similar to LibreWolf
- Hypatia (https://gitlab.com/divested-mobile/hypatia), a malware scanner that uses ClamAV signatures
- MotionLock (https://gitlab.com/divested-mobile/motionlock), automatically locks device when it is face down or has not been moved
I thought I was going to find a site that found a way of running newer Android over the old one to not have to worry about drivers and such, but I found yet another distro with support for SOME devices. I also thought I’d find support for an oldish Kindle HD8 I’ve been wanting to repurpose.
This is not to say that it might be great and all, I just felt a bit mislead by the title and I would like to find out if I’m just not seeing something.
> Bootloader relocking is restored and has been tested working on 23 devices and is available for 26 more. Verified boot is also restored on 36 of those devices and is enforcing once locked.
Edit: looks like almost all the devices with relocking support are Google / OnePlus / Fairphone, so it might not add anything in this regard to GrapheneOS. No workaround for the signing key issue, I guess.
They also seem to be doing some security hardening and blob removal, although I'm not sure how that would affect driver / device support.
The support is in the form of all the added security features, the (system) updates, and kernel patches like this: https://gitlab.com/divested-mobile/divestos-build/-/blob/mas...
Here it works ~perfectly...with one problem, i could not connect to a hidden wlan, but absolutely great job from DivestOS, thanks!!
https://wiki.debian.org/Mobile
Using a chroot will always be the easiest way to do this though.
This is more of a statement to the shit show of modern Android. A company worth $1T+ can’t be bothered to figure out how to support devices more than a couple of years and it’s left up to a random developer.
"They" has been an acceptable default third-person singular pronoun since at least the 1400s. If there's something you'd prefer, it might be wise to list it on one of your user profile pages.
Either way, I suppose "he/she" could be used instead if that really is an issue?
They is more inclusive! ^^
> For your sake (Iewell) // I am glad at soule, I haue no other Child; // For thy escape would teach me Tirranie // To hang clogges on them.
[0]: https://www.oed.com/view/Entry/200700#eid1288185420
[1]: https://en.wikisource.org/wiki/Shakespeare_-_First_Folio_fac...
(I suppose postmarketOS is similar in spirit)
Does building a GSI make sense to cover more devices? Or would that not make sense in this context?
Great Job and project, thanks again!
This is all well documented on the website, please read through it.
You can get a fair bit of benefit from using the boot.img like you say, but it will only go so far.
While I wouldn't recommend it, there are flashable ZIP images of microG, but it'd be at the downsides noted here: https://divestos.org/index.php?page=faq#rootSupport
Not everyone can buy a device.
But if you have an EOL device, DivestOS seems to be an amazing alternative to just staying on the stock firmware that is not going to get any updates at all.
For example checkm8 back in 2019.
With app to GPU communication being mediated by the kernel.
So the idea is you be able to easily upgrade or even multiboot different android or linux images if you wish, without having to recompile for every device.
I don't know how much of a success it has been, and I don't think it has been used to multiboot a phone or to boot a more standard Linux.
https://android-developers.googleblog.com/2017/05/here-comes...
I thought mobian was distributing a GSI to do non-Android on the Android base, but I can't seem to find it if they do that.
Also, bear in mind that this almost intentionally doesn't solve some support problems - any bugs/vulnerabilities in the base layer won't get fixed by GSIs (which is why DivestOS says it explicitly doesn't ship a GSI).
Legacy phone hardware... harder to justify.
The only real chance is to get behind brands like Faiphone.
And they have similar limitations to what I do here with regards to firmware support, as they offer longer support than Qualcomm actually does for these chips used.
The only devices with proper aftermarket OS support and five years of updates are the Google Pixel 6 and 7 series.
I mean it makes sense in a way, but all of this stuff seems to be built for very bursty behavior
Where does a lay-consumers even start? Do I buy a used, but well supported (by alt OSes) phone? Which one would that be? Do I attempt to use my existing phone?
Recently I feel like alt OSes have become really mature. I have been using a de-Googled /e/OS on a Fairphone 3+ for 1.5 years and I don't have anything to complain about the system. Even the store now works very well.
So I'd say, for your next phone, choose something that is well supported by those alternative OSes (typically Fairphone is), so that you can try, and fallback to stock Android if that's not working for you.
The other projects who support some of these older devices have numerous issues as noted here: https://divestos.org/index.php?page=patch_levels#osSecurity
Edit: also of note: DivestOS currently provides monthly updates spanning seven versions of Android, I don't know of any other project doing that specifically.
Don't get me wrong, it's terrific that security patches are backported to such ancient versions of Android by those working on DivestOS and it's a great option for devices that aren't supported by GrapheneOS, LineageOS, et al.
https://gitlab.com/divested-mobile/firmware-empty/-/blob/mas...
This is indeed an issue and is documented on multiple places of the website.
Patching everything else is the best harm-reduction for this.
Now if you're buying a device planning to run it, that's fine, but it really does limit its usefulness.
I recently got an unofficial build of LineageOS running on a Nexus 4 (mako) device and I was positively surprised with the speed it can run modern software. But this is an unofficial build that is also broken on some essential points, such as WiFi.
For these old devices, Graphene is not an option and if there are others targeting the same devices as DivestOS (which I will surely be checking out soon) I have yet to see them.
Not sure what you mean about their ecosystem, I personally don't have an eCloud account. They have a NextCloud integration that I don't use but could work with your self-hosted instance.
So yeah, no lock-in as far as I can tell.
With /e/OS I haven't seen such a thing, it just feels like a nice community.
Then I've seen exchanges between the GrapheneOS author and some Calyx people on some GitHub issue, and they were borderline insulting each other. At this point is difficult for me to believe that somehow the GrapheneOS author is always the victim. And if that's the case, then that's bad for the CalyxOS community anyway.
Maybe that's misinformation, and they all love each other. Maybe not. How could I tell? What I see is that I would not want to be part of such discussions.
It's always a question of threat model. The /e/OS experience is perfect for me, and I am convinced it is much more likely to reach my friends than e.g. GrapheneOS, which is much more into security (at the cost of UX).
In the end it's good to have the alternative, and to realise that they target different profiles.
Do realize that combined with their Advanced Privacy app which routes users over Tor, it can very well result in HTTP only connections being MiTM'ed.
I've seen it with some of my own users recently and their RSS feeds being hijacked.
I ask /e/ team every month to do something about it and they don't, yet users keep trumpeting them and buying devices from them. It is downright negligent of them.
I use Firefox, not their chromium-based browser. I can't mention an app that I use that is using a WebView though... I remember there was one, but I could set it up to use my browser. I use their PDF reader, I'll have to check that.
> Do realize that combined with their Advanced Privacy app which routes users over Tor, it can very well result in HTTP only connections being MiTM'ed.
I don't route over Tor.
Or is there a list of supported devices for DivestOS already? the 2 devices are an old Alcatel and some random OEM Android (LOGICOM).
For a copy of the stock OS you can usually find it on the vendors website.
The precursor to GrapheneOS also used to have a non-foss license for a period of time.
There is an older condensed list of changes here: https://gist.github.com/thestinger/ee536cbd1ca674b94dde05831...
Newer changes are in the updated repos.
The name sure is pretentious.
The situation has got so bad that regulators should probably get involved.
Important software people depend on such as banking or electronic payment apps can't be used with relatively safe and maintained operating systems, forcing the use of unmaintained, insecure stock system just to get SafetyNet these apps wrongly require.
Why can't Android do the same?
Now say you want to get updates from upstream regularly. Every time, you may have conflicts with your patches, and you have to fix them. That's costly, so why would you do that for old phones people already paid years ago?
Long story short, I believe it's easier for Apple to not break compatibility with old iPhones than for an Android OEM to stay up-to-date with upstream.
What exactly makes mobile special?
Or more succinctly, because phones won the race to the bottom.
I guess it's different for laptops, somehow.
p.s. status on this? thanks https://github.com/phhusson/treble_experimentations/issues/1...
This is basically what I was getting at.
Sure, Google could release newer Android versions (assuming they'll run under whatever last kernel version Qualcomm provided support for, which isn't always the case), or at least release patches for flaws in Android itself, as long as they'd want to, but after the chipset support runs out, they can't update some drivers and firmware. I think it's not unreasonable to just declare those devices as insecure and move on.
Google has managed to get support up to five years, but only on newer Pixel devices. I'm sure that wasn't an easy negotiation.
Apple, in contrast, builds all the hardware and software in iPhones and iPads, so they can decide to support devices for as long as they wish.
1. The lockscreen bypass security flaw of last week is major compared to any flaw Qualcomm currently have.
2. Apple still updates devices hit with checkm8, so maybe security doesn't dictate everything for them. Not sure why it needs to for Google.
3. What does security has to do with getting Material You to my device? (to give just one example). Maybe the idea is that if a device is insecure, then it must get to the trash bin...? I hope not.
They only supported the 5C for two years after they sold the last device.