A closer look at e/OS: Murena's privacy-first 'deGoogled' Android alternative
techcrunch.com
techcrunch.com
Please see this independent comparison table: https://eylenburg.github.io/android_comparison.htm
And additionally the reviews by Kuketz: https://www.kuketz-blog.de/android-grapheneos-calyxos-und-co...
See also my table that shows historical release dates for monthly Android Security Bulletins: https://divestos.org/misc/a-dates.txt
and the Chromium (WebView): https://divestos.org/misc/ch-dates.txt
It would be nice to have just the one or two options, with app store and some kind of official entities backing (say, states, or universities, or distros).
It's weird that the article doesn't mention microG even once, since it's what /e/ uses instead of the Google Play Services client.
true
seems like the whole aftermarket android ecosystem hinges on the functionality of this, mostly unrecognized, component
Degoogling is not deblobbing and Lineage or /e/ use plenty of closed source software during runtime. The top parent and DivestOS author really is deblobbing* to some degree, but forks of LineageOS that introduce measures of "degoogling" hold onto vendor firmware blobs on androids /vendor partition for functionality. Those aren't known for connecting to the Google hivemind though.
* https://github.com/Divested-Mobile/DivestOS-Build/blob/de3ba...
My interpretation of the term degoogling fits the second part of your sentence, "getting away from online services": it is user agency in what network connections can occur, so either by default or optionally users can stop any signaling coming from the device they use. They don't have that freedom with the software the device came with.
What I don't get about this is that a lot of people who install custom ROMs do so, to ungoogle their devices, and just plainly get rid of Google. So why exactly is Google deemed to be a safe hardware vendor?
I don't care that deeply about privacy/security, just being a bit devils-advocat-y.
On the other hand if you're trying to avoid an oppressive state, you probably want to avoid any potential for a sub-poena to a big corp yielding information on you; in which case considering fully open firmware makes much more sense.
I even got one of these and all I did with it was install a couple of different distros, since then it's collecting dust as it's unbelievably slow and the battery lasts for about 2 hours.
I won't doubt that you know that iPhone is a thing.
What privacy is that which is not accessible?
GrapheneOS has good reason to only support Pixel devices, they consistently do the right thing with regards to relocking, verified boot, CFI/SCS support, strongbox support, and even now MTE support.
Many other devices fail to support these, eg: https://divestos.org/pages/faq#kernelCFI
Even the FP4 shown in the article is fundamentally broken and trusts the AOSP public test-keys for verified boot: https://divestos.org/pages/faq#deviceBootloader
To me this is leagues ahead of any other degoogled experience because at any time I can temporarily turn on Google when I need it (and I often do). But it doesn't defeat the purpose because for the most part you can just turn it off
If you don't mind the battery drain and having both profiles running it is just a menu drop down + single button and ~1 second wait and you have your other profile.
Personally I hate the battery drain so the process for me is a menu drop + single button and ~3 second wait and then unlock pin and I am in my other profile (not ideal, but far better than anything else if you want degoogled).
You can even get notifications from other user profile(s). This is absolutely impossible with dual boot.
So I would say they are not targetting the same users and you can't really compare them equally.
There are old versions of GrapheneOS for older devices, and some devices are still in extended support, like the Pixel 4a (although not for long I expect). So if you are OK with the compromised Galaxy S9+, you could also be OK with the compromised Pixel 3a, which received the June 2022 security patch in GrapheneOS[1], while the S9+ received the March 2022 security patch[2]
[1]: https://grapheneos.org/releases#2022081800 [2]: https://doc.samsungmobile.com/sm-g965f/dbt/doc.html
There's tons of value on the software side on GrapheneOS and those legacy devices could benefit from it.
So I'm running CalyxOS on Fairphone and I've gotten almost all play store apps to work via MicroG and anonymous login on Aurora store (in-app purchases don't work).
AFAIK the only reason why Google Pay NFC payments don't work is because Google Pay keeps a list of hardware and OS that's allowed to use that feature, and GrapheneOS is not in that list. It's not an OS limitation.
There was an open issue to spoof this data so that Google Pay NFC payments, among other Google features behind this check, would work. But it looks like it got discarded 2 days ago: https://github.com/GrapheneOS/os-issue-tracker/issues/1986
They recommend that app developers adopt the much stronger and vendor-neutral Android hardware attestation API instead.
Wait, what? What did I miss here -> https://github.com/GrapheneOS/os-issue-tracker/issues/1986 ?
The only things that don't work that I've noticed are android auto (I don't use it anyway), Google passive / offline music recognition, and Google pay.
I thought Google pay not working was a known issue, so I'm surprised you say it works for you?
* McDonalds international app ("phone insecure")
* Pokemon Go's VR
* Android Auto (but will "soon")
* Google One's backup & restore
Oh, OK then. Hard pass from me for this little experiment. Coming from a former communist country this is the equivalent of "I guess if the neighbor is not using video to rat you to state police he's a good guy and you can trust him with your anti-communist ideas" attitude. The river bed of Danube-Black Sea channel is ridden with the bones of people who trusted their neighbors.
Yep, and this is why most people won't care.
the first downloads a handful of useful apps and stays with them
the second downloads apps on a dayli basis
the first group can be can be weaned off with pwa'shttps://gitlab.e.foundation/e/devices/android_device_fairpho...
https://gitlab.e.foundation/e/devices/android_device_fairpho...
microG itself connects directly to Google: https://github.com/microg/GmsCore/wiki/Google-Network-Connec...
and /e/OS default enables those connections: https://gitlab.e.foundation/e/os/android_prebuilts_prebuilta...
including the default download and running of the proprietary Google SafetyNet binaries: https://gitlab.e.foundation/e/os/android_prebuilts_prebuilta...
Kuketz covered the connections made in full at the very end here: https://www.kuketz-blog.de/e-datenschutzfreundlich-bedeutet-...
No shit, of course they do.
>In general, we obviously try to minimize the connections to Google, but some services strictly rely on them and would just not work without.
What exactly do you think they should do instead?
Or by activating the Play Store and installing a couple Google apps, am I negating all the privacy benefits I would get from a deGoogled Android?
> Your @murena.io account is at the center of the your private digital life, allowing you to store, back up and retrieve your data safely on remote servers.
Not very private
Google is an advertising company. I expect them to serve ads based on their reading of any Gmail emails, Drive documents, or image analysis of Google Photos, any Google Search/Maps queries, any Chrome browsing, and notifications/app usage/other entries in Googleified Android.
That makes storing documents in Google's cloud significantly not private.
Murena's whole reason for being is privacy, if it came out through whistleblowing or user analysis that Murena was analyzing and selling user data... that would (I hope, though I have less faith than I used to) that would sink the company.
I'm not paranoid enough to think that Google or the FBI is attacking the CalyxOS supply chain with rootkits that analyze/upload data on Murena phones in the same way they do on regular Android phones because that data is not useful to them. If they can't show ads in your murena.io email, why would they go to great lengths to read it?
I do think that the only option left for those who are individual targets of investigation from a nation-state or international mega corporation is to not use cloud services and smartphones.
https://community.e.foundation/t/service-announcement-26-may...
Per https://docs.nextcloud.com/server/latest/admin_manual/config...
> The encryption app does not protect your data if your Nextcloud server is compromised, and it does not prevent Nextcloud administrators from reading user’s files. It encrypts only the contents of files, and not filenames and directory structures.
I still prefer a straight-up linueageOS install...
About this part, I'm not sure I understand.
"deMicrosoft" was, and is a thing. See "windows 7 umattended edition" or "windows 10 reclaim scripts". Same with android and custom roms.
Corporate greed bloats up perfectly fine operating systems for as long as I can remember, and de-bloating them has and is still a thing.
Stock android is not so bad (2023); android has to cater to a broader ecosystem of vendors and hardware, hence the heterogenity and the overall not streamlined experience that comes with it, that much is certainly true.
If you like android though deGoogled alternatives are good but they're a niche