It does.
I have an FLX1, a review sample.
https://www.theregister.com/2025/02/03/furiphone_flx1/
I had 3 app stores on mine: Amazon, F-Droid, and Aurora. Apps from all 3 worked.
I thought there was a robust android emulator for linux such that I could run android apps - and call an Uber or whatever - from desktop linux ...
Is that not so ?
There are some but not really great and it will become impossible very soon with remote attestation and play integrity. Already Uber is one of the few apps that have the hardware attestation keys for grapheneos manually added.
Beg to differ: https://linuxphoneapps.org/
(And no, that does not list all of them. Only all I got around to adding.)
The Bank of America app runs on Graphene without issues however. So generally speaking it is not true that banking apps don't run on de-Googled phones. Here it is the developers that are to blame if they enforce compliance with Google's requirements and don't stick to the basic FOSS version of the OS.
GrapheneOS can only pass a check for BASIC integrity. It cannot pass a check for DEVICE or STRONG integrity.
STRONG integrity is hardware-backed (think TPM) and is not spoofable. DEVICE integrity can be spoofed and there are tools to do it, if you root your device, but Graphene does not want to this for various reasons. [1]
It is up to the developer of every app to choose to use this API or not, and to lock some or all of the features of their app behind this API.
GrapheneOS actually supports hardware integrity (the STRONG variant), but in a particular way. Every OS integrity API (including eg. Secure Boot) is based on a list of master keys, that are installed with every computer. Users that want to install custom operating system that are not signed by a major company will have to enroll their own keys into the Secure Boot system.
Hardware integrity also requires root keys, and those are owned by Google. But the API is actually general enough to allow both a "Verified" (signed by a root Google key) and "SelfSigned" custom keys. GrapheneOS provides a guide [2] that describes how to adapt the hardware integrity checks to accept either a Verified key or a SelfSigned key from a list of keys from GrapheneOS.
There is no reason why app developers should not accept operating systems signed by GrapheneOS just like those signed by Google, for the simple reason that it provides the exact same anti-tamper protection.
Note that all this anti-tamper protection is, in the end, an effort to protect users from others hacking their devices and gaining access to their apps. These measures do not help companies per-se, since user commands should ALWAYS be verified server-side.
[1]: "they use fingerprinting techniques such as GPU fingerprinting and send along that data, which enables detecting and banning spoofing. It is NOT practical to pretend to pass these checks. It is only possible in the short term at a small scale. It will get banned and stop working."
[2]: https://grapheneos.org/articles/attestation-compatibility-gu...
This is the stated reason, but the behavior of it is anything but: if they really cared, they would fail massively outdated versions of android that have critical remotely exploitable vulnerabilities, but they do not. It is also much easier to tamper with a ROM slightly and have a version that passes these checks, compared to having a secure, up-to-date, maintainable ROM that passes.
A mobile OS fundamentally needs a different application model -- apps can't just decide to run whenever they like. How will desktop GIMP know that it shouldn't waste my battery when in the background (unless it very specially requests it throuhg an API made just for that)? Does suspending it work as you expect? For how long will you suspend it, shouldn't you kill it as well after a while? Who saves stuff?
I can't help but feel that anyone strongly advocating for a GNU Linux phone (because let's be honest, Android is the linux phone) is just not familiar with the actual context of what it entails.
Even if we assume that a good chunk of that may be "duplicate" in terms of functionality (e.g. todo apps), that is still just a completely different dimension of apps and use cases covered by android natively.
It's Linux, if you need something you or someone else will eventually write it. But first there needs to be acceptable, working hardware. Enter the FLX1/s, and we come full circle.
Besides, open-source doesn't have to be GNU, there are a bunch of open source apps on F-Droid.
I don't need more than a handful of apps, one being a browser. These already exist.
I'm glad Waydroid is a thing for folks that are, and sorry attestation prevents full compatibility. But neither issue should get in the way of investment in modern Linux phones, which I've been desperately waiting for, for years.
Web apps are still a thing as well, believe it or not.
That said, Google Play is not really the thing to compare this too. F-Droid could be. Summing up the "Show all ..." counts, F-Droid clocks in at 6147 apps, and it started way earlier (2009? 2010?).
Some of these F-Droid apps (specifically those created in QtQuick or Flutter) should also run with very minor tweaks on #MobileLinux.
Also, there's more than these 720, some are just very hard to evaluate (because they are for hardware or services I don't have/use), which then keeps me from adding these apps.