Android 17 is the first since 3.x to add new APIs without releasing to the AOSP
grapheneos.social
grapheneos.social
Bigger problem is HarmonyOS and similar devices, compatible with Android. Opensource threat from china!
And no NSA backdoors or honeypots!
Otherwise there's no need for NSA backdoors (as Cellebrite matrix shows) :)
lmao
Not particularly relevant but the lawful spying implemented in the telecommunications system by our own government has been abused by Chinese hackers as well.
Pre-7 was just not an operating system that anyone except the geekiest of geeks wanted to use.
Windows Phone is a case study of missed opportunity.
Android won because it was available "right now" and easy to hack. Vendors could get a BSP (Board Support Package) from a chip manufacturer, slap Android userspace on top of it, and ship a phone within half a year. It was a glorious mess for a while.
Google then slowly tightened the reins and made the ecosystem more ordered.
I'm interested and wishing to see a future mobile OS that does not pander to the "attention economy" like Android/iOS are, but with billions now addicted and trapped by it, I'm realistic that it won't be an overnight success.
Android is not a Linux desktop or server distro. It is not about you getting to put what you want on the hardware you bought for free.
Operating systems are hellaciously expensive to maintain and that only gets worse in markets with rapid hardware improvements, as the smartphone market was up until maybe the late 2010s. Google is not a charity. SV did not come into national prominence for making investors $0. There is no money in giving maybe one in one-hundred smartphone users (and that's being generous) a bunch of code, for free, so that they can put it on their gizmo and talk to their nerd friends at their hacker meetup.
When they pitched Android as "open", they meant that carriers and device makers could load it up with all of the revenue-enhancing bloat that they wanted. In return, Google got a device that would let them hoover up all of the data they could ever want in order to build better ad service profiles for those using the devices. That is, after all, their business.
For a while, this could coexist with us screwing around with a real-life tricorder. At some point, though, the free stuff turned into a revenue opportunity that had to be exploited. And so, it will be.
Wish I could upvote you twice for that line alone. It perfectly sums up what I always wanted Android to be. Alas, the closer we are to this in hardware, the further away we are getting in software.
(Did they fix that whole "store contacts in a linked list" problem in Android already?)
Intel used to do the same with their anti theft technology aka Intel theft deterrent on their classmate PCs, so students had to enter unlock codes from an IT admin every 3 months or every say 200 boots to prevent the computer from being locked at the bios level preventing it from booting an OS, and there was an update which disabled that functionality permanently. And you would be warned when you had around 50 boots left to get the unlock code.
With a 6 digit code cracking it will take close to a year on average. With your screen pattern example it's around 100 days. That's more than enough time for the owner to notice and turn on anti theft features. Maybe even for the police to find and return the phone.
I would say pins are even less secure because people usually set it up as something like their birthday and thieves also often simultaneously steal some id card in a wallet which has exactly that.
I think we're all more surprised by how long it took for Google to make these bad moves. For a period of time in the 2010s we actually started thinking maybe Google was alright.
This is to extent that some carriers still insist that they design phones and phone manufacturers are just factories. People need to understand that power dynamic before blaming those "mere factories" for not making Linux phones.
There has to be like an SVP of SoandSo Wireless pushing like three pillar approach of iOS, Android and Linux. Otherwise the pitch decks for any alternative phones just go straight to trash(or into a motorized shredder if it is still physical).
Only in the USA.
Edit: September update for 8a has a kernel build from July. I believe it's still vulnerable but the exploit will need its offsets adjusting etc.
It'd be interesting to see which one is happening here.
GrapheneOS is often around 4 to 6 months ahead on merging Linux kernel LTS releases. We used to handle this ourselves but switched to the Android GKI LTS branch maintained by Greg KH. Unfortunately, it was often struggling to keep up even before the absolutely massive increase in Linux kernel security patches this year. AI models have rapidly accelerated vulnerability discovery and it's an ongoing crisis for the Linux kernel. We want to be on the latest LTS revision within days and want to be using the latest LTS branch within months of it being released. We're not at all happy with how Android is handling things and plan to fix that ourselves. We'll get things back to how they should be.
We also ship all the AOSP userspace patches months before Pixels due to shipping all of the security preview patches as soon as possible. There are sometimes minor regressions but we find and fix them ourselves downstream. The security preview system has a terrible design especially considering that frontier AI models can reverse engineer the patches. There should at least only be a source embargo for around 24 to 72 hours rather than pretending as if it can work with the patches available 2 to 6 months in advance.
Perfect is the enemy of good. What's better for privacy, an old but inexpensive smartphone running Android 11, or the same smartphone running an up-to-date third-party rebuild of Android 16 or newer with as many privacy-improving bells and whistles as the hardware can support?
> Soon there will be two different phone brands which you can install it on.
...will they be available in my country (Brazil)? I don't think I've ever seen a Google Pixel phone in person.
Not sure if you have any experience with eBay. I looked it up and people had problems selling to Brazil [1] but there are various listings that offer to ship. So maybe not a great option.
KaBuM!, Intec Store, Performance Solutions all charge significantly more with a 10a being more than double than from Google.
Motorola officially sells the Signature in Brazil [2] at the same price or cheaper than in the UK. It will be supported by GrapheneOS in 2027 on the 2027 version. From then on, hopefully Qualcomm brings MTE to the non-flagship chips and Motorola and GrapheneOS support budget or midrange devices.
>perfect is the enemy of good
I don't consider that relevant when users deserve ≥ security than an iPhone. GrapheneOS is not purpose-built to avoid big-tech's services although it does that more completely than any other alternative mobile operating system, the focus is privacy.
GrapheneOS on the state of privacy and security for their ethos: https://x.com/GrapheneOS/status/2044440381803069778
[0] https://www.ebay.com/sch/i.html?_nkw=google+pixel+9
[1] https://reddit.com/r/Ebay/comments/1d92pyn/
https://community.ebay.com/forum/shipping-57923/topic/diffic...
[2] https://www.motorola.com.br/smartphone-motorola-signature/p?...
Do these phones have ANATEL certification? Because if they don't, they will be rejected by customs. It's not simply a case of the item being held until you pay a 60% import tax.
I see your point, but it would be very misleading, since the phone would still have a lot of known holes. Only the OS would get updated, typically not the drivers, driver firmware, possibly not the kernel. The phone would still be easily compromised through all the known RCEs. So you tie up non-profit projects in a lot of extra work to get an improvement that does not really matter.
This is a mess created by the OEMs and they will continue to create this mess until people will stop buying from OEMs that only give lip service to security updates (roll out Android Security Bulletins to show a high patch level, while in reality the phone the phone has many known CVEs).
Android Security Bulletins set a very low bar since the AOSP patches are available to ship by OEMs 2-6 months prior to the bulletin being published. It's also only High/Critical severity patches being listed. Due to a recent policy change, it's also officially only a subset of the patches for AOSP. That's visible through the Android platform components having patches in the Pixel Update Bulletin for September 2026 despite those being applicable to other operating systems. It's because they no longer want to backport all High and Critical severity patches due to the high volume of issues discovered by AI models. It's similar to how they stopped backporting any Low and Moderate severity patches years ago due to high volume.
You understand that just having a firewall is a big step for security?
Whould you recommend using a Pixel 6a in 2026 even though it has no hardware memory tagging (MTE)?
Enough to know that it is as fingerprintable as any other phone. Disabling Javascript JIT will not change that.
They're not treating GrapheneOS very differently from other vendors, except that Graphene isn't relevant enough to sign a contract with because they don't make phones (or money, really).
Google should be putting out the code and patches like they used to, but the constant badgering of Google on this issue feels off. I don't see anyone complaining that Samsung isn't supporting their security-focused fork enough, or complain that Apple is delaying the bootloader unlock process by a day.
Despite their very worst, selfish intentions, Google is the very best vendor of commercial open source software. While Google's open source project collapses, there's plenty of space for other vendors to step in.
We should bemoan Google's fall from grace, but only because they're on the way to becoming just as bad as every vendor but Librem if they keep this up another decade.
https://source.puri.sm/Librem5/fw/firmware-librem5-nonfree
https://source.puri.sm/Librem5/arm-trusted-firmware
I hope I'm looking in the wrong place.
Can we just stop saying "Google" as if it's same faceless org? No, it's not Google, one or two asshole execs are behind this policy.
> Google simply regrets android being open source.
Android wouldn't be what it is if it wasn't open source. With all the work from outside Google. The same is true chrome.But they won't learn that on their own. They are breaking the deals. So we move. We force their hand
What do you have in mind?
This is the message that Firefox needs to push: Hate ads? Use Firefox.
Also, switching browsers is trivial. I do it on my parents' machines and they don't notice
The GPL is worth nothing if nobody is enforcing it aggressively.
Accompany it with a written offer, valid for at least three years, to give any third party, for a charge no more than your cost of physically performing source distribution, a complete machine-readable copy of the corresponding source code, to be distributed under the terms of Sections 1 and 2 above on a medium customarily used for software interchange; or,
Many people argued that 'customarily used for software interchange' is worded-as is to always be relevant to the times when the license is applied and that providing access to a Git repository is customary nowadays. In fact:
- The upstream Linux tree is distributed through Git.
- The relevant Pixel kernel sources used to be distributed through Git.
IANAL, so I am not sure how this part of the license will hold up in court, but the spirit is clear. Providing a Google Drive link is not customarily used for software interchange.
Also, I think it is fairly clear that the procedure is put in place to make everyone's life difficult, given that the relevant source used to be distributed through Git.
With something like a browser (engine), I'm totally okay with someone saying "I'm an expert and I'm trying something with my own vision/priorities. I don't want input from random people that I have to spend time evaluating."
Only GPL is somewhat immune, because Stallman was always right.
This is why they are developing their own kernel.
I've been using it for more than 20 years.
I don't know why either of use loled though
I’m not doubting they added some ai junk somewhere. But whatever they did seems very easy to ignore.
A simpler, better time. I miss it :(
IOW:
Don’t threaten to stop using Google Chrome if they do one more evil thing. Start now.
If the goal of a hard fork is "the community will invest equal resources that Google does today" then you wildly underestimate how many engineers work on Chrome.
Not at first. Yet over time the work increases as one must differ more and more from Chrome. I believe that's why so many forks are giving up on Manifest V2.
Under the hood, what the MV2 uBlock can do and Lite can't is at the least stripping tracking parameters from links and block 3rd party trackers that are cloaked in a subdomain of the originating site.
The thing is that most of this is invisible to people who already live within Google’s bubble which is probably why they don’t get called out for it. The promotion is visible mostly to those of us who don’t, and it gets irritating.
Chrome was better than competition pretty much all its lifetime and there's plenty of historic articles to prove it, no matter how much your emotions refuse to accept the history.
We were there and we didn't install Chrome via some made up toolbar installer, but because it was significantly better than what Mozilla and Internet Explorer offered.
https://www.osnews.com/story/25184/adobe-tricks-users-into-d...
https://www.labnol.org/software/chrome-with-adobe-reader/201...
https://forum.filezilla-project.org/viewtopic.php?style=246&...
> nearly 10 % of the installers came with a third-party browser (e.g. Chrome)
https://www.sciencedirect.com/science/article/pii/S016740481...
Actually, use it now.
The actual maps are much better in osm than in Google.
That reminds me, place reviews using ATProto. Kinda surprised that no map client jumped on that when it's the exact thing you need to replace a centralized service. A lot of people use Google Maps to find businesses more than directions.
Because of their enshitification we do have alternatives that were developed.
At this point the their only services I'm using are Maps, Translate and Keep Notes and it is mostly due to lazyiness as all of those already have alternatives.
Edit: forgot about YouTube, which is ironic, because that one is a toughest one because the value comes from creators, but I'm doing my part and using GrayJay[1] so I can follow them if they switch their platform.
Playing at their table is a losing game, the house always wins.
Android is even more of tragedy, given how all relevant NDK game development APIs are also available on GNU/Linux.
The reason why no one runs AOSP is because the phone market rewards differentiation. Each phone manufacture wants to build their own experience and building on top of AOSP is how they do so.
Is it really a losing game? Building a new OS from scratch is not worth it. Why throw away an entire app catalog for your device? Consumers want access to existing app catalogs when buying a phone. If anything is a losing game it's building a new mobile operating system over forking Android as a base.
Technologists need to aggressively reject solutions which don't spread freedom to ordinary users as well.
AI generating code changes the game significantly, though there are issues with that. A new OS would have taken several millions and multiple teams, but can now be done for far less. The problem is hardware to run it on. Who'd pay $2,000 for a shittier phone with less features when a $500 used one with GrapheneOS is right there? So the market, (in)efficiently, hasn't come up with a new phone OS. Not because it isn't warranted, but because the free market isn't a perfect system.
https://www.reddit.com/r/ClaudeAI/comments/1wfpydl/i_asked_c...
No, the reason is that AOSP doesn't even include a functional keyboard nor a functional call manager nowadays.
AOSP apps were abandonned around Android 11, you can't just keep them as is for real users, it looks amateur.
Even the open-source ROMs came to the same conclusion eventually and developed their own.
No one was using those apps so it didn't make sense to spend time on them.
Don't be a prick.
This is what empire-building middle managers say to rationalize their boondoggles, but in actual fact most customers can't even tell the difference between two different vendors' Android skins, definitely can't tell the difference before they buy one, and the way they actually differentiate phones is on real hardware differences that show up in the specs like the camera or performance.
The hardware company's idiosyncratic fork of the software is irrelevant at best and annoyingly irregular in the common case.
You forgot about one thing they care about above all others — cost.
And the easiest way to keep costs down is through "alternative revenue streams", which involve your own tracking, your own app bundling deals and your own App Store, which you're pushing on users constantly. And if you do that, you may as well get the branding win from doing the custom skin too.
Assuming you can get a hardware vendor to support your fork.
Android has always been a weird blend of proprietary BSPs wedged together with the core AOSP project - we used to have an entire team whose full-time job was merging the Qualcomm BSP into our AOSP fork. At the time you didn't even get access to that BSP without inking a deal with QCOM...
It is completely insane how many people work on Chrome. It seems like it is time to deprecate web browsers and do something different. Like you get a frame-buffer to draw on with something like a wasm vm. Web pages get replaced by programs (which they essentially are anyway). Get rid of 99.9% of the cruft that has accumulated over the decades in browsers. If you want to have some of that cruft, that is a library you have to send.
It should be the users choice how their browser renders, it's their damn browser. Instead, browsers are built to follow standards that mostly favor the developers preferences above those of the person who actually own the device rendering it.
The modern web is user hostile by design.
A lot of websites back in the 90s were just made up of images that were clickable using image maps. It was not a fun time.
I get what the parent comment is saying, though, and it's why I use Gemini (the protocol[0], not the AI). It doesn't align with corporate interests, but for now I consider that a good thing.
Think "an interactive visualisation for choosing a seat when buying a concert ticket." That's not a "traditional" webpage, should work on whatever device the user is currently on (so native is unsuitable), and shouldn't require the user to install anything.
People clearly want web pages to be exactly this; we're on iteration #3 of the idea now. Iterations 1 and 2 were Java Applets and Flash, not necessarily in that order, and they were massively popular despite their shortcomings. Clearly, if we somehow deprecated the web as it is now (which is an utterly ridiculous idea, which makes me really curious what comments like yours are exactly trying to achieve here), as long as we keep it an open standard, users will choose browsers which offer this capability in some form. We should appreciate that the current iteration is an open standard which anybody is free to implement, instead of some proprietary blob that you need to license from Oracle or Adobe.
So do hackers. A big chunk of the open standards revolve around sandboxing malicious code, and given the amount of tracking happening anyway, fail at it.
The biggest thing standing in the way of this is actually Apple, since they don't allow competing browser engines or equivalent so you can't make something like this for iOS whatsoever.
Doing that in Safari doesn't work twice. First, if Safari doesn't already expose whatever GPU primitives you need to do things efficiently, you can't get them. And second, your API implementation (which is likely to be large) would then have to be distributed by anyone using it instead of being part of the browser they use for all sites, creating a >100MB dependency for a <50kB web page.
As for the styling and fonts - it's all a bunch of low-key trade-offs here. The businesses want to exercise total control over the end-user experience, for sales/marketing and branding reasons. At the same time, going off the beaten path quickly makes development costs skyrocket.
Flash was a good choice back when all visitors were using a PC and there were like 3 different screen resolutions to choose from. Once laptops gained popularity, this started to shift, then pre-iPhone mobile briefly became consideration, and Flash stopped being sufficient; then iPhone came out, killed Flash, and started an era where every visitor has a different screen than the previous one. "Responsible web" became the cheapest option, and you can see its evolution as a trajectory towards giving more and more control over experience to developers, and less and less to the users.
Otherwise, explain Flutter.
If AMZN couldnt make their fire whatever it was called fork of Android really grow, what chance has the community got ?
Difficulties maintaining a sufficient number of contributors to keep the project viable have persisted for several years. In January 2015, the project reported a lack of active developers and code contributions.[49] There have been continual problems providing timely fixes to security vulnerabilities since 2015.[50][51][52][53] In September 2016, OpenOffice's project management committee chair Dennis Hamilton began a discussion of possibly discontinuing the project, after the Apache board had put them on monthly reporting due to the project's ongoing problems handling security issues.[54][55][56]
Sounds like AOO is effectively dead, so this example is a fail to my challenge.
OpenSearch & ElasticSearch both seem alive, as well as OC & NC.
Neither https://github.com/privacyidea/privacyidea or https://github.com/eduMFA/eduMFA say either is a fork of the other.
I think you failed to share 3, 2 seem to valid examples of my challenge but the other 2 are questionable.
You didn’t ask for examples where both projects are alive!
NetBSD -> OpenBSD
To some extent I would argue that Linux is a spiritual fork of Minix and Unix.
But I think it’s also worth pointing out that these were in vastly different times where a single person or a small group of people could maintain an OS. An OS or browser is vastly more complex now.
BSD is a killer example of that point, too. Using a BSD Unix got to be pretty difficult after Linux containers became hegemonic.
Safari started as a fork of KHTML, and Chrome started as a fork of (the open-source parts of) Safari.
I think they're fully aware of this. They just don't care, because the goal of "get market share super high" has been reached, so now they have no need for it to continue being open.
I don't disagree about what that means we should do; I just don't think we should assume they're being naive here. It's like writing a program to play chess; you should select your move assuming the opponent is smart and will make the optimal counterplay rather than assuming weakness, and then if they end up being less smart than that, you're still in a good place.
A lot of the people now in charge of large organizations have never been down in the trenches. Or even near them.
They operate in an abstract world with very little connection to reality.
Google needs to be broken up.
You do care about the market and aren't just angry because a corp doesn't listen to your orders, right? RIGHT?
It’s search. And ads.
So yes, I do think they are being naïve. The stance is myopic. It is only a good move in the short term, and barely even that. It is under the false belief that we operate in a zero sum game.
Also in the last century most software was commercial, and thanks to business friendly licenses we are back to demos, PD, Shareware and co, only with new names for a younger generation.
Google will do just fine.
I’ve seen many open source contributors deflated because they wanted to share their code/solutions with other individuals and the world to learn from only to have their work sold as a service by a big cloud vendor without seeing something back for it. Or maybe even getting more work back to support the cloud vendor for free.
So I’m not surprised at all that licenses that allow commercial use up to a point and above that require seperate license or contributions back. It is still open source in a lot of ways. Can still be part of other open source distributions that themselves make no profit etc. And only companies that are more than able to pay must pay something.
If companies avoid using software governed by such licenses then the overall impact is negative in my opinion, because it will lead to competing and diverging clean room clones that just split the community and the ecosystem.
Correlation is not causation.
What I lived through, was Linux taking off like a juggernaut, and IBM embracing it as a result. Large corps came along for the ride, they didn't drive it and at best paid for some gas.
DEVs being paid is simply what it is. The entire scsi/sata stack was originally re-authored by 3ware for example.
Why?
To sell stuff, and the guy was an advocate too.
It's always been this way, under the great wonder of the GPL, blessed be it.
You must have a good source of information for such a statement.
Do you want examples why Solaris was selling so well before the .com crash?
There is no conflict in "linux was growing without the big boys' and 'it started with small market share'.
And yes, you can find exceptions to the rule, although regardless, do you see me saying "exclusively"? What does someone using Solaris, have to do with Linux only growing due to external help?
There certainly were mailing lists, usenet, forums, all of an all-encompasing scope. But there were also very local user groups, and pockets of wildly more and less usage depending upon region. The Internet was young, and many made decisions predicated upon what they saw around them.
The best way to be sure you had support, was a local healthy community of hackers around.
Famously IBM did eventually buy Red Hat, but not for another 20 years. The fact is, Linux was alive and well and growing as far back as the late 1990s, and devs were getting paid. You could literally buy CDs in a box of an installable Linux distribution at an ordinary retail chain bookstore in 1998.
And for whatever it’s worth, the reason Linux took off the way it did when it did was because the Dot Com Bubble helped pump smaller companies like Red Hat or SuSE up, and they were certainly selling floppies and pressed CDs at a margin like Shareware as well, since most people didn’t have the time or hardware to download and burn ISOs until the early/mid-2000s when P2P music took over the world.
(I remember. I was there. I guess I’m old now…)
Granted, we know Android would not be where it is today without open source contributions.
But the parts of Android that are majority outside developed is still available as the Linux kernel. I have my doubts that the uniquely Android bits of the userland and system services have many outside contributions.
When Android launched, making it open source (ish) was the right competitive decision. It got phone makers and carriers on board and accelerated the ecosystem’s development. Today it being open source (kinda) is a met negative for Google. So, yeah, they’re changing that.
Well-run companies aren’t zealots. They adapt to changing conditions. If a company’s actions happen to align with your personal preferences today, it doesn’t mean you’ve found a lifelong philosophical soulmate. Ditto if a company’s actions run counter to what you want today. Either can and will change, and there’s nothing morally concerning either way.
companies exist for the sole reason to make money - not to make the world better - that's a side effect.
but unfortunately a lot of people wanna see the world as they wish it to be, not the way it is.
just like the USA at it's founding - deliberate actions were taken etc that were counter to the normal. & going against the wind takes a lot of energy.
at a certain point in time - you run out of energy or you've to keep keep reinvesting to not run out otherwise barbarians are knocking down at the gate.
Costco, specifically, I have a good story about. Jim Sinegal spoke at my MBA program, and he talked about when they were starting and the challenge was a value prop of “buy bulk, lower cost” contrasted with bulk actually being more expensive than small quantities, therefore needing to target higher incomes.
Part of the solution: wider parking spaces. Make people feel like their expensive cars are safer, it’s easier to get in and out of the car (especially for older people, who have more wealth), and differentiate from typical stores.
Now, you tell me: would you be just as happy with cramped parking spaces because the larger ones are profit-driven? Does motive even matter here?
It's profit driven in its own way, but against the grain of modern corporate strategy.
A lot of people get the wrong impression from reading Dodge Brothers and think companies are legally required to put profit first. What really happened is Friedman and Reagan planted the idea of shareholder supremacy, convinced schools to teach it and now generations of business majors think it's a sacred truth they have to enforce anywhere they go. Never let a MBA take over.
Companies that don’t do a good job of making profits tend to go away, thus there exists natural selective pressure to put profits ahead of other concerns. Note that none of the above has anything at all to do with morals or ethics.
This is why a healthy, society-aligned regulatory regime is impoetant, to set incentives. If you make more money being decent than you would being abusive, companies will adapt. They are more like corals than they are like people.
Companies are not sentient beings in themselves: they are made up of human beings with wills. If the human being(s) make moral choices the result will be companies that do moral actions.
> companies exist for the sole reason to make money - not to make the world better - that's a side effect.
That is one interpretation on the purpose of companies (and a relatively recent one):
* https://en.wikipedia.org/wiki/Friedman_doctrine
There are others:
* “Profits are to business as breathing is to life. Breathing is essential to life, but is not the purpose for living. Similarly, profits are essential for the existence of the corporation, but they are not the reason for its existence.” ― Charles A. O'Reilly, Lead and Disrupt: How to Solve the Innovator's Dilemma, https://en.wikipedia.org/wiki/Charles_A._O%27Reilly_III
* “On the face of it, shareholder value is the dumbest idea in the world. Shareholder value is a result, not a strategy...your main constituencies are your employees, your customers and your products.”[72] — https://en.wikipedia.org/wiki/Jack_Welch#Politics
Or going back a few decades:
> In 1949 General Foods’ president Clarence Francis told Congress that he had a “three-way responsibility to the American consumer, to our associates in this business, and to the 68,000 [stockholders in General Foods]. We . . . would serve (the company’s) interests badly by shifting the fruits of the enterprise too heavily toward any one of those groups.” Two years later, the president of Standard Oil of New Jersey claimed that managers needed “to conduct the affairs of the enterprise in such a way as to maintain an equitable and working balance among the claims of the various directly interested groups—stockholders, employees, customers, and the public at large.” So widespread were such views that, in 1959, one writer in the Harvard Business Review complained that it was no longer “fashionable for the corporation to take gleeful pride in making money.” Instead, he complained, it was typical “for the corporation to show that it is a great innovator; more specifically, a great public benefactor; and, very particularly, that it exists ‘to serve the public’.”
* https://law.temple.edu/10q/purpose-corporation-brief-history...
> American corporate law has long drawn a bright line between for-profit and non-profit corporations. In recent years, hybrid or social enterprises have increasingly put this bright-line distinction to the test. This Article asks what we can learn about the purpose of the American business corporation by examining its history and development in the United States in its formative period from roughly 1780-1860. This brief history of corporate purpose suggests that the duty to maximize profits in the for-profit corporation is a relatively recent development. Historically, the American business corporation grew out of an earlier form of corporation that was neither for-profit nor nonprofit in today’s parlance but rather, served a multitude of municipal, religious, charitable, educational, and eventually business purposes in early nineteenth-century New England. The purposes of early American business corporations—rather than maximization of profit to private shareholders— were often overtly public, involving development of local transportation, finance, and other much-needed economic infrastructure. With the rise of factory-based manufacturing, railroads, and other capital-intensive industries in the middle decades of the nineteenth century and the advent of general incorporation statutes, the purpose of the American business corporation shifted fundamentally from public to private. By 1860, the stage was set for the modern firm.
Self-reply: see also Boeing company ethos pre-McD acquisition versus post-McD acquisition ethos:
* https://www.goodreads.com/en/book/show/55994102-flying-blind
They exist to make money but not by all means.
Companies are allowed to make money because it’s a net benefit for society.
If that changes companies lose their reason of existence.
Setting on "companies exist for the sole reason to make money" as the only motivating factor just makes it a self-fulfilling prophecy.
It's another when they say they're going to do one thing, you align with them, and then they do another later. That's generally frowned upon morally because it's considered to be deceptive/untruthful.
It's not surprising, but that doesn't mean people should be ok with it, especially when other businesses get by fine making more ethical business choices, or at least avoid outright lying for their own benefit.
They stay away from those.
What license was KHTML again? Checked: LGPL.
They absolutely are zealots; the zealotry focuses on profit.
Why these types of stories are so jarring to some is that they serve as a reminder that your pet technology or project will get fed into the wood chipper if enough bloodless “Ex-Bain, Ex-Mercer, I Love LinkedIn” types tell the ceo it’s a profitable idea. And you and I are just as expendable.
Just because you know there's a chance of being punched in the face, doesn't mean it still isn't a bit painful actually being punched in the face. Even if you brace for it.
But yes, that's the beauty of open source. The ability to take your ball home if and when the maintainer breaks the social contract. It's a contingency plan for this exact scenario.
>and there’s nothing morally concerning either way.
There's many moral concerns. Whether or not the company cares does not expel the concerns itself.
With the way Firefox is heading, that might not be the best idea. Nowadays Mozilla seem more focused on riding the AI-hype wave than actually making an excellent browser people want to actually use.
If your competition is attracting the worst kind of users, do you really want to get in their way?
As for the excellent browser that people want, that raises the question of what people want. There are likely as many answers as people.
My biggest pain point at the moment (entirely subjective mind you) is not even the AI nonsense, but how disjointed and alien the Firefox UX and general feel is to Apple platforms (what I use, at the moment). I don’t want Firefox to mirror Safari 1:1 but I do want the Firefox UI and UX to feel polished, well thought out and thoroughly in line with system HIG specs—given that I spend a lot of time in a browser, it shouldn’t feel like a stranger in a strange land amidst my other desktop applications.
Aggressive UI improvements would go a long way to restore some faith in the incandescent fox‘ mission—at least for me.
Every other browser aren’t using macOS native UI therefore are wrong in this environment. But right on their own in being the same everywhere.
If my OS says windows and tabs close on the left, then I expect every single app to be a good platform citizen and not make me relearn default controls just to operate simple functions. Windows and tabs close on the left. End of story.
And despite what many people here like to think: these things matter. UX improvements compound exponentially, and so do UX problems. Firefox has an opportunity here to be a first-class citizen on every OS it runs on. It has the opportunity to be the browser that respects your OS choices no matter what, but alas, Firefox seems rather content carrying its “ah yeah I remember using it back in ‘06” reputation.
Firefox is not a bad browser by any means, but it feels like Firefox is the browser equivalent of the “how do you do fellow kids” meme. An out-of-time experience pretending to blend in under the guise of “AI”.
It is also worth noting that the macOS UI/UX isn't anywhere near perfect. It is a hodgepodge of design decisions that go back to the origin of OS X or, in a few cases, the origin of the Macintosh iitself. Padding and margins may help achieve visual balance, but it's Windows management paradigm is an absolute functional mess.
Then again: while I believe bad UI/UX is a thing, I don't think there is an ideal. Different people think in different terms, or have different preferences. Some forms of interaction are better in one domain than another. There are undoubtedly many other reasons.
As for Firefox taking things into their own hands, that's the developer's decision. I have already given two reasons why that may be the case (users may expect consistency across platforms, and it may require too much effort for too little return).
Maybe you’re too preoccupied trying to discredit valid criticism as “fanboyism” to realise how important UI and UX are for products such as browsers.
Besides, Chrome itself is already an absolute mess of conflicting and downright distasteful UX choices and patterns. Firefox seems to be stuck in the past but Chrome seems to actively DESPISE being available on Mac.
Very puzzled why there isn't more love for Firefox, even on HN.
There is also a layer of hypocrisy when people beg for Mozilla to generate greater revenue diversity, but then an immediate scoff whenever they try anything unrelated to Firefox -- where there is no money beyond search deals since Mozilla can't go down the Brave crypto route.
Google is not the same company Mozilla partnered with decades ago. You can listen to retrospectives from Mozilla engineers, and you sense a desire to bite the corrupted hand that feeds.
However, for Mozilla to be the bold, it needs funding diversity, and that isn't going to come from a browser alone.
I have not agreed with everything Mozilla has thrown against the wall, but I sincerely hope something sticks. We need it to.
What would be the point of a browser compatibility matrix then?
Which for the large majority of companies means Chrome and Safari nowadays.
Thanks to Apple's stance on iOS, otherwise it would be only Chrome, as younger generations apparently never got the IE history lesson.
Mentioned as "one customer" in the PDF.
Edit: spelling
Yes, and now that they've achieved market saturation, it's time to pull up the ladder.
Thanks for all the free work, suckers!
I mean, FOSDEM full of Apple laptops on the corridors, the message was really lost.
Now that the chromebooks are also Android, it feels like the slide is only going to grow ever more fearsome.
Implying I ever left Firefox in the first place.
Just point out how that hurts security or privacy and we’re with you!
Advocating for chromium to do what?
So we move. We force their hand
How?Remember this upcoming Christmas that the ye oldie tradition of fixing PCs clearing awful exploiting phone apps (and cancelling subscriptions) should also include the "fix my browser" again, instead of Internet Explorer being replaced by Chrome, our collective duties is to replace Chrome with Firefox, plus its useful extensions to block ads and improve the web experience removing trackers etc.
Your call to arms today is to ensure all your tech colleagues join the movement, and then we can see Google's management views on "market growth"; they forget they made Chrome, we sold it - its our fault we forgot the "infinite growth of shareholder value"...
This is correct but rarely in practiced.
During firefox DRM/HTML5 issue, I know many people from Free software foundation Europe absolutely telling in their blogs, talks etc please stop Mozilla from implementing this DRM or that... but finally when I spoke to these in private they told --- ya, whatever - I need to see this series in netflix etc- so I have another device with chrome etc to watch it. (Indeed Firefox did implement it)
This behavior is the reason average Joe gives up...
(This is also why we should be be vary, and quite sceptical of, Canonical's new Rust-based port of GNU CoreUtils too. Apparently, Canonical plans to replace GNU CoreUtil completely in Ubuntu with this port. The original GNU Coreutils are licensed under the GPL, but the Rust based ports are not. This means that Canonical will now have the ability to stop distributing the source code of its CoreUtils port in future Ubuntu Oses).
I never left. The only thing I don't like is that I can't directly donate to fund Firefox, only towards the Mozilla Foundation in general.
As the cash cow, it will always receive what it needs, but it will also act as the vehicle for funding possible avenues of diversity.
Mozilla is never going to be independent off of Firefox alone -- that revenue simply doesn't exist.
I wish Mozilla had taken Proton's approach, but regardless, I hope they manage to throw something that sticks.
A fully financially secure Mozilla would truly allow their organization to shine.
Google is a lawn mower, stop anthropologizing them. This goes the same with Apple, Microsoft, Meta, Amazon, ...
Of course, it does. Google is no longer afraid to spit on open source. People happy to use Chromium features better remember this. You are renting everything and your landlord will soon come demanding it back.
It only doesn’t make sense if you’re assuming conspiracy.
It makes a lot more sense if you assume they just don’t give a shit.
When Patrick Pichette left and Sundar became CEO both led to massive culture shifts.
Could Google backtrack on this if they wanted? If they suddenly decided to stop releasing public code updates, what would they be violating? I can guess: Anti-trust maybe. probable at least contractual commitments Or is there some stronger forcing function?
What? Google is advertisement business. Not a software house. They sell ads. It all makes sense to build a walled garden. They are effectively a monopoly for half of the personal devices _in the world_. And they _will_ return their investments into the opensource. By locking Android and Chrome and showing ads to everyone.
Like the old days shitty TV, full of ads.
> Google simply regrets android being open source.
No, they are benefitting from it! They gained some trust and removed competition from the horizon. Now they are locking the platform down to do what their business is about: displaying ads.The Motorola transition can't come soon enough, IMHO
But I agree with the other comments out there. It will get ugly and they will loose. I am convinced there many heavy weights just waiting for the right time to hit google hard on this. While I don’t know all of them and don’t like the ones I think I know, I will sing and dance when it’ll happen.
And no, Apple is no better.
* Google drop "real" Android source-code updates to OEMs _and_ the public every half.
* But they ship four Pixel updates, including documentation + SDKs.
* Now they added new APIs in a Pixel-only update.
* Google also drop security update backports to "trusted" OEMs monthly (which GrapheneOS have had access to for years).
So, there are now Pixel-exclusive app features on the Pixel SDK version which isn't available to OEMs - but, it's highly unlikely any app developer would actually depend on these new APIs, since Pixel marketshare is tiny to begin with. This in essence just makes Pixels a weird beta-testing device for what will come out a quarter later to "normal" devices, which is sort of an odd business decision, but also a weird thing to get really mad about, in my opinion (I do see what GrapheneOS are trying to do, with having OEMs saber-rattle about not getting features on the same cadence as Pixels, it just doesn't resonate very loudly for me).
However, the API headline seems to bury a deeper lede; in the thread, GrapheneOS also claim that the quarterly Pixel releases contain security content which is not appearing in the monthly backports. This is quite bad and very sloppy if true, since the Pixel releases can easily be patch-diffed and exploits backed out of them. I'd be interested in seeing this enumerated in more depth.
Nobody buys a Pixel because of this minute software advantage.
Maybe get Motorola or Samsung to support security updates for six years and get back to Pixel users.
There are currently around 400k to 600k active Pixels with GrapheneOS. There have been far more than that when including the past devices our users have purchased. Pixels are a small segment of the overall market and that's substantial. If you add in people on other operating systems such as LineageOS then there are even more people using Pixels with another OS. A significant portion of people who bought Pixels did so because they were AOSP reference devices.
Samsung provides 7 years of support with monthly updates for their flagship devices. Unlike the Pixel OS, Samsung ships a lot of the security preview patches early.
Motorola Signature (2026) has 7 years of support. The upcoming successor to it is the first non-Pixel meeting all of the update and hardware security feature requirements for GrapheneOS.
Pixel 11 currently doesn't meet our security requirements due to at least temporary lack of MTE support which may get added in Android 17 QPR2. The upcoming Motorola device is also going to be using a 6.18 kernel at launch rather than 6.12. We would have launched Pixel 11 series support already if they met our security requirements. It's likely they will down the road but it's not clear why they omitted firmware and software support for a major security feature at launch. It's the firmware part which impacts us.
Did they though? Or is this just conjecture? Because, honestly, Pixels are not even available worldwide so a few AOSP enthusiasts dropping off and going to Graphene hardly seems concerning for the mighty G.
AOSP reference was a tagline for a few nerds that still wanted the Nexus devices of yore, but it was clear from day one that Google wanted their Pixel phones to be their iPhones.
> I did
Precisely my point.
Pixels are sold in 33 countries across North America, Europe, Asia and Oceania. A substantial portion of the Pixel userbase is using other operating systems. 400k to 600k active GrapheneOS users on Pixels is a significant amount based on how many Pixels are sold. It's only one of the alternate operating systems people are using. It's not only a few users as you're claiming.
My first phone was a Motorola that shipped with Eclair. Froyo had already been released and Motorola had a release date for Froyo scheduled in their website. They changed their mind. I don't trust Motorola one iota. Google has never lied to me they way they Motorola has. Good luck.
Many people bought Pixel because they saw it in a store or online. A few people bought Pixel because it was supposed to represent the leading edge of Android and it still does. Almost no one bought Pixel for AOSP reasons or even know what AOSP is.
That's usually reserved for iPhones and Samsungs. Pixels have a tiny marketshare compared to Apple and Samsung. The GP is right when they say a significant portion of buyers bought a Pixel believing Google's claim that it was the 'purest' Android experience since it was a reference AOSP device.
All of the major OEM shave access to the internal source with a _very_ small delay. OEMs don't ship these intermediate releases because they choose not to, not because Google witholds the source for them.
So now everybody is off worse. Not only are OEMs still slow with security updates, while CVEs float around for months among those within the know (or reverse engineering skills) for months.
I think the overall source embargo is rational _until_ fixes appear in a released binary build. Otherwise there's an integration/QA/rollout window where a source patch is public while the binary patch is unavailable to anyone, including attackers, which is undesirable. In "full" open source this has always been a time-suck mental gymnastics exercise around hidden mailing lists and obfuscated commit messages (which probably aren't useful in the LLM era anyway). It makes sense for Google to avoid engaging with that given they don't need to; I think it would be fully logical for them to perform source drops gated on the rollout cadence to the first available binary release channel.
I fully agree the slower-than-Pixel "vendor lead time" windows are really detrimental. Once the binary patch is out, the source patch and disclosure is effectively out too; those extra windows just let OEMs continue to be lazy as a matter of policy (which they love to do regardless) while exploits are already available.
It's probably no decision at all, but merely poor coordination between separate departments.
Once a bureaucracy surpasses a certain size, odd side effects accumulate on their own, and the growing number of people affected by them seek to cast blame where no purpose ever existed.
GrapheneOS has the bootable AOSP and will have Google-alternative device support.
We probably need an equivalent to Play Services, app signing/porting/publishing tools.
With these in hand could we talk Valve into providing the scalable alternative to the play store?
They have replacement portions for Play Services already (attestation, an app store, and location), but it'd be interesting if they also offered something for push notifications.
If you have it to give you can spend your budget on a donation and fund the effort directly.
As a personal device it works pretty well. For ssh terminal and reading markdown, it has by far best display.
Huawei made a big mistake by not fully open sourcing HarmonyOS, you can't flash OpenHarmony so it doesn't count.
I feel like Huawei missed a gigantic opportunity there: forking AOSP may have gotten them traction. I would totally buy a Huawei device if it could run GrapheneOS, and I wouldn't mind if GrapheneOS was based on Huawei's fork rather than Google's.
It doesn't have anything directly to do with GrapheneOS, and would have enabled custom OS support of any Android distribution.
Things will keep as is for as long as they keep making these OSs FOR the tech nerds.
Downvote me all you want. You know it’s true. An OS made for nerds and by nerds will never reach mainstream and will not, ever, move the needle anywhere. Tech is no longer a hobbyist’s game.
But Graphene doesn’t mean anything to the general public. People aren’t buying “an iOS device”, they are buying iPhones. People aren’t buying “an Android phone”, they are buying “a Samsung/Galaxy” or a “Pixel”.
Mind you, when I say people, I mean the general population. Not those actually interested in these subjects.
My point is: people don’t care about these specifics, people care about having a frictionless experience (or as close to frictionless as possible). Having to explain what Graphene even is is friction enough for most people to not even bother listening to your explanation.
Well, they kinda do. Apps are available on Android and iOS. They are not "available on Android, iPhone, iPad and Apple watch". iOS is actually used and recognized by the general public.
No. They are available on the “Play Store” and the “App Store”. OSs are rarely mentioned. Store tags only feature store logos and store names, for device specific ones you get the device itself. The OS remains irrelevant in this scenario.
>GrapheneOS is not made for nerds, it is made for normal people.
There is also no statistics resulting from surveys, studies, reports, etc., that would indicate such a conclusion about user demographics.
People have more than enough brain power to reason about this. "There are several distributions, I recommend this one" is not exactly rocket science.
We really need to stop treating people like they have an IQ of 30 and only 5 minutes of free time per day, or we'll never defeat Google et al that purposefully maintain us in this belief.
And I don't see how the name "GrapheneOS" is any worse than "Android". Really, the biggest barriers to adoption are:
- No phones come with it pre-installed (yet)
- They only work with Pixel phones (for now)
- Some apps like certain banking apps don't work
Pixels are currently the only devices providing the required updates and hardware security features. There will be at least one Motorola flagship with GrapheneOS support in 2027 meeting the same requirements. It will expand to more Motorola devices from there. iOS only runs on iPhones but that's hardly a barrier to adoption for it. Pixels aren't quite broadly available enough and it will take time before we can support lower end Motorola devices in the same price range as an 'a' series Pixel.
The vast majority of Android apps do work. Banking apps are a special case where around 10% don't work due to banning using a non-Google-certified OS. Most banking apps definitely work on GrapheneOS.
By your own definition, is it meant to make the mainstream?
Great way to demonstrate you don't know the general public and think and speak only nerd.
That being said people DO buy Google Pixel for GrapheneOS and they WILL buy Motorola for GrapheneOS too.
That is the power of GrapheneOS that all the other BingaBoingoKonohaOS can only wish for.
What a weird angle to have a pop over.
We (yes, "we," not hiding who I am, check my bio) have seen many users from all walks of life asking for assistance. For example, I remember multiple times newcomers in our community asking for help self-identified as old, or retired, or grandparents switching to GrapheneOS. It's not hard to use, and we have a fairly large community of people who are happy to help others learn the ropes.
GrapheneOS is easy to use, just ask the grandparents rocking it. Our userbase will only continue to increase as we continue to deliver features that people want, with the latest being Secure Paste. Many of users are very excited about the feature. More are planned.
As for the complaint about the name, okay? GrapheneOS is open source. You can change the name everywhere and build it yourself.
But to be honest, many banking apps randomly stop working with GrapheneOS anyway. So if you see this...
https://privsec.dev/posts/android/banking-applications-compa...
https://github.com/PrivSec-dev/banking-apps-compat-report
And check the issues, it's unpredictable whether a bank will continue to work with GrapheneOS
So.. if you accept GrapheneOS might not be reliable for this use case, and decide have two phones (one just for banking stuff, another for.. using), then degoogling is fine.
Only thing is that the banking device probably needs to be a phone (or tablet I guess), I don't think you can emulate a real device good enough for it to work on something like Waydroid
Dont confuse intent with laziness, running on cobol genuinely gives them many advantages.
I didn't want two phones, because it just seems so silly. The tablet, based on it's larger size, at least offers things that another phone cannot.
Now with LLM and agentic factories pumping out bugfixes/code, does the equation on opensource still look attractive to a for-profit company? Why give away that sweet source code?
Further contribution to the trend of humans becoming more capable but less social.
So it seems like the problem isn't that the new API is Pixel exclusive, but that the first and third quarterly release patches each year are Pixel exclusive?
https://grapheneos.social/@GrapheneOS/117282190165630051
> It would be interesting to know if Google's legal team is aware they're giving Pixels months of early access to new Android features and bug fixes including certain important security patches. Pixels being given this competitive edge over Google's OEM partners is very dubious.
The only way to fully free Android from Google's hands is a hard fork. Graphene OS probably doesn't have the resources for that on its own, but all the other Android OEMs put together might. Frankly I'm kind of surprised it hasn't happened yet, but I do seem to remember Google having some anticompetitive clauses in their license terms for GMS which may be preventing this... not sure if those are still in place.
No, these are standard Android APIs included since Android 17 QPR1. These will be available through AOSP and other OEMs via Android 17 QPR2 in December 2026. It's currently exclusive to Pixels because it was released as part of Android 17 QPR1 since QPR1 and QPR3 releases are now Pixel exclusive since Android 16.
This is simply the first time they've added APIs in a QPR1 or QPR3 release following no longer releasing QPR1 and QPR3 to AOSP after the release of Android 16.Regulate them! that is the only way.
Their should be a path for an AOSP build to be just as privileged as a google signed build.
But at least we can get updated internals for the Q20 (and soon the Passport). It'll be the closest we can get to carrying a BlackBerry for some time, if ever, and I'm happy enough with mine that I picked up a spare mainboard
I was also a backer for the Mecha Comet[1] earlier in the year, which I'm hopeful about, although that's a couple of steps away from a daily driver phone at this stage, I guess.
I never owned a blackberry, but for me, the ultimate winner would be for someone to copy or licence the layout and form of the dopod838pro[2] (a.k.a. HTC Hermes 100) and pop some newer internals in it... If I had 100 million dollars, that's what I'd be doing...
[0] https://www.clicks.tech/en
[1] https://www.kickstarter.com/projects/mecha-systems/mecha-com...
By the time the product becomes "popular", it's then just one more platform that needs to follow investor interest and laws.
Which is why we should support them today and not wait until the walled gardens become inescapable.
I've a feeling companies like Meta, Amazon, Steam are well placed to do this (esp. Meta and Steam). But not sure it will be helpful to them in any way, besides they'd want to ensure their own control and locks.
Amazon did one in 2014: https://en.wikipedia.org/wiki/Fire_Phone
He is a serial fabricator and charlatan.
https://nitter.space/GrapheneOS/status/1894511926962446670#m
Fixes/updates the modem firmware.
(HN types would snicker, "Google's getting all your data, it's not secure" but that wasn't the conversation.)
I'm glad they disclosed it, but what a huge black eye.
https://digital-markets-act.ec.europa.eu/developer-portal/in...
Side note, that API here is HID. USB HID is so cool. There's so much stuff in this spec! Chargers and batteries can both communicate all kinds of status, which, well, afaik no one does, there's all kinds of sensors. It's this ancient spec that has so much, and weirdly is just so far ahead of where we are. More HID on Android will be great. Wish they'd played with others to make this so though!
You're probably asking if they're able contribute anymore?
in terms of accepting, unless it's stuff like bugfixes to core mechanisms, not really.
especially since its radio and thats not too easy to determine if a device is or isnt sending weird stuff. (dont come with the lte or wifi sniffers or such things. u'd need thorough spectrum analysis during operations on a quite broad spectrum too to rule that out. the antennae in the devices can produce a lot of types of signals... or do they decap the chips and reverse those to see whats in it? i doubt it would be possible at the right scale but theres options i guess.
people in certain regions/ high assurance security work roles will do this to hundreds of devices that are identical to try and determine if a supplier is compromised or not. order a full batch, take em all apart. taking x-rays, dissolving chips package, etching layers one by one, taking pictures with electron microscopes etc, probing bond wires in the packages as they run etc etc.
somehow i dont see some OS creator do all of this, but ofc i could be very wrong :). interested to find out why people think google while with a different OS is truly de-googled or if they kinda just hope for the best...
https://discuss.grapheneos.org/d/10150-not-your-average-why-...
the tl;dr:
- There has never been any evidence found of any hardware backdoors in Pixel devices. - Those would be quickly noticed. - Those are poor and inefficient methods for any sort of data collection.
To answer your question they are not "just hoping for the best".
Ubuntu Touch has left behind UBPorts which uses Android's hardware layer to provide a usable UI on existing Android devices.
There's the Librem phone with an open source stack, though its hardware doesn't come close to a cheap Android phone these days.
There are projects like PostmarketOS which work to get mainline Linux on phones. From there, you can run Linux on phones through desktop environments such as Phosh and Plasma Mobile which are touch optimized.
FirefoxOS died but was forked into KaiOS, though the modern iteration of KaiOS is an Android fork.
Samsung has TizenOS but I don't think any phones run it anymore. It's probably the closest equivalent to Android in the way it has been developed.
If you want to throw money at something, Sailfish may be the project to keep an eye on. All the other volunteer-run operating systems are worth donating to, of course, but Sailfish is actually trying to be a real third option rather than an open source proof of concept or alternative for shitty vendors stopping updates.
Gnome is undertaking some mobile work in-house (no need for a different DE like Phosh or Plasma). My ideal would be a "Fedora Mobile" spin (based on ARM Silverblue).
https://www.youtube.com/watch?v=T6vCWFleBHk
It's looking good! Wish this would get the momentum it deserves.
In terms of usability, SailfishOS is the most usable, but it has some proprietary components and is commercially backed by Jolla, so there's no need to donate to them. I do encourage you to buy their devices if you can though. Speaking of devices, Furilabs and Volla also make practical, decent spec Linux phones (based on Debian and Ubuntu Touch), so they're worth checking out as well.
But it is not easy, and it takes a huge amount of effort. As others have said, theres SailfishOS, Ubuntu Touch, PostmarketOS and a few others.
I'm not sure which one is in a better position to become that third alternative we need, but this year I'm experimenting with all of them on different devices, to try to understand where they stand.
"posted from an Ubuntu Touch mobile device"
I hoped we'll get an OS more amenable to opening up the device, exposing its capabilities to the owner, but alas, I fear there is no way for an OS to survive in this space unless it acts the same way the Big Two do. As it is, I can't help to think that Graphene is just the same as Google and Apple: just another security-maximizing vendor owning your computer.
Desktop environments can't/don't because there is an inherent expectation of users that they should work a certain way and they are built upon decades of neglectful security practices.
Mobile OSes are the attempt to change that and provide better security models from the ground up. AOSP being open-source is what gives you the actual control to modify your platform as you see fit, not having runtime root access exposed to the user.
The idea of "control" that you are describing is illusory and only serves to actually undermine your real control. If you expose root access in that way, you have a much lower guarantee that the rules and permissions that you set are going to be able to be enforced by the system, because you have allowed the system to be modified. If something malicious gains that access, you have lost that guarantee.
Pretty much.
> Desktop environments can't/don't because there is an inherent expectation of users that they should work a certain way
Yes, and many of those expectations are exactly how computers are supposed to behave in general.
> and they are built upon decades of neglectful security practices.
That is true, but:
> Mobile OSes are the attempt to change that and provide better security models from the ground up
I strongly disagree with unqualified "better" here. Better for whom is what matters, and mobile OSes are security-maxxing in the direction that's - IMO - bad for users. They're optimizing for market ecosystem.
> AOSP being open-source is what gives you the actual control to modify your platform as you see fit, not having runtime root access exposed to the user.
That I vehemently disagree with, in two dimensions:
- Open-source as panacea to everything is a bullshit belief techies overindex on. OSS has long been defeated, SaaS killed it. Whether code is open source or not is immaterial, what matters whether this particular code executing on this particular machine I use is open to me, which is not - and I can't even guarantee it's the same code that's supposedly "open" on some repository somewhere.
- "having runtime root access exposed to the user" is precisely what freedom of computing means. That is the one thing that matters.
> If you expose root access in that way, you have a much lower guarantee that the rules and permissions that you set are going to be able to be enforced by the system, because you have allowed the system to be modified. If something malicious gains that access, you have lost that guarantee.
Wrong. I have a much higher guarantee, because the alternative is that I cannot set any rules at all. Per basic math, "very little" is still greater than 0.
You seem to be conflating the ecosystems (which I concede are largely profit-driven), and the platform architecture. The security models that include sandboxing, MAC/SELinux, Verified Boot, and many more; are unequivocally pro-user.
I get it seems like we're speaking of totally different things but hopefully I can bridge that. You having "freedom" to have runtime root access means that any malicious actor, rogue binary, etc. also has that freedom to run amok on your machine and that access cannot be so easily taken back.
I don't know how to respond to your comment about rules other than to say that it's incredibly easy to demonstrate being wrong.
Mobile OSes like AOSP have a much better ability for you to set rules. Access permissions for microphone, camera, other sensors, network, filesystem, are HEAVILY gated by the system which enforces the rules that you choose to set.
Desktop platforms are largely ill-equipped to handle this and are highly permissive. In fact, desktop OSes are frantically trying to copy mobile OS architecture: MacOS SIP, flatpak, Wayland, Windows Virtualization based security, the list goes on and on.
Runtime root access would allow a malicious app to silently bypass every rule that you think you've set. It does the exact opposite of guaranteeing those rules.
I'd like a device where I can, to use a random example, trivially wire up so all messages are collected to shared database I can search, and voice messages are directed to a local or remote transcription endpoint. Or even simpler, I want a phone where I can screenshot the list of transactions in my bank app. Right now this is near-impossible, because by the time I defeat enough of "security" measures to access the data, the phone stops passing attestation checks and some of the apps in question won't load anymore.
Governments are paid out to not intervene. They should have stepped in decades ago. They should have made Google to release source code and interoperate with public services. They already make profit from their services.
But if Pixels are getting early access to security patches too, that's more like one hat.
We live in a time, if you want to build an android app, you easily can, but installing will be harder due to google concerns.
Nothing will happen, as it never does.
Respect for the GrapheneOS for pushing through regardless, even if they have to reverse engineer stuff. Can't wait to buy their phone.
Oh, the possibilities are endless and they're just getting started. Besides stopping releases of AOSP completely they could also mandate that any "certified" Android device should not allow bootloader unlocking (albeit OEMs will disallow that anyway)..
Good phrasing. It's certainly not _your_ phone, you're just an untrusted user who is extended the privilege of using it.
Exposing root to userspace does not make you the owner of it, and serves to erode the guarantee that the OS is enforcing the rules you set. The way it is used is a hacky shortcut to achieving functionality that should be written into the OS itself so that the security model can be maintained.
It’s closed too, sure, but at least it’s more consistent.
Google may just want to kill us and Apple don't even let this kind of software exist without massive hurdles...
However at this point, as a GrapheneOS user if I couldn't use it for any reason I'll go to iOS (even though I used it for a couple of years and I've been fed up).
I'm going to start donating to a few free android distros I guess, I'm probably going to be trying them sooner rather than later, and without AOSP support the dev burden is going to be much higher, and it probably means they'll end up diverging and incompatible at some point (not in both directions, lineage will probably always have to have Android app support)
There are permissively licensed alternatives to most copyleft projects and they're increasingly the better options. You aren't going to reverse that by licensing niche projects as copyleft. Companies wanting to avoid copyleft can make permissively licensed replacements more easily than ever.
People thought they were part of some collaborative, good of the world type effort, when the reality is that there were always ulterior and hidden motives to manipulate and exploit that gullible and rather foolish nature of Americans in particular; a foolishness that has long, if not always existed in the genuine American core character, but at the very least was cultivated and even selected for a long time ago.
How do you motivate people in modern times to do free labor for you as the parasitic ruling class without the threat or resort to violence? You of course trick them into believing that what they are doing or support makes them a good boy, regardless of all the evidence and proof to the contrary.
Go bankrupt, Alphabet!
Still I am mostly interested about GrapheneOS or a RaspberryPi5 with an Android 17 build.
But they seem to even own the RAM market.
Yet somehow this same logic somehow becomes invalid when any open source software made by Google is brought up.
If Linux was targeted for mobile devices, there would inevitably be wasted effort reinventing the wheel just to match the feature set of Android when there’s already a suitable base to start community work from.
Her PC is also 13+ years old (an old Dell Optiplex 9020), which is unsuitable for running any supported versions of Windows. The high -performance, efficient and low-memory-usage nature of Linux makes it possible for her to complete productivity tasks even on such old hardware.
There are also non-nerds benefiting from Linux on low-end gaming devices such as the Steam Deck, or the countless number of emulators such as the Anbernic RG35XX Series, Miyoo Mini etc. Linux is the reason that such humble hardware is feasible for gaming.
The great "open-source" OS that was supposed to free us all from vendor and telco tyranny has... not.
You need to have enough money to actually survive the lawsuit, even if it's a slam-dunk to win (and they almost never are).
Of course it's not great for their business model. Not to mention, no more trustworthy app distribution.
I don't see the EU really being able to forcing them to de-google android phones.
I am also curious how much those phones would cost, BTW, since the cost calculation to release such an OS would be a bit complicated.
So yeah, don't expect EU to defend you here.
Capitalism is transforming to feudalism.
This whole topic is basically people demanding that Google continues giving them their code for free for their operating system.
If it's really such a cancer, why whine and demand the continued work then?
Google is trying to take from the community potluck without giving anything back.
The community potluck has been replaced with a Google Play-shaped stock exchange over a decade ago.
Which is why they planned to replace the entire kernel and services with zircon and fuchsia, and a new Android runtime ontop.
Guess what, turns out Google actually does need the community contributions of the Linux and Java projects.
Google also fully maintains the ART VM running on Android - despite Oracle, the owner and developer of Java - famously wanting a piece of it.
What community contributions are you talking about there? Where does this myth come from?
Linux has a lot of corporate contributors, but it's been a long standing problem that many of these only add new features that their new pet project needs. Long-term maintenace and improvements is often done by volunteers, and many important subsystems rely entirely on volunteer work.
This was also famously an issue with e.g. AMD's GPU driver, which was appreciated as it allowed a mainstream GPU to be fully supported with an in-kernel driver, but the disadvantage that now volunteers had to maintain hundredthousands of LOC of code, most of which was autogenerated hardware interfaces with little documentation, which made refactoring and cleanup work almost impossible.
> Google also fully maintains the ART VM running on Android - despite Oracle, the owner and developer of Java - famously wanting a piece of it.
Had you followed the release notes, you'd have noticed that that hasn't been the case since Android 8 Oreo, when the entire Java standard library on Android was switched from Apache Harmony to OpenJDK. That's why Android was finally able to move beyond Java 7 and introduce modern functionality, fix the broken NIO implementation, and add JSR-310 Date and Time fuctions, just to mention a few of the improvements since then.
These have been developed by the Java community, including corporations and individual contributors.
Graphene is reaching that status for me every day and i'm looking forward to switching to it as my daily driver.
The short is that yes the GNOME/KDE apps do often look more impressive, but they suffer the same sort of malaise which seems to have infected Linux desktops sometime since Eternal September, and between the sporadic crashing and "this doesn't feel right", it's really hard for me to accept "It's more polished than AOSP!".
pmOS's installation page opening with a warning:
Make sure you read state of postmarketOS before installing postmarketOS.
Which leads to a page that opens with: The goal is to make postmarketOS usable for everyone, but we are not there yet. Usability and most importantly stability issues need to be worked out first. If you are looking for an OS that is as usable as iOS or Android, this project is currently not for you.
Does not do a lot to dissuade my skepticism. I know you said the apps specifically, but even there, it's like... I dunno.All of the default apps in GrapheneOS are being rapidly overhauled or replaced. It wasn't a priority due to the incredibly good open source app ecosystem with many existing alternatives available. There isn't a similarly large and high quality open source mobile app ecosystem available for what's being promoted.
All of the default apps in GrapheneOS are being rapidly overhauled or replaced. It wasn't a priority due to the incredibly good open source app ecosystem with many existing alternatives available. There isn't a similarly large and high quality open source mobile app ecosystem available for what's being promoted.
Pixel 3a will lack firmware updates regardless of what you put on it. Having serious unpatched vulnerabilities for radios and other firmware is considered acceptable for desktop operating systems but definitely not by us.
All of the default apps in GrapheneOS are being rapidly overhauled or replaced. It wasn't a priority due to the incredibly good open source app ecosystem with many existing alternatives available. There isn't a similarly large and high quality open source mobile app ecosystem available for what's being promoted.
there is clearly no future for android for anyone wanting an open and spyware free platform. its time to invest out efforts elsewhere.
All of the default apps in GrapheneOS are being rapidly overhauled or replaced. It wasn't a priority due to the incredibly good open source app ecosystem with many existing alternatives available. There isn't a similarly large and high quality open source mobile app ecosystem available for what's being promoted.
All of the default apps in GrapheneOS are being rapidly overhauled or replaced. It wasn't a priority due to the incredibly good open source app ecosystem with many existing alternatives available. There isn't a similarly high quality open source mobile app ecosystem available there.
[0]: https://www.claimsjournal.com/news/national/2024/03/15/32248...
Not to mention to reach GOS’ requirements the cost of the phone would have to significantly increase which I imagine only hurts Android phones even more for no real gain since GOS users are minuscule overall.
And the long term support is definitely not the norm yeah. It’s pretty much just Apple and Google doing it for their own devices. Motorola will be a newcomer to this concept with GOS. But we can only wait and see if they actually stick to it, given their track record prior to the collaboration.
Google probably got away with it cause they made the chips and security chips themselves. I read something like Tensor costing $70 vs. a Qualcomm chip with MTE costing $250.
But even with of all this, it wouldn’t make sense for GOS to spend it’s limited resources developing for a less secure platform when appropriate target devices exist (they mentioned something to this effect a few days ago on reddit too): https://www.reddit.com/r/GrapheneOS/comments/1wifsiq/comment...
Anyone is free to fork, add the desired hardware support and flash.
(that's aside of some Moto flagships in 2027)
You say they can. How?
This is a real threat, but the reality is that the average person is more likely to be hacked/spied on from the software side, which Graphene would protect you from as effectively as it does on Pixel.
:)
Well, go for it, fork and "provide support" to the hardware hostile to non-stock OS, be a hero :)
The rest is not (might be lazy, insecure or just silly but not hostile)
It's surprising some vendors still don't support unlocking and/or relocking.
Delayed patches (they don't keep up with AOSP), missing secure element (makes disk encryption key cracking trivial in comparison).
Fairphone 6/6+ (the latest), is based on..... It's pretty hard to find the Android version it's based on... Got it. They ship phones based on Android 16 half of the year after the release of 17 (9 since public beta).
Many security patches are NOT backported to 16, which makes Fairphone insecure by design.
They allow relocking the bootloader, which is nice, If they also support custom AVB keys, I'd say this is a fine example of the example of the vendor that is not hostile, just not good enough.
I wouldn't say they're hostile - Samsung is hostile for example.
So, what's your angle here? Do you want me to go through every vendor you bring up or what?
> Well, go for it, fork and "provide support" to the hardware hostile to non-stock OS, be a hero :)
In the comment about issues with software and hardware, that somehow is being painted as GrapheneOS fault, I mentioned (among other things) hardware hostile to non-stock OS.
I didn't say it's Fairphone, I didn't name them.
You brought them up, so I addressed that, explained why I don't consider Nothing hostile but just vulnerable by default and inadequate. I even provided an example of the vendor I actually consider hostile (Samsung).
So if you understood quite well, you're trolling now and not discussing in the good faith.
The alternative is you didn't understand and thought I consider ALL vendors as hostile, which is putting claims in my mouth, which would be fine if you asked, but you keep discussing with strawman.
So please go bother someone else; this is the second time you're doing that and I wasted enough time on that.
Fully supporting and using AVB grants protection against persistence of *all* kinds. If an attacker gains privilege escalation through a remote attack, persistence become much easier if the system is not cryptographically verified every time the device boots.
Keystore and Attestation also rely on the bootloader being locked. If the hardware root of trust reports the device as untrusted, there is a broken chain of trust for biometrics, encrypted app data that uses the hardware keystore, and any form of attestation checks (like AOSP's Hardware Attestion API) will report the device as untrusted.
Going back to the first point, if it is possible to modify the system and gain persistence, there is also the possibility of modifying the kernel, which would allow an attacker to rewrite or patch the kernel, rendering AOSP's sandbox useless.
This would also make it more vulnerable to downgrade attacks because rollback protection is tied to a locked bootloader and AVB.
This could all be accomplished through remote exploitation. The "software side" you speak of is built atop AVB as a minimum requirement to assure that the software you're running is unmodified and intact.
Oracle was a mighty powerhouse when it bought MySQL, StarOffice, and more. It lost defacto control of all of them, due to its stupidity. In the world of open source, the tighter you hold on, the less likely you'll retain control.
And yet, here we are, with Google playing games.
Google, a note: there are far more relying upon Android than you, and now there are forced alternative stores in the mix. If Samsung and everyone else said "sorry Google', or even a large majority, you're out. Gone. Nada.
They can now fork, and force old Android to have their new fancy pants 'Play' store too.
Google is also getting more and more pushy with Chrome. What if everyone depending upon that backend, shrugs and says "Sorry Google, we're hard-forking Chrome and we'll all maintain it".
It definitly still is. We run Postgres when we host our banking / financial stuff, but when we talk with banks and say that, they demand Oracle not that 'open source amateur stuff'. We have a version of our software for Oracle (and MSSQL) as well so no biggy, but still, we always try if we know it's not a complete immediate kill (which it will be if we put it in our documentation as only option). Oracle is still everywhere at the big guys.
Postgres ftw. Long may it eat their lunch.
Our Oracle license licensing went up so dramatically that the team I work with is moving some very large databases to postgres from Oracle because it doesn’t make financial sense anymore.
now, if we could only stop eating at the trough of Broadcom…
Oracle used to be a must-have because it was one of the few products that could handle transactions on a scale of a bank, with all the requirements for backups, redundancy, etc.
A fun anecdote. Back in 2000, I was present at negotiations (as a note-taker) where database vendors were bidding for a project for a factory control system. Vendors submitted benchmark results for various DB sizes up to 40Gb, and Oracle's rep hautingly said something like: "Our minimal size for benchmarks is 80Gb, so here are our results for that size".
And this was a _lot_ for that time. Now? It's so ridiculously tiny that you can host it on a smartwatch. So why would you pay Oracle?
Who will step up to maintain it? Keep in mind that it has to be somebody that every other OEM trust. In other words it would likely have to be an alliance of manufacturers. And they'd inevitably treat OEMs outside the alliance poorly and we'd be back to the current situation, but worse.
The OEMs are incapable of writing a competent operating system, and don't particularly care to.
> Google is also getting more and more pushy with Chrome. What if everyone depending upon that backend, shrugs and says "Sorry Google, we're hard-forking Chrome and we'll all maintain it".
With what maintainers?
https://chrome-commit-tracker.arthursonzogni.com/organizatio...
Anything Oracle doesn't have much relevance. They were not really interested in growing any marketshare of those products for anyone.
They have their private own agreements with Google to secure whatever access they need to maintain their OneUI fork and are not the one making any public complaints. Samsung did have a love/hate relationship with Google that was openly simmering with resentment during the early years of Android but those days are long past.
Samsung already includes their own Galaxy store alongside the Play Store on all their devices, and have for 10+ years. But during that time have actually moved the opposite direction from your hypothetical fork scenario and both companies clearly view their current relationship as mutually beneficial.
Even though GrapheneOS and Samsung both maintain their own Android fork their views on AOSP/Google are not aligned.
Back then the primary goal was checkboxes for the carrier to advertise and UI/UX was a distant second priority at most. Sometimes an advertised feature would just flat out be unusable (such as MP3 players), but good luck waiting for any kind of update because by then those developers had already been reassigned to the next handset model they promised to carriers.
Also, Samsung extensively customizes their OneUI fork of Android, with its own UI look and feel that evolves independently from Android based on their own priorities. Plus Samsung's Android maintains hundreds of features that either don't exist at all on AOSP/Pixels or later get folded into mainline Android.
(Including the little known killer app suite "Good Lock" available on Samsung's Galaxy store which gives power users an almost obscene amount of additional niche options and customizations that would give UX minimalist designers at Google or Apple a heart attack)
But despite how different Pixel vs. OneUI look and feel, I can use the exact same apps whether on a Pixel or Galaxy or $100 trash phone. Interoperability is very easy to take for granted and Android app ecosystem is (still) paradise compared to the lowest common denominator J2ME "app" era of the 2000s.
Or they can get a Garmin watch with contactless payment, or do what I do - stick a credit card in their phone case.