1,310 karma · joined June 18, 2026
GrapheneOS is often around 4 to 6 months ahead on merging Linux kernel LTS releases. We used to handle this ourselves but switched to the Android GKI LTS branch maintained by Greg KH. Unfortunately, it was often struggling to keep up even before the absolutely massive increase in Linux kernel security patches this year. AI models have rapidly accelerated vulnerability discovery and it's an ongoing crisis for the Linux kernel. We want to be on the latest LTS revision within days and want to be using the latest LTS branch within months of it being released. We're not at all happy with how Android is handling things and plan to fix that ourselves. We'll get things back to how they should be.
We also ship all the AOSP userspace patches months before Pixels due to shipping all of the security preview patches as soon as possible. There are sometimes minor regressions but we find and fix them ourselves downstream. The security preview system has a terrible design especially considering that frontier AI models can reverse engineer the patches. There should at least only be a source embargo for around 24 to 72 hours rather than pretending as if it can work with the patches available 2 to 6 months in advance.
The past couple weeks of our replies were maliciously flagged. We've made a post about it on social media as we've had to do before when this happens. This happens very regularly to posts by GrapheneOS or posts which simply support GrapheneOS. There are a bunch of malicious accounts which show up to each thread about GrapheneOS to make personal attacks towards our team, baselessly claim it's a honey pot, promote non-hardened products reducing privacy/security compared to AOSP and to make a bunch of disingenuous attacks towards it. The attacks towards our team often involve fabricated stories about us and harassment content. There's an account active in many of these recent threads making disingenuous replies and spreading Kiwi Farms harassment content in their profile:
That account should clearly be banned rather than a subset of their posts getting flagged. The same applies to several other blatant ones.
Hello
Check: https://news.ycombinator.com/item?id=49096839
Please upvote/comment/share/mitigate
We passed it along to our developer working on solving VPN leaks. We didn't feel it was necessary to reply to a post linking to a public article. The article was shared with us by our users before we checked out emails.We have a bunch of internally discovered VPN leaks which are already being worked on and this was added to that workload. We've already shipped a bunch of fixes and will ship more soon. We plan to eventually overhaul the whole system to prevent leaks in a much more systemic way.
A security issue being closed means you aren't getting a bounty and it won't be fixed for existing Android releases. It doesn't mean it won't be fixed in a future Android release. They do track VPN leaks as issues internally and regularly ship fixes in new major releases. They unfortunately don't consider those security issues so they don't get prioritized. If they were considered security issues, then they'd likely consider them Low or Moderate severity which means those wouldn't be backported.
Only a large subset of patches for High and Critical severity issues are backported to older releases of Android. Low and Moderate severity issues stopped having patches backported years ago due to volume. High and Critical severity patch backporting is now being scaled down too due to AI accelerated vulnerability discovery. You need the latest yearly or QPR2 release to get full updates.
GrapheneOS has had to fix a bunch of VPN leak issues and we're in the process of fixing more of the issues. We plan to heavily overhaul the VPN implementation to make most forms of leaks nearly impossible rather than continuing to use the current system prone to it.
Pixels have long term availability of official parts for repairs and also official repairs.
Unlike Fairphones, Pixels have very good updates over the long term. Fairphones do not provide anything close to decent updates and it greatly degrades over the lifetime of the device. Fairphone 5 and earlier have an end-of-life kernel without security support. The devices start out lagging months behind on partial security backports and a year or more behind on full security updates which gets worse over time.
An OS without the core features and updates of GrapheneOS clearly isn't GrapheneOS. It's not permitted to refer to it as such.
> That's kind of the whole point of FOSS, right?
No, the point of FOSS is that you can take all of our code and use it for other purposes. Calling an incomplete port to another device GrapheneOS is misleading users. It isn't GrapheneOS and must have a unique name.
Google Messages is essentially the only remaining RCS client for Android and it's the only one with end-to-end encryption. It already works on GrapheneOS via a toggle for ICC authentication extending our sandboxed Google Play compatibility layer. We want to add support for it to our own Messaging app but that's not straightforward since it's not at all an open platform even to the extent of SMS/MMS.
GrapheneOS users can update to it via the Alpha channel and try it out rather than looking at screenshots. There's still more to improve before it will go to the Beta and Stable channels.
It's the default SMS/MMS app for GrapheneOS and isn't available for use outside GrapheneOS so we aren't trying to promote it as an option.
> It's not as though we're talking about a device with hardware specs locked behind an NDA and drivers that only support outdated kernel versions.
Fairphone 5 and earlier have an end-of-life Linux kernel. Fairphone 6 is approaching the same fate. None of their devices keep up with the incomplete security backports to older releases, let alone the full security updates via new major releases. All of their devices are missing important hardware security features which should be standard. They're repeatedly said they don't consider any of this a significant issue and have no plans to significantly change it.
We've announced our plan to add RCS with Messaging Layer Security (MLS) for E2EE compatible with Google Messages and iOS.
> GOS got a big donation
We receive large donations on an ongoing basis.
> or has a volunteer that wants to do messaging
Everyone doing substantial work on the project is paid to do it full time. We hired all the people doing large amounts of high quality volunteer work. We've moved on to a process of filtering candidates based on their CV, an interview process and small test projects.