Comment by pizzaiolo

15 hours ago

Graphene is clearly bullish on Android, but I have no idea why. The writing is on the wall, Google is slowly asphyxiating AOSP.

Apps are written for android. Graphene can run all the apps because it's android. If it couldn't run apps, you wouldn't use it. Are you posting today from a pinephone?

  • Their post history has several posts related to PostmarketOS on the Fairphone, so kind of, possibly? pmOS does have Waydroid to run Android apps, though, which also relies on AOSP.

    • Waydroid can't run nearly as many Android apps as AOSP on bare metal or especially GrapheneOS with the compatibility features it provides. It's an approach with far more limited compatibility.

      Waydroid has very poor privacy and security due to disabling most of the app sandbox. It's also based on an old version of LineageOS so it's missing many important privacy/security updates, but it's much more relevant that it doesn't have SELinux and exposes much more kernel attack surface to apps. SELinux is not an extra layer of security for Android but rather is used in a far more deeply integrated way than any typical desktop/server usage. It's a huge portion of the security model including the app sandbox and protecting the Linux kernel.

      We greatly prefer virtual machines over a half-baked container approach disabling most of the privacy/security model. There's already hardware accelerated virtualization on all of the supported devices for GrapheneOS and we plan to make a lot more use of that in the future.

What's the concern? They are working with Motorola as a manufacturer. It'll probably be a hard fork eventually but why not make it work in the meantime.

  • If they hard fork, a lot of apps that are generally "necessary for the average person" (e.g. Uber, banking apps, Gmail, Whatsapp/Wechat/Line) might stop working.

    • Sure, but what could graphene do in the meantime? It's either make it work for the moment or stop those apps from working today.

      I'd like to see them lay more ground work for web apps but it's a tough spot and the easiest choice at the moment is to continue with AOSP.

      3 replies →

    • Yes, but there is no alternative other than giving up. Starting a new OS from scratch with zero apps is a much worse starting point compared to a platform where 99.9% of apps work (minus those relying on Play Integrity with strong integrity) which may have its rug pulled in the future. The race here is about getting to a big enough market share that GrapheneOS cannot just be ignored as completely niche but has to be treated as a small but not insignificant minority.

    • It's not ideal, but in the case a hard fork happens, they could implement the same APIs and most apps will probably continue to work. Similar to how microG is a replacement for Play Services and still works for most apps (not as well as sandboxed Google Play of course).

      Above that, not much would change for a few years anyway, because apps still target ancient Android versions.

  • Seriously, I don't see a mediocre android provider like Motorola running and maintaining a hard fork.

    Forking is all easy, keeping it up to date year after year as codebases diverge is a whole different story.

    I could see Samsung doing it. But they won't, they're too good buddies with Google. But they have the resources. A Motorola no. The grapheneos team won't either, maintaining a disparate fork and introducing new features independently from aosp would just be beyond their scope. You're not just hardening at that point. You're basically doing everything.

    Don't forget when Huawei didn't fork. Well they started with that but then replaced every component with their own design. It's easier because if you fork you're still bound by decisions made by the original party. Better to greenfield the whole thing then.

    And look at how many people made a soft fork of chrome with some ui changes. There's tons of those. There's no hard fork that no longer follows Google. Even a large company like Microsoft didn't.

  • [flagged]

    • We've collaborated with many Google engineers working on Android. Many of their engineers, security researchers and even people in management positions follow us on social media. One person who describes themselves as an AOSP engineer on Hacker News doesn't reflect what their overall engineering team thinks about GrapheneOS. This person likely also finds the security engineers at Google complaining about the same things and pushing for improvements annoying too.

    • They basically have opposite goals to Google so I don't imagine there will every be good feelings there. There shouldn't be.

      Yes Google wants android to be secure, but the problem is that to be truly secure it should be secure from Google too. And they don't want that. They want it to be their personal datamine and walled garden. Just like Apple with ios.

      1 reply →

    • One AOSP engineer.

      Google is the one making bad actions, which it makes sense to complain about. They moved to building in private so forks don't get features as they come and more recently they stopped providing certain source code in a timely manner.

So what should they do instead? Just give up? Assume that it's simply inevitable that Google will cancel AOSP entirely and so Graphene should hurry up and die?

There is no alternative.

Apple isn't going to let them build on top of iOS, and anything except those two is dead in the water because it'll never have users because it is missing a bunch of critical apps, and will never have those apps because it doesn't have users.

  • Remember when we thought IE's monopoly could never be broken? Or windows?

    Anything can and will go down. Nothing is forever.

    • IE's monopoly was replaced by Chrome and Safari's, and Safari only exists because Apple gives you no choice but to use it on iOS. Firefox had a brief spot on top, but it really didn't last that long.

      Windows still has the vast majority share of desktop.

      4 replies →

  • > There is no alternative.

    There have been several projects like Ubuntu Touch to create an open Linux for smartphones.

    That would be an open alternative.

    Android is not open.

    • Android is an open source Linux distribution for smartphones. It doesn't have to be used with Google Mobile Services. AOSP is far more private, secure, usable and compatible with a far broader amount of apps. Why wouldn't we use that as the starting point even if the goal was to diverge?

  • [flagged]

    • That's a huge downgrade for privacy, security, usability, battery life and compatibility with apps. GrapheneOS is Linux too. Linux doesn't mean glibc and systemd. Linux is unfortunately not a great base for an OS focused on privacy and security but it's the only practical choice at this time. In the long term, it needs to be replaced as the bare metal kernel.

    • I have it. It's far too slow to be useful, and it's not the hardware's fault. GTK and Libhybris are bad separately and hot garbage together. This problem won't be going away while the hardware is relevant.

      1 reply →

Yes RCS is barely a standard worth implementing, let alone the best one. Make SMS/MMS and XMPP work together seamlessly in one app, forget RCS.

  • Yes RCS is a pig with lipstick. Invented by the carriers to recoup some control over instant messaging, then abandoned and picked up by Google for the same reason. They're the ones that added encryption to it.

    It was always meant to be a walled garden. Exactly what an open system shouldn't be.

  • It's important for us to provide out-of-the-box end-to-end encrypted (E2EE) messaging for contacts on Google Messages and iOS. Both Google Messages and iOS provide RCS with end-to-end encryption via Messaging Layer Security (MLS). Google Messages is the standard text messaging app on Google Mobile Services Android and iOS now also supports RCS with MLS. The vast majority of people have an E2EE messaging app on their smartphone and it's important for us to provide compatibility with it. Currently, a growing number of our users are installing Google Messages to have better usability and privacy for texting with contacts on Google Messages and iOS.

    People can already install the messaging apps of their choice on GrapheneOS. It would go against our approach to choose specific messaging apps and protocols to bundle with the OS beyond SMS/MMS/RCS. We shouldn't be the ones choosing Signal vs. SimpleX vs. Element or other options but rather that's up to users to decide. We need a messaging app to handle carrier-based messaging in the OS including providing end-to-end encryption for it and the rest is up to other open source developers.

    • It would go against our approach to choose specific messaging apps and protocols to bundle with the OS beyond SMS/MMS/RCS. We shouldn't be the ones choosing Signal vs. SimpleX vs. Element or other options but rather that's up to users to decide.

      I disagree with this somewhat. Apple and Google make these sweeping decisions for their users and in effect promote one tech over another. Adopting RCS and integrating it natively, but shunning open protocols and leaving them for third party apps (with probably worse OS integration) means you are following, not leading.

      I would at least consider shifting approaches somewhere down the line. Yes, there are a plethora of open messaging protocols out there, but adopting one for first party integration doesn't prevent the others from being used.

      4 replies →

  • Unless one wants interoperability with other people who use Apple and "Samsung" (because they don't know the word Android refers to an OS). It's a de facto standard now, whether you like it or not.

Have you used GrapheneOS? It's fantastic UX[1] and while probably being one of if not the most secure and private OS available.

[1] thanks to Android (once you replace some of the worse default apps, but they are doing that as we can see)

> Graphene is clearly bullish on Android, but I have no idea why.

Their resources are historically better spent hardening vs literally reinventing the wheel.

Multiple variables in that equation have changed - so it could be interesting where we end up.

Someone (else!) may yet arise chasing their stated model without Android, as well.

Perhaps they're hoping to get significant market share before they lose the opportunity for good?