Hacker Newsnew | past | comments | ask | show | jobs | submit | ysnp's commentslogin

I am a little surprised people jump to Proton as beloved by HN. Proton has a lot of detractors and tends to be a target of some conspiracy/controversy. HN darling definitely suggests Kagi, who are not significantly impressive in terms of privacy-tech which I assumed was why pro-privacy was in air quotes.

Is there anything like a generalised protocol which would allow network-privacy seekers to decide each hop? Apple iCloud+ Private Relay (2021), INVISV Relay (2022), Obscura VPN (2025, first of its kind) and so on are OK, but it would be nice if the user/customer could choose any two providers that didn't have business relationships with each other without mirimir-style proxy chaining.

Have they confirmed whether Motorola will change their onerous unlocking process to be more like the Google Pixels?

Do you know if that's the process for the 2026 Signature? I don't remember exactly but GrapheneOS may have mentioned that for the current Motorola flagship devices the unlocking isn't as onerous.

Considering Motorola is doing a lot of the porting, I would guess it will be improved or will be easy.


If there's a "process" that isn't just something done on-device, it is vulnerable to a rug pull (see LG, Sony, Nokia) where they just suddently stop offering it or the service just stops working somehow.

I am not too sure about this. There is no company I trust to sell GrapheneOS-preinstalled phones other than GrapheneOS themselves.

We are going to be reinstalling GrapheneOS on the phones shipping with it.

That's my plan too. I do appreciate devices are coming and will be buying them, but the whole point is to trust custody of the software, which isn't handled by the preinstalled os in any scenario with any os.

Well you could always use the GrapheneOS Auditor (hardware-based attestation) to verify. Although simply re-installing is about as much effort.

Preinstalled GrapheneOS would be funded by state Honeypot operators, or potentially thieves or blackmailers.

If you wish to steal from someone, select from a population of thieves since they won't go to the police (although they may use illegal means to punish you).

Going with the stereotype that people doing illegal things prefer a secure OS (and are not smart enough to pick a safe source).


You can verify the installation integrity via android attestation, which grapheneos uses

GrapheneOS is installed with their keys which you can verify, right?

GrapheneOS is not made for nerds, it is made for normal people.

You don’t know any normal people, do you?

For what it is worth, GrapheneOS have expressed interest in a new base OS with an Android compatibility/virtualisation layer, but they do not have the resources to build it themselves and a suitable open source one does not already exist for them to leverage.

Historically, some very large Android OEMs based in China and selling in China also provided bootloader unlocking support in their devices including Xiaomi https://github.com/zenfyrdev/bootloader-unlock-wall-of-shame... and Oppo https://github.com/zenfyrdev/bootloader-unlock-wall-of-shame...

It doesn't have anything directly to do with GrapheneOS, and would have enabled custom OS support of any Android distribution.


Xiaomi claims to provide unlocking, but doesn't actually. I don't know about Oppo.

What if GrapheneOS believe that privacy/security is what gives users real abuse-resistant agency and control over what happens on their device with their data?

GrapheneOS is permissively licensed so that people can do exactly that (and fork for different hardware platforms) if they want to. It is a donation-supported open source project with a small team, and it is not a crime or moral failing for them to put those resources into doing the best that they can, instead of spreading themselves thin on something they cannot be motivated or proud of.

GrapheneOS have discussed and explored replacing Google Play/Google Mobile Services functionality with equivalent or open source replacements. See: eSIM management, location services, push notifications et cetera. What they have refused is bundling a privileged component (for full Google Services functionality/compatibility) and enabling signature spoofing support.

GrapheneOS also heavily promote the use of open source Android apps. What they refuse is having app stores that reuse app package names, centralise the signing of app packages, perform reproducible builds on outdated infrastructure, significantly delay app updates et cetera.

I cannot deny your opinion, but just want to suggest that from my understanding GrapheneOS are not against microG and F-Droid as concepts, just against their current implementations.


Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: