Officially yes, but I suspect he is still behind the official social media accounts. Their tone is unchanged and I recently got blocked by the GOS account on Bluesky and immediately by Micay's account as well.
Opinions about the GrapheneOS maintainer aside, there are real reasons why device support has been limited to Pixels (note recently announced intentions to support Motorola devices). As long as you understand what you will/won't be getting with this fork (can it be decrypted BFU/AFU with a cellebrite device?) in comparison to GrapheneOS, then power to you. I recently switched to GOS after years on LineageOS with microG. I do miss my OnePlus hardware, and Graphene took some getting used to. But I do feel comfortable that I'm running the most secure phone now.
Having read the comments I still see two major isssues with this:
This looks like an almost-as-secure-as-GrapheneOS fork, therefore creating a (false) sense of security, because..
GrapheneOS's security is based on secure hardware (Pixel's Titan chip) to verify the software. Only having software security without the underlying secure hardware is kind of pointless or at least well.. a false sense of security.
I think the reason GrapheneOS never did a GSI is because most of their security improvements rely on specific hardware calls that GSI abstractions don't provide access to. This probably would still be an improvement over lineage though, just not as secure as base Graphene is.
It depends. I run GrapheneOS and it can pass everything except the most strict integrity check (which is just that you're using a custom ROM at all).
In practice most apps don't have any problems. Google assistant doesn't really work for me but I've seen posts saying people have gotten it working. Google wallet and Google Pay are also explicitly blocked by google, so they will never work.
Doesn't GrapheneOS have a lot of benefits besides the 3 pixel-requiring hardening features which are removed in Graphite (and the 3 others which are disabled by default but can be re-enabled on some devices)?
I'm not disputing that those hardening features are worthwhile! Pixels with Graphene are obviously much more difficult to exploit than phones without those features.
But there are billions of non-Pixel phones in the world which aren't about to be thrown away, and the vast majority of phone users absolutely cannot afford a Pixel. GraphiteOS (if it actually works?) seems to me like it is probably a major improvement over the other options available for them.
I think it's a lot more than just 3 features removed. AFAIK the whole hardware attestation is based on the Titan chip and you don't have to trust the devices hardware, because you can cryptographically prove that the software is unchanged. It's not only about the Auditor app, but the whole integrity of the OS, the boot process and firmware is secured by the Pixel's hardware or more specific the Titan chip.
And the billions of devices can not be saved by a GrapheneOS fork because they're mostly missing crucial firmware and generally get no updates anymore. That's why GrapheneOS is only supporting recent devices and especially Pixel devices because they receive up to 7 years updates.
I'm all into getting people a more secure OS but I fear that a GrapheneOS fork is perceived as a secure OS when it's actually not. The most important security features are still recent (firmware) updates and hardware attestation, verified boot etc.
It breaks the security model. Graphene doesn't only support Pixel for fun. Pixels have the best security hardware features, unfortunately (until the Motorola device comes out).
I would never use this ROM, personally. At that point I'd just use something like Lineage.
At that point I’d just use something like Lineage
My impression is that Graphene-without-the-features-requiring-Pixel-hardware would still be a much more secure operating system than Lineage (or the other options available).
It ultimately depends on your threat model, but many of the most important security features in Graphene are at the hardware level. Without those, it's very possible that a bad actor could bypass the rest of the protections, since Graphene is designed with those hardware features in mind.
I saw it already, but those hardware security features also secure the features you mention there. The other features were developed with the hardware security features in mind. Again, without secure hardware, it's possible for your software to be modified and no longer secure. That's the broken security model I keep mentioning.
While it could definitely be more secure than other ROMs, security was never tested without the hardware features and thus it could also expose you to attacks because of that. Worse, it could make you assume that you're secure when you're really not.
An excellent example is Cerberos. GrapheneOS is able to completely block attacks from Cerberos by disabling the USB port data lanes entirely, something that most (if not all non Pixel phones) are unable to do. Cerberos uses many zero day vectors to break in though the data lanes, and in this case you likely would not be able to block the attack. They'd be able to dump your phone contents and then much of the software security features wouldn't matter.
Should the world just throw away the billions of non-Pixel devices in use today?
And/or should everyone just give up on improving security at all for the vast majority of phone users who cannot afford Pixels, since they can't ever be as secure as a Pixel?
The developer of GrapheneOS is... Interesting, to say the least. Restricts the ROM to a select group of devices, and is very toxic to people who disagree with or even question him.
I understand him though, GrapheneOS without the underlying security hardware is a huge security risk for the end user. It makes people think they get benefits from running a secure os while in fact, they are at the same level as running lineage.
That's vastly underestimating the hardware on other devices as well as overestimating the danger. There are plenty of software optimizations that can be done to enhance security that work even if the hardware isn't ideal. Simply ignoring those devices is letting perfect be the enemy of better. Not everyone wants or even can buy a pixel, and that just excludes all of those users (and also sends even more money Google's way, which I would honestly like to avoid).
There is a lot of people arguing about fine distinctions ITT.
The GrapheneOS leadership (well Daniel) are uncompromising for a reason: this fork will be fundamentally less secure.
You are also right: there are useful features that will improve security on GSI devices. As always choose your threat model.
Hopefully both parties can play nicely.
41 Comments
RobotToaster@mander.xyz · 90 pts · 154d
I wonder what the Graphene owner's calm and reasonable response to this will be?
statelesz@slrpnk.net · 22 pts · 154d
I would love to know, but he blocked me everywhere.
Agent641@lemmy.world · 5 pts · 154d
Explain?
Bombastic@sopuli.xyz · 17 pts · 154d
Daniel Micay, GrapheneOS project lead, has a, shall we say, less refined approach to public relations
::: spoiler Tap for spoiler He's a complete schizo when talking about anyone he perceives as disagreeing with him. :::
RobotToaster@mander.xyz · 10 pts · 153d
To be fair it's kinda reassuring, if they had a professional PR team I'd be suspicious it's a government honeypot.
Of course that could just be what they want us to think.
AndrewZabar@lemmy.world · 3 pts · 153d
Or what they want you to think they want you to think they think. Good luck sleeping tonight. Lol. ;-)
Agent641@lemmy.world · 2 pts · 154d
Awesome, thank you.
Sunny@slrpnk.net · 1 pts · 153d
Didnt he step down from PL position back in 2023?
Sunny@slrpnk.net · 1 pts · 153d
He stepped down a while ago no?
statelesz@slrpnk.net · 4 pts · 153d
Officially yes, but I suspect he is still behind the official social media accounts. Their tone is unchanged and I recently got blocked by the GOS account on Bluesky and immediately by Micay's account as well.
Sunny@slrpnk.net · 2 pts · 153d
Ugh thats a shame.. guess im not too shocked about him not leaving.. Its a shame great projects like this also involve toxic people 🙄
electric_nan@lemmy.ml · 17 pts · 154d
Opinions about the GrapheneOS maintainer aside, there are real reasons why device support has been limited to Pixels (note recently announced intentions to support Motorola devices). As long as you understand what you will/won't be getting with this fork (can it be decrypted BFU/AFU with a cellebrite device?) in comparison to GrapheneOS, then power to you. I recently switched to GOS after years on LineageOS with microG. I do miss my OnePlus hardware, and Graphene took some getting used to. But I do feel comfortable that I'm running the most secure phone now.
statelesz@slrpnk.net · 11 pts · 153d
Having read the comments I still see two major isssues with this:
statelesz@slrpnk.net · 7 pts · 153d
This is actually quite a good read and pinpoints the issue. (Sorry for the Reddit-link though.) https://www.reddit.com/r/GrapheneOS/comments/1s8q534/response_to_a_post_about_grapheneos_on_another/
Bonje@lemmy.world · 9 pts · 154d
Oh man this is great. Maybe some smart folks get it working with Sony Xperia 1 Vii and I don't have to worry about the sideloading restriction bs.
CodenameDarlen@lemmy.world · 8 pts · 154d
cypherpunks@lemmy.ml · 12 pts · 154d
Reading that FAQ I get the impression that it should/could run on a very large number of devices, but maybe there is some caveat I'm missing? 🤔
CodenameDarlen@lemmy.world · 11 pts · 154d
hexagonwin@lemmy.today · 3 pts · 154d
it may or may not work properly, but in my experience GSIs tend to work well enough.
statelesz@slrpnk.net · 4 pts · 154d
But why?
cypherpunks@lemmy.ml · 32 pts · 154d
so that many non-pixel devices can have an OS with most of the benefits of GrapheneOS?
Zangoose@lemmy.world · 23 pts · 154d
I think the reason GrapheneOS never did a GSI is because most of their security improvements rely on specific hardware calls that GSI abstractions don't provide access to. This probably would still be an improvement over lineage though, just not as secure as base Graphene is.
warmaster@lemmy.world · 10 pts · 154d
Wait... an improvement over Lineage ? That alone makes it worth existing in the first place.
At first I thought, Graphene OS without it's features... Why? But what you say sounds like it actually makes sense.
umbrella@lemmy.ml · 5 pts · 154d
Zangoose@lemmy.world · 4 pts · 153d
It depends. I run GrapheneOS and it can pass everything except the most strict integrity check (which is just that you're using a custom ROM at all).
In practice most apps don't have any problems. Google assistant doesn't really work for me but I've seen posts saying people have gotten it working. Google wallet and Google Pay are also explicitly blocked by google, so they will never work.
statelesz@slrpnk.net · 6 pts · 154d
But those benefits rely on the Pixel's hardware. This is contradictory.
cypherpunks@lemmy.ml · 12 pts · 154d
Doesn't GrapheneOS have a lot of benefits besides the 3 pixel-requiring hardening features which are removed in Graphite (and the 3 others which are disabled by default but can be re-enabled on some devices)?
I'm not disputing that those hardening features are worthwhile! Pixels with Graphene are obviously much more difficult to exploit than phones without those features.
But there are billions of non-Pixel phones in the world which aren't about to be thrown away, and the vast majority of phone users absolutely cannot afford a Pixel. GraphiteOS (if it actually works?) seems to me like it is probably a major improvement over the other options available for them.
statelesz@slrpnk.net · 2 pts · 153d
I think it's a lot more than just 3 features removed. AFAIK the whole hardware attestation is based on the Titan chip and you don't have to trust the devices hardware, because you can cryptographically prove that the software is unchanged. It's not only about the Auditor app, but the whole integrity of the OS, the boot process and firmware is secured by the Pixel's hardware or more specific the Titan chip.
And the billions of devices can not be saved by a GrapheneOS fork because they're mostly missing crucial firmware and generally get no updates anymore. That's why GrapheneOS is only supporting recent devices and especially Pixel devices because they receive up to 7 years updates.
I'm all into getting people a more secure OS but I fear that a GrapheneOS fork is perceived as a secure OS when it's actually not. The most important security features are still recent (firmware) updates and hardware attestation, verified boot etc.
CorrectAlias@piefed.blahaj.zone · 5 pts · 154d
It breaks the security model. Graphene doesn't only support Pixel for fun. Pixels have the best security hardware features, unfortunately (until the Motorola device comes out).
I would never use this ROM, personally. At that point I'd just use something like Lineage.
cypherpunks@lemmy.ml · 9 pts · 154d
My impression is that Graphene-without-the-features-requiring-Pixel-hardware would still be a much more secure operating system than Lineage (or the other options available).
CorrectAlias@piefed.blahaj.zone · 4 pts · 154d
It ultimately depends on your threat model, but many of the most important security features in Graphene are at the hardware level. Without those, it's very possible that a bad actor could bypass the rest of the protections, since Graphene is designed with those hardware features in mind.
cypherpunks@lemmy.ml · 0 pts · 154d
see my other comment in this thread
CorrectAlias@piefed.blahaj.zone · 4 pts · 154d
I saw it already, but those hardware security features also secure the features you mention there. The other features were developed with the hardware security features in mind. Again, without secure hardware, it's possible for your software to be modified and no longer secure. That's the broken security model I keep mentioning.
While it could definitely be more secure than other ROMs, security was never tested without the hardware features and thus it could also expose you to attacks because of that. Worse, it could make you assume that you're secure when you're really not.
An excellent example is Cerberos. GrapheneOS is able to completely block attacks from Cerberos by disabling the USB port data lanes entirely, something that most (if not all non Pixel phones) are unable to do. Cerberos uses many zero day vectors to break in though the data lanes, and in this case you likely would not be able to block the attack. They'd be able to dump your phone contents and then much of the software security features wouldn't matter.
cypherpunks@lemmy.ml · 0 pts · 154d
Should the world just throw away the billions of non-Pixel devices in use today?
And/or should everyone just give up on improving security at all for the vast majority of phone users who cannot afford Pixels, since they can't ever be as secure as a Pixel?
unknownuserunknownlocation@kbin.earth · 3 pts · 154d
The developer of GrapheneOS is... Interesting, to say the least. Restricts the ROM to a select group of devices, and is very toxic to people who disagree with or even question him.
Renohren@lemmy.today · 6 pts · 154d
I understand him though, GrapheneOS without the underlying security hardware is a huge security risk for the end user. It makes people think they get benefits from running a secure os while in fact, they are at the same level as running lineage.
unknownuserunknownlocation@kbin.earth · -1 pts · 154d
That's vastly underestimating the hardware on other devices as well as overestimating the danger. There are plenty of software optimizations that can be done to enhance security that work even if the hardware isn't ideal. Simply ignoring those devices is letting perfect be the enemy of better. Not everyone wants or even can buy a pixel, and that just excludes all of those users (and also sends even more money Google's way, which I would honestly like to avoid).
prex@aussie.zone · 6 pts · 154d
There is a lot of people arguing about fine distinctions ITT.
The GrapheneOS leadership (well Daniel) are uncompromising for a reason: this fork will be fundamentally less secure.
You are also right: there are useful features that will improve security on GSI devices. As always choose your threat model.
Hopefully both parties can play nicely.
Solrac@lemmy.world · -3 pts · 153d
Oh they fixed 50% of the problems with Graphene! Now if they can only do something about the toxic behaviour of the dev behind the og...