I've said this many times and it's always on my mind. Google is a terrible steward for Android. We need alternatives that are viable and don't came with huge dealbreakers.
Edit: From a reply below, this may be a different company? Looking into it now.
Edit: Looks like the cellphone company, Motorola Mobility LLC, is currently wholly owned by the, now Chinese company, Lenovo. So, certainly appears to be different organizations. Glass someone caught me on that.
As they say it's useful to find vulnerabilities which is true.
And as far as code they said:
Frontier models are very good at finding bugs but it requires an experienced developer to babysit it and extract the useful portion of the output. Important bugs are often found but mixed in with a bunch of low quality output.
Which is the opposite of vibe coding.
It's fair to dislike any LLM usage. But it can have value. But it's often coming from unethical entities like OpenAI and Anthropic etc
I think this is the distinction of uses I canost get behind. If you find an attack using any tool, whether that be a CVE, a script kiddy, or an LLM, then you can go on to understand how the vulnerability works and patch it. This leaves the understanding part to the programmer, but not the arduous task of trying to find problems. If you use vibecoding to do the actual fixing you never have the understanding of how the code works and therefore what the changes will actually do.
LLMs can be useful in a lot of ways, but they should never replace thinking and understanding. Just like you do need to memorise some things but not others, there are cognitive tasks you don't have to do all the time but others you really have to in order to actually be a good programmer. If you outsource thinking you stop doing it and get weaker at it. If you outsource meaningless tasks or use systems to reduce the need for them that is actually useful for freeing up your mind for tasks which cannot be automated.
So in my view using these tools to find bugs in code can be useful. Knowing that if a bug is found it may not be disclosed to you by the tool because the provider of the tool wants to keep some bugs hidden is something people should consider, I mean that is exactly what the NSA has been going for decades with zero day exploits in various operating systems and platforms, why would they not do so now?
Yet, the GrapheneOS devs will continue to insist that Linux isn't viable because of "security". Well, how useful is AOSP going to continue being with Google holding it hostage?? It sure seems to me that spending effort to make mobile Linux more secure and usable would be a much better long-term strategy than to keep developing for a dying, hostile ecosystem.
The way i understand it, what Google did in Android is no joke, and definitely very hard to implement on a small team that basically works on just fine tuning your existing code. Birthing all this onto Linux is quite an undertaking, and it would need hardware partnership agreements.
Like almost everything Google has done, android was bought by Google. Admittedly, it's been quite a while since then and I couldn't tell you how much can be attributed to the original team vs Google's input.
Yes, and the biggest thing Android has going for it in terms of security is the fact that everything runs with under a strict sandbox and permission model.
You could absolutely build a cohesive, secure Linux system using Flatpak to acheive something similar. It will still have rough edges and holes, but if GOS devs put in the same amount of effort into making Linux secure as they have with AOSP, we could get it to where it needs to be.
Again, agreed, but hindsight is 20/20. I'm not sure if when they started in 2016, they would've believed that by this time, things would be going so badly. That said, I suppose we all really should have assumed they'd be enshittified as soon as google removed "Don't be evil" from their policy in 2018.
For me, it's been pretty obvious that Android was going this direction for almost a decade, but any time people bring up mobile Linux, the GOS devs still bend over backwards to defend building for the dying AOSP ecosystem and speak ill of the security of Linux.
Yes. But for usability, the biggest thing Android has going for it is nothing technical, it's a ridiculous amount of apps to do literally anything you want and billions of existing users, which means more bugs are found and fixed. The mainline kernel Linux phone ecosystem does not have this and it's a bit of a hurdle.
Yes, and that's why we should put effort into making mobile Linux have those things. A team of talented developers like the ones that GOS has could go a long way toward that.
I wish it was as easy, but remember, Microsoft, despite having an actually decent mobile operating system (the people I know who had Windows phones generally liked the UI), could not compete because they were too late to the market.
Sure, but that was an entirely different world. 2011 was pre-Snowden leaks and before people ever considered what the modern era's tech giants would be doing. Google's motto was still Don't be evil and very few but the most privacy-conscious people disbelieved them. People had more skepticism of Microslop, but this was before the public had Windows 8, 10, or 11 pushed on them. There wasn't really a market for privacy-friendly mobile OS because the modern, smart mobile OSes had only existed for a few years at that point and the general public has not yet been as obviously betrayed by Google, Apple, or M$ at that point.
The modern era of tech has been so terrible that even politically uninvolved and privacy unaware folks are frothing at their mouths about datacenters & surveillance cameras and showing up to city council meetings to actually do something about it.
Still, I don't expect mobile Linux to dominate, even when it's ready. But there are plenty of people who are asking for it, beyond those that you would assume.
Another key difference between Windows Phone failing and the hypothetical chance for mobile Linux to succeed is that Linux has the largest pool of software developers to pull from and an unfathomable amount of software that won't even need to be manually ported to work on phones (some will, but most modern software use portable graphics libraries like GTK, Qt, etc.,).
Contrast that with Windows Phone being a bespoke, locked-down ecosystem with Linux having developer tools that more open, easy to integrate, and better documented than any proprietary walled-garden ever did.
Getting apps for mobile Linux won't be an issue like it was for Windows Phone except for cases like banks and other draconian companies. And those are important exceptions, but those can be overcome just as Linux gaming has. If those companies refuse to build for us, then we will build for ourselves, and they will be forced to cooperate when we become undeniable.
And even if you don't share my optimism for what future mobile Linux adoption might look like, I think we can agree that regardless of mobile Linux's "market success", people are going to build it anyway because people will always build cool stuff just for the love of the game. I just wish large teams like Graphene would consider divesting from AOSP and start putting some effort into mobile Linux in the long term.
::: spoiler Edit:
Sorry if that sounded goofy. I had drugs for the first time. They do really interesting stuff to your cognition! It may affect the way I write 🙃
Yes, corporations buy up small businesses and startups. In this case all they got seems to be the Android name and an idea to make a phone OS? AFAICT the project was neither open source or based on the Linux kernel until Google took over.
I'm not trying to whitewash Google here, they did that pretty well themselves in open sourcing Android development. That's given them a 20+ years alibi to be complete arseholes in pretty much any other part of their business — and now they're clamping down on Android, too.
Android is not the problem here. In fact I love Android very much. What I don't like is Google.
AOSP and Google need to be seperated. While Linux mobile would be nice, phones work differently than PCs and I don't think Linux will just "work" like it does on desktop. There's a reason why it's so far behind. Popularity and viability. I just don't think it's worth it.
Android is amazing. It's secure, great, snappy and it's still very open. However I do NOT trust Google that they will not fuck up the freedom aspect of it in the near future.
Agreed. It's time to have a truly open source OS. I didn't know that they had that opinion, but it doesn't surprise me. They seem extremely... determined is probably the nicest way I can put it.
I used to be enthusiastic about graphene, but between this and a few other things, I'm not sure pursuing using graphene is really worthy of my time, if only because of the devs' attitudes, or at least the attitude of whoever is doing their communications.
Starting to read this title had me in completely the wrong headspace and trying to recall any android 3 at all. Furthest back I could remember was 8er.
36 Comments
usernameunnecessary@lemmy.zip · 66 pts · 1d
I've said this many times and it's always on my mind. Google is a terrible steward for Android. We need alternatives that are viable and don't came with huge dealbreakers.
rockSlayer@lemmy.blahaj.zone · 16 pts · 1d
Hopefully Graphene is developing a hard fork of AOSP with Motorola, so they don't have to be reliant on Google
lemmyng@lemmy.world · 11 pts · 1d
That's why I was so gutted that DivestOS shut down. It was such a good alternative to GrapheneOS and was usable on phones other than Pixel.
I guess CalyxOS is the next best thing nowadays, since it can be used on some Motorola phones, Fairphones and the ShiftPhone 8:
https://calyxos.org/install/
vimmiewimmie@slrpnk.net · 2 pts · 7h
Though, I recently found out Motorola has license plate reading cameras and supposedly works with ICE. Which is gd gutting to hear.
https://wpde.com/news/local/flock-vs-automated-license-plate-readers-what-are-they-and-who-are-they-for-surveillance-ice-dhs-motorola-federal-government-court-lawsuit-artificial-intelligence-ai
https://www.motorolasolutions.com/en_us/video-security-access-control/license-plate-recognition-camera-systems.html
https://callmc.com/ai-transforming-public-safety-lpr-assist-ai/
Edit: From a reply below, this may be a different company? Looking into it now.
Edit: Looks like the cellphone company, Motorola Mobility LLC, is currently wholly owned by the, now Chinese company, Lenovo. So, certainly appears to be different organizations. Glass someone caught me on that.
rockSlayer@lemmy.blahaj.zone · 1 pts · 7h
Fuck. Guess I need to seriously reconsider
vimmiewimmie@slrpnk.net · 1 pts · 6h
Apparently, it may be a different company. Checking on that.
vimmiewimmie@slrpnk.net · 1 pts · 6h
Looks like the cellphone company, Motorola Mobility LLC, is currently wholly owned by the, now Chinese company, Lenovo.
traxex@lemmy.dbzer0.com · 1 pts · 7h
Wrong Motorola. There are two different companies.
vimmiewimmie@slrpnk.net · 1 pts · 6h
Oh shit. Fr? I'm totally uninformed. I'll look this up but any quick pointers to help?
traxex@lemmy.dbzer0.com · 1 pts · 6h
Motorola Solutions and Motorola Mobility are two separate companies created from the split of the original Motorola, Inc. in January 2011
keisatsu@infosec.pub · 1 pts · 1d
don't hope too much, they have admitted they are vibing it
wilmo@lemmy.ml · 18 pts · 1d
They specifically aren't vibing it though.
As they say it's useful to find vulnerabilities which is true.
And as far as code they said:
Which is the opposite of vibe coding.
It's fair to dislike any LLM usage. But it can have value. But it's often coming from unethical entities like OpenAI and Anthropic etc
rowinxavier@lemmy.world · 3 pts · 1d
I think this is the distinction of uses I canost get behind. If you find an attack using any tool, whether that be a CVE, a script kiddy, or an LLM, then you can go on to understand how the vulnerability works and patch it. This leaves the understanding part to the programmer, but not the arduous task of trying to find problems. If you use vibecoding to do the actual fixing you never have the understanding of how the code works and therefore what the changes will actually do.
LLMs can be useful in a lot of ways, but they should never replace thinking and understanding. Just like you do need to memorise some things but not others, there are cognitive tasks you don't have to do all the time but others you really have to in order to actually be a good programmer. If you outsource thinking you stop doing it and get weaker at it. If you outsource meaningless tasks or use systems to reduce the need for them that is actually useful for freeing up your mind for tasks which cannot be automated.
So in my view using these tools to find bugs in code can be useful. Knowing that if a bug is found it may not be disclosed to you by the tool because the provider of the tool wants to keep some bugs hidden is something people should consider, I mean that is exactly what the NSA has been going for decades with zero day exploits in various operating systems and platforms, why would they not do so now?
trevor@lemmy.blahaj.zone · 5 pts · 1d
Where?
keisatsu@infosec.pub · 3 pts · 1d
Their mastodon profile is talking at length about it.
lambalicious@lemmy.sdf.org · -1 pts · 1d
Shit, well that pretty much seals the deal on no Motophene for me. As if the Epstein Class price tag was not doing enough as a disincentive.
trevor@lemmy.blahaj.zone · 36 pts · 1d
Yet, the GrapheneOS devs will continue to insist that Linux isn't viable because of "security". Well, how useful is AOSP going to continue being with Google holding it hostage?? It sure seems to me that spending effort to make mobile Linux more secure and usable would be a much better long-term strategy than to keep developing for a dying, hostile ecosystem.
iturnedintoanewt@lemmy.world · 18 pts · 1d
The way i understand it, what Google did in Android is no joke, and definitely very hard to implement on a small team that basically works on just fine tuning your existing code. Birthing all this onto Linux is quite an undertaking, and it would need hardware partnership agreements.
theparadox@lemmy.world · 8 pts · 1d
Like almost everything Google has done, android was bought by Google. Admittedly, it's been quite a while since then and I couldn't tell you how much can be attributed to the original team vs Google's input.
trevor@lemmy.blahaj.zone · 6 pts · 1d
Yes, and the biggest thing Android has going for it in terms of security is the fact that everything runs with under a strict sandbox and permission model.
You could absolutely build a cohesive, secure Linux system using Flatpak to acheive something similar. It will still have rough edges and holes, but if GOS devs put in the same amount of effort into making Linux secure as they have with AOSP, we could get it to where it needs to be.
Quexotic@infosec.pub · 2 pts · 1d
Again, agreed, but hindsight is 20/20. I'm not sure if when they started in 2016, they would've believed that by this time, things would be going so badly. That said, I suppose we all really should have assumed they'd be enshittified as soon as google removed "Don't be evil" from their policy in 2018.
trevor@lemmy.blahaj.zone · 1 pts · 10h
For me, it's been pretty obvious that Android was going this direction for almost a decade, but any time people bring up mobile Linux, the GOS devs still bend over backwards to defend building for the dying AOSP ecosystem and speak ill of the security of Linux.
Quexotic@infosec.pub · 2 pts · 5h
They seem quite attached, don't they?
boonhet@sopuli.xyz · 1 pts · 5h
Yes. But for usability, the biggest thing Android has going for it is nothing technical, it's a ridiculous amount of apps to do literally anything you want and billions of existing users, which means more bugs are found and fixed. The mainline kernel Linux phone ecosystem does not have this and it's a bit of a hurdle.
trevor@lemmy.blahaj.zone · 1 pts · 5h
Yes, and that's why we should put effort into making mobile Linux have those things. A team of talented developers like the ones that GOS has could go a long way toward that.
boonhet@sopuli.xyz · 1 pts · 5h
I wish it was as easy, but remember, Microsoft, despite having an actually decent mobile operating system (the people I know who had Windows phones generally liked the UI), could not compete because they were too late to the market.
trevor@lemmy.blahaj.zone · 1 pts · 3h
Sure, but that was an entirely different world. 2011 was pre-Snowden leaks and before people ever considered what the modern era's tech giants would be doing. Google's motto was still Don't be evil and very few but the most privacy-conscious people disbelieved them. People had more skepticism of Microslop, but this was before the public had Windows 8, 10, or 11 pushed on them. There wasn't really a market for privacy-friendly mobile OS because the modern, smart mobile OSes had only existed for a few years at that point and the general public has not yet been as obviously betrayed by Google, Apple, or M$ at that point.
The modern era of tech has been so terrible that even politically uninvolved and privacy unaware folks are frothing at their mouths about datacenters & surveillance cameras and showing up to city council meetings to actually do something about it.
Still, I don't expect mobile Linux to dominate, even when it's ready. But there are plenty of people who are asking for it, beyond those that you would assume.
Another key difference between Windows Phone failing and the hypothetical chance for mobile Linux to succeed is that Linux has the largest pool of software developers to pull from and an unfathomable amount of software that won't even need to be manually ported to work on phones (some will, but most modern software use portable graphics libraries like GTK, Qt, etc.,).
Contrast that with Windows Phone being a bespoke, locked-down ecosystem with Linux having developer tools that more open, easy to integrate, and better documented than any proprietary walled-garden ever did.
Getting apps for mobile Linux won't be an issue like it was for Windows Phone except for cases like banks and other draconian companies. And those are important exceptions, but those can be overcome just as Linux gaming has. If those companies refuse to build for us, then we will build for ourselves, and they will be forced to cooperate when we become undeniable.
And even if you don't share my optimism for what future mobile Linux adoption might look like, I think we can agree that regardless of mobile Linux's "market success", people are going to build it anyway because people will always build cool stuff just for the love of the game. I just wish large teams like Graphene would consider divesting from AOSP and start putting some effort into mobile Linux in the long term.
::: spoiler Edit:
Sorry if that sounded goofy. I had drugs for the first time. They do really interesting stuff to your cognition! It may affect the way I write 🙃
:::
halm@leminal.space · 2 pts · 17h
Yes, corporations buy up small businesses and startups. In this case all they got seems to be the Android name and an idea to make a phone OS? AFAICT the project was neither open source or based on the Linux kernel until Google took over.
I'm not trying to whitewash Google here, they did that pretty well themselves in open sourcing Android development. That's given them a 20+ years alibi to be complete arseholes in pretty much any other part of their business — and now they're clamping down on Android, too.
hyperio@lemmy.dbzer0.com · 6 pts · 22h
Android is not the problem here. In fact I love Android very much. What I don't like is Google.
AOSP and Google need to be seperated. While Linux mobile would be nice, phones work differently than PCs and I don't think Linux will just "work" like it does on desktop. There's a reason why it's so far behind. Popularity and viability. I just don't think it's worth it.
Android is amazing. It's secure, great, snappy and it's still very open. However I do NOT trust Google that they will not fuck up the freedom aspect of it in the near future.
Quexotic@infosec.pub · 3 pts · 1d
Agreed. It's time to have a truly open source OS. I didn't know that they had that opinion, but it doesn't surprise me. They seem extremely... determined is probably the nicest way I can put it.
I used to be enthusiastic about graphene, but between this and a few other things, I'm not sure pursuing using graphene is really worthy of my time, if only because of the devs' attitudes, or at least the attitude of whoever is doing their communications.
sem@lemmy.blahaj.zone · 13 pts · 1d
I didn't realize we were getting so close to the future
ColeSloth@discuss.tchncs.de · 2 pts · 1d
Starting to read this title had me in completely the wrong headspace and trying to recall any android 3 at all. Furthest back I could remember was 8er.
Goodlucksil@lemmy.dbzer0.com · 5 pts · 20h
Android 3 did exist, but it was only released on tablets around 2011-12
ColeSloth@discuss.tchncs.de · 2 pts · 14h
Dragon ball, man. I was thinking dragon ball.
Goodlucksil@lemmy.dbzer0.com · 2 pts · 14h
Oh yeah, those Androids. I haven't seen Dragon Ball so I didn't make the connection.
ColeSloth@discuss.tchncs.de · 1 pts · 9h
Yeah. I've actually been using Android since v1.xx