992 points by theanonymousone about 22 hours ago | 555 comments | View on ycombinator
wps about 22 hours ago |
bri3d about 21 hours ago |
* Google drop "real" Android source-code updates to OEMs _and_ the public every half.
* But they ship four Pixel updates, including documentation + SDKs.
* Now they added new APIs in a Pixel-only update.
* Google also drop security update backports to "trusted" OEMs monthly (which GrapheneOS have had access to for years).
So, there are now Pixel-exclusive app features on the Pixel SDK version which isn't available to OEMs - but, it's highly unlikely any app developer would actually depend on these new APIs, since Pixel marketshare is tiny to begin with. This in essence just makes Pixels a weird beta-testing device for what will come out a quarter later to "normal" devices, which is sort of an odd business decision, but also a weird thing to get really mad about, in my opinion (I do see what GrapheneOS are trying to do, with having OEMs saber-rattle about not getting features on the same cadence as Pixels, it just doesn't resonate very loudly for me).
However, the API headline seems to bury a deeper lede; in the thread, GrapheneOS also claim that the quarterly Pixel releases contain security content which is not appearing in the monthly backports. This is quite bad and very sloppy if true, since the Pixel releases can easily be patch-diffed and exploits backed out of them. I'd be interested in seeing this enumerated in more depth.
publlus_enigma about 17 hours ago |
largbae about 21 hours ago |
GrapheneOS has the bootable AOSP and will have Google-alternative device support.
We probably need an equivalent to Play Services, app signing/porting/publishing tools.
With these in hand could we talk Valve into providing the scalable alternative to the play store?
hacker_homie about 13 hours ago |
Regulate them! that is the only way.
Their should be a path for an AOSP build to be just as privileged as a google signed build.
undefined about 1 hour ago |
Ajedi32 about 21 hours ago |
So it seems like the problem isn't that the new API is Pixel exclusive, but that the first and third quarterly release patches each year are Pixel exclusive?
barbazoo about 21 hours ago |
mahboi about 1 hour ago |
But if Pixels are getting early access to security patches too, that's more like one hat.
natterangell about 21 hours ago |
cromka about 2 hours ago |
teekert about 21 hours ago |
xnx about 21 hours ago |
saidnooneever about 5 hours ago |
especially since its radio and thats not too easy to determine if a device is or isnt sending weird stuff. (dont come with the lte or wifi sniffers or such things. u'd need thorough spectrum analysis during operations on a quite broad spectrum too to rule that out. the antennae in the devices can produce a lot of types of signals... or do they decap the chips and reverse those to see whats in it? i doubt it would be possible at the right scale but theres options i guess.
people in certain regions/ high assurance security work roles will do this to hundreds of devices that are identical to try and determine if a supplier is compromised or not. order a full batch, take em all apart. taking x-rays, dissolving chips package, etching layers one by one, taking pictures with electron microscopes etc, probing bond wires in the packages as they run etc etc.
somehow i dont see some OS creator do all of this, but ofc i could be very wrong :). interested to find out why people think google while with a different OS is truly de-googled or if they kinda just hope for the best...
Velocifyer about 21 hours ago |
DrewADesign about 16 hours ago |
TeMPOraL about 5 hours ago |
I hoped we'll get an OS more amenable to opening up the device, exposing its capabilities to the owner, but alas, I fear there is no way for an OS to survive in this space unless it acts the same way the Big Two do. As it is, I can't help to think that Graphene is just the same as Google and Apple: just another security-maximizing vendor owning your computer.
Ritewut about 15 hours ago |
petcat about 21 hours ago |
tyrabound about 6 hours ago |
People thought they were part of some collaborative, good of the world type effort, when the reality is that there were always ulterior and hidden motives to manipulate and exploit that gullible and rather foolish nature of Americans in particular; a foolishness that has long, if not always existed in the genuine American core character, but at the very least was cultivated and even selected for a long time ago.
How do you motivate people in modern times to do free labor for you as the parasitic ruling class without the threat or resort to violence? You of course trick them into believing that what they are doing or support makes them a good boy, regardless of all the evidence and proof to the contrary.
solarkraft about 7 hours ago |
QuantumGood about 17 hours ago |
exabrial about 21 hours ago |
VerifiedReports about 7 hours ago |
The great "open-source" OS that was supposed to free us all from vendor and telco tyranny has... not.
LelouBil about 6 hours ago |
varispeed about 2 hours ago |
pino83 about 6 hours ago |
IronWolve about 21 hours ago |
We live in a time, if you want to build an android app, you easily can, but installing will be harder due to google concerns.
rustcleaner about 16 hours ago |
Go bankrupt, Alphabet!
jauntywundrkind about 2 hours ago |
soleil-colza about 12 hours ago |
matheusmoreira about 19 hours ago |
Respect for the GrapheneOS for pushing through regardless, even if they have to reverse engineer stuff. Can't wait to buy their phone.
vkaku about 21 hours ago |
m4rtink about 10 hours ago |
ironqcold about 20 hours ago |
VCFundedGenYer about 22 hours ago |
palata about 20 hours ago |
claudiojulio about 20 hours ago |
linzhangrun about 9 hours ago |
jokoon about 19 hours ago |
Of course it's not great for their business model. Not to mention, no more trustworthy app distribution.
I don't see the EU really being able to forcing them to de-google android phones.
I am also curious how much those phones would cost, BTW, since the cost calculation to release such an OS would be a bit complicated.
HumblyTossed about 18 hours ago |
cton about 9 hours ago |
fithisux about 13 hours ago |
Governments are paid out to not intervene. They should have stepped in decades ago. They should have made Google to release source code and interoperate with public services. They already make profit from their services.
tomaskafka about 6 hours ago |
jauntywundrkind about 19 hours ago |
https://digital-markets-act.ec.europa.eu/developer-portal/in...
Side note, that API here is HID. USB HID is so cool. There's so much stuff in this spec! Chargers and batteries can both communicate all kinds of status, which, well, afaik no one does, there's all kinds of sensors. It's this ancient spec that has so much, and weirdly is just so far ahead of where we are. More HID on Android will be great. Wish they'd played with others to make this so though!
hagbard_c about 21 hours ago |
ahmd-sh about 22 hours ago |
Graphene is reaching that status for me every day and i'm looking forward to switching to it as my daily driver.
shevy-java about 21 hours ago |
Onavo about 21 hours ago |
dingdong2026 about 21 hours ago |
undefined about 15 hours ago |
charcircuit about 16 hours ago |
escanor about 12 hours ago |