Because the EU wants attestation for age verification, digital surveillance and censorship, not free software platforms that wont implement any of those.
Well that was the original android phone idea. Get a hackable open device that you can write apps for your self. Even attach third party hardware to it for extra functionality with lots of customisation. But this idea has mutated quite a bit.
Even by 2015 the noise in Google was “the Chrome OS model is better” with reference to them centrally controlling everything.
Andy Rubin was no saint, on so many levels, but when he was removed from Android leadership and the Chrome culture effectively took over this was always how it was going to go.
I fully agree with it. But I think Google also understands that the platform is unatractive for businesses. In my case I just don't do Android app because I know it is easy to just take and hack. It is not the case on iPhone. And my app is one time payment so the ability to just copy out the APK leaves me not doing an app at all...
It is a bit different. My app doesn't rely on 3rd party services at all. It just provides functionality.
It is not about breaking into someones account.
I just know that the app can just be cracked - there are plenty of sites that do that for android. Because you can't just load your app on iOS - this is just not possible (well perhaps there are a few percent of some jailbroken iPhones, but that is neglibile).
On Android though, you can soon see such app stolen and on some of the apk warez sites. It just breaks the model.
The crypographic flow that allows payments to work is straight up pub/priv key encryption with one time use tokens. It's not something you can hack. As soon you see the token it's already been used and thrown away. So whatever nonsense about decompiling literally doesn't matter.
He said his app is a one time payment. Presumably there isn’t a backend and he relies on App Store purchases. I know, it’s shocking an app could just be an actual application rather than a web view.
So your professional opinion is that the attack surface of mobile banking apps is limited to tokenized payments? Honestly, I'd be appalled if tokens were routed through my banking app. There is no reason the local client needs that data.
My professional opinion is that APKs can be de-compiled regardless and that has nothing to do with tokenized payments themselves which are like you said handled through server-server communications at the payment processor level. Your phone simply sends a one time use token to authorize the transaction.
The payment doesn't happen on the device. It happens at the VISA/Mastercard/AMEX level. So "the app" should be doing the validation upstream on the server side and simply reporting yes/no to the app. If you hack the yes/no okay but most payments are for physical things IRL so the payment gateway that is not on your phone is gonna be like ??? - in other words it's on the app not to trust a raw true/false signal and instead rely on server side checks. This is all irrelevant. I make regular massive purchases on my linux box where I can read the memory. It doesn't change anything.
The EU has enough tech talent to do it, but the political and managerial class lack both the strategic ability or the willingness to adequately reward the effort it would take, almost certainly preferring to, again, outsource the concern, and then be shocked Pikachu later.
Anyone doubting this should see how BMW think about their in car software. And that is for a supposedly premium product.
There's GrapheneOS. It's Canadian, not European. I'm not sure where LineageOS is from.
BMW isn't the EU government. Like I said, someone has to actually do it. BMW Actually Did It in a really user hostile way, and that's the best we have. Why is nobody Actually Doing It but good? Or why aren't we buying MNT products?
BMW behaviour is perfectly representative of the EU mentality.
As is your comment. It is basically “someone else should do this properly and I will take the benefits” but not actually willing to put up the hard bit themselves.
The root problem here is the EU is culturally broken, and until some grand disaster will simply decline ever further with everyone involved wondering why no one else is doing anything about it.
If the govvies (any govvies; there is nothing specific to EU here) drive that process of forking a large, powerful, universally used system you will end up with more surveillance, not less.
Because kids, because pornography, because terrorism, whatever. This is too powerful an option for control freaks to resist.
And this is why everyone gives up on doing anything while standing around complaining that no one does the right thing.
What is so pernicious about the EU approach is the enthusiasm and efficiency with which it stops anyone from doing anything, while simultaneously attempting to regulate what everyone else in the world can do. If they put even a small part of that energy into encouraging the right thing to happen they would be in such a better place it is insane.
Honestly your reading comprehension is not good today.
They said if the government “drive the process of forking” which could mean encourage a group of academics to do it, or a commercial consortium. It does not mean the EU government take on the task themselves.
It is self evident from actual EU behaviour that any mobile os that gets to users will be legally required to be a surveillance disaster area, regardless of origin, and the only people that have prevented this already are evil US corporations.
I'm not 100% sure about surveillance but you will definitely end up with the most milquetoast risk-averse bland corporate system ever, complete with 6 months of paperwork and KYC to get a certificate to sign any executable with your real name, so it will be allowed to run.
They can make the product according to rules that are imposed on them. One rule: allow privacy. Unless the privacy is not in the field of interest of both the producer and the EU
While the EU and its member countries can't (or at least morally shouldn't) force people to make the product, if it was a priority they could incentivise it with funding, tax breaks, etc.
There is no shortage of general-purpose computing hardware in the EU. If you need some general-purpose compute to make a car, an oven, or a phone, you can get it. That consumers mostly buy special-purpose devices that don't always allow them to make full use of the possibilities of the hardware is hardly a sovereignity challenge.
yeah but processors phone home anyway at a level beneath the OS and there’s no european chip development worth mentioning. so i’m not sure real sovereignty is ever going to be possible. crazy considering ASML being in europe.
In the next decade open hardware will win, any machine that exposes itself to be programmed by its user will be infinitely better than a machine that doesn't.
From keyboards to phones to tractors.
The appstore will die, and the walled gardens will die.
Unless they use 'for the children' to make open machines illegal.
GrapheneOS has minimal, private [1] system apps so you don't have to debloat anything yourself. Manual debloating is not a good solution at the user level.
Some system apps are being overhauled, so that's something to look forward to. Gallery will be [2] based on ReFra [3].
[1] Except phone and messaging but that's the cell network.
GrapheneOS recommends Signal/Molly or SimpleX instead.
GrapheneOS or other custom ROMs don't solve the actual problem that you can't just buy a smartphone and install any operating system like you can with an actual computer, despite technically being one.
Also, GrapheneOS supports device attestation (the non-google kind at least), which is still ridiculous as such systems have no benefit to people, only to technofeudalist corporations.
Device attestation is how you can use private keys you don't actually have access to. It has a lot of value to literally anyone who wants to store tokens or use one time authentication codes. Linux folks need to implement the full stack and offer an open alternative to payments, secrets, and tokens. In the age of LLMs there is no excuse. It is annoying as hell that I can't buy a System76 or Framework laptop with a fingerprint sensor but a Lenovo comes with one that works on Linux perfectly.
It needs to come stock on every Linux laptop from now going forward period. Like you expect a screen to come with your machine. Every Mac has one now and I'm not going back to typing my password in every single time.
If this is your stance it's trivial to have your cake and eat it. You can easily build your own GrapheneOS based image, which will then be unable to use attestation (because your own keys you'll use for the secure boot won't match).
And I'm not trying to be snarky, if that's the only thing, it's solvable right now. Everything else will work.
And concerning "you can't just buy a device and install is" - android and iOS are far more secure than any desktop os, and both pixel/iPhones are far more secure than any computer (or any other phone as well (we'll get the third one next year)). GrapheneOS actually explains "whys" in their hardware support faw section.
Generally maintaining an os is a hard work, so that perhaps explains why there's not many mature offerings.
GrapheneOS has got absolutely nothing to do with any of this. LineageOS, pure AOSP, are all the same. No bloat, no locks.
The way they've successfully marketed a more involved custom ROM as a special OS to tech illiterates is very funny I'll admit.
And Graphene OS is also anti-user by being tremendously rude about NOT providing root and using the same tired "suck-u-rity" crap Google and Apple also use.
If you're smart enough to buy a phone that supports GrapheneOS, AND install it, yeah you should have root.
And tools like XPrivacy and plugins allow control of subsystems like GPS spoofing and lying to apps.
If you are technical and want root its very easy to patch a build of GrapheneOS to include whatever mechanism you want. You can even automate this to continue to receive updates.
I think the decision of GrapheneOS to maintain the attestation features and not providing user root is what gives it a fighting chance of being accepted as legitimate 3rd choice. See: Revolut and others adding GrapheneOS keys and trusting their attestation
Like or not, for most users, having root access is a liability, especially with more and more important things being held on phones . Someone downloading a photo editing app and then having a rootkit installed in the background that waits to empty their bank account is not a workable situation.
>If you are technical and want root its very easy to patch a build of GrapheneOS to include whatever mechanism you want. You can even automate this to continue to receive updates.
You don't even need to patch it, AFAIK. You can just install magisk, which is how you're supposed to get root on LineageOS as well.
GrapheneOS's goals are privacy which must start from a secure baseline. If you want to make it less secure yourself, you can, but it's not the goal of the project.
It's not anti-user if it doesn't add the features you want that would destroy the security of the OS.
It has many features that give the user more control. Like disabling emergency alerts, protecting your data from attackers, contact and storage scopes (lying to apps for more privacy while retaining functionality), sensors permission, network permission.
Seriously question; why is the answer to this not a phone that can just run GNU/Linux? Is it just the lack of application support? I mean, you’ll have blobs, but at least at the os level you’ll have options?
Because this will be less profitable. Google created a cartel-like model where if you make a device that doesn't respect user choice, you will make more money because Google will share with you, providing you obey their rules.
This model is attractive for almost everyone - Google, OEMs, operators and even governments.. the only side that loses here is.. the user.
This situation can't be solved with market forces alone, it must be solved by law.
Desktop operating systems != phone operating systems. You need to have a lot of support for things like "sleep apps you're not using right now" or you'll burn through battery. Not to mention that we tend to expect a lot of functionality which only works when the OS enables it, e.g. the sort of app-to-app coordination enabled by Android's App Intents. You certainly could build something like that on top of DBus, but, well, you'd have to build it.
This seems to be a case of “I want to use services from companies that are built on business models hostile towards my sovereignty, privacy, and rights! ; I can’t believe hostilecorp wont let me work around their hostileOS?”
I mean, it really sucks that so many people have made themselves dependent on this crap, but at some point you just have to stop buying the poison or stop complaining that it makes you sick.
The poison to utility ratio has gotten so high that it’s getting increasingly attractive just to ditch the whole thing. You either have to draw the line or accept that there is no line, and that you will yield any degree of agency in exchange for convenience.
For so many people, big corporations decide what they will buy, where they will eat, who they will date, how they will interact, what they believe, where they will go, how they will get there.
Multiple choice is not choice. It is the illusion of choice in a fully packaged life.
xdg already provides "portals" and "XDG Intents" that implement most of what android does. Flatpak implements most of the sandboxing you have on android. It doesn't have feature parity but IMO it doesn't need to. CGroups and systemd-user can prevent apps from running in the background.
I think it might be a good idea to pause updates on our Android devices, as horrible as it is for security just to prevent this from happening. My OEM has a lot of bloat (Facebook and other junk apps you can't uninstall, useless system services, etc) that mostly do nothing except provide some functionality I don't use along with analytics every minute so they are uninstalled.
"Disabling" an app does not do that much, the OS can re enable it with an update or prevent you from disabling it.
I doubt there is true full privacy on a phone anymore with a stock ROM.
Every single reboot on my lower end Motorola phone, they have decided it fit to re-enable com.glance.lockscreenM every single boot and on every single update.
It's horrible. I don't think I can trust them to produce a Graphene phone at all, really, despite all of everyone's assurances.
At least you can disable it; on some phones (especially Chinese phones) you cannot do anything to the system services, they intercept all app requests, essentially what Google did but with their system. The only recommendation I can give you is to look into Hail (device-owner app that can "freeze" apps, a "lower level" form of disabling, see https://f-droid.org/en/packages/com.aistra.hail/) which will mean even if the app gets reinstalled on system update, the device owner app will prevent it from running.
I think GrapheneOS might have issues in the future considering that Android will be getting more and more locked down. People say GrapheneOS is the better OS when it just is hardened Android; it is doomed purely because of the Android base.
Perhaps a Linux based edition of GrapheneOS would do well, even if it will not have a lot of app compatibility. There's only so much patching you have to do to Android before it just becomes more work than good.
This sucks. I use adb to uninstall all of the system apps like facebook, youtube, web browser, etc. to give myself a minimalist, distraction-free phone that still has niche apps, maps, and communication apps. Might have to look into the expensive light phones as an alternative now if this update hits my phone.
I had the exact same problem because I had a strong addiction to smartphone apps.
I looked into the Light Phone and The Mudita Kompakt, but I ended up buying a refurbished Pixel 8 and putting Graphene OS on it, then I installed only essential apps I need. I keep my old iPhone 12 in a drawer at home and use it for anytime I Need any apps that don't work on a custom ROM, which includes my bank app (plus, imo, it's safer not carry around a phone that has my baking data on it in case it gets lost or stolen).
The light phones are a really cool concept but the Light Phone 3 is quite expensive (more expensive than a new Pixel 10) and the Mudita Kompakt seems to have a huge amount of grievances from users on their forum, so that put me off.
Extremely "Googly" responses there. Not a single mention of the strategy of Google to include, oh, payment, social gaming, ads ... effectively building it into the system and totally disregarding the reasoning that people might want to remove or replace Google Play Services for those reasons. Just act like all that doesn't exist.
Why would you uninstall them over disabling them? They make good point uninstalling is pointless, disabling achieves same purpose and it is safer. You can't use that system space anyway.
if you don't want some system app running just "uninstall" (disable) it with Shizuku + Canta on any non-rooted Android, my current phone is the first one in 15 years with Android which I didn't root since unlocking bootloader on XIaomi is pretty much impossible, but anyway I can achieve pretty much same results with Shizuku and additional apps like Canta, Hail, Shizuwall, etc.
Potential benefits:
as mentioned, Android 17 prohibits uninstalling system apps, but allows disabling
disabling apps is usually safer, and they could be re-enabled from Settings in some cases
many system apps run in the background after being uninstalled, but it's unknown whether they do when disabled.
Neutral:
some apps might get re-enabled unless they're uninstalled (or the opposite).
Potential harm:
that would make it more risky for those who prefer to uninstall instead to save storage
most of the already listed apps are primarily tested for uninstalling rather than disabling
disabling instead, decreases privacy by not hiding apps, keeping the device unique.
Noose keeps tightening, the war on General Purpose Computing, the war against users owning devices intensifies. How utterly fallen.
We'll see what happens with the proposed ADB changes. Lots of no one asking for this, lots of people describing how badly their phone use will be greviously impacted, and seemingly very little discussion/engagement/justification. Maybe they'll fire the bullet anyways. https://issuetracker.google.com/issues/526109803
I said the same thing about waiting for 24hrs before being able to use adb to install apps. About 24hrs being not a big blocker and that it was good for security. It's all about boiling the frog slowly, 24hrs is the start and then they'll add more restrictions once users accept that. Ultimately goog would like to have the system as much locked down as apple or even more.
Maybe they're right, albeit for all the wrong reasons.
Perhaps the problem is our desire to have everything, no matter what the compromises are. Perhaps the problem is our inability to say, I'm going to go with product X even though it lacks Y because we actually own X. There is virtually no incentive for competition to pop up in such an environment since established companies have a lead of years, decades if you consider the size of the established companies, so consumers will follow their lead.
I don't mean to suggest that buying alternatives is a solution to the problem as a whole, but doing so may allow enough niche products to survive to give those of us who are interested in alternatives and alternative to choose from.
I don't understand why ensuring general-purpose computing is not a priority of the European Union.
All that talk about sovereignty, and we are giving full control of our digital lives to 2 American companies.
Because the EU wants attestation for age verification, digital surveillance and censorship, not free software platforms that wont implement any of those.
Well that was the original android phone idea. Get a hackable open device that you can write apps for your self. Even attach third party hardware to it for extra functionality with lots of customisation. But this idea has mutated quite a bit.
Even by 2015 the noise in Google was “the Chrome OS model is better” with reference to them centrally controlling everything.
Andy Rubin was no saint, on so many levels, but when he was removed from Android leadership and the Chrome culture effectively took over this was always how it was going to go.
I fully agree with it. But I think Google also understands that the platform is unatractive for businesses. In my case I just don't do Android app because I know it is easy to just take and hack. It is not the case on iPhone. And my app is one time payment so the ability to just copy out the APK leaves me not doing an app at all...
> I know it is easy to just take and hack
No you don't, otherwise we wouldn't have banking apps on it.
It is a bit different. My app doesn't rely on 3rd party services at all. It just provides functionality. It is not about breaking into someones account.
I just know that the app can just be cracked - there are plenty of sites that do that for android. Because you can't just load your app on iOS - this is just not possible (well perhaps there are a few percent of some jailbroken iPhones, but that is neglibile).
On Android though, you can soon see such app stolen and on some of the apk warez sites. It just breaks the model.
Have you tried extracting, decompiling, and modifying someone else's app?
It wasn't hard before LLMs and it's nearly trivial now.
Is that not possible with ios applications?
You can't sideload iOS applications. Meaning there's no point to doing any of the listed things.
Of course you can. How do you think developers test their apps?
The crypographic flow that allows payments to work is straight up pub/priv key encryption with one time use tokens. It's not something you can hack. As soon you see the token it's already been used and thrown away. So whatever nonsense about decompiling literally doesn't matter.
He said his app is a one time payment. Presumably there isn’t a backend and he relies on App Store purchases. I know, it’s shocking an app could just be an actual application rather than a web view.
So your professional opinion is that the attack surface of mobile banking apps is limited to tokenized payments? Honestly, I'd be appalled if tokens were routed through my banking app. There is no reason the local client needs that data.
My professional opinion is that APKs can be de-compiled regardless and that has nothing to do with tokenized payments themselves which are like you said handled through server-server communications at the payment processor level. Your phone simply sends a one time use token to authorize the transaction.
You were the one that brought up payments though. Nobody else specified. They just said it could be hacked, which you seem to agree with.
You can patch out the payment checks if you can decompile it
The payment doesn't happen on the device. It happens at the VISA/Mastercard/AMEX level. So "the app" should be doing the validation upstream on the server side and simply reporting yes/no to the app. If you hack the yes/no okay but most payments are for physical things IRL so the payment gateway that is not on your phone is gonna be like ??? - in other words it's on the app not to trust a raw true/false signal and instead rely on server side checks. This is all irrelevant. I make regular massive purchases on my linux box where I can read the memory. It doesn't change anything.
Sovereignity of the EU regime, not of their subjects.
Why would these corrupt bureacrats give up their full control over the lives of those who didn't elect them?
I'm sure Europe currently uses the surveillance capabilities of those systems to prevent bad shit from happening.
So maybe they prefer another solution to the sovereignty issue.
It's a regulated market economy. Someone has to actually make the product. They can't force someone to make a product.
There's MNT in the EU.
Do what the Chinese did and fork Android.
The EU has enough tech talent to do it, but the political and managerial class lack both the strategic ability or the willingness to adequately reward the effort it would take, almost certainly preferring to, again, outsource the concern, and then be shocked Pikachu later.
Anyone doubting this should see how BMW think about their in car software. And that is for a supposedly premium product.
There's GrapheneOS. It's Canadian, not European. I'm not sure where LineageOS is from.
BMW isn't the EU government. Like I said, someone has to actually do it. BMW Actually Did It in a really user hostile way, and that's the best we have. Why is nobody Actually Doing It but good? Or why aren't we buying MNT products?
BMW behaviour is perfectly representative of the EU mentality.
As is your comment. It is basically “someone else should do this properly and I will take the benefits” but not actually willing to put up the hard bit themselves.
I'm talking about the government of the EU. You seem to be talking about all the countries and the people in the countries.
You need to parse the word mentality in context.
The root problem here is the EU is culturally broken, and until some grand disaster will simply decline ever further with everyone involved wondering why no one else is doing anything about it.
Why don't we export some better culture to Europe then? That would be a good place and now would be a good time for Americans to flee to.
You couldn’t epitomize the problem more if you tried.
If the govvies (any govvies; there is nothing specific to EU here) drive that process of forking a large, powerful, universally used system you will end up with more surveillance, not less.
Because kids, because pornography, because terrorism, whatever. This is too powerful an option for control freaks to resist.
And this is why everyone gives up on doing anything while standing around complaining that no one does the right thing.
What is so pernicious about the EU approach is the enthusiasm and efficiency with which it stops anyone from doing anything, while simultaneously attempting to regulate what everyone else in the world can do. If they put even a small part of that energy into encouraging the right thing to happen they would be in such a better place it is insane.
Not really. They weren't saying if it existed in the EU it'd have to surveil. They were saying if the EU government created it it'd have to surveil.
Honestly your reading comprehension is not good today.
They said if the government “drive the process of forking” which could mean encourage a group of academics to do it, or a commercial consortium. It does not mean the EU government take on the task themselves.
It is self evident from actual EU behaviour that any mobile os that gets to users will be legally required to be a surveillance disaster area, regardless of origin, and the only people that have prevented this already are evil US corporations.
I'm not 100% sure about surveillance but you will definitely end up with the most milquetoast risk-averse bland corporate system ever, complete with 6 months of paperwork and KYC to get a certificate to sign any executable with your real name, so it will be allowed to run.
They can make the product according to rules that are imposed on them. One rule: allow privacy. Unless the privacy is not in the field of interest of both the producer and the EU
Yes, you could make the product. But you're not. And neither is anyone else. And there's nothing the EU government can directly do about that.
Then why are you not making it?
While the EU and its member countries can't (or at least morally shouldn't) force people to make the product, if it was a priority they could incentivise it with funding, tax breaks, etc.
NLnet funds a lot of things, few of which get very popular. It keeps a lot of FOSS gears turning but it's not making the next iPhone.
They could give more funding to SailfishOS, for example
Sailfish would have to ask for it. Possibly via NLnet. Have they?
And they need a plan to spend it.
There is no shortage of general-purpose computing hardware in the EU. If you need some general-purpose compute to make a car, an oven, or a phone, you can get it. That consumers mostly buy special-purpose devices that don't always allow them to make full use of the possibilities of the hardware is hardly a sovereignity challenge.
Show me where I can get a general-purpose computing hardware with 8GB+ of RAM that fits in my pocket and has a touchscreen.
why do you still believe that EU is a benevolent entity?
Either a paid shill or a useful idiot.
yeah but processors phone home anyway at a level beneath the OS and there’s no european chip development worth mentioning. so i’m not sure real sovereignty is ever going to be possible. crazy considering ASML being in europe.
In the next decade open hardware will win, any machine that exposes itself to be programmed by its user will be infinitely better than a machine that doesn't.
From keyboards to phones to tractors.
The appstore will die, and the walled gardens will die.
Unless they use 'for the children' to make open machines illegal.
GrapheneOS has minimal, private [1] system apps so you don't have to debloat anything yourself. Manual debloating is not a good solution at the user level.
Some system apps are being overhauled, so that's something to look forward to. Gallery will be [2] based on ReFra [3].
[1] Except phone and messaging but that's the cell network.
GrapheneOS recommends Signal/Molly or SimpleX instead.
[2] https://nitter.net/GrapheneOS/status/2083724696722301266#m
[3] https://github.com/IacobIonut01/ReFra
GrapheneOS or other custom ROMs don't solve the actual problem that you can't just buy a smartphone and install any operating system like you can with an actual computer, despite technically being one.
Also, GrapheneOS supports device attestation (the non-google kind at least), which is still ridiculous as such systems have no benefit to people, only to technofeudalist corporations.
Device attestation is how you can use private keys you don't actually have access to. It has a lot of value to literally anyone who wants to store tokens or use one time authentication codes. Linux folks need to implement the full stack and offer an open alternative to payments, secrets, and tokens. In the age of LLMs there is no excuse. It is annoying as hell that I can't buy a System76 or Framework laptop with a fingerprint sensor but a Lenovo comes with one that works on Linux perfectly.
Framework has a fingerprint sensor. [1]
[1] https://frame.work/products/fingerprint-reader-kit?v=FRANTD0...
It needs to come stock on every Linux laptop from now going forward period. Like you expect a screen to come with your machine. Every Mac has one now and I'm not going back to typing my password in every single time.
>which is still ridiculous as such systems have no benefit to people, only to technofeudalist corporations.
GrapheneOS literally has an app that uses attestation and isn't for "technofeudalist corporations".
https://attestation.app/about
If this is your stance it's trivial to have your cake and eat it. You can easily build your own GrapheneOS based image, which will then be unable to use attestation (because your own keys you'll use for the secure boot won't match).
And I'm not trying to be snarky, if that's the only thing, it's solvable right now. Everything else will work.
And concerning "you can't just buy a device and install is" - android and iOS are far more secure than any desktop os, and both pixel/iPhones are far more secure than any computer (or any other phone as well (we'll get the third one next year)). GrapheneOS actually explains "whys" in their hardware support faw section.
Generally maintaining an os is a hard work, so that perhaps explains why there's not many mature offerings.
GrapheneOS has got absolutely nothing to do with any of this. LineageOS, pure AOSP, are all the same. No bloat, no locks. The way they've successfully marketed a more involved custom ROM as a special OS to tech illiterates is very funny I'll admit.
What does GrapheneOS have to do with this?
This is very useful on OEM ROMs with a bunch of scrapware, no one expects a custom ROM to have this issue.
in grapheneOS you can disable or uninstall almost everything without adb anyways
And Graphene OS is also anti-user by being tremendously rude about NOT providing root and using the same tired "suck-u-rity" crap Google and Apple also use.
If you're smart enough to buy a phone that supports GrapheneOS, AND install it, yeah you should have root.
And tools like XPrivacy and plugins allow control of subsystems like GPS spoofing and lying to apps.
If you are technical and want root its very easy to patch a build of GrapheneOS to include whatever mechanism you want. You can even automate this to continue to receive updates.
I think the decision of GrapheneOS to maintain the attestation features and not providing user root is what gives it a fighting chance of being accepted as legitimate 3rd choice. See: Revolut and others adding GrapheneOS keys and trusting their attestation
Like or not, for most users, having root access is a liability, especially with more and more important things being held on phones . Someone downloading a photo editing app and then having a rootkit installed in the background that waits to empty their bank account is not a workable situation.
>If you are technical and want root its very easy to patch a build of GrapheneOS to include whatever mechanism you want. You can even automate this to continue to receive updates.
You don't even need to patch it, AFAIK. You can just install magisk, which is how you're supposed to get root on LineageOS as well.
GrapheneOS's goals are privacy which must start from a secure baseline. If you want to make it less secure yourself, you can, but it's not the goal of the project.
It's not anti-user if it doesn't add the features you want that would destroy the security of the OS.
It has many features that give the user more control. Like disabling emergency alerts, protecting your data from attackers, contact and storage scopes (lying to apps for more privacy while retaining functionality), sensors permission, network permission.
Seriously question; why is the answer to this not a phone that can just run GNU/Linux? Is it just the lack of application support? I mean, you’ll have blobs, but at least at the os level you’ll have options?
Can’t you run an android sandbox in Linux?
Docker phone?
I’m sure I’m missing something here, but what?
Many of the apps that people need to have smartphone to access will not run in an Android sandbox. Banking apps are the obvious example.
Not to mention that the options outside iOS and Android are slim and for the most part bad (or atleast simply even worse than those).
Because this will be less profitable. Google created a cartel-like model where if you make a device that doesn't respect user choice, you will make more money because Google will share with you, providing you obey their rules.
This model is attractive for almost everyone - Google, OEMs, operators and even governments.. the only side that loses here is.. the user.
This situation can't be solved with market forces alone, it must be solved by law.
Desktop operating systems != phone operating systems. You need to have a lot of support for things like "sleep apps you're not using right now" or you'll burn through battery. Not to mention that we tend to expect a lot of functionality which only works when the OS enables it, e.g. the sort of app-to-app coordination enabled by Android's App Intents. You certainly could build something like that on top of DBus, but, well, you'd have to build it.
This seems to be a case of “I want to use services from companies that are built on business models hostile towards my sovereignty, privacy, and rights! ; I can’t believe hostilecorp wont let me work around their hostileOS?”
I mean, it really sucks that so many people have made themselves dependent on this crap, but at some point you just have to stop buying the poison or stop complaining that it makes you sick.
The poison to utility ratio has gotten so high that it’s getting increasingly attractive just to ditch the whole thing. You either have to draw the line or accept that there is no line, and that you will yield any degree of agency in exchange for convenience.
For so many people, big corporations decide what they will buy, where they will eat, who they will date, how they will interact, what they believe, where they will go, how they will get there.
Multiple choice is not choice. It is the illusion of choice in a fully packaged life.
xdg already provides "portals" and "XDG Intents" that implement most of what android does. Flatpak implements most of the sandboxing you have on android. It doesn't have feature parity but IMO it doesn't need to. CGroups and systemd-user can prevent apps from running in the background.
I think it might be a good idea to pause updates on our Android devices, as horrible as it is for security just to prevent this from happening. My OEM has a lot of bloat (Facebook and other junk apps you can't uninstall, useless system services, etc) that mostly do nothing except provide some functionality I don't use along with analytics every minute so they are uninstalled.
"Disabling" an app does not do that much, the OS can re enable it with an update or prevent you from disabling it.
I doubt there is true full privacy on a phone anymore with a stock ROM.
Every single reboot on my lower end Motorola phone, they have decided it fit to re-enable com.glance.lockscreenM every single boot and on every single update.
It's horrible. I don't think I can trust them to produce a Graphene phone at all, really, despite all of everyone's assurances.
At least you can disable it; on some phones (especially Chinese phones) you cannot do anything to the system services, they intercept all app requests, essentially what Google did but with their system. The only recommendation I can give you is to look into Hail (device-owner app that can "freeze" apps, a "lower level" form of disabling, see https://f-droid.org/en/packages/com.aistra.hail/) which will mean even if the app gets reinstalled on system update, the device owner app will prevent it from running.
I think GrapheneOS might have issues in the future considering that Android will be getting more and more locked down. People say GrapheneOS is the better OS when it just is hardened Android; it is doomed purely because of the Android base.
Perhaps a Linux based edition of GrapheneOS would do well, even if it will not have a lot of app compatibility. There's only so much patching you have to do to Android before it just becomes more work than good.
just use Shizuku + Canta to remove it
This sucks. I use adb to uninstall all of the system apps like facebook, youtube, web browser, etc. to give myself a minimalist, distraction-free phone that still has niche apps, maps, and communication apps. Might have to look into the expensive light phones as an alternative now if this update hits my phone.
> I use adb to uninstall all of the system apps like facebook
I've only ever used Cyanogen/Lineage or Graphene, so I had no idea this was a thing. I'm not surprised but ... WOOF.
I had the exact same problem because I had a strong addiction to smartphone apps.
I looked into the Light Phone and The Mudita Kompakt, but I ended up buying a refurbished Pixel 8 and putting Graphene OS on it, then I installed only essential apps I need. I keep my old iPhone 12 in a drawer at home and use it for anytime I Need any apps that don't work on a custom ROM, which includes my bank app (plus, imo, it's safer not carry around a phone that has my baking data on it in case it gets lost or stolen).
The light phones are a really cool concept but the Light Phone 3 is quite expensive (more expensive than a new Pixel 10) and the Mudita Kompakt seems to have a huge amount of grievances from users on their forum, so that put me off.
-cough-
pseudo-root via system-user* https://github.com/timschneeb/awesome-shizuku
* https://github.com/legendsayantan/ShizuTools
* https://github.com/RikkaApps/Shizuku/discussions/462
Extremely "Googly" responses there. Not a single mention of the strategy of Google to include, oh, payment, social gaming, ads ... effectively building it into the system and totally disregarding the reasoning that people might want to remove or replace Google Play Services for those reasons. Just act like all that doesn't exist.
Why would you uninstall them over disabling them? They make good point uninstalling is pointless, disabling achieves same purpose and it is safer. You can't use that system space anyway.
if you don't want some system app running just "uninstall" (disable) it with Shizuku + Canta on any non-rooted Android, my current phone is the first one in 15 years with Android which I didn't root since unlocking bootloader on XIaomi is pretty much impossible, but anyway I can achieve pretty much same results with Shizuku and additional apps like Canta, Hail, Shizuwall, etc.
Potential benefits:
as mentioned, Android 17 prohibits uninstalling system apps, but allows disabling disabling apps is usually safer, and they could be re-enabled from Settings in some cases many system apps run in the background after being uninstalled, but it's unknown whether they do when disabled. Neutral:
some apps might get re-enabled unless they're uninstalled (or the opposite). Potential harm:
that would make it more risky for those who prefer to uninstall instead to save storage most of the already listed apps are primarily tested for uninstalling rather than disabling disabling instead, decreases privacy by not hiding apps, keeping the device unique.
Noose keeps tightening, the war on General Purpose Computing, the war against users owning devices intensifies. How utterly fallen.
We'll see what happens with the proposed ADB changes. Lots of no one asking for this, lots of people describing how badly their phone use will be greviously impacted, and seemingly very little discussion/engagement/justification. Maybe they'll fire the bullet anyways. https://issuetracker.google.com/issues/526109803
I said the same thing about waiting for 24hrs before being able to use adb to install apps. About 24hrs being not a big blocker and that it was good for security. It's all about boiling the frog slowly, 24hrs is the start and then they'll add more restrictions once users accept that. Ultimately goog would like to have the system as much locked down as apple or even more.
>I said the same thing about waiting for 24hrs before being able to use adb to install apps.
I thought it was 24 hours OR use adb?
You will own nothing and you'll be happy.
Maybe they're right, albeit for all the wrong reasons.
Perhaps the problem is our desire to have everything, no matter what the compromises are. Perhaps the problem is our inability to say, I'm going to go with product X even though it lacks Y because we actually own X. There is virtually no incentive for competition to pop up in such an environment since established companies have a lead of years, decades if you consider the size of the established companies, so consumers will follow their lead.
I don't mean to suggest that buying alternatives is a solution to the problem as a whole, but doing so may allow enough niche products to survive to give those of us who are interested in alternatives and alternative to choose from.
You, too, will love Big Brother
Ok this is not as bad as I feared, disable still works and that uninstalls any updates that app has gotten.
It was always a bit surprising you could uninstall an app in a "read only" partition
HN users are so hilariously out of touch with the Android world they are downvoting your completely correct observation.
I'd probably get more useful information reading Hindi Telegram groups without translating anything