Pixel 11 doesn't yet meet the GrapheneOS security standards and may be skipped
discuss.grapheneos.org382 points by finnlab 9 hours ago
382 points by finnlab 9 hours ago
As others have said, this is not the most recent status update (it depends on future Google changes in QPR1 or QPR2).
The much more interesting recent news IMO is that Google is not allowing (non-Samsung) OEMs to sell devices with GrapheneOS:
https://news.ycombinator.com/item?id=49946698
See the last paragraph.
For example, non-Samsung Android OEMs aren't allowed to directly sell devices with GrapheneOS and Google will only permit it within a quota. It can and is being worked around and there will be devices sold with GrapheneOS as the stock OS without Google restricting how many can be sold.
My guess is that the workaround is that Motorola sells them with Google-certified Android. A third-party (non-OEM) buys them in bulk and preinstalls GrapheneOS.
But this is really end-90s/begin-00s Microsoft levels of anti-competitiveness. I'm surprised that (particularly non-US) regulators are not investigating them yet.
> But this is really end-90s/begin-00s Microsoft levels of anti-competitiveness. I'm surprised that (particularly non-US) regulators are not investigating them yet.
Every company is nice until the monies they earn is not guaranteed anymore. They were closing the doors they have intentionally left open in the name of security for a couple of generations.
Now they're being more open about why they are limiting user choice. Because like Chrom(e/ium), Android is designed to be a large data sink for Google to feed The Machine.
"Because like Chrom(e/ium), Android is designed to be a large data sink for Google to feed The Machine."
Also maintaining the monopoly over the app market and getting a good cut out of every transaction within. A non google controlled device in the mass market can introduce new markets independent of google (and not paying them).
They would not like that.
Apple did the same thing. In the early days of OSX much of Darwin was open-sourced. Now, not so much.
It's all about that sweet backdoor. With Google and Samsung the NSA can just waltz in and out of your phone no matter which OS is running. But if some Chinese OEM decides that Unisoc chip & baseband would be the best choice for your GrapheneOS device the NSA will be quite unhappy.
I'm honestly a little surprised we haven't seen a Chinese OEM use grapheneOS or their own fork of it.
Graphene is a privacy focussed rom. In China there is not such a concept as privacy. In fact, it might be illegal to be distributing this, even for export.
Clothes, handbags, etc. brands regularly complain that Chinese factories sell apparent clones at lower prices.
Can design forgeries be prevented by selecting as designs phrases and fragments of text that are politically provocative in China? To the extent that they continue to make faithful copies to sell in the West, they are exposing labor force to provocative say anti-party content. Or they forego the imitation business?
> The much more interesting recent news IMO is that Google is not allowing (non-Samsung) OEMs to sell devices with GrapheneOS:
how is that legal??
that sounds like a very clean cut case of thinks companies aren't allowed to do under fair market lawes
It's only illegal if the law is enforced and the US federal government gave up on anti-trust enforcement a long time ago and any attempts to re-awaken it get nerfed quick.
Yeah, I don't understand this, graphene is FOSS and unaffiliated with google so if you as an oem install grapheneos on hardware you manufactured how does Google have any say at all?
Because Google will cut you off from access to the privileged Android access to Play Store, Services and everything else. So it’s basically all or nothing.
Which, again, appears at a glance to be clearly illegal. For reference see what happened to Microsoft in both the US and Europe.
Same as RedHat saying you can't redistribute the source code that they are obligated to give every customer.
The GPL clearly grants every recipient the same full rights as whoever they received something from, so copyright law itself says that you can take that source and redistribute it.
But starting a year or so ago RedHat says you may not redistribute, which they can't actually say, so you still can, but if you do you will be fired as a customer and lose all future access, so you only get to do it once.
Given the clear wording that makes the intent of the GPL unambiguous, that every end user is fully empowered and you may not do anything to curtail that, I don't see how they get away with it except the simple fact that no one has been willing to take on the legal fight.
If you're a pre-"stream" Centos user, you don't have the money for that. If you're a paying RHEL user, you don't want to be on bad terms with RedHat or maybe IBM either, and neither the licence costs nor the rules bothers you at all anyway.
So it's plainly illegal in my opinion, but will stand, illegal and yet in effect and unchallenged probably indefinitely.
I guess GPL needs a line that says you aren't allowed to discriminate against customers that exercise the rights given to them by the license.
> I'm surprised that (particularly non-US) regulators are not investigating them yet.
This is basically the reason Google lost their Play Store anti-trust lawsuit when Apple won theirs. Google did all these incriminating, behind closed doors deals to lock out competition from their “open ecosystem”, where Apple never pretended to be open to behind with.
This is just the Breaking Bad "He can't keep getting away with it" meme, for tech giants. Google has been ruling Android with an iron fist for over a decade, and they continue to do so. This came up in a different comment chain of mine [0] recently as well, and is probably more worth reading than a lot of the other comments here that are just now realizing how restrictive Google is with Android
[0] https://tildes.net/~tech/1wam/blocking_of_unverified_apps_on...
> Apple never pretended to be open
Except when Steve Jobs lied saying FaceTime would be an open standard.
"FaceTime is based on a lot of open standards: H.264 video, AAC audio, and a bunch of alphabet-soup acronyms. And we’re going to take it all away. We’re going to the standards bodies, starting tomorrow, and we’re going to make FaceTime an open industry standard." - Steve Jobs at Apple’s WWDC 2010 keynote (emphasis mine)
That was their intention but that changed after they lost a patent troll lawsuit.
Corporations learned they have to get in bed with regulators first, and how to do it.
I saw an interview with Bill Gates once where he said that one thing he would've done differently is more quickly come around to the idea of sending people to Washington. Apparently he didn't like the idea of lobbying and that cost them when the regulators started coming for them
Wow, then there we go: don't hate the player, hate the game. You're telling me even Bill Gates wasn't evil until the system forced him to either become evil or get shut down.
No, he just say he's inexperienced.
Bill Gates published that infamous open letter about copying software, and both Bill Gates and Brad Smith said that Microsoft's core pillar is IP: "Microsoft is built upon the idea of having IP and protecting and using it" (paraphrased by me).
The quotes I can find by digging the net:
> Microsoft was founded on the premise that software is valuable intellectual property that people should pay for. --Bill Gates
> Microsoft was founded on intellectual property. Intellectual property is the foundation of our business. --Brad Smith (This is the quote I remember in the first place)
So, Microsoft never wanted to be an open company. They were the epitome of the closed source, behemoth software company, where you get the goods, get to use it, and pay them for the privilege.
Closed source software is a reality, not an explicit evil. It is the same reason I don't have schematics for my bedframe. I've worked at software companies - have you? - it takes extra effort to release source code, causes a lot of risk, and provides absolutely no benefit whatsoever so it is simply irrational to do it.
Reality vs explicit evil is a false dichotomy.
Microsoft doesn't just choose not to release source code; they send takedown notices to projects that redistribute Microsoft's proprietary software (e.g. Ninjutsu OS). They also put clauses in the EULA for Windows to disallow reverse engineering and certain kinds of remote access (something related to if you change who has access too frequently).
Microsoft takes extra effort to prevent people from sharing or modifying Microsoft software, in order to make more money.
Yes, some of those parts are evil. The mere lack of releasing source code, or being frustrated people are using your product without paying, itself isn't.
I think that mischaracterizing a business model as evil is an overloaded practice.
Is it evil to introduce terms and conditions that restrict how you expect your users to use your product? No, it's probably more hypocritical than evil; I don't think my parents telling me not to smoke while they struggled with addiction was evil, but it sure didn't model the best behaviour.
Is it evil to lobby government to curtail the freedoms of individuals to protect your business model? Yeah, probably; in most cases I believe that reducing consenting adults freedoms is usually a pretty evil act.
Microsoft is guilty of both, but I prefer to save Evil to describe actions that actively cause harm, either physically, mentally, emotionally, or in terms of harming the freedoms that people enjoy, especially if that choice to cause harm is economically motivated.
I'm not advocating on behalf of Bill Gates or Microsoft, just on clear terminology so that we can focus on actual evil behaviour versus consenting adults entering into a valid contract for mutual benefit.
I agree, I think.
I may have been too focused on the "false dichotomy" part and forgotten that you were talking about old Microsoft and not current Microsoft. I don't know enough about old Microsoft to say whether they were "evil" all along, so I won't comment on that part. I do agree with "don't hate the player, hate the game" in general though.
Closed source was perfectly acceptable when planned obsolescence and government mandated kill switches/backdoors weren't a thing.
I'm not an opponent/critic of closed source software or enemy of it. I pay for quite a few high quality closed source software packages, and I like them as much as the Free Software counterparts which I use every day.
I also understand that we need to eat and have bills to pay, and there are many ways to achieve that, incl. Free or Closed Source software.
What I'm against is weaponization of closed source software beyond reasonable point. To EEE, to deprecate otherwise capable and functional hardware in the market, to limit user freedom or to extort money.
I hope I made my point clear.
Furthermore:
> I've worked at software companies - have you?
I didn't work at a software company per se, yet I develop open source software for the projects we work on, and I know what preparing a codebase for publishing entails. I also worked as a tech-lead of a Linux distribution, and a nation-wide one at that. I know what it entails, trust me.
If we're talking about experience in terms of years, I'm doing this for ~20 years, using Linux for ~25 years, and using computers in a level I understand what programming them entails for ~30 years.
So yeah, I'm not that newbie who have seen some Python and tied themselves to a knot of awe.
> causes a lot of risk,
Don't let's get into FUD territory of "Free Software is insecure", shall we? We see how Windows has been breached yesterday and today, and will see it more for years to come, as with other software.
> and provides absolutely no benefit whatsoever so it is simply irrational to do it.
Hmm, I'll agree to disagree here because 90% of the thing your digital stack is living on is Open Source and Free Software.
I don't have time to flesh out the benefit and irrationality aspect of it, because I mean, it's plainly wrong when it's put that squarely. We can find some nuances maybe, but it's limited to certain scenarios.
by weaponization you mean Win 11 requiring specific hardware etc?
your comment honestly just sounds like you dislike closed-source software.
for most commercial software projects, releasing the source provides no tangible benefit, aside from people like HNers being happy
but if Microsoft would've open sourced their OS, they would've been vulnerable to their OS being diluted into free versions or maybe even OEM-maintained versions
from a business sense, it makes no sense.
and as for security, closed source software is harder to attack (and was a lot harder to attack before LLMs). like, there's still much that we don't know about Windows internals exactly, and even those who do are a very small group of people.
it'd be a lot easier to find vulnerabilities if the source was open.
yes, it doesn't mean it's automatically more secure, in fact it can be less so if people don't have eyes on it, but I'd say the amount of attacks is less and usually done by more sophisticated attackers
Weaponization of closed source software could take many forms and is just part of the general weaponization of market mechanisms that businesses do.
Right now it doesn't really affect me that Ableton Live is closed-source. But it would affect me if the main method of sharing music on the internet was Ableton Live project files. And if Ableton had cultivated that situation on purpose they would be weaponizing the closedness of their software.