• dastanktal@lemmy.ml
    link
    fedilink
    English
    arrow-up
    1
    ·
    4 days ago

    Great question. It’s not actually because graphene is all that demanding on the phone hardware. It’s because they have specific security requirements that demand certain class of hardware to be installed that’s not found in every phone. That’s why they require Pixel phones because they come with this required software. They stopped being able to do this with the Pixel 10 because Google stopped releasing The Pixel build with the Android open source code.

    • solrize@lemmy.ml
      link
      fedilink
      English
      arrow-up
      2
      ·
      3 days ago

      Is there an obstacle to adapting Graphene to run on phones people actually have? Those users might lose some special security features but the idea is purely degoogling rather than special enhanced security. Phones are inherently insecure anyway.

      • dastanktal@lemmy.ml
        link
        fedilink
        English
        arrow-up
        1
        ·
        3 days ago

        Yes, if you ask the graphene developers. They are known to be rather persnickety about their security features. They are highly critical of devices and security, and if it doesn’t meet their standards, they’re not going to do it. And most phones don’t meet their standards, which is why they don’t make graphene OS for anybody else. If you want an OS that’s going to run on everybody’s phone, you’re going to be looking at, like, lineage OS or one of the Linux distributions But unfortunately, there’s just not a lot of money and momentum behind these projects. There’s people that want them, but nobody really has the capital to really fund and push them and give them a lot of momentum.

        • solrize@lemmy.ml
          link
          fedilink
          English
          arrow-up
          1
          ·
          3 days ago

          . If you want an OS that’s going to run on everybody’s phone, you’re going to be looking at, like, lineage OS or one of the Linux distributions But unfortunately, there’s just not a lot of money and momentum behind these projects. There’s people that want them, but nobody really has the capital to really fund and push them and give them a lot of momentum.

          Well Graphene isn’t that well funded either. If Moto is willing to build the fancy hardware for a Graphene phone, maybe they could be willing to install Lineage on a basic phone without special hardware.

          • dastanktal@lemmy.ml
            link
            fedilink
            English
            arrow-up
            1
            ·
            2 days ago

            Fair, but they’re the only OS project that’s working with a hardware distributor right now.

            And the security on the graphene phones is genuinely top-notch. So these are the ones I’m most hopeful for.

            As far as lineage goes, there’s lots of phones that already works on. You do have to go through some steps to make it work on a lot of phones. But you know, it should work on most phones.

            • solrize@lemmy.ml
              link
              fedilink
              English
              arrow-up
              1
              ·
              2 days ago

              It’s not just extra steps, it’s significant effort to find a phone that it works on that’s not too obsolete and not too expensive.

              What is the top notch Graphene security about that’s absent from Lineage? A phone inherently reports your location to Big Brother every few seconds, plus the hardware is literally a microphone connected to the internet. No OS can fix that.

              • dastanktal@lemmy.ml
                link
                fedilink
                English
                arrow-up
                1
                ·
                1 day ago

                No, it’s really not. Just go buy any of the old Pixel phones and they all work with lineage. I mean, it’s not that big of a deal. You’re making it sound like it’s a huge effort to find a new phone, and you just have to accept the fact that you’re going to have a couple of generations older to run these type of OSes.

                A phone will only call out to Big Brother if it has the code to do so. It needs the code. If the phone is flashed a certain way, it won’t call out to Big Brother.

                It’s not exactly a fun experience, but I wouldn’t call it a massive problem either. More of a small headache.

                As far as Graphene goes, it goes down to literal hardware chips in your phone that drive security that are only found in certain devices, typically enterprise-style devices. It’s like a TPM chip in your computer.

                As far as security goes, there’s no competition. Graphene OS is the best, and that includes current modern OSes. Governments really fucking hate this OS and have been targeting people that have it on their phones Because there’s absolutely no backdoors and there’s no way to get the data off the phone, unlike a Google or an Apple device.

                • solrize@lemmy.ml
                  link
                  fedilink
                  English
                  arrow-up
                  1
                  ·
                  edit-2
                  1 day ago

                  But I like my Moto G which has an SD slot, 3.5mm audio jack, more battery life, stylus, and easier to replace battery than a Pixel. So I’d rather not downgrade my phone just to run Graphene. Why would I want a TPM chip anyway? Those are mainly intended to enforce DRM. I can believe no backdoors in the OS, but no vulnerabilities in the hardware? That’s a stretch, think of the Intel management platform and everything else (https://tpm.fail/). If the hardware was really that secure, the govt would block its manufacture. There would also be no market in HSMs. I can believe in TPM slowing attackers down but that’s about it.

                  Anyway I distrust my phone enough to not have anything super sensitive on it. I don’t think a TPM chip would change that. So I’m still skeptical.

                  Do Graphene users really bother to enter a 128 bit decryption key to unlock their phone? How do they do it? I’ve thought of a few ways but am unfamiliar with anyone using them.

                  • dastanktal@lemmy.ml
                    link
                    fedilink
                    English
                    arrow-up
                    1
                    ·
                    1 day ago

                    You know that Moto G is like a first-class supported phone on lineage, right? It seems like every one of their newest models is on lineage.

                    I’m not sure where you got the idea that a TPM chip is used for DRM, because that is not their function. It’s a hardware encryption chip used to generate Cryptographically secure keys.

                    DRM Enforcement works with or without these hardware chips being installed on your phone.

                    You want something like the TPM chip because it makes your phone very difficult to break into when you do things like encrypt the entire drive. HSMs Are far more effective at securing your phone than the standard baseline security that you get from a CPU. This isn’t an opinion. This is a well-researched fact.

                    You also are, I think, maybe conflating technological vulnerabilities? Also, you said phones call back to Big Brother intentionally. What you’re talking about are vulnerabilities that can be exploited that are not intentional features of the chip. Intel is kind of famous for their insecurity. There was a big fucking vulnerability their CPUs had due to a hardware bug like a decade ago that AMD managed to get by because they don’t use the same architecture. Now I do get what you’re coming at that these vulnerabilities probably exist on every model of phone, but it’s best to go for a phone os that’s actively trying to close all of these vulnerabilities rather than one that says they “exist on all phones, I don’t care”.

                    I disagree with your assessment that the government wouldn’t shoot themselves in the foot by giving people a technology that would allow them to hide shit from the government. They have, and they do constantly. I mean, the US is kind of famous for having more firearms per capita than people. Also somebody has clearly never heard of the legend of TrueCrypt. There’s a reason the original developers ended up fucking off somewhere to obscurity, and the project is now VeraCrypt.

                    Also, the government does want corporations to be able to protect their private information from foreign entities. That seems like it would be prudent for the US to be able to do. You know what I mean? They don’t want China all up in their business. In fact, it’s a big concern from the business perspective. So having something like a TPM chip on every laptop to encrypt all of your data is a good thing. And typically, that’s what the US wants. They just want a software backdoor To get at the data they want. They also have so much monitoring that it’s almost a moot point.

                    As far as graphene users go, it’s secure enough that Various governments consider graphene phones a dead end when they collect them And I’m pretty sure the US has never been able to crack one As far as we are aware and we would definitely be aware because they would be stupid enough to sing it from the fucking mountaintops with this administration.

                    I understand you’re skeptical, but there is a reason that Graphene is preferred by the security community. There is no competition for security. They are the best hands down. When you have various Western governments admitting that they can’t get into these phones, that’s as Good as a recommendation you can get. Notice how they aren’t bothered about Apple phones and Google phones. The governments hate graphene phones and are making it harder to get a hold of them.