AOSP eng here;<p>I don't interact with Graphene or any of their folks at all; I'm just a distant observer like most folks here.<p>Still, I can't help but think that Graphene seems to want to complain about everything and anything that doesn't fit their niche use case. (As much as it seems beloved here, people that flash custom Android OSs are the very definition of niche users.)<p>My personal attitude to Graphene seems to get a bit more negative with each one of these "rants" and I doubt I'd go far out of my way to help them, even if I had exposure to them.
> that Graphene seems to want to complain about everything and anything that doesn't fit their niche use case<p>What would you want them to complain about instead? Of course they'll complain about that, just like Googlers will complain about things affecting their stock price, no one is surprised that people care about stuff they're personally involved in, it makes a lot of sense.<p>Now if these complaints weren't accurate, then I'd walk with you and feel a bit more negative with each piece. But the ones I've looked into, have been spot on, so who cares if it's for their specific niche? I expect them to care about their niche, that's why those people all work together in that organization in the first place.
> As much as it seems beloved here, people that flash custom Android OSs are the very definition of niche users.<p>Hmm... Let's try reframing this: "as much as it seems beloved here, people that install their own operating systems on PCs are the very definition of niche users"<p>I'm absolutely certain that's how IBM felt before the clones. But the ability to install what they wanted on a defacto standard platform is what launched the computing revolution. I think we'd still be living in a sterile monopolistic environment with $10k compilers otherwise.<p>Folks installing their own ROMs on phones are only niche because they've been pushed out at every opportunity using locked bootloaders, embedded security processors, factory installed secret keys, etc.<p>Despite all that, there's still thriving communities developing and using custom ROMs on their phones. That demonstrates more than niche demand.
Perhaps they complain because that's literally the only way to get Google to take notice?<p>Let's be real, AOSP doesn't exist any more. Google have closed down nearly everything. All the development happens in private, you've stopped addressing bugs raised by the public, the source of patches are only infrequently released, device trees are gone.<p>Wouldn't you complain?
<i>All the development happens in private, you've stopped addressing bugs raised by the public, the source of patches are only infrequently released, device trees are gone.</i><p>To emphasize this point a bit more: only "QPR0" (major release) and QPR3 are released as part of AOSP. QPR1 and QPR3 are not released at all anymore, but contain fixes for vulnerabilities that are not marked high/critical (so don't end up in ASB). It is not clear to me whether OEMs get access to QPR1 and QPR3, but Google are not only witholding features, but also a set of security fixes.<p>Besides that, they are torpedoing other systems through Play Integrity.<p>IMO it would be best if AOSP was spun off from Google into its own org that actually cares about developing an open source system for others (both open source systems like GrapheneOS/Lineage and commercial vendors like Samsung) and that would have an attestation system that is open to vendors that have good device security.
If they're just some "niche use case" then why would Motorola partner with them? The way they see it,<p>> By combining GrapheneOS’s pioneering engineering with Motorola’s decades of security expertise, real‑world user insights, and Lenovo’s ThinkShield solutions, the collaboration will advance a new generation of privacy and security technologies. In the coming months, Motorola and the GrapheneOS Foundation will continue to collaborate on joint research, software enhancements, and new security capabilities, with more details and solutions to roll out as the partnership evolves.<p><a href="https://motorolanews.com/motorola-three-new-b2b-solutions-at-mwc-2026/" rel="nofollow">https://motorolanews.com/motorola-three-new-b2b-solutions-at...</a>
Even in the EU spyware use is prevalent (and i 'd guess everywhere else in the world). There have been many scandals of government authorized commercial spyware been deployed against journalists. Is it really that niche a mobile OS that tries to not be exploitable by them?
Graphene doesn't position itself against spyware.<p>For example, a user being able to inspect and edit the files written by an app, no matter where or how those files were written, would be an anti-spyware feature: you could better observe the behavior of a closed-source application.<p>Grapene opposes this feature because the app security model protects the app AGAINST the device user editing or reading protected files.<p>Graphene's philosophy is enforcing the Android security model. The Android security model gives guarantees to the app developer about how their app can behave, even where the device's owner wishes otherwise. See: Play Integrity.
GrapheneOS have mentioned wanting to expand the logging/intrusion detection capabilities of their Auditor app but contend with the need to include it as a system app which is against their philosophy (PoLP). It is not accurate to say they don't want to do anything about spyware.<p>They are also completely against Play Integrity as implemented on principle.
Graphene puts a HEAVY emphasis on security.<p>Also your argument about a user inspecting and editing application files feels like a strawman argument. For example many spyware use malicious links to infect the devices, not malicious apps.
So other projects are not supposed to critize Google? Graphene's focus is on security and they complain about lack of security in your products. Seems valid to me.<p>Also security and using non-Google OS are not niche usecases. I'm not sure how you are working on Android, the most popular OS while claiming security is a niche usecase. In fact, I have less confidence in security of your work.
The way I read the comment (admittedly putting words in their mouth), is that there are different ways of "complaining". I am someone who is actually quite sympathetic to Graphene's project and have considered getting one of their Motorola supported phones when they come out. But every time I encounter their writing, they come off as unnecessarily abrasive. They could be making the same points with a lot less potential bridge burning.<p>They are not neutrally pointing out places where their preferred priorities aren't being met (which would be reasonable), but they are speaking (forgive me the hyperbole) like religious zealots. I don't blame someone who doesn't share their particular viewpoint with being hesitant to work with someone like that.<p>As a consumer, I don't particularly care. I'm not going to make my decision based on their comms style. But a developer who actually has to work with them? Yeah I could imagine it mattering.
Agreed. They clearly know their shit and they are stunningly great engineers, but Graphene OS would be much more loved and respected if they had a PR person to take care of online communications.
The "religious zealots" have their own motherfucking Cellebrite column. That means they are <i>right</i>.<p>They can be abrasive all they want. People who are wrong still need to sit down and listen instead of spitefully "burning bridges".<p>And that's assuming they're actually guilty of this "abrasiveness" that people accuse them of. I don't actually think that's true. I think their comments are extremely informative and filled to the brim with valuable technical information. I've spent quite some time reading strcat's comments here and it's actually changed my viewpoints on some security matters. For example, I'm no longer as obsessed with knowing what's inside firmware as I used to be, it's better to minimize and isolate such black boxes so they can do no harm. I started valuing IOMMU support and grouping in PC motherboards.<p>If there's any "abrasiveness" in their posts, it's probably just an undercurrent of frustration with a world that simply refuses to understand or cooperate. A feeling I can't help but have enormous sympathy for.
> <i>They can be abrasive all they want. People who are wrong still need to sit down and listen instead of spitefully "burning bridges".</i><p>While I wish that were how humans work, it definitely is not. You can make the strongest argument ever and still lose if you deliver it in a way that the listener can't process it because you're triggering emotions. The best arguments IME are factual and respectful.
The best thing about being right is it doesn't matter if the listeners can process it, you're still right.<p>There are consequences to ignoring GrapheneOS developers. Insecure phones can get people <i>killed</i>.<p>The best arguments are respectful and measured, but few things in this world are ideal. It's in your best interests to tolerate any perceived "abrasiveness". Ignore the the guys who make Cellebrite sweat at your own peril.
The argument about the seriousness of the topic seems to be to be arguing <i>for</i> taking into account human psychology and toning down rhetoric (note: <i>not</i> failing to make the claims, or dropping points, just changing tone) in order to make it more likely that you get listened to. To the earlier commenters point: it would be great if nothing other than correctness + importance determined likelihood of being listened to. But that's not the way the world works.
You might not like their style of speech, at least they care about their users. Maybe Google uses nice flowery language that makes the reader feel nice—IDC—actions speak louder than words.<p>Stock Pixel is an awful experience. So many useless notifications, popups, ads, privacy not by default.<p>Company: "We care about your privacy" meanwhile 1400 corporations they share data with<p>GrapheneOS: "There's zero telemetry in GrapheneOS"<p>The more you read the more you realize they are nearly always correct.
> at least they care about their users<p>No, users are secondary to the mission. If they happen to overlap, that's a happy coincidence. And caring for a user stops if Daniel has the slightest interpretation of their comments being an attack (i.e. any mild criticism or disagreement about direction)<p>They care about their mission and Daniel's stance first and foremost<p>I wouldn't be surprised if this comment is branded an attack
> If they happen to overlap, that's a happy coincidence.<p>I can't know what the developers of any OS are actually thinking, but based their actions, GrapheneOS does more for their users than any other OS.<p>Therefore I assume that doing good things for users equals care for users. It's probably stupid to try to guess about care.
When you are a minority you have to be incredibly loud for any chance to sway things your way.<p>Not saying whether it's a good thing or a bad thing, but just the nature of reality.
Could you please explain why supporting MTE/potentially EMTE in production as a goal represents a niche use case? Isn't mitigating memory corruption issues a mainstream ideal? How else would you propose to do it?
> people that flash custom Android OSs are the very definition of niche users.<p>This is a mischaracterization. The niche isn't Android hobbyists, it's people with what should be a basic expectation for privacy. I wouldn't flash GOS or any other OS if I could safely avoid it.
Maybe if Google did not shove their spyware down people's throats and actually allowed users control of their phones, there wouldn't be a need for projects like Graphene and Lineage. Until then, complaints are more than justified.
This doesn't read as a rant to me, but as calm and factual, regarding a genuine security regression that merits public attention. What is your interest in mischaracterizing it?
Thankfully the project doesn't care about your personal attitude. That "niche use case" literally saves lives in countries where saying the wrong thing can put you to death. Since when is calling something out a rant?
Graphene relies on donations, and will be dependent on more than just the users where their lives are at risk.<p>If everyone in North America and Europe stopped using Graphene, I doubt they would last very long.<p>High standards are great, but they have to interact with the community and the sanctimony doesn't help.
In a world where economics makes security hardly a secondary concern, a situation exploited by both the intelligence and surveillance broker sectors, dogmatic sanctimony for high security is a feature and not a bug.
They are good enough to have their own Cellebrite column. If they complain about something, you should probably listen.
> My personal attitude to Graphene seems to get a bit more negative with each one of these "rants" and I doubt I'd go far out of my way to help them, even if I had exposure to them.<p>My thoughts entirely, I prefer to use CalyxOS, which for some reason in the eyes of GrapheneOS is pure evil.
I've never seen them call it "evil". I've seen them debunk CalyxOS security claims as well as criticism of GrapheneOS, and they usually provide some serious reasoning and technical information when they do it. They know what they're talking about.<p>Don't take it personally. I'm a huge fan of Linux, and GrapheneOS routinely comes here and calls it a huge security liability. And they are <i>right</i>.
... and my opinion becomes more positive with each rant. We'll have to agree to disagree. The only reason I buy Pixels for myself and my family members is because of GrapheneOS, otherwise it would be used out of date hardware for LineageOS or some kind of Linux phone. I am thankful that they are attempting to diversify with Motorola, being entirely Pixel dependent has been a project vulnerability; anytime Google decided to lock down the boot loader, it would have been curtains for the project.
Security shouldn’t be a niche use case. There’s a constant trickle of CVEs, and spyware vendors are known to abuse these exploits in their software. All this on devices that are reachable in the US through a text or MMS, sent to an easily located 10 digit number that isn’t easily changed. These are devices that people now use for all kinds of sensitive tasks!<p>Security should be the number one priority, frankly. Graphene has shown that this is possible, and they have tried multiple times to get Google to integrate their work.
"I don't know anything but I don't like Graphene"<p>Well we know Google isn't enabling MTE, while LLM-enabled exploits are multiplying rapidly. Maybe you need to get back to work?
I'm not an AOSP engineer, but that was my thought reading GOS's comments: Why be negative toward the people who you want help from? They don't need more stress in their day and wouldn't want to engage, with the promise of enjoying more of the same treatment. If it's consolation, much of their communication seems the same - it has nothing to do with AOSP or Google. :)<p>Communication is a challenging skill and not all good engineers are good at it. It's stressful to be in a role that demands lots communication if you feel you aren't good at it (I'm not speaking for GOS leaders - I don't know what they think).<p>Going out on a limb, hoping it helps - the most powerful single solution IME is <i>compassion</i>: Compassion toward yourself and toward others. They are engineers like you, trying to get through a stressful day like you, and they could use some pleasant interaction from someone who understands what it's like. You could use some of that too. Running GOS isn't easy, I'm sure.
<i>I'm not an AOSP engineer, but that was my thought reading GOS's comments: Why be negative toward the people who you want help from?</i><p>What help though? Google has closed off AOSP and only does source code drops twice a year. Google has embargoed security patches for three months and only provides them to OEMs of Google-certified Android phones, not other AOSP-based projects. Google stopped providing git trees of kernel sources and instead requires projects to submit a request for a Google drive link <i>for each kernel version</i> that takes up to weeks to process. Google is shutting out open Android systems through Play Integrity.<p>Google is not helping anymore, over the last 1-2 years they have tried everything to sabotage AOSP-based projects. The only reason that they are not fully closing AOSP is probably because 1.) they would get in hot water with regulators; and 2.) AOSP will probably get forked.