GrapheneOS in 2027 available on high-end Motorola phones

(grapheneos.social)

344 points | by exceptione 3 hours ago

19 comments

  • felooboolooomba 2 hours ago
    > .. obtaining source code via Google Drive ...

    Let this sink in. Google, this small tech company (correct me if I'm wrong), is peddling source code via tarballs on google drive.

    Something the head of the Android ecosystem, Sameer Samat could be proud of on his CV: https://www.linkedin.com/in/sameersamat

    • exceptione 1 hour ago
      There is a little bit of clumsiness in the way Google communicates with the public. What they really mean to say is: we need to be broken up.
      • smallmancontrov 23 minutes ago
        I am in awe at the amount of capital Google's market dominance affords them and the consistency with which they squander that capital.

        https://killedbygoogle.com/

        This is not the way.

    • J-Kuhn 1 hour ago
      Yeah, its the "well, legally, we have to provide the source code, but we make it as painful and slow for you as we can without it becoming a blatant violation of the GPL."
      • RobotToaster 1 hour ago
        Not quite, they could make you request it by post and send it on a stack of floppies.
        • steve_taylor 1 hour ago
          Sounds like a cheap way to get my hands on some floppies.
          • afiori 1 hour ago
            you are right a stack of printed qr codes is better
            • sunaookami 1 hour ago
              Reminds me of Lavabit where the US wanted the encryption keys and they printed them out in a 4 point font :D

              https://en.wikipedia.org/wiki/Lavabit#Legacy

            • heftig 1 hour ago
              No, that's too easily machine-read. Print it in a fancy calligraphy font or one with ambiguous characters.
            • newswasboring 1 hour ago
              That's too convenient, cameras can read many qr codes at a time. Encode the binary on some punch cards.
              • eptcyka 1 hour ago
                Pretty sure cameras can be used to read punchcards too.
    • teekert 51 minutes ago
      At this point, without Git commit history (assuming it is a bare code dump), is it still even possible to guarantee it is what Google says it is?
      • gruez 1 minute ago
        You can compare against old dumps.
    • FartyMcFarter 17 minutes ago
      > Google, this small tech company (correct me if I'm wrong), is peddling source code via tarballs on google drive.

      What is the context for this? It's not clear to me from the linked social media post.

      The Android kernel source code is in git: https://android.googlesource.com/kernel/common/

      Plus there's a lot of other Android source hosted on Google's git servers: https://android.googlesource.com/

    • mngnt 1 hour ago
      > ...after making a request through Google Forms This is even more ridiculous to me.
    • rjzzleep 16 minutes ago
      3 years, checks out. Probably buddy buddy with someone. Reminds me of that 3rd Google Pay they made that they had to sack because it was so dumb.
    • StrLght 1 hour ago
      [flagged]
      • felooboolooomba 1 hour ago
        This is absolutely not a witch-hunt. People in that position wield enormous power and take their paycheck and responsibility that comes with it. Linking to his professional linked in relation to his responsibility is nothing but professional.
      • blablablerg 1 hour ago
        Why not, his linkedin profile is public and easily findable. This is not doxxing.
      • phatfish 1 hour ago
        If you are worried about internet witch-hunts I'd stay away from the "creators" and content that Google platforms and makes money from on Youtube.
      • VulgarExigency 1 hour ago
        anything but holding people accountable for their anti-consumer actions
        • bflesch 1 hour ago
          It's quite painful to resolve cognitive dissonance, so I understand the downvotes for your comment.

          People are clever enough to reach high level corporate roles, but at the same time they're are too weak to emotionally process the consequences of their "work" on their human cash cows of below-average intelligence.

          However with these kind of moral/ethical questions, it's really hard to draw the line.

          Is working at Google and thereby facilitating the scamming of my grandmother worse than being an ordinary pickpocket or an lobbyist for big oil?

        • StrLght 1 hour ago
          Well, sounds like you have a rather weird definition of accountability. You do you.
          • brendoelfrendo 1 hour ago
            He's the head of Android ecosystem; who else is accountable?
      • bflesch 1 hour ago
        I think it's a stretch to call OP doing a "witch-hunt" here. That Android guy is a mini LinkedIn celebrity with 100k followers.
        • StrLght 1 hour ago
          This doesn't excuse a message that literally reads like call to action.
          • bflesch 1 hour ago
            I'm just thinking that someone who has 100k LinkedIn followers might be happy about any type of engagement, including nerdy rage bait.
          • owebmaster 1 hour ago
            Public companies and their executives deserve the same treatment as the government and the politicians. It is completely fine to let them know that the people are upset with their decisions.
          • crest 1 hour ago
            What would be wrong with a call to action addressed at someone likely in a position to stop this bullshit if he cared enough?
      • Hizonner 1 hour ago
        You know what? Fuck that guy. And it's a public profile. LinkedIn is basically an advertising platform. If you are on it, you are putting yourself out there to the whole world, on purpose.
  • Cider9986 2 hours ago
    Specific devices:

    >At the time of writing, within ~12 months, in 2027, the 2027 Signature, Razr fold, and Razr flip will meet the hardware security requirements and should have official GrapheneOS support. Motorola is currently porting GrapheneOS to their devices.

    https://news.ycombinator.com/item?id=49038982

    • LarryDarrell 52 minutes ago
      I knew it would be their higher end devices but I really wish they would have put it on their lower end as well.

      I have a Moto G running LineageOS and it's my favorite phone ever. The ability to have my 800GB of music synced to a sdcard is something I'm loath to give up.

      • BoldColdHold 31 minutes ago
        Lower end devices simply don't have the hardware required.
        • cosmic_cheese 25 minutes ago
          I would bet that what Motorola can change without trouble on the lower end is more restricted, too. Generally low end models use more parts that are old, off the shelf, and/or shared with several other models to keep costs low, and so major changes can quickly balloon costs.
    • maelito 24 minutes ago
      What I hope is that a compact and high-end device will have Graphene support.
    • Arrowmaster 59 minutes ago
      The 2026 Signature doesn't appear to be for sale in the US. Does this mean we have to wait for the lower end devices if we don't want a fold/flip?
      • Noaidi 17 minutes ago
        Wow, I do not think any of these phones are available in the U.S.
  • tfrancisl 2 hours ago
    I've never really understood why we chase Android-alikes on mobile platforms instead of trying to build on mainstream Linux. I know some folks in the nix community (nix-on-droid and other projects) have tried to bring us closer to this, but projects like Graphene seem to have a lot of traction.
    • inigyou 2 hours ago
      All the existing apps are on Android and iOS. Graphene lets you run them. You can't have a bank account on a Linux phone* because they won't let you, but you can on Android including on Graphene.

      * before replying snarkily that Android is Linux, please take a long walk off a short pier, thanks

      • yjftsjthsd-h 1 hour ago
        > All the existing apps are on Android and iOS. Graphene lets you run them.

        We have waydroid for that.

        > You can't have a bank account on a Linux phone* because they won't let you, but you can on Android including on Graphene.

        Unless of course it uses those stupid integrity apis to block anything that isn't stock.

        • pteraspidomorph 1 hour ago
          Graphene passes basic integrity, so most of them work. There is a list here:

          https://privsec.dev/posts/android/banking-applications-compa...

        • imkac 1 hour ago
          Porting traditional Linux desktop distributions to Android devices is meaningless, all you get is more instability, more unsafe and more trouble. Waydroid is a bad implementation on security and compatibility, just running Android in VM is better.
          • yjftsjthsd-h 26 minutes ago
            > Waydroid is a bad implementation on security and compatibility, just running Android in VM is better.

            What security problems does waydroid have that a VM wouldn't?

      • wseqyrku 15 minutes ago
        I can't care less about "apps". Web is already powerful enough to do all sort of stuff on device.

        That said, I think wasi containers support for a mobile OS would be a game changer.

      • tfrancisl 2 hours ago
        What's stopping me from using a browser to log in to my bank? Assuming my bank is one of the ones that requires you to lock down sideloading (they aren't, but i know many are).
        • cesarb 2 minutes ago
          > What's stopping me from using a browser to log in to my bank?

          The "security module" they require you to install on your computer. In the past, when browsers had plugins, this was a browser plugin; nowadays, it's an always-on service (running as root) which exposes a local HTTP server which the bank site connects to to validate your computer. For an example from a major bank in this country (the same "security module" is used by several banks in this country), https://seg.bb.com.br/home.html is the diagnostic page for that "security module" (the FAQ page there has links to the installers).

        • owaislone 1 hour ago
          Nothing is stopping you. You're free to use a desktop web app that either doesn't work or is terribly slow or has limited features on a mobile web browser. I'd love it if all apps were PWAs but that is not the case.
          • georgeecollins 1 hour ago
            My broker has a much more fully featured web app then it does on iOS or Android. You can do things in a browser that the phone apps will send you to a browser to do. BofA is just as good of a web app. Maybe people are just used to using their phones?
            • georgeecollins 14 minutes ago
              Looking down the thread I am also thinking maybe this is a Europe thing? I am usa.
          • thesuitonym 57 minutes ago
            That's not terribly compelling. Android and iOS banking apps also don't work, are terribly slow, and have limited features.
          • mikestew 46 minutes ago
            Eh? The bank apps I’ve seen appear to be webviews wrapping their mobile site. Much to my chagrin, I’ll add.
        • terribleperson 1 hour ago
          I had to replace a credit card yesterday. Part of the default flow involves the call center sending a notification to your app. When I told them my android version was too old, it took them twenty minutes to find out they could instead send a text message. That text message sends you to a photo-and-id verification service, but that's another issue.

          Soon, there won't even be an alternative flow. There are a lot of places where there already isn't.

          • georgeecollins 1 hour ago
            Are you sure? This seems like a forum with a lot of early adopters and a lot of late adopters still use browsers, email, text messages. Like, let me guess that your credit cars isn't capitol one. Not that it should be, but that would be more "normie".
        • gf000 7 minutes ago
          Well, it's kinda hard to scan a QR code displayed on your screen when the camera is attached to its back (semi-joking)
        • Yeroc 2 hours ago
          The websites don't have feature parity with the apps these days. Things like being able to deposit a cheque aren't available among other things.
          • lopis 55 minutes ago
            Some older banks do have more features in their website than their app. It's usually the ones with the worse, most outdated UIs and almost useless mobile apps. After years of using several mobile-first neo-banks, I switched to a traditional bank and boy, was I not ready for the trip back in time.
          • encom 9 minutes ago
            >deposit a cheque

            That would be inconvenient if this was 1985.

        • Alpha3031 2 hours ago
          Some banks are app only and/or build MFA functionality into their apps.
          • thesuitonym 57 minutes ago
            That would be a hell naw from me.
          • wseqyrku 7 minutes ago
            You know the web is also bits and bytes right? Someone who has a say should fix it so banks can do whatever they need right in the browser.
        • inigyou 2 hours ago
          The 2FA code you need to get from the phone app to log in on a desktop. It isn't 2005 any more.
          • Aachen 1 hour ago
            Apparently I live in 2005 then? I do 2FA with the same chip+pin method that I use to pay in the store. Works in any browser
            • patall 1 hour ago
              Maybe that is possible in Germany. It is impossible here in Sweden.

              Or in other words: of course you can have mobile bankid without a smartphone, just use a tablet computer ;)

              • patall 1 hour ago
                @fsflover: and my mobile phone provider. And my insurance. And my eletricity provider. And my housing associations customer portal. Getting doctors appointments. Mortgage. Union. National retirement savings account. Some of these may have some alternative left, but far too many you will be left out.

                Well, I can buy a train ticket without it, so I could still leave.

              • fsflover 1 hour ago
                Looks like it is possible in Sweden: https://news.ycombinator.com/item?id=47562094

                Consider switching your bank to one not forcing you into American megacorps.

          • stvltvs 1 hour ago
            Highly location dependent. This is more true in Europe than in America.
          • tcfhgj 1 hour ago
            my bank (and others) doesn't require the 2f to be a smartphone
          • jonathanstrange 1 hour ago
            Right, 2FA. My bank wants me to log in to my phone app and then sends an SMS to the same phone to confirm the app transaction. It's super-secure.
        • saidinesh5 2 hours ago
          The bank website typically needs the app to enable two factor authentication in a lot of places.

          For eg. There's no browser based alternative to make UPI payments that i know of.

          • dotancohen 23 minutes ago
            How about for clients with no smartphones?
        • TFNA 45 minutes ago
          In many countries, all major local banks require their phone app as the second factor to log in to the browser version of their online banking. Sometimes functionality is removed from the browser version and made available only in the phone app.
          • drnick1 33 minutes ago
            "Many" is doing a lot of work here. A more accurate statement would be that some banks in some countries require invasive apps, but fortunately it isn't the case everywhere (yet).
          • dotancohen 24 minutes ago
            And what do people without a smartphone use?
            • renehsz 0 minutes ago
              A hardware-based CardTAN device, which is super inconvenient. Or else they can't do any online banking at all.

              crying in EU :(

          • DANmode 44 minutes ago
            Name five.
        • justsomehnguy 1 hour ago
          The bank itself. They want to see where are you, what you do and snoop on anything they can about you. Having a spywa^W sorry, bank app is the best way to do that.

          Source: my bank which recently 'upgraded' a browser version to a glorified SPA which even renders as a vertical oriented app on a landscape 4K monitor.

          • thesuitonym 51 minutes ago
            Sounds like it's time for a new bank.
      • t1234s 1 hour ago
        Even Graphine is limited in what apps work properly compared to a normal google phone. You have to give up a lot in order to have privacy these days.

        A pure linux non-android phone would be great however you wouldn't have access to properly working apps and would not be able to participate in modern society.

        • m4xp 46 minutes ago
          Not true, if you install play services you can run 99.9% of apps, i can even run all the italian apps from yhe goverment. You are still using google but its running as user service and you can even revoke most of the permissions including location.
        • unethical_ban 30 minutes ago
          Running their sandboxed Play, I can run everything. The only thing I notice in the US is some banking apps (stupidly, idiotically, moronically) force 2FA on every login instead of trusting biometric entirely like they do on stock OS.
      • sehw 54 minutes ago
        I use my web browser to access my bank and tell banks that require apps to go fuck themselves.
      • megous 1 hour ago
        Banks care very little about actual security. Some force you either to SMS codes, or to their app on a hopelessly broken platform based on shoving many untrusted spying apps onto one device and hoping some SW will be able to keep them apart.

        Almost none support strong dedicated HW authenticators or second factors. Not even as an option to those who care.

        Anyway it's always possible to just reverse their web api and use it directly. 2FA that consists of copying some code from SMS is no barrier, especially not on the Linux phone that you fully control.

      • jambalaya8 1 hour ago
        yeah, people suggesting Android is Linux are as annoying as people saying Digital Unix/Tru64 was OSF/1, or MacOS/OSX is now Darwin or OSF/1 or Gnu Hurd itself.
      • xnickb 1 hour ago
        Some (European) banks/healthcare apps block GOS and require stock android. Just saying
        • protimewaster 1 hour ago
          I wonder if practices will change any of there's ever a device that ships with GOS. Right now, many companies are happy to shrug off GOS, because they don't support "modified devices".

          If any of the Motorola devices have GOS as a pre-installed option, now the companies don't have the excuse that the device is modified.

          I'm guessing the companies will continue to be difficult, but it'll be amusing to watch, at least.

        • drnick1 28 minutes ago
          What is the point of apps for these things in particular? I understand that some banks require an app for 2FA, but I don't see why anyone would want some invasive healthcare app on their phone.
        • gunalx 1 hour ago
          Yep. Had to change banks because of my old one suddenly dropping grapheme support by adding stupid attestation mechanics.

          They surely must have gotten feedback from me and others because the next update it worked again. But I and probably others where already a lost customer.

      • throwaway_94383 1 hour ago
        most banking apps don't run on graphene
        • DANmode 40 minutes ago
          Stop parroting this. It’s not true.

          Diminishingly few apps do not work, and it’s down to them.

    • drnick1 11 minutes ago
      Like others have said, it comes down to apps mostly. But there is also the fact that Google and others have spent more than a decade optimizing the OS for appliances. Android was built from the ground up for mobile devices and handles things like background apps, notifications, and charging as expected on a phone. All of this could be ported or rebuilt, but the work has already been done for Android and billions of devices prove that it works.
    • QwenGlazer9000 2 hours ago
      Everyone else mentioned the app support which is true, but for graphene specifically, they do not like desktop Linux at all because they don't like its security. They would much rather build on AOSP than desktop linux.
    • Gigachad 2 hours ago
      Because you need app support. Not even Microsoft could pull that off.
      • jorvi 2 hours ago
        You mean Microsoft proactively kept shooting devs in the kneecaps?

        Leaving phones behind on old incompatible OS versions 2 times in 3 years and switching app frameworks 3 times in 4 years does not a good app developer experience make.

        Piled on top of that, Google became actively hostile to 3rd party developers building support for YouTube (and Gmail and Gmaps, but those had workarounds / alternatives).

        • Yokolos 1 hour ago
          What a colossal disaster. I was a huge Windows Phone fan, so their yearly missteps were quite painful to watch. I was especially annoyed when my first gen WP wasn't going to get an upgrade to WP8. My HTC 7 Pro is still my favourite phone I've ever owned, but after that I finally gave up and switched to Android.
      • nextaccountic 2 hours ago
        What about running the whole Android infrastructure, but on top of a non-Android Linux distro? And this, on top of a Android kernel (otherwise you won't have the drivers yo uneed)

        The advantage being, we can manage packages using a regular Linux distro

        • saidinesh5 1 hour ago
          A lot of "non Android Linux distributions" like sailfish os actually use a lot of Android infrastructure to keep working.

          Drivers doesn't just mean the kernel. It's the user space binary blobs and services that need to talk to the kernel to enable the hardware.

          Other than that there's waydroid, alien dalvik etc.. that run another Android instance in a container.

          The thing is a lot of Android applications use safety net/other methods to make sure they only run on. "Approved"/stock hardware.

        • tfrancisl 2 hours ago
          This is exactly where my head goes. There's nothing special about this hardware other than its small form factor. Sure, some desktop apps would likely want a different skin, but thats hardly limiting.
        • realusername 1 hour ago
          You can't because a lot of apps check that the phone is controlled by Google with Play Integrity.

          Google thought about this, don't worry. They learned their lesson after CyanogenMod tried to compete by offering an alternative. Non-Google Android are now dead except in China.

          • arxari 55 minutes ago
            Well for me I use Lineage without even MicroG and everything I need works - yes even banking
          • imthatsteve 1 hour ago
            CyanogenMod became LineageOS and its still going strong, im typing this on an unofficial lineageOS build right now.
      • puzzlingcaptcha 2 hours ago
        App support, stable ABI, uniform UI/UX, hardware vendor cooperation...
      • tfrancisl 2 hours ago
        I dont think app support is all that important. Most apps are garbage as they are ime, so rebuilding from scratch, or using existing software that runs fine on linux, would keep me happy.
      • tcfhgj 1 hour ago
        Microsoft could, but abandoned just as they gained traction in Europe
      • deaton 29 minutes ago
        Microsoft can barely pull off their flagship desktop operating system, so that doesn't say much.
      • inigyou 2 hours ago
        Doesn't windows run android apps natively now?
        • dzikimarian 2 hours ago
          It doesn't. There was a plan, but Microsoft abandoned it.
          • AstralSerenity 1 hour ago
            They did end up releasing Windows Subsystem for Android via the Windows Insider Program, which was enough for the OSS community to take it over after it was abandoned. It still exists and has worked quite well for my use case: https://github.com/MustardChef/WSABuilds
    • compass_copium 2 hours ago
      GOS is broadly compatible with most phone use cases out of the box--chat, mail, browsing. A Google Play profile lets me use almost all apps (including my bank apps, but I understand that's not true for everyone).

      In principle I agree about a Linux phone, but the gaps are much greater. I am also sympathetic to the GOS team's arguments that sandboxing on Android is better, and important on a device that allows control of essentially my whole life (2FA apps etc.)

    • gf000 9 minutes ago
      Because it's a mobile platform and "GNU+Linux" is laughably terrible in this space.

      It's almost like Android has put millions of expert dev hours into making it the most used OS in the world. Like GNU+linux on laptops only works the way it does because of android-upstreamed battery saver kernel features.

      But a mobile is also people's most used devices with all of their data, bank accounts etc there - it has to be safe. And GNU+linux has not even a single thought about security, while android just has it worked out (every app runs as its own user, so it's even built on standard UNIX security).

      A mobile OS also has to race to suspend and for that it needs cooperation from "apps" -- desktop apps just run, they don't care about anything besides SIGKILL. That's not a workable model on a mobile and android solves it.

      And I say all that as someone who runs linux everywhere I can and I absolutely love it. It's imo the best kernel out there -- but the userspace is not where it should be and if anything, the correct question would be what can we take from Android and add to GNU+Linux. (And nix is fantastic, but it's a packaging solution, I don't really see how it comes into question here. I can run nix on my android phone just fine by the way)

    • dzonga 1 hour ago
      once Huawei was forbidden from using Android - that's when people ie western markets & the world at large should've shifted. look at HarmonyOS.

      in China - there's no google apps available on their 'android' versions.

      their platforms are already performant and fluid - so people should build on that.

      • RobotToaster 1 hour ago
        It's a shame that the newest version of harmonyOS isn't open source.
    • otekengineering 1 hour ago
      i recently put debian (mobian) on a pixel 3a and it's pretty solid, though i haven't tried it out as daily driver yet.

      claude code makes stuff like that super accessible to do in your spare time. another example is installing debian on a synology 918+, there's no way i would've had the grit to do that without ai. it's open season for any gadget that's got a debug uart port.

    • matheusmoreira 1 hour ago
      Because without Android I can't run WhatsApp and my bank's app on my phone, which promptly reduces it to a paperweight. I wish it wasn't so, but reality refuses to cooperate, so let's just be happy that we've got GrapheneOS which is so good it has its own column in Cellebrite's support matrix.
    • throwIeoeor 2 hours ago
      Because Android is miles ahead in terms of security, permission management, app separation, power management, privacy...

      Linux crowd can not even agree on compositor, and if systemd or sudo is a good idea.

      • bigfishrunning 34 minutes ago
        Why should Linux users have to agree? run what you want, it's your computer.
      • thesuitonym 42 minutes ago
        > Linux crowd can not even agree on compositor, and if systemd or sudo is a good idea.

        This is actually a feature.

    • owaislone 1 hour ago
      Apps. We'd love a completely different OS and it is viable on desktop because web almost does everything but on mobile you're basically locked out of very essential functionality like banking, transit, messaging etc. The compatibility layers aren't good enough (yet) to offer a seamless experience.
      • gunalx 1 hour ago
        Also almost any native desktop app forced to mobile has broken ux.
    • DANmode 40 minutes ago
      Your point is valid for every flavor of Android except GrapheneOS.

      GrapheneOS’ security model makes that of desktop Linux look like a joke.

      This is an objective analysis based on x86 security, GrapheneOS hardening (including isolation and hardened mem allocator), Pixel hardware security.

    • Cider9986 2 hours ago
      AOSP has way better security and therefore privacy than desktop linux.
      • arxari 52 minutes ago
        This is something that no Linux phone enthusiast seems to understand.

        Also if we use atomic distros with flatpaks and whatnot that mimic Android security the end user basically ends up having to essentially use Termux (but busybox or something similar) on their Linux phone as well

      • drnick1 21 minutes ago
        Stop repeating this nonsense, AOSP isn't any more "private" than Linux. AOSP is only more "secure" because, on some devices like Pixels, it exploits hardware features typically not found on general purpose computers. By default, Android also limits user control and takes root away. That may be a sensible design for an appliance, but it isn't something we should want on desktops.
    • deaton 35 minutes ago
      Because the Android Runtime (ART) is very necessary to run APKs, and APKs are the only non-iOS standard for packaging mobile apps that is supported enough to be viable. Without it, you might get some open source apps to run on a linux phone, but you won't have banking apps, clash of clans, or a million other things people really would like to have on their phones.
    • kotaKat 1 hour ago
      All we had to do was build PWAs instead of native apps and instead all we did was build PWAs into bad browser wrappers.
      • cosmic_cheese 9 minutes ago
        I don’t see PWAs becoming dominant so long as web development stubbornly retains its highly atomized “bring your own everything” philosophy. At the very minimum, there needs to exists a community-accepted web UI framework with a similar level of “batteries included”-ness in terms of scope and depth as that of SwiftUI/Compose, or preferably that of UIKit.

        The existence of such a framework would make the various tradeoffs with going web-only sting less and make that the advantageous route, not just the cost-cutting route that it’s seen as now (and why those bad browser wrappers continue to proliferate).

    • geremiiah 2 hours ago
      I don't either. Don't we have free market capitalism? Why don't I have a Linux phone? And why do I need to worry that my government and banking apps won't work if I get a Linux phone?
      • rcxdude 2 hours ago
        Because in a free market you can't compel someone to support your niche platform, nor even compel someone to create the niche platform you want. The market for a Linux phone is tiny because there's almost no reason for the average phone user to prefer it over android.
        • fsflover 1 hour ago
          > you can't compel someone to support your niche platform

          You mean, a browser?

      • post-it 2 hours ago
        Because you don't have capital.
      • attila-lendvai 1 hour ago
        no, we don't, far from it.

        (which doesn't mean there's not a lot farther from here).

      • realusername 1 hour ago
        > Don't we have free market capitalism?

        Not in the mobile world no, it's not a free market by any means

    • StrLght 2 hours ago
      AOSP is Linux.

      If by "mainstream" Linux you mean something like postmarketOS, I'd suggest you look up reviews or give it a try yourself. A few months ago, people were reporting a hard time placing a call, taking a photo, etc.

  • unfocso 2 hours ago
    A year ago or so, the ThinkPhone 23 (Snapdragon 8, 2023, a weird "flagship") was available for 229€ new on various retail stores. The phone also supports Mobian/PostmarketOS and the bootloader is unlockable with no adverse effects.

    Out of nowhere, it received (along with other older phones) updates up to Android 16.

    I wouldn't be surprised if the "sudden" update was just a side effect of Motorola preparing for Graphene to be released on these older phones.

  • virajk_31 2 hours ago
    I bought the Moto signature a month ago , I already assumed it prolly won't support graphene, since some of the previous replies on X indicate that the graphene team requires full hardware compliance with their requirements, and the Signature apparently is not compliant yet.

    Anyway I ended up buying a really good smartphone.. just not a graphene supported haha :(

    Also this is really great collab from moto & graphene as more vendors will officially recognize Graphene as legit OS (legel/OEM is different concept). I heard month ago Volkswagen banned graphene, hopefully we we will see moving things in opposite direction...

    • drnick1 2 minutes ago
      > I heard month ago Volkswagen banned graphene, hopefully we we will see moving things in opposite direction...

      Why would anyone want a car app? Is being tracked by the car's telematics unit (cellular modem) not enough?

    • hypfer 2 hours ago
      They didn't "ban" them, but they did enable some attestation feature that effectively "bans" anything that isn't Google Android.

      Which still makes you wonder why Volkswagen is so keen on alienating what little is left of their customer base with completely stupid security theater.

      • inigyou 2 hours ago
        Because the EU is run by lawyers and lawsuits. They probably decided there was a risk of being sued for insufficient security if they didn't enable every security feature, and they considered it as zero impact to customers because nobody uses graphene.
        • hypfer 2 hours ago
          Yes, but that is still very confusing to me, because you're not paying other people money so that they just follow incentives without thinking, vision or backbone.

          The whole idea of buying something is giving people money for their (assumed correct) judgement, which then leads to desired artifacts downstream.

          • inigyou 2 hours ago
            No, the idea of buying is that you get something in exchange for money.
            • hypfer 1 hour ago
              Yes, but not any something, but a specific something shaped by taste.
      • tsss 1 hour ago
        The people at VW don't think about the customer. They are essentially bureaucrats who only live to expand their personal fiefdom in the bureaucracy. I bet that many in the IT-security team would insist that their team doesn't have customers.
  • throwfaraway135 33 minutes ago
    I get that you don't like Twitter/Facebook/Reddit or whatever, but a clear solution to this problem is to hurt googles public image as much as you can and for that you need a platform with as large of a reach as possible.

    edit: they have X but didn't post it there https://x.com/GrapheneOS

  • therealmarv 21 minutes ago
    I just wonder how they handle full Google's certification for hardware integrity + Google Play Store with GrapheneOS. They contradict on this part on the normal GrapheneOS mod and I don't see a way how they will not on Motorola phones.

    Banking apps (e.g. Revolut) block GrapheneOS actively and many other apps too.

    But it will be interesting times once they are out!

  • rh94 1 hour ago
    Anyone has any idea if this changes current situation with nfc payments? Currently many banking apps do not work, and google pay is just unavailable, to my understanding it was related to secure chip on phone - as graphene wasnt "stocked" android os approved by google, i dearly hope this chnages with motorola
  • matheusmoreira 1 hour ago
    Looking forward to this! Google is not competent enough to sell Pixels worldwide, it's a pain in the ass to buy one!
  • exceptione 3 hours ago

      "The initial devices with GrapheneOS support should be available in 2027. The initial devices will be flagships so they'll be higher end hardware than Pixels at a higher price. Lower end devices will take more time to meet our requirements since the updates and security features aren't as good. It's mostly due to how Qualcomm handles it. The latest Snapdragon flagships have the best security features. We'll also need Motorola to start paying them for longer updates below flagships."
    • tortasaur 3 hours ago
      I don't doubt they will cost more than the Pixel line, but I'm somewhat skeptical that the hardware will be higher quality. Perhaps my idea of what Motorola is capable of is outdated.
      • ai-astrologer 2 hours ago
        Google’s Tensor chipset is weak by modern standards, and Motorola is taking the strongest off the shelf processors from the best mobile chip designer (Qualcomm).
        • scrlk 2 hours ago
          Plus the Samsung Exynos modems that they were using from Pixel 6-10 (11 switched to Mediatek) had worse power efficiency and performance vs Qualcomm.
        • IAmBroom 2 hours ago
          So...what's your comment? Opposing Motorola's comment, in that they already buy the best? Supporting, in that their standards haven't dropped?
      • ernst_klim 24 minutes ago
        Pixel itself is very mediocre hardware, it's not hard to surpass. The battery is my main problem with it, my current pixel can't barely survive half a day of usage.
      • kvuj 2 hours ago
        Realistically, most smartphones are made by the same ODMs. Since they don't make their own screens, shells, CPUs or modems, the only thing being set apart is the software.
        • Aachen 1 hour ago
          Except that it's all Android?

          I'm not selecting which phone I buy on whether the stock OS comes with lockscreen shortcuts. At best, a software requirement someone might use as a deciding factor is OS support and bootloader unlock. The real differences are in hardware: size, battery life, chipset speed, RAM or other local model enablers, picture quality (this part also depends on good software to be fair), included accessories, satellite connectivity hardware, headphone jack, gimmicks like UWB or FM radio support, whether it's a flip/fold phone, storage space / sdcard support... all hardware differences

          • bigfishrunning 30 minutes ago
            > Except that it's all Android?

            If only this were true. Samsung makes arguably the best hardware, but I refuse to buy a phone with Facebook pre-loaded and unremovable, a second (worse) app store preloaded and unremovable, and a bunch of redundant samsung-branded copies of the google apps. The best android images are as close to vanilla AOSP android as possible -- this used to mean Sony or Google branded phones, except Sony doesn't really market phones in the United States anymore and the Pixel phones are diverging from AOSP

  • DemiGuru 12 minutes ago
    Am I the only one that is uncomfortable with the idea of GrapheneOS running on a Lenovo owned company (with all its past security shenanigans)?
  • closingreunion 1 hour ago
    I wonder if this could enable a samsung dex-style desktop mode
  • Retr0id 2 hours ago
    > the updates and security features aren't as good [on lower end Motorola devices]

    Having looked at some low-end Motorolas recently, this is accurate (albeit an understatement!)

  • jauntywundrkind 1 hour ago
    Anyone want to place bets in whether this will be an unlockable bootloader, or some GrapheneOS only install path?

    Sure would be nice to have phones that can be rooted, or OS replaced. I've been hopeful this would perhaps enable that, but I fret my excitement may be premature.

  • LoganDark 2 hours ago
    If they only "should" be available in 2027, that sounds like late 2027.
    • Cider9986 2 hours ago
      Iirc they said they will be able to release Android updates like Android 17, for example, at the time it's released. This year it was a few weeks until it came to stable.

      This somewhat indicates to me it will be available when the Motorolas release which should be on their regular release patterns. That's been May for the 2025 and 2026 Razrs.

  • Noaidi 21 minutes ago
    This is good news but not so much good news for us poors. I was waiting four this announcement in hopes of getting away from google totally but with the 2026 Moto Signature going for $1000 I am sure the 2027 will be more so I will probably get Pixel 10 instead.

    Maybe this will lighten the price on the Pixel 10's though...

    • catlikesshrimp 10 minutes ago
      All other phones will have a higher price tag due to memory hogging by datacenters. How much will that google pixel 10 be when the motorolla phone arrives?
  • mrdoe 2 hours ago
    [flagged]
    • StrLght 2 hours ago
      Because it doesn't spam you with dickovers suggesting you log in when you open the link. But you're not really interested in this, are you?
    • afavour 2 hours ago
      Tell me you're in a bubble without telling me you're in a bubble.

      (Mastodon is, of course, also a bubble. But largely by design. A lot of more tech-leaning folks decamped there any stayed there)

      EDIT: ah, OP is just a troll that only ever seems to comment when someone mentions a short form social media network that isn't Twitter.

  • nunobrito 2 hours ago
    An Android distro with dubious funding that only runs on high-end hardware from NSA suppliers.

    Thanks, but no thanks. I'll keep using Lineage on any cheap smartphone under the sun.

    • Retr0id 2 hours ago
      Security-through-obscurity (i.e. using a custom ROM on a lesser-known device) does have some upsides, since you're less likely to be compatible with off-the-shelf exploits. But this is much less true now that LLMs exist, and anyone who can afford the tokens can port any exploit to any and all vulnerable devices.

      Who maintains the kernel+driver trees used by the LineageOS port you're using? And what's the modem's security like?

      • nunobrito 59 minutes ago
        I'd prefer to take my changes with a potentially outdated kernel than with an intentionally malicious one.

        Furthermore, when the hardware is cheap then it is also cheap to upgrade/move often. Which is not the case for those pixel/motorola/nsa luxury devices that only a few people in the globe can acquire.

        • Retr0id 4 minutes ago
          If a state actor wants to pwn your phone, they don't need to orchestrate a complex inter-organizational conspiracy to get there.
      • jambalaya8 1 hour ago
        Just gave me something else to be annoyed about today ("anyone who can afford the tokens can port any exploit to any and all vulnerable devices.")

        Not sure that is exactly correct yet but guessing not long til it would be. Bleh.

        • Retr0id 1 hour ago
          I can tell you from first-hand experience that it is true already (Well, it's true for the specific exploit/device pairings I've tried, I've not tried to construct an omni-exploit)

          Completely random public example: https://github.com/BuSung-dev/Root-My-Galaxy-Payloads/pull/1... (where GLM 5.2 is credited with the port) (Check out the other PRs in that repo for other similar examples)

    • flexagoon 2 hours ago
      Are you also one of those people who think AES is backdoored because the NSA recommends it?
      • dwedge 2 hours ago
        A member of the NSA also provided the ECDSA P-256 curve seeds but totally can't remember why
        • Alpha3031 1 hour ago
          It would be funny if it actually was intentionally selected, but for DES-like instead of Dual EC reasons, and they're just too embarrassed by Dual EC to admit it.
      • nekusar 2 hours ago
        Ridiculous comment.

        This is a known adversary and highly skilled opponent org who has even attacked senators in charge of their appropriations. I find anything they say or do to be highly suspect and default guilt until cleared.

        And backdoor isn't the same as mathematical vulnerabilities. I can easily see them pushing an encryption that would give them 10 or 20 bits complexity reduction.

        So no, I don't trust AES either.

        • inigyou 2 hours ago
          Hitler ate sugar so I don't.
          • DANmode 37 minutes ago
            You could be onto something, there.

            He was not well.

    • unethical_ban 2 hours ago
      Since we're speculating here, I hope whatever phone you have allows you to lock the bootloader (My oneplus doesn't after installing LineageOS). And certainly NSA has no way of infiltrating AOSP or less hardened chipsets.
    • goodpoint 1 hour ago
      There has been successful honeypots like EncroChat. What's the evidence that GrapheneOS is not yet another one?
    • m00dy 2 hours ago
      so you think whole thing is a honeypot ? I mean you're not alone.
      • asf1279 2 hours ago
        I found the promotion of GrapheneOS by Richard Medhurst on X after his phone was snatched and then allegedly rebooted (within 18 hours?!) very weird.

        He is adamant that the state could not read his phone but all he has is their assurance that they could not read his phone. Of course they'll say they couldn't read it if they are after his contacts and network rather than after him.

        (You could equally say that I am a deep state shill who is trying to discourage people from GrapheneOS. That is also possible, but I'd really prefer something like LinuxFromScratch for phones.)

        • officeplant 1 hour ago
          >Of course they'll say they couldn't read it if they are after his contacts and network rather than after him.

          From what a friend working in a state police cyber crime office says, "Cellebrite can't currently, unless its a Graphene OS user that's far behind on updates"

          They also said iOS is equally safe unless you're an update or two behind.

          • Cider9986 1 hour ago
            GrapheneOS seems to do better than anything else at preventing AFU exploitation based on the leaks.

            iOS will be quite good BFU but on iOS the auto reboot (brings phone to BFU after 72 hours without unlocking) is, well, 72 hours. On GrapheneOS it's 18 by default and can be as low as 10 minutes.

            Good luck on that, Cellebrite :)

      • dwedge 2 hours ago
        I ran Graphene without a Sim card for 2 months and as soon as I added a Sim card (with of course, difficult to vet networking) the phone is always hot and the battery life reduced by half. Might be a coincidence but also made me rethink how I feel about Graphene
        • swed420 1 hour ago
          > I ran Graphene without a Sim card for 2 months and as soon as I added a Sim card (with of course, difficult to vet networking) the phone is always hot and the battery life reduced by half. Might be a coincidence but also made me rethink how I feel about Graphene

          Strange you're being flagged since it's easy to find many other people on the graphene forums reporting the same (unresolved) problem.

          Doesn't mean it's guaranteed to be limited to graphene in scope, but definitely seems to be a prevalent issue for some yet-to-be-determined reason.

          Possibly related, does anybody know if graphene is vulnerable to Pegasus?

        • BLKNSLVR 1 hour ago
          My 9a running GrapheneOS doesn't get hot and battery life seems no different to other phones I've had the last few years.
          • nunobrito 57 minutes ago
            That can also indicate you are not a PoI
            • BLKNSLVR 1 minute ago
              It would seem dwedge is likely a PoI in many jurisdictions.
        • gonzalohm 48 minutes ago
          That happened to my pixel running stock android and it was the 5G. As soon as I disabled it the battery lasted longer and the phone was way cooler. After all, I'm totally fine with LTE speeds
        • zache6 2 hours ago
          What Pixel do you have? Modem quality varies and signal strength could play a role. My 9a gets hot in areas with poor reception but is fine at work where I get over a gigabit down.
          • dwedge 2 hours ago
            9. I left it with 70% battery for 5 hours and came home and it was red hot and dead. In a city with no reception issues.
            • BLKNSLVR 59 minutes ago
              That's definitely a problem, but if it was the standard experience of GrapheneOS users, then GrapheneOS wouldn't have as many fans* as it seems to.

              *Fans as in happy users, not fans as in blowing cool air over a red hot device

            • zache6 2 hours ago
              That's strange. Have you tried the stock OS and had the same problem?
        • inigyou 2 hours ago
          How many apps have network permission? Did you install anything from the play store at all? As a rule of thumb, the play store and everything on it is spyware.

          I had the opposite experience. I was pleasantly surprised by the battery life you can get when your phone isn't full of shitware apps and even when you do install shitware, the OS helps you confine it.

          • dwedge 1 hour ago
            It happens in every profile. Only one has the play store and is rarely used, doesn't run in the background
        • Cider9986 1 hour ago
          You can ask on the forum for troubleshooting. Pixels just have bad performance unfortunately.

          https://discuss.grapheneos.org

        • unethical_ban 2 hours ago
          Did you check the forums or research for any benign reason that could happen? I've run Graphene on Pixel 9 and 10 and never had such battery issues.