back
452 comments
https://tbot.substack.com/p/grapheneos-new-oem-partnership

> GrapheneOS has officially confirmed a major new hardware partnership—one that marks the end of its long-standing Pixel exclusivity. According to the team, work with a major Android OEM began in June and is now moving toward the development of a next-generation smartphone built to meet GrapheneOS’ strict privacy and security standards.

Oh that's one of the best news in the smartphone world in a long time.

It's impossible to escape the Apple/Google duopoly but at least GrapheneOS makes the most out of Android regarding privacy.

I still wish we could get some kind of low resource, stable and mature Android clone instead of Google needlessly increasing complexity but this will over time break app compatibility (Google will make sure of it)

Edit: I do think Pixel devices used to be one of the best but still I'd like to choose my hardware and software separately interoperating via standards

We will see how that goes. I love GrapheneOS, I've used it for years, but the details matter. An OEM partnership might promise a lot at the start, but a lot can change between now and delivery.
I wonder if a real OEM supports graphene if that would solve device attestation for things like banking apps.
This is really cool, but, longer term, what happens if Google makes android closed source? I feel this is a very real risk.
Has the OEM in question been revealed yet? Likely not one of the major OEMs because they all lock their bootloaders. I'm crossing my fingers it's Fairphone but that's because I love my FP5. The GrapheneOS devs have been pretty harsh towards Fairphone because of their slow updates.
This is excellent news. Google doesn't sell Pixels in my country for some reason. Hopefully the new phones will be easier to obtain.
Damn, I just got a Pixel 10 pro XL for installing GrapheneOS. I hate how below average Pixel's hardware is and I wouldn't have minded waiting a couple of more years for this.
I guess my 8a is gonna have to do for a bit longer. This one is very exciting.
I literally just bought a pixel this week. Just my luck.
Why was it that in the early PC days, IBM was unable to keep a lid on 'IBM compatible', allowing for the PC interoperability explosion, yet today, almost every phone has closed drivers, closed and locked bootloaders, and almost complete corporate control over our devices? Why are there not yet a plethora of phones on the market that allow anyone to install their OS of choice?
Nobody gave you the actual answer. IBM was under an antitrust decree and had to openly license their technology for a nominal fee. (Supposedly about $5/PC.) So yes, they were in a hurry and used generic parts, but they still had tons of patents on it. When they got out from under this, they came up with Microchannel.
You're getting a lot of indirect responses. If you've ever tried to mod your android phone the answer is simple. Its google play services and hardware attestation for things like banking websites.

Its really easy to make a custom rom but hard to do serious "real life" stuff; companies don't want to make it easy. To most regular users, if they cant download apps from the google play store, and they can't use venmo\cashapp, then the OS is dead in the water from day 1

> Why are there not yet a plethora of phones on the market that allow anyone to install their OS of choice?

There are technical reasons, but as ever the real underlying causes are incentives. Companies realized that the OS is a profit center, something they can use to influence user behavior to their benefit. Before the goal was to be a hardware company and offer the best hardware possible for cost. Now the goal is to own as large a slice of your life as possible. It's more of a social shift than a technological one. So why would a company, in this new environment, invest resources in making their hardware compatible with competing software environments? They'd be undercutting themselves.

That's not to say that attempts to build interoperability don't exist, just that they happen due to what are essentially activist efforts, the human factor, acting in spite of and against market forces. That doesn't tend to win out, except (rarely) in the political realm.

i.e. if you want interoperable mobile hardware you need a law, the market's not going to save you one this one.

The only thing proprietary in the early PC architecture was the BIOS. Everything else was pre-existing architecture from third parties, there was nothing to keep a lid on.

Since a PC was a big box of parts anyone could manufacture one. A modern phone is much more complicated.

As to why there aren’t a plethora: the market doesn’t demand it that much. The people doing it aren’t wildly successful. Perhaps that’s changing (I hope so) but I know very few people outside this community who have ever thought “I wish I could have a third party version of Android”.

> Why was it that in the early PC days, IBM was unable to keep a lid on 'IBM compatible', allowing for the PC interoperability explosion

IBM didn't think to lock it down, the BIOS was the main blocker and was relatively quickly reverse-engineered (properly, not by copying over the BIOS source IBM had included in the reference manual). They tried to fix some with the MCA bus of the PS/2 but that flopped.

> almost every phone has closed drivers

Lots of hardware manufacturers refuse to provide anything else and balk at the idea of open drivers. And reverse engineering drivers is either not worth the hassle for the manufacturer or a risk of being sued.

> Why are there not yet a plethora of phones on the market that allow anyone to install their OS of choice?

Incentive. Specifically its complete lack of existence.

Cory Doctorow answers this in his book “The Internet Con”. IBM fought with DoJ for years. Today, it’s a felony to mess with anything locked down (anti circumvention)
The systems and software were vastly less complex and powerful in the 8088 days.

Very little of it was open, including the headliner apps of WordPerfect and 123.

Google had the benefit of three decades to study IBM's loss of control to prevent it with Android. Aside from China, they have been largely successful.

Other companies saw that IBM effectively lost control over their platform (and thus lost a large revenue stream), and are determined to not make the same mistake.

That's a long running effort, going all the way from lobbying (DMCA and their ilk), to all kinds of hardware root-of-trust, encrypted and signed firmware, OS kernels and drivers etc etc. And yes, today we have the transistor budgets to spend on things like this, which wasn't an option back when the PC architecture was devised.

The hardware was evolving way faster 40 years ago and in much consequent ways than these days. Plus number of users grew exponentially. So a company spending too much efforts on software could loose its edge on the hardware side. And locking hardware would be counterproductive since as it would limit new users.

These days things are way slower and the are no exponential growth in users. Plus fast cellular networks made the speed of local hardware much less relevant. So the software became way more important and so its control.

Because the original IBM PC was designed to be cheap and built in a hurry. IBM had a mandate for the original PC to use off the shelf components as much as possible. They also neglected to secure an exclusive license from Microsoft for DOS. 95% of building an IBM PC clone was buying the same parts and getting a DOS license from Microsoft (which they were very happy to sell you). Everyone saw what happened to IBM and just didn't do it that way again.
> Why are there not yet a plethora of phones on the market that allow anyone to install their OS of choice?

Here you go: https://puri.sm/products/librem-5 and https://pine64.com/product-category/pinephone/

Well, back in the day many of the people making buying decisions were tech enthusiasts who like the idea of upgradeability, etc. Computers were quite expensive, and people didn't want to waste money on a box which can only do one thing.

Besides that, "app store" was just not feasible with tech of the day.

When vast majority of customers do not care, you can ship a locked down device.

You can buy a hackable phone, but it's a niche

Obviously this situation can't go on.

If neither of the two major players can make an open, secure, _simple_, easy-to-understand, bloat-free OS, then we somehow need another player.

Presently (and I confess, my bias to seek non-state solutions may show here), it seems that a non-trivial part of the duopoly stems from regulatory capture insofar as the duopoly isn't merely software, but extends all the way to TSMC and Qualcomm, whose operations seem to be completely subject to state dictates, both economic/regulatory and of the darker surveillance/statecraft variety (and of those, presumably some are classified).

I'm reminded of the server market 20ish years ago, where, although there were more than two players, the array of simple, flexible linux distros that are dominant today were somewhere between poorly documented and unavailable. I remember my university still running windows servers in ~2008 or so.

What do we need to do to achieve the same evolution that the last 2-3 decades of server OS's have seen? Is there presently a mobile linux OS that's worth jumping on? Is there simple hardware to go with it?

Understaffed gift product wants 1 week cycles.

OEMs want 2-4 month cycles.

This is a perfect representation of the state of the software industry.

You can tell it's truly secure and private because the Cellebrite leak says they can't break it (one of very few!) and some governments assume you're a drug dealer if you use it. My next phone will run GrapheneOS.
The GrapheneOS obsession with picking a fight with everyone else is the most unfortunate part of the project.
Great, so this means that the only way to get an Android release that's up-to-date on security patches is a binary-only distro - either Google Pixel, or the GrapheneOS preview channel.

Just wonderful. Google should know better than this, shame on the other OEMs that forced this mess.

GrapheneOS goes even further by allowing you to opt in to pre-embargo security releases, bypassing the vulnerable window between vendor disclosure and OEM patches. Awesome!
So this is interesting, they release the patched binaries several months before anyone else does and several months before the source code of the patches is released?

This implies that anyone can download GrapheneOS firmware images and use binary diffing techniques to find what are still 0-day vulnerabilities on every Android other than GrapheneOS.

Useful! Thank you GrapheneOS developers.

> may i ask how you obtain the source? Are you registered as an OEM at Google?

Same question, how does Graphene get patches?

I absolutely loved my Moto X with the walnut back. I switched to an iPhone when it stopped getting security patches.

It was built back when Google owned Motorola, before they sold off everything but the patent suite. And was intended to be their flagship phone - which the Pixel later became. Looking at the GrapheneOS FAQ, it doesn't look like I have a prayer of installing it on such an old device as it doesn't have the needed security hardware. Is there a lightweight Android install available?

As a LineageOS user, I'd be interested in the disparity between GrapheneOS and LineageOS.
Although I don't use it I will be supporting the project. I'm quite proud of what they've achieved so far.
I notice my battery life is much better switching to graphine from the stock google rom.
For Google Pixel 6-9 phones only.

https://grapheneos.org/faq#device-support

The problem with custom android ROM is that the kernel is built with proprietary drivers, and porting them to other custom android is really hard
Graphene has really caught my eye in the last several months, but unfortunately I couldn't find a good deal for Pixel phones (>128GB storage), used or new. That's the biggest bottleneck for adoption it seems. I just finally switched from an S10E to a S25Ultra (black friday deal brought down to $820), but not being able to use Graphene in the future hurts a bit for sure.
There are millions if not billions of older devices. What we need is an OS that support those.
This is long needed! a lot of big tech giants, even some authorities are trying to convert mobile phones into a spying gadget.
who is the android oem they are partnering with
which pixel model is best for grephene? I strongly prefer long battery life.

will other phones be supported? why only pixel?

damn, an upgrade path from my pixel 5.
AI can't work if the OS isn't secure... lol... I'm doomed.
Is this supposed to be a joke? The best security of GrapheneOS is useless to people who don't own Don't-be-evil-hardware.
Samsung Androids are not safe? Big surprise there! /s
... maybe, but it also drops support pretty fast, and not supported on most phones :-(
i like graphite its nice and blcack and conductive