>At the time of writing, within ~12 months, in 2027, the 2027 Signature, Razr fold, and Razr flip will meet the hardware security requirements and should have official GrapheneOS support. Motorola is currently porting GrapheneOS to their devices.
I have a Moto G running LineageOS and it's my favorite phone ever. The ability to have my 800GB of music synced to a sdcard is something I'm loath to give up.
I think I'll buy one of those new Motorolas with GrapheneOS just to hopefully vote with my wallet a bit, and make them port it/use it for more phones in the future, which just maybe might eventually be a "normal" sized phone again.
> Lower end devices will take more time to meet our requirements since the updates and security features aren't as good. It's mostly due to how Qualcomm handles it. The latest Snapdragon flagships have the best security features. We'll also need Motorola to start paying them for longer updates below flagships
Expandable storage is priceless to me and the main reason I opt for this product.
I got stuck in Spotify for new music but that obviously doesn’t work long term
* before replying snarkily that Android is Linux, please take a long walk off a short pier, thanks
We have waydroid for that.
> You can't have a bank account on a Linux phone* because they won't let you, but you can on Android including on Graphene.
Unless of course it uses those stupid integrity apis to block anything that isn't stock.
https://privsec.dev/posts/android/banking-applications-compa...
What security problems does waydroid have that a VM wouldn't?
Soon, there won't even be an alternative flow. There are a lot of places where there already isn't.
The "security module" they require you to install on your computer. In the past, when browsers had plugins, this was a browser plugin; nowadays, it's an always-on service (running as root) which exposes a local HTTP server which the bank site connects to to validate your computer. For an example from a major bank in this country (the same "security module" is used by several banks in this country), https://seg.bb.com.br/home.html is the diagnostic page for that "security module" (the FAQ page there has links to the installers).
For eg. There's no browser based alternative to make UPI payments that i know of.
It's not just for clients with no smart phones. It's also clients who activate developer mode on their smartphone etc... clients who use VPN. Clients who run AdBlocker. Clients who use Firefox.
There needs to be a severe push back against this.
Things have gotten so crazy that the homeless here are walking around with QR codes printed out when begging for money. I'm guessing they're a network of people who share the same smartphone/payment method..
The relevant regulations are Commission Delegated Regulation (EU) 2018/389 and the earlier Directive (EU) 2015/2366.
While these laws are deliberately vague when it comes to specific technologies, they do require at least two independent factors from different categories, such as knowledge (password) and possession (phone).
That, in and of itself, wouldn't be a problem. The way most banks implement it, however, is by giving you two choices:
1. You use their mobile app (which likely requires device attestation and Google Play Services, so won't work on a plain LineageOS install)
2. You use their CardTAN device, which is extremely inconvenient to always carry around.
Sure, we nerds might argue they should just let us use our Yubikeys or regular old TOTP, but pretty much no bank implements that. (Why? Your guess is as good as mine.)
Personally, I had to buy a second stock Samsung phone just for banking apps. And yes, there are still alternatives (only very very few though), but no, none of them are convenient, for various unrelated reasons.
I wouldn't be surprised if this continues to spread to the US too, under the sneaky disguise of "security".
In reality, most of time it's just a matter of choosing the right bank wherever you are. I'm writing this on a GNU/Linux phone that does my banking just fine. I'm from the EU.
crying in EU :(
Or in other words: of course you can have mobile bankid without a smartphone, just use a tablet computer ;)
Consider switching your bank to one not forcing you into American megacorps.
Well, I can buy a train ticket without it, so I could still leave.
I wonder why there would be such a difference in policy between countries, not only in government but across the private sector? This doesn't make any sense to me. If anything, I'd expect Sweden to have a more sensible, left wing attitude than Oz.
Source: my bank which recently 'upgraded' a browser version to a glorified SPA which even renders as a vertical oriented app on a landscape 4K monitor.
A pure linux non-android phone would be great however you wouldn't have access to properly working apps and would not be able to participate in modern society.
It seems not all of them, and that things will only get worse if recent news comes true.
That said, I think wasi containers support for a mobile OS would be a game changer.
(^ Here's a startup idea if you're looking out for one. I for one throw out all my devices from the balcony to get this)
I haven't figured out how to make them talk with each other though. I imagine that's the place where I'd notice this lack of support.
Almost none support strong dedicated HW authenticators or second factors. Not even as an option to those who care.
Anyway it's always possible to just reverse their web api and use it directly. 2FA that consists of copying some code from SMS is no barrier, especially not on the Linux phone that you fully control.
If any of the Motorola devices have GOS as a pre-installed option, now the companies don't have the excuse that the device is modified.
I'm guessing the companies will continue to be difficult, but it'll be amusing to watch, at least.
They surely must have gotten feedback from me and others because the next update it worked again. But I and probably others where already a lost customer.
Diminishingly few apps do not work, and it’s down to them.
Leaving phones behind on old incompatible OS versions 2 times in 3 years and switching app frameworks 3 times in 4 years does not a good app developer experience make.
Piled on top of that, Google became actively hostile to 3rd party developers building support for YouTube (and Gmail and Gmaps, but those had workarounds / alternatives).
The advantage being, we can manage packages using a regular Linux distro
Drivers doesn't just mean the kernel. It's the user space binary blobs and services that need to talk to the kernel to enable the hardware.
Other than that there's waydroid, alien dalvik etc.. that run another Android instance in a container.
The thing is a lot of Android applications use safety net/other methods to make sure they only run on. "Approved"/stock hardware.
Google thought about this, don't worry. They learned their lesson after CyanogenMod tried to compete by offering an alternative. Non-Google Android are now dead except in China.
In principle I agree about a Linux phone, but the gaps are much greater. I am also sympathetic to the GOS team's arguments that sandboxing on Android is better, and important on a device that allows control of essentially my whole life (2FA apps etc.)
People will tell you that chromium is "more up to date" as if Google wasn't the one setting the standards, making it impossible for anyone else to be similarly complete. Seems like we have a very similar problem here...
Linux crowd can not even agree on compositor, and if systemd or sudo is a good idea.
This is actually a feature.
in China - there's no google apps available on their 'android' versions.
their platforms are already performant and fluid - so people should build on that.
claude code makes stuff like that super accessible to do in your spare time. another example is installing debian on a synology 918+, there's no way i would've had the grit to do that without ai. it's open season for any gadget that's got a debug uart port.
Yes, you can, although it may require tinkering and compromises: https://itsfoss.com/whatsapp-linux-desktop/ and https://news.ycombinator.com/item?id=49363246
Also if we use atomic distros with flatpaks and whatnot that mimic Android security the end user basically ends up having to essentially use Termux (but busybox or something similar) on their Linux phone as well
You don't think, say, isolating apps has anything to do with it?
It's almost like Android has put millions of expert dev hours into making it the most used OS in the world. Like GNU+linux on laptops only works the way it does because of android-upstreamed battery saver kernel features.
But a mobile is also people's most used devices with all of their data, bank accounts etc there - it has to be safe. And GNU+linux has not even a single thought about security, while android just has it worked out (every app runs as its own user, so it's even built on standard UNIX security).
A mobile OS also has to race to suspend and for that it needs cooperation from "apps" -- desktop apps just run, they don't care about anything besides SIGKILL. That's not a workable model on a mobile and android solves it.
And I say all that as someone who runs linux everywhere I can and I absolutely love it. It's imo the best kernel out there -- but the userspace is not where it should be and if anything, the correct question would be what can we take from Android and add to GNU+Linux. (And nix is fantastic, but it's a packaging solution, I don't really see how it comes into question here. I can run nix on my android phone just fine by the way)
As to your other userspace concerns... these are all solveable. Perhaps with some elbow grease, but devices like the Steam Deck prove that mobile linux isnt as much of a problem re: userspace as you claim.
Ed.: I'd also like to add that the fuss around security is _mostly_ Google propaganda. Android is not meaningfully more secure, _without application level changes_ than Linux.
It's almost like the free market only works when we have well-defined and regulated markets. This has been known by Adam Smith and quite logical, yet people expect Google and Apple giga-corporations with monopolies to somehow abide by the laws of selling grains on the market.
No. This is the end state of any semblance of laissez-faire economics. Full stop. Massive accumulation at the top, power to those with capital, rags for the poorest.
(which doesn't mean there's not a lot farther from here).
Not in the mobile world no, it's not a free market by any means
GrapheneOS’ security model makes that of desktop Linux look like a joke.
This is an objective analysis based on x86 security, GrapheneOS hardening (including isolation and hardened mem allocator), Pixel hardware security.
The existence of such a framework would make the various tradeoffs with going web-only sting less and make that the advantageous route, not just the cost-cutting route that it’s seen as now (and why those bad browser wrappers continue to proliferate).
Because there is no such thing as "mainstream Linux" when it comes to anything related to user-facing consumer software. Not on desktops, not on tablets, not on phones.
I mean you invoked "mainstream Linux" and "Nix" in the same paragraph. That alone should clue you into why this, absolutely, does not work.
See here is the problem:
https://wiki.pine64.org/wiki/PinePhone_Software_Releases
"Linux enthusiests" would rather muck around with rewriting the same software over and over and over again because they dislike using GTK or whatever, and put monumental amount of efforts making new package managers, then, say, getting the ability to take simple photographs using a phone camera.
I mean... In that page there is no less then 25 different "Linux Phone OSes" listed.
None of them actually work.
They are all going to be slow, they are all going to burn through battery life. There is no meaningful security to speak of.
If I handed a unlocked "Linux phone" to somebody and said "take a photograph of me"... The chances of that actually working is slim to none.
Meanwhile we have Android OS that is proven to work. It is open source. It is used by, literally, billions of people. The security model is as good as it gets. It has better application support then Windows.
Taking something that works and then making it more secure and more open and more privacy focused is infinitely more productive and meaningful then trying over from scratch because you want a phone based around Nix packages or whatever.
Even if Google decided to close source Android from now on and be actively hostile to any open source kernel modules... Forking the Android that exists today and trying to make it work is exponentially more likely to yield positive results then, say, starting on a Debian-based "Linux phone OS".
And Android can still use nix-pkgs if you really wanted to.
If by "mainstream" Linux you mean something like postmarketOS, I'd suggest you look up reviews or give it a try yourself. A few months ago, people were reporting a hard time placing a call, taking a photo, etc.
Out of nowhere, it received (along with other older phones) updates up to Android 16.
I wouldn't be surprised if the "sudden" update was just a side effect of Motorola preparing for Graphene to be released on these older phones.
https://www.androidauthority.com/lenovo-thinkphone-hands-on-...
Anyway I ended up buying a really good smartphone.. just not a graphene supported haha :(
Also this is really great collab from moto & graphene as more vendors will officially recognize Graphene as legit OS (legel/OEM is different concept). I heard month ago Volkswagen banned graphene, hopefully we we will see moving things in opposite direction...
Which still makes you wonder why Volkswagen is so keen on alienating what little is left of their customer base with completely stupid security theater.
The whole idea of buying something is giving people money for their (assumed correct) judgement, which then leads to desired artifacts downstream.
Why would anyone want a car app? Is being tracked by the car's telematics unit (cellular modem) not enough?
> Fairphones lack the updates and hardware-based security features expected by GrapheneOS.
This is not the way.
Lest you forget that modern computing exists because ATT built unix and then threw it out to the public, at speed, as they drove away from it as fast as possible. (Something about being an actual monopoly...).
There is at least one thing, on that list that I can almost assure you will be coming back (in concept and spirt) in the next 5 years. Likely open source, because google tossed it...
Meanwhile it has other very public and open winners: Golang, Kubernetes being two stellar examples of them not dropping something like a hot potato.
> I just want to get rid of forms. Like, I never want to fill out a form again.
The opening line from this interview with Sameer Samat on the Google for Developers YouTube channel in June.
Ugh.
Also I can't believe it's been 10 years since they shut down Google Code.
This is how a multibillion company that benefited infinitely from open source pays back.
What is the context for this? It's not clear from the linked social media post.
The Android kernel source code is in git: https://android.googlesource.com/kernel/common/
Plus there's a lot of other Android source hosted on Google's git servers: https://android.googlesource.com/
That's the mainline kernel. Actual devices use various LTS kernels, for instance the pixel 9a uses kernel 6.1[1], which was hasn't been updated in a year[2]
[1] https://wiki.lineageos.org/devices/tegu/
[2] https://android.googlesource.com/device/google/tegu-kernels/...
I'm not sure which one the latest update for the Pixel 9a is using, I have an older Pixel 8. When I look at the Settings -> Android Version I can see it's using a build from January 2026 (also 6.1).
Technically this is because a lot of apps thumb their nose at the requirement to have safe areas around swipeable elements in their app, but as a user, that is not my problem to fix. It's Google's.
The workaround is so ridiculously easy too: only allow backswipes to count in the lowest 15% of the bottom left of the screen. Yet despite having hundreds of engineers earning ±350.000 per year work on this problem for years, they haven't been able to either implement or even think of it.
The real fix would be to deprecate the three button layout in Android 18 and remove it in Android 19. Force apps to comply.
I use an Android tablet and I only backswipe at the upper left.
Also, I have 6GB of RAM in my phone - switching from a browser to youtube, or vice-versa, should not cause the other to clear and start back again from a freshly-loaded state.
350,000 a year and people can't even get basic things to operate properly. Google needs broken up and their engineers need to go back to the 90s and learn some real programming skill.
People are clever enough to reach high level corporate roles, but at the same time they're are too weak to emotionally process the consequences of their "work" on their human cash cows of below-average intelligence.
However with these kind of moral/ethical questions, it's really hard to draw the line.
Is working at Google and thereby facilitating the scamming of my grandmother worse than being an ordinary pickpocket or an lobbyist for big oil?
Banking apps (e.g. Revolut) block GrapheneOS actively and many other apps too.
But it will be interesting times once they are out!
You've misunderstood something here. Revolut doesn't "block GrapheneOS actively". I'm running Revolut and most of my banking apps on GrapheneOS right now.
In my experience, there are two major categories of incompatibility:
- High levels of Google Play Integrity checks: app only works on releases of Android that have been allowlisted by Google. The only app that does this for me so far is McDonalds.
- Commercial root detection APIs: some of GrapheneOS' security features like "Secure App Spawning" trip root detection heuristics. This is the kind of incompatibility I usually run into for banking apps. You can disable individual features on a per-app basis these days to get around this.
edit: they have X but didn't post it there https://x.com/GrapheneOS
"The initial devices with GrapheneOS support should be available in 2027. The initial devices will be flagships so they'll be higher end hardware than Pixels at a higher price. Lower end devices will take more time to meet our requirements since the updates and security features aren't as good. It's mostly due to how Qualcomm handles it. The latest Snapdragon flagships have the best security features. We'll also need Motorola to start paying them for longer updates below flagships."I'm not selecting which phone I buy on whether the stock OS comes with lockscreen shortcuts. At best, a software requirement someone might use as a deciding factor is OS support and bootloader unlock. The real differences are in hardware: size, battery life, chipset speed, RAM or other local model enablers, picture quality (this part also depends on good software to be fair), included accessories, satellite connectivity hardware, headphone jack, gimmicks like UWB or FM radio support, whether it's a flip/fold phone, storage space / sdcard support... all hardware differences
If only this were true. Samsung makes arguably the best hardware, but I refuse to buy a phone with Facebook pre-loaded and unremovable, a second (worse) app store preloaded and unremovable, and a bunch of redundant samsung-branded copies of the google apps. The best android images are as close to vanilla AOSP android as possible -- this used to mean Sony or Google branded phones, except Sony doesn't really market phones in the United States anymore and the Pixel phones are diverging from AOSP
Not to defend Samsung specifically, just that most phones' software is fine after a bit of setup whereas you can't download more RAM (don't believe the scams that are out there! :P). Even on Huawei I remember there were some things better than on stock but forgot what specifically (the only thing that comes to mind was a lockscreen menu that you could open with a gesture and I used all the time)
Apropos Sony, that was the only brand where I kept having issues because my mom, who had the phone, constantly had questions about what to do with some notification that the OS was pushing and we couldn't get rid of. Basically product ads, iirc to try this-or-that app or function
I do get what you mean about bloatware, just that it's more of a tie-breaker (saving you an hour of debloating, assuming you stay on stock) as compared to the permanent differences in hardware capabilities
Having looked at some low-end Motorolas recently, this is accurate (albeit an understatement!)
Sure would be nice to have phones that can be rooted, or OS replaced. I've been hopeful this would perhaps enable that, but I fret my excitement may be premature.
Besides, GrapheneOS would probably don't want to get into a situation where their keys are burnt into hardware non-modifiable. They had to revoke such a key once in order to protect their users (against an attempt to hijack the project).
right now if you have it with you graphene just needlessly raises suspicions, its unjustified but thats what it is
This somewhat indicates to me it will be available when the Motorolas release which should be on their regular release patterns. That's been May for the 2025 and 2026 Razrs.
Maybe this will lighten the price on the Pixel 10's though...
Who maintains the kernel+driver trees used by the LineageOS port you're using? And what's the modem's security like?
Not sure that is exactly correct yet but guessing not long til it would be. Bleh.
Completely random public example: https://github.com/BuSung-dev/Root-My-Galaxy-Payloads/pull/1... (where GLM 5.2 is credited with the port) (Check out the other PRs in that repo for other similar examples)
GrapheneOS also doesn't have any custom messengers or other services which could potentially be monitored. It's very easy to check where your phone is sending requests, and if Graphene was secretly MITMing all of your traffic it would be discovered within days.
From what a friend working in a state police cyber crime office says, "Cellebrite can't currently, unless its a Graphene OS user that's far behind on updates"
They also said iOS is equally safe unless you're an update or two behind.
iOS will be quite good BFU but on iOS the auto reboot (brings phone to BFU after 72 hours without unlocking) is, well, 72 hours. On GrapheneOS it's 18 by default and can be as low as 10 minutes.
Good luck on that, Cellebrite :)
Strange you're being flagged since it's easy to find many other people on the graphene forums reporting the same (unresolved) problem.
Doesn't mean it's guaranteed to be limited to graphene in scope, but definitely seems to be a prevalent issue for some yet-to-be-determined reason.
Possibly related, does anybody know if graphene is vulnerable to Pegasus?
*Fans as in happy users, not fans as in blowing cool air over a red hot device
I had the opposite experience. I was pleasantly surprised by the battery life you can get when your phone isn't full of shitware apps and even when you do install shitware, the OS helps you confine it.
(Mastodon is, of course, also a bubble. But largely by design. A lot of more tech-leaning folks decamped there any stayed there)
EDIT: ah, OP is just a troll that only ever seems to comment when someone mentions a short form social media network that isn't Twitter.