The GrapheneOS team is security focused to the point where it is detrimental to the regular user experience. I.e. “Secure App Spawning” increases app startup time considerably on older devices like the Pixel 4a.
That’s why Graphene allows you to disable the security features. Turning off secure app spawning won’t make your device incredibly vulnerable, it will just be set back to normal AOSP security level.
Also, the GrapheneOS team has very high standards for security features supported by a phone. Basically no phone besides Pixel supports those features, which obviously isn’t a big problem for most people (else we’d have a big problem).
You know which phone has basically all of those security features? The iPhone. GrapheneOS is not building something insane, they’re just hardening Android to a point where it’s actually comparable to iPhone security. Sure, usability might not be perfect because Google only releases base Android as open source software and keeps all their fancy apps proprietary, but it’s not in a state where it’s totally unusable either.
Obviously they comply with the GPL, otherwise they would get sued. But Red Hat acts exactly like a proprietary software company. That’s what the quote is trying to say.
The GrapheneOS team has already absolutely dismanteled the Fairphone on Mastodon:
Fairphone is an insecure device with substantially delayed privacy and security patches. It receives the Android Security Bulletin patches consistently 1 to 2 months late and receives the recommended patches years late. It has a broken, insecure verified boot implementation. They have also misled their users about support by claiming their devices will get 6 years of support when they can only provide 2-3 years of security patches. That is not a privacy first device at all.
To quote Software Freedom Conservancy:
For approximately twenty years, Red Hat (now a fully owned subsidiary of IBM) has experimented with building a business model for operating system deployment and distribution that looks, feels, and acts like a proprietary one, but nonetheless complies with the GPL and other standard copyleft terms.
If you want to support a Linux phone project, the PinePhone looks most promising. If you want an actual usable phone that runs open source software, offers great privacy and security, good (open source) app support and doesn’t come with ads, trackers or any other bloatware, get a Google Pixel and install GrapheneOS and F-Droid.
No, they only fucked CentOS, and they made RHEL proprietary last year. Since Ubuntu’s decline, Fedora basically took it’s place. It’s very stable but not extremely outdated, has great security, always supports the newest technologies like Flatpak, Wayland, Pipewire, etc., has good Desktop spins and constantly innovates. The next Fedora KDE release will even completely drop support for X11, which is a good step because it forces developers to adopt Wayland. They also have pretty good immutable spins like Silverblue, Kinoite and others. Other cool distros like Nobara and uBlue are also built on top of Fedora.
This would be awesome. Fedora has really been one of the best distros lately, hopefully they don’t get fucked by Red Hat in the future.
I always need
CLI:
Did you set up GPU passthrough?