Hacker News

New stories

Live mirror
30 storiesupdated just nowView source snapshot
  1. A related skill that is recommended as a CS student
    discuss
  2. How Randomness Builds the Universe: A Cosmic Puzzle (2025)(medium.com/kosmologi.indonesia ↗)
    discuss
  3. Integrate Architecture with Topography: Strategies to Build on Hills and Slopes(archdaily.com ↗)
    discuss
  4. Parallel vector graphics rasterization on CPU(gasiulis.name ↗)
    discuss
  5. Recursively Scaling Auto-Research Loops for Efficient Agent Harness(dair.ai ↗)
    discuss
  6. A Stop Sign for $1k(maxmautner.com ↗)
    discuss
  7. US troop deaths during Iran war exceed Pentagon count by at least four(reuters.com ↗)
    4comments
  8. Bill Joy – Why the future doesn't need us (2000)(wired.com ↗)
    1comments
  9. OpenAI hacked by small team of white hat security researchers(venturebeat.com ↗)
    discuss
  10. Trump announces 'forever' deal to defend Greenland, Denmark says sign next week(washingtonpost.com ↗)
    1comments
  11. Al-Khwarizmi – Father of Algebra (c.780-850)(storyofmathematics.com ↗)
    discuss
  12. Hex turns complex analysis into visual reports with GPT-6 Astra(openai.com ↗)
    discuss
  13. The US 'Kill Chain' That Destroyed an Iranian School(bloomberg.com ↗)
    discuss
  14. What Software Teams Can Learn from the Factory Transition to Electricity(ito.ai ↗)
    discuss
  15. 'Ask for what you want' is a key skill for the 21st century(robinsloan.com ↗)
    discuss
  16. Energy-Based Models(energy-based-model.github.io ↗)
    discuss
  17. Gemini Hacked Three Companies in First Known Breakout by Google's AI(wsj.com ↗)
    3comments
  18. Hacker News Firehose for iOS(harrison.page ↗)
    1comments
  19. US and Denmark reach deal over Greenland security(bbc.co.uk ↗)
    discuss
  20. Flox will require login for search/install commands starting in October(flox.dev ↗)
    discuss
  21. Open source tool to schedule, analyze, and grow your LinkedIn page(github.com/yapsgg ↗)
    discuss
  22. Could we reboot the modern world without fossil fuels?(aeon.co ↗)
    discuss
  23. How the Boeing 737 MAX Disaster Looks to a Software Developer (2019)(ieee.org ↗)
    1comments
  24. Qantas is retiring its A380s(cnn.com ↗)
    discuss
  25. SAIR's Open Math Model Initiative(terrytao.wordpress.com ↗)
    discuss
  26. Anthropic Shifts Planned IPO to November(wsj.com ↗)
    discuss
  27. Brian Greene interviews Stephen Wolfram: Can spacetime emerge from simple rules? [video](youtube.com ↗)
    discuss
  28. Steve Eisman on AI: Companies are trying to manufacture a crisis(youtube.com ↗)
    1comments
  29. A 6502 emulator written in Markdown (and executed by an LLM)(dunkels.com ↗)
    discuss
  30. ATRA-mediated RAR-α activation attenuates acrylamide-induced testicular toxicity(nature.com ↗)
    discuss

Android 17 is the first since 3.x to add new APIs without releasing to the AOSP

385 pointsby 3h agographeneos.social
175 comments
3h agoHN ↗

i despise where Google is going with this. it's a duopoly in the smartphone OS space and we need (for lack of a better analogy, spare the technicals) open-source distros like we have with Linux on desktop.

Graphene is reaching that status for me every day and i'm looking forward to switching to it as my daily driver.

3h agoHN ↗

GrapheneOS is pretty neat, https://postmarketos.org/ is also pretty damn polished out of the box these days. I'd argue the "mobile desktop Linux systems" are actually a bit more polished than Graphene, esp. when it comes to default apps (no AOSP abandonware dialer, contacts etc. apps to fight with, it's all just maintained, responsive GNOME/KDE apps)

3h agoHN ↗

I want to believe this, but it's hard for me to take this at face value. It's been about 4 years since I've run pmOS, so my experience IS very out of date, but I also have a hard time believing that the experience has radically changed in the meantime.

The short is that yes the GNOME/KDE apps do often look more impressive, but they suffer the same sort of malaise which seems to have infected Linux desktops sometime since Eternal September, and between the sporadic crashing and "this doesn't feel right", it's really hard for me to accept "It's more polished than AOSP!".

pmOS's installation page opening with a warning:

   Make sure you read state of postmarketOS before installing postmarketOS. 

Which leads to a page that opens with:

  The goal is to make postmarketOS usable for everyone, but we are not there yet. Usability and most importantly stability issues need to be worked out first. If you are looking for an OS that is as usable as iOS or Android, this project is currently not for you.

Does not do a lot to dissuade my skepticism. I know you said the apps specifically, but even there, it's like... I dunno.

3h agoHN ↗

I tried getting it to run on a Pixel 3a and struggled for hours, eventually gave up (albeit I tried running it with Wayland and Niri which seems less tried-and-true).

2h agoHN ↗

I recently installed pmos on two 3a's and it was as simple as a Lineage image. Works well too!

3h agoHN ↗

I just wish Graphene had better support for non-Google hardware.

3h agoHN ↗

More like OEMs need to take security more seriously and add in the capable hardware and commit to firmware updates long term.

2h agoHN ↗

Unless there is a real market advantage to it, they won't. Consumers prove over and over again they are willing to trade security to save a few dollars. Furthermore, why commit to providing hardware and software support for a device to last 5+ years, when ~25% of Americans report damaging their device each year[0]. Most of a device's population will have been replaced in 3 years.

[0]: https://www.claimsjournal.com/news/national/2024/03/15/32248...

2h agoHN ↗

Yeah unfortunately this is the case. Privacy and security in general are things most average consumers don’t necessarily care for, and especially don’t care for when it provides inconveniences. Even in more tech enthusiast crowds you see this reflected most obviously in people wanting to use Firefox over any Chromium variant of a browser.

Not to mention to reach GOS’ requirements the cost of the phone would have to significantly increase which I imagine only hurts Android phones even more for no real gain since GOS users are minuscule overall.

And the long term support is definitely not the norm yeah. It’s pretty much just Apple and Google doing it for their own devices. Motorola will be a newcomer to this concept with GOS. But we can only wait and see if they actually stick to it, given their track record prior to the collaboration.

Google probably got away with it cause they made the chips and security chips themselves. I read something like Tensor costing $70 vs. a Qualcomm chip with MTE costing $250.

But even with of all this, it wouldn’t make sense for GOS to spend it’s limited resources developing for a less secure platform when appropriate target devices exist (they mentioned something to this effect a few days ago on reddit too): https://www.reddit.com/r/GrapheneOS/comments/1wifsiq/comment...

3h agoHN ↗

Those Razr phone updates need to start landing sooner ....

3h agoHN ↗

They can't due to the shortcomings of the hardware (why develop a hardened os to the grossly insecure hardware) or the vendor (no/slow updates, etc).

Anyone is free to fork, add the desired hardware support and flash.

(that's aside of some Moto flagships in 2027)

3h agoHN ↗

If Google doesn't smarten up, it will no longer be in control of Android.

Oracle was a mighty powerhouse when it bought MySQL, StarOffice, and more. It lost defacto control of all of them, due to its stupidity. In the world of open source, the tighter you hold on, the less likely you'll retain control.

And yet, here we are, with Google playing games.

Google, a note: there are far more relying upon Android than you, and now there are forced alternative stores in the mix. If Samsung and everyone else said "sorry Google', or even a large majority, you're out. Gone. Nada.

They can now fork, and force old Android to have their new fancy pants 'Play' store too.

Google is also getting more and more pushy with Chrome. What if everyone depending upon that backend, shrugs and says "Sorry Google, we're hard-forking Chrome and we'll all maintain it".

2h agoHN ↗

Oracle was a mighty powerhouse

It definitly still is. We run Postgres when we host our banking / financial stuff, but when we talk with banks and say that, they demand Oracle not that 'open source amateur stuff'. We have a version of our software for Oracle (and MSSQL) as well so no biggy, but still, we always try if we know it's not a complete immediate kill (which it will be if we put it in our documentation as only option). Oracle is still everywhere at the big guys.

2h agoHN ↗

Are they still forbidding benchmarking the Oracle database in their T&Cs? I laugh. Such litigious losers.

Postgres ftw. Long may it eat their lunch.

2h agoHN ↗

as someone who is associated with “the big guys”, I can tell you this is changing.

Our Oracle license licensing went up so dramatically that the team I work with is moving some very large databases to postgres from Oracle because it doesn’t make financial sense anymore.

now, if we could only stop eating at the trough of Broadcom…

1h agoHN ↗

I hope so, I see some changes; far less than many seem to think here though.

1h agoHN ↗

I'm advising a startup doing software for banks, and the overall attitude of their clients is: "We want to get away from the #&I$*@&^#$ Oracle, but we're stuck for now".

Oracle used to be a must-have because it was one of the few products that could handle transactions on a scale of a bank, with all the requirements for backups, redundancy, etc.

A fun anecdote. Back in 2000, I was present at negotiations (as a note-taker) where database vendors were bidding for a project for a factory control system. Vendors submitted benchmark results for various DB sizes up to 40Gb, and Oracle's rep hautingly said something like: "Our minimal size for benchmarks is 80Gb, so here are our results for that size".

And this was a _lot_ for that time. Now? It's so ridiculously tiny that you can host it on a smartwatch. So why would you pay Oracle?

2h agoHN ↗

Google's Android customers are phone OEMs. The major ones seem to like how things are going. Until Samsung and whomever start the OpenHandset Foundation or some such and fork Android, there's never going to be the Mariadb of Android.

2h agoHN ↗

it will no longer be in control of Android

Who will step up to maintain it? Keep in mind that it has to be somebody that every other OEM trust. In other words it would likely have to be an alliance of manufacturers. And they'd inevitably treat OEMs outside the alliance poorly and we'd be back to the current situation, but worse.

2h agoHN ↗

If Samsung and everyone else said "sorry Google', or even a large majority, you're out. Gone. Nada.

The OEMs are incapable of writing a competent operating system, and don't particularly care to.

Google is also getting more and more pushy with Chrome. What if everyone depending upon that backend, shrugs and says "Sorry Google, we're hard-forking Chrome and we'll all maintain it".

With what maintainers?

https://chrome-commit-tracker.arthursonzogni.com/organizatio...

2h agoHN ↗

i so desperately wish we were still in the days of manufacturers making their own OS. It's why I moved to iphone: when the hardware company makes the software and vice-versa the integration is much better and less error-prone/bloated. It never made sense to me for android to be shoehorned into thousands of devices, instead of a fork being made and for thorough OS rework to happen to support the device.

2h agoHN ↗

Graphene has been my daily driver for the past year or so. The only thing I miss is the ability to do contactless payments. Otherwise, it's been awesome. I don't run any games nor do I care about any of the AI features. YMMV.

2h agoHN ↗

for some people contactless payments are essential for their lifes

2h agoHN ↗

Contactless payments do work on Graphene - but only with the Curve app. It also requires the card-holder to be from the UK or EU.

3h agoHN ↗

Android has been so thoroughly disappointing through the years. Started as a great open free form alternative to iOS, to becoming the very thing it sought to combat.

3h agoHN ↗

If Android wants to be the inferior not-open-source mobile OS, why would I not just buy an iPhone instead then?

It’s closed too, sure, but at least it’s more consistent.

3h agoHN ↗

Android has free and open artificial pancreas that is still easy to install and keeps us with complex type 1 diabetes alive.

Google may just want to kill us and Apple don't even let this kind of software exist without massive hurdles...

2h agoHN ↗

Because it's much worse (for me).

However at this point, as a GrapheneOS user if I couldn't use it for any reason I'll go to iOS (even though I used it for a couple of years and I've been fed up).

2h agoHN ↗

Because (1) you'd be rewarding the entity that originated and normalized the loss of freedom that Google much later adopted, and (2) as Apple restricts more freedoms you'll still be able to enjoy them on Android for a few more years as Google remains (comparatively) more user friendly.

1h agoHN ↗

I had never considered using lineageos and the like, but honestly the writing is on the wall. Google is going straight into a closed AI device.

I'm going to start donating to a few free android distros I guess, I'm probably going to be trying them sooner rather than later, and without AOSP support the dev burden is going to be much higher, and it probably means they'll end up diverging and incompatible at some point (not in both directions, lineage will probably always have to have Android app support)

3h agoHN ↗

The amount of roadblocks Google is putting up for GrapheneOS is just ridiculous. None of their decisions make any sense, from the delayed source patches upstream, to the embargos, attestation issues, etc. Google simply regrets android being open source.

3h agoHN ↗

There's a non-zero chance that three-letter agencies are lobbying for at least some of this.

3h agoHN ↗

GrapheneOS does not even register on Google scale! It does not even manufacture its own devices!

Bigger problem is HarmonyOS and similar devices, compatible with Android. Opensource threat from china!

And no NSA backdoors or honeypots!

2h agoHN ↗

If the hardware security is on par with iPhone / pixel 8+, then sure.

Otherwise there's no need for NSA backdoors (as Cellebrite matrix shows) :)

2h agoHN ↗

Sure, let's just trade the NSA for the CCP, no issues there.

2h agoHN ↗

One poses an active, unchecked threat to the constitutional rights of US citizens, has a chartered mission to subvert and undermine the very field of cryptography itself - going so far as to bribe standards bodies to adopt backdoored algorithms (using taxpayer funds to do so), has plotted to mass-violate the constitutional rights of their own citizens and lie about it to the national legislature (which they carried out successfully, committing perjury in the process and facing zero consequences for it), secretly cooperates with the criminal justice system via parallel construction to target nonviolent, law-abiding political activists with fabricated criminal charges as retaliation for politically disfavored speech, while the other is about 6500 miles away, has negligible presence in / reach into the US, and is generally unconcerned with the domestic political activities of US citizens.

1h agoHN ↗

has negligible presence in / reach into the US, and is generally unconcerned with the domestic political activities of US citizens.

lmao

3h agoHN ↗

It's not a regret. Android would never have been popular in the first place if it had not been open source. If phone makers had been able to anticipate how much the demons at Google would be able to lock down the Android then they would never had used the OS back in ~2009.

3h agoHN ↗

That’s possible (never underestimate the bad decision-making of phone makers), but what would they have done instead? Windows Mobile 6 was the only licensable alternative, but it was a known quantity and obviously a generation behind Android and iOS.

2h agoHN ↗

I remember using a Maemo device circa 2009. I recall overall really liking the OS.

2h agoHN ↗

Windows Phone was pretty nice, too bad Microsoft didn't follow their DOS and Windows strategy of getting it preinstalled on every consumer PC sold. There was really only the Nokia Lumia line that I recall, but everyone I knew who had one loved it.

2h agoHN ↗

Windows Phone 7 didn’t ship until 2 years after Android. 2 more years later Windows Phone 8 was released and it was a legitimate option but just too late.

Pre-7 was just not an operating system that anyone except the geekiest of geeks wanted to use.

1h agoHN ↗

Yeah I guess Apple set too high a bar and MS was caught flatfooted (again) and was too far behind.

51m agoHN ↗

I don’t have visibility into what happened with the Windows Phone team, but Android from what I understand saw immediately that they needed to follow Apple’s lead and pivoted (originally they were building something closer to a BlackBerry). The Windows Phone team either didn’t believe they need to pivot initially or they just took too long to do so.

Windows Phone is a case study of missed opportunity.

2h agoHN ↗

WebOS was pretty cool (Palm). But I’m not sure if Palm would have licensed it. Lg ended up with it.

2h agoHN ↗

Symbian and LiMo were both available at the time. It is hard to say they were good alternatives though. Windows 7 - even with the weight of Microsoft behind it - wasn't able to attract enough hardware manufacturers.

1h agoHN ↗

There were several credible competitors: WebOS, Symbian, Maemo/MeeGo, Palm OS 6, and of course Windows Mobile. But they required cooperating with a single vendor and/or a lot of work to adapt.

Android won because it was available "right now" and easy to hack. Vendors could get a BSP (Board Support Package) from a chip manufacturer, slap Android userspace on top of it, and ship a phone within half a year. It was a glorious mess for a while.

Google then slowly tightened the reins and made the ecosystem more ordered.

2h agoHN ↗

I don't think this is actually true. Phone makers seem happy to have the platform locked down even further. They're putting even more roadblocks, as evidenced by most of them making bootloaders unlockable.

2h agoHN ↗

They're happy that it is locked down. They're not happy that they're not the ones doing the locking down.

2h agoHN ↗

This is what lots of people forget.

Android is not a Linux desktop or server distro. It is not about you getting to put what you want on the hardware you bought for free.

Operating systems are hellaciously expensive to maintain and that only gets worse in markets with rapid hardware improvements, as the smartphone market was up until maybe the late 2010s. Google is not a charity. SV did not come into national prominence for making investors $0. There is no money in giving maybe one in one-hundred smartphone users (and that's being generous) a bunch of code, for free, so that they can put it on their gizmo and talk to their nerd friends at their hacker meetup.

When they pitched Android as "open", they meant that carriers and device makers could load it up with all of the revenue-enhancing bloat that they wanted. In return, Google got a device that would let them hoover up all of the data they could ever want in order to build better ad service profiles for those using the devices. That is, after all, their business.

For a while, this could coexist with us screwing around with a real-life tricorder. At some point, though, the free stuff turned into a revenue opportunity that had to be exploited. And so, it will be.

2h agoHN ↗

Any discussion about this is shut down. I just read an article https://www.bbc.com/news/articles/ckqxvy98x578o In the UK according to the BBC, politicians are pressing Samsung and apple to make stolen phones bricks. Samsung in response said that they have implemented several security features for this purpose. I think Samsung considers removing OEM unlocking a security feature according to the bootloader unlock hall of shame.

Intel used to do the same with their anti theft technology aka Intel theft deterrent on their classmate PCs, so students had to enter unlock codes from an IT admin every 3 months or every say 200 boots to prevent the computer from being locked at the bios level preventing it from booting an OS, and there was an update which disabled that functionality permanently. And you would be warned when you had around 50 boots left to get the unlock code.

2h agoHN ↗

Making the bootloaders unlockable is a good thing.

2h agoHN ↗

I think OP misspoke. He probably meant that they're not able to be unlocked by the consumers, usually.

2h agoHN ↗

No, everyone knew what they were getting into with Android. It wasn't taken lightly by the power users of the time either. I still have a phone somewhere with Ubuntu Touch on it. I really was hoping that would be my phone OS by now. Not that Canonical isn't capable of similar, but that it would bring about acceptance of Linux phones.

I think we're all more surprised by how long it took for Google to make these bad moves. For a period of time in the 2010s we actually started thinking maybe Google was alright.

2h agoHN ↗

It wasn't Canonical's limitation. Mozilla can confirm: the barriers to enter the phone manufacturing market are immense. Samsung, Ericsson, Sony, LG, etc, all had solid control of the deals with the network operators worldwide. It's a highly regulated market, you can't get in without Verizon, att, Vodafone etc to let you in. Canonical, Open Moko, Mozilla... Didn't have the strength to push through. Google and Apple did.

1h agoHN ↗

It's operators that have grips on manufacturers. Phone OEMs don't make any without the sales networks and financing structures of cellular carriers.

This is to extent that some carriers still insist that they design phones and phone manufacturers are just factories. People need to understand that power dynamic before blaming those "mere factories" for not making Linux phones.

There has to be like an SVP of SoandSo Wireless pushing like three pillar approach of iOS, Android and Linux. Otherwise the pitch decks for any alternative phones just go straight to trash(or into a motorized shredder if it is still physical).

2h agoHN ↗

Phone manufacturers had Symbian which became open source

3h agoHN ↗

Google is also seriously dropping the ball in terms of security. The CVE-2026-43499 root LPE (aka ghostlock) is still unpatched across all Pixel devices, on the latest """security""" update, despite weaponized exploits being public for months.

2h agoHN ↗

Try https://github.com/alex193a/Root-My-Pixel, worked on my 9a as of a few days ago (the version table in the readme is stale). I haven't checked the September update yet though (installing it now, to check).

Edit: September update for 8a has a kernel build from July. I believe it's still vulnerable but the exploit will need its offsets adjusting etc.

2h agoHN ↗

There's "dropping the ball" and then there's "not reaching out your glove to catch it to begin with".

It'd be interesting to see which one is happening here.

2h agoHN ↗

Pixels used to have far better updates than any other Android devices but they stopped improving it years ago. It should have kept improving because it's not at all adequate. They need to be able to release OS updates more than once per month and it shouldn't take months for patches to make it into the OS. It currently takes them at least around 2 months to get even the most urgent patches into the OS. They could fix emergency calls being broken if the patch was made around 3 weeks before an OS release, but that's about as quick as they can go. It's not at all adequate for security and is a complete joke compared to Chromium's release cycle. They can get an emergency Chrome update released within a couple days. They should at least be able to do it for the Pixel OS in a week.

GrapheneOS is often around 4 to 6 months ahead on merging Linux kernel LTS releases. We used to handle this ourselves but switched to the Android GKI LTS branch maintained by Greg KH. Unfortunately, it was often struggling to keep up even before the absolutely massive increase in Linux kernel security patches this year. AI models have rapidly accelerated vulnerability discovery and it's an ongoing crisis for the Linux kernel. We want to be on the latest LTS revision within days and want to be using the latest LTS branch within months of it being released. We're not at all happy with how Android is handling things and plan to fix that ourselves. We'll get things back to how they should be.

We also ship all the AOSP userspace patches months before Pixels due to shipping all of the security preview patches as soon as possible. There are sometimes minor regressions but we find and fix them ourselves downstream. The security preview system has a terrible design especially considering that frontier AI models can reverse engineer the patches. There should at least only be a source embargo for around 24 to 72 hours rather than pretending as if it can work with the patches available 2 to 6 months in advance.

1h agoHN ↗

I'd love to use GrapheneOS on less secure devices, just for the sake of Google autonomy rather than privacy.

1h agoHN ↗

GrapheneOS's goal is privacy for the world and that's achieved through secure devices. You can get a phone specifically for GrapheneOS just as you choose a new device when you're buying a new one. Soon there will be two different phone brands which you can install it on. There's already an estimated 500,000 users with Pixel exclusivity.

https://grapheneos.social/@GrapheneOS/117249893761790371

1h agoHN ↗

Same thing here, I use Graphene for the sake of user control. All the security features and hardening of the Pixel phones and of the OS are good to have, but they not the main reason.

1h agoHN ↗

GrapheneOS will be available on Motorola devices meeting all of our requirements for updates and security features in 2027. It will be starting out on a high end flagship and expanding down from there as devices improve to meet our requirements. We aren't going to support devices unable to provide a reasonable level of security.

2h agoHN ↗

The thread states that Google is putting out patches that affect other Android vendors too.

They're not treating GrapheneOS very differently from other vendors, except that Graphene isn't relevant enough to sign a contract with because they don't make phones (or money, really).

Google should be putting out the code and patches like they used to, but the constant badgering of Google on this issue feels off. I don't see anyone complaining that Samsung isn't supporting their security-focused fork enough, or complain that Apple is delaying the bootloader unlock process by a day.

Despite their very worst, selfish intentions, Google is the very best vendor of commercial open source software. While Google's open source project collapses, there's plenty of space for other vendors to step in.

We should bemoan Google's fall from grace, but only because they're on the way to becoming just as bad as every vendor but Librem if they keep this up another decade.

2h agoHN ↗

It's a net loss. Less data and in their view makes development harder.

2h agoHN ↗

Google

Can we just stop saying "Google" as if it's same faceless org? No, it's not Google, one or two asshole execs are behind this policy.

2h agoHN ↗

I hope people remember this when advocating for chromium. Just because it is open source doesn't mean they don't control it. We need to start the long process of hard forking now or turn to alternatives like Firefox as a new foundation.

  > Google simply regrets android being open source.

Android wouldn't be what it is if it wasn't open source. With all the work from outside Google. The same is true chrome.

But they won't learn that on their own. They are breaking the deals. So we move. We force their hand

2h agoHN ↗

So we move. We force their hand

What do you have in mind?

2h agoHN ↗

We need to start the long process of hard forking now or turn to alternatives like Firefox as a new foundation.

1h agoHN ↗

oh yes sure. just like we can shift the population into installing Debian into their machines so we also deter M$ and Apple abuse /s

46m agoHN ↗

It's so much easier to switch browsers than platform/OS. Unless you have an iPhone or iPad.

2h agoHN ↗

Well, it is time to realise that GPL and similar variants, are better in the long term. I like MIT too, but GPL worked so much better for the linux kernel. Google and others abuse the ecosystem of open source contributors here.

2h agoHN ↗

You mean the Linux kernel that the GrapheneOS project has to request every update for and then has to wait up to weeks to get a Google Drive link?

The GPL is worth nothing if nobody is enforcing it aggressively.

1h agoHN ↗

The GPL is the only reason they even get that. More enforcement would certainly be good, but it's not like the GPL is worthless without a legal team backing you up.

1h agoHN ↗

Could you quote the part of the GPL that they're not adhering to (which you seem to be implying), in this situation?

1h agoHN ↗

They have their own problems. They may be "open source", but they don't accept contributions. I'm skeptical it will ever become more than a hobby project.

56m agoHN ↗

Is not accepting contributions the only/biggest issue you have with the project? I'm honestly becoming more and more okay with the "cathedral" style of open source. Depending on the project, catering to "the community" can lead a loss of focus, lack of a cohesive "vision" or scope, and just generally trying to be everything to everyone without the resources to maintain a giant beast.

With something like a browser (engine), I'm totally okay with someone saying "I'm an expert and I'm trying something with my own vision/priorities. I don't want input from random people that I have to spend time evaluating."

1h agoHN ↗

I'm reading your comment on Firefox. You can probably read mine and write a reply on it too!

2h agoHN ↗

LOL "start" using Firefox. I've been using Firefox for half a decade. There's zero I miss about Chrome.

1h agoHN ↗

LOL half a decade.

I've been using it for more than 20 years.

I don't know why either of use loled though

1h agoHN ↗

LOL, I've been using it since Netscape Navigator 3.0 Gold, via Mozilla M3 (SeaMonkey tech preview), Phoenix, Firebird, and then finally Firefox :D

1h agoHN ↗

Me too. Too bad I had to abandon it because Mozilla seem more focused on making AI-nonsense than a browser nowadays. No, Firefox, you don’t need AI features. You do need a better UI. You do need smoother scrolling. You do need privacy focus (which automatically means you do not need AI features). You do need to feel like you belong on the platform you’re installed on and not wish everything were Linux. You do need better designers that understand UX is not just “add controls everywhere”.

16m agoHN ↗

Huh? What ai features? Firefox seems largely the same as it did a few years ago.

I’m not doubting they added some ai junk somewhere. But whatever they did seems very easy to ignore.

1h agoHN ↗

I've been using it since the time it was called Netscape Navigator. Just sayin'

1h agoHN ↗

Loved netscape navigator! That entire suite with mail, website builder (composer?)

1h agoHN ↗

Some of us have been using it for two decades more or less.

1h agoHN ↗

Hard forking doesn't solve the problem of closed source.

If the goal of a hard fork is "the community will invest equal resources that Google does today" then you wildly underestimate how many engineers work on Chrome.

1h agoHN ↗

But the open source project wouldn’t need to invest as much as Google does. There are all kinds of features and things they are working on that the general public really does not care about.

11m agoHN ↗

but perhaps we dont need several gigabytes compressed code to have a browser. perhaps what google have been doing is an utter abomination?

1h agoHN ↗

But they won't learn that on their own

I think they're fully aware of this. They just don't care, because the goal of "get market share super high" has been reached, so now they have no need for it to continue being open.

I don't disagree about what that means we should do; I just don't think we should assume they're being naive here. It's like writing a program to play chess; you should select your move assuming the opponent is smart and will make the optimal counterplay rather than assuming weakness, and then if they end up being less smart than that, you're still in a good place.

1h agoHN ↗

The “we” in your post is interesting to me. Who do you mean? Individuals?

1h agoHN ↗

or turn to alternatives like Firefox as a new foundation.

With the way Firefox is heading, that might not be the best idea. Nowadays Mozilla seem more focused on riding the AI-hype wave than actually making an excellent browser people want to actually use.

1h agoHN ↗

It's not really a "both sides" thing given the scale difference between what Google is up to and that.

1h agoHN ↗

No one is forcing Mozilla’s hand (afaik) and no one is actually thinking “if Firefox had a chatbot that might convince me to move over”. Youre right that it is not a “both sides” thing, its a “Mozilla thing”. Through and through.

47m agoHN ↗

It is sad to see Firefox riding various hype trains over the years, but I can't really blame them. Miss the wrong train, and you fall behind and may not be able to catch up. Miss the train to nowhere, and you are only wasting resources.

As for the excellent browser that people want, that raises the question of what people want. There are likely as many answers as people.

34m agoHN ↗

Yeah. It’s a tough balance to achieve but that’s the situation we’re in right now so Mozilla really ought to step up (and I totally wish they would).

My biggest pain point at the moment (entirely subjective mind you) is not even the AI nonsense, but how disjointed and alien the Firefox UX and general feel is to Apple platforms (what I use, at the moment). I don’t want Firefox to mirror Safari 1:1 but I do want the Firefox UI and UX to feel polished, well thought out and thoroughly in line with system HIG specs—given that I spend a lot of time in a browser, it shouldn’t feel like a stranger in a strange land amidst my other desktop applications.

Aggressive UI improvements would go a long way to restore some faith in the incandescent fox‘ mission—at least for me.

22m agoHN ↗

What aspects feel foreign on macOS? The Firefox preferences for sure. Anything else?

23m agoHN ↗

Mozilla definitely wastes a bunch of money building features I don’t want. But underneath it all, Firefox is still an excellent web browser. You just occasionally have to disable “pocket” or “gadgets” or something.

45m agoHN ↗

Android wouldn't be what it is if it wasn't open source.

Yes, and now that they've achieved market saturation, it's time to pull up the ladder.

Thanks for all the free work, suckers!

31m agoHN ↗

It's sad we lost ChromeOS. They got Linux, they got open source, they didn't make so so so many unforced errors.

Now that the chromebooks are also Android, it feels like the slide is only going to grow ever more fearsome.

2h agoHN ↗

And don't forget about Manifest V2/uBlock Origin removal!

1h agoHN ↗

Agree. The only time a company does something in the public interest is when it believes doing so would ultimately benefit the shareholders. Everything is a business decision.

3h agoHN ↗

Does anyone contribute to AOSP besides Google? Does Google actually accept any patches into "upstream" and ultimately into their own commercial distro?

3h agoHN ↗

The phrasing of your first question is ironic given GrapheneOS has upstreamed a ton of their security hardening.

You're probably asking if they're able contribute anymore?

2h agoHN ↗

Can you link to patches or commits they upstteamed? I'm not aware Google ever accepted any.

2h agoHN ↗

quite a few manufacturers do, specifically in the automotive sphere and ofc samsung etc.

in terms of accepting, unless it's stuff like bugfixes to core mechanisms, not really.

3h agoHN ↗

Many developers will likely be developing at Android 16 APIs only. Will rely on Aptoide+AOSP exclusively. This is likely the timeline we'll see a decline in Play Store and Pixel usage.

2h agoHN ↗

You vastly overestimate how many people care (developers included) outside of FOSS and HN circles.

Nothing will happen, as it never does.

2h agoHN ↗

Pixel market share is and always has been absolutely tiny, and the people that care about this are a rounding error.

2h agoHN ↗

QPR1 and QPR3 are now Pixel exclusive since Android 16. That means the new APIs for app developers added in Android 17 QPR1 are Pixel exclusive until Android 17 QPR2. There hasn't been a case of new APIs for apps not being open source or not being available to every OEM since Android Honeycomb (3.x).

1h agoHN ↗

Seems like that's anti-competitive behavior, holding back security updates except for Google's own stock users.

https://grapheneos.social/@GrapheneOS/117282190165630051

It would be interesting to know if Google's legal team is aware they're giving Pixels months of early access to new Android features and bug fixes including certain important security patches. Pixels being given this competitive edge over Google's OEM partners is very dubious.

2h agoHN ↗

  No, these are standard Android APIs included since Android 17 QPR1. These will be available through AOSP and other OEMs via Android 17 QPR2 in December 2026. It's currently exclusive to Pixels because it was released as part of Android 17 QPR1 since QPR1 and QPR3 releases are now Pixel exclusive since Android 16.
  This is simply the first time they've added APIs in a QPR1 or QPR3 release following no longer releasing QPR1 and QPR3 to AOSP after the release of Android 16.
2h agoHN ↗

This is confirming my belies that Google is trying to block OEMs that don't pay them to be part of GMS, with the goal of eventually being the only android phone maker.

2h agoHN ↗

If you mean GNU/Linux phones, they already exist and can be used as daily drivers by technical people. Sent from my Librem 5.

2h agoHN ↗

Yes, but a popular one that's usable by regular people and with a very wealthy organization behind it.

2h agoHN ↗

This can be achieved if more people support the effort. If you expect megacorps to offer you a device respecting your freedom, think again.

2h agoHN ↗

They exist but they need more polish and support from device vendors to be a viable alternative to the duopoly. It should be just as easy for the average phone buyer to get and use a 'Linux phone' as it is to get an Android or fruit phone. This is more or less true now for Linux distributions no matter what the naysayers keep on repeating, the next step is to make it true for mobile devices. There will still be naysayers but... who cares? Let them listen to themselves in their echo chambers like they've been doing w.r.t. 'Linux on the desktop'.

2h agoHN ↗

Fine, whatever but no Android 17-derived Google-free AOSP distribution for me if these APIs are in any way essential to the functioning of the device or required by one or more of the government/bank-mandated applications which are sometimes needed. If they are in any way related to some Google service I don't care since I don't use those anyway.

2h agoHN ↗

I'm on GrapheneOS and I will never go back to Google Android or iOS. The amount of control you get is just liberating. I hope Google doesn't crush them.

2h agoHN ↗

I get the sense Android is going the way of MacOS and Darwin. At some point Google will release something non-free end users experience as an absolutely integral part of OS, and it won't be possible to continue as an equivalent alternative. AOSP will still be free and underlying the whole thing, but slowly rot away as anything more than a code base.

2h agoHN ↗

I'm going to guess that google is afraid of the age of AI, they should be, those API's will be reverse engineered pretty quick. Lots of bad actors will using AI.

We live in a time, if you want to build an android app, you easily can, but installing will be harder due to google concerns.

2h agoHN ↗

Alright AI maximalists, what's the estimated token budget to remove the Google dependency?

GrapheneOS has the bootable AOSP and will have Google-alternative device support.

We probably need an equivalent to Play Services, app signing/porting/publishing tools.

With these in hand could we talk Valve into providing the scalable alternative to the play store?

2h agoHN ↗

A lot. But I don't think you can do it with just tokens. Android without the Play store and Google Play Services is just not very useful (in the West anyway).

2h agoHN ↗

The token budget isn't to remove Google it's to create drivers for individual phone hardware, which phone and chip manufacturers keep closed source. Also it would be used to find exploits to unlock permanently locked bootloaders

2h agoHN ↗

What's the token budget to build a new phone OS?

2h agoHN ↗

GrapheneOS accepts donations and, to my knowledge, they spend it in hiring full time engineers.

They have replacement portions for Play Services already (attestation, an app store, and location), but it'd be interesting if they also offered something for push notifications.

If you have it to give you can spend your budget on a donation and fund the effort directly.

1h agoHN ↗

Buy HarmonyOS device. No google jumk, android compatible os, fdroid works, years of security updates from maker, and 40% lower price.

As a personal device it works pretty well. For ssh terminal and reading markdown, it has by far best display.

1h agoHN ↗

HarmonyOS kernel (HongMeng) is not only closed source but also encrypted. Those devices do not allow you to unlock the bootloader or install apps not signed by them (albeit I don't know how that works for emulator apps, a signed Android emulator could possibly allow arbitrary apks).

Huawei made a big mistake by not fully open sourcing HarmonyOS, you can't flash OpenHarmony so it doesn't count.

1h agoHN ↗

That's Huawei's Android fork, right? Is it available on devices outside of China? I'm not seeing an obvious place to buy a device running it.

1h agoHN ↗

I think it started like this, but it no longer is the case.

I feel like Huawei missed a gigantic opportunity there: forking AOSP may have gotten them traction. I would totally buy a Huawei device if it could run GrapheneOS, and I wouldn't mind if GrapheneOS was based on Huawei's fork rather than Google's.

1h agoHN ↗

LOL an OS controlled by the Chinese government?

48m agoHN ↗

As long as it's OSS, you could always fork it back l.

43m agoHN ↗

If only Graphene had a better marketing team. It pains me to say this but it is the absolute truth: the public does not know Graphene and does not care about Graphene. Even it’s name is absolutely awful. This is like the Linux distro hell: “you should use BingaBoingoKonohaOS_v34 or Peppermint_Cinn4monR0ll with the OutOfThisWorld DE, but steer clear of the Pancake package manager, use openMsPacMan with GrassFaceWhazzit frontend instead.” How is anyone (as in not us, the tech nerds) supposed to reason about this?

Things will keep as is for as long as they keep making these OSs FOR the tech nerds.

2h agoHN ↗

So...if you vibe code API shims Google can't sue your right? It would be clean room implementation by definition.

1h agoHN ↗

Ah that's great news! Do you know how to force an upgrade?

1h agoHN ↗

It's in the alpha channel for now, you have to join the alpha channel to get it immediately (at your risk).

2h agoHN ↗

Someone please make a linux-based, using proper cgroups/containers for app isolation, where programs are one of: regular JVM ByteCode, or WASM. APIs follow a JEP-style Process with multiple incubators until we got it right.

2h agoHN ↗

So, the real thing that's happening here is:

* Google drop "real" Android source-code updates to OEMs _and_ the public every half.

* But they ship four Pixel updates, including documentation + SDKs.

* Now they added new APIs in a Pixel-only update.

* Google also drop security update backports to "trusted" OEMs monthly (which GrapheneOS have had access to for years).

So, there are now Pixel-exclusive app features on the Pixel SDK version which isn't available to OEMs - but, it's highly unlikely any app developer would actually depend on these new APIs, since Pixel marketshare is tiny to begin with. This in essence just makes Pixels a weird beta-testing device for what will come out a quarter later to "normal" devices, which is sort of an odd business decision, but also a weird thing to get really mad about, in my opinion (I do see what GrapheneOS are trying to do, with having OEMs saber-rattle about not getting features on the same cadence as Pixels, it just doesn't resonate very loudly for me).

However, the API headline seems to bury a deeper lede; in the thread, GrapheneOS also claim that the quarterly Pixel releases contain security content which is not appearing in the monthly backports. This is quite bad and very sloppy if true, since the Pixel releases can easily be patch-diffed and exploits backed out of them. I'd be interested in seeing this enumerated in more depth.

2h agoHN ↗

I don't really see what the Pixel-only early API releases achieve except for allowing developers to work on Pixels ahead of time, but Pixels are such a small sliver of the universe that it basically just gives Google a leg up, I would assume. And if you're on Graphene why would you care about Google's beta edge apps?

1h agoHN ↗

Exclusive access to QPR1 and QPR3 releases gives Pixels an unfair advantage over other Android OEMs. They get an extra 2 major updates per year. Introducing new APIs for third party app developers as part of these updates means third party apps will now run best on the Pixel OS. Google apps already run best on the Pixel OS due to many exclusive features. It's Google's standard overall approach to propping up parts of their business with their monopolies in other markets. It's not legal.

1h agoHN ↗

I honestly don't think anyone would care. They have a "leg up" for what 3 months every 3 months?

Nobody buys a Pixel because of this minute software advantage.

Maybe get Motorola or Samsung to support security updates for six years and get back to Pixel users.

1h agoHN ↗

Pixel 9a and earlier were officially sold as Android Open Source Project reference devices. Google made a commitment to providing 7 years of updates from launch for 8th/9th gen Pixels. Google then arbitrarily declared they were no longer AOSP reference devices with the release of Android 16 and stopped providing those updates. Many people bought Pixels due to this and it wasn't fulfilled. GrapheneOS has been able to continue support with a massive amount of work including reverse engineering, but other operating systems haven't been as successful and mostly haven't even moved to Android 17 yet or supported 10th gen Pixels.

There are currently around 400k to 600k active Pixels with GrapheneOS. There have been far more than that when including the past devices our users have purchased. Pixels are a small segment of the overall market and that's substantial. If you add in people on other operating systems such as LineageOS then there are even more people using Pixels with another OS. A significant portion of people who bought Pixels did so because they were AOSP reference devices.

Samsung provides 7 years of support with monthly updates for their flagship devices. Unlike the Pixel OS, Samsung ships a lot of the security preview patches early.

Motorola Signature (2026) has 7 years of support. The upcoming successor to it is the first non-Pixel meeting all of the update and hardware security feature requirements for GrapheneOS.

Pixel 11 currently doesn't meet our security requirements due to at least temporary lack of MTE support which may get added in Android 17 QPR2. The upcoming Motorola device is also going to be using a 6.18 kernel at launch rather than 6.12. We would have launched Pixel 11 series support already if they met our security requirements. It's likely they will down the road but it's not clear why they omitted firmware and software support for a major security feature at launch. It's the firmware part which impacts us.

51m agoHN ↗

Many people bought Pixels due to this and it wasn't fulfilled.

Did they though? Or is this just conjecture? Because, honestly, Pixels are not even available worldwide so a few AOSP enthusiasts dropping off and going to Graphene hardly seems concerning for the mighty G.

AOSP reference was a tagline for a few nerds that still wanted the Nexus devices of yore, but it was clear from day one that Google wanted their Pixel phones to be their iPhones.

1h agoHN ↗

The rattling is because of the security patches of course.

35m agoHN ↗

* Google drop "real" Android source-code updates to OEMs _and_ the public every half.

All of the major OEM shave access to the internal source with a _very_ small delay. OEMs don't ship these intermediate releases because they choose not to, not because Google witholds the source for them.

2h agoHN ↗

One can not simply trust Google. While I personally like the MIT licence more, I think it is time that the GPL or variants of it (Affero etc...) get used a lot more. It worked very well with the Linux kernel. Corporations keep on abusing this.

1h agoHN ↗

Google is increasingly locking down Android. I wouldn't be surprised if they killed off AOSP entirely in a few years...

1h agoHN ↗

Forget Android. The future is Plasma Mobile.

1h agoHN ↗

Agreed. Linux is the future, fk Android. GrapheneOS should stop wasting their efforts on Android, when they could've contributed towards PostmarketOS or similar, or even made their own distro. Working on Android is a complete and utter waste of time and effort.

1h agoHN ↗

I wonder how low Google will sink next time.

Respect for the GrapheneOS for pushing through regardless, even if they have to reverse engineer stuff. Can't wait to buy their phone.

45m agoHN ↗

I wonder how low Google will sink next time.

Oh, the possibilities are endless and they're just getting started. Besides stopping releases of AOSP completely they could also mandate that any "certified" Android device should not allow bootloader unlocking (albeit OEMs will disallow that anyway)..

31m agoHN ↗

I mean, even if android is/was open source, it was always fastidious to build a de-googled android image for a phone model.

Of course it's not great for their business model. Not to mention, no more trustworthy app distribution.

I don't see the EU really being able to forcing them to de-google android phones.

I am also curious how much those phones would cost, BTW, since the cost calculation to release such an OS would be a bit complicated.

22m agoHN ↗

Worth reminding folks that the EU DMA Act is forcing Google to start unlocking some of their APIs, such as the AI services AI. Right now a bunch of the apis for digital assistants/chat stuff are kind of proprietary, and this is demanding interoperation. August 1, 2027 is the deadline for most of this (but open access to hotword listening capabilities is slated for Aug 1, 2028).

https://digital-markets-act.ec.europa.eu/developer-portal/in...

Side note, that API here is HID. USB HID is so cool. There's so much stuff in this spec! Chargers and batteries can both communicate all kinds of status, which, well, afaik no one does, there's all kinds of sensors. It's this ancient spec that has so much, and weirdly is just so far ahead of where we are. More HID on Android will be great. Wish they'd played with others to make this so though!