this post was submitted on 20 Jul 2026
40 points (95.5% liked)

Android

21974 readers
86 users here now

The new home of /r/Android on Lemmy and the Fediverse!

Android news, reviews, tips, and discussions about rooting, tutorials, and apps.

πŸ”—Universal Link: !android@lemdro.id


πŸ’‘Content Philosophy:

Content which benefits the community (news, rumours, and discussions) is generally allowed and is valued over content which benefits only the individual (technical questions, help buying/selling, rants, self-promotion, etc.) which will be removed if it's in violation of the rules.


Support, technical, or app related questions belong in: !askandroid@lemdro.id

For fresh communities, lemmy apps, and instance updates: !lemdroid@lemdro.id

πŸ’¬Matrix Chat

πŸ’¬Telegram channels / chats

πŸ“°Our communities below


Rules

  1. Stay on topic: All posts should be related to the Android OS or ecosystem.

  2. No support questions, recommendation requests, rants, or bug reports: Posts must benefit the community rather than the individual. Please post to !askandroid@lemdro.id.

  3. Describe images/videos, no memes: Please include a text description when sharing images or videos. Post memes to !androidmemes@lemdro.id.

  4. No self-promotion spam: Active community members can post their apps if they answer any questions in the comments. Please do not post links to your own website, YouTube, blog content, or communities.

  5. No reposts or rehosted content: Share only the original source of an article, unless it's not available in English or requires logging in (like Twitter). Avoid reposting the same topic from other sources.

  6. No editorializing titles: You can add the author or website's name if helpful, but keep article titles unchanged.

  7. No piracy or unverified APKs: Do not share links or direct people to pirated content or unverified APKs, which may contain malicious code.

  8. No unauthorized polls, bots, or giveaways: Do not create polls, use bots, or organize giveaways without first contacting mods for approval.

  9. No offensive or low-effort content: Don't post offensive or unhelpful content. Keep it civil and friendly!

  10. No affiliate links: Posting affiliate links is not allowed.

Quick Links

Our Communities

Lemmy App List

Chat and More


founded 3 years ago
MODERATORS
you are viewing a single comment's thread
view the rest of the comments
[–] Turret3857@infosec.pub 2 points 1 day ago (1 children)

Graphene is only leading in security updates if you choose to run their closed source builds. Otherwise the difference in security updates between open source Graphene, Calyx and Lineage (can't speak to other Roms, have no experience with them) is usually days.

[–] 01189998819991197253@infosec.pub 3 points 1 day ago (1 children)

Closed source builds? Isn't the point of GOS is that it's hardened and OSS?

[–] Turret3857@infosec.pub 3 points 1 day ago (2 children)

Google made changes to the AOSP release cycle last year. This change took AOSP from an open source project where every commit was visible, to more of a source available "here is a tar ball with squished commits so you can't say we violated the license" once every 6 months sort of deal.

Due to those changes, AOSP forks are faced with 2 options. Stay fully FOSS, reverse engineer each tarball drop for figuring out what each new commit was for and adapting that into your codebase, or the Graphene approach of partnering with an OEM (Motorola) to gain access to embargoed AOSP code, and maintaining 2 codebases (Graphene FOSS, and the Graphene embargoed version).

Graphene is trying to maintain their security goals even if it means the end user can not completely compile the most secure version of their OS on their hardware.

Lineage, Calyx, and Lineage forks l4mg, /e/OS and iodeOS are (whether by choice or by the fact collaborating with an OEM is a difficult pain in the ass) taking the first route.

You can use GrapheneOS's open source update channel, but you miss out on some security updates.

Ive always felt every android fork has its place, just the same way every linux distro does. They all serve a different purpose.

[–] 01189998819991197253@infosec.pub 2 points 12 hours ago (1 children)

Source available still allows them to vett the code, but just not know how Google got there, so not closed source, but not truly open. Did I understand correctly?

[–] Turret3857@infosec.pub 1 points 10 hours ago

Yeah thats pretty much the gist of it

[–] nebulahhh@lemmy.blahaj.zone 0 points 21 hours ago (1 children)

How do you get the closed source varient? I have never seen anything about this from graphene

[–] Turret3857@infosec.pub 1 points 19 hours ago* (last edited 19 hours ago) (1 children)

https://discuss.grapheneos.org/d/27068-grapheneos-security-preview-releases

It should've asked you if you wanted to switch update channels a few months back.

[–] nebulahhh@lemmy.blahaj.zone 1 points 5 hours ago

Thanks I wasn't aware of this