â–² 38 â–¼ North Korea's Pixel 8 Pro clone packs 16GB of RAM despite RAMageddon (www.notebookcheck.net) submitted 1 week ago by schizoidman@lemmy.zip to c/android@lemdro.id 33 comments fedilink hide all child comments
[–] 01189998819991197253@infosec.pub 3 points 5 days ago (1 child) Closed source builds? Isn't the point of GOS is that it's hardened and OSS? permalink fedilink source parent hideshow 2 child comments replies: [–] Turret3857@infosec.pub 3 points 5 days ago (2 children) Google made changes to the AOSP release cycle last year. This change took AOSP from an open source project where every commit was visible, to more of a source available "here is a tar ball with squished commits so you can't say we violated the license" once every 6 months sort of deal. Due to those changes, AOSP forks are faced with 2 options. Stay fully FOSS, reverse engineer each tarball drop for figuring out what each new commit was for and adapting that into your codebase, or the Graphene approach of partnering with an OEM (Motorola) to gain access to embargoed AOSP code, and maintaining 2 codebases (Graphene FOSS, and the Graphene embargoed version). Graphene is trying to maintain their security goals even if it means the end user can not completely compile the most secure version of their OS on their hardware. Lineage, Calyx, and Lineage forks l4mg, /e/OS and iodeOS are (whether by choice or by the fact collaborating with an OEM is a difficult pain in the ass) taking the first route. You can use GrapheneOS's open source update channel, but you miss out on some security updates. Ive always felt every android fork has its place, just the same way every linux distro does. They all serve a different purpose. permalink fedilink source parent hideshow 4 child comments replies: [–] 01189998819991197253@infosec.pub 2 points 4 days ago (1 child) Source available still allows them to vett the code, but just not know how Google got there, so not closed source, but not truly open. Did I understand correctly? permalink fedilink source parent hideshow 2 child comments replies: [–] Turret3857@infosec.pub 2 points 4 days ago Yeah thats pretty much the gist of it permalink fedilink source parent [–] nebulahhh@lemmy.blahaj.zone 0 points 5 days ago (1 child) How do you get the closed source varient? I have never seen anything about this from graphene permalink fedilink source parent hideshow 2 child comments replies: [–] Turret3857@infosec.pub 1 point 5 days ago* (1 child) https://discuss.grapheneos.org/d/27068-grapheneos-security-preview-releases It should've asked you if you wanted to switch update channels a few months back. permalink fedilink source parent hideshow 2 child comments replies: [–] nebulahhh@lemmy.blahaj.zone 1 point 4 days ago Thanks I wasn't aware of this permalink fedilink source parent
[–] Turret3857@infosec.pub 3 points 5 days ago (2 children) Google made changes to the AOSP release cycle last year. This change took AOSP from an open source project where every commit was visible, to more of a source available "here is a tar ball with squished commits so you can't say we violated the license" once every 6 months sort of deal. Due to those changes, AOSP forks are faced with 2 options. Stay fully FOSS, reverse engineer each tarball drop for figuring out what each new commit was for and adapting that into your codebase, or the Graphene approach of partnering with an OEM (Motorola) to gain access to embargoed AOSP code, and maintaining 2 codebases (Graphene FOSS, and the Graphene embargoed version). Graphene is trying to maintain their security goals even if it means the end user can not completely compile the most secure version of their OS on their hardware. Lineage, Calyx, and Lineage forks l4mg, /e/OS and iodeOS are (whether by choice or by the fact collaborating with an OEM is a difficult pain in the ass) taking the first route. You can use GrapheneOS's open source update channel, but you miss out on some security updates. Ive always felt every android fork has its place, just the same way every linux distro does. They all serve a different purpose. permalink fedilink source parent hideshow 4 child comments replies: [–] 01189998819991197253@infosec.pub 2 points 4 days ago (1 child) Source available still allows them to vett the code, but just not know how Google got there, so not closed source, but not truly open. Did I understand correctly? permalink fedilink source parent hideshow 2 child comments replies: [–] Turret3857@infosec.pub 2 points 4 days ago Yeah thats pretty much the gist of it permalink fedilink source parent [–] nebulahhh@lemmy.blahaj.zone 0 points 5 days ago (1 child) How do you get the closed source varient? I have never seen anything about this from graphene permalink fedilink source parent hideshow 2 child comments replies: [–] Turret3857@infosec.pub 1 point 5 days ago* (1 child) https://discuss.grapheneos.org/d/27068-grapheneos-security-preview-releases It should've asked you if you wanted to switch update channels a few months back. permalink fedilink source parent hideshow 2 child comments replies: [–] nebulahhh@lemmy.blahaj.zone 1 point 4 days ago Thanks I wasn't aware of this permalink fedilink source parent
[–] 01189998819991197253@infosec.pub 2 points 4 days ago (1 child) Source available still allows them to vett the code, but just not know how Google got there, so not closed source, but not truly open. Did I understand correctly? permalink fedilink source parent hideshow 2 child comments replies: [–] Turret3857@infosec.pub 2 points 4 days ago Yeah thats pretty much the gist of it permalink fedilink source parent
[–] Turret3857@infosec.pub 2 points 4 days ago Yeah thats pretty much the gist of it permalink fedilink source parent
[–] nebulahhh@lemmy.blahaj.zone 0 points 5 days ago (1 child) How do you get the closed source varient? I have never seen anything about this from graphene permalink fedilink source parent hideshow 2 child comments replies: [–] Turret3857@infosec.pub 1 point 5 days ago* (1 child) https://discuss.grapheneos.org/d/27068-grapheneos-security-preview-releases It should've asked you if you wanted to switch update channels a few months back. permalink fedilink source parent hideshow 2 child comments replies: [–] nebulahhh@lemmy.blahaj.zone 1 point 4 days ago Thanks I wasn't aware of this permalink fedilink source parent
[–] Turret3857@infosec.pub 1 point 5 days ago* (1 child) https://discuss.grapheneos.org/d/27068-grapheneos-security-preview-releases It should've asked you if you wanted to switch update channels a few months back. permalink fedilink source parent hideshow 2 child comments replies: [–] nebulahhh@lemmy.blahaj.zone 1 point 4 days ago Thanks I wasn't aware of this permalink fedilink source parent
[–] nebulahhh@lemmy.blahaj.zone 1 point 4 days ago Thanks I wasn't aware of this permalink fedilink source parent