19 comments

  • wps 54 minutes ago
    The amount of roadblocks Google is putting up for GrapheneOS is just ridiculous. None of their decisions make any sense, from the delayed source patches upstream, to the embargos, attestation issues, etc. Google simply regrets android being open source.
    • godelski 7 minutes ago
      I hope people remember this when advocating for chromium. Just because it is open source doesn't mean they don't control it. We need to start the long process of hard forking now or turn to alternatives like Firefox as a new foundation.

        > Google simply regrets android being open source.
      
      Android wouldn't be what it is if it wasn't open source. With all the work from outside Google. The same is true chrome.

      But they won't learn that on their own. They are breaking the deals. So we move. We force their hand

      • nomel 5 minutes ago
        > So we move. We force their hand

        What do you have in mind?

        • PaulCarrack 2 minutes ago
          > We need to start the long process of hard forking now or turn to alternatives like Firefox as a new foundation.
    • 7734128 45 minutes ago
      It's not a regret. Android would never have been popular in the first place if it had not been open source. If phone makers had been able to anticipate how much the demons at Google would be able to lock down the Android then they would never had used the OS back in ~2009.
      • alightsoul 2 minutes ago
        Phone manufacturers had Symbian which became open source
      • mrpippy 39 minutes ago
        That’s possible (never underestimate the bad decision-making of phone makers), but what would they have done instead? Windows Mobile 6 was the only licensable alternative, but it was a known quantity and obviously a generation behind Android and iOS.
        • edent 4 minutes ago
          Symbian and LiMo were both available at the time. It is hard to say they were good alternatives though. Windows 7 - even with the weight of Microsoft behind it - wasn't able to attract enough hardware manufacturers.
        • SoftTalker 16 minutes ago
          Windows Phone was pretty nice, too bad Microsoft didn't follow their DOS and Windows strategy of getting it preinstalled on every consumer PC sold. There was really only the Nokia Lumia line that I recall, but everyone I knew who had one loved it.
        • LTL_FTC 11 minutes ago
          WebOS was pretty cool (Palm). But I’m not sure if Palm would have licensed it. Lg ended up with it.
        • pmlnr 34 minutes ago
          Maemo.
          • michaelmior 30 minutes ago
            I remember using a Maemo device circa 2009. I recall overall really liking the OS.
        • thomasahle 27 minutes ago
          Also Bada
      • thevillagechief 36 minutes ago
        I don't think this is actually true. Phone makers seem happy to have the platform locked down even further. They're putting even more roadblocks, as evidenced by most of them making bootloaders unlockable.
        • ardacinar 27 minutes ago
          They're happy that it is locked down. They're not happy that they're not the ones doing the locking down.
        • lenerdenator 18 minutes ago
          This is what lots of people forget.

          Android is not a Linux desktop or server distro. It is not about you getting to put what you want on the hardware you bought for free.

          Operating systems are hellaciously expensive to maintain and that only gets worse in markets with rapid hardware improvements, as the smartphone market was up until maybe the late 2010s. Google is not a charity. SV did not come into national prominence for making investors $0. There is no money in giving maybe one in one-hundred smartphone users (and that's being generous) a bunch of code, for free, so that they can put it on their gizmo and talk to their nerd friends at their hacker meetup.

          When they pitched Android as "open", they meant that carriers and device makers could load it up with all of the revenue-enhancing bloat that they wanted. In return, Google got a device that would let them hoover up all of the data they could ever want in order to build better ad service profiles for those using the devices. That is, after all, their business.

          For a while, this could coexist with us screwing around with a real-life tricorder. At some point, though, the free stuff turned into a revenue opportunity that had to be exploited. And so, it will be.

      • sublinear 30 minutes ago
        No, everyone knew what they were getting into with Android. It wasn't taken lightly by the power users of the time either. I still have a phone somewhere with Ubuntu Touch on it. I really was hoping that would be my phone OS by now. Not that Canonical isn't capable of similar, but that it would bring about acceptance of Linux phones.

        I think we're all more surprised by how long it took for Google to make these bad moves. For a period of time in the 2010s we actually started thinking maybe Google was alright.

        • reedciccio 9 minutes ago
          It wasn't Canonical's limitation. Mozilla can confirm: the barriers to enter the phone manufacturing market are immense. Samsung, Ericsson, Sony, LG, etc, all had solid control of the deals with the network operators worldwide. It's a highly regulated market, you can't get in without Verizon, att, Vodafone etc to let you in. Canonical, Open Moko, Mozilla... Didn't have the strength to push through. Google and Apple did.
    • Retr0id 41 minutes ago
      Google is also seriously dropping the ball in terms of security. The CVE-2026-43499 root LPE (aka ghostlock) is still unpatched across all Pixel devices, on the latest """security""" update, despite weaponized exploits being public for months.
      • grapheneos 6 minutes ago
        Pixels used to have far better updates than any other Android devices but they stopped improving it years ago. It should have kept improving because it's not at all adequate. They need to be able to release OS updates more than once per month and it shouldn't take months for patches to make it into the OS. It currently takes them at least around 2 months to get even the most urgent patches into the OS. They could fix emergency calls being broken if the patch was made around 3 weeks before an OS release, but that's about as quick as they can go. It's not at all adequate for security and is a complete joke compared to Chromium's release cycle. They can get an emergency Chrome update released within a couple days. They should at least be able to do it for the Pixel OS in a week.

        GrapheneOS is often around 4 to 6 months ahead on merging Linux kernel LTS releases. We used to handle this ourselves but switched to the Android GKI LTS branch maintained by Greg KH. Unfortunately, it was often struggling to keep up even before the absolutely massive increase in Linux kernel security patches this year. AI models have rapidly accelerated vulnerability discovery and it's an ongoing crisis for the Linux kernel. We want to be on the latest LTS revision within days and want to be using the latest LTS branch within months of it being released. We're not at all happy with how Android is handling things and plan to fix that ourselves. We'll get things back to how they should be.

        We also ship all the AOSP userspace patches months before Pixels due to shipping all of the security preview patches as soon as possible. There are sometimes minor regressions but we find and fix them ourselves downstream. The security preview system has a terrible design especially considering that frontier AI models can reverse engineer the patches. There should at least only be a source embargo for around 24 to 72 hours rather than pretending as if it can work with the patches available 2 to 6 months in advance.

      • jeroenhd 29 minutes ago
        I just ran https://github.com/CakesTwix/Android-CVE-2026-43499 on my Pixel 9 Pro and it seems to have been patched. I did get a system update not long ago, though.
      • lenerdenator 28 minutes ago
        There's "dropping the ball" and then there's "not reaching out your glove to catch it to begin with".

        It'd be interesting to see which one is happening here.

    • jeroenhd 22 minutes ago
      The thread states that Google is putting out patches that affect other Android vendors too.

      They're not treating GrapheneOS very differently from other vendors, except that Graphene isn't relevant enough to sign a contract with because they don't make phones (or money, really).

      Google should be putting out the code and patches like they used to, but the constant badgering of Google on this issue feels off. I don't see anyone complaining that Samsung isn't supporting their security-focused fork enough, or complain that Apple is delaying the bootloader unlock process by a day.

      Despite their very worst, selfish intentions, Google is the very best vendor of commercial open source software. While Google's open source project collapses, there's plenty of space for other vendors to step in.

      We should bemoan Google's fall from grace, but only because they're on the way to becoming just as bad as every vendor but Librem if they keep this up another decade.

    • monomania 49 minutes ago
      There's a non-zero chance that three-letter agencies are lobbying for at least some of this.
    • alightsoul 18 minutes ago
      It's a net loss. Less data and in their view makes development harder.
    • curiousgal 9 minutes ago
      > Google

      Can we just stop saying "Google" as if it's same faceless org? No, it's not Google, one or two asshole execs are behind this policy.

    • bebeirjd848r 46 minutes ago
      GrapheneOS does not even register on Google scale! It does not even manufacture its own devices!

      Bigger problem is HarmonyOS and similar devices, compatible with Android. Opensource threat from china!

      And no NSA backdoors or honeypots!

      • subscribed 30 minutes ago
        If the hardware security is on par with iPhone / pixel 8+, then sure.

        Otherwise there's no need for NSA backdoors (as Cellebrite matrix shows) :)

      • ChickeNES 24 minutes ago
        Sure, let's just trade the NSA for the CCP, no issues there.
        • anonym29 4 minutes ago
          One poses an active, unchecked threat to the constitutional rights of US citizens, has a chartered mission to subvert and undermine the very field of cryptography itself - going so far as to bribe standards bodies to adopt backdoored algorithms (using taxpayer funds to do so), has plotted to mass-violate the constitutional rights of their own citizens and lie about it to the national legislature (which they carried out successfully, committing perjury in the process and facing zero consequences for it), secretly cooperates with the criminal justice system via parallel construction to target nonviolent, law-abiding political activists with fabricated criminal charges as retaliation for politically disfavored speech, while the other is about 6500 miles away, has negligible presence in / reach into the US, and is generally unconcerned with the domestic political activities of US citizens.
  • largbae 16 minutes ago
    Alright AI maximalists, what's the estimated token budget to remove the Google dependency?

    GrapheneOS has the bootable AOSP and will have Google-alternative device support.

    We probably need an equivalent to Play Services, app signing/porting/publishing tools.

    With these in hand could we talk Valve into providing the scalable alternative to the play store?

    • IshKebab 4 minutes ago
      A lot. But I don't think you can do it with just tokens. Android without the Play store and Google Play Services is just not very useful (in the West anyway).
    • z3ratul163071 6 minutes ago
      exactly
  • bri3d 6 minutes ago
    So, the real thing that's happening here is:

    * Google drop "real" Android source-code updates to OEMs _and_ the public every half.

    * But they ship four Pixel updates, including documentation + SDKs.

    * Now they added new APIs in a Pixel-only update.

    * Google also drop security update backports to "trusted" OEMs monthly (which GrapheneOS have had access to for years).

    So, there are now Pixel-exclusive app features on the Pixel SDK version which isn't available to OEMs - but, it's highly unlikely any app developer would actually depend on these new APIs, since Pixel marketshare is tiny to begin with. This in essence just makes Pixels a weird beta-testing device for what will come out a quarter later to "normal" devices, which is sort of an odd business decision, but also a weird thing to get really mad about, in my opinion (I do see what GrapheneOS are trying to do, with having OEMs saber-rattle about not getting features on the same cadence as Pixels, it just doesn't resonate very loudly for me).

    However, the API headline seems to bury a deeper lede; in the thread, GrapheneOS also claim that the quarterly Pixel releases contain security content which is not appearing in the monthly backports. This is quite bad and very sloppy if true, since the Pixel releases can easily be patch-diffed and exploits backed out of them. I'd be interested in seeing this enumerated in more depth.

  • Ajedi32 40 minutes ago
    Important details further down: https://grapheneos.social/@GrapheneOS/117282129725629495

    So it seems like the problem isn't that the new API is Pixel exclusive, but that the first and third quarterly release patches each year are Pixel exclusive?

    • Insimwytim 21 minutes ago

        No, these are standard Android APIs included since Android 17 QPR1. These will be available through AOSP and other OEMs via Android 17 QPR2 in December 2026. It's currently exclusive to Pixels because it was released as part of Android 17 QPR1 since QPR1 and QPR3 releases are now Pixel exclusive since Android 16.
        This is simply the first time they've added APIs in a QPR1 or QPR3 release following no longer releasing QPR1 and QPR3 to AOSP after the release of Android 16.
    • grapheneos 28 minutes ago
      QPR1 and QPR3 are now Pixel exclusive since Android 16. That means the new APIs for app developers added in Android 17 QPR1 are Pixel exclusive until Android 17 QPR2. There hasn't been a case of new APIs for apps not being open source or not being available to every OEM since Android Honeycomb (3.x).
  • Velocifyer 35 minutes ago
    This is confirming my belies that Google is trying to block OEMs that don't pay them to be part of GMS, with the goal of eventually being the only android phone maker.
  • natterangell 20 minutes ago
    I get the sense Android is going the way of MacOS and Darwin. At some point Google will release something non-free end users experience as an absolutely integral part of OS, and it won't be possible to continue as an equivalent alternative. AOSP will still be free and underlying the whole thing, but slowly rot away as anything more than a code base.
  • teekert 10 minutes ago
    Installed GrapheneOS on my Pixel 10 yesterday, only used the stock rom to start the installer... Am feeling a little unconfortable due to this situation: [0]. Hope this gets better. Really feeling the dislike for Google on this one.

    [0]: https://news.ycombinator.com/item?id=49741510

  • exabrial 10 minutes ago
    Someone please make a linux-based, using proper cgroups/containers for app isolation, where programs are one of: regular JVM ByteCode, or WASM. APIs follow a JEP-style Process with multiple incubators until we got it right.
  • shevy-java 0 minutes ago
    One can not simply trust Google. While I personally like the MIT licence more, I think it is time that the GPL or variants of it (Affero etc...) get used a lot more. It worked very well with the Linux kernel. Corporations keep on abusing this.
  • petcat 47 minutes ago
    Does anyone contribute to AOSP besides Google? Does Google actually accept any patches into "upstream" and ultimately into their own commercial distro?
    • nzeid 40 minutes ago
      The phrasing of your first question is ironic given GrapheneOS has upstreamed a ton of their security hardening.

      You're probably asking if they're able contribute anymore?

      • izacus 15 minutes ago
        Can you link to patches or commits they upstteamed? I'm not aware Google ever accepted any.
  • IronWolve 20 minutes ago
    I'm going to guess that google is afraid of the age of AI, they should be, those API's will be reverse engineered pretty quick. Lots of bad actors will using AI.

    We live in a time, if you want to build an android app, you easily can, but installing will be harder due to google concerns.

  • xnx 33 minutes ago
    The world needs a Steam Phone.
    • fsflover 26 minutes ago
      If you mean GNU/Linux phones, they already exist and can be used as daily drivers by technical people. Sent from my Librem 5.
      • xnx 23 minutes ago
        Yes, but a popular one that's usable by regular people and with a very wealthy organization behind it.
        • fsflover 17 minutes ago
          This can be achieved if more people support the effort. If you expect megacorps to offer you a device respecting your freedom, think again.
        • lanfeust6 18 minutes ago
          I miss my blackberry
      • hagbard_c 19 minutes ago
        They exist but they need more polish and support from device vendors to be a viable alternative to the duopoly. It should be just as easy for the average phone buyer to get and use a 'Linux phone' as it is to get an Android or fruit phone. This is more or less true now for Linux distributions no matter what the naysayers keep on repeating, the next step is to make it true for mobile devices. There will still be naysayers but... who cares? Let them listen to themselves in their echo chambers like they've been doing w.r.t. 'Linux on the desktop'.
  • vkaku 42 minutes ago
    Many developers will likely be developing at Android 16 APIs only. Will rely on Aptoide+AOSP exclusively. This is likely the timeline we'll see a decline in Play Store and Pixel usage.
    • DaSHacka 29 minutes ago
      You vastly overestimate how many people care (developers included) outside of FOSS and HN circles.

      Nothing will happen, as it never does.

    • tiagod 26 minutes ago
      Pixel market share is and always has been absolutely tiny, and the people that care about this are a rounding error.
  • dingdong2026 0 minutes ago
    Google is a cancer on humanity.
  • barbazoo 24 minutes ago
    I'm on GrapheneOS and I will never go back to Google Android or iOS. The amount of control you get is just liberating. I hope Google doesn't crush them.
  • Onavo 10 minutes ago
    So...if you vibe code API shims Google can't sue your right? It would be clean room implementation by definition.
  • hagbard_c 24 minutes ago
    Fine, whatever but no Android 17-derived Google-free AOSP distribution for me if these APIs are in any way essential to the functioning of the device or required by one or more of the government/bank-mandated applications which are sometimes needed. If they are in any way related to some Google service I don't care since I don't use those anyway.
  • VCFundedGenYer 56 minutes ago
    Android has been so thoroughly disappointing through the years. Started as a great open free form alternative to iOS, to becoming the very thing it sought to combat.
    • josteink 54 minutes ago
      If Android wants to be the inferior not-open-source mobile OS, why would I not just buy an iPhone instead then?

      It’s closed too, sure, but at least it’s more consistent.

      • pimeys 51 minutes ago
        Android has free and open artificial pancreas that is still easy to install and keeps us with complex type 1 diabetes alive.

        Google may just want to kill us and Apple don't even let this kind of software exist without massive hurdles...

      • subscribed 35 minutes ago
        Because it's much worse (for me).

        However at this point, as a GrapheneOS user if I couldn't use it for any reason I'll go to iOS (even though I used it for a couple of years and I've been fed up).

      • add-sub-mul-div 10 minutes ago
        Because (1) you'd be rewarding the entity that originated and normalized the loss of freedom that Google much later adopted, and (2) as Apple restricts more freedoms you'll still be able to enjoy them on Android for a few more years as Google remains (comparatively) more user friendly.
  • ahmd-sh 1 hour ago
    i despise where Google is going with this. it's a duopoly in the smartphone OS space and we need (for lack of a better analogy, spare the technicals) open-source distros like we have with Linux on desktop.

    Graphene is reaching that status for me every day and i'm looking forward to switching to it as my daily driver.

    • pojntfx 55 minutes ago
      GrapheneOS is pretty neat, https://postmarketos.org/ is also pretty damn polished out of the box these days. I'd argue the "mobile desktop Linux systems" are actually a bit more polished than Graphene, esp. when it comes to default apps (no AOSP abandonware dialer, contacts etc. apps to fight with, it's all just maintained, responsive GNOME/KDE apps)
      • spijdar 44 minutes ago
        I want to believe this, but it's hard for me to take this at face value. It's been about 4 years since I've run pmOS, so my experience IS very out of date, but I also have a hard time believing that the experience has radically changed in the meantime.

        The short is that yes the GNOME/KDE apps do often look more impressive, but they suffer the same sort of malaise which seems to have infected Linux desktops sometime since Eternal September, and between the sporadic crashing and "this doesn't feel right", it's really hard for me to accept "It's more polished than AOSP!".

        pmOS's installation page opening with a warning:

           Make sure you read state of postmarketOS before installing postmarketOS. 
        
        Which leads to a page that opens with:

          The goal is to make postmarketOS usable for everyone, but we are not there yet. Usability and most importantly stability issues need to be worked out first. If you are looking for an OS that is as usable as iOS or Android, this project is currently not for you.
        
        Does not do a lot to dissuade my skepticism. I know you said the apps specifically, but even there, it's like... I dunno.
      • cobertos 41 minutes ago
        I tried getting it to run on a Pixel 3a and struggled for hours, eventually gave up (albeit I tried running it with Wayland and Niri which seems less tried-and-true).
        • brnt 25 minutes ago
          I recently installed pmos on two 3a's and it was as simple as a Lineage image. Works well too!
    • aftbit 29 minutes ago
      Graphene has been my daily driver for the past year or so. The only thing I miss is the ability to do contactless payments. Otherwise, it's been awesome. I don't run any games nor do I care about any of the AI features. YMMV.
      • edent 8 minutes ago
        Contactless payments do work on Graphene - but only with the Curve app. It also requires the card-holder to be from the UK or EU.
      • dlahoda 16 minutes ago
        for some people contactless payments are essential for their lifes
        • eppp 11 minutes ago
          That seems a little excessive.
    • austinthetaco 32 minutes ago
      i so desperately wish we were still in the days of manufacturers making their own OS. It's why I moved to iphone: when the hardware company makes the software and vice-versa the integration is much better and less error-prone/bloated. It never made sense to me for android to be shoehorned into thousands of devices, instead of a fork being made and for thorough OS rework to happen to support the device.
    • kenhwang 47 minutes ago
      I just wish Graphene had better support for non-Google hardware.
      • subscribed 40 minutes ago
        They can't due to the shortcomings of the hardware (why develop a hardened os to the grossly insecure hardware) or the vendor (no/slow updates, etc).

        Anyone is free to fork, add the desired hardware support and flash.

        (that's aside of some Moto flagships in 2027)

      • vkaku 41 minutes ago
        Those Razr phone updates need to start landing sooner ....
      • armadyl 45 minutes ago
        More like OEMs need to take security more seriously and add in the capable hardware and commit to firmware updates long term.
        • dessimus 11 minutes ago
          Unless there is a real market advantage to it, they won't. Consumers prove over and over again they are willing to trade security to save a few dollars. Furthermore, why commit to providing hardware and software support for a device to last 5+ years, when ~25% of Americans report damaging their device each year[0]. Most of a device's population will have been replaced in 3 years.

          [0]: https://www.claimsjournal.com/news/national/2024/03/15/32248...

    • b112 45 minutes ago
      If Google doesn't smarten up, it will no longer be in control of Android.

      Oracle was a mighty powerhouse when it bought MySQL, StarOffice, and more. It lost defacto control of all of them, due to its stupidity. In the world of open source, the tighter you hold on, the less likely you'll retain control.

      And yet, here we are, with Google playing games.

      Google, a note: there are far more relying upon Android than you, and now there are forced alternative stores in the mix. If Samsung and everyone else said "sorry Google', or even a large majority, you're out. Gone. Nada.

      They can now fork, and force old Android to have their new fancy pants 'Play' store too.

      Google is also getting more and more pushy with Chrome. What if everyone depending upon that backend, shrugs and says "Sorry Google, we're hard-forking Chrome and we'll all maintain it".

      • murderfs 29 minutes ago
        > If Samsung and everyone else said "sorry Google', or even a large majority, you're out. Gone. Nada.

        The OEMs are incapable of writing a competent operating system, and don't particularly care to.

        > Google is also getting more and more pushy with Chrome. What if everyone depending upon that backend, shrugs and says "Sorry Google, we're hard-forking Chrome and we'll all maintain it".

        With what maintainers?

        https://chrome-commit-tracker.arthursonzogni.com/organizatio...

      • anonzzzies 35 minutes ago
        > Oracle was a mighty powerhouse

        It definitly still is. We run Postgres when we host our banking / financial stuff, but when we talk with banks and say that, they demand Oracle not that 'open source amateur stuff'. We have a version of our software for Oracle (and MSSQL) as well so no biggy, but still, we always try if we know it's not a complete immediate kill (which it will be if we put it in our documentation as only option). Oracle is still everywhere at the big guys.

        • mrlonglong 31 minutes ago
          Are they still forbidding benchmarking the Oracle database in their T&Cs? I laugh. Such litigious losers.

          Postgres ftw. Long may it eat their lunch.

      • tredre3 30 minutes ago
        > it will no longer be in control of Android

        Who will step up to maintain it? Keep in mind that it has to be somebody that every other OEM trust. In other words it would likely have to be an alliance of manufacturers. And they'd inevitably treat OEMs outside the alliance poorly and we'd be back to the current situation, but worse.

      • linuxftw 30 minutes ago
        Google's Android customers are phone OEMs. The major ones seem to like how things are going. Until Samsung and whomever start the OpenHandset Foundation or some such and fork Android, there's never going to be the Mariadb of Android.