GrapheneOS

Last updated

GrapheneOS
GrapheneOS Logo.svg
GrapheneOS Screenshot.png
GrapheneOS home screen
Developer GrapheneOS team
OS family Android (Linux)
Working stateCurrent
Source model Open source
Initial releaseApril 2019;5 years ago (2019-04)
Latest release 2024022300 [1]   OOjs UI icon edit-ltr-progressive.svg / 23 February 2024
Repository
Marketing targetPrivacy/security-focused smartphones
Update method Over-the-air (OTA) or locally
Package manager APK-based
Kernel type Monolithic (Linux)
License MIT, Apache License, various permissive open-source
Official website grapheneos.org OOjs UI icon edit-ltr-progressive.svg

GrapheneOS (formerly Android Hardening or AndroidHardening) is an Android-based, open source, privacy and security-focused mobile operating system for selected Google Pixel devices, including smartphones, tablets and foldables that is recommended by Edward Snowden.

Contents

History

The main developer, Daniel Micay, originally worked on CopperheadOS, until a schism over software licensing between the co-founders of Copperhead Limited led to Micay's dismissal from the company in 2018. [2] After the incident, Micay continued working on the Android Hardening project, [2] [3] which was renamed as GrapheneOS [3] and announced in April 2019. [2]

According to Damien Wilde of 9to5Google , GrapheneOS released Android 12L for Google Pixel devices before Google did, second to ProtonAOSP. [4] GrapheneOS apps "Secure Camera" and "Secure PDF Viewer" (based on pdf.js) were released to the Google Play Store and GitHub. [5]

Features

GrapheneOS default "Apps" app screen. GrapheneOS "Apps" app.png
GrapheneOS default "Apps" app screen.

As of March 2024, GrapheneOS only officially supports Google Pixel devices. [6] By default Google apps are not installed with GrapheneOS, [6] [7] but users can install a sandboxed version of Google Play Services from the "Apps" app, which is installed with GrapheneOS. [7] The sandboxed Google Play Services allows access to the Google Play Store and apps dependent on it, along with features including push notifications and in-app payments. [7] [8]

GrapheneOS developed a hardened Chromium-based web browser and WebView implementation known as Vanadium. [9]

GrapheneOS introduces revocable network access and sensors permission toggles for each installed app. [6] [9] GrapheneOS also randomizes MAC address per-connection by default, [2] [10] and includes a PIN scrambling option for the lock screen. [11] A hardware-based attestation app known as Auditor is also included. [12]

As of January 2024, Android Auto is now supported, allowing users to install it via the "Apps" app. [13] The Sandboxed Google Play compatibility layer settings adds a new permission menu with 4 toggles for granting the minimal access required for wired Android Auto, wireless Android Auto, audio routing and phone calls. [14]

Reception

In 2019, Georg Pichler of Der Standard , and other news sources, quoted Edward Snowden saying on Twitter, "If I were configuring a smartphone today, I'd use Daniel Micay's GrapheneOS as the base operating system." [15] In discussing why services should not force users to install proprietary apps, Lennart Mühlenmeier of netzpolitik.org suggested GrapheneOS as an alternative to Apple or Google. [16] Svět Mobilně and Webtekno repeated the suggestions that GrapheneOS is a good security- and privacy-oriented replacement for standard Android. [17] [18] In a detailed review of GrapheneOS for Golem.de, Moritz Tremmel and Sebastian Grüner said they were able to use GrapheneOS similarly to other Android systems, while enjoying more freedom from Google, without noticing differences from "additional memory protection, but that's the way it should be." They concluded GrapheneOS cannot change how "Android devices become garbage after three years at the latest", but "it can better secure the devices during their remaining life while protecting privacy." [2]

In June 2021, reviews of GrapheneOS, KaiOS, AliOS, and Tizen OS, were published in Cellular News. The review of GrapheneOS called it "arguably the best mobile operating system in terms of privacy and security." However, they criticized GrapheneOS for its inconvenience to users, saying "GrapheneOS is completely de-Googled and will stay that way forever—at least according to the developers." They also noticed a "slight performance decrease" and said "it might take two full seconds for an app—even if it’s just the Settings app—to fully load." [19]

In March 2022, writing for How-To Geek Joe Fedewa said that Google apps were not included due to concerns over privacy, and GrapheneOS also did not include a default app store. Instead, Fedewa suggested, F-Droid could be used. [6] In a 2022, Jonathan Lamont of MobileSyrup reviewed GrapheneOS installed on a Pixel 3, after one week of use. He called GrapheneOS install process "straightforward" and concluded that he liked GrapheneOS overall, but criticized the post-install as "often not a seamless experience like using an unmodified Pixel or an iPhone", attributing his experience to his "over-reliance on Google apps" and the absence of some "smart" features in GrapheneOS default keyboard and camera apps, in comparison to software from Google. [7] In his initial impressions post a week prior, Lamont said that after an easy install there were issues with permissions for Google's Messages app, and difficulty importing contacts; Lamont then concluded, "Anyone looking for a straightforward experience may want to avoid GrapheneOS or other privacy-oriented Android experiences since the privacy gains often come at the expense of convenience and ease of use." [20] In July 2022, Charlie Osborne of ZDNet suggested that individuals who suspect a Pegasus infection use a secondary device with GrapheneOS for secure communication. [21]

In January 2023, a Swiss startup company, Apostrophy AG, announced AphyOS, which is a subscription fee-based Android operating system and services "built atop" GrapheneOS. [22] [23]

See also

Related Research Articles

<span class="mw-page-title-main">Android 13</span> Thirteenth major version of the Android mobile operating system

Android 13 is the thirteenth major release and the 20th version of Android, the mobile operating system developed by the Open Handset Alliance led by Google. It was released to the public and the Android Open Source Project (AOSP) on August 15, 2022. The first devices to ship with Android 13 were the Pixel 7 and 7 Pro.

Android is a mobile operating system based on a modified version of the Linux kernel and other open-source software, designed primarily for touchscreen mobile devices such as smartphones and tablets. Android is developed by a consortium of developers known as the Open Handset Alliance, though its most widely used version is primarily developed by Google. It was unveiled in November 2007, with the first commercial Android device, the HTC Dream, being launched in September 2008.

A mobile operating system is an operating system used for smartphones, tablets, smartwatches, smartglasses, or other non-laptop personal mobile computing devices. While computers such as typical/mobile laptops are "mobile", the operating systems used on them are generally not considered mobile, as they were originally designed for desktop computers that historically did not have or need specific mobile features. This line distinguishing mobile and other forms has become blurred in recent years, due to the fact that newer devices have become smaller and more mobile unlike hardware of the past. Key notabilities blurring this line are the introduction of tablet computers, light-weight laptops, and the hybridization of the two in 2-in-1 PCs.

<span class="mw-page-title-main">UC Browser</span> Chinese web browser developed by UCWeb Inc

UC Browser is a web browser developed by mobile internet company UCWeb, a subsidiary of the Alibaba Group. It was the most popular mobile browser in India, Indonesia, and Mali, as well as the second-most popular one in China as of 2017. Its world-wide browser share as of May 2022 is 0.86% overall according to StatCounter.

The version history of the Android mobile operating system began with the public release of its first beta on November 5, 2007. The first commercial version, Android 1.0, was released on September 23, 2008. The operating system is developed by Google on a yearly cycle since at least 2011. New major releases are announced at Google I/O along with its first public beta to supported Google Pixel devices. The stable version is then released later in the year.

<span class="mw-page-title-main">Guardian Project (software)</span> Open source security software project

The Guardian Project is a global collective of software developers, designers, advocates, activists, and trainers who develop open-source mobile security software and operating system enhancements. They also create customized mobile devices to help individuals communicate more freely and protect themselves from intrusion and monitoring. The effort specifically focuses on users who live or work in high-risk situations and who often face constant surveillance and intrusion attempts into their mobile devices and communication streams.

<span class="mw-page-title-main">F-Droid</span> Repository for free and open source Android apps

F-Droid is an open-source app store and software repository for Android, serving a similar function to the Google Play store. The main repository, hosted by the project, contains only free and open source apps. Applications can be browsed, downloaded and installed from the F-Droid website or client app without the need to register for an account. "Anti-features" such as advertising, user tracking, or dependence on non-free software are flagged in app descriptions.

<span class="mw-page-title-main">Google Mobile Services</span> Googles proprietary software bundle on the Android platform

Google Mobile Services (GMS) is a collection of proprietary applications and application programming interfaces (APIs) services from Google that are typically pre-installed on Android devices, such as smartphones, tablets, and smart TVs. GMS is not a part of the Android Open Source Project (AOSP), which means an Android manufacturer needs to obtain a license from Google in order to legally pre-install GMS on an Android device. This license is provided by Google without any licensing fees except in the EU.

<span class="mw-page-title-main">Google Allo</span> Instant messaging app by Google

Google Allo was an instant messaging mobile app by Google for the Android and iOS mobile operating systems, with a web client available in some web browsers. It closed on March 12, 2019.

<span class="mw-page-title-main">CopperheadOS</span> Mobile operating system focused on privacy and security

CopperheadOS is a mobile operating system for smartphones, based on the Android mobile platform. It adds privacy and security features to the official releases of the Android Open Source Project by Google. CopperheadOS is developed by Copperhead, a Canadian information security company. It is licensed under Creative Commons BY-NC-SA 4.0, although its source code is not available for public download.

/e/ is a fork of LineageOS, an Android-based mobile operating system, and associated online services. /e/ is presented as privacy software that does not contain proprietary Google apps or services, and challenges the public to "find any parts of the system or default applications that are still leaking data to Google."

<span class="mw-page-title-main">Android 10</span> Tenth major version of the Android mobile operating system

Android 10 is the tenth major release and the 17th version of the Android mobile operating system. It was first released as a developer preview on March 13, 2019, and was released publicly on September 3, 2019.

HarmonyOS (HMOS) is a distributed operating system developed by Huawei for smartphones, tablets, smart TVs, smart watches, personal computers and other smart devices. It has a multikernel design with dual frameworks: the operating system selects suitable kernels from the abstraction layer in the case of devices that use diverse resources. The operating system was officially launched by Huawei in August 2019.

CalyxOS is an operating system for smartphones based on Android with mostly free and open-source software. It is produced by the Calyx Institute as part of its mission to "defend online privacy, security and accessibility."

<span class="mw-page-title-main">Android 12</span> Twelfth major version of the Android mobile operating system

Android 12 is the twelfth major release and 19th version of Android, the mobile operating system developed by the Open Handset Alliance led by Google. The first beta was released on May 18, 2021. Android 12 was released publicly on October 4, 2021, through Android Open Source Project (AOSP) and was released to supported Google Pixel devices on October 19, 2021. As of April 2024, it is the oldest Android version still supported.

<span class="mw-page-title-main">Bootloader unlocking</span> Process of disabling secure device booting

Bootloader unlocking is the process of disabling the bootloader security that makes secure boot possible. It can make advanced customizations possible, such as installing a custom firmware. On smartphones this can be a custom Android distribution or another mobile operating system. Some bootloaders are not locked at all, others can be unlocked using a standard command, others need assistance from the manufacturer. Some do not include an unlocking method and can only be unlocked through a software exploit.

References

  1. "Releases | GrapheneOS". 23 February 2024. Retrieved 26 February 2024.
  2. 1 2 3 4 5 Tremmel, Moritz; Grüner, Sebastian (11 December 2019). "GrapheneOS: Ein gehärtetes Android ohne Google, bitte" [GrapheneOS: A hardened Android without Google, please]. Golem.de (in German). pp. 1–3. Archived from the original on 15 November 2021. Retrieved 20 July 2022.{{cite web}}: CS1 maint: unfit URL (link)
  3. 1 2 Baader, Hans-Joachim (9 April 2019). "Android Hardening wird zu GrapheneOS" [Android Hardening becomes GrapheneOS]. Pro-Linux (in German). Archived from the original on 21 September 2019. Retrieved 17 September 2019.
  4. Wilde, Damien (11 March 2022). "Privacy-focused GrapheneOS based upon Android 12L comes to Pixel 6 in latest beta". 9to5Google . Archived from the original on 28 June 2022. Retrieved 28 June 2022. After news that custom ROM project ProtonAOSP offers Pixel 6 owners the opportunity to run Android 12L ahead of the official stable release, GrapheneOS is the second such ROM to offer the latest build ahead of Google.
  5. Hazarika, Skanda (4 March 2022). "GrapheneOS brings its camera and PDF viewer apps to the Play Store". XDA. Archived from the original on 22 June 2022. Retrieved 22 June 2022.
  6. 1 2 3 4 Fedewa, Joe (23 March 2022). "What Is GrapheneOS, and How Does It Make Android More Private?". How-To Geek. Archived from the original on 10 June 2022. Retrieved 4 July 2022.
  7. 1 2 3 4 Lamont, Jonathan (20 March 2022). "A week with GrapheneOS exposed my over-reliance on Google". MobileSyrup. Blue Ant Media. Archived from the original on 6 July 2022. Retrieved 6 July 2022.
  8. "South Korea to probe Apple and Google over in-app payment rule break". TechCrunch. 9 August 2022. Archived from the original on 5 February 2023. Retrieved 20 August 2022.
  9. 1 2 Mascellino, Alessandro (16 June 2022). "What is GrapheneOS and how does it improve privacy and security?". Android Police. Archived from the original on 22 July 2022. Retrieved 17 August 2022.
  10. Valeri, Vitor (17 June 2022). "O que é o GrapheneOS? Como ele aumenta a segurança e a privacidade do celular?". Oficina da Net (in Brazilian Portuguese). Archived from the original on 22 June 2022. Retrieved 5 August 2022.
  11. "This is why James Bond doesn't use an iPhone". Wired UK. ISSN   1357-0978. Archived from the original on 17 August 2022. Retrieved 17 August 2022.
  12. "Features overview". GrapheneOS. Archived from the original on 28 January 2023. Retrieved 5 February 2023.
  13. Schoon, Ben (3 January 2024). "GrapheneOS, a privacy-focused version of Android, is adding Android Auto support". 9to5Google . Archived from the original on 3 January 2024. Retrieved 3 January 2024.
  14. "Releases". GrapheneOS. Archived from the original on 20 December 2023. Retrieved 3 January 2024.
  15. "If I were configuring a smartphone today, I'd use @DanielMicay's @GrapheneOS as the base operating system. I'd desolder the microphones and keep the radios (cellular, wifi, and bluetooth) turned off when I didn't need them. I would route traffic through the @torproject network". Twitter. Archived from the original on 15 November 2022. Retrieved 5 February 2023.
  16. Mühlenmeier, Lennart (19 July 2019). "Warum Post, Bank und Co. ihre Kunden nicht zwingen sollten, Apps zu benutzen" [Why Post, Bank and Co. shouldn't force their customers to use apps]. netzpolitik.org (in German). Archived from the original on 18 September 2019. Retrieved 18 November 2019.
  17. Šlik, Jáchym (6 April 2019). "GrapheneOS chce napravit bezpečnostní prohřešky Androidu" [GrapheneOS wants to fix Android security violations]. Svět Mobilně (in Czech). Archived from the original on 8 April 2019. Retrieved 17 September 2019.
  18. Kalelioğlu, Eray (3 April 2019). "Android Tabanlı İşletim Sistemi 'GrapheneOS' ile Tanışın" [Meet the GrapheneOS Android-Based Operating System]. Webtekno (in Turkish). Archived from the original on 3 April 2019. Retrieved 17 September 2019.
  19. Diane (28 June 2021). "GrapheneOS: A Hardened Android Alternative (Review)". CellularNews. Archived from the original on 14 July 2022. Retrieved 4 July 2022.
  20. Lamont, Jonathan (13 March 2022). "I replaced Android on a Pixel 3 with an Android-based privacy OS". MobileSyrup. Blue Ant Media. Archived from the original on 6 July 2022. Retrieved 6 July 2022.
  21. "How to find and remove spyware from your phone". ZDNET. Archived from the original on 20 August 2022. Retrieved 20 August 2022.
  22. "Swiss Startup Takes On Apple and Google With Privacy-First OS". Bloomberg.com. 16 January 2023. Archived from the original on 23 May 2023. Retrieved 25 May 2023.
  23. "Swiss startup takes on Apple and Google with privacy-first OS". The Star. Archived from the original on 25 May 2023. Retrieved 25 May 2023.