>While it’s still in experimental state, it has successfully booted on:
>Common x86_64 PCs
>Apple Silicon Macs
>NVIDIA DGX Spark
>Qualcomm Snapdragon X Series Laptops
That actually sounds awesome! Refurbishing old laptops with Android would be a nice choice alongside with Desktop Linux.
Android is pretty slick overall and the user experience is simpler and more familiar to people than Windows or Linux (even if they're an iPhone user). You'd be surprised how many people don't really use PCs.
Though it might have some use if you at least can run linux userland inside android, including a whole desktop session, without any performance degradation.
With this attitude it's almost inevitable. Politics can stop the corporate-OS attestation apocalypse. If it happens, it's on us.
A long time ago when I was young and not yet thoughtful I had a variety of regular big name banks like Citi and BofA etc.
It was the easiest thing in the world to just choose a different one that works for me.
For example, would you really want to live in a world in which photographs are no longer considered evidence of anything because any photo might be AI generated? When a citizen standing on his apartment's balcony used his camcorder to record police beating Rodney King in 1991, it started a national movement against police brutality. So, you're OK with a world where there can be no national conversation sparked by any recording because as far as anyone knows, the recording could've been faked by AI? Remote attestation by the camera is the only way I have been able to think of to avoid that world.
For another example, banking and finance started relying on attestation in 1997 with the availability of the IBM 4758 PCI Cryptographic Coprocessor and have come to rely heavily on it.
Don't worry, photographs were being faked before Lee Harvey Oswald.
We know it is practical to have a LiDAR scanner in the same assembly as an image sensor because the rear camera bump of the iPhone Pro has a LiDAR scanner.
The technology need not be 100% tamper-proof to have a large effect on society: there is a huge difference in persuasiveness between the claim that anyone could have created a particular video by submitting to an AI some starting videos and images and some prompts and the claim that anyone with years of training and experience in cutting-edge microelectronics could have bought 500 iPhones and used very expensive equipment to create 499 ruined iPhones and one iPhone that can be used to create false attestations of recordings -- particularly because in a high profile instance such as a repeat of the Rodney King beating, Apple engineering would tend to be very interested in examining the device used to make the recording.
The iPhone Pro starts at $1199.
Moreover, LiDAR is essentially a laser that emits at a particular wavelength and a camera that detects that wavelength, so it could be fooled by pointing it at a screen that emits at the same wavelength, which in turn could be an ordinary screen with something in front of it that converts light at a wavelength it emits to the one the LiDAR sensor is expecting.
And that's if you insist on using light. The LiDAR sensor itself is an analog piece of hardware that converts the light into an electrical signal, so if you substitute its electrical output as the input to the signing hardware then it signs whatever you want and never knows the difference.
The hardest part about this is probably creating a credible depth map of a generated 2D image, which is the part that doesn't require signatures or attestation.
> The technology need not be 100% tamper-proof to affect society: there is a huge difference in persuasiveness between the claim that anyone could have created a particular video by submitting to an AI some starting videos and images and a few prompts and the claim that anyone with years of technical training and experience could have bought 500 iPhones and used very expensive equipment to create 499 ruined iPhones and one iPhone that Apple's engineers have not detected yet that can be used to create falsely attested recordings.
Until one of the people with the capacity to do it sets up a website where anyone can submit an image and have it signed.
Moreover, isn't "most people can't do this but some people still can" actually worse? It's a system for providing undue credibility to the forgeries from the people who can do it.
Without even making most legitimate images more credible, since most phone cameras don't have fancy LiDAR hardware.
The camcorder used to record the Rodney King beating also probably cost at least $1199. LiDAR will spread to cheaper smartphones if enough consumers start to value it, and many (maybe most) consumers will do if it becomes necessary for the consumer to retain the ability to make recordings that can be used as evidence.
>it could be fooled by pointing it at a screen that emits at the same wavelength
LiDAR emits a pulse, then times how long it takes to get a pulse back, so your exploit got a lot more technically complicated since of course these pulses travel at the speed of light.
>substitute its electrical output as the input to the signing hardware
The LiDAR scanner is part of an integrated circuit (IC) that encrypt the data from the LiDAR scanner. To get at the unencrypted data, you would have to uncap the IC and use a scanning electron microscope or such.
How do I know so much about iPhone hardware? I don't, except I know that Apple is widely believed to be the world's leader in hardware security, so I strongly suspect that every single data path in a recent iPhone is encrypted before it leaves any IC.
>Until one of the people with the capacity to do it sets up a website where anyone can submit an image and have it signed.
The web server behind the site would have to be connected to a compromized iPhone Pro. As soon as Apple becomes aware of the web site, they will disable that iPhone Pro. Specifically, they will be able to determine its ID number (term?) from the attestation, and I'm pretty sure they already have the ability to disable an iPhone by ID number.
>Moreover, isn't "most people can't do this but some people still can" actually worse?
If Apple cares and is willing to expend the necessary engineering resources, then anyone (other the Apple itself) who makes any sort of notable or economically important or culturally important use of their ability to create a false attestation will retain the ability for only a brief time.
The last time a public jailbreak was released for modern iPhone hardware running the actively signed, latest iOS version was in May 2020, which is over six years ago. It is possible that someone will publish a jailbreak in the future, but the lifespan of that jailbreak will probably be only a few days. I expect Apple could exert a level of control over "camera remote attestation" similar to the level of control it has already achieved over which OSes (and which apps) can run on its iPhones. In general, these "technical regimes" are designed to make it easy for the engineering organization to recover from exploits as soon as the organization becomes aware of the exploit.
Again: do you really want photographic evidence to stop being useful in almost every situation (e.g., in court)? If not, then what is your alternative to "technical regimes" reliant on remote attestation similar to the regime I just described?
You expect $50 phones to have LiDAR hardware?
> LiDAR emits a pulse, then times how long it takes to get a pulse back, so your exploit got a lot more technically complicated since of course these pulses travel at the speed of light.
That's assuming you're trying to detect the pulse rather than sending back photons with particular timing from when you expect it to come. Notice that you can also try more than once and only publish the image where you got the timing right.
You also have the advantage because you can have something which is directly in front of the sensor but is sending back photons later than that because you're pretending to be something which is further away.
> The LiDAR scanner is part of an integrated circuit (IC) that encrypt the data from the LiDAR scanner. To get at the unencrypted data, you would have to uncap the IC and use a scanning electron microscope or such.
With the right equipment you can affect electrical signals within an IC without disassembling it.
Or you can disassemble it. It doesn't have to be easy when only one person has to do it.
> The web server behind the site would be connected to a compromized iPhone Pro. As soon as Apple becomes aware of the web site, they will disable the iPhone. Specifically, they will be able to determine ID number (term?) of the iPhone from the attestation data, and I'm pretty sure they already have the ability to disable an iPhone by ID number.
So they set up an apparatus where they can put any such a phone, buy them in bulk and resell them immediately after use for the same price they paid. Then most are never detected and even if a few of them are, Apple is only disabling the phone of the innocent third party buyer, likely outside of the return window, and thereby negatively impacting the resale value of their own brand.
Also, your premise was that this would be in every phone and then they're not buying late model iPhones, they're getting e-waste phones with dead batteries or cracked screens by the pallet for ~free to use once on their way to the scrapper.
> The last time a public jailbreak was released for modern iPhone hardware running the actively signed, latest iOS version was in May 2020, which is over six years ago. It is possible that someone will publish a jailbreak in the future, but the lifespan of that jailbreak will probably be only a few days.
You're assuming they publish their methods for Apple to patch instead of setting up the service to sign images without documenting exactly how they do it.
And also that every phone OEM cares to that extent, which they obviously don't.
That's a pretty rich qualification. "I know" suggests you can prove it, but you have to qualify it with "believed" because you can't. You can't cite anyone that audited Apple's source code, or ask a knowledgeable stakeholder for a credible architectural understanding. You haven't written an exploit, or reverse-engineered one.
It's purely faith. You're making an argument "you know" based on the loyal assumption that Apple's marketing is correct. You could be citing security theater muppets for all you know, but apparently your argument isn't contingent on veracity or transparency.
> Again: do you really want photographic evidence to stop being useful in almost every situation (e.g., in court)?
Yes? Do you really want a purity spiral where people that get abused, subjected to police brutality or sexually assaulted are discredited because they're too poor for a LIDAR camera? I would lobby day and night for this two-tiered evidence system to be reversed because it would force the miscarriage of justice as a marketing gimmeck for iPhone technology. It's not a scalable, holistic, trustworthy, accessible, or safe option for anyone, let alone Americans. There is not a single company in the United States that can implement a system like this protected from domestic or foreign adversaries.
Truly, go fuck yourself if you genuinely think this false dichotomy is the only worthy perspective.
(@0xcafebabe: ADHD high-five, I've got almost the same target list, except I'm playing with their NPUs)
Not a lot of them unfortunately.. but with current bootloader unlocking situation, only newer motorolas seem to be missing... OnePlus 15 was added (or is in the making)
Is this still the case? My guess is that Lineage doesn't get the drivers necessary for better quality maybe.
Just trying to understand why that's a mystery :thinking_face:
Who do you think "you guys" is exactly? You guys is you. You can port it to your chosen device and be the maintainer for that device and then we can thinking face wonder why you didn't give us some other device we wish was supported.
Privacy heavily depends on security. GrapheneOS greatly improves both privacy/security patches and privacy/security protections. The sole reason for the focus on security in GrapheneOS is because it's a privacy project. It has no other reason to work on security.
Android 17 was released in June 2026 and has been required for full standard Android privacy and security patches since then. Only a subset of the patches Google deems to be High or Critical severity are backported. Keeping up with the standard backports and major updates is important but increasingly inadequate.
A sufficiently motivated threat actor will have them (the exploits) too.
Motorola will be working towards providing the same thing as part of our partnership with them, but we're starting out with the high end flagship devices due to those currently being required for it.
I don't understand why it took LineageOS so long to update to AOSP 17, while GrapheneOS managed to update to 17 in just 3 days. LineageOS really should be based directly on GrapheneOS.
Here's a hint: GrapheneOS has paid developers working on it full-time, while LineageOS is done by people in their spare time. Also, GrapheneOS has a collaboration with Motorola and through that gets for instance early access to security patches, and probably other things as well. And lastly, LineageOS supports roughly 10x the number of devices. It's significantly easier if you restrict yourself to Pixels.
Just for clarification (your points are very valid): the GrapheneOS developers have stated on several occasions that they getting embargoed patches from another OEM than Motorola.
GrapheneOS does not have circle battery.
> LineageOS really should be based directly on GrapheneOS.
What would that achieve?
LOS => most security, most usability, breadth of support
- secure app spawning (huge because without it, many hardening improvements are useless)
- extremely secure memory allocator
- fully enabled MTE on shiba and newer
- relockable bootloader
- stronger forensics resistance
- more trustworthy developers (ever heard of LOSCoins?)
- rapid support for new Pixels
- lightning fast security updates faster than most OEMs/ODMs
- built-in TTS without GMS
- real GMS that isn't priv-app
and so much more
It’s a bit more annoying but also isolates stuff like photos etc. by default, so you don’t have to think about it.
Anyways, since you're here perhaps you can answer my question from the other subthread: If I flash GOS and then flash Magisk on it, how hard is it to stay unbricked? Is it as easy as declining to relock the bootloader once, or is the system going to actively fight me on every boot?
Although as an extension of that - I'm hesitant to use software written by people with such a philosophical difference. It might work today, but I wouldn't trust it to work tomorrow.
Such sad state of affairs for Android. They dropped the ball on making any working edge deep learning inference framework. iOS is way better at this of all things. For being an OSS platform the amount of rigidity in not letting users customize to the fullest without rooting is just tragic.
Are you running unofficial builds right now ?
Just see out of touch with reality this section is compared to the insanse community work on Apple Silicon across whisper.cpp/mflux/llama.cpp/MLX/Exo & way more
A bargain for a test device or a daily driver for the not so wealthy.
You want to change something? Want to be recognized for making anything better?
Port it on sub $200 devices.
That's where the masses are.
That's where you start the degoogle revolution. Where you can build a sustainable business.
The device that I am typing this on (which runs LineageOS) cost me around $170 new.
Maybe if you include third party android OEMs like samsung, but google pixels are as up to date as you can get.
Is there any evidence that the git commits weren't in the ROMs from months ago? The monthly ASB corresponds to when the bugs are publicly disclosed, not when they made it into ROMs.
The only way to get the full set of security preview patches is through GrapheneOS. It's strange Google doesn't ship more for the Pixel OS but that's the way it is right now. It takes them around 4 weeks to make a release and even longer when including the time for adding changes to it so there's a long delay built into the process. They should fix it but are clearly not prioritizing it without media pressure that's not happening. They do a lot better than other OEMs but that's much different from doing a good job.
BRB gonna try this out on my old Fairphone
The only problem I've discovered is that group texts sometimes don't work (I can't see others' replies or worst case I don't receive the group text at all). Not sure if anyone else has run into this, seems like it could be related to RCS and unlocked bootloader not playing nice.
It's so bad.
The only reason I have been switching phones is banking apps: so much for Europe's right to repair..
What possesses companies to do things like this? A customer running a current version of LineageOS is going to have better security than running the out of date Android version that came with the phone. An attacker who wants root on something that will run the bank app doesn't have to use a different OS, they can just use any of this month's CVEs to root the "approved" version. Even requiring the latest patches -- which would exclude entirely too many actual customers' phones -- wouldn't stop attackers from controlling their own devices, because they could root the device before installing the patch and then install the patch for the vulnerability they used to get root on the device where they already have it.
And attackers who are going to modify the system to carry out an attack inherently have some kind of software development capacity, so measures like this have no effect on them and all they actually do is interfere with the ability of honest normies to replace their out of date OS with a version that is less likely to be compromised by attackers.
Are they just taking kickbacks from Google or something?
Even if the something is no more than engaging less fatuous attorneys.
Yes, because that particular set of lawyers haven’t said it has to be blocked. Doesn’t mean my statement that lawyers have final say is “objectively not true”.
All it takes for this to happen is the lawyers not knowing.
The state for me personally is that my joint bank account with my wife uses a play integrity protected banking app (changing your own a accounts to a better bank is one thing). Also beyond banks things now require proprietary 'secure' TAN apps like my insurance broker. The issue is that for me every a new problem like this popped up and to find solutions take time over and over. Even thing that work now may stop working the next minute because there is no real effort of fintech and its management to keep compatible with niche devices. It is mostly either coincidence or the effort of tech savvy individuals at those companies.
We only can hope that a large group of people including regulators get sanctioned or mandated not to use any US tech even privately so they see little offer is left even inside Europe that is truly sovereign. I gave up for now (after about 10 years exclusive on LineageOS ). I actually bought a pixel to have Graphene as a way out of vendor ROMs again, but I still don't have the energy to switch (alone reregistration all those TAN apps takes ages often involving waiting weeks for stupi snail mail activation letters)
I don't even have Google Wallet installed anymore.
Otherwise, vote with your wallet wherever possible and prefer those businesses that do accept cash.
I'm glad the option is still there in most places, but it's clear most people don't actually care for cash (neither do I for that matter, other than as a backup solution).
I actually called N26 (I'm a Metal customer with my own phone support) and asked will they support Graphene OS or no, and they said to me they will and gave me instructions what to keep in mind when installing the app.
Instead I opened an account with Wise, and have never once been forced to use their app. One occasion where some ID verification process pushed me towards the app online, I spoke with support and everything was sorted without it. Wise.com, just need a web browser and a phone number, zero phone app dependency.
It requires a sim card and cannot be used from multiple phones. So they put you to this endless face scan loop and then lock you out.
This is separate from the Magisk root app.
I don't believe using the ADB root functionality is problematic. The Magisk app also has a hide mode.
[1] eg. https://review.lineageos.org/q/b309b56b8cca20dcf6f678777d3ac...