• usernameunnecessary@lemmy.zip
    link
    fedilink
    English
    arrow-up
    55
    ·
    1 day ago

    I’ve said this many times and it’s always on my mind. Google is a terrible steward for Android. We need alternatives that are viable and don’t came with huge dealbreakers.

    • rockSlayer@lemmy.blahaj.zone
      link
      fedilink
      English
      arrow-up
      18
      arrow-down
      2
      ·
      1 day ago

      Hopefully Graphene is developing a hard fork of AOSP with Motorola, so they don’t have to be reliant on Google

      • Lemmayng@lemmy.world
        link
        fedilink
        English
        arrow-up
        10
        ·
        1 day ago

        That’s why I was so gutted that DivestOS shut down. It was such a good alternative to GrapheneOS and was usable on phones other than Pixel.

        I guess CalyxOS is the next best thing nowadays, since it can be used on some Motorola phones, Fairphones and the ShiftPhone 8:

        https://calyxos.org/install/

        • Wilmo@lemmy.ml
          link
          fedilink
          English
          arrow-up
          19
          arrow-down
          1
          ·
          1 day ago

          They specifically aren’t vibing it though.

          As they say it’s useful to find vulnerabilities which is true.

          And as far as code they said:

          Frontier models are very good at finding bugs but it requires an experienced developer to babysit it and extract the useful portion of the output. Important bugs are often found but mixed in with a bunch of low quality output.

          Which is the opposite of vibe coding.

          It’s fair to dislike any LLM usage. But it can have value. But it’s often coming from unethical entities like OpenAI and Anthropic etc

          • rowinxavier@lemmy.world
            link
            fedilink
            English
            arrow-up
            3
            arrow-down
            1
            ·
            15 hours ago

            I think this is the distinction of uses I canost get behind. If you find an attack using any tool, whether that be a CVE, a script kiddy, or an LLM, then you can go on to understand how the vulnerability works and patch it. This leaves the understanding part to the programmer, but not the arduous task of trying to find problems. If you use vibecoding to do the actual fixing you never have the understanding of how the code works and therefore what the changes will actually do.

            LLMs can be useful in a lot of ways, but they should never replace thinking and understanding. Just like you do need to memorise some things but not others, there are cognitive tasks you don’t have to do all the time but others you really have to in order to actually be a good programmer. If you outsource thinking you stop doing it and get weaker at it. If you outsource meaningless tasks or use systems to reduce the need for them that is actually useful for freeing up your mind for tasks which cannot be automated.

            So in my view using these tools to find bugs in code can be useful. Knowing that if a bug is found it may not be disclosed to you by the tool because the provider of the tool wants to keep some bugs hidden is something people should consider, I mean that is exactly what the NSA has been going for decades with zero day exploits in various operating systems and platforms, why would they not do so now?

        • lambalicious@lemmy.sdf.org
          link
          fedilink
          English
          arrow-up
          3
          arrow-down
          4
          ·
          23 hours ago

          Shit, well that pretty much seals the deal on no Motophene for me. As if the Epstein Class price tag was not doing enough as a disincentive.

  • trevor (any/all) @lemmy.blahaj.zone
    link
    fedilink
    English
    arrow-up
    37
    arrow-down
    3
    ·
    1 day ago

    Yet, the GrapheneOS devs will continue to insist that Linux isn’t viable because of “security”. Well, how useful is AOSP going to continue being with Google holding it hostage?? It sure seems to me that spending effort to make mobile Linux more secure and usable would be a much better long-term strategy than to keep developing for a dying, hostile ecosystem.

    • kinosaki@lemmy.dbzer0.com
      link
      fedilink
      English
      arrow-up
      6
      arrow-down
      1
      ·
      edit-2
      13 hours ago

      Android is not the problem here. In fact I love Android very much. What I don’t like is Google.

      AOSP and Google need to be seperated. While Linux mobile would be nice, phones work differently than PCs and I don’t think Linux will just “work” like it does on desktop. There’s a reason why it’s so far behind. Popularity and viability. I just don’t think it’s worth it.

      Android is amazing. It’s secure, great, snappy and it’s still very open. However I do NOT trust Google that they will not fuck up the freedom aspect of it in the near future.

    • iturnedintoanewt@lemmy.world
      link
      fedilink
      English
      arrow-up
      18
      ·
      1 day ago

      The way i understand it, what Google did in Android is no joke, and definitely very hard to implement on a small team that basically works on just fine tuning your existing code. Birthing all this onto Linux is quite an undertaking, and it would need hardware partnership agreements.

      • theparadox@lemmy.world
        link
        fedilink
        English
        arrow-up
        7
        ·
        22 hours ago

        what Google did in Android

        Like almost everything Google has done, android was bought by Google. Admittedly, it’s been quite a while since then and I couldn’t tell you how much can be attributed to the original team vs Google’s input.

        • Handles@leminal.space
          link
          fedilink
          English
          arrow-up
          2
          ·
          8 hours ago

          Yes, corporations buy up small businesses and startups. In this case all they got seems to be the Android name and an idea to make a phone OS? AFAICT the project was neither open source or based on the Linux kernel until Google took over.

          I’m not trying to whitewash Google here, they did that pretty well themselves in open sourcing Android development. That’s given them a 20+ years alibi to be complete arseholes in pretty much any other part of their business — and now they’re clamping down on Android, too.

        • trevor (any/all) @lemmy.blahaj.zone
          link
          fedilink
          English
          arrow-up
          5
          ·
          18 hours ago

          Yes, and the biggest thing Android has going for it in terms of security is the fact that everything runs with under a strict sandbox and permission model.

          You could absolutely build a cohesive, secure Linux system using Flatpak to acheive something similar. It will still have rough edges and holes, but if GOS devs put in the same amount of effort into making Linux secure as they have with AOSP, we could get it to where it needs to be.

          • ɔiƚoxɘup@infosec.pub
            link
            fedilink
            English
            arrow-up
            2
            ·
            18 hours ago

            Again, agreed, but hindsight is 20/20. I’m not sure if when they started in 2016, they would’ve believed that by this time, things would be going so badly. That said, I suppose we all really should have assumed they’d be enshittified as soon as google removed “Don’t be evil” from their policy in 2018.

            • trevor (any/all) @lemmy.blahaj.zone
              link
              fedilink
              English
              arrow-up
              1
              ·
              1 hour ago

              For me, it’s been pretty obvious that Android was going this direction for almost a decade, but any time people bring up mobile Linux, the GOS devs still bend over backwards to defend building for the dying AOSP ecosystem.

    • ɔiƚoxɘup@infosec.pub
      link
      fedilink
      English
      arrow-up
      3
      ·
      18 hours ago

      Agreed. It’s time to have a truly open source OS. I didn’t know that they had that opinion, but it doesn’t surprise me. They seem extremely… determined is probably the nicest way I can put it.

      I used to be enthusiastic about graphene, but between this and a few other things, I’m not sure pursuing using graphene is really worthy of my time, if only because of the devs’ attitudes, or at least the attitude of whoever is doing their communications.

  • ColeSloth@discuss.tchncs.de
    link
    fedilink
    English
    arrow-up
    2
    ·
    17 hours ago

    Starting to read this title had me in completely the wrong headspace and trying to recall any android 3 at all. Furthest back I could remember was 8er.