Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

> Phone: Pixel with GrapheneOS or CalyxOS

I've seen this recommendation very often lately. As I am shopping for a new phone: Why is it that hardware directly from Google is recommended for putting another OS onto it (I've seen recommendations for LineageOS as well). What makes it better than any stock phone supported by LineageOS?



Consistency. All the Google hardware forever has allowed easy factory unlocking without a fuss, easy ways to restore to standard OS images without jumping through hoops, and are widely available. Plus they allow re-locking the booloader and the phone equivalent of enrolling your own custom secure boot keys. They also provide firmware updates for a long time so you can get platform/hardware patches too. CalyxOS does provide these in their images.

The 3a/4a are cheap and have headphone jacks and good cameras. What's not to love? Until they change their policy on unlocking bootloaders and installing custom OSs they're great devices. I still have a Nexus 5 that runs PostmarketOS and Ubuntu Touch, and if it completely breaks I can always use ADB/Fastboot to flash the Android 6 images that are still on Google's website. Don't even have to log in to get them.


Devices supported by the Sony Open Device Program shoukd be also a good target:

https://developer.sony.com/develop/open-devices/

There are projects such as Sailfish OS that make use of this to run on originally Android hardware.


See the GrapheneOS or CalyxOS websites for more details, they are significantly hardened for security compared to LineageOS.

Currently those two projects only support Pixels, mainly because they're all bootloader unlockable. If these projects had as many volunteers as LOS then more devices could be officially supported.

LOS on a supported Android phone is still a better option than a stock Android or iPhone at least.


My https://divestos.org project, while not as secure as GrapheneOS, provides lots of security to many older devices.


Interesting project. Thanks for sharing! Any reason why at least some of those patches couldn't be upstreamed to LOS?


Most things simply aren't in their scope.

I do send occasional patches to Lineage if they are in-scope and am in contact with some of them reasonably frequently.

The big blocker is that their Gerrit instance requires a Google account to login.

Example of a recent fix I emailed them: https://review.lineageos.org/c/LineageOS/android_device_htc_...




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: