Having to click "Verify you are a human" every single time is still awful.
HN user
SubzeroCarnage
/e/OS ranks poorly and is consistently months behind security updates: https://eylenburg.github.io/android_comparison.htm
Also visual voicemail should actually work just fine on select carriers.
Back when I was developing my DivestOS project, test calling 911 was actually a thing I tried to do each month for this reason.
There was one time where I did ship an update that broke select calls but I had it fixed on all devices in under 24 hours.
The oneplus3 cannot be relocked as it wrongly trusts test-keys. It also has public EDL firehose files available allowing anyone to flash it arbitrarily even when locked or further dump ram or userdata.
I previously documented this here: https://web.archive.org/web/20250120181249/https://divestos....
Briar started in 2011: https://sourceforge.net/p/briar/mailman/message/27393146/
Briar is actually even older than that!
2011: https://sourceforge.net/p/briar/mailman/message/27393146/
interesting!
I suppose a sufficiently older agesa may actually load the newer microcode then if that was a recent addition in preparation for this
recent microcode appears to be rejected by older agesa in my testing, so it is very possible it is more than an implementation issue
under agesa 1.2.0.2b
microcode: CPU1: update failed for patch_level=0x0a60120c
under agesa 1.2.0.3a PatchA (which asus leaked that it fixes this issue)
microcode: Updated early from: 0x0a60120c
Reminder that AMD has stopped providing microcode updates for consumer platforms via linux-firmware.
index of linux-firmware, 41 cpus supported: https://github.com/divestedcg/real-ucode/blob/master/index-a...
index of my real-ucode project, 106 cpus supported: https://github.com/divestedcg/real-ucode/blob/master/index-a...
sadly, unless you have this recent agesa update you can no longer load recent microcodes due to this fix
which very well means quite a substantial amount of models whose vendors don't provide a bios update for this (since it goes back to zen1) will not be able to load any future fixes via microcode
the updates were all on time: https://divestos.org/misc/ffa-dates.txt
the 21 port was actually largely complete: https://github.com/Divested-Mobile/DivestOS-Build/blob/maste...
ECH can be used regardless of DoT, DoH, dnscrypt, or plain as long as your resolver passes HTTPS queries.
You can easily test this: dig @8.8.8.8 https pq.cloudflareresearch.com
Firefox 128.0.3 and higher has this globally disabled for Android.
I added payout counts after seeing a comment on a recent thread here.
Script here: https://github.com/Divested-Mobile/DivestOS-Website/blob/mas...
There is also a Firefox version here: https://divestos.org/misc/ffa-dates.txt
Also if you don't have a bios update available for that newer microcode, give my real-ucode package a try: https://github.com/divestedcg/real-ucode
The linux-firmware repo does not provide AMD microcode updates to consumer platforms unlike Intel.
KPTI won't be default enabled on Linux on AMD CPUs is the issue here.
Yet it provides valuable separation between kernel and userspace address ranges.
iirc the predecessor to KPTI was made before these hw flaws were announced as a general enhancement to ASLR.
AMD aside, Spectre V2 isn't even default mitigated for userspace across the board, you must specify spectre_v2=on for userspace to be protected.
https://www.kernel.org/doc/html/latest/admin-guide/kernel-pa...
That row covers whether or not the opt-in/out is provided during setup wizard, not post install.
If there is such an option then you can report it here: https://github.com/eylenburg/eylenburg.github.io/issues
Most "degoogled" systems are not degoolged: https://eylenburg.github.io/android_comparison.htm
Google Play System updates provide very few security patches and this only applies to devices with Android 10 and higher and most APEX modules are only updatable in later versions.
I track security patch counts of monthly Android Security Bulletin vs available APEX vs my aftermarket backports for A7 through A13 here: https://divestos.org/pages/patch_counts#aggregatePatchCounts
I document this more in depth here https://divestos.org/misc/gnss.txt
My Mull disables WASM by default, please see the documented workarounds here: https://divestos.org/pages/broken#mull
can’t ensure security features
They are indeed different projects. GrapheneOS is maximum security possible. DivestOS is best effort security of old/EOL devices to prevent them from being completely e-waste.
so one is limited to generally the apps
It has the only unprivileged microG implementation, please read this: https://divestos.org/pages/faq#appCompatibility
They've already leaked user data once and never published a follow up like they said they would, just told users to delete files/contacts/calendars that weren't their own.
https://community.e.foundation/t/service-announcement-26-may...
Per https://docs.nextcloud.com/server/latest/admin_manual/config...
The encryption app does not protect your data if your Nextcloud server is compromised, and it does not prevent Nextcloud administrators from reading user’s files. It encrypts only the contents of files, and not filenames and directory structures.
My DivestOS supports decade+ old devices and provides monthly security updates for seven versions of Android, no other project does this.
GrapheneOS has good reason to only support Pixel devices, they consistently do the right thing with regards to relocking, verified boot, CFI/SCS support, strongbox support, and even now MTE support.
Many other devices fail to support these, eg: https://divestos.org/pages/faq#kernelCFI
Even the FP4 shown in the article is fundamentally broken and trusts the AOSP public test-keys for verified boot: https://divestos.org/pages/faq#deviceBootloader
Be opt-in like the other systems, not opt-out.
You can use a work profile via Shelter/Insular instead which makes this entirely seamless, simply swipe right on your launcher to launch work apps. They even get their own VPN slot too!
They literally include Google Widevine DRM and Google EUICC:
https://gitlab.e.foundation/e/devices/android_device_fairpho...
https://gitlab.e.foundation/e/devices/android_device_fairpho...
microG itself connects directly to Google: https://github.com/microg/GmsCore/wiki/Google-Network-Connec...
and /e/OS default enables those connections: https://gitlab.e.foundation/e/os/android_prebuilts_prebuilta...
including the default download and running of the proprietary Google SafetyNet binaries: https://gitlab.e.foundation/e/os/android_prebuilts_prebuilta...
Kuketz covered the connections made in full at the very end here: https://www.kuketz-blog.de/e-datenschutzfreundlich-bedeutet-...
/e/OS falls significantly behind the other alternative Android systems with regards to privacy and security.
Please see this independent comparison table: https://eylenburg.github.io/android_comparison.htm
And additionally the reviews by Kuketz: https://www.kuketz-blog.de/android-grapheneos-calyxos-und-co...
See also my table that shows historical release dates for monthly Android Security Bulletins: https://divestos.org/misc/a-dates.txt
and the Chromium (WebView): https://divestos.org/misc/ch-dates.txt