From 3aa64b0076bf5b4928d2e064dfb506dc7955d436 Mon Sep 17 00:00:00 2001 From: Tommy Date: Sun, 30 Jan 2022 18:38:00 -0500 Subject: [PATCH] Update CalyxOS comparison (#548) CalyxOS is now on Android 12. I will look into their new Firewall when I can get my hands on a CalyxOS device or someone can help me do some testing. --- collections/_evergreen/android.html | 10 ++-------- 1 file changed, 2 insertions(+), 8 deletions(-) diff --git a/collections/_evergreen/android.html b/collections/_evergreen/android.html index 6735ef7a..b9f2dfcb 100644 --- a/collections/_evergreen/android.html +++ b/collections/_evergreen/android.html @@ -8,7 +8,7 @@ The main privacy concern with most Android devices is that they usually include ---

@@ -157,19 +157,13 @@ We have these general tips:

MicroG is a reimplementation of Google Play Services. This means it needs to be updated every time Android has a major version update (or the Android API changes). It also needs to run in the highly privileged system_app SELinux domain like the normal Play Services and is less secure than the Sandboxed Play Service approach. We do not believe MicroG provides any privacy advantages over Sandboxed Play Services except for the option to shift trust of the location backend from Google to another provider such as Mozilla or DejaVu.

-

Device Patch Level
- -

GrapheneOS includes the latest Android 12 and comes with full firmware security patches for non "extended support" devices. If it is supported you will have the latest security patch level.

- -

CalyxOS has not yet finished Android 12 support. This means they cannot include the updated proprietary firmware with security patches that were designed for Android 12.

-
Privileged App Extensions

Android 12 comes with special support for seamless app updates with third party app stores. The popular Free and Open Source Software (FOSS) repository F-Droid doesn't implement this feature and requires a privileged extension to be included with the Android distribution in order to have unattended app installation.

GrapheneOS doesn't compromise on security, therefore they do not include the F-Droid extension therefore, users have to confirm all updates manually if they want to use F-Droid. GrapheneOS officially recommends Sandboxed Play Services instead. Many FOSS Android apps are also in Google Play but sometimes they are not (like NewPipe).

-

CalyxOS includes the privileged extension, which may lower device security. Seamless app updates should be possible with Aurora Store when CalyxOS is upgraded to Android 12 and #153 is completed.

+

CalyxOS includes the privileged extension, which may lower device security. Seamless app updates should be possible with Aurora Store when #153 is completed.

Additional Hardening

GrapheneOS improves upon AOSP security with: