Conversation

Since they stop publishing factory images and device support code for the previous major release. With your own device, you control your own destiny in that regard. AOSP supports each major release for 3 years and your vendor updates won't require a new major release of Android.
1
2
Without your own device, simply targeting ANYTHING other than a Pixel, since the OEM takes longer to migrate you have a lot more time to port your changes and get your fork of AOSP ready. Treble also allows moving to a new major release without device support code being updated.
1
1
Pixels make this hard, since they move immediately, right when the new OS you need to port your code to becomes publicly available, and they immediately drop support for the previous major release. Treble means AOSP is backwards compatible with device support code, but new device
1
2
support code isn't backwards compatible with an old version of AOSP so we can't simply continue having GrapheneOS based on Android 10 while shipping Android 11 device support code. Forced to migrate rapidly which is extremely difficult. All of this is caused by targeting Pixels.
1
2
Our long-term goal is to be targeting custom hardware in collaboration with organizations like Calyx, where hardware is produced to suit the needs of multiple projects. Would no longer have these issues regardless of how much SoC vendor code is open + can take time to migrate.
2
5
+ even if SoC vendor code isn't open, at least we'd still get to audit, modify and build most of it internally including a lot of the SoC firmware. Maybe there would be an SoC vendor with decent security and open source device support code at that point - right now, not really.
1
1
We won't target a device with serious remote and local code execution vulnerabilities in firmware and drivers, along with very sub-par exploit mitigations, no verified boot, no attestation, lack of Wi-Fi anonymity, etc. Not going back to the stone ages of privacy and security.
2
1
We want our own hardware to avoid having Google as a middleman between us and the vendors. Either way, components are closed source hardware with closed source firmware. Avoiding closed source libraries often means making major sacrifices like using very insecure / outdated hw.
1
1
Years ago, OEMs even got the source code for the Qualcomm baseband, but they stopped sharing it and allowing modifications. Anyways, SoC vendor choice becomes something in our control if we have our own hardware. It doesn't have to stay the same between generations either.
1
1
We can choose what we think is the least bad compromise and then that choice can change as the situation changes. We hardly have any issues AOSP and it has rapidly improving privacy/security itself. Our issues are with the OEMs (Google as the Pixel OEM) and their hw vendors.
1
1
Show replies