zlacker

[return to "GrapheneOS is the only Android OS providing full security patches"]
1. raggi+qK[view] [source] 2025-12-06 20:15:34
>>akyuu+(OP)
Understaffed gift product wants 1 week cycles.

OEMs want 2-4 month cycles.

This is a perfect representation of the state of the software industry.

◧◩
2. luca02+4M[view] [source] 2025-12-06 20:32:46
>>raggi+qK
I don't think that's a fair comparison.

OEMs have quite a lot of extra steps before releasing any build to the public.

They have to pass xTS, the set of test suites required before getting certified by Google, possibly carrier certification, regulatory requirements and more depending on where the build will be released.

There are "quicker" release channels for security fixes, but I don't think it's common for OEMs to only ship those without any other change to the system.

I don't think Graphene does anything of sort, they take what's already certified in the Pixel builds and uses it. Not like they could do much aside testing on the public part of xTS.

◧◩◪
3. yaro33+lT[view] [source] 2025-12-06 21:43:33
>>luca02+4M
Yep. And GrapheneOS's changes to the kernels of devices they ship are laughably small, 20-30 commits at most. I don't think they even do any basic CVE checks on any of the source code.

Fuzzing, actual security analysis - all those things are done by Google.

[go to top]