upvote
Contact Scopes and Storage Scopes are a small subset of the privacy features provided by GrapheneOS. It's also adding major privacy improvements on a regular basis including the recently added secure paste feature and ongoing fixes for upstream Android VPN leaks. There are many other privacy features beyond those.

Privacy heavily depends on security. GrapheneOS greatly improves both privacy/security patches and privacy/security protections. The sole reason for the focus on security in GrapheneOS is because it's a privacy project. It has no other reason to work on security.

Android 17 was released in June 2026 and has been required for full standard Android privacy and security patches since then. Only a subset of the patches Google deems to be High or Critical severity are backported. Keeping up with the standard backports and major updates is important but increasingly inadequate.

reply
Don't forget proprietary security patches are only open sourced 3 months after -- GOS has them due to their partnership with Motorola.

A sufficiently motivated threat actor will have them (the exploits) too.

reply
GrapheneOS doesn't receive early access to security patches via Motorola. We receive those through a different partner. We were already doing security preview releases prior to Motorola giving us access to their repositories which don't contain those.
reply
deleted
reply
It's optional.
reply
Unless you are using the most expensive flagship of a few Android brands, you are also vulnerable anyways
reply
Pixels provide the same security features and updates for the budget 'a' series devices as the regular ones. Pixel 8a is one of the recommended devices for GrapheneOS since it still meets all the current era security standards and still has over 4.5 years of updates remaining despite being 3 generations old due to starting with 7 and launching after the initial set of 8th gen devices.

Motorola will be working towards providing the same thing as part of our partnership with them, but we're starting out with the high end flagship devices due to those currently being required for it.

reply
Interesting, I didn't know about that. Props to Google for bringing the security updates for the cheaper devices as well.
reply
I'm definitely open to trading some security/privacy features in favour of some QoL features Lineage had last time I used it - moving the clock back to the right (where persistent notifications belong) and power button for flashlight. It's a shame this has to be a "or" but as I use a burner phone when crossing borders anyway...
reply
GrapheneOS actually feels just like LineageOS, except that it has faster upstream updates, better security, and greater usability...

I don't understand why it took LineageOS so long to update to AOSP 17, while GrapheneOS managed to update to 17 in just 3 days. LineageOS really should be based directly on GrapheneOS.

reply
> I don't understand why it took LineageOS so long to update to AOSP 17, while GrapheneOS managed to update to 17 in just 3 days.

Here's a hint: GrapheneOS has paid developers working on it full-time, while LineageOS is done by people in their spare time. Also, GrapheneOS has a collaboration with Motorola and through that gets for instance early access to security patches, and probably other things as well. And lastly, LineageOS supports roughly 10x the number of devices. It's significantly easier if you restrict yourself to Pixels.

reply
GrapheneOS doesn't receive early access to security patches via Motorola. We receive those through a different partner. We were already doing security preview releases prior to Motorola giving us access to their repositories which don't contain those.
reply
Also, GrapheneOS has a collaboration with Motorola and through that gets for instance early access to security patches, and probably other things as well.

Just for clarification (your points are very valid): the GrapheneOS developers have stated on several occasions that they getting embargoed patches from another OEM than Motorola.

reply
LineageOS code can update pretty fast, but the problem is they want to do refactors, and also that bringing up a hundred outdated devices is difficult.
reply
GrapheneOs is limited to some specific devices, LOS is all about supporting as much hardware as possible. Theybhave different target
reply
> I don't understand why it took LineageOS so long to update to AOSP 17, while GrapheneOS managed to update to 17 in just 3 days.

GrapheneOS does not have circle battery.

> LineageOS really should be based directly on GrapheneOS.

What would that achieve?

reply
GOS => security, usability

LOS => most security, most usability, breadth of support

reply
Actually LineageOS has less usability due to AOSP bugs, no GMS, unlocked boot loader, etc. The weak security is cost of wide support.
reply
Could you explain how the ability to unlock a bootloader makes a device less usable?
reply
I think they are referring to that LineageOS by and large (there are probably exceptions) does not have support for relocking the bootloader. Some apps refuse to work with an unlocked bootloader (but there are ways around it).
reply
GrapheneOS has even less usability on my Oneplus 7T Pro, in fact it has none
reply
i'm fine with that "less security" as my threat model does not include crossing the US border.
reply
You're conflating local data extraction with security vulnerabilities remotely exploitable via WhatsApp or RCE du jour. Don't.
reply
GrapheneOS is significantly more private, secure, and usable than LineageOS.
reply
While not great, a private space or work profile with Shelter can work in a a pinch. I use it e.g. WhatsApp, where I just need three people, but which is almost unusable if you don’t give it the permission.

It’s a bit more annoying but also isolates stuff like photos etc. by default, so you don’t have to think about it.

reply
You're losing a lot more than that:

- secure app spawning (huge because without it, many hardening improvements are useless)

- extremely secure memory allocator

- fully enabled MTE on shiba and newer

- relockable bootloader

- stronger forensics resistance

- more trustworthy developers (ever heard of LOSCoins?)

- rapid support for new Pixels

- lightning fast security updates faster than most OEMs/ODMs

- built-in TTS without GMS

- real GMS that isn't priv-app

and so much more

reply
What a weird take. I see it the other way round: if you can run GrapheneOS, run GrapheneOS, period. If you can't, then there is a really cool project called LineageOS that you probably can run, and you should look into it :-).
reply
It's not quite that simple. I don't use GOS because GOS and I have mutually incompatible views of user control. I prefer that I control my phone, they say I can't be trusted with that.
reply
That's an inaccurate portrayal of our approach and especially how it compares to LineageOS. LineageOS does not provide app or user accessible root accessible either. As a counterexample to your narrative, GrapheneOS provides full manual and automatic call recording functionality internationally while LineageOS restricts it based on region.
reply
It's really not; you've argued extensively with me that the moment a user can run an app with root the whole system is insecure. LOS sadly doesn't ship anything but `adb root` by default (although... they do that, so yes they do ship "user accessible root"), but they're still less hostile about it.

Anyways, since you're here perhaps you can answer my question from the other subthread: If I flash GOS and then flash Magisk on it, how hard is it to stay unbricked? Is it as easy as declining to relock the bootloader once, or is the system going to actively fight me on every boot?

reply
Indeed, LineageOS doesn't officially support rooting *at all* anymore. They also ban Magisk from their communities IIRC.
reply
In which ways does GOS not let you control your device? I'm curious because to me intalling GOS felt very liberating (compared to stock)
reply
I'm mostly talking about their stance on root. Certainly I agree GOS is vastly better than stock.
reply
You can root Graphene. It's not something the developers condone as it breaks their view of security, but it can be done.
reply
I suppose it depends how hard it tries to relock the bootloader; if I can tell it once to not do that then perhaps it's fine, but I don't want to risk a misclick soft bricking the device.

Although as an extension of that - I'm hesitant to use software written by people with such a philosophical difference. It might work today, but I wouldn't trust it to work tomorrow.

reply
Same thing can be said for LineageOS too.
reply
Yes this is probably a good summary. If you have a fairly recent Pixel, there is probably no reason to pick Lineage over Graphene. But Lineage covers far more devices and device types, including ancient ones.
reply
deleted
reply