Privacy heavily depends on security. GrapheneOS greatly improves both privacy/security patches and privacy/security protections. The sole reason for the focus on security in GrapheneOS is because it's a privacy project. It has no other reason to work on security.
Android 17 was released in June 2026 and has been required for full standard Android privacy and security patches since then. Only a subset of the patches Google deems to be High or Critical severity are backported. Keeping up with the standard backports and major updates is important but increasingly inadequate.
A sufficiently motivated threat actor will have them (the exploits) too.
Motorola will be working towards providing the same thing as part of our partnership with them, but we're starting out with the high end flagship devices due to those currently being required for it.
I don't understand why it took LineageOS so long to update to AOSP 17, while GrapheneOS managed to update to 17 in just 3 days. LineageOS really should be based directly on GrapheneOS.
Here's a hint: GrapheneOS has paid developers working on it full-time, while LineageOS is done by people in their spare time. Also, GrapheneOS has a collaboration with Motorola and through that gets for instance early access to security patches, and probably other things as well. And lastly, LineageOS supports roughly 10x the number of devices. It's significantly easier if you restrict yourself to Pixels.
Just for clarification (your points are very valid): the GrapheneOS developers have stated on several occasions that they getting embargoed patches from another OEM than Motorola.
GrapheneOS does not have circle battery.
> LineageOS really should be based directly on GrapheneOS.
What would that achieve?
LOS => most security, most usability, breadth of support
It’s a bit more annoying but also isolates stuff like photos etc. by default, so you don’t have to think about it.
- secure app spawning (huge because without it, many hardening improvements are useless)
- extremely secure memory allocator
- fully enabled MTE on shiba and newer
- relockable bootloader
- stronger forensics resistance
- more trustworthy developers (ever heard of LOSCoins?)
- rapid support for new Pixels
- lightning fast security updates faster than most OEMs/ODMs
- built-in TTS without GMS
- real GMS that isn't priv-app
and so much more
Anyways, since you're here perhaps you can answer my question from the other subthread: If I flash GOS and then flash Magisk on it, how hard is it to stay unbricked? Is it as easy as declining to relock the bootloader once, or is the system going to actively fight me on every boot?
Although as an extension of that - I'm hesitant to use software written by people with such a philosophical difference. It might work today, but I wouldn't trust it to work tomorrow.