GrapheneOS Overhauled Default Apps and Secure Clipboard

(grapheneos.social)

210 points | by Cider9986 6 hours ago ago

137 comments

  • cwillu 2 hours ago

    “We'll be making a new release later today with a completely overhauled user interface written in ‹whatever›” is something developers love, and users fear.

    • grapheneos an hour ago

      Saying it's going to be released later today means to the Alpha channel. GrapheneOS and each of our apps have Alpha, Beta and Stable channels. Every Stable channel release made it through Alpha and Beta channel testing. We don't expect the initial Messaging app release to reach the Stable channel. AOSP Messaging hasn't been actively developed since around Android 5.x and nearly no one is going to be unhappy with the changes.

      We're changing very little about the overall layout and structure of the app in this initial phase of the overhaul. Over the past couple months, it was carefully ported to Compose with a lot of code review and added tests. It was a lot of work and is going to look a lot more modern. It's also now possible to greatly improve the user interface in much more substantial ways than making it look modern.

    • HybridStatAnim8 44 minutes ago

      If you have used GrapheneOS, you know Messaging is positively ancient and bitrotting. The overhaul makes it look like the rest of the OS and uses standard material 3. Its not something to fear.

    • chasil an hour ago

      LineageOS keyboard and the Trebuchet launcher would be most helpful.

      I do miss keyboard symbols without shifting and icon packs.

  • pizzaiolo 4 hours ago

    Graphene is clearly bullish on Android, but I have no idea why. The writing is on the wall, Google is slowly asphyxiating AOSP.

    • mitxela an hour ago

      Apps are written for android. Graphene can run all the apps because it's android. If it couldn't run apps, you wouldn't use it. Are you posting today from a pinephone?

      • Crestwave an hour ago

        Their post history has several posts related to PostmarketOS on the Fairphone, so kind of, possibly? pmOS does have Waydroid to run Android apps, though, which also relies on AOSP.

        • grapheneos 41 minutes ago

          Waydroid can't run nearly as many Android apps as AOSP on bare metal or especially GrapheneOS with the compatibility features it provides. It's an approach with far more limited compatibility.

          Waydroid has very poor privacy and security due to disabling most of the app sandbox. It's also based on an old version of LineageOS so it's missing many important privacy/security updates, but it's much more relevant that it doesn't have SELinux and exposes much more kernel attack surface to apps. SELinux is not an extra layer of security for Android but rather is used in a far more deeply integrated way than any typical desktop/server usage. It's a huge portion of the security model including the app sandbox and protecting the Linux kernel.

          We greatly prefer virtual machines over a half-baked container approach disabling most of the privacy/security model. There's already hardware accelerated virtualization on all of the supported devices for GrapheneOS and we plan to make a lot more use of that in the future.

    • kllrnohj 2 hours ago

      So what should they do instead? Just give up? Assume that it's simply inevitable that Google will cancel AOSP entirely and so Graphene should hurry up and die?

    • ConceitedCode 3 hours ago

      What's the concern? They are working with Motorola as a manufacturer. It'll probably be a hard fork eventually but why not make it work in the meantime.

      • qurren 3 hours ago

        If they hard fork, a lot of apps that are generally "necessary for the average person" (e.g. Uber, banking apps, Gmail, Whatsapp/Wechat/Line) might stop working.

        • ConceitedCode 2 hours ago

          Sure, but what could graphene do in the meantime? It's either make it work for the moment or stop those apps from working today.

          I'd like to see them lay more ground work for web apps but it's a tough spot and the easiest choice at the moment is to continue with AOSP.

          • mitxela an hour ago

            I don't want to see more groundwork for web apps. GrapheneOS is meant to be secure, which means running trusted apps on-device. My messages are less secure if they permanently are stored on a server.

          • qurren 2 hours ago

            I mean we privacy nerds all love webapps but the reality is the people actually in charge of S&P500 companies hate them. They really, REALLY want to fingerprint your device and use it as a verification and tracking mechanism.

            Until that changes, webapps aren't going to sell.

            Even Google tried multiple things to "sell" the idea of webapps (e.g. Polymer project) in 2011-2015 and failed.

            Funny enough, Wechat kinda succeeded at webapps in China because there's a strong user preference to stay inside one monolithic "everything app".

            • bentley an hour ago

              I find, as a user primarily of free and open source software, it’s really the opposite: native FOSS apps have minimal tracking and analytics that defaults to off or is easily disabled, while most free and open source webapps are behind Cloudflare, blocking access to them until I turn off my VPN and disable the anti‐fingerprinting features in my browser.

      • wolvoleo 3 hours ago

        Seriously, I don't see a mediocre android provider like Motorola running and maintaining a hard fork.

        Forking is all easy, keeping it up to date year after year as codebases diverge is a whole different story.

        I could see Samsung doing it. But they won't, they're too good buddies with Google. But they have the resources. A Motorola no. The grapheneos team won't either, maintaining a disparate fork and introducing new features independently from aosp would just be beyond their scope. You're not just hardening at that point. You're basically doing everything.

        Don't forget when Huawei didn't fork. Well they started with that but then replaced every component with their own design. It's easier because if you fork you're still bound by decisions made by the original party. Better to greenfield the whole thing then.

        And look at how many people made a soft fork of chrome with some ui changes. There's tons of those. There's no hard fork that no longer follows Google. Even a large company like Microsoft didn't.

        • ConceitedCode 3 hours ago

          I think graphene could maintain a hard fork with manufacturer support (Motorola). At least for a while. Long term viability is an open question.

          • wolvoleo 2 hours ago

            They could for a while but what's the point if it's not sustainable? Google is not going to turn around and make it more open again.

            With every Android release you will build up more feature base to replicate. Unless you cut all ties and drive a separate ecosystem but good luck getting enough developers to buy into that.

            • unrented7977 an hour ago

              And the US might grow a government with a spine and take Android away from Google. It's all hypothetical.

      • matheusmoreira 3 hours ago

        The concern is AOSP engineers see them as annoying complainers.

        https://news.ycombinator.com/item?id=49537268

        There's clearly some kind of situation brewing here. Hopefully the GPL proves to be enough to keep code in the hands of GrapheneOS developers.

        • wolvoleo 3 hours ago

          They basically have opposite goals to Google so I don't imagine there will every be good feelings there. There shouldn't be.

          Yes Google wants android to be secure, but the problem is that to be truly secure it should be secure from Google too. And they don't want that. They want it to be their personal datamine and walled garden. Just like Apple with ios.

        • Cider9986 an hour ago

          One AOSP engineer.

          Google is the one making bad actions, which it makes sense to complain about. They moved to building in private so forks don't get features as they come and more recently they stopped providing certain source code in a timely manner.

    • tgsovlerkhgsel 2 hours ago

      There is no alternative.

      Apple isn't going to let them build on top of iOS, and anything except those two is dead in the water because it'll never have users because it is missing a bunch of critical apps, and will never have those apps because it doesn't have users.

      • wolvoleo 2 hours ago

        Remember when we thought IE's monopoly could never be broken? Or windows?

        Anything can and will go down. Nothing is forever.

        • ryan_lane 2 hours ago

          IE's monopoly was replaced by Chrome and Safari's, and Safari only exists because Apple gives you no choice but to use it on iOS. Firefox had a brief spot on top, but it really didn't last that long.

          Windows still has the vast majority share of desktop.

          • mitxela an hour ago

            Chrome is the outlier there. It didn't come with any desktop OS and still got near 100% market share, even before Android contributed to that. How? It's worth studying.

            • unrented7977 an hour ago

              The made the best browser on the planet in Google's Bell Labs era and then they used it as leverage during their "do evil" era.

          • wolvoleo an hour ago

            Yes but that's my point. Monopolies don't last. We have other ones now yes. But that's because the earlier ones died.

            And yes we still have windows as the major desktop OS but don't forget, in the 90s/early 2000s windows was equivalent to computing.

            These days the desktop OS is much less relevant than it was and many people don't even own a laptop or desktop anymore. They just do everything on their phone. And Microsoft totally and completely lost that race.

      • GeekyBear 2 hours ago

        > There is no alternative.

        There have been several projects like Ubuntu Touch to create an open Linux for smartphones.

        That would be an open alternative.

        Android is not open.

        • HybridStatAnim8 40 minutes ago

          The AOSP is fully open source. What you suggest is a significant step back in terms of privacy and security.

      • yndoendo 2 hours ago

        FuriLabs makes a Linux phone that is designed as a daily driver. Looking at it to replace Android.

        • MrDrMcCoy an hour ago

          I have it. It's far too slow to be useful, and it's not the hardware's fault. GTK and Libhybris are bad separately and hot garbage together. This problem won't be going away while the hardware is relevant.

    • NewJazz 3 hours ago

      Yes RCS is barely a standard worth implementing, let alone the best one. Make SMS/MMS and XMPP work together seamlessly in one app, forget RCS.

      • grapheneos 34 minutes ago

        It's important for us to provide out-of-the-box end-to-end encrypted (E2EE) messaging for contacts on Google Messages and iOS. Both Google Messages and iOS provide RCS with end-to-end encryption via Messaging Layer Security (MLS). Google Messages is the standard text messaging app on Google Mobile Services Android and iOS now also supports RCS with MLS. The vast majority of people have an E2EE messaging app on their smartphone and it's important for us to provide compatibility with it. Currently, a growing number of our users are installing Google Messages to have better usability and privacy for texting with contacts on Google Messages and iOS.

        People can already install the messaging apps of their choice on GrapheneOS. It would go against our approach to choose specific messaging apps and protocols to bundle with the OS beyond SMS/MMS/RCS. We shouldn't be the ones choosing Signal vs. SimpleX vs. Element or other options but rather that's up to users to decide. We need a messaging app to handle carrier-based messaging in the OS including providing end-to-end encryption for it and the rest is up to other open source developers.

      • wolvoleo 3 hours ago

        Yes RCS is a pig with lipstick. Invented by the carriers to recoup some control over instant messaging, then abandoned and picked up by Google for the same reason. They're the ones that added encryption to it.

        It was always meant to be a walled garden. Exactly what an open system shouldn't be.

        • grapheneos 33 minutes ago

          RCS is important because it provides end-to-end encryption (E2EE) for contacts with Google Messages and iOS. That means having E2EE for the vast majority of smartphone users since Google Messages is the standard GMS Android carrier-based messaging app.

          https://news.ycombinator.com/item?id=49593026

      • Geezus_42 3 hours ago

        Remember Pidgin and Trillium?

        • DANmode 2 hours ago

          I remember who forced me to consider other options.

    • Cider9986 an hour ago

      Have you used GrapheneOS? It's fantastic UX[1] and while probably being one of if not the most secure and private OS available.

      [1] thanks to Android (once you replace some of the worse default apps, but they are doing that as we can see)

    • palata 3 hours ago

      They may as well get ready for an eventual hard fork, then?

    • DANmode 2 hours ago

      > Graphene is clearly bullish on Android, but I have no idea why.

      Their resources are historically better spent hardening vs literally reinventing the wheel.

      Multiple variables in that equation have changed - so it could be interesting where we end up.

      Someone (else!) may yet arise chasing their stated model without Android, as well.

    • dataflow 3 hours ago

      Perhaps they're hoping to get significant market share before they lose the opportunity for good?

  • lucb1e 4 hours ago

    Ctrl+f clipboard, no results. What does "Secure Clipboard" in the title refer to?

    The release seems to be only the SMS/RCS app, rest is future:

    > We're also going to be overhauling or fully replacing the rest of the AOSP apps in the near future. AOSP Gallery is incredibly outdated and is being entirely replaced. AOSP Keyboard may be similar. We recently hired a bunch of new people and will be hiring more so our progress will be accelerating.

  • ravenstine 4 hours ago

    I hope they replace the AOSP keyboard with FUTO keyboard. I'm mostly fine with the other stock apps, but that keyboard was the one thing I absolutely had to end up replacing due to its jenky behavior.

    • Cider9986 4 hours ago

      I agree FUTO is the best right now but it's not open source so they won't.

      • Groxx 3 hours ago

        The source is here: https://gitlab.futo.org/keyboard/latinime

        Featured prominently in the "Source Code" container on https://keyboard.futo.tech/

        AFAIK everything FUTO makes is open source? I haven't seen a counter-example (I have not looked hard though!), and https://futo.tech/about claims the following:

        >All FUTO-funded projects are expected to be open source or develop a plan to eventually become so. No effort will ever be taken to hide from the people what their computers are doing, to limit how they use them, or to modify their behavior through their software.

        • mrob 3 hours ago

          From the LICENSE file:

          https://gitlab.futo.org/keyboard/latinime/-/blob/master/LICE...

          >You may modify the software only for non-commercial purposes such as personal use for research, experiment, and testing for the benefit of public knowledge, personal study, private entertainment, hobby projects, amateur pursuits, or religious observance, all without any anticipated commercial application.

          Violates clause 3 (Derived Works) and clause 6 (No Discrimination Against Fields of Endeavor) of the Open Source Definition [0].

          >You may distribute the software or any part of its source code only if you do so free of charge for non-commercial purposes.

          Violates clause 1 (Free Redistribution) and clause 6.

          >Notwithstanding the above, you may not remove or obscure any functionality in the software related to payment to the Licensor in any copy you distribute to others.

          Violates clause 3.

          It is a "source available" license, not Open Source.

          [0] https://opensource.org/osd

          • Groxx 2 hours ago

            Ah, yeah, agreed - "source available" fits that much better. I'm pretty sure that's the same for immich (which is also from FUTO).

            Thank you for the details! That lays it out nicely for anyone else passing through.

        • idle_zealot 3 hours ago

          https://gitlab.futo.org/keyboard/latinime/-/blob/master/LICE...

          It is not open source. They use a custom source available license. There's no way any Android distribution would include it. A layman's reading is that FUTO could claim license violation on account of the distribution accepting donations (non-commercial use only) and there's a weird clause about not accusing FUTO of patent infringement.

          • mitxela an hour ago

            Alternatively they could ask FUTO for a commercial license.

            • HybridStatAnim8 39 minutes ago

              Maybe, but there are better candidates GrapheneOS is more interested in.

        • jazzyjackson 3 hours ago

          Right, they are adhering to a definition of open that includes free as in liberty, so licensing matters. What good is it to read the source if I don’t have rights to modify and redistribute?

    • broodbucket 3 hours ago

      I use Gboard with the network permission disabled. It works well but I hope they have a better stock keyboard, I haven't found any others that don't annoy me in one way or another.

      • MrDrMcCoy an hour ago

        The latest FUTO works just as well as Gboard for me. Their somewhat recent update to their swiping library really changed the game, and their voice recognition is also pretty decent.

    • Geezus_42 2 hours ago

      I wish Futo had the ability to use a typing heat map for more accurate predictions like SwiftKey. It constantly suggests "AMD" when I am trying to type "and". I have fat thumbs OK! I don't even have the caps on and I RARELY talk about AMD. It's just the one thing I miss. I do find the predictions generally less accurate as well, but perfectly usable.

    • HybridStatAnim8 39 minutes ago

      They cannot. The license FUTO uses is not open source and is incompatible with being bundled with GrapheneOS.

    • dsr_ 4 hours ago

      Heliboard is good, customizable, and actually open source - GPL3.

      • HybridStatAnim8 37 minutes ago

        If you are referring to Heliboard as an AOSP board replacement, that cannot work, GrapheneOS cannot use GPLv3 projects.

        If you mean it as a user installed app, please disregard.

      • sublinear 3 hours ago

        I like Heliboard a lot, but its autocorrect gets stuck in the mud all the time.

        It completely falls apart and starts injecting nonsense phrases made up of nonsense misspelled words moment you miss a space ('v' or 'b') or type a really long word it doesn't know.

        It also stubbornly incorrects other things like 'a' into "and" if it thinks it knows a phrase fragment. It's always wrong. It just happened to me now twice. Above, "or type a" became "or type and". Also, "it's" became "IRS".

        Heliboard would be perfect if it stuck to word-only spellcheck and never split words. Just now again, it tried correcting "heliboard" into "hellenized" and "he lib oars".

        This is not a matter of just lowering how aggressive the spellcheck is. It will still generate slop every time. The only real option is to completely turn it off. Futo can have similar problems, but there are a lot more options to tweak and the defaults aren't so bad.

        • NewJazz 3 hours ago

          I turn off automatic autocorrect except for "I". I can use it manually when I need it (jot often).

        • armadyl 3 hours ago

          this was my experience. the autocorrect for heliboard is beyond atrocious and renders the keyboard unusable.

          i ended up just using gboard on gos because every other one i tried fell short.

          hopefully the stock gos one can be reworked into an actually decent keyboard.

    • matheusmoreira 3 hours ago

      Why not Unexpected Keyboard?

  • goda90 5 hours ago

    I believe this is the planned gallery app. I've already been using it: https://github.com/IacobIonut01/ReFra

    • aussieguy1234 3 hours ago

      Just tried this out. I may soon be cancelling by Google Photos subscription...

      • ticoombs 36 minutes ago

        While you're doing that check out Immich - https://immich.app

        One of the best solutions I've ever used for photos, backups, enrichment, etc

  • Cider9986 6 hours ago
  • drnick1 4 hours ago

    Certainly, with Opus 5 and GPT-6, modernizing or even completely rewriting self-contained, non-critical tools seems like a Friday afternoon job now. I wonder however how important this is, in the grand scheme of things. I use GrapheneOS and the bundled messaging app is serviceable. It isn't pretty, but it gets the job done.

    • grapheneos an hour ago

      We're definitely not churning out code with AI models. There's no vibe coding going on in GrapheneOS. We're carefully writing and reviewing code as we've always done. We now have additional tools to assist with it. The main way we're using AI models is for code review and helping to write a lot more tests than we used to. It's helping to improve our code quality, not reducing it. We're not trying to get things done substantially faster.

      The code generated by even the bleeding edge publicly available frontier models is rarely good enough to meet our standards. AI models are creating a lot of additional work for us because of how many more security issues are being discovered in upstream projects. It's also helping us raise our standards for our own work by pointing it at that to get extremely pedantic criticism catching many things we would miss.

      We've hired multiple experienced app developers who have spent months working on modernizing the Messaging app and carefully reviewing it. There's no vibe coding going on for our apps. Why not look at the actual process of porting Messaging to Compose and our code review for each incremental part of the process?

      https://github.com/GrapheneOS/Messaging/pulls?q=is%3Apr+is%3...

    • Cider9986 4 hours ago

      They are using AI [1]. I don't think messaging app is non-critical though.

      [1] https://github.com/GrapheneOS/Camera/tree/compose

      • grapheneos an hour ago

        Our port of Messaging to Compose was clearly not vibe coded as both the parent comment and yours are wrongly portraying it. Experienced developers have been working on overhauling the app for months with a lot of back and forth code review to get the pull requests into shape. We don't have a policy against using AI for assistance as long as the resulting code meets our high standards.

        We definitely use frontier AI models with cybersecurity access unlocked for code review. Those often find problems we didn't catch via multiple rounds of human review. The output is filled with hallucinations and incorrect details but an experienced developer can sift through it, identify the real issues it uncovered and get those fixed.

        • Cider9986 33 minutes ago

          How did my comment portray your port as you are vibecoding it? I just said that AI is being used.

          It seems obvious to me that you guys would use it responsibly.

      • BearOso 2 hours ago

        I dunno. If they're using AI, it's well controlled. I don't see a lot of artifacts you usually get from full-on vibe-coding.

        • grapheneos an hour ago

          Our code quality standards are very high. Vibe coding is not capable of meeting those standards. The details of how things get written and improved to meet our standards is up to individual developers. We don't have a policy against developers using AI for assistance. They need to understand all of the code and it needs to pass our code review. Our code review is now usually a lot more thorough than before. In addition to human review, we regularly pass code through a couple frontier AI models and then review the results to figure out which claims it makes are valid. Even the frontier models hallucinate many non-existent problems and often get a lot of details wrong when they find real problems, but they do find a lot of real problems.

          https://news.ycombinator.com/item?id=49592770

  • kotaKat 6 hours ago

    "RCS isn't an open platform in practice. It isn't even as open as SMS/MMS. It heavily depends on proprietary Google and carrier infrastructure in practice. We can start by replicating Google's approach and then we can work on only using carrier services for carriers where it's actually supported."

    Except... what carriers still remain using their own RCS carrier services and haven't been pressured by Google to adopt Jive?

    • benwaffle an hour ago

      None except Jio in India and various carriers in China

  • exceptione 6 hours ago

      > RCS isn't an open platform in practice. It isn't even as open as SMS/MMS. It heavily depends on proprietary Google and carrier infrastructure in practice. We can start by replicating Google's approach and then we can work on only using carrier services for carriers where it's actually supported.
    
    What is the point of RCS though? It seems to be strictly inferior to Signal. It seems a Google product meant to serve Google. I wouldn't hate it if GrapheneOS would totally ignore RCS. I fail to see any value in it, but maybe I am lacking information(?)
    • cosmic_cheese 5 hours ago

      RCS was DOA from day one as far as I'm concerned. The carriers being involved in any capacity deeper than providing dumb pipes alone was enough to make it pointless, but no E2E in the base spec makes it extra pointless. They may as well have just extended SMS to be more capable, because that's what they've effectively created.

      • glub 2 hours ago

        I don't know much about RCS other than that carriers need to be involved, but there's a way to not involve them, which Google did for a while using some kind of compat-service (jibe or something?), and then they stopped doing it.

        Never seen RCS working on any carrier ever since. I don't understand why Google couldn't just continue doing what it was doing. Why require carriers?

        • mitxela an hour ago

          The intended purpose of RCS was to be federated between carriers, just like SMS. If you centralise it then it's just a worse version of any of Google's abandoned chat apps. But there's a realpolitik reason to insist on centralised RCS: because it's already got the reputation of decentralisation, it makes it look like Google is better than it actually is.

          • glub an hour ago

            > The intended purpose of RCS was to be federated between carriers, just like SMS.

            Oof, so it was essentially destined to fail when the spec was being written.

            • mitxela 5 minutes ago

              Did SMS fail? Sort of, as it's rarely used, but also not, because it continues to work and it's still the only federated messaging system you can rely on being available on your phone (besides phone calls).

      • HybridStatAnim8 4 hours ago

        The RCS spec has encryption in its documentation. I think the current spec version is 4.0?

        • jazzyjackson an hour ago

          Yes but there are different specs that “compatible” apps will have to adhere to, basically until everyone is always running auto updating software to the latest version supporting RCS 4.0

          Long story short somebody preferred to “ship it” instead of waiting to figure out how to make encryption compatible between iOS and Android. I guess there’s some differences in how the key rings work, but Signal can figure it out and /they’re/ open source so it sucks they ever supported unencrypted messages. They just wanted to say it technically worked for rich text messages and reactions.

        • Groxx 2 hours ago

          It has it in its current documentation (maybe 3.0 too? I forget, but it's new this year), and Apple and Google have had messages to themselves encrypted for a while (but not to each other, which is what the RCS docs are intended to resolve). It took many years to get it documented though (despite loudly claiming RCS is more secure the whole time), and AFAIK none yet implement it. Definitely none with all the documented things it needs to show to be compliant with the spec I read, e.g. key verification - I certainly don't see any of that in Google's "Messages" app! Though hopefully that will all change.

          But honestly, in a non-open ecosystem, can you really trust that the near-exclusive two major players are actually playing by the rules? Apple has been relatively protective of its users on privacy stuff, but I've lost all trust in Google at this point.

        • bronson 2 hours ago

          Almost none of my RCS conversations are encrypted. Who cares what's in the spec if nobody uses it?

    • fc417fc802 5 hours ago

      The point of the exercise is for Google and Apple to maintain control over the ecosystem.

      RCS is technically superior (protocol, transport, security, all of it) but is captured from the start on the technical level by design by the big players. From the perspective of the vast majority of users who have very limited technical awareness, it was silently slipped in as an upgrade at one point or another. This means that those not adopting the proprietary BigTech solution are perceived as being difficult by insisting on using software that's now perceived as outdated or as otherwise mildly incompatible.

      • HybridStatAnim8 5 hours ago

        GrapheneOS does not want to adopt RCS for public perception. It is still a better option than SMS/MMS and providing it is beneficial. GrapheneOS will still recommend using better platforms and protocols but RCS being bundled and cross platform are great reasons to implement it.

      • george_perez 4 hours ago

        Eh, I don’t think you have to include Apple here. If it were up to them, the iPhone would still have zero RCS support right now. The current implementation of RCS, even in iOS 27 beta, is clunky.

        To me, the only they’re trying to maintain control of is AppleOS-to-AppleOS text communication.

        • fc417fc802 3 hours ago

          > To me, the only they’re trying to maintain control of is AppleOS-to-AppleOS text communication.

          Yes, exactly. Apple and Google are both acting to maintain control and this has resulted in a standard that improves functionality but is effectively poisoned at the technical level. Left to their own devices I'm sure Apple would have preferred to stay with their original solution that is even more closed off.

        • anon7000 4 hours ago

          Idk, I mean RCS on iPhone is just SMS/MMS but fixing like 90% of the issues. I don’t find it that clunky.

    • ebb_earl_co 5 hours ago

      From [0], it seems that RCS can use the cellular signal instead of LTE or 5G:

      > In cases where RCS is able to operate over cellular networks without data, it supports messaging as well as file transfer, enriched calling, and more.

      [0]: https://en.wikipedia.org/wiki/Rich_Communication_Services

      • wolvoleo 3 hours ago

        In LTE and 5G there exists no cellular signal without data. That was a 2G/3G thing. Since 4G everything is data. The separate sms and voice services are gone. And 3G is rapidly being deprecated.

        • MrDrMcCoy an hour ago

          That's not quite true. VoLTE was an optional part of 4G in the beginning. I had one of the gaming ASUS phones that shipped with 4G, but no VoLTE. 6 months after getting it, the US phone carriers conspired to make VoLTE mandatory for connecting to their towers, effectively bricking my device. ASUS never issued the firmware update that would have enabled the feature in the modem, which had the capability, and the community hack to enable it never worked for me.

    • mitxela an hour ago

      I believe it was meant to be federated, like SMS, and then in practice it wasn't. With Signal you depend on your carrier and on Signal - with SMS you only depend on your carrier.

    • HybridStatAnim8 4 hours ago

      The point is to access an e2ee protocol bundled by default on many devices, and is cross-platform.

      GrapheneOS does recommend using superior platforms like Signal, but that is 3rd party, and thus has adoptability issues in convincing people to use it. Just because better platforms exist does not mean RCS should be ignored.

      • exceptione 4 hours ago

        Thanks for clarification. Anything first party from Big Tech is a lost cause privacy wise. At the same time, nobody uses it (maybe that is different in the USA, don't know). So for me this would be ultra-low prio as I (and I expect almost every other GOS user) will never use it. But I believe GOS knows what it is doing.

        • HybridStatAnim8 27 minutes ago

          I assume many people would use it due to SMS concerns and difficulty having people move to other platforms. I would personally use it as a fallback to Signal since my current fallback is SMS, which I dont like.

          If the protocol is properly e2ee, it does not matter who backs it or hosts it. GrapheneOS would be in control of the client which is what matters in an e2ee system.

        • annzabelle 4 hours ago

          Nearly everybody uses it in the USA. It's very common to text people through the default messaging app on your phone there (probably an outgrowth of the popularity of iPhones and iMessage), and backup options would be Instagram, Snapchat for a certain demographic, or Facebook messages. Whatsapp is only for messaging foreigners, and Signal/Telegram are for messaging your drug dealer.

          • SoftTalker 4 hours ago

            Yep, I have never used anything other than the stock messaging app that came with the phone. Whether that's SMS, iMessage, or whatever has never crossed my mind

          • michael-bey 3 hours ago

            I was really disappointed when Signal went away from being used as an "everything" messenger, including regular SMS. I onboarded all my family and now because it's not a default messenger, nobody is using it.

        • nemomarx 4 hours ago

          In the US everyone with an iphone uses RCS, so you'll often have family group conversations on it and so on. Whatsapp or signal are comparatively rare (although more common for anyone with overseas family naturally)

          • bronson an hour ago

            No, in the US, everyone with an iphone uses imessage. (Basically all my family's messaging goes over imessage) It's only when non-iphone users are on the chat that RCS comes into play.

    • hollow-moe 3 hours ago

      RCS's point is to deliver ads. It is its first purpose. The way I see the situation, the point for Graphene to implement RCS is to prepare for the foreseeable deprecation of SMS. Who knows when it will happen, but better start working now than wait and get stranded when it'll happen. I'm pretty sure RCS implementation will take a long while.

    • kevin_thibedeau 5 hours ago

      RCS allows higher resolution pictures than MMS.

      • cesarb 3 hours ago

        Perhaps it's different in other countries, but I've never seen anyone use MMS. (Everyone uses WhatsApp nowadays, but even before WhatsApp existed, I never saw anyone use MMS.)

        • Telaneo 2 hours ago

          I've seen people try, only for it to never actually work (images either compress horribly, to the point there's no reason even sending it, or just fail to send).

          MMS bring broken since day 1 in my experience is probably the reason I jumped on internet chat and email, since those actually work as advertised (sure, they has some practical limits, but they tell you about those!). I probably would have sent my mum that image over MMS if MMS actually every worked. Since it never did, using a difference service was a must.

          Then again, this feels like an extension of the rest of the phone system. Anything beyond calls between two people, SMS and data that involves connecting to the phone system has always (in my experience) been either janky or broken. No wonder I try to use anything else given the opportunity.

        • Groxx 2 hours ago

          It depends heavily on country, yes. USA is extremely light on WhatsApp, and MMS use is widespread (and has been free for a long time now, and SMS even longer). RCS is a mostly silent upgrade for USA.

          I'm not sure which of the two is better tbh. Utterly dominated by a Facebook-owned system, or using something that's crappy enough that people spread out to a variety of systems?

  • andrepd 5 hours ago

    There are excellent FOSS gallery apps already, like the Fossify suite. Why not use them I wonder?

    • HybridStatAnim8 5 hours ago

      Their license is invalid due to being GPLv3. GPLv3 cannot be included in GrapheneOS as that would necessitate GrapheneOS give up their permissive licensing.

      Refra Gallery is licensed as Apache 2.0, which is a permissive license GrapheneOS can bundle in the OS.

      • graemep 4 hours ago

        Its not part of the OS so why would it affect the Graphene OS license? Its an app, not a library.

        • HybridStatAnim8 32 minutes ago

          The Refra gallery fork would replace the current ancient gallery app. That would be bundled with the OS. Doing the same with the fossify suite or similar would be illegal. These licenses do not treat apps or libraries differently. GPLv3 code forces the code that it is bundled with to also be GPLv3.

        • Cider9986 4 hours ago

          The preinstalled apps are part of the OS.

          • gray_-_wolf 3 hours ago

            That cannot be true, when I install e.g., Ubuntu system, there are plenty of applications installed for me, with incompatible licenses.

            • HybridStatAnim8 31 minutes ago

              It is true, and if Ubuntu is shipping apps as a part of the OS with incompatible licenses, that is a crime.

            • novafunc 3 hours ago

              Can you please elaborate on what you mean?

              Ubuntu does not aim to be a permissively-licensed system. It can include copyleft (e.g. GPL) and permissive (e.g. MIT) without issue.

              Permissively-licensed systems like FreeBSD and GrapheneOS cannot include GPL code if they want to remain permissive.

          • yjftsjthsd-h 3 hours ago

            IANAL, but I would expect that to fall under "mere aggregation"

      • gkoz 4 hours ago

        Can the Linux kernel be included in the OS?

        • HybridStatAnim8 31 minutes ago

          Yes, the GPLv2 license does not have the same restrictions GPLv3 does, it does not necessitate making the code it is bundled with GPLv2.

        • palata 3 hours ago

          Linux is GPLv2, though. Not sure if that makes a difference here.

    • DANmode 2 hours ago

      Media handlers are a security nightmare, might lead you to the right answer if it isn’t it.

  • 0points 3 hours ago

    Maybe I'm old school but

    big announcement

    > We're well into the process of converting the Messaging app included in GrapheneOS into a modern app.

    > We'll be making a new release later today

    Back in my day this would not make for excitement. On the contrary. (We would expect months/years? of release candidates, test releases and such after such big rewrite)

    How come a recognized brand such as GrapheneOS speak like this?

    Have their leadership fallen to AI psychosis too?

    • grapheneos 2 minutes ago

      We've done months of work on overhauling the Messaging app. It has been done in incremental portions with code review for each. It often goes back and forth several times before it gets merged. Why not look at the quite open development and code review process on GitHub?

      https://github.com/GrapheneOS/Messaging/pulls?q=is%3Apr+is%3...

      Every release of GrapheneOS and GrapheneOS apps goes through internal testing followed by public Alpha channel testing and then public Beta channel testing before reaching the Stable channel. No update goes to Stable without internal, Alpha and Beta channel testing phases.

    • HybridStatAnim8 34 minutes ago

      What? The Messages overhaul has been going on in the background for months. They announced it near the end of the port rather than the start. What is wrong with that? It has nothing to do with AI.

      You can check github and see this development has been going on for awhile.

  • IshKebab 6 hours ago

    Very good idea! Google abandoned these long ago.

    I don't really get why so many Americans want RCS to succeed though. Do you guys not remember when carriers charged 10p/text? Why on earth would you want to give any power at all back to those people?

    • Dusseldorf 5 hours ago

      After getting several family group chats finally converted over to RCS, one day my phone just started absolutely refusing to verify my connection to the RCS servers. Instead of any kind of notification, I was just silently not sending or receiving messages for nearly an entire day. I had to disable RCS on my phone, which created a several day long issue where some chats would just fall back to SMS and others absolutely refused to work, or strange interactions with Apple devices where certain messages would not be displayed. After enough trouble with it I convinced everyone to switch to a third party messaging app. I'll never turn RCS on again, I can't trust that it won't just start silently failing.

    • annzabelle 3 hours ago

      Americans have had unlimited texting plans for much longer than Europeans. I'm pretty sure most Americans had unlimited texts before Whatsapp existed, so there was never the move to it for economic reasons.

      • wolvoleo 2 hours ago

        Yes I think this is the main reason for WhatsApp's popularity in Europe. Our providers were hanging on to sms as a cash cow and they were pretty much the most expensive bits you could send.

        Malicious providers like kpn in the Netherlands even sought to charge extra for WhatsApp traffic because they lost so much revenue. However the EU shot that down hard under net neutrality.

        But I remember it well and this is why I always disable RCS. I don't ever want to give my provider the chance to do that again. And I don't trust Google either. SMS is completely dead here too. It's been years since anyone sent me a personal message. It's just spam and poorly implemented 2FA shit.

        It's not an issue here in Spain anyway. The only phone with iPhones are rich expats. Most of the people I know use cheap budget androids.

    • HybridStatAnim8 5 hours ago

      The main benefit of RCS is the fact it is available by default on other platforms like certified android and IOS. 3rd party messaging apps hit adoptability issues. A bundled, cross platform E2EE protocol is a huge step above SMS and MMS.

      Many 3rd party platforms are still better though.

    • goda90 5 hours ago

      It's a bandaid over iMessage's dominance among iOS users.

      • NamTaf 5 hours ago

        Text messages in iMessage or SMS are a fairly US-centric relic. That's not to say overseas is better - Europe depends on Whatsapp - but outside the US the whole 'blue box' thing isn't even a thing.

    • downrightmike 5 hours ago

      The only benefit is sending higher DPI pictures between android and ios

      • annzabelle 3 hours ago

        It makes group messaging work a lot better, too. Previously, group chats with a mixture of ios and android users were really buggy leading to iPhone users significantly preferring group chats with all ios, which led to some social exclusion for android users in the US, leading to market dominance for iPhones. Now, with RCS, you can make a functional group chat across platforms and you don't have to convince anybody to install something new.

        • wolvoleo 3 hours ago

          Well that is if that user uses Google messages. I certainly don't even have it installed.

          • annzabelle 2 hours ago

            If you have a smartphone from the last 5 years, you have to have done something unusual to it to not have an SMS app that also does RCS.

  • thinkp26 6 hours ago

    I'm happy todays update shipped auto call recording.

    • subscribed 3 hours ago

      Yay! Finally, been waiting for it for ages.

      Maybe they'll work on the backup now, this *** seedvault is worse than nothing (consistently broken on both my GOS phones, never giving the same results with 2 backups, never giving out as much as the status I could trust)