GrapheneOS Isn't Happy With Google Over Pixel's Widening Head Start

It's FOSS GrapheneOS Isn't Happy With Google Over Pixel's Widening Head Start
preview

Google’s September 2026 Pixel Update Bulletin contains patches beyond what’s in that month’s regular Android Security Bulletin. According to GrapheneOS, some of those extra patches touch standard Android platform code, the kind that runs on non-Pixel devices, not just Pixel-branded hardware.

None of that platform-level code has reached the regular monthly bulletin or the private preview patches other manufacturers typically draw from to get their own patches ready.

And at this rate, these won’t reach non-Pixel OEMs at all until Android 17 QPR2 ships later this year in December.

The project is characterizing this as Google “gatekeeping security patches to the standard Android platform code from Android OEMs.” The complaints

GrapheneOS says Android 17 QPR1 shipped new developer APIs that never made it into AOSP. This is something they claim hasn’t happened since Android’s Honeycomb days.

Google’s API diff report backs this up. Comparing Android 17 to QPR1 shows one new package, android.hardware.hid, plus changes across sixteen others, including android.media, android.os, android.provider, android.telecom, and android.view.

GrapheneOS has ported its code to QPR1 before Google even released it, but still doesn’t have permission to ship that work. For now, the project is backporting Pixel firmware, kernel drivers, userspace drivers, and HALs from QPR1 onto Android 17 instead.

On top of all that, there’s a compliance issue that seems to be recurring.

Google was slow to comply with a GPL source request. GrapheneOS requested sources for a build (CD1A.260905.001.A1) on September 1, and access only came through more than two weeks later.

Why this is worrying

None of these three issues is catastrophic by itself. A three-month patch delay, a paused API rollout, a two-week wait on source code—each is the kind of thing that could pass as a one-off.

Taken together, however, they point to a recurring theme. Google is holding security fixes back from the wider Android ecosystem, withholding new APIs from AOSP for the first time in over a decade, and slow-walking GPL compliance it’s required to meet.

Don’t even get me started on what they are doing to the Android app ecosystem.

Google is on track to require every Android app developer, whether on the Play Store, F-Droid, or anywhere else, to register with them. Come 2027, that means handing over legal identification and signing key evidence before an app can run on any certified device.

Sideloading an unverified app following this would mean enabling developer settings, waiting through a mandatory 24-hour cooldown, and clicking past several warning screens (classic scare tactics, btw).

GrapheneOS is one of dozens of organizations that signed onto the Keep Android Open campaign opposing this, alongside F-Droid, the Electronic Frontier Foundation, and the Free Software Foundation.

If you ask me, this Big Tech company is doing what’s regrettably natural for it, clamping down open access to things so that its competition cannot benefit.

GOS beginner guide

preview

Hey everyone, I am setting my new (used) pixel 8 with GOS. I read on GOS site a lot,but want clearer understand some things. How to set different profiles- one for private and one for daily use. I understood its possible, right? I read another bothering thing,that GOS use 2 steps authentication- fingerprints and pin to open the phone. I am very against biodata, I never use it. Is it possible to leave only with pin ? Any advice what to apps to install will be greatly appreciated.

Looking to move from Caddy

preview

Recently it’s come to my attention that Caddy has an AI sponsor so I have been looking at moving away from Caddy.

I’m currently looking for another reverse proxy to use in place of Caddy. For TLS I am looking into using CertBot and it appears there’s a module (github.com/desec-io/certbot-dns-desec) I can use that works for desec.io to handle my certs.

I have two questions, the first is about CertBot. Since Caddy is handling my certs automatically, how often would I want to renew my certs? Desec.io has this command to obtain a cert:

certbot certonly \
     --authenticator dns-desec \
     --dns-desec-credentials /etc/letsencrypt/secrets/$DOMAIN.ini \
     -d "$DOMAIN" \
     -d "*.$DOMAIN"

Would I be required to run the same command periodically to renew my cert?

My second question is a bit more open ended. I am looking to hear any suggestions or experiences about different reverse proxies that are preferably free of AI. There is a list here with some suggested alternatives: codeberg.org/ethical-foss/open-slopware#web-serve…

It’s not just LG. Every TV company is spying on you

The Verge There are ways to protect yourself from your spying TV
preview

Crossposted from infosec.pub/post/52518361

The TV world has been a pot of controversy thanks to a two-hour-and-15-minute video from Gamers Nexus claiming LG TVs are nefariously spying on everything you do. They can record and store audio even when they seem to be off, track everything you watch, and could even be hacked remotely and turned into covert surveillance […]

burger? DAY 75 [OC, brainmade]

photo taken on a bed. the bed has orange sheets and a thick red patterned blanket on it. there is a blahaj shark plushy on the blanket in the background. there is a cardboard box with the text "baby burger" largely printed on it. on the box, a single "baby burger" is displayed. it has mayonaise, lettuce, tomatoes, a patty and ketchup on it. it is rather small. text overtop says "will you be my baby burger?". bottom right says "by maria on lemmy".
preview

will you? imagine how i’d hold you.

alt image (catbox, high quality)

i’ve had this image since march this year and i have somehow not used it in a post yet. now i have.

i present to you: baby burgers. the one displayed is the baby whopper. not very whopping, is it?

anyway, i’m a bit hungry but also not really soooo umm imma go eepy sleepy now. it’s late and i got group therapy tomorrow ~ughhhh~ ~it~ ~sucks~ ~so~ ~bad…~ and i might visit BK afterwards sooooo yea whatever. maybe. maybe not. probably? dunno. can’t tell, am not hungry rn.

just so u know: the burgers are not all that tasty. they are fine, but you should just get regular burgers instead.

i wish you a wonderful day where you, even if just temporarily, turn into someones baby burger ~

LibreOffice developer explains why it cannot display some Microsoft Office charts

www.neowin.net
preview

Your daily dose of “fuck Microsoft” is here!

The Document Foundation (TDF) recently announced the release of LibreOffice 26.8, and while it packs many new features, its highlight is the lack of any AI integration. This is quite the opposite of what Microsoft has been doing with its Office suite, but the tale of the disagreements between these two entities is as old as time itself, so nothing surprising. Now, TDF has explained why it cannot display some fancy charts that Microsoft Office can visualize without a problem.

Also explained at LO’s blog, with a less of a clickbait title: blog.documentfoundation.org/…/libreoffice-26-8-an…

Meta puts its AI assistant on a keychain

Ars Technica Meta puts its AI assistant on a keychain
preview

The device, which features a screen showing the Muse avatar, will also have real-time voice interactivity and is set to be released in December.

“If you’re not wearing glasses, this is going to be by far the fastest way to talk to your Muse and to show what’s going on around you,” the chief executive said.

Muse, development of which was first revealed by the FT in May, has helped change the momentum of Zuckerberg’s huge bet on AI, quickly becoming the most downloaded app on both the Apple and Android app stores in the US since its launch two weeks ago.

[AIP] Last weekend I published Plume RC1, my side-project for a self-hosted, flat-file publishing platform built to simplify independent publishing

www.plume.pub
preview

cross-posted from: lemmy.world/post/52289547

Hey Lemmy, longtime open source developer here. After about a year of work on a side-project I dropped the first release candidate of Plume, a self-hosted, Markdown-powered, flat-file publishing platform and I’d love this community’s feedback. Read the release announcement or check out the demo and let me know what you think.

What is Plume?

Plume is a publishing (i.e. blogging) platform. It’s designed to make writing and publishing frictionless. Your content is just files, plain Markdown in a flat-file structure without a database. You can write locally and upload via SFTP or keep everything in Git and sync automatically. It’s Dockerized out of the box for easy set up. Full-text search (powered by YetiSearch) is built in so there’s no external service to wire up. Plume also includes details you’d expect like Shiki syntax highlighting, automatic light and dark modes and an auto-generated RSS feed.

The stack

Plume is written in PHP using Slim Framework + PHP-DI, tested with PHPUnit, statically analyzed with PHPStan, styled with PHP-CS-Fixer. The front end utilizes Alpine.js bundled with Vite. The architecture leans on Directory Lister, a project I’ve maintained for years.

But why?

I primarily developed Plume for my own use. I occasionally like writing short-form on Bluesky (or previously Twitter) but have been growing tired of handing my content to someone else’s platform. And long-form writing came with too much friction, killing my motivation before ever actually getting published. With Plume, publishing is as simple as creating a file and writing.

The AI caveat

Most software ships with heavy AI involvement these days. However, Plume was developed in my spare time over the past year, initially without any AI assistance. I’ve only recently adopted AI, and only sparingly, mainly for debugging, tests and help with documentation. However, every line committed exists because I put it there with intention. I’m not claiming perfection but I know how and why everything works, which matters for the long-term maintenance of the project.

Feedback wanted

Despite being designed for my own use, Plume was intentionally built so it could be shared. So try it, break it and tell me what’s missing. Ideas and questions can be posted on GitHub Discussions or Bluesky. For bugs open a GitHub Issue.

Resources

Plume is fully open sourced on GitHub with full documentation is available at docs.plume.pub.

I’ll be hanging out in the comments, so ask me anything.

CBH]

First-ever case of euthanasia on very young child, 2, was handled well

NL Times First-ever case of euthanasia on very young child, 2, was handled well: Dutch committee
preview

Excerpt:

The doctor who performed the Netherlands’ first case of euthanasia on a child under 12 did so with due care, the supervising committee concluded after investigating. The patient, a child of nearly 2 years who suffered from several severe medical conditions, died at the end of 2025.

[News] The Failure at God School Gets TV Anime Adaptation, Supernatural School Drama by The Apothecary Diaries Author Hyuuganatsu

preview

Source: https://us.oricon-group.com/news/9298/
Archive link: https://archive.ph/U3HUZ

The Failure at God School is officially getting a TV anime adaptation. The popular manga is written by Hyuuganatsu, author of The Apothecary Diaries, with manga art by Modomu Akagawara, known for Ani Tomo, and is currently serialized in Hakusensha’s Hana to Yume with cooperation on the original work from Seikaisha. A teaser visual has also been unveiled, along with comments from Hyuuga and Akagawara.

EU’s new social media child protection rules to require all social media accounts to produce state ID - Leaked documents suggest that some existing accounts will also be subject to identification che…

www.independent.ie
preview

Full title: EU’s new social media child protection rules to require all social media accounts to produce state ID - Leaked documents suggest that some existing accounts will also be subject to identification checks

Need help from users to volunteer testing of his digital wellbeing software

preview

A few days ago i made a post on various platforms sharing my software ScreenGuard which received mixed reviews every where , since I AM using it for myself i decided to take in the reviews and am working towards adding necessary features and primarily polishing up things that were left behind and can have some 1st time setup hiccups.

The new features-

* Settings menu added

General tab(control notifications and sounds)

- add notification sounds(custom options too)

-toggle sounds and notifications for various causes

- dark mode(asked bby a few people so added the option)

Tracker Daemon tab

-stop background daemon

- toggle autostart of daemon on boot

- warning when daemon is off Pomodoro timer tab

- Turn on pomodoro in focus mode settings (fixes the unbaked settings of focus mode in v0.1.0 -set break between pomodoros

- no of pomodoro loops

* Daily limits can now be set instead of the fixed 8hr daily limit bug with v0.1.0

* Several changes to Daemon, including some minute layout changes to optimise resources while adding the newer features which are Stated above

Note: this is a beta release and will NOT be pushed to the APT ,COPR AND ARCH repositories for casual users, this is meant for testers and people eager to help me out find the bugs and tiny issues here and there AND YOU CAN HAVE A LOOK INTO THE CODE IN THE BETA BRANCH OF THE REPOSITORY, it hasn’t been pushed to main branch to keep it clear until bugs are fixed.

Release page: (github.com/…/v0.1.1-beta.4)

_____________________________________________________________________________

CLEAR AI EXTENT

Codebase: Manual

Implementation: Manual

Debugging:Assisted

Packaging: generated(specifically for Custom aarch repository due to issues with AUR)

Documentation: Assisted

The latest versions of Common Voice datasets, Scripted Speech v27.0 and Spontaneous Speech v5.0, are available for download on the Mozilla Data Collective

mozilladatacollective.com
preview

The latest versions of Common Voice datasets, Scripted Speech v27.0 and Spontaneous Speech v5.0, are available for download on the Mozilla Data Collective! A giant thank you to all of our contributors for their hard work putting together these datasets.

What’s new in this release:

Version 27.0 of Scripted Speech includes datasets for 295 languages. These datasets contain 32,349,999 voice clips, making approximately 42,593 hours of speech data available for developing and improving speech technology.
Version 5.0 of Spontaneous Speech includes datasets in 80 languages. These datasets contain 89,754 voice clips of free-form answers to questions, of which 302 hours have been transcribed and validated.

Since the last release, the Common Voice community has welcomed 1 language to Scripted Speech - Pa’O (blk) - and 6 languages to Spontaneous Speech - Chinese (China, zh-CN), Swahili (sw), Palauan (pau), Sundanese (su), Bengali (bn) and Shan (shn).