As others have said, this is not the most recent status update (it depends on future Google changes in QPR1 or QPR2).
The much more interesting recent news IMO is that Google is not allowing (non-Samsung) OEMs to sell devices with GrapheneOS:
https://news.ycombinator.com/item?id=49946698
See the last paragraph.
For example, non-Samsung Android OEMs aren't allowed to directly sell devices with GrapheneOS and Google will only permit it within a quota. It can and is being worked around and there will be devices sold with GrapheneOS as the stock OS without Google restricting how many can be sold.
My guess is that the workaround is that Motorola sells them with Google-certified Android. A third-party (non-OEM) buys them in bulk and preinstalls GrapheneOS.
But this is really end-90s/begin-00s Microsoft levels of anti-competitiveness. I'm surprised that (particularly non-US) regulators are not investigating them yet.
> But this is really end-90s/begin-00s Microsoft levels of anti-competitiveness. I'm surprised that (particularly non-US) regulators are not investigating them yet.
Every company is nice until the monies they earn is not guaranteed anymore. They were closing the doors they have intentionally left open in the name of security for a couple of generations.
Now they're being more open about why they are limiting user choice. Because like Chrom(e/ium), Android is designed to be a large data sink for Google to feed The Machine.
"Because like Chrom(e/ium), Android is designed to be a large data sink for Google to feed The Machine."
Also maintaining the monopoly over the app market and getting a good cut out of every transaction within. A non google controlled device in the mass market can introduce new markets independent of google (and not paying them).
They would not like that.
Apple did the same thing. In the early days of OSX much of Darwin was open-sourced. Now, not so much.
> The much more interesting recent news IMO is that Google is not allowing (non-Samsung) OEMs to sell devices with GrapheneOS:
how is that legal??
that sounds like a very clean cut case of thinks companies aren't allowed to do under fair market lawes
Yeah, I don't understand this, graphene is FOSS and unaffiliated with google so if you as an oem install grapheneos on hardware you manufactured how does Google have any say at all?
Because Google will cut you off from access to the privileged Android access to Play Store, Services and everything else. So it’s basically all or nothing.
Which, again, appears at a glance to be clearly illegal. For reference see what happened to Microsoft in both the US and Europe.
Same as RedHat saying you can't redistribute the source code that they are obligated to give every customer.
The GPL clearly grants every recipient the same full rights as whoever they received something from, so copyright law itself says that you can take that source and redistribute it.
But starting a year or so ago RedHat says you may not redistribute, which they can't actually say, so you still can, but if you do you will be fired as a customer and lose all future access, so you only get to do it once.
Given the clear wording that makes the intent of the GPL unambiguous, that every end user is fully empowered and you may not do anything to curtail that, I don't see how they get away with it except the simple fact that no one has been willing to take on the legal fight.
If you're a pre-"stream" Centos user, you don't have the money for that. If you're a paying RHEL user, you don't want to be on bad terms with RedHat or maybe IBM either, and neither the licence costs nor the rules bothers you at all anyway.
So it's plainly illegal in my opinion, but will stand, illegal and yet in effect and unchallenged probably indefinitely.
I guess GPL needs a line that says you aren't allowed to discriminate against customers that exercise the rights given to them by the license.
That is an interesting point. The issue here IIUC is that only customers being coerced currently have legal standing while the presence of such a clause would give standing to all copyright holders. So yeah, arguably an oversight of current copyleft licenses.
It's only illegal if the law is enforced and the US federal government gave up on anti-trust enforcement a long time ago and any attempts to re-awaken it get nerfed quick.
The US isn’t the only place Android phones are sold.
True.. but aren't they the only gov that can force a breakup?
Other governments could make it fairly inconvenient for the executives.
e.g. "Execs can no longer vacation in or transit through France without threat of arrest because they've ignored a legal directive."
See e.g. Oliver Schmidt of VW who was arrested on vacation in Florida from Germany, and served seven years in prison. Or Meng Wanzhou of Huawei.
Much more sensible would be barring the sale of Google products and services in their jurisdiction. Which is enough of a threat that Google tends to pay their fines and doesn't just ignore legislation outright.
It's all about that sweet backdoor. With Google and Samsung the NSA can just waltz in and out of your phone no matter which OS is running. But if some Chinese OEM decides that Unisoc chip & baseband would be the best choice for your GrapheneOS device the NSA will be quite unhappy.
I'm honestly a little surprised we haven't seen a Chinese OEM use grapheneOS or their own fork of it.
Graphene is a privacy focussed rom. In China there is not such a concept as privacy. In fact, it might be illegal to be distributing this, even for export.
Clothes, handbags, etc. brands regularly complain that Chinese factories sell apparent clones at lower prices.
Can design forgeries be prevented by selecting as designs phrases and fragments of text that are politically provocative in China? To the extent that they continue to make faithful copies to sell in the West, they are exposing labor force to provocative say anti-party content. Or they forego the imitation business?
no lol
Those brands would lose the Chinese market.
Why are you surprised? Since when does China care about privacy?
They already have HarmonyOS, which is much better than Android
How so ?
Better performance, better security. No Google shit
Better security of a proprietary OS versus free and open-source OS? Who made the audit and where is it?
It apparently has better foundations (microkernel capability-based) than Linux/Android but whether such a comparatively new OS is resilient to compromise needs much more independent research that's true.
Android is not really proprietary. It was open source once a while ago at least.
No Google services, but let's not pretend Huawei ones are any better in terms of privacy.
Much better for any westerner. The Chinese will not divert any flights, because of what I said online, nor will they refuse entry into the US or partner country, or search my company devices.
I don't care about China, because first I will hardly travel there, nor do I expect any problems if so. Unlike GB, Turkey, Israel or the US.
Eh, I feel like data gets sold around so much that it could find a way to harm or at least impact you, especially if it's this extensive.
Also I personally am not even a Westerner, for me Chinese data collection could indeed impact me more directly than Google's.
Last time I looked, it didn't even allow installing apps from outside AppGallery at all. Also, I don't think the Huawei services are any less intrusive than privileged Google Play.
I am fine with AppGallery apps only lately. Did so for the last year on my Android Huawei.
First - a lot of things are just not on there. And second - not allowing alternative sources gets really bad when said store is asked to censor apps, like, say, proxy clients or alternative social media apps (Newpipe, etc.).
because they have no reason to trust it...
It's the other way round.
If the device is sufficiently secure, it will be considered for the official support from GrapheneOS.
Of course, GOS can be forked by anyone, including Chinese OEM with insecure hardware.
Sorry, which backdoor(s) exactly are you referring to?
> I'm surprised that (particularly non-US) regulators are not investigating them yet.
This is basically the reason Google lost their Play Store anti-trust lawsuit when Apple won theirs. Google did all these incriminating, behind closed doors deals to lock out competition from their “open ecosystem”, where Apple never pretended to be open to behind with.
> Apple never pretended to be open
Except when Steve Jobs lied saying FaceTime would be an open standard.
"FaceTime is based on a lot of open standards: H.264 video, AAC audio, and a bunch of alphabet-soup acronyms. And we’re going to take it all away. We’re going to the standards bodies, starting tomorrow, and we’re going to make FaceTime an open industry standard." - Steve Jobs at Apple’s WWDC 2010 keynote (emphasis mine)
That was their intention but that changed after they lost a patent troll lawsuit.
This is just the Breaking Bad "He can't keep getting away with it" meme, for tech giants. Google has been ruling Android with an iron fist for over a decade, and they continue to do so. This came up in a different comment chain of mine [0] recently as well, and is probably more worth reading than a lot of the other comments here that are just now realizing how restrictive Google is with Android
[0] https://tildes.net/~tech/1wam/blocking_of_unverified_apps_on...
You can always notify the EC anti competition whatsdpg through their wistleblower portal:)
with how EC has been behaving recently that might make things worse..
EU is hell bent on locking "your" devices down as much as possible so they can shove their big brother spyware down your throat under the guise of "protecting the kids" [1]. They are building tons of EU and national level apps where strong Play Integrity is required [2] and will pair these up with the need to prove your identity to "make sure you are an adult" everywhere on the internet [3]. At least one EU country, Spain, has already begun to profile people based on whether they may be running phone OSes other than Google blessed ones [4]
[1] https://fightchatcontrol.eu/chat-control-overview
[2] https://waag.org/en/article/european-digital-id-wallets-are-...
[3] https://en.wikipedia.org/wiki/EU_Kids_Act
[4] https://www.androidauthority.com/why-i-use-grapheneos-on-pix...
Speaking of 'EU' as a single entity seems a bit like a deep state conspiracy theory. Yes l, there is lobbying around CSAM scanning, security agency, banking industry and media networks, that all work against open source and security by design. Still there is also other movements and I don't think anticompetition has the same agenda. But in the end it is politics: there needs to be enough people to care about something. For anticompetition to be active I think the problem is rather there is no European market to protect. And particularly graphene (I will get downvotes for this) is not really good in joining forces with other European businesses in this space. Activism is important, but for lobbying you need to escape the niche.
The EU bureaucracy IS a single entity controlled by the EU Commission President, currently Ms. von der Leyen. Speaking of it as a single entity is definitely not a conspiracy theory as anyone can read how the EU works and see how the only democratic component of the EU, the Parliament, is an absolutely powerless body. Basically, the Commission can get what it wants every time.
How? Even in the case a majority of MEPs have different views to the Commission, it does not matter because only the Commission can initiate legislation. On the off chance the Commission does not get what it wants from the Parliament they can just ask the Council to send the same proposal to the Parliament as an 'emergency' procedure that has to be rejected by a minimum of 361 MEPs even if 50%+1 of the MEPs in attendance vote against. That's how Chat Control 1 was resurrected after it was voted down by a majority of MEPs. 331 MEPs voted against it vs 301 for, and it still passed due to the 361 rule. Which is why lobbying anyone except the Commission is pointless. You can do that even in China - people lobby the CCP there too, nobody claims this is democratic.
So, no conspiracy is needed, this is the EU functioning exactly as designed.
I am working with different EU DGs in a very different context and I can assure you first hand that it would be rather nice in many cases if that would be true in general.
Just a reminder that there are still disinformation campaigns, useful idiots and just plain nazis (overlaps the previous) that are posting anti-union comments everywhere.
I posted sources to back up my claims. Please try to refute the specific points in the post instead of resorting to unsubstantiated ad hominems.
They probably know already, it's not the first time it happens. See the illegal pressure Google has made against OEM after CyanogenMod wanted to go commercial.
Google was found guilty by the EU antitrust investigation and payed a 4 billions euros fine (and Google has changed nothing since then, they only increased the pressure).
GrapheneOS is especially annoying for them as it destroys their blanket excuse that it's ""for security""
> My guess is that the workaround is that Motorola sells them with Google-certified Android.
Was this ever the deal with Moto? They announced something recently, but it didn't read like Moto would be distributing devices with preinstalled GOS. Just that it would be able to run GOS.
Unless they've recently changed the deal, they'll be selling GOS out of the box. That was the announcement two or so years ago, and so far as I know nothing had changed.
That was not the announcement. This was never stated anywhere. Motorola is making a subset of future devices meet the GrapheneOS hardware security requirements, greenboot and preinstalled options are not confirmed, and may not happen at all for the first few devices.
One obvious challenge with the distribution is: would you want to buy a phone with pre-installed GrapheneOS?
This seems similar to wanting to follow the advice of "only buy bottled water on your trip to India", but the bottle you're buying has the cap removed so they could put a straw in it for your convenience.
GrapheneOS has attempted to cover this, it comes with an Auditor app that can be used from another Android device to check for tampering.
> The Auditor app uses hardware-based security features to validate the identity of a device, along with the authenticity and integrity of the operating system. It ensures the device is running a verified operating system with a locked bootloader and that no tampering has occurred." [0]
I assume that it would be quickly discovered if Motorola were tampering with phones en masse.
[0] https://attestation.app/about
Yes. That would remove the need to flash, which is a roadblock for many. Greenboot support and Auditor would ensure your install of GrapheneOS is genuine.
That IS a good analogy, actually.
Sometimes you can see the bottle, from ice to your hands, and the vendor and area are clean.
Other times, there’s an invisible bug on a surface the vendor touched, or they bring it up from a hidden, moldy refrigerator, and it was refilled with tap water…
Motorola is at 5% of the world's market share. They fell really deep.
5% of a $500b market? Sign me up.
Well, they designed some handsets (one is announced, maybe there's another one or two) to meet Pixels / GrapheneOS level of hardware security. That alone is BIG.
Then there's expectation GOS might be sold pre-installed as well.
The original announcement was vague[0]. Most assumed that Motorola will be releasing a GOS phone[1], but as more information became available it seems that Motorola will release a GOS-compatible phone. At least to start. Both sides are not commenting on if a phone would eventually ship with GOS from the factory AFAIK. But I'm guessing neither wants to commit to anything right now.
[0] https://grapheneos.social/@GrapheneOS/116159602850585685
[1] https://www.reddit.com/r/GrapheneOS/comments/1rik0np/motorol...
> But this is really end-90s/begin-00s Microsoft levels of anti-competitiveness. I'm surprised that (particularly non-US) regulators are not investigating them yet.
You mean like the Skyhook vs Google 2014 lawsuit? (look it up) Settled before it could go any further.
> I'm surprised that (particularly non-US) regulators are not investigating them yet.
Because corporate managed phones are required for all the id crap governance franchises intend to foist on people.
> For example, non-Samsung Android OEMs aren't allowed to directly sell devices with GrapheneOS and Google will only permit it within a quota. It can and is being worked around and there will be devices sold with GrapheneOS as the stock OS without Google restricting how many can be sold.
It's worth noting that Microsoft did/does LITERALLY EXACTLY THIS to OEMs that sold Windows. They couldn't get the "Made for Windows" badge if they sold over a certain amount of Linux machines. IIRC this is why consumers could only buy machines with either "Windows" or "nothing".
How the turn f**ng tables.
> I'm surprised that (particularly non-US) regulators are not investigating them yet.
So that in three years (after Graphene has gone under and after Google pressured Samsung to stop working with them) Judge Mehta can rule that it is in fact illegal but not doing it would damage Google's business so he will allow it?
I regret to inform you that the manager will not save you. The manager will be doing $100K speeches on a tour of google campuses.
> end-90s/begin-00s Microsoft levels of anti-competitiveness.
Also got away with it. The only consolation prize we got was a glimpse at a bunch of documents that made clear that they knew full well what they were doing. That actually makes it worse.
Also reminiscent of iirc Intel's choke hold on companies like Dell that froze out AMD
It takes EU regulators like half a decade or so to make up their minds on each issue.
The EU never sanctionned Microsoft for monopoly. They received $2bn fines in 2005 for lack of transparency on the documentation for drivers, if I remember, then a little extra for paperwork. Then Microsoft complied mostly at the last minute before being fined (even for the 6-months disappearance of the Browser Choice Dialog, it only cost them $500m).
But never, never has the EU sanctionned Microsoft for signing OEM deals that prevent companies from installing other OS than Windows.
Right. The EU still seems successful in shaping (foreign) tech to some extent. Handing out huge fines is maybe less important than effecting change. Though it would of course be good if other national/transnational regulators would join in and take care of some of these topics. Imagine for example if Japan, South Korea, Taiwan, Australia and New Zealand teamed up. Together they might be able to accomplish something.
Time for US regulators to show how it's done? I'm sure Americans can show Europe how this is done properly, right?
This is where governments should slam them with regulations.
Absolute anti-competitive behavior. "Android is open, but not really"
You want to lead an assault on companies that develop OSS because they don't follow your dictats on how to work?
That sounds like a brilliant idea, I'm sure it'll be amazing show of force for all the top kernel contributors as well.
No, just lead an assault on companies that abuse their market position to kneecap any possibility of OSS being deployed meaningfully.
This actually is a brilliant idea.
Which companies are that? The market leader of US phone market is running a closed, proprietary golden-cage OS which will increase it's share if your harebrained scheme is implemented.
What’s wrong with that?
You think that Google throwing its weight around to prevent competition to even exist (however small it may be) is fine because otherwise Apple may gain share and yet you have the boldness to call anything harebrained.
This is rich even for the very low standards of HN.
Moronic take of the day. Quite a feat.
Google can't be "throwing around to prevent competition" when they don't even have market dominance, especially when the main player is the one aggressively implementing anti-competitive standards and you're completely mum about it.
It's really kind of bizarre that you want to attack developers of an OSS OS when the other option is so much worse on every level when it comes to freedom.
Believe me, I hate Apple more than I hate Google (which is why when my choice is between both devils, I pick Android).
But in this case, it is Google kneecapping a small viable option (Graphene OS). How can a new, better player enter the space when no OEM may even sell Graphene OS without threatening their ability to also sell Android devices?
I am not here attacking a an OSS OS developer. I am attacking one of the largest corporations in the world, a member of a duopoly in the mobile OS market, engaging in ridiculous anti-competitive behavior.
So long for monopoly laws...
> I'm surprised that (particularly non-US) regulators are not investigating them yet.
Simple reason, they're afraid of Trump bullying them into submission, just look at the oil/diesel stockpile release drama.
The US has never been shy about its politicians up to and including the President being an extended arm of the large US corporations - but Trump takes that x1000.
I don't think they're fit to lead their nations if that's the case. Trump acts like an emotional child, and makes policy based on how he feels about a leader. That means he's easy to manipulate. Therefore, the strategy is for a group of leaders to get together as a group and call him a coward, a war criminal, a murderer (he is all of these things) and then Trump will just go insane with self-defeating policies trying to get back at them. The US can't cut off trade with the entire world but he'll try, and bring down his own country in the process. Not only has no one attempted this, they're scared to even call the proposed Canada-EU partnership an anti-US coalition. They're not even trying.
> Therefore, the strategy is for a group of leaders to get together as a group and call him a coward, a war criminal, a murderer (he is all of these things) and then Trump will just go insane with self-defeating policies trying to get back at them.
Which largely is correct, but. Geopolitics - as much as I dislike it - is so much more murky.
The chief issue is Russia. Us Europeans have a hot war directly at our Eastern border. That's like less than 1000km away from where I live, about a day worth of driving and I could go and visit people that got literal bombs falling upon their heads a day or two ago. We do not have the armies, the ammunition, the logistics or the nuclear arms to be a meaningful deterrent to Russia, and so our leaders have decided it's best to appease Trump where it is cheap but oppose him where it matters (e.g. annexing Greenland or Canada), in order to maximize the chance of Trump not doing what he openly called for - disbanding NATO.
The second issue is Big Tech. For better or worse, we're hooked on American technology. If Trump were to retaliate against us by, say, ordering Microsoft, Google and Apple to cease providing service to countries opposing him - we'd be thoroughly fucked. Almost all of our government services and our companies run, to a huge degree, either Microsoft, Google or Apple devices that are vitally dependent on the cloud for functionality. And that's before getting into the hot mess that is "the cloud" itself - even if we were to seize AWS's data centers by force, they'd be useless because all of their core control plane infra infamously runs in us-east-1.
> The US can't cut off trade with the entire world but he'll try, and bring down his own country in the process.
It's a highly privileged position to even suggest such plans. Sure, in the end you are correct, and we're already seeing this in action. But the "collateral damage" is insane, similarly to the people that say "you can hand the power to the far-right and let them fail in the front of everyone's eyes". A lot of people will suffer for this foolish attitude, and it will mostly be the lower rungs of society - the poor, disabled, migrants, LGBT, everyone that doesn't have the resources to "ride out" the storm.
> The much more interesting recent news IMO is that Google is not allowing (non-Samsung) OEMs to sell devices with GrapheneOS:
To be That Guy, Apple is not allowing anyone anywhere to sell any devices with anything but MacOS/iOS.
> But this is really end-90s/begin-00s Microsoft levels of anti-competitiveness.
It's not even the most anti-competitive in the market of 2026!
To be That Guy, Apple is not allowing anyone anywhere to sell any devices with anything but MacOS/iOS.
Apple doesn't allow Apple selling Apple devices with other operating systems.
Google doesn't allow other OEMs selling the OEMs' devices with other operating systems.
Big difference.
(Yes, pedantics: I know that OEMs could sell devices with other OSes, but not being able to sell GMS Android devices would lose them most of their customers.)
> Big difference.
Not from the perspective of competition, as I see it. Like, if you want to compete with Apple by using part of its platform for your own stuff, you can't at all. But you can with Google, just not all of it and in all ways.
Point being: this is just another platform flame. People with one kind of phone in their pocket are outraged at the maker of the other thing.
No, it is different. They are using their market power over Android to prevent OEMs from selling other mobile OSs.
Apple doesn’t prevent other OEMs from selling phones.
> They are using their market power over Android to prevent OEMs from selling other mobile OSs.
That... is pretty spun, especially with regard to the Microsoft comparison upthread to which I responded.
They aren't trying to restrict "other mobile OSs", they're specifically saying GrapheneOS, and in general any AOSP-derived system which is designed to interoperate with the GMS frameworks.
Like, even AOSP alone would be fine, c.f. Fire or Harmony which never got this attention. GrapheneOS is specifically in violation because it includes a feature to suck down and essentially "pirate" an unlicensed copy of the GMS suite, thus making the phone into the practical equivalent of a Pixel.
That is what Google objects to, because they sell GMS as a product and aren't interested in their downstream OEMs "giving it away" for free by bundling a third party product that doesn't license it.
Basically GrapheneOS, as it exists right now, just can't be shipped as a commercial product. There's no license for the magic stuff they claim to support.
You're making up a whole phony story based on how you think GrapheneOS functions and your incorrect belief that Google has an issue with it. None of that is true. Google forbids every Android OEM licensing Google Mobile Services from shipping any fork of AOSP not certified by Google. Your claims about GrapheneOS are extraordinarily inaccurate.
GrapheneOS can be shipped as a commercial product and is going to be shipped as one on Motorola devices. It's only Motorola themselves which is unable to sell devices with it. Google's license doesn't say they can't provide official support for GrapheneOS and sell devices to other companies to sell GrapheneOS on those.
The approach to handling Google Mobile Services in GrapheneOS is entirely legal and Google has never raised any issue with it either with us or Motorola. We don't include it in GrapheneOS but rather only include a compatibility layer to make it run as a regular sandboxed app if users install it. We don't need to mirror it for the sandboxed Google Play feature to be usable. Mirroring freely available software is highly protected and no different from the many APK mirror sites. It's the Google Mobile Services licensing and Google's overall behavior with it egregiously violating antitrust laws which is illegal.
You're claiming providing a compatibility layer to run freely available software without privileged access it piracy. What we're doing is strongly protected under the law. Google's efforts to interfere with providing Android app compatibility elsewhere under the guise of a supposed security feature are going to have serious consequences for them. That's already coming in the EU and beyond. The bait and switch they've pulled with the Android Open Source Project and the coercive rules for their OEM partners is also going to have consequences beyond what it already has.
With all respect, and like I said, that's just spin. You're saying all the same stuff I did with different emphasis.
You can't get a license for GMS if you want to make money shipping devices that allow users to run unlicensed GMS. You can make all the money you want shipping AOSP devices that don't/can't run GMS. We both agree on that much, right?
None of what we wrote is spin. Your claims about both the Google Mobile Services licensing model and GrapheneOS are inaccurate.
Google has license terms for Google Mobile Services forbidding their OEM partners from selling devices with forks of AOSP which are not certified by Google. The certification process doesn't permit GrapheneOS. It would require removing many of the privacy/security features and would create unacceptable delays for updates. Their certification process does permit our sandboxed Google Play feature and has no rules against it. We could obtain certification for an OS with sandboxed Google Play but without many of our other features. It would have significant delays for updates similar to how all regular Android OEMs cannot ship an update without weeks of delay.
Google is not allowed their OEM partners to sell unlimited amounts of devices with GrapheneOS or any other AOSP-based OS not certified by Google. They're only willing to permit it at a small scale. It has nothing to do with sandboxed Google Play. Google knows it's illegal and unenforceable in court but they're using it to intimidate OEMs into going along with what they want.
We don't include Google Mobile Services in GrapheneOS and are not violating the license. Google has repeatedly helped us improve sandboxed Google Play. Google added GrapheneOS and Vanadium support for FIDO2 and passkeyhs to Play services which allowed us to remove our workarounds for it. They aren't putting any significant effort into avoiding regressions with it but definitely aren't intentionally breaking it. We have a testing and release channel process for sandboxed Google Play since it's not officially supported.
iOS was never never an OS that was open to any device maker who cared to use it.
Google made the choice to announce that Android was open to all, in an attempt to take market share from Windows Phone.
Now they want to go back on their word.
That may well be true. But the upthread point was that this was "anti-competitive", not "word-breaking". And in an argument about competition, Android is and remains by far (!) the most accessible platform. The restriction here is just that you can't get a license for Google's proprietary stuff if you also sell GrapheneOS, not even that you can't run GrapheneOS.
Google was already found guilty of antitrust, in part because they tried to contractually prevent device manufacturers from building devices to run forks of Android (like Amazon's Fire OS) if they also made devices for an OEM who used Google's Android.
> Alphabet's Google on Thursday lost its long-running fight against a record [€4.1 Billion] EU antitrust fine for using its Android mobile operating system to block rivals
https://www.usnews.com/news/top-news/articles/2026-07-02/goo...
Now they are trying block Motorola from pre installing a different fork of Android.
They will either back down or face another enormous fine in the EU.
Again, even accepting all that, Android remains more open to competition within its own ecosystem than it's main (heh) competitor. And being outraged in only one direction is a smell that tells me... we aren't talking about competition.
Apple never lied and claimed that iOS was "open" in the first place.
The important part is allowing users to make an informed choice, which requires you to be honest about what you are selling.
Android is as open as ever (so far). Google doesn’t make or sell mobile phones for other OEMs, so their claims about Android openness can’t be applied to hardware from other OEMs being closed. Two different things.
Blocking Motorola from selling devices that run a fork of Android isn't open at all.
You're missing the point. Selling a closed device is legally permissible whereas attempting to strong arm behavior of other companies is deemed anti-competitive. So apple is within the bounds of the law (regardless of whether you approve of that) while google is not.
No, you're completely wrong. Google forbids their OEM partners from selling any fork of the Android Open Source Project which isn't certified by Google. They forbid this as part of licensing Google Mobile Services but it applies to any fork of AOSP. GrapheneOS does not include Google Mobile Services and doesn't want to include it.
> The much more interesting recent news IMO is that Google is not allowing (non-Samsung) OEMs to sell devices with GrapheneOS:
Every time I've said on HN "I don't trust google with anything, not with software or hardware" someone shows up and goes "bUt ItS oPeN sOuRcE".
Folks, just because something is or isn't open source, the story doesn't end there. It doesn't there aren't levers of power which may be invisible to you.
I was right, as usual.
Corporations learned they have to get in bed with regulators first, and how to do it.
I saw an interview with Bill Gates once where he said that one thing he would've done differently is more quickly come around to the idea of sending people to Washington. Apparently he didn't like the idea of lobbying and that cost them when the regulators started coming for them
Wow, then there we go: don't hate the player, hate the game. You're telling me even Bill Gates wasn't evil until the system forced him to either become evil or get shut down.
No, he just say he's inexperienced.
Bill Gates published that infamous open letter about copying software, and both Bill Gates and Brad Smith said that Microsoft's core pillar is IP: "Microsoft is built upon the idea of having IP and protecting and using it" (paraphrased by me).
The quotes I can find by digging the net:
> Microsoft was founded on the premise that software is valuable intellectual property that people should pay for. --Bill Gates
> Microsoft was founded on intellectual property. Intellectual property is the foundation of our business. --Brad Smith (This is the quote I remember in the first place)
So, Microsoft never wanted to be an open company. They were the epitome of the closed source, behemoth software company, where you get the goods, get to use it, and pay them for the privilege.
Closed source software is a reality, not an explicit evil. It is the same reason I don't have schematics for my bedframe. I've worked at software companies - have you? - it takes extra effort to release source code, causes a lot of risk, and provides absolutely no benefit whatsoever so it is simply irrational to do it.
I'm not an opponent/critic of closed source software or enemy of it. I pay for quite a few high quality closed source software packages, and I like them as much as the Free Software counterparts which I use every day.
I also understand that we need to eat and have bills to pay, and there are many ways to achieve that, incl. Free or Closed Source software.
What I'm against is weaponization of closed source software beyond reasonable point. To EEE, to deprecate otherwise capable and functional hardware in the market, to limit user freedom or to extort money.
I hope I made my point clear.
Furthermore:
> I've worked at software companies - have you?
I didn't work at a software company per se, yet I develop open source software for the projects we work on, and I know what preparing a codebase for publishing entails. I also worked as a tech-lead of a Linux distribution, and a nation-wide one at that. I know what it entails, trust me.
If we're talking about experience in terms of years, I'm doing this for ~20 years, using Linux for ~25 years, and using computers in a level I understand what programming them entails for ~30 years.
So yeah, I'm not that newbie who have seen some Python and tied themselves to a knot of awe.
> causes a lot of risk,
Don't let's get into FUD territory of "Free Software is insecure", shall we? We see how Windows has been breached yesterday and today, and will see it more for years to come, as with other software.
> and provides absolutely no benefit whatsoever so it is simply irrational to do it.
Hmm, I'll agree to disagree here because 90% of the thing your digital stack is living on is Open Source and Free Software.
I don't have time to flesh out the benefit and irrationality aspect of it, because I mean, it's plainly wrong when it's put that squarely. We can find some nuances maybe, but it's limited to certain scenarios.
by weaponization you mean Win 11 requiring specific hardware etc?
your comment honestly just sounds like you dislike closed-source software.
for most commercial software projects, releasing the source provides no tangible benefit, aside from people like HNers being happy
but if Microsoft would've open sourced their OS, they would've been vulnerable to their OS being diluted into free versions or maybe even OEM-maintained versions
from a business sense, it makes no sense.
and as for security, closed source software is harder to attack (and was a lot harder to attack before LLMs). like, there's still much that we don't know about Windows internals exactly, and even those who do are a very small group of people.
it'd be a lot easier to find vulnerabilities if the source was open.
yes, it doesn't mean it's automatically more secure, in fact it can be less so if people don't have eyes on it, but I'd say the amount of attacks is less and usually done by more sophisticated attackers
Weaponization of closed source software could take many forms and is just part of the general weaponization of market mechanisms that businesses do.
Right now it doesn't really affect me that Ableton Live is closed-source. But it would affect me if the main method of sharing music on the internet was Ableton Live project files. And if Ableton had cultivated that situation on purpose they would be weaponizing the closedness of their software.
If we're talking about weaponization, then for sake of completeness let's remember that weaponization of open source is a very powerful business strategy that's been frequently used in the past 20 years, whether to market software, acquire free work, or as direct move, to try and destroy a market some competitor works on.
Some business models - like OSS, and free-with-ads - are like dimension-folding weapons from Dark Forest trilogy: once deployed, there is no stopping them, they just permanently drop a degree of freedom from the universe, inside a shell expanding at the speed of light.
> by weaponization you mean Win 11 requiring specific hardware etc?
I can understand specific hardware and/or CPU generation requirements up to a certain point. Because CPU generations bring more than new instructions and performance, but I don't understand why Windows Team or Microsoft doesn't use function multi versioning to allow more systems to use up to date versions of Windows for longer time.
On the other hand, using closed file format related documentation as reference in a supposedly open format's specifications and trying to short-circuit ISO to push their seemingly open but ultimately closed document formats as standard or using Embrace, Extend, Extinguish tactics to kill competing products, or inserting code which makes their applications crash in competitors' operating systems is straight up malice.
...and we have Halloween documents which are openly(!) trying to make Linux non-functional on PC hardware, so there's that.
I'll note that these stuff can be also weaponized in Free / Open Source software. Pulling hardware baseline higher, deprecating drivers, and not giving good enough errors to make the problems obvious while not giving the source and/or building instructions/configurations is also a tactic of Red^H^H^H IBM. Remember: If you merge a company with IBM, you get IBM.
> your comment honestly just sounds like you dislike closed-source software.
Insisting about something when I openly and honestly said it's not is not very nice. Yes, Free Software is my first choice and where my heart lives at, but I'm not malicious about closed source software. This comment is being written on a Mac, for example. If you really want to dig that, my comment history is also in the open. For the record, as I always say, I prefer Linux desktops and Mac laptops, again for ~20 years or so.
> but if Microsoft would've open sourced their OS, they would've been vulnerable to their OS being diluted into free versions or maybe even OEM-maintained versions
I'm not saying that Windows would be dead if it was open source, but we'd have versions where ads and telemetry are straight up ripped from every possible part of it. Windows 11 and 10 to a certain point feels like it's working against me. Constant nagging, no ability to use local accounts during install, suggested apps everywhere... It's not an operating system anymore. It's a software holding me hostage to its agenda with a side effect of making my computer run. Windows XP was not like that, 2000 was not like that. Even 7 was good.
> from a business sense, it makes no sense.
You can always make it sense, if you decide to do that. There's SQLite for example. It's not an OS, but its development environment is protected enough so you can't get the quality the official versions propose.
However, I'm not saying that Windows shall be open source. However, its closed source nature is weaponized towards its users. Not with hardware requirements primarily, but how it herds the user and siphons data out of the computer in the name of telemetry.
> and as for security, closed source software is harder to attack
Ha, no. A small anecdote: When WMF attack vector was introduced, WINE team had the laugh of their life because the problem seemed so stupid to pass on. The next day, WINE released a patch, because it turned out that WINE also had the same security hole. They reverse engineered Windows API to a level that their implementation was bug for bug compatible.
Another one, about WINE again: My friends' Linux machine got infected with a Windows virus via WINE. The virus was unable to do harm, but it was infecting any USB drive attached to that computer. So, even if we didn't have the code, WINE has reverse engineered and implemented a bug-for-bug compatible Win32 API under Linux.
Both are pre 2010 events, BTW.
Also, with the leaks we have learnt that NSA had a truckload of zero days to infiltrate Windows systems. Great for security, right?
> it'd be a lot easier to find vulnerabilities if the source was open.
This is the half truth. Finding, fixing and evading the introduction of vulnerabilities are a lot easier if the source is open. We evaded 7z incident. Do we know that there's no universal backdoor in Windows? I don't. You can't know either. I don't my computer to have a TSA-approved keyhole somewhere.
Do you remember how NSA backdoored a cryptography algorithm? I do. See: https://en.wikipedia.org/wiki/Dual_EC_DRBG
Have you ever read how Crypto AG rigged secure communication devices sold to certain countries, even NATO allies, because they were in fact owned by CIA (and BND up to a certain point)? See: https://en.wikipedia.org/wiki/Crypto_AG
Closed source something can't be audited to be secure or anything. It doesn't make it harder to attack, however. Only the good guys (or nobody but us) doctrine doesn't work. An intentional backdoor doesn't discriminate. You say the correct phrase, and it opens.
> yes, it doesn't mean it's automatically more secure, in fact it can be less so if people don't have eyes on it, but I'd say the amount of attacks is less and usually done by more sophisticated attackers
Security through obscurity never stopped anyone from infiltrating anything. With enough persistence, any system even obfuscated can be cracked, even without LLMs. People reverse engineered SMB despite Microsoft's best efforts. Then, they registered it as CIFS and open sourced it, because they had to.
Please, we have gone through this 30 years ago. These arguments doesn't hold water anymore.
> Insisting about something when I openly and honestly said it's not is not very nice.
I'm not insisting anything, I'm just saying that I don't think your arguments are purely objective, but rather from a matter of principle, which is fine, but to frame it as some kind of established fact that it's being "Weaponized" even though I'd say it's a bit extreme.
I don't like Windows, especially Windows 11, but I can understand why they exist and what markets they serve.
> but I don't understand why Windows Team or Microsoft doesn't use function multi versioning
because otherwise they'd have to support systems for a really long time and they'd be unable to support newer features that *they* think are important.
> I'm not saying that Windows would be dead if it was open source, but we'd have versions where ads and telemetry are straight up ripped from every possible part of it.
this is what I mean. your views are incompatible with closed-source software. not saying all closed-source software needs to have telemetry, but for the average user, this stuff probably helps catch bugs and things.
local accounts, I agree, I've never bothered with Windows 11 for that reason.
it's enshittification, not weaponization.
> You can always make it sense, if you decide to do that. There's SQLite for example.
this is just not a very good point. we're talking about paid products, paid OS that is paid by an OEM or an end-user.
> Not with hardware requirements primarily, but how it herds the user and siphons data out of the computer in the name of telemetry.
what data specifically? I'm not a fan of this either and I'd always disable everything, but it might again be something that people would really not care about. and for an organization like Microsoft, telemetry is probably very useful because otherwise they'd have to rely on user reports or test everything themselves
> Ha, no. A small anecdote
I really think you're dismissing this just because of your principles like "security through obscurity isn't security"
yet security through obscurity literally works. it's not foolproof, but a lot of bugs are never found because of it. and a big part of finding bugs is to get enough information to know where to look
like you saying "look my friend got a bug 15 years ago" doesn't disprove what I claimed.
> Also, with the leaks we have learnt that NSA had a truckload of zero days to infiltrate Windows systems. Great for security, right?
and what are you saying with this? the fact that only NSA (and some others probably) had the ability to find bugs is proof that the security failed?
> Finding, fixing and evading the introduction of vulnerabilities are a lot easier if the source is open.
yes, that is why I said "in fact it can be less so if people don't have eyes on it".
> Do we know that there's no universal backdoor in Windows? I don't.
that's right. we can't know there isn't one in MacOS either.
and yes, I do know about DUAL_EC_DRBG and Crypto AG.
"Closed source something can't be audited to be secure or anything. It doesn't make it harder to attack"
It literally does. the only argument against it is that with it being open you'd have others that would catch bugs and report them to the vendor, vs. keeping it to themselves, which I think is fair, but it doesn't make it harder to attack, at least historically when you had to put a lot of effort into security research which of course the intelligence agencies could leverage. I think this is changing with LLMs.
"Security through obscurity never stopped anyone from infiltrating anything. With enough persistence, ..."
it has stopped tons of attempts. literally.
there simply isn't an infinite amount of "persistence" available to people/orgs. it takes a huge amount of time to meticulously reverse engineer and find security holes in an OS like Windows, it's like games with DRM like Denuvo, it works. it's security through obscurity, but it works, it has held off games for like 6+ months after release.
"security" doesn't mean impenetrable, there's always going to be new bugs even in Linux, Chromium and others even though they're open.
but with closed source software, it is much harder to comb through it and find bugs.
> Please, we have gone through this 30 years ago. These arguments doesn't hold water anymore.
like, I don't understand what you mean with this.
you're talking like this is a settled argument and that you're just absolutely right, closed-source software is not harder to attack and it's just propaganda from the NSA or something?
like, we can be objective and point out the flaws of closed-source software and security through obscurity, but we also have to be realistic. things may be changing now, but at least up until very recently, only the most determined actors (usually organized groups) would be able to conduct sophisticated attacks against these systems
but also remember that a lot of the major vulnerabilities against Windows have been through leaks from the CIA and etc. that is not Windows being "breached yesterday and today". and Microsoft has the resources to hire very well-paid engineers who work on security around the clock, unlike with many FOSS projects
Closed source was perfectly acceptable when planned obsolescence and government mandated kill switches/backdoors weren't a thing.
Reality vs explicit evil is a false dichotomy.
Microsoft doesn't just choose not to release source code; they send takedown notices to projects that redistribute Microsoft's proprietary software (e.g. Ninjutsu OS). They also put clauses in the EULA for Windows to disallow reverse engineering and certain kinds of remote access (something related to if you change who has access too frequently).
Microsoft takes extra effort to prevent people from sharing or modifying Microsoft software, in order to make more money.
Yes, some of those parts are evil. The mere lack of releasing source code, or being frustrated people are using your product without paying, itself isn't.
I agree, I think.
I may have been too focused on the "false dichotomy" part and forgotten that you were talking about old Microsoft and not current Microsoft. I don't know enough about old Microsoft to say whether they were "evil" all along, so I won't comment on that part. I do agree with "don't hate the player, hate the game" in general though.
I think that mischaracterizing a business model as evil is an overloaded practice.
Is it evil to introduce terms and conditions that restrict how you expect your users to use your product? No, it's probably more hypocritical than evil; I don't think my parents telling me not to smoke while they struggled with addiction was evil, but it sure didn't model the best behaviour.
Is it evil to lobby government to curtail the freedoms of individuals to protect your business model? Yeah, probably; in most cases I believe that reducing consenting adults freedoms is usually a pretty evil act.
Microsoft is guilty of both, but I prefer to save Evil to describe actions that actively cause harm, either physically, mentally, emotionally, or in terms of harming the freedoms that people enjoy, especially if that choice to cause harm is economically motivated.
I'm not advocating on behalf of Bill Gates or Microsoft, just on clear terminology so that we can focus on actual evil behaviour versus consenting adults entering into a valid contract for mutual benefit.
Well, one aspect of evil anyhow.
Poor innocent early 00s Microsoft corrupted by the system.
The thing being described would have been in the 1980s.
> even Bill Gates
Not a big news person?
How can you say someone visiting Epstein island is not evil?
I’d like any explanation for why this is a bad question.
I think , probably, evil covers a wider spectrum than whether or not you're in bed with feds.
Source: https://www.politico.com/story/2011/04/how-microsoft-learned...
If you say something about it you are accused to be a communist because you are against free market, from people that doesn't even know what the term free market means (yes, we need rules to make the market truly free, deregulation is not the way).
A free market is like an OS without memory protection. Every process can scratch in memory everywhere they want. Some may like it, but for most people it's just terrible.
That's a deregulated market. A free market is more like an android phone (minus developer ID verification) where everyone gets a space, you can do what you want in your space, you can't intrude on others' spaces without consent, and the market is formed and boundaries are enforced by some higher power who is not part of the market and is out of reach of all market participants.
Or, you know, any actual market. Where I can sell whatever I want from my stall but I can't sabotage other people's stalls.
Yes, that's why we need regulation.
> Or, you know, any actual market. Where I can sell whatever I want from my stall but I can't sabotage other people's stalls.
Oh, if you sell in your stall oranges at 10c box, with plenty of stock, you will sabotage the other stall selling fruit. And you can do that because your actual business is another one.
But you don't because you don't have the money to afford infinite free oranges. If you did, you wouldn't be running a fruit stall.
This is why one - myself, in this case - should never use analogies. I skipped the part where having the other stalls going bankrupt helps your other cash-cow business.