A new version of the CalyxOS 2.8.0 project is available, developing a firmware based on the Android 11 platform, free from ties to Google services, and providing additional means for ensuring privacy and security. The ready-made version of the firmware is prepared for Pixel devices (2, 2 XL, 3, 3a, 3 XL, 4, 4a, 4 XL, and 5) and Xiaomi Mi A2.
Platform Features:
- Monthly formation of automatically installable updates, including current vulnerability patches.
- Priority is given to encrypted communications. By default, the Signal messenger is used. Integrated support for making encrypted calls via Signal or WhatsApp within the call interface. The K-9 mail client is provided with OpenPGP support. OpenKeychain is used for managing encryption keys.

- Support for devices with dual SIM cards and programmable SIM cards (eSIM, allows connection to mobile network operators via QR-code activation).
- By default, the DuckDuckGo Browser is used with ad and tracker blocking. The Tor Browser is also available in the system.
- Integrated support for VPN — users can choose to connect to the internet through the free VPNs Calyx and Riseup.
- When using the phone as a hotspot, there is an option to connect through VPN or Tor.
- Cloudflare DNS is available as a DNS provider.
- For installing applications, the F-Droid catalog and the Aurora Store app (an alternative client for Google Play) are offered.

- Instead of Google Network Location Provider for obtaining location information, a layer for using the Mozilla Location Service or DejaVu is offered. The OpenStreetMap Nominatim service is used for converting addresses into locations (Geocoding Service).
- A set of microG is provided instead of Google services (an alternative implementation of Google Play API, Google Cloud Messaging, and Google Maps, requiring no installation of proprietary Google components). The inclusion of microG is at the user's discretion.

- A Panic button is provided for emergency data wiping and the removal of certain applications.
- Confidential phone numbers, such as helpline numbers, are excluded from the call log.
- By default, blocking of unknown USB devices is implemented.
- The Wi-Fi and Bluetooth disabling feature is available after a certain period of inactivity.
- A firewall called Datura is used to manage application access to the network.

- To protect against firmware substitution or malicious modification during the boot phase, system verification is carried out using digital signatures.
- An automatic application backup system has been integrated. It is possible to move encrypted backups to a USB drive or to cloud storage Nextcloud.
- There is a clear interface for tracking application permissions.

Among the changes in the new release:
- Round icons and rounded dialog corners are enabled by default.
- August vulnerability fixes from the AOSP repository have been transferred.
- Protection has been added to prevent devices connected via hotspot from accessing the network bypassing the VPN if the 'Allow clients to use VPNs' setting is enabled.
- The 'Settings -> Status bar -> System icons' menu now includes the option to hide icons for disabling the microphone and camera.
- The Chromium browser engine has been updated to version 91.0.4472.164.
- A button for configuring eSIM has been added to the SetupWizard.
- Application versions have been updated.
Source: opennet.ru





