Publication has been resumed Android- CalyxOS firmware, not tied to Google services

The CalyxOS 7.2.2.0 project, which develops firmware based on the platform, has been released. Android, freed from Google service dependencies and offering additional privacy and security features. CalyxOS 7.2.2.0 is the first stable release since the update suspension last August, which was prompted by the need to rework the release process, conduct a full audit, and change cryptographic keys following the departure of the project founder and technical lead, who had access to the digital signature keys. The new release has been migrated to the codebase. Android 16 and is available in builds for Pixel 4-9, Fairphone 4/5, Motorola Moto G32-G84, and SHIFTphone 8 devices.

Instead of Google services, CalyxOS offers the microG suite, which offers an alternative implementation of the Google Play, Google Cloud Messaging, and Google Maps APIs that doesn't require installing proprietary Google components. Instead of the Google Network Location Provider for Wi-Fi and base station location services, a layer using Positon or BeaconDB is used. Nominatim from the OpenStreetMap project is used for address-to-location conversion (Geocoding Service).

To control access to the network, the Datura firewall is used, which allows you to restrict access to the network in relation to individual applications, connection methods (Wi-Fi, mobile network, VPN) and activity (for example, you can deny access to apps running in the background). There's an interface for monitoring app permissions. The default browser is Calyx Chromium with the DuckDuckGo search engine, with the Tor Browser available as an option. F-Droid and Aurora Store (an alternative anonymous client for Google Play) are available for installing apps.

Other features of CalyxOS:

  • A privacy-focused calling interface with built-in end-to-end encrypted calls via Signal and WhatsApp messaging apps. Sensitive phone numbers, such as helplines, are hidden from call logs.
  • Block unknown USB devices by default.
  • Function to turn off Wi-Fi, Bluetooth, microphone and camera after a certain period of inactivity.
  • Block network access for recently installed applications.
  • The ability to use profiles to separate work and personal activity, isolating data and applications between profiles.
  • Integrated VPN support with pre-installed apps for Tor and Riseup. The phone can be used as a hotspot (USB or Wi-Fi) with traffic forwarded through a VPN or Tor.
  • System verification using a digital signature to protect against firmware tampering or malicious modification.
  • Automatic monthly delivery of updates in OTA (over-the-air) mode.
  • Panic button for emergency data cleaning and deletion of specific applications.
  • An automated application backup system that allows you to save backups to a USB drive or to Nextcloud cloud storage with client-side encryption.
  • Using CoMaps for maps, OnionShare for file sharing and Thunderbird for email.

Among the changes in the new release, in addition to the transition to Android 16, support for the SHIFTphone 8 smartphone and updates to built-in apps are being implemented. Builds are digitally signed using a new private key stored in a redesigned infrastructure based on a hardware security module (HSM), which has passed a security audit and is not controlled by individual participants. Plans include resuming regular OTA updates and releasing CalyxOS 8 based on Android 17.

The new firmware digital signature infrastructure was built to eliminate dependency on individual participants and protect against key leakage in the event of a system compromise. The YubiHSM 2 USB token was selected as the HSM module for hardware key storage and performing digital signature operations without extracting keys. Since each supported device and firmware component requires a separate key to generate a digital signature, and all keys do not fit on the YubiHSM 2 USB token, multilayer encryption was used: only the base primary key (wrap key) is permanently stored in the HSM, while the keys for creating digital signatures are stored externally in a form encrypted with the primary key. When creating a digital signature, the required encrypted external key is loaded into the HSM, decrypted by the primary key within the HSM, and used to generate signatures without extracting keys from the HSM using tools that support the PKCS#11 standard (apksigner, signapk, and OpenSSL).

A new computer purchased at a random store was used to generate the primary private key, create a backup copy, and write the key to the HSM. Without an internet connection, the Tails distribution was loaded in live mode from a pre-verified DVD, from which two YubiHSM 2 USB tokens (primary and backup) were configured and initialized. Additionally, a key backup was created using the Shamir partitioning scheme, dividing the key into five parts and distributing it among five trusted individuals (in the event of a USB token failure, at least three parts would need to be reassembled to restore the key).

Source: opennet.ru

Buy reliable hosting for sites with DDoS protection, VPS VDS servers 🔥 Buy reliable website hosting with DDoS protection, VPS VDS servers | ProHoster