For example, non-Samsung Android OEMs aren't allowed to directly sell devices with GrapheneOS and Google will only permit it within a quota. It can and is being worked around and there will be devices sold with GrapheneOS as the stock OS without Google restricting how many can be sold.
My guess is that the workaround is that Motorola sells them with Google-certified Android. A third-party (non-OEM) buys them in bulk and preinstalls GrapheneOS.
But this is really end-90s/begin-00s Microsoft levels of anti-competitiveness. I'm surprised that (particularly non-US) regulators are not investigating them yet.
> But this is really end-90s/begin-00s Microsoft levels of anti-competitiveness. I'm surprised that (particularly non-US) regulators are not investigating them yet.
Every company is nice until the monies they earn is not guaranteed anymore. They were closing the doors they have intentionally left open in the name of security for a couple of generations.
Now they're being more open about why they are limiting user choice. Because like Chrom(e/ium), Android is designed to be a large data sink for Google to feed The Machine.
"Because like Chrom(e/ium), Android is designed to be a large data sink for Google to feed The Machine."
Also maintaining the monopoly over the app market and getting a good cut out of every transaction within. A non google controlled device in the mass market can introduce new markets independent of google (and not paying them).
I saw an interview with Bill Gates once where he said that one thing he would've done differently is more quickly come around to the idea of sending people to Washington. Apparently he didn't like the idea of lobbying and that cost them when the regulators started coming for them
Wow, then there we go: don't hate the player, hate the game. You're telling me even Bill Gates wasn't evil until the system forced him to either become evil or get shut down.
Bill Gates published that infamous open letter about copying software, and both Bill Gates and Brad Smith said that Microsoft's core pillar is IP: "Microsoft is built upon the idea of having IP and protecting and using it" (paraphrased by me).
The quotes I can find by digging the net:
> Microsoft was founded on the premise that software is valuable intellectual property that people should pay for. --Bill Gates
> Microsoft was founded on intellectual property. Intellectual property is the foundation of our business. --Brad Smith (This is the quote I remember in the first place)
So, Microsoft never wanted to be an open company. They were the epitome of the closed source, behemoth software company, where you get the goods, get to use it, and pay them for the privilege.
Closed source software is a reality, not an explicit evil. It is the same reason I don't have schematics for my bedframe. I've worked at software companies - have you? - it takes extra effort to release source code, causes a lot of risk, and provides absolutely no benefit whatsoever so it is simply irrational to do it.
I'm not an opponent/critic of closed source software or enemy of it. I pay for quite a few high quality closed source software packages, and I like them as much as the Free Software counterparts which I use every day.
I also understand that we need to eat and have bills to pay, and there are many ways to achieve that, incl. Free or Closed Source software.
What I'm against is weaponization of closed source software beyond reasonable point. To EEE, to deprecate otherwise capable and functional hardware in the market, to limit user freedom or to extort money.
I hope I made my point clear.
Furthermore:
> I've worked at software companies - have you?
I didn't work at a software company per se, yet I develop open source software for the projects we work on, and I know what preparing a codebase for publishing entails. I also worked as a tech-lead of a Linux distribution, and a nation-wide one at that. I know what it entails, trust me.
If we're talking about experience in terms of years, I'm doing this for ~20 years, using Linux for ~25 years, and using computers in a level I understand what programming them entails for ~30 years.
So yeah, I'm not that newbie who have seen some Python and tied themselves to a knot of awe.
> causes a lot of risk,
Don't let's get into FUD territory of "Free Software is insecure", shall we? We see how Windows has been breached yesterday and today, and will see it more for years to come, as with other software.
> and provides absolutely no benefit whatsoever so it is simply irrational to do it.
Hmm, I'll agree to disagree here because 90% of the thing your digital stack is living on is Open Source and Free Software.
I don't have time to flesh out the benefit and irrationality aspect of it, because I mean, it's plainly wrong when it's put that squarely. We can find some nuances maybe, but it's limited to certain scenarios.
by weaponization you mean Win 11 requiring specific hardware etc?
your comment honestly just sounds like you dislike closed-source software.
for most commercial software projects, releasing the source provides no tangible benefit, aside from people like HNers being happy
but if Microsoft would've open sourced their OS, they would've been vulnerable to their OS being diluted into free versions or maybe even OEM-maintained versions
from a business sense, it makes no sense.
and as for security, closed source software is harder to attack (and was a lot harder to attack before LLMs). like, there's still much that we don't know about Windows internals exactly, and even those who do are a very small group of people.
it'd be a lot easier to find vulnerabilities if the source was open.
yes, it doesn't mean it's automatically more secure, in fact it can be less so if people don't have eyes on it, but I'd say the amount of attacks is less and usually done by more sophisticated attackers
Weaponization of closed source software could take many forms and is just part of the general weaponization of market mechanisms that businesses do.
Right now it doesn't really affect me that Ableton Live is closed-source. But it would affect me if the main method of sharing music on the internet was Ableton Live project files.
> My guess is that the workaround is that Motorola sells them with Google-certified Android.
Was this ever the deal with Moto? They announced something recently, but it didn't read like Moto would be distributing devices with preinstalled GOS. Just that it would be able to run GOS.
> But this is really end-90s/begin-00s Microsoft levels of anti-competitiveness. I'm surprised that (particularly non-US) regulators are not investigating them yet.
You mean like the Skyhook vs Google 2014 lawsuit? (look it up) Settled before it could go any further.
EU is hell bent on locking "your" devices down as much as possible so they can shove their big brother spyware down your throat under the guise of "protecting the kids" [1]. They are building tons of EU and national level apps where strong Play Integrity is required [2] and will pair these up with the need to prove your identity to "make sure you are an adult" everywhere on the internet [3]. At least one EU country, Spain, has already begun to profile people based on whether they may be running phone OSes other than Google blessed ones [4]
They probably know already, it's not the first time it happens. See the illegal pressure Google has made against OEM after CyanogenMod wanted to go commercial.
Google was found guilty by the EU antitrust investigation and payed a 4 billions euros fine (and Google has changed nothing since then, they only increased the pressure).
GrapheneOS is especially annoying for them as it destroys their blanket excuse that it's ""for security""
To be That Guy, Apple is not allowing anyone anywhere to sell any devices with anything but MacOS/iOS.
Apple doesn't allow Apple selling Apple devices with other operating systems.
Google doesn't allow other OEMs selling the OEMs' devices with other operating systems.
Big difference.
(Yes, pedantics: I know that OEMs could sell devices with other OSes, but not being able to sell GMS Android devices would lose them most of their customers.)
Then they'll be breaching their contract with Google so they'll lose the benefits of the contract, such as being allowed to preinstall the play store or Google apps like Gmail, or to call them Android devices. They might also be required to pay Google millions or billions of dollars in compensation for lost revenue.
Or you could also find a source and explain since the GrapeneOS dude does have a social media history full of accusations of conspiracy against them with tenuous connection to actual truth.
If you say something about it you are accused to be a communist because you are against free market, from people that doesn't even know what the term free market means (yes, we need rules to make the market truly free, deregulation is not the way).
A free market is like an OS without memory protection. Every process can scratch in memory everywhere they want. Some may like it, but for most people it's just terrible.
That's a deregulated market. A free market is more like an android phone (minus developer ID verification) where everyone gets a space, you can do what you want in your space, you can't intrude on others' spaces without consent, and the market is formed and boundaries are enforced by some higher power who is not part of the market and is out of reach of all market participants.
Or, you know, any actual market. Where I can sell whatever I want from my stall but I can't sabotage other people's stalls.
> Or, you know, any actual market. Where I can sell whatever I want from my stall but I can't sabotage other people's stalls.
Oh, if you sell in your stall oranges at 10c box, with plenty of stock, you will sabotage the other stall selling fruit. And you can do that because your actual business is another one.
The Pixel 11 is the first Pixel phone to be released after the RAMpocolypse. It has made a lot of compromises in the name of lowering cost. I am definitely going to skip that generation. I tend to upgrade every 3 years, but there really isn't a big driver to do so right now. My Pixel 8 is holding up great. If I broke it and needed to buy a new phone today, I'd probably get a used Pixel 10 instead of a new 11.
To be fair, the trade in offers are larger this year than during P10 release window, at least where I live. So I was able to go from 10 Pro 16/256 to 11P 16/512 for something like 650 eur. It's a great deal IMHO as the SoC + modem combo is at least 30 to 40% more efficient. The phone runs faster, cooler and I don't have the battery anxiety that I got after 10 Pro.
I used the OP15 in the meantime and its ram management and (ironically enough) performance in day to day apps was somehow much worse. It unloaded apps, skipped notifications, apps took longer to open. Google have put in a lot of work into software ahead of the rampocalipse.
Just be careful with the 8 because their motherboards tend to randomly fry themselves - both me and a friend had this happen around 2 years into owning ours and there are a decent number of people online with the same issue. Switched to the 10a on sale right before the price hike and man I'm glad I did. It'll probably be the last great Pixel if hardware costs keep getting worse and Google keeps shoving Gemini down everyone's throats.
I had this happen twice with pixel 5a's as well. Older, but just to say I'm not sure this is limited to the 8 line. One of them literally just died in my hand and was unfixable.
If you're worried about things like this you should probably switch to a physical sim and just earmark some money so you can buy a new phone when it happens and transfer the sim. Maybe get some yubikeys while you're at it.
Anything complex enough to get over the air updates could lose its trustworthiness at any time. If a device is going to contain your digital soul, it should be simple and pluggable.
I use an eSim adaptor in my physical sim slot. You can then transfer eSims effortlessly between phones. This seems the obvious solution to get the best of both worlds - all the good things about eSims, none of the bad.
Yes but I don't want my phone to be lost or destroyed or stolen. So using a phone that will likely fail until it does so is not taking preventative measures.
I had an 8 Pro and it had a fantastic run, and it was probably the best phone I ever had until I upgraded to the 10 Pro.
Sadly I never, ever put the 8 Pro in any case or protective shell, and the damage of repeated minor drops took its toll. The screen was just cracked a tiny bit around the corners, but eventually the upper-right corner began a creeping black amoeba of darkness, and finally the entire touchscreen became unreliable, I suppose due to that damage, so I decided to bail out. Repairs were exorbitant so I decided to take Google's own trade-in deal.
I have Pixel 9a and considered Pixel 10 for a while, but seeing Pixel 11 show up with absurdly microscopic improvements over 10 made me realize, that this smartphone line is just a solved problem since years ago.
Same thing here, I will keep my 10a for the foreseeable figure. It's unclear if future Pixels will support GOS at all, and the new Motorola is almost certainly going to be a $1000+ phone. Hopefully mid-range models will follow. I don't need a huge, expensive phone with five cameras.
I know it's not really an argument, but I tend to change my devices also every 2-3 years, just so I can pass the "old" one to my less technical family.
I hear people say things like this about phones, laptops and cars, but anecdotally I have never once seen any sort of trade-in offer, and only rarely and arguably on any kind of lease or lease-to-buy arrangement, where I would consider that even remotely true.
Huh, good point. I wonder if this is the beginning of the end of constant phone upgrades. It used to be that new phones had much better hardware, so software that was only tested on new phones would make an older phone grind to a halt. But if the upgrades are much more incremental, perhaps a phone will last a lot longer?
It's an emotional discussion about Google not supporting MTE on Pixel 11 (old news of August, GrapheneOS had to roll back that statement in September [0]).
Now the question is whether MTE will be enabled by Google as part of a future OS-upgrade, to which there is no definite answer AFAIK
> It still has at least bare minimum support for MTE at a hardware level. We think they removed most of the hardware acceleration from the CPU cache to save money. They ruined the performance so it ended up being fully disabled in firmware. It may still be usable.
MTE support in itself says nothing as vendors usually obscure implementation details and also MTE is a perfect place to implant undocumented backdoors for security services to use.
This reads like “your front door lock is the perfect place for security services to have a master key.” True, but not strong as an argument against having a lock.
>This reads like “your front door lock is the perfect place for security services to have a master key
Even that analogy fails because MTE is in addition to existing countermeasures against memory corruption attacks. In the worst case, compromising MTE just means you don't have MTE, not that you get arbitrary code execution.
>It appears Google cut an important security feature to save money.
If you're doing comms for a serious project, it's probably best not to speculate on the justification of an internal decision at a different org, even if you're reasonably sure.
>For example, non-Samsung Android OEMs aren't allowed to directly sell devices with GrapheneOS and Google will only permit it within a quota. It can and is being worked around and there will be devices sold with GrapheneOS as the stock OS without Google restricting how many can be sold.
I think at this point is too late for complicity, they are actively fighting against GrapheneOS anyway. You either fight back, or wait until you loose all the leverage
Because? The obvious implication is you're saying Google will abuse their monopoly to hurt you if you upset them. Is that what you're implying? Or is it user trust, or something else you think is improved by avoiding such speculation?
Innuendo about how large organizations make decisions, issued by people who have never had a job, are de rigueur for open source activists and catnip for HN.
Not surprised, since it wasn't used in Android to begin with they probably thought nobody will notice if it's removed. And indeed, for the vast majority of people nobody will notice.
The field is certainly moving in the opposite direction. Apple has their own extension of MTE (MIE) and uses it in the kernel and a bunch of system processor. Samsung has had MTE support in flagship Exynos for some years now and they started experimenting with MTE in the OneUI 9 betas (not sure what the MTE status in the final release is).
MTE requires several things to work well. Notably there is some missing hardware believed to be necessary for MTE to be performant on the pixel 11.
In terms of mitigation of UAF, a great deal of new code written for Android userspace these days is in memory safe languages such as rust. Also, a lot of testing with instrumented code sanitizers is still done before release. We don't know how much risk MTE actually mitigates.
English version:
Yes, please buy the low volume phone from a 5% market share manufacturer.
Someone high up got tired of having to pull over every pixel user at the border.
With the new Motorola, TSA lines are going to move faster than ever!
If you care about privacy, stay away from the moto release and stick with pixel.
For reference Pixels have about 1% market share, the graphene phones will be the same hardware as normal moto flagships and 99% of TSA agents won't be able to differentiate motorola models
Moreover motorola flagships (ie. the only model that support grapheneos for now) are likely a fraction of the market share of motorola as a whole, so OP is still correct in that motorola grapheneos phones are more identifiable.
>the graphene phones will be the same hardware as normal moto flagships and 99% of TSA agents won't be able to differentiate motorola models
That argument could be used for pixels as well, which are also just generic black rectangles, especially the "a" models that lack the distinctive camera bump. Also if DHS/ICE really wanted to, they could avoid this problem altogether by requiring travelers to self-declare what phone they have. Sure, you can lie, but then you committed a federal offense by lying on immigration paperwork.
My pixel 7 is starting to get long in the tooth, I know I'll run it into the ground but I'm starting to wonder where I'll go for the next one now that Google is increasingly locking down their platform.
Motorola Signature 27, since that seems to be the phone that is going to support GrapheneOS? I have a P10P, but I'm very excited that they are working with a manufacturer that actually supports them. I'll most likely buy the Signature 27 at some point, just to vote with my wallet (even if the P10P) is still fine.
Serious question about phone security: do phone application operating systems do anything to protect against the device's real-time OS from being able to access RAM/Disk that's being used by the application OS? Because if that cannot be controlled security at the application OS level is meaningless.
There are several peripherals running their own OS. Those have their access to RAM limited by an iommu and they have no direct access to the primary storage (they may have some local ROM storage for firmware). If you're asking about the other OS that runs on the application processor such as the bootloaders, trusted firmware, trusted os, etc, then no, those have a superset of access to what the primary OS running on those cores have access to. This is by design.
>do phone application operating systems do anything to protect against the device's real-time OS from being able to access RAM/Disk that's being used by the application OS? Because if that cannot be controlled security at the application OS level is meaningless.
If you're talking about the baseband, AFAIK it's already isolated on both iPhones and pixels. Not sure about other androids.
Security isn't just an absolute, it's also a multi-faceted series of defense-in-depth measures.
Can you get arbitrary code execution on the RTOS from another app? No? Then adding layers to protect apps from each other is meaningful.
What you're saying isn't too far from "Well, if the attacker has physical access they can just freeze and decap the memory to read all secrets, so like there's no point in even hashing passwords or fixing XSS"
What's meant by "your device's real-time OS"? Heard several variations of this questioning recently and it seems more like FUD than anything else. I presume it's a telephone game away from the fact that some modem processors have DMA access and are network-facing and exploitable?
Yes, at least Pixels and Apple devices do (the Titan/T security chips handle disk encryption and communication and are behind IOMMU which disallows direct acces from things like modems).
The much more interesting recent news IMO is that Google is not allowing (non-Samsung) OEMs to sell devices with GrapheneOS:
https://news.ycombinator.com/item?id=49946698
See the last paragraph.
For example, non-Samsung Android OEMs aren't allowed to directly sell devices with GrapheneOS and Google will only permit it within a quota. It can and is being worked around and there will be devices sold with GrapheneOS as the stock OS without Google restricting how many can be sold.
My guess is that the workaround is that Motorola sells them with Google-certified Android. A third-party (non-OEM) buys them in bulk and preinstalls GrapheneOS.
But this is really end-90s/begin-00s Microsoft levels of anti-competitiveness. I'm surprised that (particularly non-US) regulators are not investigating them yet.
Every company is nice until the monies they earn is not guaranteed anymore. They were closing the doors they have intentionally left open in the name of security for a couple of generations.
Now they're being more open about why they are limiting user choice. Because like Chrom(e/ium), Android is designed to be a large data sink for Google to feed The Machine.
Also maintaining the monopoly over the app market and getting a good cut out of every transaction within. A non google controlled device in the mass market can introduce new markets independent of google (and not paying them).
They would not like that.
Bill Gates published that infamous open letter about copying software, and both Bill Gates and Brad Smith said that Microsoft's core pillar is IP: "Microsoft is built upon the idea of having IP and protecting and using it" (paraphrased by me).
The quotes I can find by digging the net:
> Microsoft was founded on the premise that software is valuable intellectual property that people should pay for. --Bill Gates
> Microsoft was founded on intellectual property. Intellectual property is the foundation of our business. --Brad Smith (This is the quote I remember in the first place)
So, Microsoft never wanted to be an open company. They were the epitome of the closed source, behemoth software company, where you get the goods, get to use it, and pay them for the privilege.
I also understand that we need to eat and have bills to pay, and there are many ways to achieve that, incl. Free or Closed Source software.
What I'm against is weaponization of closed source software beyond reasonable point. To EEE, to deprecate otherwise capable and functional hardware in the market, to limit user freedom or to extort money.
I hope I made my point clear.
Furthermore:
> I've worked at software companies - have you?
I didn't work at a software company per se, yet I develop open source software for the projects we work on, and I know what preparing a codebase for publishing entails. I also worked as a tech-lead of a Linux distribution, and a nation-wide one at that. I know what it entails, trust me.
If we're talking about experience in terms of years, I'm doing this for ~20 years, using Linux for ~25 years, and using computers in a level I understand what programming them entails for ~30 years.
So yeah, I'm not that newbie who have seen some Python and tied themselves to a knot of awe.
> causes a lot of risk,
Don't let's get into FUD territory of "Free Software is insecure", shall we? We see how Windows has been breached yesterday and today, and will see it more for years to come, as with other software.
> and provides absolutely no benefit whatsoever so it is simply irrational to do it.
Hmm, I'll agree to disagree here because 90% of the thing your digital stack is living on is Open Source and Free Software.
I don't have time to flesh out the benefit and irrationality aspect of it, because I mean, it's plainly wrong when it's put that squarely. We can find some nuances maybe, but it's limited to certain scenarios.
your comment honestly just sounds like you dislike closed-source software.
for most commercial software projects, releasing the source provides no tangible benefit, aside from people like HNers being happy
but if Microsoft would've open sourced their OS, they would've been vulnerable to their OS being diluted into free versions or maybe even OEM-maintained versions
from a business sense, it makes no sense.
and as for security, closed source software is harder to attack (and was a lot harder to attack before LLMs). like, there's still much that we don't know about Windows internals exactly, and even those who do are a very small group of people.
it'd be a lot easier to find vulnerabilities if the source was open.
yes, it doesn't mean it's automatically more secure, in fact it can be less so if people don't have eyes on it, but I'd say the amount of attacks is less and usually done by more sophisticated attackers
Right now it doesn't really affect me that Ableton Live is closed-source. But it would affect me if the main method of sharing music on the internet was Ableton Live project files.
Was this ever the deal with Moto? They announced something recently, but it didn't read like Moto would be distributing devices with preinstalled GOS. Just that it would be able to run GOS.
You mean like the Skyhook vs Google 2014 lawsuit? (look it up) Settled before it could go any further.
Absolute anti-competitive behavior. "Android is open, but not really"
[1] https://fightchatcontrol.eu/chat-control-overview
[2] https://waag.org/en/article/european-digital-id-wallets-are-...
[3] https://en.wikipedia.org/wiki/EU_Kids_Act
[4] https://www.androidauthority.com/why-i-use-grapheneos-on-pix...
Google was found guilty by the EU antitrust investigation and payed a 4 billions euros fine (and Google has changed nothing since then, they only increased the pressure).
GrapheneOS is especially annoying for them as it destroys their blanket excuse that it's ""for security""
To be That Guy, Apple is not allowing anyone anywhere to sell any devices with anything but MacOS/iOS.
> But this is really end-90s/begin-00s Microsoft levels of anti-competitiveness.
It's not even the most anti-competitive in the market of 2026!
Apple doesn't allow Apple selling Apple devices with other operating systems.
Google doesn't allow other OEMs selling the OEMs' devices with other operating systems.
Big difference.
(Yes, pedantics: I know that OEMs could sell devices with other OSes, but not being able to sell GMS Android devices would lose them most of their customers.)
The linked comment was posted a day ago by what appears to be an account used for speaking officially about GrapheneOS.
So, like, you could go ask.
Or, you know, any actual market. Where I can sell whatever I want from my stall but I can't sabotage other people's stalls.
Oh, if you sell in your stall oranges at 10c box, with plenty of stock, you will sabotage the other stall selling fruit. And you can do that because your actual business is another one.
I used the OP15 in the meantime and its ram management and (ironically enough) performance in day to day apps was somehow much worse. It unloaded apps, skipped notifications, apps took longer to open. Google have put in a lot of work into software ahead of the rampocalipse.
- Suddenly being without a phone while you're travelling or dealing with something important is generally not fun
- Anything stored locally that isn't backed up is gone
- You can't transfer over your eSIM yourself
- Probably going to be a pain in the ass to get into accounts where the now brick was set up for 2FA
Devices need to be considered disposable. Expensive but disposable.
Anything complex enough to get over the air updates could lose its trustworthiness at any time. If a device is going to contain your digital soul, it should be simple and pluggable.
Another good reason not to buy an iPhone. As if there weren't enough good reasons already.
Sadly I never, ever put the 8 Pro in any case or protective shell, and the damage of repeated minor drops took its toll. The screen was just cracked a tiny bit around the corners, but eventually the upper-right corner began a creeping black amoeba of darkness, and finally the entire touchscreen became unreliable, I suppose due to that damage, so I decided to bail out. Repairs were exorbitant so I decided to take Google's own trade-in deal.
Don't forget the notorious vertical pink line issue! Luckily that had (has?) an extended warranty programme.
£50 for the 8 Plus isn't too bad though
(€150 = £127)
It's an emotional discussion about Google not supporting MTE on Pixel 11 (old news of August, GrapheneOS had to roll back that statement in September [0]).
Now the question is whether MTE will be enabled by Google as part of a future OS-upgrade, to which there is no definite answer AFAIK
[0] https://news.ycombinator.com/item?id=49536384
Still means that currently the phone has no support for MTE.
I have bought too many things on vague promises that did not happen.
It's not there now -> it's not supported. EOL.
MTE but slow
It has no MTE right now, okay. Is there any evidence on the rest?
This reads like “your front door lock is the perfect place for security services to have a master key.” True, but not strong as an argument against having a lock.
Even that analogy fails because MTE is in addition to existing countermeasures against memory corruption attacks. In the worst case, compromising MTE just means you don't have MTE, not that you get arbitrary code execution.
If you're doing comms for a serious project, it's probably best not to speculate on the justification of an internal decision at a different org, even if you're reasonably sure.
I think at this point is too late for complicity, they are actively fighting against GrapheneOS anyway. You either fight back, or wait until you loose all the leverage
Edit: Maybe you replied to the wrong comment? I didn't say anything about complicity and neither did the GrapheneOS announcement in the part I quoted.
Because? The obvious implication is you're saying Google will abuse their monopoly to hurt you if you upset them. Is that what you're implying? Or is it user trust, or something else you think is improved by avoiding such speculation?
Have they introduced some other mitigations, for eg UAF, to improve memory safety?
It seems possible that nixing MTE is to prevent stomping on some TLAs exploits?
In terms of mitigation of UAF, a great deal of new code written for Android userspace these days is in memory safe languages such as rust. Also, a lot of testing with instrumented code sanitizers is still done before release. We don't know how much risk MTE actually mitigates.
[1]: https://grapheneos.social/@GrapheneOS/117194007157499435
Someone high up got tired to pull over every pixel user at the border.
With the new Motorola, TSA line are going to move faster that ever!
If you care about privacy, stay away for the moto release and stick with pixel.
For reference Pixels have about 1% market share, the graphene phones will be the same hardware as normal moto flagships and 99% of TSA agents won't be able to differentiate motorola models
Every Google Pixel model per generation ends up supported.
DO NOT UNDERESTIMATE TSA.
Social hardening is a real problem.
You're off by a factor of 3, unless you count global market share, which includes random brands unlikely to be in the US like xiaomi or huawei.
https://counterpointresearch.com/en/insights/us-smartphone-m...
Moreover motorola flagships (ie. the only model that support grapheneos for now) are likely a fraction of the market share of motorola as a whole, so OP is still correct in that motorola grapheneos phones are more identifiable.
>the graphene phones will be the same hardware as normal moto flagships and 99% of TSA agents won't be able to differentiate motorola models
That argument could be used for pixels as well, which are also just generic black rectangles, especially the "a" models that lack the distinctive camera bump. Also if DHS/ICE really wanted to, they could avoid this problem altogether by requiring travelers to self-declare what phone they have. Sure, you can lie, but then you committed a federal offense by lying on immigration paperwork.
I missed a news story. Context?
If you're talking about the baseband, AFAIK it's already isolated on both iPhones and pixels. Not sure about other androids.
Can you get arbitrary code execution on the RTOS from another app? No? Then adding layers to protect apps from each other is meaningful.
What you're saying isn't too far from "Well, if the attacker has physical access they can just freeze and decap the memory to read all secrets, so like there's no point in even hashing passwords or fixing XSS"