• mfed1122@discuss.tchncs.de
    link
    fedilink
    English
    arrow-up
    0
    ·
    1 month ago

    I love graphene, but I hope they’re planning to also roll out some very strong stock software - or else this will make for a very rough first impression on a large audience of normies and hurt graphene’s long run chance of success. The camera, gallery, and app store in particular will not come up to many users’ standards.

    • anon_8675309@lemmy.world
      link
      fedilink
      English
      arrow-up
      0
      ·
      1 month ago

      There are some really talented people working on the camera systems for Apple and Google etc. what I don’t get is surely there are some equally talented engineers (in image processing) who love open source so why aren’t they working on an open source camera platform?

      It seems an itch that’s not getting scratched.

      • Ernest@lemmy.zip
        link
        fedilink
        English
        arrow-up
        0
        ·
        1 month ago

        idk if this is the case here but on a firmware level, interfacing with these camera chips almost always requires an NDA that they’ll only sign with very large minimum orders

        • JustEnoughDucks@slrpnk.net
          link
          fedilink
          English
          arrow-up
          0
          ·
          1 month ago

          This is also why open source wearables can’t have the best PPG heart rate/SPO2 tracking.

          There are only about 4 PPG analog front ends still in production that don’t require an NDA and the Max86141 is the only one worth anything it seems.

          You can’t do analog front ends with any small FPGAs that I know of and it is simply to large to do it (well, at least) on a small wearable with discrete components.

    • rumba@lemmy.zip
      link
      fedilink
      English
      arrow-up
      0
      ·
      1 month ago

      Motorola should be able to lead them into the right direction for this. Moto controls their own drivers and while i don’t know, i don’t expect they’re using stock android camera, they can probably just provide the camera app to graphene

    • Sophienomenal@lemmy.blahaj.zone
      link
      fedilink
      English
      arrow-up
      0
      ·
      1 month ago

      My impression from the article is that the Motorola phones ship with default Android, but flashing to GrapheneOS is officially supported. So it would only be people who would be flashing GrapheneOS anyway.

      • mfed1122@discuss.tchncs.de
        link
        fedilink
        English
        arrow-up
        0
        ·
        1 month ago

        Yeah by “switch to” they probably do mean flash. I could have sworn they had plans to ship Graphene phones but maybe that’s a later phase.

        • Sophienomenal@lemmy.blahaj.zone
          link
          fedilink
          English
          arrow-up
          0
          ·
          1 month ago

          There are some third party vendors online that ship pre-flashed GrapheneOS phones iirc, but I don’t believe there has ever been on with it factory installed.

            • Sophienomenal@lemmy.blahaj.zone
              link
              fedilink
              English
              arrow-up
              0
              ·
              1 month ago

              I agree, you should always flash it yourself. Though GrapheneOS does have the Auditor app to attest the integrity of the operating system against another GrapheneOS device. It’s always going to be best practice to do it yourself, however.

        • late_pessimistic@slrpnk.net
          link
          fedilink
          English
          arrow-up
          0
          ·
          1 month ago

          I could have sworn they had plans to ship Graphene phones

          They do. They say it in their roadmap:

          Hardware and firmware security are core parts of the project, but it’s currently limited to research and submitting suggestions and bug reports upstream. In the long term, the project will need to move into the hardware space.

          https://grapheneos.org/faq#roadmap

        • pHr34kY@lemmy.world
          link
          fedilink
          English
          arrow-up
          0
          ·
          1 month ago

          Would you trust a pre-flashed phone though?

          I guess with GOS they have integrity checkers.

          • mfed1122@discuss.tchncs.de
            link
            fedilink
            English
            arrow-up
            0
            ·
            1 month ago

            At least for right now I would trust one that had the backing of the Graphene devs. Them and Signal are probably the two most rock solid trust sources right now. (Of course this must constantly be reevaluated)

    • chronicledmonocle@lemmy.world
      link
      fedilink
      English
      arrow-up
      0
      ·
      1 month ago

      AFAIK they’re only targeting their flagship models first. Guess we’ll see, but I don’t think the Moto G series will get it. At least not initially.

  • DupaCycki@lemmy.world
    link
    fedilink
    English
    arrow-up
    0
    ·
    1 month ago

    This will apply to 2027 flagship Motorola devices, starting with a regular non-folding device, according to GrapheneOS developers who hinted at it being the successor to the Signature.

    Thank goodness it won’t just be one foldable. I was worried for a bit.

    • diaphragmwp@discuss.tchncs.de
      link
      fedilink
      English
      arrow-up
      0
      ·
      1 month ago

      All of them are foldable, many times, some just get the power button jammed at like 4 degrees and break a bit around 12 or so.

    • jaygray91@piefed.zip
      link
      fedilink
      English
      arrow-up
      0
      ·
      1 month ago

      I was hoping that when Apple released thr iPhone 17 with a horizontal island it would end the wobble on a lot of phones, as others tend to copy Apple.

      Unbelievably and fucking annoyingly, the iPhone 17 still has one of it’s fucking camera lens jut out enough to fucking wobble still. Which fucking engineer okayed this fucking shit.

      I still want a google pixel for the visor, but last year I bought a S24 Ultra as it was cheaper and I don’t like the performance of the Pixle 9 overall. (I always buy the previous gen of current year, when I need to). Oh well, after my S24U breaks maybe when pixel 14 or 15 comes around I’ll get a pixel. Or some other phone with a visor camera island like it.

        • FG_3479@lemmy.world
          link
          fedilink
          English
          arrow-up
          0
          ·
          1 month ago

          I think apps will still be developed however they will reach only the custom ROM audience which I expect will grow massively.

          • WhyJiffie@sh.itjust.works
            link
            fedilink
            English
            arrow-up
            0
            ·
            1 month ago

            I think the second part is correct, but the first one is not because lots of developers don’t use a custom ROM, and neither does a large part of their intended audience. Sadly, many people are not ready to give up the bank’s app, perhaps literally cannot give up the government app, but also hardware compatibility with most phones is not there, because of missing drivers.

    • Jyek@sh.itjust.works
      link
      fedilink
      English
      arrow-up
      0
      ·
      1 month ago

      I’m pretty sure this is wrong. Like obviously it’s a bad thing that they are making it harder to distribute apps through 3rd parties but they aren’t stopping you from sideloading unsigned apps. They are introducing an additional step to unlock your phone to allow unsigned apps. Yes it is annoying and no I do not agree with what they are doing. But they are not removing unsigned app support from all android devices.

      The new step will be deciding how long you wish to allow unsigned apps to be installable on your device (either 7 days or indefinitely) and then it requires you to wait 24 hours before you can start to uninstall apps without Google developer signing.

      These rules do suck, and it is a bad thing, but lying or exaggerating what is happening will not make them reverse course. It only justifies them when they say “it’s not that bad and it’s for your protection.”

      • leaf_skeleton@lemmy.world
        link
        fedilink
        English
        arrow-up
        0
        ·
        1 month ago

        I would agree, but that flow is through google play services not through the system itself, so google can just remove it whenever they want.

    • 1985MustangCobra@lemmy.ca
      link
      fedilink
      English
      arrow-up
      0
      ·
      1 month ago

      yeah i need my banking, only thing stopping me from using a non-googled phone. everything else can fuck off

      • leanleft@lemmy.ml
        link
        fedilink
        English
        arrow-up
        0
        ·
        1 month ago

        i dont think you need google play services for banking.
        furthermore, i disabled play services. i dont need it for 99% of apps.
        sometimes theres one cool heavily proprietary app that forces you to use it. sucks. and i just gotta uninstall it.

  • buddascrayon@lemmy.world
    link
    fedilink
    English
    arrow-up
    0
    ·
    1 month ago

    My question is, what support will there be for NFC contactless payment? The convenience of being able to not have to carry a wallet full of cards is one of the biggest things holding me back from fully embracing GrapheneOS.

    • OpenPassageways@programming.dev
      link
      fedilink
      English
      arrow-up
      0
      ·
      1 month ago

      NFC pay is not ubiquitous enough in my area so I use a phone case that has room for cards. I still need to carry a physical health insurance card and a physical ID as well so my wallet case is not going away. I actually bought a pixel 9 instead of 10 just because my favorite wallet case was available.

      I’m considering just getting a Garmin watch that I keep disconnected from my phone to use for NFC pay. Seems like I would be able to set up my cards in Garmin Pay app and then just disconnect it.

    • Nate Cox@programming.dev
      link
      fedilink
      English
      arrow-up
      0
      ·
      1 month ago

      Graphene supports NFC, but Google wallet goes out of its way not to work on it.

      If you’re in the EU you have other wallet options, in the US you’re pretty much fucked.

      I thought I would miss digital wallets way more than I actually do. Bought a slim wallet, carry just what I need, and get all the privacy benefits of not being on mainline android.

      • sunbytes@lemmy.world
        link
        fedilink
        English
        arrow-up
        0
        ·
        1 month ago

        There’s problems with the eu ones too. I barely used them anyway before but did test after installing and it errored out.

        Though yeah that could have just been google pay, now i think about it…

        • Nate Cox@programming.dev
          link
          fedilink
          English
          arrow-up
          0
          ·
          1 month ago

          I keep hearing about curve, and I saw something about walt.is just the other day… But I’m in the US without access to any of them, so I wouldn’t trust my references.

    • pjusk@lemmy.dbzer0.com
      link
      fedilink
      English
      arrow-up
      0
      ·
      1 month ago

      iirc, as of right now, its only the expensive processors that meet the security standards GrapheneOS has. Therefore only being available in the future high-end Motorola phones.

    • schipelblorp@sh.itjust.works
      link
      fedilink
      English
      arrow-up
      0
      ·
      1 month ago

      What are the odds that it filters down?

      I’ll pick up a cheap android and put Lineage on it before I buy another flagship phone.

    • ChanchoManco@lemmy.zip
      link
      fedilink
      English
      arrow-up
      0
      ·
      1 month ago

      Yeah the signature phones cost around $1.500 here in my country, my budget is $400 tops, no way I can afford that, my hopes are lost.

    • zewm@lemmy.world
      link
      fedilink
      English
      arrow-up
      0
      ·
      1 month ago

      I was looking at the lowest end pixel for Graphene (Pixel 7) and they are still nearly $400 on the aftermarket. It’s insane.

      • frongt@lemmy.zip
        link
        fedilink
        English
        arrow-up
        0
        ·
        1 month ago

        Where are you looking? I see Pixel 8s, used and unlocked, on ebay for $200-300.

      • NewOldGuard@lemmy.ml
        link
        fedilink
        English
        arrow-up
        0
        ·
        1 month ago

        Anecdotally I bought a used pixel 9a last year for ~$350, could be regional or due to ongoing inflation though

        • AlligatorBlizzard@sh.itjust.works
          link
          fedilink
          English
          arrow-up
          0
          ·
          1 month ago

          I bought a new in box old stock Pixel 9a for $350 USD a couple months ago from eBay. This was just before that Cop City protestor gave a duress password to border patrol, I wonder if that caused a bit of a spike in demand for old Pixels?

        • zewm@lemmy.world
          link
          fedilink
          English
          arrow-up
          0
          ·
          1 month ago

          I’m guessing inflation and the tech related bullshit. Everyone marking shit up.

      • excursion22@piefed.ca
        link
        fedilink
        English
        arrow-up
        0
        ·
        1 month ago

        I got a 7 Pro around 6 months ago for $280 CAD. Surely there are other less expensive sources you could find.

      • RaisinCrazyFool@kopitalk.net
        link
        fedilink
        English
        arrow-up
        0
        ·
        1 month ago

        Damn, the market’s crazy. You could get a Pixel 7 brand new, unlocked, for less than $400 when it was still current, 3 years ago.

        The only things Pixels have going for them are the aggressive sales and GrapheneOS.

    • masterofn001@lemmy.ca
      link
      fedilink
      English
      arrow-up
      0
      ·
      1 month ago

      I got a deal on a new 9 from my carrier for $5 a month for 24 months.

      $120 CAD.

      But, in canada, the phones come carrier unlocked and had no issue flashing it. Though i only ever powered it on once before it was flashed - to turn on oem unlocking. The sim was not used until then. So it didn’t do any auto downloads that might have caused a problem.

      Long short: you can find them cheap if you look.

      • Auli@lemmy.ca
        link
        fedilink
        English
        arrow-up
        0
        ·
        1 month ago

        What is your plan price though. I see lots of thee x a month for phone but they also have a really high base price.

        • masterofn001@lemmy.ca
          link
          fedilink
          English
          arrow-up
          0
          ·
          1 month ago

          In canada it’s all high. But i have 120GB data, unlimited calling and text in north America, free roaming, for 45$/mo

          So my bill is 50 + tax.

          I’ve had the phone for lver a year now.

  • daniskarma@lemmy.dbzer0.com
    link
    fedilink
    English
    arrow-up
    0
    ·
    1 month ago

    I 100% understand and support why the moved away from google.

    And Motorola was a good choice. But they really should have supported some budget phones.

    A pixel series a could easily be found for under 500€ new. These flagship motorola phones are all way over 1000€.

    And the developer clearly said they had currently no intention to support cheaper motorola phones. Among other things because Motorola won’t offer 7 year updates for anything but these flagships.

    So, I get it. But let’s face it that people on a budget will keep using pixels for GOS while they are maintained.

    • pucker4676@lemmy.ml
      link
      fedilink
      English
      arrow-up
      0
      ·
      1 month ago

      They didn’t specifically disregard budget phones. The budget phones just won’t have the hardware required to meet GrapheneOS requirements. They’ve states that as the next gen flagship hardware trickles down to the budget phones, there’ll be more options.

      • willington@lemmy.dbzer0.com
        link
        fedilink
        English
        arrow-up
        0
        ·
        1 month ago

        I keep hearing this thing about the necessary hardware.

        What is this exotic piece of hardware that the GrapheneOS needs? Please, someone tell me what it is.

          • willington@lemmy.dbzer0.com
            link
            fedilink
            English
            arrow-up
            0
            ·
            edit-2
            1 month ago

            (nothing I am about to say is necessarily personal; I am genuinely grateful for the link!)

            Is there a table of these requirements as columns and vendors as rows?

            I think most of this list is acquired by having a modern CPU or SoC, no?

            Much of the list is software requirements.

            There is one item that sticks out:

            • Support for disabling USB data and also USB as a whole at a hardware level in the USB controller

            Just how much of the hardware list is satisfied by say having a Snapdragon SoC?

            I would prefer if people said such and such vendor is missing such and such feature which we need. Always NAME the SPECIFICS. A link to a web page with the exact specifics missing for the most popular phones would help, imo. This is clear and educational. Instead we get “they don’t got no good hardware maaaan.” It’s annoying. Looks handwavy even when it is not.

            • pucker4676@lemmy.ml
              link
              fedilink
              English
              arrow-up
              0
              ·
              1 month ago

              I haven’t seem anyway respond in the way you’re complaining about.

              There’s a long list of requirements, with a big one being hardware memory tagging.

              https://www.techtimes.com/articles/325679/20260826/grapheneos-expands-motorola-better-snapdragon-radio-isolation-google-pixel.htm

              The Snapdragon 8 Elite Gen 5 — the chip inside the 2026 Motorola Signature — introduced MTE support, but only in the Elite variant. The Foundation has characterized MTE in the non-Elite Snapdragon 8 Gen 5 as effectively broken for GrapheneOS’s purposes. This is why even Motorola’s current flagship lineup cannot qualify: the chip is close but the specific hardware feature GrapheneOS treats as non-negotiable is not reliably present across the Snapdragon lineup.

    • diaphragmwp@discuss.tchncs.de
      link
      fedilink
      English
      arrow-up
      0
      ·
      1 month ago

      These flagship motorola phones are all way over 1000€

      Yes. And now it’s not going down. See, the corporation cannot make any money off of ads and analytics if there are none.

    • FG_3479@lemmy.world
      link
      fedilink
      English
      arrow-up
      0
      ·
      1 month ago

      The 2027 models will likely be flagship only however Graphene has tweeted that they plan to support cheaper Motorola phones in the future.

    • FeelThePower@lemmy.dbzer0.com
      link
      fedilink
      English
      arrow-up
      0
      ·
      1 month ago

      they didn’t abandon pixels though. they just take a little extra time because they have to manually update the old device trees now.

    • roofuskit@lemmy.world
      link
      fedilink
      English
      arrow-up
      0
      ·
      1 month ago

      Not the same company. Lenovo bought only the name of the mobile division and slapped it on their products. Google bought Motorola Mobility first, stripped it bare of all the people and IP of value and sold the name to Lenovo.

  • jobbies@lemmy.zip
    link
    fedilink
    English
    arrow-up
    0
    ·
    1 month ago

    Interestingly, Motorola itself is doing “a large portion of the work of porting GrapheneOS to their devices”.

    …and Motorola is owned by Lenovo, which is effectively controlled by the Chinese state.

    I love GrapheneOS but jumping into bed with the CCP is bad, bad idea.

    • tal@lemmy.today
      cake
      link
      fedilink
      English
      arrow-up
      0
      ·
      1 month ago

      …and Motorola is owned by Lenovo

      Huh, you’re right. I had not realized that had happened.

      It looks like it’s just their phone division, Motorola Mobility.

      • bedwyr@piefed.ca
        link
        fedilink
        English
        arrow-up
        0
        ·
        1 month ago

        What’s enslaving hundreds of millions of people to work 6 days a week 12 hours a day compared to the US president that says mean things eh?

        • Refract@lemmy.ca
          link
          fedilink
          English
          arrow-up
          0
          ·
          1 month ago

          Homie, ITS ALL China, Vietnam, Taiwan, south korea or maybe malaysia made. I’m speaking to the level of spying I want on my phone.

    • schipelblorp@sh.itjust.works
      link
      fedilink
      English
      arrow-up
      0
      ·
      edit-2
      1 month ago

      I’ll take my chances with the CCP over ICE any fucking day of the year.

      We are always under more threat from our own governments than a foreign one and I do not live in China or China-aligned country. I’m safer with my data in Beijing than in Redmond.

      And that’s the worst case scenario. Likely, it’s enough of a win for China to have an OS that the US doesn’t have backdoors into without China needing their own.

      • bedwyr@piefed.ca
        link
        fedilink
        English
        arrow-up
        0
        ·
        1 month ago

        Your data is going to the US government and data brokers, even if you don’t know it.

        • schipelblorp@sh.itjust.works
          link
          fedilink
          English
          arrow-up
          0
          ·
          1 month ago

          Source that China is using its backdoors to share information with the US? I mean, it very well might be, at least it’s an extra step. I’m saying I’d rather not share my information with anyone, but if i had to choose, it would be a foreign government ahead of my own.

          I’m not sure where I’m going wrong, there.

          • bedwyr@piefed.ca
            link
            fedilink
            English
            arrow-up
            0
            ·
            1 month ago

            Not what I meant, the US is grabbing all the information on their own, don’t think they aren’t. Maybe some of you more sophisticated computer heads can avoid it, but I wouldn’t expect it.

            They have everything compromised on a basic level, basic levels. China could sell your information back to the US too though in some kind of deal.

            But yeah I agree, I’d rather have foreign governments having it than mine own. But it’s near impossible for a layman, or person without substantial resources, to keep their information out of the hands of the NSA and data brokers, I strongly suspect, as Edward Snowden informed us.

            • schipelblorp@sh.itjust.works
              link
              fedilink
              English
              arrow-up
              0
              ·
              1 month ago

              Yup. And if I were a foreign government interested in collecting data, I’d definitely start up a low-cost VPN. You can’t trust anyone.

        • schipelblorp@sh.itjust.works
          link
          fedilink
          English
          arrow-up
          0
          ·
          1 month ago

          That’s the point: I don’t even know the name of the Chinese agency I would even theoretically need to worry about.

            • schipelblorp@sh.itjust.works
              link
              fedilink
              English
              arrow-up
              0
              ·
              1 month ago

              Not proud, not ashamed. I’m just using my ignorance of something to evaluate a risk, which is certainly a flawed and lazy algorithm, but probably operates better than chance.

          • jobbies@lemmy.zip
            link
            fedilink
            English
            arrow-up
            0
            ·
            1 month ago

            Back when Grindr was owned by a Chinese company there was concerns that data from the platform could be used to blackmail western politicians and civil servants.

            I can’t remember the details but my point is - just because you don’t live in China it doesn’t mean you’re risk free.

            • schipelblorp@sh.itjust.works
              link
              fedilink
              English
              arrow-up
              0
              ·
              1 month ago

              I’m neither a politician nor a civil servant, and if I were, as a leftist, I’d be more threatened by Trump having my data than Xi Jinping.

              Do I just keep repeating this or…?

            • schipelblorp@sh.itjust.works
              link
              fedilink
              English
              arrow-up
              0
              ·
              1 month ago

              I find your inability to understand why an American is more afraid of ICE than a Chinese government agency really perplexing.

              But, in honor of your concern, I will forthwith carry a rock that keeps away Chinese agents.

              • WhyJiffie@sh.itjust.works
                link
                fedilink
                English
                arrow-up
                0
                ·
                1 month ago

                I find your inability to understand why an American is more afraid of ICE than a Chinese government agency really perplexing.

                that’s. not. what. you. were. saying.

                you are just ignorant and proud of it.

                • schipelblorp@sh.itjust.works
                  link
                  fedilink
                  English
                  arrow-up
                  0
                  ·
                  1 month ago

                  Honestly, that was the sum totality of my intention. If you would like to review the logs and tell me where my language reflected differently, I would love to know about it because I never had an intent to say anything else.

      • jobbies@lemmy.zip
        link
        fedilink
        English
        arrow-up
        0
        ·
        1 month ago

        I think Lenovo would’ve been prevented from teaming up with Graphene if there wasn’t a way around its security measures, be that hardware or software.

        • 9tr6gyp3@lemmy.world
          link
          fedilink
          English
          arrow-up
          0
          ·
          edit-2
          1 month ago

          You believe GrapheneOS is not able protect against Motorola? Or do you think GrapheneOS is weaking the OS specifically for Motorola? Do you believe that’s also the case for Google with their Pixels and the USgovt? Are you saying stay on stock Android? Is there another mobile OS you are recommending? Your message is not clear and you seem to be making unsubstantiated claims with no evidence to back it up.

          • jobbies@lemmy.zip
            link
            fedilink
            English
            arrow-up
            0
            ·
            1 month ago

            If you read what I originally wrote I mentioned that Motorola had done most of the work in porting GOS to their hardware. To me that sounds like Motorola/Lenovo having oversight of both hardware and software. I’m not an expert in the capabilities of the Chinese state but I’d put money on them using their influence to give them an advantage on GOS.

            Again, I’m not a fan of US or Chinese tech. I’m not a fan of either regime. I don’t know what the alternatives are. I’m on an older Pixel running GOS but I won’t be upgrading to Motorola - once this phone dies I’ll probably get a dumb phone or give up mobiles entirely.

            • ArcaneSlime@lemmy.dbzer0.com
              link
              fedilink
              English
              arrow-up
              0
              ·
              1 month ago

              Good luck, dumb phone means no encryption, SMS and MMS are stored plaintext and freely shared with US three letters and phone convos have been spied on en masse since the 80s.

              For that to be effective you’d have to give up phones, smart, dumb, even carphones and landlines. Not only that, you’d have to reliably know your contacts are never contacting you through their phones, windows PCs, etc, that all themselves have that compromised HW as well. Realistically you’d need to fall back on the postal service, but people can steam open letters, so you’ll need directly employed couriers, but can you really trust anyone else? So you need to hand deliver it, but can you really trust your contact to burn after reading? Better say it face to face, if you can be sure they (or third parties) aren’t recording, but then Flock knows they were with you and they could be tortured later.

              • jobbies@lemmy.zip
                link
                fedilink
                English
                arrow-up
                0
                ·
                1 month ago

                Good luck, dumb phone means no encryption, SMS and MMS are stored plaintext and freely shared with US three letters and phone convos have been spied on en masse since the 80s.

                That wouldn’t be an issue, if say, the dumb phone existed for emergencies only.

                you’d have to give up phones

                I did mention that as a possibility

                Realistically you’d need to fall back on the postal service, but people can steam open letters

                Well there’s always carrier pigeons and jungle drums.

                • ArcaneSlime@lemmy.dbzer0.com
                  link
                  fedilink
                  English
                  arrow-up
                  0
                  ·
                  1 month ago

                  Even jungle drums, you’d need your own drum-language. If the rest of the tribe knows it…

                  You could book cypher all of your comms, I guess.

          • solrize@lemmy.ml
            link
            fedilink
            English
            arrow-up
            0
            ·
            1 month ago

            You believe GrapheneOS is not able protect against Motorola?

            Um yes? How do you protect against someone who literally controls the hardware?

            • 9tr6gyp3@lemmy.world
              link
              fedilink
              English
              arrow-up
              0
              ·
              1 month ago

              Ask GrapheneOS. Thats literally their mission.

              Device support

              Devices are carefully chosen based on their merits rather than the project aiming to have broad device support. Broad device support is counter to the aims of the project, and the project will eventually be engaging in hardware and firmware level improvements rather than only offering suggestions and bug reports upstream for those areas. Much of the work on the project involves changes that are specific to different devices, and officially supported devices are the ones targeted by most of this ongoing work.

              Hardware, firmware and software specific to devices like drivers play a huge role in the overall security of a device. The goal of the project is not to slightly improve some aspects of insecure devices and supporting a broad set of devices would be directly counter to the values of the project. A lot of the low-level work also ends up being fairly tied to the hardware.

              Non-exhaustive list of requirements for future devices, which are standards met or exceeded by current Pixel devices:

              • Support for using alternate operating systems including full hardware security functionality
              • Complete monthly Android Security Bulletin patches without any regular delays longer than a week for device support code (firmware, drivers and HALs)
              • At least 5 years of updates from launch for device support code with phones (Pixels now have 7) and 7 years with tablets
              • Device support code updated to new monthly, quarterly and yearly releases of AOSP within several months to provide new security improvements (Pixels receive these in the month they’re released)
              • Linux 6.1, 6.6 or 6.12 Generic Kernel Image (GKI) support
              • Hardware accelerated virtualization usable by GrapheneOS (ideally pKVM to match Pixels but another usable implementation may be acceptable)
              • Hardware memory tagging (ARM MTE or equivalent)
              • Hardware-based coarse grained Control Flow Integrity (CFI) for baseline coverage where type-based CFI isn’t used or can’t be deployed (BTI/PAC, CET IBT or equivalent)
              • PXN, SMEP or equivalent
              • PAN, SMAP or equivalent
              • Isolated radios (cellular, Wi-Fi, Bluetooth, NFC, etc.), GPU, SSD, media encode and decode, image processor and other components
              • Support for A/B updates of both the firmware and OS images with automatic rollback if the initial boot fails one or more times
              • Verified boot with rollback protection for firmware
              • Verified boot with rollback protection for the OS (Android Verified Boot)
              • Verified boot key fingerprint for yellow boot state displayed with a secure hash (non-truncated SHA-256 or better)
              • StrongBox keystore provided by secure element
              • Hardware key attestation support for the StrongBox keystore
              • Attest key support for hardware key attestation to provide pinning support
              • Weaver disk encryption key derivation throttling provided by secure element
              • Insider attack resistance for updates to the secure element (Owner user authentication required before updates are accepted)
              • Inline disk encryption acceleration with wrapped key support
              • 64-bit-only device support code
              • Wi-Fi anonymity support including MAC address randomization, probe sequence number randomization and no other leaked identifiers
              • Support for disabling USB data and also USB as a whole at a hardware level in the USB controller
              • Reset attack mitigation for firmware-based boot modes such as fastboot mode zeroing memory left over from the OS and delaying opening up attack surface such as USB functionality until that’s completed
              • Debugging features such as JTAG or serial debugging must be inaccessible while the device is locked

              In order to support a device, the appropriate resources also need to be available and dedicated towards it. Releases for each supported device need to be robust and stable, with all standard functionality working properly and testing for each of the releases.

              The expectation is for people to buy a secure device meeting our requirements to run GrapheneOS. Broad device support would imply mainly supporting very badly secured devices unable to support our features. It would also take a substantial amount of resources away from our work on privacy and security, especially since a lot of it is closely tied to the hardware such as the USB-C port control and fixing or working around memory corruption bugs uncovered by our features. We plan to partner with OEMs to have devices produced meeting all our requirements, providing additional privacy/security features beyond them and ideally shipping with GrapheneOS rather than massively lowering our standards.

              • solrize@lemmy.ml
                link
                fedilink
                English
                arrow-up
                0
                ·
                1 month ago

                That’s all very nice but not many of us are willing to buy a $1000 phone (or an obsolete Pixel) to get Graphene. They soon won’t be able to run it on new Pixels, and also the stuff about AOSP updates stops mattering since AOSP itself is nearly dead. The obsession with security chips (fighting the seized phone attack while comparatively ignoring much more relevant threats) is another misplaced priority. It’s the old notion of “fence post security”, putting a 100 foot fence post in the middle of the desert expecting the attacker to try to climb over it instead of going around it.1 And again, I’m amused at the idea of the US and Chinese governments allowing a Motorola (Lenovo) Graphene to be sold if it’s really that secure.

                We need a de-googled Android fork (maybe Lineage is that) on mass market phones using the hardware that those phones have. Otherwise we’re acquiescing to the notion that Elon Musk deserves more privacy than Joe Schmoe when it should be the other way around.

                1 hpmor.com chapter 115.

                • 9tr6gyp3@lemmy.world
                  link
                  fedilink
                  English
                  arrow-up
                  0
                  ·
                  1 month ago

                  That’s all very nice but not many of us are willing to buy a $1000 phone (or an obsolete Pixel) to get Graphene.

                  Pixel “a” series phones typically sell for under $500 and support GrapheneOS.

                  They soon won’t be able to run it on new Pixels, and also the stuff about AOSP updates stops mattering since AOSP itself is nearly dead.

                  Source for this?

                  The obsession with security chips (fighting the seized phone attack while comparatively ignoring much more relevant threats) is another misplaced priority. It’s the old notion of “fence post security”, putting a 100 foot fence post in the middle of the desert expecting the attacker to try to climb over it instead of going around it.1

                  The obsession with security chips is what allows Pixels and iPhones to be the most secure devices on the planet. They have some of the most researched technologies being used here. You’re literally just throwing it away based on…your link to a harry potter book? Seriously, look at the source you just shared. Its not even relevant 😂

                  And again, I’m amused at the idea of the US and Chinese governments allowing a Motorola (Lenovo) Graphene to be sold if it’s really that secure.

                  What are they going to do, ban security chips like they tried to ban encryption in the 90s?

                  We need a de-googled Android fork (maybe Lineage is that) on mass market phones using the hardware that those phones have. Otherwise we’re acquiescing to the notion that Elon Musk deserves more privacy than Joe Schmoe when it should be the other way around.

                  GrapheneOS and LineageOS are already degoogled… LineageOS is extremely subpar when it comes to security since they dont enforce it onto their hardware. GrapheneOS actually enforces it and wont work unless it has those specific security features. LineageOS doesnt solve the problem you were concerned about in your post.

    • late_pessimistic@slrpnk.net
      link
      fedilink
      English
      arrow-up
      0
      ·
      1 month ago

      Your argument is extrapolating way too much. You constructed this overcomplicated chain of thought that supposedly proves GOS sold out because… They got a manufacturer to build hardware that meets GOS requirements?

      This is no different from ZOG, deep state or Blackrock conspiracy theories.

      • jobbies@lemmy.zip
        link
        fedilink
        English
        arrow-up
        0
        ·
        1 month ago

        You constructed this overcomplicated chain of thought that supposedly proves GOS sold out

        Actually, that’s not what I’m saying. GOS is a small team, and they’ve confirmed that most of the work has been left to Motorola/Lenovo. Given what we know about the Chinese state, its not a stretch to imagine that interference has happened.

        And I’m not arguing anything. All of what I’ve said is possible based on what we know (through verifiable information in the public domain) about the activities of the Chinese state. If you choose to call that a conspiracy theory thats up to you.

      • diaphragmwp@discuss.tchncs.de
        link
        fedilink
        English
        arrow-up
        0
        ·
        edit-2
        1 month ago

        There’s not much to conspire about with BlackRock, really. They are just evil assholes.

        Anyways, check your email inbox, it should look like this.
        Palantir on Slack: new account details