For example, non-Samsung Android OEMs aren't allowed to directly sell devices with GrapheneOS and Google will only permit it within a quota. It can and is being worked around and there will be devices sold with GrapheneOS as the stock OS without Google restricting how many can be sold.
My guess is that the workaround is that Motorola sells them with Google-certified Android. A third-party (non-OEM) buys them in bulk and preinstalls GrapheneOS.
But this is really end-90s/begin-00s Microsoft levels of anti-competitiveness. I'm surprised that (particularly non-US) regulators are not investigating them yet.
Grapheneos has been known to exaggerate or misconstrue facts in their communication sometimes. Do we know what is actually being forbidden by Google here?
If an OEM ships grapheneos then what? There's a quota? What's the source? And if they go beyond then what? They can no longer be certified for the playstore? But they can still ship grapheneos and grapheneos doesn't respect the play X terms of services anyway.
Or you could also find a source and explain since the GrapeneOS dude does have a social media history full of accusations of conspiracy against them with tenuous connection to actual truth.
The Pixel 11 is the first Pixel phone to be released after the RAMpocolypse. It has made a lot of compromises in the name of lowering cost. I am definitely going to skip that generation. I tend to upgrade every 3 years, but there really isn't a big driver to do so right now. My Pixel 8 is holding up great. If I broke it and needed to buy a new phone today, I'd probably get a used Pixel 10 instead of a new 11.
Just be careful with the 8 because their motherboards tend to randomly fry themselves - both me and a friend had this happen around 2 years into owning ours and there are a decent number of people online with the same issue. Switched to the 10a on sale right before the price hike and man I'm glad I did. It'll probably be the last great Pixel if hardware costs keep getting worse and Google keeps shoving Gemini down everyone's throats.
I had this happen twice with pixel 5a's as well. Older, but just to say I'm not sure this is limited to the 8 line. One of them literally just died in my hand and was unfixable.
If you're worried about things like this you should probably switch to a physical sim and just earmark some money so you can buy a new phone when it happens and transfer the sim. Maybe get some yubikeys while you're at it.
Device operating systems are neither reliable nor trustworthy enough. If a device is going to contain your digital soul, it should be simple and pluggable.
I had an 8 Pro and it had a fantastic run, and it was probably the best phone I ever had until I upgraded to the 10 Pro.
Sadly I never, ever put the 8 Pro in any case or protective shell, and the damage of repeated minor drops took its toll. The screen was just cracked a tiny bit around the corners, but eventually the upper-right corner began a creeping black amoeba of darkness, and finally the entire touchscreen became unreliable, I suppose due to that damage, so I decided to bail out. Repairs were exorbitant so I decided to take Google's own trade-in deal.
It's an emotional discussion about Google not supporting MTE on Pixel 11 (old news of August, GrapheneOS had to roll back that statement in September [0]).
Now the question is whether MTE will be enabled by Google as part of a future OS-upgrade, to which there is no definite answer AFAIK
MTE support in itself says nothing as vendors usually obscure implementation details and also MTE is a perfect place to implant undocumented backdoors for security services to use.
This reads like “your front door lock is the perfect place for security services to have a master key.” True, but not strong as an argument against having a lock.
>This reads like “your front door lock is the perfect place for security services to have a master key
Even that analogy fails because MTE is in addition to existing countermeasures against memory corruption attacks. In the worst case, compromising MTE just means you don't have MTE, not that you get arbitrary code execution.
Not surprised, since it wasn't used in Android to begin with they probably thought nobody will notice if it's removed. And indeed, for the vast majority of people nobody will notice.
The field is certainly moving in the opposite direction. Apple has their own extension of MTE (MIE) and uses it in the kernel and a bunch of system processor. Samsung has had MTE support in flagship Exynos for some years now and they started experimenting with MTE in the OneUI 9 betas (not sure what the MTE status in the final release is).
Serious question about phone security: do phone application operating systems do anything to protect against the device's real-time OS from being able to access RAM/Disk that's being used by the application OS? Because if that cannot be controlled security at the application OS level is meaningless.
>do phone application operating systems do anything to protect against the device's real-time OS from being able to access RAM/Disk that's being used by the application OS? Because if that cannot be controlled security at the application OS level is meaningless.
If you're talking about the baseband, AFAIK it's already isolated on both iPhones and pixels. Not sure about other androids.
Security isn't just an absolute, it's also a multi-faceted series of defense-in-depth measures.
Can you get arbitrary code execution on the RTOS from another app? No? Then adding layers to protect apps from each other is meaningful.
What you're saying isn't too far from "Well, if the attacker has physical access they can just freeze and decap the memory to read all secrets, so like there's no point in even hashing passwords or fixing XSS"
>It appears Google cut an important security feature to save money.
If you're doing comms for a serious project, it's probably best not to speculate on the justification of an internal decision at a different org, even if you're reasonably sure.
Because? The obvious implication is you're saying Google will abuse their monopoly to hurt you if you upset them. Is that what you're implying? Or is it user trust, or something else you think is improved by avoiding such speculation?
>For example, non-Samsung Android OEMs aren't allowed to directly sell devices with GrapheneOS and Google will only permit it within a quota. It can and is being worked around and there will be devices sold with GrapheneOS as the stock OS without Google restricting how many can be sold.
I think at this point is too late for complicity, they are actively fighting against GrapheneOS anyway. You either fight back, or wait until you loose all the leverage
English version:
Yes, please buy the low volume phone from a 5% market share manufacturer.
Someone high up got tired of having to pull over every pixel user at the border.
With the new Motorola, TSA lines are going to move faster than ever!
If you care about privacy, stay away from the moto release and stick with pixel.
For reference Pixels have about 1% market share, the graphene phones will be the same hardware as normal moto flagships and 99% of TSA agents won't be able to differentiate motorola models
Moreover motorola flagships (ie. the only model that support grapheneos for now) are likely a fraction of the market share of motorola as a whole, so OP is still correct in that motorola grapheneos phones are more identifiable.
>the graphene phones will be the same hardware as normal moto flagships and 99% of TSA agents won't be able to differentiate motorola models
That argument could be used for pixels as well, which are also just generic black rectangles, especially the "a" models that lack the distinctive camera bump. Also if DHS/ICE really wanted to, they could avoid this problem altogether by requiring travelers to self-declare what phone they have. Sure, you can lie, but then you committed a federal offense by lying on immigration paperwork.
My pixel 7 is starting to get long in the tooth, I know I'll run it into the ground but I'm starting to wonder where I'll go for the next one now that Google is increasingly locking down their platform.
Motorola Signature 27, since that seems to be the phone that is going to support GrapheneOS? I have a P10P, but I'm very excited that they are working with a manufacturer that actually supports them. I'll most likely buy the Signature 27 at some point, just to vote with my wallet (even if the P10P) is still fine.
As others have said, this is not the most recent status update (it depends on future Google changes in QPR1 or QPR2).
The much more interesting recent news IMO is that Google is not allowing (non-Samsung) OEMs to sell devices with GrapheneOS:
https://news.ycombinator.com/item?id=49946698
See the last paragraph.
For example, non-Samsung Android OEMs aren't allowed to directly sell devices with GrapheneOS and Google will only permit it within a quota. It can and is being worked around and there will be devices sold with GrapheneOS as the stock OS without Google restricting how many can be sold.
My guess is that the workaround is that Motorola sells them with Google-certified Android. A third-party (non-OEM) buys them in bulk and preinstalls GrapheneOS.
But this is really end-90s/begin-00s Microsoft levels of anti-competitiveness. I'm surprised that (particularly non-US) regulators are not investigating them yet.
You can always notify the EC anti competition whatsdpg through their wistleblower portal:)
with how EC has been behaving recently that might make things worse..
Also reminiscent of iirc Intel's choke hold on companies like Dell that froze out AMD
Grapheneos has been known to exaggerate or misconstrue facts in their communication sometimes. Do we know what is actually being forbidden by Google here?
If an OEM ships grapheneos then what? There's a quota? What's the source? And if they go beyond then what? They can no longer be certified for the playstore? But they can still ship grapheneos and grapheneos doesn't respect the play X terms of services anyway.
So what's really going on here?
> If an OEM ships grapheneos then what? There's a quota? What's the source?
The linked comment was posted a day ago by what appears to be an account used for speaking officially about GrapheneOS.
So, like, you could go ask.
Or you could also find a source and explain since the GrapeneOS dude does have a social media history full of accusations of conspiracy against them with tenuous connection to actual truth.
The Pixel 11 is the first Pixel phone to be released after the RAMpocolypse. It has made a lot of compromises in the name of lowering cost. I am definitely going to skip that generation. I tend to upgrade every 3 years, but there really isn't a big driver to do so right now. My Pixel 8 is holding up great. If I broke it and needed to buy a new phone today, I'd probably get a used Pixel 10 instead of a new 11.
Yeah, I've got a 10 Pro, jumped up from an 8. Looked briefly at upgrading to the 11 but it's clearly not worth it.
Just be careful with the 8 because their motherboards tend to randomly fry themselves - both me and a friend had this happen around 2 years into owning ours and there are a decent number of people online with the same issue. Switched to the 10a on sale right before the price hike and man I'm glad I did. It'll probably be the last great Pixel if hardware costs keep getting worse and Google keeps shoving Gemini down everyone's throats.
I had this happen twice with pixel 5a's as well. Older, but just to say I'm not sure this is limited to the 8 line. One of them literally just died in my hand and was unfixable.
So just use it until the motherboard dies, why switch before it dies?
Just off the dome:
- Suddenly being without a phone while you're travelling or dealing with something important is generally not fun
- Anything stored locally that isn't backed up is gone
- You can't transfer over your eSIM yourself
- Probably going to be a pain in the ass to get into accounts where the now brick was set up for 2FA
If you're worried about things like this you should probably switch to a physical sim and just earmark some money so you can buy a new phone when it happens and transfer the sim. Maybe get some yubikeys while you're at it.
Device operating systems are neither reliable nor trustworthy enough. If a device is going to contain your digital soul, it should be simple and pluggable.
All of those things are possibilities with any phone. If you're not prepared for the loss/damage/failure of your phone that's on you.
I had an 8 Pro and it had a fantastic run, and it was probably the best phone I ever had until I upgraded to the 10 Pro.
Sadly I never, ever put the 8 Pro in any case or protective shell, and the damage of repeated minor drops took its toll. The screen was just cracked a tiny bit around the corners, but eventually the upper-right corner began a creeping black amoeba of darkness, and finally the entire touchscreen became unreliable, I suppose due to that damage, so I decided to bail out. Repairs were exorbitant so I decided to take Google's own trade-in deal.
> Just be careful with the 8
Don't forget the notorious vertical pink line issue! Luckily that had (has?) an extended warranty programme.
Is there a point in changing a phone so often if it's not broken?
Att offered such good trade in rates for my phone that it’s been effectively free to upgrade to the last two generations.
Or even Google itself. I got a 150€ trade in rebate for an iPhone 8 with a cracked screen.
it's not free because it's priced into the phone plan (phone plan price is jacked up), unless you got grandfathered in w/ a good rate.
My Pixel 3 is still going strong! :)
The Pixel 10 Pro is even fairly cheap in many countries if you can live with 128GB storage and the base model still has 16GB RAM.
I never thought about it like that, damn.
Quite a bad signal-to-noise ratio in this link.
It's an emotional discussion about Google not supporting MTE on Pixel 11 (old news of August, GrapheneOS had to roll back that statement in September [0]).
Now the question is whether MTE will be enabled by Google as part of a future OS-upgrade, to which there is no definite answer AFAIK
[0] https://news.ycombinator.com/item?id=49536384
I wonder what the comms would have been without the Motorola partnership
MTE support in itself says nothing as vendors usually obscure implementation details and also MTE is a perfect place to implant undocumented backdoors for security services to use.
Any evidence of those backsoors?
This reads like “your front door lock is the perfect place for security services to have a master key.” True, but not strong as an argument against having a lock.
>This reads like “your front door lock is the perfect place for security services to have a master key
Even that analogy fails because MTE is in addition to existing countermeasures against memory corruption attacks. In the worst case, compromising MTE just means you don't have MTE, not that you get arbitrary code execution.
Not surprised, since it wasn't used in Android to begin with they probably thought nobody will notice if it's removed. And indeed, for the vast majority of people nobody will notice.
The field is certainly moving in the opposite direction. Apple has their own extension of MTE (MIE) and uses it in the kernel and a bunch of system processor. Samsung has had MTE support in flagship Exynos for some years now and they started experimenting with MTE in the OneUI 9 betas (not sure what the MTE status in the final release is).
Serious question about phone security: do phone application operating systems do anything to protect against the device's real-time OS from being able to access RAM/Disk that's being used by the application OS? Because if that cannot be controlled security at the application OS level is meaningless.
>do phone application operating systems do anything to protect against the device's real-time OS from being able to access RAM/Disk that's being used by the application OS? Because if that cannot be controlled security at the application OS level is meaningless.
If you're talking about the baseband, AFAIK it's already isolated on both iPhones and pixels. Not sure about other androids.
Security isn't just an absolute, it's also a multi-faceted series of defense-in-depth measures.
Can you get arbitrary code execution on the RTOS from another app? No? Then adding layers to protect apps from each other is meaningful.
What you're saying isn't too far from "Well, if the attacker has physical access they can just freeze and decap the memory to read all secrets, so like there's no point in even hashing passwords or fixing XSS"
So Arm built in MTE but Google have decided to prevent access to it at the firmware level?
Have they introduced some other mitigations, for eg UAF, to improve memory safety?
It seems possible that nixing MTE is to prevent stomping on some TLAs exploits?
>It appears Google cut an important security feature to save money.
If you're doing comms for a serious project, it's probably best not to speculate on the justification of an internal decision at a different org, even if you're reasonably sure.
>best not to
Because? The obvious implication is you're saying Google will abuse their monopoly to hurt you if you upset them. Is that what you're implying? Or is it user trust, or something else you think is improved by avoiding such speculation?
>For example, non-Samsung Android OEMs aren't allowed to directly sell devices with GrapheneOS and Google will only permit it within a quota. It can and is being worked around and there will be devices sold with GrapheneOS as the stock OS without Google restricting how many can be sold.
I think at this point is too late for complicity, they are actively fighting against GrapheneOS anyway. You either fight back, or wait until you loose all the leverage
It's hard to tell, is this a new announcement?
Looks like that post was last edited August 30th. On Sept 1st they posted saying they think they found a way forward [1].
[1]: https://grapheneos.social/@GrapheneOS/117194007157499435
It was posted 29 Aug
Old news
GrapheneOS last said they should be able to support Pixel 11 along with the Motorola phones
Yes please buy the low volume phone from a 5% market share manufacturer.
Someone high up got tired to pull over every pixel user at the border.
With the new Motorola, TSA line are going to move faster that ever!
If you care about privacy, stay away for the moto release and stick with pixel.
English version: Yes, please buy the low volume phone from a 5% market share manufacturer. Someone high up got tired of having to pull over every pixel user at the border. With the new Motorola, TSA lines are going to move faster than ever! If you care about privacy, stay away from the moto release and stick with pixel.
For reference Pixels have about 1% market share, the graphene phones will be the same hardware as normal moto flagships and 99% of TSA agents won't be able to differentiate motorola models
>For reference Pixels have about 1% market share,
You're off by a factor of 3, unless you count global market share, which includes random brands unlikely to be in the US like xiaomi or huawei.
https://counterpointresearch.com/en/insights/us-smartphone-m...
Moreover motorola flagships (ie. the only model that support grapheneos for now) are likely a fraction of the market share of motorola as a whole, so OP is still correct in that motorola grapheneos phones are more identifiable.
>the graphene phones will be the same hardware as normal moto flagships and 99% of TSA agents won't be able to differentiate motorola models
That argument could be used for pixels as well, which are also just generic black rectangles, especially the "a" models that lack the distinctive camera bump. Also if DHS/ICE really wanted to, they could avoid this problem altogether by requiring travelers to self-declare what phone they have. Sure, you can lie, but then you committed a federal offense by lying on immigration paperwork.
> With the new Motorola, TSA line are going to move faster that ever!
I missed a news story. Context?
My pixel 7 is starting to get long in the tooth, I know I'll run it into the ground but I'm starting to wonder where I'll go for the next one now that Google is increasingly locking down their platform.
Motorola Signature 27, since that seems to be the phone that is going to support GrapheneOS? I have a P10P, but I'm very excited that they are working with a manufacturer that actually supports them. I'll most likely buy the Signature 27 at some point, just to vote with my wallet (even if the P10P) is still fine.