We have a partial port of GrapheneOS to the Pixel 11 series after a week of work on it. We're unable to complete the port due to lack of support for ARM hardware memory tagging in software, firmware and near certainly hardware. It appears Google cut an important security feature to save money.
Why would manufacturers choose to meet GOS’s extra requirements?
There needs to be a give and take. It seems like GOS’s mantra is their way or the high way, which isn’t collaborative in the slightest.
Can there not be discussions held between Linux and sustainable/repairable OEMs and GOS to start integrating each other’s requirements? Diplomacy/negotiations/working groups are just completely neglected?
GOS is designed for maximum security at its base. It uses all the hardware features it requires to minimize its attack surface against adversaries that have infinite resources to attack the device and get at the infirmation inside.
Lowering those standards means opening a vulnerability, which means someone with that vulnerability can have their data stolen from the device in particularly that way, since that vulnerability is well documented.
How come other phones by Samsung, Apple, etc. seem to be doing alright despite not meeting the hyper restrictive requirements of GrapheneOS?
I reject that GrapheneOS can’t continue to do their work with Google Pixels and Motorola and NOT encourage open-source hardware developers to integrate GOS’s so that one day we can have open-source, privacy-first, truly-secure, repairable, sustainable communications devices.
It seems to me like GrapheneOS could lead the world in pushing this topic by creating cross-industry working groups to focus on fixing vulnerabilities in some of the most important intelligent devices existing today.
There could be organizations like IEEE or IEC that GOS may or may not work with, but no one has given me an answer for that. GOS seems self-isolated and therefore self-serving, as an outsider. I don’t understand why they can’t do more outreach to build coalitions in the industry, if they aren’t already.
There is a lot of government / intelligence agency interest in making sure devices can be hacked into… see the whole FBI vs. Apple thing from some time back.
Most device manufacturers are trying to keep costs down… adding security features adds R&D money they have to spend and pass on to the devices as sold.
Most people don’t know or care their devices are easily hackable… until it affects them personally.
Some people have to use GOS because enemy nations are targeting them and their devices in particular for hacking into, and normal devices are easy to break into… see Pegasus.
I agree that GrapheneOS is useful for some and vital for many people in the world.
What I’m asking (and demanding) is for GrapheneOS to not put all their eggs in one basket, and to develop alternatives. I don’t think GOS investing in phone manufacturing with Motorola will last forever, just as Google didn’t. Having non-corporate options is imperative as Big Tech ramps up more and more surveillance, walled off gardens, and enshittification
If GrapheneOS can’t handle the maintenance burden, there is nothing to negotiate.
Presumably, maintaining software for a niche phone requires effort similar in magnitude to a larger, mainstream phone. Why, then, would a solely privacy-oriented org choose to cater to a smaller audience?
GrapheneOS is an open-source fork of AOSP. Anyone could fork it again and provide kernel modules/drivers for their hardware.
To my knowledge, GrapheneOS is not standards-based. They take one operating system, and tweak it. I don’t know if there are relevant standards to contribute to, or even standards bodies to approve them.
Why would manufacturers choose to meet GOS’s extra requirements?
There needs to be a give and take. It seems like GOS’s mantra is their way or the high way, which isn’t collaborative in the slightest.
Can there not be discussions held between Linux and sustainable/repairable OEMs and GOS to start integrating each other’s requirements? Diplomacy/negotiations/working groups are just completely neglected?
GOS is designed for maximum security at its base. It uses all the hardware features it requires to minimize its attack surface against adversaries that have infinite resources to attack the device and get at the infirmation inside.
Lowering those standards means opening a vulnerability, which means someone with that vulnerability can have their data stolen from the device in particularly that way, since that vulnerability is well documented.
How come other phones by Samsung, Apple, etc. seem to be doing alright despite not meeting the hyper restrictive requirements of GrapheneOS?
I reject that GrapheneOS can’t continue to do their work with Google Pixels and Motorola and NOT encourage open-source hardware developers to integrate GOS’s so that one day we can have open-source, privacy-first, truly-secure, repairable, sustainable communications devices.
It seems to me like GrapheneOS could lead the world in pushing this topic by creating cross-industry working groups to focus on fixing vulnerabilities in some of the most important intelligent devices existing today.
There could be organizations like IEEE or IEC that GOS may or may not work with, but no one has given me an answer for that. GOS seems self-isolated and therefore self-serving, as an outsider. I don’t understand why they can’t do more outreach to build coalitions in the industry, if they aren’t already.
There is a lot of government / intelligence agency interest in making sure devices can be hacked into… see the whole FBI vs. Apple thing from some time back.
Most device manufacturers are trying to keep costs down… adding security features adds R&D money they have to spend and pass on to the devices as sold.
Most people don’t know or care their devices are easily hackable… until it affects them personally.
Some people have to use GOS because enemy nations are targeting them and their devices in particular for hacking into, and normal devices are easy to break into… see Pegasus.
I agree that GrapheneOS is useful for some and vital for many people in the world.
What I’m asking (and demanding) is for GrapheneOS to not put all their eggs in one basket, and to develop alternatives. I don’t think GOS investing in phone manufacturing with Motorola will last forever, just as Google didn’t. Having non-corporate options is imperative as Big Tech ramps up more and more surveillance, walled off gardens, and enshittification
If GrapheneOS can’t handle the maintenance burden, there is nothing to negotiate.
Presumably, maintaining software for a niche phone requires effort similar in magnitude to a larger, mainstream phone. Why, then, would a solely privacy-oriented org choose to cater to a smaller audience?
Can other organizations replicate GrapheneOS’s principles in ways where THOSE organizations can maintain the burden?
Is GrapheneOS working towards industry wide standards on privacy-first operating systems from the hardware up?
Are they contributing to the field at large, or are they keeping to themselves out of self preservation (or selfishness)?
GrapheneOS is an open-source fork of AOSP. Anyone could fork it again and provide kernel modules/drivers for their hardware.
To my knowledge, GrapheneOS is not standards-based. They take one operating system, and tweak it. I don’t know if there are relevant standards to contribute to, or even standards bodies to approve them.