• AmbitiousProcess (they/them)@piefed.social
          link
          fedilink
          English
          arrow-up
          19
          arrow-down
          1
          ·
          2 hours ago

          It wasn’t just the update cycle either, it’s that they don’t have the physical hardware chips to support Graphene’s minimum requirements for security, which would severely weaken any benefits you actually get from GrapheneOS.

            • AmbitiousProcess (they/them)@piefed.social
              link
              fedilink
              English
              arrow-up
              16
              ·
              1 hour ago

              Entirely lacking disk encryption for typical users due to not having a secure element is a pretty major flaw.

              It’s also missing hardware accelerated virtualization which is necessary for much of GrapheneOS’s sandboxing, has weak security for other keys in the OS keystore, is missing hardware memory tagging which makes it much easier for apps to use overflow attacks, doesn’t have proper verified boot support once a custom alternative OS is flashed, and leaves exposed debugging APIs even when the phone is locked.

              This breaks:

              • Secure app spawning
              • Memory corruption protection
              • Integer overflow protection
              • Most of Graphene’s kernel hardening
              • Much of Graphene’s attack surface reduction abilities
              • Hardware-based attestation and security monitoring
              • Quick tile protection pre-unlock
              • Debugging access prevention
              • Verified Boot
              • The security of your PIN against any automated attack

              At that point, GrapheneOS can’t physically provide you essentially any security anymore.

              • devfuuu@lemmy.world
                link
                fedilink
                English
                arrow-up
                5
                arrow-down
                1
                ·
                45 minutes ago

                It really depends on what security level you want out of a phone. Most people are concerned with a pickpocket stealing and being able to access everything. Most of the world doesn’t need the security level required to pass through the united states border control. Which they will just force to put the pin anyways or put you in jail for even having a secure device.

                • rumba@lemmy.zip
                  link
                  fedilink
                  English
                  arrow-up
                  1
                  ·
                  13 minutes ago

                  Well sans duress password being a good idea now, when you get to the border, you can either unlock it or they’ll just confiscate it. You don’t get to be on their list and go through with a phone because they can’t manage to decrypt it.

      • Zedd_Prophecy@lemmy.world
        link
        fedilink
        English
        arrow-up
        1
        ·
        2 hours ago

        I haven’t heard of this. Looking into it there’s at least a year wait. I’d consider it - though my Edge 2022 battery may not make it until then. Damn thing was crap from day 1.

        • lokalhorst@feddit.org
          link
          fedilink
          English
          arrow-up
          3
          ·
          1 hour ago

          I am pretty sure Motorola plans to sell flag ship devices with GrapheneOS preinstalled. They won’t support old devices. Also the manufacturer needs to still ship firmware updates for a specific duration for GrapheneOS to support it.