We have a partial port of GrapheneOS to the Pixel 11 series after a week of work on it. We’re unable to complete the port due to lack of support for ARM hardware memory tagging in software, firmware and near certainly hardware. It appears Google cut an important security feature to save money.

ARM hardware memory tagging (MTE) is used by GrapheneOS across the entire base OS including the kernel and every standard base OS process. It’s only temporarily disabled for a few device-specific processes. It greatly improves protection against nearly all remote exploits and many local exploits.

Pixel 8 launched with hardware MTE support in October 2023. We integrated it into our hardened_malloc project and began using it across the OS later that month. Android and the Pixel OS never started using it by default. Android Advanced Protection Mode in Android 16 enables it for a few processes.

Apple’s Memory Integrity Enforcement (MIE) is an always enabled feature on the iPhone 17. It’s simply a high quality implementation of MTE using the latest standard extensions. It uses MTE in the most secure mode in the kernel and a large portion of userbase. They did a very good job integrating it.

Apple’s MIE and Android 16+ AAPM don’t use MTE for user installed apps unless those explicitly opt in. GrapheneOS enables it for more apps automatically and has a toggle for users to opt-in for every user installed app. There’s a per-app toggle to opt-out for incompatible apps which is uncommon.

Neither iOS or Android encourage app developers to opt into MTE and other more aggressive security features used in the base OS. Apple’s docs warn developers of performance and stability issues. Even Signal doesn’t opt-in. Our approach enables forcing using MTE in the standard allocators regardless.

Pixel 11 does have security improvements including moving to post-quantum secure verified boot (ML-DSA) and replacing Samsung Shannon IMS with AOSP IMS. Titan M3 should significantly improve protection against data extraction in Before First Unlock state. It’s too bad they ruined it by cutting MTE.

Pixel 11 series is a lot more expensive for an incremental improvement to the CPU, the same underpowered GPU and reduced RAM for the Pro base models. They finally caught up to the last generation of Qualcomm cellular radio. It’s overpriced, the upgrades aren’t impressive and losing MTE is appalling.

Compared to the Pixel 11, a Snapdragon 8 Elite Gen 5 has 40% higher single threaded CPU performance, 80% higher multi threaded performance, over 100% higher GPU performance and a far better cellular radio. It also finally has MTE. The next gen is what will be in the first Motorola with GrapheneOS.

Pixel 9a and earlier (including Nexus devices) were the Android Open Source Project reference devices. Pixel support was removed from AOSP with Android 16. It’s now harder to support Pixels than many other devices and massive progress towards open source firmware and driver libraries was discarded.

Compared to the stock Pixel OS, GrapheneOS ships AOSP patches months earlier and Linux kernel patches many months earlier. However, we rely on them for firmware and most driver updates. We also want to move to new kernel branches earlier. These things can be improved with our Motorola partnership.

We strongly recommend against buying Pixel 11 devices. Pixel 8, 9 and 10 have much better overall security for GrapheneOS. Pixel 10 is cheaper with similar hardware and MTE. Pixel 11’s Titan M3 should improve BFU security for users without a strong passphrase, but losing MTE craters AFU security.

We haven’t determined what to do about this situation. It may be best for us to skip the Pixel 11 series devices. We can shift our focus entirely to the upcoming Motorola devices instead. Pixel 10a was really a 9th gen Pixel, so hopefully the Pixel 11a does the same with 10th gen and includes MTE.

  • Enkrod@feddit.org
    link
    fedilink
    English
    arrow-up
    5
    ·
    edit-2
    1 hour ago

    Skipping Pixel 11 is the correct response imho. Graphene is security first and has a reputation of making no compromises on it. This underscores their dedication. It’s great really that the cooperation with Motorola means they will not need to rely on a single device series.

    I really hope we’ll one day see a Fairphone that supports the security requirements.

    • Pirate_lemmy_arrrrR@lemmy.dbzer0.com
      link
      fedilink
      English
      arrow-up
      1
      ·
      19 minutes ago

      Same situation. Just bought a base 10 model a couple weeks before the 11 came out. Now I’m just waiting for US Mobile to unlock the phone so I can move to graphene.

      Coming from a galaxy S10+ though, and it seems 90% of the “improvements” since then have been Gemini, and well Gemini.

      If my S10 wasn’t a US model that can’t be unlocked and stuck on Android 12, which bank apps were starting to no longer support, it could still handle everything I needed it for.

  • ByteMe@lemmy.world
    link
    fedilink
    English
    arrow-up
    93
    ·
    edit-2
    16 hours ago

    I love how grapheneos posts never hold back. They always expose Google

    • Lka1988@lemmy.dbzer0.com
      link
      fedilink
      English
      arrow-up
      25
      ·
      11 hours ago

      Unfortunately, Daniel doesn’t hold back anywhere, including those who have genuine concerns about his behavior (dude is seriously paranoid, in the medical sense).

    • Creat@discuss.tchncs.de
      link
      fedilink
      English
      arrow-up
      26
      ·
      15 hours ago

      Which is kind of ironic as the only phones supported by them were Google phones, as they were the only ones meeting their security requirements. More specifically their security principals is what those requirements are based on. Kind of telling that Google now no longer meet them either…

    • artyom@piefed.socialOP
      link
      fedilink
      English
      arrow-up
      30
      ·
      17 hours ago

      It’s a nice idea but I haven’t heard any positive reports. Motorola seems to actually want to work with GOS and keep it going, so that will probably be the best bet moving forward.

      • lenocolomo@lemmy.ml
        link
        fedilink
        English
        arrow-up
        5
        ·
        16 hours ago

        Just hope that the “flagship” price won’t resemble the name. But if, I can wait. I’m fairly happy with my Pixel 9.

        • pucker4676@lemmy.ml
          link
          fedilink
          English
          arrow-up
          8
          ·
          15 hours ago

          There’ll be an affordablish phone eventually. I’m just so happy more options are becoming available.

          I’d love a Linux phone like yesterday, but it’s going to be a looong time until we have a Linux phone on par with GrapheneOS. Who knows, maybe the GrapheneOS team will be behind the year of the Linux phone. <3

          • lenocolomo@lemmy.ml
            link
            fedilink
            English
            arrow-up
            6
            ·
            5 hours ago

            I’d love to have a Linux Phone that’ll “just work”. The best we’ve got currently (of which I think I know) is the Jolla phone, but unfortunately it still has many issues, which make it unattractive enough. Let’s just wait and see what the future bares.

        • artyom@piefed.socialOP
          link
          fedilink
          English
          arrow-up
          2
          ·
          16 hours ago

          It will. They Motorola Signature currently sells for ~$1k-1200 USD equivalent in AUS and Euro

    • hash@slrpnk.net
      link
      fedilink
      English
      arrow-up
      5
      ·
      16 hours ago

      I like the idea of a linux phone, but do current options measure up to GrapheneOS in terms of security? My uninformed impression is they don’t?

      (And don’t make me tap the security through obscurity sign.)

      • notSys@lemmy.cafe
        link
        fedilink
        English
        arrow-up
        4
        ·
        4 hours ago

        Nothing can match GOS when it comes to security.

        You also don’t need that much security (before you get mad at me, check if you don’t have a desktop PC somewhere in your house).

      • pucker4676@lemmy.ml
        link
        fedilink
        English
        arrow-up
        7
        ·
        15 hours ago

        No, not even desktop Linux. GrapheneOS is the most secure OS that I’m aware of. Android desktop mode has me a little excited. It’s not bad right now, but I wouldn’t want to work on it all day.

        • Lka1988@lemmy.dbzer0.com
          link
          fedilink
          English
          arrow-up
          3
          ·
          edit-2
          11 hours ago

          Graphene OS is the most secure OS, and it’s been proven. Not even that infamous Israeli cracking software can get into it.

          • JustEnoughDucks@feddit.nl
            link
            fedilink
            English
            arrow-up
            3
            ·
            6 hours ago

            I don’t think cellebrite even tries to get into desktop OS’s. I don’t know if there is a tool that targets both that has leaked lists of successful targets like cellebrite that would be a good comparison.

            Graphene is definitely more secure than default popular Linux distributions, but there are probably some install scripts out there that make it about equally secure.

          • pucker4676@lemmy.ml
            link
            fedilink
            English
            arrow-up
            4
            ·
            11 hours ago

            QubesOS is interesting. It basically throws every application in it’s own VM and firewalls each other off. It’s not a bad strategy at all, and they’ve integrated everything neatly, but it’s not hardened like GrapheneOS. It’s not something I’d personally want to daily drive, especially on a laptop, but neither is Android Desktop.

            • Default Username@lemmy.dbzer0.com
              link
              fedilink
              English
              arrow-up
              5
              ·
              edit-2
              10 hours ago

              What do you mean it’s not hardened like GrapheneOS? Throwing everything in isolated VMs is the same approach that the Xbox consoles have taken since the Xbox One, and those still haven’t been hacked, save for a bootrom exploit via glitching in the original model of the Xbox One before the OS loads. If one VM (or “qube” in this case) gets compromised, it is sandboxed from the rest of the machine, and no user-installed application runs on the host OS (dom0), save for what comes preinstalled, like settings applications and the GUI, and none of that touches the Internet.

              Not wanting to daily drive it is perfectly understandable, though. I personally don’t just because of the RAM requirements compared to other OSs. Also GPU passthrough breaks things on my main gaming laptop.

              • pucker4676@lemmy.ml
                link
                fedilink
                English
                arrow-up
                3
                ·
                8 hours ago

                They’re just basic Linux installs is what I mean. QubesOS isn’t much different than having a different computer running each piece of software on your LAN.

                It’s a bit of an apples to oranges comparison, though. Desktop vs mobile. Hell, I’d hardly even compare Qubes to any Linux distro. It’s so niche and clunky to use as a daily driver. It’s basically just a hypervisor. A better comparison might be secureblue.

                And a guest escaping is definitely not unheard of. https://www.techtimes.com/articles/319941/20260708/linux-kvm-guest-host-escape-hits-both-intel-amd-two-cves-required.htm

                • Emma_Gold_Man@lemmy.dbzer0.com
                  link
                  fedilink
                  English
                  arrow-up
                  2
                  ·
                  4 hours ago

                  KVM guest escapes won’t affect Qubes, which doesn’t use it. Qubes is built on Xen instead - the Linux dom0 is itself a containerized management instance. That’s not to say that Xen container escape vulnerabilities are unheard of, but it’s a smaller attack surface and they are less common.

    • xylol@leminal.space
      link
      fedilink
      English
      arrow-up
      1
      ·
      16 hours ago

      I’ve seen some of the handheld Linux distros and its so cool to see the steam library and other PC games running on small handhelds, things are moving so fast

          • Axolotl@feddit.it
            link
            fedilink
            English
            arrow-up
            1
            ·
            49 minutes ago

            They will launch the Steam VR (idr how it was called) that will be on an ARM, so it means they will also make an x86_64 emulator for ARM