It's an emotional discussion about Google not supporting MTE on Pixel 11 (old news of August, GrapheneOS had to roll back that statement in September [0]).
Now the question is whether MTE will be enabled by Google as part of a future OS-upgrade, to which there is no definite answer AFAIK
This reads like “your front door lock is the perfect place for security services to have a master key.” True, but not strong as an argument against having a lock.
Even that analogy fails because MTE is in addition to existing countermeasures against memory corruption attacks. In the worst case, compromising MTE just means you don't have MTE, not that you get arbitrary code execution.
Someone high up got tired to pull over every pixel user at the border.
With the new Motorola, TSA line are going to move faster that ever!
If you care about privacy, stay away for the moto release and stick with pixel.
I missed a news story. Context?
For reference Pixels have about 1% market share, the graphene phones will be the same hardware as normal moto flagships and 99% of TSA agents won't be able to differentiate motorola models
You're off by a factor of 3, unless you count global market share, which includes random brands unlikely to be in the US like xiaomi or huawei.
https://counterpointresearch.com/en/insights/us-smartphone-m...
Moreover motorola flagships (ie. the only model that support grapheneos for now) are likely a fraction of the market share of motorola as a whole, so OP is still correct in that motorola grapheneos phones are more identifiable.
>the graphene phones will be the same hardware as normal moto flagships and 99% of TSA agents won't be able to differentiate motorola models
That argument could be used for pixels as well, which are also just generic black rectangles, especially the "a" models that lack the distinctive camera bump.
If you're doing comms for a serious project, it's probably best not to speculate on the justification of an internal decision at a different org, even if you're reasonably sure.
I think at this point is too late for complicity, they are actively fighting against GrapheneOS anyway. You either fight back, or wait until you loose all the leverage
The much more interesting recent news IMO is that Google is not allowing (non-Samsung) OEMs to sell devices with GrapheneOS:
https://news.ycombinator.com/item?id=49946698
See the last paragraph.
For example, non-Samsung Android OEMs aren't allowed to directly sell devices with GrapheneOS and Google will only permit it within a quota. It can and is being worked around and there will be devices sold with GrapheneOS as the stock OS without Google restricting how many can be sold.
My guess is that the workaround is that Motorola sells them with Google-certified Android. A third-party (non-OEM) buys them in bulk and preinstalls GrapheneOS.
But this is really end-90s/begin-00s Microsoft levels of anti-competitiveness. I'm surprised that (particularly non-US) regulators are not investigating them yet.
If an OEM ships grapheneos then what? There's a quota? What's the source? And if they go beyond then what? They can no longer be certified for the playstore? But they can still ship grapheneos and grapheneos doesn't respect the play X terms of services anyway.
So what's really going on here?
Have they introduced some other mitigations, for eg UAF, to improve memory safety?
It seems possible that nixing MTE is to prevent stomping on some TLAs exploits?
Retr0id•36m ago
arusahni•32m ago
[1]: https://grapheneos.social/@GrapheneOS/117194007157499435
Medea•32m ago
nubinetwork•27m ago