172 points finnlab 2 hours ago 101 comments
Retr0id 1 hour ago | parent
arusahni 1 hour ago | parent
[1]: https://grapheneos.social/@GrapheneOS/117194007157499435
Medea 1 hour ago | parent
nubinetwork 1 hour ago | parent
jordand 1 hour ago | parent
podocarp 1 hour ago | parent
microtonal 1 hour ago | parent
rickdeckard 1 hour ago | parent
It's an emotional discussion about Google not supporting MTE on Pixel 11 (old news of August, GrapheneOS had to roll back that statement in September [0]).
Now the question is whether MTE will be enabled by Google as part of a future OS-upgrade, to which there is no definite answer AFAIK
varispeed 1 hour ago | parent
brookst 1 hour ago | parent
This reads like “your front door lock is the perfect place for security services to have a master key.” True, but not strong as an argument against having a lock.
gruez 1 hour ago | parent
Even that analogy fails because MTE is in addition to existing countermeasures against memory corruption attacks. In the worst case, compromising MTE just means you don't have MTE, not that you get arbitrary code execution.
gib444 1 hour ago | parent
Luker88 58 minutes ago | parent
Still means that currently the phone has no support for MTE.
I have bought too many things on vague promises that did not happen.
It's not there now -> it's not supported. EOL.
croes 55 minutes ago | parent
MTE but slow
mrbn100ful 1 hour ago | parent
Someone high up got tired to pull over every pixel user at the border.
With the new Motorola, TSA line are going to move faster that ever!
If you care about privacy, stay away for the moto release and stick with pixel.
lesspassiveobse 1 hour ago | parent
For reference Pixels have about 1% market share, the graphene phones will be the same hardware as normal moto flagships and 99% of TSA agents won't be able to differentiate motorola models
gruez 1 hour ago | parent
You're off by a factor of 3, unless you count global market share, which includes random brands unlikely to be in the US like xiaomi or huawei.
https://counterpointresearch.com/en/insights/us-smartphone-m...
Moreover motorola flagships (ie. the only model that support grapheneos for now) are likely a fraction of the market share of motorola as a whole, so OP is still correct in that motorola grapheneos phones are more identifiable.
>the graphene phones will be the same hardware as normal moto flagships and 99% of TSA agents won't be able to differentiate motorola models
That argument could be used for pixels as well, which are also just generic black rectangles, especially the "a" models that lack the distinctive camera bump. Also if DHS/ICE really wanted to, they could avoid this problem altogether by requiring travelers to self-declare what phone they have. Sure, you can lie, but then you committed a federal offense by lying on immigration paperwork.
aftbit 1 hour ago | parent
microtonal 1 hour ago | parent
sir_eliah 1 hour ago | parent
nkingsy 1 hour ago | parent
fouc 1 hour ago | parent
tstenner 1 hour ago | parent
gib444 44 minutes ago | parent
£50 for the 8 Plus isn't too bad though
(€150 = £127)
mystifyingpoi 58 minutes ago | parent
qurren 4 minutes ago | parent
76SlashDolphin 1 hour ago | parent
gib444 1 hour ago | parent
Don't forget the notorious vertical pink line issue! Luckily that had (has?) an extended warranty programme.
kolla 1 hour ago | parent
hbn 1 hour ago | parent
- Suddenly being without a phone while you're travelling or dealing with something important is generally not fun
- Anything stored locally that isn't backed up is gone
- You can't transfer over your eSIM yourself
- Probably going to be a pain in the ass to get into accounts where the now brick was set up for 2FA
SoftTalker 1 hour ago | parent
someonebaggy 46 minutes ago | parent
hbn 23 minutes ago | parent
__MatrixMan__ 1 hour ago | parent
Anything complex enough to get over the air updates could lose its trustworthiness at any time. If a device is going to contain your digital soul, it should be simple and pluggable.
hbn 27 minutes ago | parent
drnick1 6 minutes ago | parent
Another good reason not to buy an iPhone. As if there weren't enough good reasons already.
shermantanktop 30 minutes ago | parent
Devices need to be considered disposable. Expensive but disposable.
hbn 25 minutes ago | parent
ButlerianJihad 1 hour ago | parent
Sadly I never, ever put the 8 Pro in any case or protective shell, and the damage of repeated minor drops took its toll. The screen was just cracked a tiny bit around the corners, but eventually the upper-right corner began a creeping black amoeba of darkness, and finally the entire touchscreen became unreliable, I suppose due to that damage, so I decided to bail out. Repairs were exorbitant so I decided to take Google's own trade-in deal.
bpev 1 hour ago | parent
sigbottle 1 hour ago | parent
mylasttour 1 hour ago | parent
regularfry 1 hour ago | parent
mystifyingpoi 1 hour ago | parent
gregdeon 55 minutes ago | parent
drnick1 9 minutes ago | parent
rgblambda 1 hour ago | parent
If you're doing comms for a serious project, it's probably best not to speculate on the justification of an internal decision at a different org, even if you're reasonably sure.
mgol94 1 hour ago | parent
I think at this point is too late for complicity, they are actively fighting against GrapheneOS anyway. You either fight back, or wait until you loose all the leverage
rgblambda 22 minutes ago | parent
Edit: Maybe you replied to the wrong comment? I didn't say anything about complicity and neither did the GrapheneOS announcement in the part I quoted.
pbhjpbhj 1 hour ago | parent
Because? The obvious implication is you're saying Google will abuse their monopoly to hurt you if you upset them. Is that what you're implying? Or is it user trust, or something else you think is improved by avoiding such speculation?
rgblambda 26 minutes ago | parent
realusername 34 minutes ago | parent
microtonal 1 hour ago | parent
The much more interesting recent news IMO is that Google is not allowing (non-Samsung) OEMs to sell devices with GrapheneOS:
https://news.ycombinator.com/item?id=49946698
See the last paragraph.
For example, non-Samsung Android OEMs aren't allowed to directly sell devices with GrapheneOS and Google will only permit it within a quota. It can and is being worked around and there will be devices sold with GrapheneOS as the stock OS without Google restricting how many can be sold.
My guess is that the workaround is that Motorola sells them with Google-certified Android. A third-party (non-OEM) buys them in bulk and preinstalls GrapheneOS.
But this is really end-90s/begin-00s Microsoft levels of anti-competitiveness. I'm surprised that (particularly non-US) regulators are not investigating them yet.
morkalork 1 hour ago | parent
pipodeclown 1 hour ago | parent
Xelbair 1 hour ago | parent
cherryteastain 56 minutes ago | parent
[1] https://fightchatcontrol.eu/chat-control-overview
[2] https://waag.org/en/article/european-digital-id-wallets-are-...
[3] https://en.wikipedia.org/wiki/EU_Kids_Act
[4] https://www.androidauthority.com/why-i-use-grapheneos-on-pix...
realusername 14 minutes ago | parent
Google was found guilty by the EU antitrust investigation and payed a 4 billions euros fine (and Google has changed nothing since then, they only increased the pressure).
GrapheneOS is especially annoying for them as it destroys their blanket excuse that it's ""for security""
alerighi 58 minutes ago | parent
amelius 55 minutes ago | parent
someonebaggy 49 minutes ago | parent
Or, you know, any actual market. Where I can sell whatever I want from my stall but I can't sabotage other people's stalls.
amelius 38 minutes ago | parent
darkwater 32 minutes ago | parent
Oh, if you sell in your stall oranges at 10c box, with plenty of stock, you will sabotage the other stall selling fruit. And you can do that because your actual business is another one.
someonebaggy 52 minutes ago | parent
subarctic 43 minutes ago | parent
someonebaggy 41 minutes ago | parent
bayindirh 36 minutes ago | parent
Bill Gates published that infamous open letter about copying software, and both Bill Gates and Brad Smith said that Microsoft's core pillar is IP: "Microsoft is built upon the idea of having IP and protecting and using it" (paraphrased by me).
The quotes I can find by digging the net:
> Microsoft was founded on the premise that software is valuable intellectual property that people should pay for. --Bill Gates
> Microsoft was founded on intellectual property. Intellectual property is the foundation of our business. --Brad Smith (This is the quote I remember in the first place)
So, Microsoft never wanted to be an open company. They were the epitome of the closed source, behemoth software company, where you get the goods, get to use it, and pay them for the privilege.
someonebaggy 31 minutes ago | parent
bayindirh 27 minutes ago | parent
I also understand that we need to eat and have bills to pay, and there are many ways to achieve that, incl. Free or Closed Source software.
What I'm against is weaponization of closed source software beyond reasonable point. To EEE, to deprecate otherwise capable and functional hardware in the market, to limit user freedom or to extort money.
I hope I made my point clear.
Furthermore:
> I've worked at software companies - have you?
I didn't work at a software company per se, yet I develop open source software for the projects we work on, and I know what preparing a codebase for publishing entails. I also worked as a tech-lead of a Linux distribution, and a nation-wide one at that. I know what it entails, trust me.
If we're talking about experience in terms of years, I'm doing this for ~20 years, using Linux for ~25 years, and using computers in a level I understand what programming them entails for ~30 years.
So yeah, I'm not that newbie who have seen some Python and tied themselves to a knot of awe.
> causes a lot of risk,
Don't let's get into FUD territory of "Free Software is insecure", shall we? We see how Windows has been breached yesterday and today, and will see it more for years to come, as with other software.
> and provides absolutely no benefit whatsoever so it is simply irrational to do it.
Hmm, I'll agree to disagree here because 90% of the thing your digital stack is living on is Open Source and Free Software.
I don't have time to flesh out the benefit and irrationality aspect of it, because I mean, it's plainly wrong when it's put that squarely. We can find some nuances maybe, but it's limited to certain scenarios.
b112 35 minutes ago | parent
runjake 15 minutes ago | parent
ajross 49 minutes ago | parent
To be That Guy, Apple is not allowing anyone anywhere to sell any devices with anything but MacOS/iOS.
> But this is really end-90s/begin-00s Microsoft levels of anti-competitiveness.
It's not even the most anti-competitive in the market of 2026!
microtonal 25 minutes ago | parent
Apple doesn't allow Apple selling Apple devices with other operating systems.
Google doesn't allow other OEMs selling the OEMs' devices with other operating systems.
Big difference.
(Yes, pedantics: I know that OEMs could sell devices with other OSes, but not being able to sell GMS Android devices would lose them most of their customers.)
bayindirh 39 minutes ago | parent
Every company is nice until the monies they earn is not guaranteed anymore. They were closing the doors they have intentionally left open in the name of security for a couple of generations.
Now they're being more open about why they are limiting user choice. Because like Chrom(e/ium), Android is designed to be a large data sink for Google to feed The Machine.
lukan 13 minutes ago | parent
Also maintaining the monopoly over the app market and getting a good cut out of every transaction within. A non google controlled device in the mass market can introduce new markets independent of google (and not paying them).
They would not like that.
HumblyTossed 25 minutes ago | parent
Was this ever the deal with Moto? They announced something recently, but it didn't read like Moto would be distributing devices with preinstalled GOS. Just that it would be able to run GOS.
surgical_fire 17 minutes ago | parent
Absolute anti-competitive behavior. "Android is open, but not really"
Aissen 10 minutes ago | parent
You mean like the Skyhook vs Google 2014 lawsuit? (look it up) Settled before it could go any further.
Pxtl 1 hour ago | parent
microtonal 1 hour ago | parent
someonebaggy 43 minutes ago | parent
rkozik1989 1 hour ago | parent
TheDong 1 hour ago | parent
Can you get arbitrary code execution on the RTOS from another app? No? Then adding layers to protect apps from each other is meaningful.
What you're saying isn't too far from "Well, if the attacker has physical access they can just freeze and decap the memory to read all secrets, so like there's no point in even hashing passwords or fixing XSS"
gruez 1 hour ago | parent
If you're talking about the baseband, AFAIK it's already isolated on both iPhones and pixels. Not sure about other androids.
izacus 1 hour ago | parent
surajrmal 53 minutes ago | parent
someonebaggy 42 minutes ago | parent
pbhjpbhj 1 hour ago | parent
Have they introduced some other mitigations, for eg UAF, to improve memory safety?
It seems possible that nixing MTE is to prevent stomping on some TLAs exploits?
surajrmal 47 minutes ago | parent
In terms of mitigation of UAF, a great deal of new code written for Android userspace these days is in memory safe languages such as rust. Also, a lot of testing with instrumented code sanitizers is still done before release. We don't know how much risk MTE actually mitigates.
atlgator 19 minutes ago | parent