this post was submitted on 29 Aug 2026
341 points (99.1% liked)

Android

22056 readers
442 users here now

The new home of /r/Android on Lemmy and the Fediverse!

Android news, reviews, tips, and discussions about rooting, tutorials, and apps.

πŸ”—Universal Link: !android@lemdro.id


πŸ’‘Content Philosophy:

Content which benefits the community (news, rumours, and discussions) is generally allowed and is valued over content which benefits only the individual (technical questions, help buying/selling, rants, self-promotion, etc.) which will be removed if it's in violation of the rules.


Support, technical, or app related questions belong in: !askandroid@lemdro.id

For fresh communities, lemmy apps, and instance updates: !lemdroid@lemdro.id

πŸ’¬Matrix Chat

πŸ’¬Telegram channels / chats

πŸ“°Our communities below


Rules

  1. Stay on topic: All posts should be related to the Android OS or ecosystem.

  2. No support questions, recommendation requests, rants, or bug reports: Posts must benefit the community rather than the individual. Please post to !askandroid@lemdro.id.

  3. Describe images/videos, no memes: Please include a text description when sharing images or videos. Post memes to !androidmemes@lemdro.id.

  4. No self-promotion spam: Active community members can post their apps if they answer any questions in the comments. Please do not post links to your own website, YouTube, blog content, or communities.

  5. No reposts or rehosted content: Share only the original source of an article, unless it's not available in English or requires logging in (like Twitter). Avoid reposting the same topic from other sources.

  6. No editorializing titles: You can add the author or website's name if helpful, but keep article titles unchanged.

  7. No piracy or unverified APKs: Do not share links or direct people to pirated content or unverified APKs, which may contain malicious code.

  8. No unauthorized polls, bots, or giveaways: Do not create polls, use bots, or organize giveaways without first contacting mods for approval.

  9. No offensive or low-effort content: Don't post offensive or unhelpful content. Keep it civil and friendly!

  10. No affiliate links: Posting affiliate links is not allowed.

Quick Links

Our Communities

Lemmy App List

Chat and More


founded 3 years ago
MODERATORS
 

We have a partial port of GrapheneOS to the Pixel 11 series after a week of work on it. We're unable to complete the port due to lack of support for ARM hardware memory tagging in software, firmware and near certainly hardware. It appears Google cut an important security feature to save money.

ARM hardware memory tagging (MTE) is used by GrapheneOS across the entire base OS including the kernel and every standard base OS process. It's only temporarily disabled for a few device-specific processes. It greatly improves protection against nearly all remote exploits and many local exploits.

Pixel 8 launched with hardware MTE support in October 2023. We integrated it into our hardened_malloc project and began using it across the OS later that month. Android and the Pixel OS never started using it by default. Android Advanced Protection Mode in Android 16 enables it for a few processes.

Apple's Memory Integrity Enforcement (MIE) is an always enabled feature on the iPhone 17. It's simply a high quality implementation of MTE using the latest standard extensions. It uses MTE in the most secure mode in the kernel and a large portion of userbase. They did a very good job integrating it.

Apple's MIE and Android 16+ AAPM don't use MTE for user installed apps unless those explicitly opt in. GrapheneOS enables it for more apps automatically and has a toggle for users to opt-in for every user installed app. There's a per-app toggle to opt-out for incompatible apps which is uncommon.

Neither iOS or Android encourage app developers to opt into MTE and other more aggressive security features used in the base OS. Apple's docs warn developers of performance and stability issues. Even Signal doesn't opt-in. Our approach enables forcing using MTE in the standard allocators regardless.

Pixel 11 does have security improvements including moving to post-quantum secure verified boot (ML-DSA) and replacing Samsung Shannon IMS with AOSP IMS. Titan M3 should significantly improve protection against data extraction in Before First Unlock state. It's too bad they ruined it by cutting MTE.

Pixel 11 series is a lot more expensive for an incremental improvement to the CPU, the same underpowered GPU and reduced RAM for the Pro base models. They finally caught up to the last generation of Qualcomm cellular radio. It's overpriced, the upgrades aren't impressive and losing MTE is appalling.

Compared to the Pixel 11, a Snapdragon 8 Elite Gen 5 has 40% higher single threaded CPU performance, 80% higher multi threaded performance, over 100% higher GPU performance and a far better cellular radio. It also finally has MTE. The next gen is what will be in the first Motorola with GrapheneOS.

Pixel 9a and earlier (including Nexus devices) were the Android Open Source Project reference devices. Pixel support was removed from AOSP with Android 16. It's now harder to support Pixels than many other devices and massive progress towards open source firmware and driver libraries was discarded.

Compared to the stock Pixel OS, GrapheneOS ships AOSP patches months earlier and Linux kernel patches many months earlier. However, we rely on them for firmware and most driver updates. We also want to move to new kernel branches earlier. These things can be improved with our Motorola partnership.

We strongly recommend against buying Pixel 11 devices. Pixel 8, 9 and 10 have much better overall security for GrapheneOS. Pixel 10 is cheaper with similar hardware and MTE. Pixel 11's Titan M3 should improve BFU security for users without a strong passphrase, but losing MTE craters AFU security.

We haven't determined what to do about this situation. It may be best for us to skip the Pixel 11 series devices. We can shift our focus entirely to the upcoming Motorola devices instead. Pixel 10a was really a 9th gen Pixel, so hopefully the Pixel 11a does the same with 10th gen and includes MTE.

top 33 comments
sorted by: hot top controversial new old
[–] Enkrod@feddit.org 10 points 3 hours ago* (last edited 3 hours ago)

Skipping Pixel 11 is the correct response imho. Graphene is security first and has a reputation of making no compromises on it. This underscores their dedication. It's great really that the cooperation with Motorola means they will not need to rely on a single device series.

I really hope we'll one day see a Fairphone that supports the security requirements.

[–] notSys@lemmy.cafe 9 points 6 hours ago (1 children)

Holy! Good thing i bought pixel 10a instead of waiting for 11a

Same situation. Just bought a base 10 model a couple weeks before the 11 came out. Now I'm just waiting for US Mobile to unlock the phone so I can move to graphene.

Coming from a galaxy S10+ though, and it seems 90% of the "improvements" since then have been Gemini, and well Gemini.

If my S10 wasn't a US model that can't be unlocked and stuck on Android 12, which bank apps were starting to no longer support, it could still handle everything I needed it for.

[–] ByteMe@lemmy.world 113 points 18 hours ago* (last edited 18 hours ago) (2 children)

I love how grapheneos posts never hold back. They always expose Google

[–] lka1988@lemmy.dbzer0.com 31 points 12 hours ago (2 children)

Unfortunately, Daniel doesn't hold back anywhere, including those who have genuine concerns about his behavior (dude is seriously paranoid, in the medical sense).

[–] DanceMomsSavedMe@lemmy.zip 8 points 2 hours ago

He isn't the main dude anymore is he? I thought he doesn't make comments or posts any.ore after that whole fiasco and just does the software.

That only makes him more trustworthy. Sincerity is the free software way.

[–] Creat@discuss.tchncs.de 29 points 16 hours ago

Which is kind of ironic as the only phones supported by them were Google phones, as they were the only ones meeting their security requirements. More specifically their security principals is what those requirements are based on. Kind of telling that Google now no longer meet them either...

[–] inlandempire@jlai.lu 83 points 19 hours ago

Yikes from big G ; Motorolla couldn't come sooner

[–] Midnitte@beehaw.org 31 points 18 hours ago (3 children)

Really starting to want to just move to something like PostmarketOS...

[–] artyom@piefed.social 34 points 18 hours ago (1 children)

It's a nice idea but I haven't heard any positive reports. Motorola seems to actually want to work with GOS and keep it going, so that will probably be the best bet moving forward.

[–] lenocolomo@lemmy.ml 6 points 18 hours ago (2 children)

Just hope that the "flagship" price won't resemble the name. But if, I can wait. I'm fairly happy with my Pixel 9.

[–] pucker4676@lemmy.ml 9 points 16 hours ago (1 children)

There'll be an affordablish phone eventually. I'm just so happy more options are becoming available.

I'd love a Linux phone like yesterday, but it's going to be a looong time until we have a Linux phone on par with GrapheneOS. Who knows, maybe the GrapheneOS team will be behind the year of the Linux phone. <3

[–] lenocolomo@lemmy.ml 7 points 6 hours ago

I'd love to have a Linux Phone that'll "just work". The best we've got currently (of which I think I know) is the Jolla phone, but unfortunately it still has many issues, which make it unattractive enough. Let's just wait and see what the future bares.

[–] artyom@piefed.social 2 points 17 hours ago (1 children)

It will. They Motorola Signature currently sells for ~$1k-1200 USD equivalent in AUS and Euro

[–] sukhmel@programming.dev 1 points 28 minutes ago

I wouldn't be so sure, but time will tell, eventually

[–] hash@slrpnk.net 6 points 17 hours ago (3 children)

I like the idea of a linux phone, but do current options measure up to GrapheneOS in terms of security? My uninformed impression is they don't?

(And don't make me tap the security through obscurity sign.)

[–] Midnitte@beehaw.org 1 points 50 minutes ago

I dont think any Linux project operates on the idea of security through obscurity - but just growing very disillusioned with Android due to how Google has continued to lock it down. GrapheneOS only continues to exist for Pixels because Google hasn't decided to lock the bootloader yet.

Deciding to not include features Graphene demands for compatibility could very well be their benign loophole to achieve that

[–] notSys@lemmy.cafe 6 points 6 hours ago

Nothing can match GOS when it comes to security.

You also don't need that much security (before you get mad at me, check if you don't have a desktop PC somewhere in your house).

[–] pucker4676@lemmy.ml 8 points 16 hours ago (2 children)

No, not even desktop Linux. GrapheneOS is the most secure OS that I'm aware of. Android desktop mode has me a little excited. It's not bad right now, but I wouldn't want to work on it all day.

[–] lka1988@lemmy.dbzer0.com 4 points 12 hours ago* (last edited 12 hours ago) (1 children)

Graphene OS is the most secure OS, and it's been proven. Not even that infamous Israeli cracking software can get into it.

[–] JustEnoughDucks@feddit.nl 3 points 7 hours ago

I don't think cellebrite even tries to get into desktop OS's. I don't know if there is a tool that targets both that has leaked lists of successful targets like cellebrite that would be a good comparison.

Graphene is definitely more secure than default popular Linux distributions, but there are probably some install scripts out there that make it about equally secure.

[–] defaultusername@lemmy.dbzer0.com 3 points 13 hours ago (1 children)
[–] pucker4676@lemmy.ml 4 points 13 hours ago (1 children)

QubesOS is interesting. It basically throws every application in it's own VM and firewalls each other off. It's not a bad strategy at all, and they've integrated everything neatly, but it's not hardened like GrapheneOS. It's not something I'd personally want to daily drive, especially on a laptop, but neither is Android Desktop.

[–] defaultusername@lemmy.dbzer0.com 5 points 12 hours ago* (last edited 12 hours ago) (1 children)

What do you mean it's not hardened like GrapheneOS? Throwing everything in isolated VMs is the same approach that the Xbox consoles have taken since the Xbox One, and those still haven't been hacked, save for a bootrom exploit via glitching in the original model of the Xbox One before the OS loads. If one VM (or "qube" in this case) gets compromised, it is sandboxed from the rest of the machine, and no user-installed application runs on the host OS (dom0), save for what comes preinstalled, like settings applications and the GUI, and none of that touches the Internet.

Not wanting to daily drive it is perfectly understandable, though. I personally don't just because of the RAM requirements compared to other OSs. Also GPU passthrough breaks things on my main gaming laptop.

[–] pucker4676@lemmy.ml 4 points 9 hours ago (1 children)

They're just basic Linux installs is what I mean. QubesOS isn't much different than having a different computer running each piece of software on your LAN.

It's a bit of an apples to oranges comparison, though. Desktop vs mobile. Hell, I'd hardly even compare Qubes to any Linux distro. It's so niche and clunky to use as a daily driver. It's basically just a hypervisor. A better comparison might be secureblue.

And a guest escaping is definitely not unheard of. https://www.techtimes.com/articles/319941/20260708/linux-kvm-guest-host-escape-hits-both-intel-amd-two-cves-required.htm

[–] Emma_Gold_Man@lemmy.dbzer0.com 2 points 5 hours ago (1 children)

KVM guest escapes won't affect Qubes, which doesn't use it. Qubes is built on Xen instead - the Linux dom0 is itself a containerized management instance. That's not to say that Xen container escape vulnerabilities are unheard of, but it's a smaller attack surface and they are less common.

[–] pucker4676@lemmy.ml 2 points 3 hours ago* (last edited 3 hours ago)

I'm aware. It was just a quick example. Here, this should make you feel better I guess?:

https://www.csoonline.com/article/561467/xen-hypervisor-faces-third-highly-critical-vm-escape-bug-in-10-months.html

It seems Xen has it's fair share of issues. https://xenbits.xen.org/xsa/

[–] xylol@leminal.space 2 points 17 hours ago (1 children)

I've seen some of the handheld Linux distros and its so cool to see the steam library and other PC games running on small handhelds, things are moving so fast

[–] artyom@piefed.social 2 points 17 hours ago (1 children)

You can run the same things on Android now with FEX.

[–] pucker4676@lemmy.ml 4 points 16 hours ago (1 children)

Valve is killing it. They must have some incredible plans.

[–] Axolotl_cpp@feddit.it 1 points 2 hours ago (1 children)

They will launch the Steam VR (idr how it was called) that will be on an ARM, so it means they will also make an x86_64 emulator for ARM

[–] pucker4676@lemmy.ml 1 points 18 minutes ago

Yeah, it's neat. It'll be very interesting to see how useful it'll be on fairly low-end SoC.