[flagged]
If they're just some "niche use case" then why would Motorola partner with them? The way they see it, > By combining GrapheneOS’s pioneering engineering with Motorola’s decades of security expertise, real‑world user insights, and Lenovo’s ThinkShield solutions, the collaboration will advance a new generation of privacy and security technologies. In the coming months, Motorola and the GrapheneOS Foundation will contin…
GrapheneOS says Pixel 11 has MTE support after all
91–100 of 175 posts
Re: GrapheneOS says Pixel 11 has MTE support after all
#92[flagged]
[flagged]
Don't take it personally. I'm a huge fan of Linux, and GrapheneOS routinely comes here and calls it a huge security liability. And they are right.
Re: GrapheneOS says Pixel 11 has MTE support after all
#93Earlier quoted context omitted.
I've read that there's a significant performance cost to MTE on Android (or on Tensor). It might just be that.
There's only a significant cost to synchronous MTE. MTE ships two modes. synchronous mode and asynchronous mode. SYNC is slower but gives you far better traces and throws an SEGV_MTESERR as soon as violations happen. ASYNC however is async so there's a bit of a delay between a violation and the "catch" that throws SEGV_MTEAERR. Strictly speaking async is worse for security because there's a brief window of time where…
Re: GrapheneOS says Pixel 11 has MTE support after all
#94Re: GrapheneOS says Pixel 11 has MTE support after all
#95It’s absurd that a small project like Graphene is able to run rings around a giant like Google in the security sphere. Almost makes you wonder if some of those vulnerabilities are intentionally allowed to exist. Vulnerabilities in the world’s most popular (by volume) mobile OS could provide a plausibly deniable global espionage backdoor.
Elsewhere in the thread, someone reports that with MTE enforcement enabled, there are lots of crashes. And app and system service developers don't seem responsive to them. That's not something that's really acceptable on a $500+ phone... so if you're Google, you're not going to turn that on by default and you're not really going to be interested in keeping it as a feature that users can turn on. Graphene has a differ…
Re: GrapheneOS says Pixel 11 has MTE support after all
#96[flagged]
Re: GrapheneOS says Pixel 11 has MTE support after all
#97Earlier quoted context omitted.
Even in the EU spyware use is prevalent (and i 'd guess everywhere else in the world). There have been many scandals of government authorized commercial spyware been deployed against journalists. Is it really that niche a mobile OS that tries to not be exploitable by them?
[flagged]
Also your argument about a user inspecting and editing application files feels like a strawman argument. For example many spyware use malicious links to infect the devices, not malicious apps.
Re: GrapheneOS says Pixel 11 has MTE support after all
#98I am almost certainly going to live with whatever drawbacks in terms of camera quality, battery life, etc. Come with their Motorola phone when it's time to upgrade. MTE is such a non-negotiable for modern digital security on phones it's crazy Google would be so okay with this regression. What's especially stuck in my mind lately is how insecure basically all desktop OS' feel. In at the point of buying a second and th…
I made the same observations and conclusions as you, but a few years ago. I have been daily driving Qubes OS exclusively since on my Thinkpads. If you haven't started to yet, I implore you to consider the following when buying a system for Qubes: mid-line CPU with plenty of PCs (turn off the ECs), As much RAM as you can afford (seriously, budgetmaxxx on RAM), dedicated secondary GPU with the minimum specs you need is a must for inference (may have to widen the budget a little bit after budgetmaxxing RAM).
Expect to not game on the platform. I have not tried this but if you can't cut the digital crack-cocaine habit then it may be possible to set up a gaming qube which takes the dGPU passed through: get a monitor + second USB keyboard & mouse, plug the monitor into the dGPU's HDMI ports, and pass through the secondary peripherals. Digital crack-cocai... err games... don't like having their frames pushed over X11 forwarding even if the dGPU is passed through, so you will need the monitor; the secondary input devices are so the mouse and keyboard inputs don't leave the gaming qube.