this post was submitted on 18 Aug 2026
869 points (99.1% liked)

Technology

87337 readers
3680 users here now

This is a most excellent place for technology news and articles.


Our Rules


  1. Follow the lemmy.world rules.
  2. Only tech related news or articles.
  3. Be excellent to each other!
  4. Mod approved content bots can post up to 10 articles per day.
  5. Threads asking for personal tech support may be deleted.
  6. Politics threads may be removed.
  7. No memes allowed as posts, OK to post as comments.
  8. Only approved bots from the list below, this includes using AI responses and summaries. To ask if your bot can be added please contact a mod.
  9. Check for duplicates before posting, duplicates may be removed
  10. Accounts 7 days and younger will have their posts automatically removed.

Approved Bots


founded 3 years ago
MODERATORS
you are viewing a single comment's thread
view the rest of the comments
[–] toph@feddit.uk 21 points 15 hours ago* (last edited 15 hours ago) (5 children)

It still sucks for security. If you own this phone you should consider that the authorities and pretty much anyone who really wants to can get into your phone at will. I wish they could meet Graphene’s hardware requirements.

[–] lightnsfw@reddthat.com 6 points 10 hours ago (2 children)

Aren't Graphene's hardware requirements "be a Pixel"?

[–] toph@feddit.uk 1 points 30 minutes ago* (last edited 24 minutes ago)

No lol, they have a list of specific hardware security requirements for a device to have, the biggest one being a secure element. Without a secure element there is no hardware-backed key derivation throttling, so it's much more possible for an attacker to brute force your phone's PIN.

Support for using alternate operating systems including full hardware security functionality
Complete monthly Android Security Bulletin patches without any regular delays longer than a week for device support code (firmware, drivers and HALs)
At least 5 years of updates from launch for device support code with phones (Pixels now have 7) and 7 years with tablets
Device support code updated to new monthly, quarterly and yearly releases of AOSP within several months to provide new security improvements (Pixels receive these in the month they're released)
Linux 6.1, 6.6 or 6.12 Generic Kernel Image (GKI) support
Hardware accelerated virtualization usable by GrapheneOS (ideally pKVM to match Pixels but another usable implementation may be acceptable)
Hardware memory tagging (ARM MTE or equivalent)
Hardware-based coarse grained Control Flow Integrity (CFI) for baseline coverage where type-based CFI isn't used or can't be deployed (BTI/PAC, CET IBT or equivalent)
PXN, SMEP or equivalent
PAN, SMAP or equivalent
Isolated radios (cellular, Wi-Fi, Bluetooth, NFC, etc.), GPU, SSD, media encode / decode, image processor and other components
Support for A/B updates of both the firmware and OS images with automatic rollback if the initial boot fails one or more times
Verified boot with rollback protection for firmware
Verified boot with rollback protection for the OS (Android Verified Boot)
Verified boot key fingerprint for yellow boot state displayed with a secure hash (non-truncated SHA-256 or better)
StrongBox keystore provided by secure element
Hardware key attestation support for the StrongBox keystore
Attest key support for hardware key attestation to provide pinning support
Weaver disk encryption key derivation throttling provided by secure element
Insider attack resistance for updates to the secure element (Owner user authentication required before updates are accepted)
Inline disk encryption acceleration with wrapped key support
64-bit-only device support code
Wi-Fi anonymity support including MAC address randomization, probe sequence number randomization and no other leaked identifiers
Support for disabling USB data and also USB as a whole at a hardware level in the USB controller
Reset attack mitigation for firmware-based boot modes such as fastboot mode zeroing memory left over from the OS and delaying opening up attack surface such as USB functionality until that's completed
Debugging features such as JTAG or serial debugging must be inaccessible while the device is locked

Until the collaboration with Motorola produces a device, only the recent Pixels meet the requirements.

Fairphone is also one of the worse OEM's when it comes to how slowly they patch and releases security vulnerabilities, and they are known to be quite sloppy, in the past they have published their private keys. I wouldn't trust keeping anything remotely private or sensitive on a Fairphone.

[–] FeelThePower@lemmy.dbzer0.com 1 points 6 hours ago* (last edited 6 hours ago) (2 children)

nah. grapheneos requires open source drivers and immediate security updates from the oems as well as an unlockable bootloader. pixel just happens to be the only one who fits the bill for all of those. as an example, the Samsung I had before my pixel wouldn't get security updates for months after an Android release which was really annoying. Motorola will soon comply with these standards too, but they have their own line of flock camera alternatives so I won't be touching their products with a 10 foot pole.

[–] FG_3479@lemmy.world 2 points 4 hours ago

Those cameras are from Motorola Solutions, which is a seperate company to Motorola Mobility.

[–] lightnsfw@reddthat.com 2 points 6 hours ago

But you touch Google?

[–] Bahnd@lemmy.world 5 points 11 hours ago (1 children)

This

My dream phone is made by Fairphone, runs Graphene and has pin-board power switches like the Pinephone (its got good ideas, but its running a 2013 chipset, its a dev device for making linux mobile work better)

... Wishful thinking.

[–] unglueclass23@programming.dev 6 points 10 hours ago* (last edited 10 hours ago)

Samsung hardware

Fairphone sustainability / repairability

Pixel / GrapheneOS privacy

Chinese prices

Dream phone of mine.

[–] majster@lemmy.zip 6 points 13 hours ago (1 children)

You probably aren't safe from Pegasus but at least you are not streaming your location and IRL contacts to Google 24/7.

[–] ScoffingLizard@lemmy.dbzer0.com -1 points 12 hours ago (1 children)
[–] majster@lemmy.zip 1 points 11 hours ago

Why? I'm not sure what am I missing?

[–] dastanktal@lemmy.ml 2 points 12 hours ago

Look, at least this way I don't have to worry about all the software back doors phoning home.

I just don't take the phone out with me when I think I'm going to be arrested or something.

[–] ScoffingLizard@lemmy.dbzer0.com 1 points 12 hours ago (1 children)

How do you break into it? If it's not hard then why doesn't everyone do it.

[–] Buddahriffic@lemmy.world 2 points 10 hours ago

Everyone? The group of people that includes those who can't use their computer after their desktop icons get sorted?

It still takes some skills, but those skills might just be "desoldering chips to stick them in a chip reader device" and doing that on the storage chips. Or maybe tapping a trace to read the signals that are sent over it to grab a key or something. "Not hard" doesn't mean "you don't need skill to do it", it means "someone who has some skills won't have difficulty applying them".