HN.zip

Pixel 11 doesn't yet meet the GrapheneOS security standards and may be skipped

382 points by finnlab - 214 comments
microtonal [3 hidden]5 mins ago
As others have said, this is not the most recent status update (it depends on future Google changes in QPR1 or QPR2).

The much more interesting recent news IMO is that Google is not allowing (non-Samsung) OEMs to sell devices with GrapheneOS:

https://news.ycombinator.com/item?id=49946698

See the last paragraph.

For example, non-Samsung Android OEMs aren't allowed to directly sell devices with GrapheneOS and Google will only permit it within a quota. It can and is being worked around and there will be devices sold with GrapheneOS as the stock OS without Google restricting how many can be sold.

My guess is that the workaround is that Motorola sells them with Google-certified Android. A third-party (non-OEM) buys them in bulk and preinstalls GrapheneOS.

But this is really end-90s/begin-00s Microsoft levels of anti-competitiveness. I'm surprised that (particularly non-US) regulators are not investigating them yet.

bayindirh [3 hidden]5 mins ago
> But this is really end-90s/begin-00s Microsoft levels of anti-competitiveness. I'm surprised that (particularly non-US) regulators are not investigating them yet.

Every company is nice until the monies they earn is not guaranteed anymore. They were closing the doors they have intentionally left open in the name of security for a couple of generations.

Now they're being more open about why they are limiting user choice. Because like Chrom(e/ium), Android is designed to be a large data sink for Google to feed The Machine.

lukan [3 hidden]5 mins ago
"Because like Chrom(e/ium), Android is designed to be a large data sink for Google to feed The Machine."

Also maintaining the monopoly over the app market and getting a good cut out of every transaction within. A non google controlled device in the mass market can introduce new markets independent of google (and not paying them).

They would not like that.

dreamcompiler [3 hidden]5 mins ago
Apple did the same thing. In the early days of OSX much of Darwin was open-sourced. Now, not so much.
grommz [3 hidden]5 mins ago
It's all about that sweet backdoor. With Google and Samsung the NSA can just waltz in and out of your phone no matter which OS is running. But if some Chinese OEM decides that Unisoc chip & baseband would be the best choice for your GrapheneOS device the NSA will be quite unhappy.
RobotToaster [3 hidden]5 mins ago
I'm honestly a little surprised we haven't seen a Chinese OEM use grapheneOS or their own fork of it.
thenthenthen [3 hidden]5 mins ago
Graphene is a privacy focussed rom. In China there is not such a concept as privacy. In fact, it might be illegal to be distributing this, even for export.
DoctorOetker [3 hidden]5 mins ago
Clothes, handbags, etc. brands regularly complain that Chinese factories sell apparent clones at lower prices.

Can design forgeries be prevented by selecting as designs phrases and fragments of text that are politically provocative in China? To the extent that they continue to make faithful copies to sell in the West, they are exposing labor force to provocative say anti-party content. Or they forego the imitation business?

throawayonthe [3 hidden]5 mins ago
no lol
anvuong [3 hidden]5 mins ago
Why are you surprised? Since when does China care about privacy?
rurban [3 hidden]5 mins ago
They already have HarmonyOS, which is much better than Android
dathinab [3 hidden]5 mins ago
> The much more interesting recent news IMO is that Google is not allowing (non-Samsung) OEMs to sell devices with GrapheneOS:

how is that legal??

that sounds like a very clean cut case of thinks companies aren't allowed to do under fair market lawes

markasoftware [3 hidden]5 mins ago
Yeah, I don't understand this, graphene is FOSS and unaffiliated with google so if you as an oem install grapheneos on hardware you manufactured how does Google have any say at all?
madeofpalk [3 hidden]5 mins ago
Because Google will cut you off from access to the privileged Android access to Play Store, Services and everything else. So it’s basically all or nothing.
fc417fc802 [3 hidden]5 mins ago
Which, again, appears at a glance to be clearly illegal. For reference see what happened to Microsoft in both the US and Europe.
Brian_K_White [3 hidden]5 mins ago
Same as RedHat saying you can't redistribute the source code that they are obligated to give every customer.

The GPL clearly grants every recipient the same full rights as whoever they received something from, so copyright law itself says that you can take that source and redistribute it.

But starting a year or so ago RedHat says you may not redistribute, which they can't actually say, so you still can, but if you do you will be fired as a customer and lose all future access, so you only get to do it once.

Given the clear wording that makes the intent of the GPL unambiguous, that every end user is fully empowered and you may not do anything to curtail that, I don't see how they get away with it except the simple fact that no one has been willing to take on the legal fight.

If you're a pre-"stream" Centos user, you don't have the money for that. If you're a paying RHEL user, you don't want to be on bad terms with RedHat or maybe IBM either, and neither the licence costs nor the rules bothers you at all anyway.

So it's plainly illegal in my opinion, but will stand, illegal and yet in effect and unchallenged probably indefinitely.

eikenberry [3 hidden]5 mins ago
It's only illegal if the law is enforced and the US federal government gave up on anti-trust enforcement a long time ago and any attempts to re-awaken it get nerfed quick.
NetMageSCW [3 hidden]5 mins ago
The US isn’t the only place Android phones are sold.
madeofpalk [3 hidden]5 mins ago
> I'm surprised that (particularly non-US) regulators are not investigating them yet.

This is basically the reason Google lost their Play Store anti-trust lawsuit when Apple won theirs. Google did all these incriminating, behind closed doors deals to lock out competition from their “open ecosystem”, where Apple never pretended to be open to behind with.

xethos [3 hidden]5 mins ago
This is just the Breaking Bad "He can't keep getting away with it" meme, for tech giants. Google has been ruling Android with an iron fist for over a decade, and they continue to do so. This came up in a different comment chain of mine [0] recently as well, and is probably more worth reading than a lot of the other comments here that are just now realizing how restrictive Google is with Android

[0] https://tildes.net/~tech/1wam/blocking_of_unverified_apps_on...

rationalist [3 hidden]5 mins ago
> Apple never pretended to be open

Except when Steve Jobs lied saying FaceTime would be an open standard.

"FaceTime is based on a lot of open standards: H.264 video, AAC audio, and a bunch of alphabet-soup acronyms. And we’re going to take it all away. We’re going to the standards bodies, starting tomorrow, and we’re going to make FaceTime an open industry standard." - Steve Jobs at Apple’s WWDC 2010 keynote (emphasis mine)

NetMageSCW [3 hidden]5 mins ago
That was their intention but that changed after they lost a patent troll lawsuit.
someonebaggy [3 hidden]5 mins ago
Corporations learned they have to get in bed with regulators first, and how to do it.
subarctic [3 hidden]5 mins ago
I saw an interview with Bill Gates once where he said that one thing he would've done differently is more quickly come around to the idea of sending people to Washington. Apparently he didn't like the idea of lobbying and that cost them when the regulators started coming for them
someonebaggy [3 hidden]5 mins ago
Wow, then there we go: don't hate the player, hate the game. You're telling me even Bill Gates wasn't evil until the system forced him to either become evil or get shut down.
bayindirh [3 hidden]5 mins ago
No, he just say he's inexperienced.

Bill Gates published that infamous open letter about copying software, and both Bill Gates and Brad Smith said that Microsoft's core pillar is IP: "Microsoft is built upon the idea of having IP and protecting and using it" (paraphrased by me).

The quotes I can find by digging the net:

> Microsoft was founded on the premise that software is valuable intellectual property that people should pay for. --Bill Gates

> Microsoft was founded on intellectual property. Intellectual property is the foundation of our business. --Brad Smith (This is the quote I remember in the first place)

So, Microsoft never wanted to be an open company. They were the epitome of the closed source, behemoth software company, where you get the goods, get to use it, and pay them for the privilege.

someonebaggy [3 hidden]5 mins ago
Closed source software is a reality, not an explicit evil. It is the same reason I don't have schematics for my bedframe. I've worked at software companies - have you? - it takes extra effort to release source code, causes a lot of risk, and provides absolutely no benefit whatsoever so it is simply irrational to do it.
JacobKfromIRC [3 hidden]5 mins ago
Reality vs explicit evil is a false dichotomy.

Microsoft doesn't just choose not to release source code; they send takedown notices to projects that redistribute Microsoft's proprietary software (e.g. Ninjutsu OS). They also put clauses in the EULA for Windows to disallow reverse engineering and certain kinds of remote access (something related to if you change who has access too frequently).

Microsoft takes extra effort to prevent people from sharing or modifying Microsoft software, in order to make more money.

someonebaggy [3 hidden]5 mins ago
Yes, some of those parts are evil. The mere lack of releasing source code, or being frustrated people are using your product without paying, itself isn't.
ygjb [3 hidden]5 mins ago
I think that mischaracterizing a business model as evil is an overloaded practice.

Is it evil to introduce terms and conditions that restrict how you expect your users to use your product? No, it's probably more hypocritical than evil; I don't think my parents telling me not to smoke while they struggled with addiction was evil, but it sure didn't model the best behaviour.

Is it evil to lobby government to curtail the freedoms of individuals to protect your business model? Yeah, probably; in most cases I believe that reducing consenting adults freedoms is usually a pretty evil act.

Microsoft is guilty of both, but I prefer to save Evil to describe actions that actively cause harm, either physically, mentally, emotionally, or in terms of harming the freedoms that people enjoy, especially if that choice to cause harm is economically motivated.

I'm not advocating on behalf of Bill Gates or Microsoft, just on clear terminology so that we can focus on actual evil behaviour versus consenting adults entering into a valid contract for mutual benefit.

JacobKfromIRC [3 hidden]5 mins ago
I agree, I think.

I may have been too focused on the "false dichotomy" part and forgotten that you were talking about old Microsoft and not current Microsoft. I don't know enough about old Microsoft to say whether they were "evil" all along, so I won't comment on that part. I do agree with "don't hate the player, hate the game" in general though.

squarefoot [3 hidden]5 mins ago
Closed source was perfectly acceptable when planned obsolescence and government mandated kill switches/backdoors weren't a thing.
bayindirh [3 hidden]5 mins ago
I'm not an opponent/critic of closed source software or enemy of it. I pay for quite a few high quality closed source software packages, and I like them as much as the Free Software counterparts which I use every day.

I also understand that we need to eat and have bills to pay, and there are many ways to achieve that, incl. Free or Closed Source software.

What I'm against is weaponization of closed source software beyond reasonable point. To EEE, to deprecate otherwise capable and functional hardware in the market, to limit user freedom or to extort money.

I hope I made my point clear.

Furthermore:

> I've worked at software companies - have you?

I didn't work at a software company per se, yet I develop open source software for the projects we work on, and I know what preparing a codebase for publishing entails. I also worked as a tech-lead of a Linux distribution, and a nation-wide one at that. I know what it entails, trust me.

If we're talking about experience in terms of years, I'm doing this for ~20 years, using Linux for ~25 years, and using computers in a level I understand what programming them entails for ~30 years.

So yeah, I'm not that newbie who have seen some Python and tied themselves to a knot of awe.

> causes a lot of risk,

Don't let's get into FUD territory of "Free Software is insecure", shall we? We see how Windows has been breached yesterday and today, and will see it more for years to come, as with other software.

> and provides absolutely no benefit whatsoever so it is simply irrational to do it.

Hmm, I'll agree to disagree here because 90% of the thing your digital stack is living on is Open Source and Free Software.

I don't have time to flesh out the benefit and irrationality aspect of it, because I mean, it's plainly wrong when it's put that squarely. We can find some nuances maybe, but it's limited to certain scenarios.

r_lee [3 hidden]5 mins ago
by weaponization you mean Win 11 requiring specific hardware etc?

your comment honestly just sounds like you dislike closed-source software.

for most commercial software projects, releasing the source provides no tangible benefit, aside from people like HNers being happy

but if Microsoft would've open sourced their OS, they would've been vulnerable to their OS being diluted into free versions or maybe even OEM-maintained versions

from a business sense, it makes no sense.

and as for security, closed source software is harder to attack (and was a lot harder to attack before LLMs). like, there's still much that we don't know about Windows internals exactly, and even those who do are a very small group of people.

it'd be a lot easier to find vulnerabilities if the source was open.

yes, it doesn't mean it's automatically more secure, in fact it can be less so if people don't have eyes on it, but I'd say the amount of attacks is less and usually done by more sophisticated attackers

someonebaggy [3 hidden]5 mins ago
Weaponization of closed source software could take many forms and is just part of the general weaponization of market mechanisms that businesses do.

Right now it doesn't really affect me that Ableton Live is closed-source. But it would affect me if the main method of sharing music on the internet was Ableton Live project files. And if Ableton had cultivated that situation on purpose they would be weaponizing the closedness of their software.

TeMPOraL [3 hidden]5 mins ago
If we're talking about weaponization, then for sake of completeness let's remember that weaponization of open source is a very powerful business strategy that's been frequently used in the past 20 years, whether to market software, acquire free work, or as direct move, to try and destroy a market some competitor works on.

Some business models - like OSS, and free-with-ads - are like dimension-folding weapons from Dark Forest trilogy: once deployed, there is no stopping them, they just permanently drop a degree of freedom from the universe, inside a shell expanding at the speed of light.

bayindirh [3 hidden]5 mins ago
> by weaponization you mean Win 11 requiring specific hardware etc?

I can understand specific hardware and/or CPU generation requirements up to a certain point. Because CPU generations bring more than new instructions and performance, but I don't understand why Windows Team or Microsoft doesn't use function multi versioning to allow more systems to use up to date versions of Windows for longer time.

On the other hand, using closed file format related documentation as reference in a supposedly open format's specifications and trying to short-circuit ISO to push their seemingly open but ultimately closed document formats as standard or using Embrace, Extend, Extinguish tactics to kill competing products, or inserting code which makes their applications crash in competitors' operating systems is straight up malice.

...and we have Halloween documents which are openly(!) trying to make Linux non-functional on PC hardware, so there's that.

I'll note that these stuff can be also weaponized in Free / Open Source software. Pulling hardware baseline higher, deprecating drivers, and not giving good enough errors to make the problems obvious while not giving the source and/or building instructions/configurations is also a tactic of Red^H^H^H IBM. Remember: If you merge a company with IBM, you get IBM.

> your comment honestly just sounds like you dislike closed-source software.

Insisting about something when I openly and honestly said it's not is not very nice. Yes, Free Software is my first choice and where my heart lives at, but I'm not malicious about closed source software. This comment is being written on a Mac, for example. If you really want to dig that, my comment history is also in the open. For the record, as I always say, I prefer Linux desktops and Mac laptops, again for ~20 years or so.

> but if Microsoft would've open sourced their OS, they would've been vulnerable to their OS being diluted into free versions or maybe even OEM-maintained versions

I'm not saying that Windows would be dead if it was open source, but we'd have versions where ads and telemetry are straight up ripped from every possible part of it. Windows 11 and 10 to a certain point feels like it's working against me. Constant nagging, no ability to use local accounts during install, suggested apps everywhere... It's not an operating system anymore. It's a software holding me hostage to its agenda with a side effect of making my computer run. Windows XP was not like that, 2000 was not like that. Even 7 was good.

> from a business sense, it makes no sense.

You can always make it sense, if you decide to do that. There's SQLite for example. It's not an OS, but its development environment is protected enough so you can't get the quality the official versions propose.

However, I'm not saying that Windows shall be open source. However, its closed source nature is weaponized towards its users. Not with hardware requirements primarily, but how it herds the user and siphons data out of the computer in the name of telemetry.

> and as for security, closed source software is harder to attack

Ha, no. A small anecdote: When WMF attack vector was introduced, WINE team had the laugh of their life because the problem seemed so stupid to pass on. The next day, WINE released a patch, because it turned out that WINE also had the same security hole. They reverse engineered Windows API to a level that their implementation was bug for bug compatible.

Another one, about WINE again: My friends' Linux machine got infected with a Windows virus via WINE. The virus was unable to do harm, but it was infecting any USB drive attached to that computer. So, even if we didn't have the code, WINE has reverse engineered and implemented a bug-for-bug compatible Win32 API under Linux.

Both are pre 2010 events, BTW.

Also, with the leaks we have learnt that NSA had a truckload of zero days to infiltrate Windows systems. Great for security, right?

> it'd be a lot easier to find vulnerabilities if the source was open.

This is the half truth. Finding, fixing and evading the introduction of vulnerabilities are a lot easier if the source is open. We evaded 7z incident. Do we know that there's no universal backdoor in Windows? I don't. You can't know either. I don't my computer to have a TSA-approved keyhole somewhere.

Do you remember how NSA backdoored a cryptography algorithm? I do. See: https://en.wikipedia.org/wiki/Dual_EC_DRBG

Have you ever read how Crypto AG rigged secure communication devices sold to certain countries, even NATO allies, because they were in fact owned by CIA (and BND up to a certain point)? See: https://en.wikipedia.org/wiki/Crypto_AG

Closed source something can't be audited to be secure or anything. It doesn't make it harder to attack, however. Only the good guys (or nobody but us) doctrine doesn't work. An intentional backdoor doesn't discriminate. You say the correct phrase, and it opens.

> yes, it doesn't mean it's automatically more secure, in fact it can be less so if people don't have eyes on it, but I'd say the amount of attacks is less and usually done by more sophisticated attackers

Security through obscurity never stopped anyone from infiltrating anything. With enough persistence, any system even obfuscated can be cracked, even without LLMs. People reverse engineered SMB despite Microsoft's best efforts. Then, they registered it as CIFS and open sourced it, because they had to.

Please, we have gone through this 30 years ago. These arguments doesn't hold water anymore.

serf [3 hidden]5 mins ago
I think , probably, evil covers a wider spectrum than whether or not you're in bed with feds.
b112 [3 hidden]5 mins ago
Well, one aspect of evil anyhow.
DANmode [3 hidden]5 mins ago
> even Bill Gates

Not a big news person?

miroljub [3 hidden]5 mins ago
How can you say someone visiting Epstein island is not evil?
Kudos [3 hidden]5 mins ago
Poor innocent early 00s Microsoft corrupted by the system.
someonebaggy [3 hidden]5 mins ago
The thing being described would have been in the 1980s.
pipodeclown [3 hidden]5 mins ago
You can always notify the EC anti competition whatsdpg through their wistleblower portal:)
cherryteastain [3 hidden]5 mins ago
EU is hell bent on locking "your" devices down as much as possible so they can shove their big brother spyware down your throat under the guise of "protecting the kids" [1]. They are building tons of EU and national level apps where strong Play Integrity is required [2] and will pair these up with the need to prove your identity to "make sure you are an adult" everywhere on the internet [3]. At least one EU country, Spain, has already begun to profile people based on whether they may be running phone OSes other than Google blessed ones [4]

[1] https://fightchatcontrol.eu/chat-control-overview

[2] https://waag.org/en/article/european-digital-id-wallets-are-...

[3] https://en.wikipedia.org/wiki/EU_Kids_Act

[4] https://www.androidauthority.com/why-i-use-grapheneos-on-pix...

riedel [3 hidden]5 mins ago
Speaking of 'EU' as a single entity seems a bit like a deep state conspiracy theory. Yes l, there is lobbying around CSAM scanning, security agency, banking industry and media networks, that all work against open source and security by design. Still there is also other movements and I don't think anticompetition has the same agenda. But in the end it is politics: there needs to be enough people to care about something. For anticompetition to be active I think the problem is rather there is no European market to protect. And particularly graphene (I will get downvotes for this) is not really good in joining forces with other European businesses in this space. Activism is important, but for lobbying you need to escape the niche.
cherryteastain [3 hidden]5 mins ago
The EU bureaucracy IS a single entity controlled by the EU Commission President, currently Ms. von der Leyen. Speaking of it as a single entity is definitely not a conspiracy theory as anyone can read how the EU works and see how the only democratic component of the EU, the Parliament, is an absolutely powerless body. Basically, the Commission can get what it wants every time.

How? Even in the case a majority of MEPs have different views to the Commission, it does not matter because only the Commission can initiate legislation. On the off chance the Commission does not get what it wants from the Parliament they can just ask the Council to send the same proposal to the Parliament as an 'emergency' procedure that has to be rejected by a minimum of 361 MEPs even if 50%+1 of the MEPs in attendance vote against. That's how Chat Control 1 was resurrected after it was voted down by a majority of MEPs. 331 MEPs voted against it vs 301 for, and it still passed due to the 361 rule. Which is why lobbying anyone except the Commission is pointless. You can do that even in China - people lobby the CCP there too, nobody claims this is democratic.

So, no conspiracy is needed, this is the EU functioning exactly as designed.

riedel [3 hidden]5 mins ago
I am working with different EU DGs in a very different context and I can assure you first hand that it would be rather nice in many cases if that would be true in general.
Xelbair [3 hidden]5 mins ago
with how EC has been behaving recently that might make things worse..
realusername [3 hidden]5 mins ago
They probably know already, it's not the first time it happens. See the illegal pressure Google has made against OEM after CyanogenMod wanted to go commercial.

Google was found guilty by the EU antitrust investigation and payed a 4 billions euros fine (and Google has changed nothing since then, they only increased the pressure).

GrapheneOS is especially annoying for them as it destroys their blanket excuse that it's ""for security""

Aissen [3 hidden]5 mins ago
> But this is really end-90s/begin-00s Microsoft levels of anti-competitiveness. I'm surprised that (particularly non-US) regulators are not investigating them yet.

You mean like the Skyhook vs Google 2014 lawsuit? (look it up) Settled before it could go any further.

HumblyTossed [3 hidden]5 mins ago
> My guess is that the workaround is that Motorola sells them with Google-certified Android.

Was this ever the deal with Moto? They announced something recently, but it didn't read like Moto would be distributing devices with preinstalled GOS. Just that it would be able to run GOS.

subscribed [3 hidden]5 mins ago
Well, they designed some handsets (one is announced, maybe there's another one or two) to meet Pixels / GrapheneOS level of hardware security. That alone is BIG.

Then there's expectation GOS might be sold pre-installed as well.

eszed [3 hidden]5 mins ago
Unless they've recently changed the deal, they'll be selling GOS out of the box. That was the announcement two or so years ago, and so far as I know nothing had changed.
sebastiennight [3 hidden]5 mins ago
One obvious challenge with the distribution is: would you want to buy a phone with pre-installed GrapheneOS?

This seems similar to wanting to follow the advice of "only buy bottled water on your trip to India", but the bottle you're buying has the cap removed so they could put a straw in it for your convenience.

mikem170 [3 hidden]5 mins ago
GrapheneOS has attempted to cover this, it comes with an Auditor app that can be used from another Android device to check for tampering.

> The Auditor app uses hardware-based security features to validate the identity of a device, along with the authenticity and integrity of the operating system. It ensures the device is running a verified operating system with a locked bootloader and that no tampering has occurred." [0]

I assume that it would be quickly discovered if Motorola were tampering with phones en masse.

[0] https://attestation.app/about

mschuster91 [3 hidden]5 mins ago
Motorola is at 5% of the world's market share. They fell really deep.
stkdump [3 hidden]5 mins ago
It takes EU regulators like half a decade or so to make up their minds on each issue.
eastbound [3 hidden]5 mins ago
The EU never sanctionned Microsoft for monopoly. They received $2bn fines in 2005 for lack of transparency on the documentation for drivers, if I remember, then a little extra for paperwork. Then Microsoft complied mostly at the last minute before being fined (even for the 6-months disappearance of the Browser Choice Dialog, it only cost them $500m).

But never, never has the EU sanctionned Microsoft for signing OEM deals that prevent companies from installing other OS than Windows.

stkdump [3 hidden]5 mins ago
Right. The EU still seems successful in shaping (foreign) tech to some extent. Handing out huge fines is maybe less important than effecting change. Though it would of course be good if other national/transnational regulators would join in and take care of some of these topics. Imagine for example if Japan, South Korea, Taiwan, Australia and New Zealand teamed up. Together they might be able to accomplish something.
izacus [3 hidden]5 mins ago
Time for US regulators to show how it's done? I'm sure Americans can show Europe how this is done properly, right?
RRRA [3 hidden]5 mins ago
So long for monopoly laws...
morkalork [3 hidden]5 mins ago
Also reminiscent of iirc Intel's choke hold on companies like Dell that froze out AMD
verisimi [3 hidden]5 mins ago
> I'm surprised that (particularly non-US) regulators are not investigating them yet.

Because corporate managed phones are required for all the id crap governance franchises intend to foist on people.

surgical_fire [3 hidden]5 mins ago
This is where governments should slam them with regulations.

Absolute anti-competitive behavior. "Android is open, but not really"

izacus [3 hidden]5 mins ago
You want to lead an assault on companies that develop OSS because they don't follow your dictats on how to work?

That sounds like a brilliant idea, I'm sure it'll be amazing show of force for all the top kernel contributors as well.

surgical_fire [3 hidden]5 mins ago
No, just lead an assault on companies that abuse their market position to kneecap any possibility of OSS being deployed meaningfully.

This actually is a brilliant idea.

izacus [3 hidden]5 mins ago
Which companies are that? The market leader of US phone market is running a closed, proprietary golden-cage OS which will increase it's share if your harebrained scheme is implemented.
NetMageSCW [3 hidden]5 mins ago
What’s wrong with that?
mschuster91 [3 hidden]5 mins ago
> I'm surprised that (particularly non-US) regulators are not investigating them yet.

Simple reason, they're afraid of Trump bullying them into submission, just look at the oil/diesel stockpile release drama.

The US has never been shy about its politicians up to and including the President being an extended arm of the large US corporations - but Trump takes that x1000.

ajross [3 hidden]5 mins ago
> The much more interesting recent news IMO is that Google is not allowing (non-Samsung) OEMs to sell devices with GrapheneOS:

To be That Guy, Apple is not allowing anyone anywhere to sell any devices with anything but MacOS/iOS.

> But this is really end-90s/begin-00s Microsoft levels of anti-competitiveness.

It's not even the most anti-competitive in the market of 2026!

GeekyBear [3 hidden]5 mins ago
iOS was never never an OS that was open to any device maker who cared to use it.

Google made the choice to announce that Android was open to all, in an attempt to take market share from Windows Phone.

Now they want to go back on their word.

ajross [3 hidden]5 mins ago
That may well be true. But the upthread point was that this was "anti-competitive", not "word-breaking". And in an argument about competition, Android is and remains by far (!) the most accessible platform. The restriction here is just that you can't get a license for Google's proprietary stuff if you also sell GrapheneOS, not even that you can't run GrapheneOS.
GeekyBear [3 hidden]5 mins ago
Google was already found guilty of antitrust, in part because they tried to contractually prevent device manufacturers from building devices to run forks of Android (like Amazon's Fire OS) if they also made devices for an OEM who used Google's Android.

> Alphabet's Google on Thursday lost its long-running fight against a record [€4.1 Billion] EU antitrust fine for using its Android mobile operating system to block rivals

https://www.usnews.com/news/top-news/articles/2026-07-02/goo...

Now they are trying block Motorola from pre installing a different fork of Android.

They will either back down or face another enormous fine in the EU.

ajross [3 hidden]5 mins ago
Again, even accepting all that, Android remains more open to competition within its own ecosystem than it's main (heh) competitor. And being outraged in only one direction is a smell that tells me... we aren't talking about competition.
fc417fc802 [3 hidden]5 mins ago
You're missing the point. Selling a closed device is legally permissible whereas attempting to strong arm behavior of other companies is deemed anti-competitive. So apple is within the bounds of the law (regardless of whether you approve of that) while google is not.
GeekyBear [3 hidden]5 mins ago
Apple never lied and claimed that iOS was "open" in the first place.

The important part is allowing users to make an informed choice, which requires you to be honest about what you are selling.

NetMageSCW [3 hidden]5 mins ago
Android is as open as ever (so far). Google doesn’t make or sell mobile phones for other OEMs, so their claims about Android openness can’t be applied to hardware from other OEMs being closed. Two different things.
microtonal [3 hidden]5 mins ago
To be That Guy, Apple is not allowing anyone anywhere to sell any devices with anything but MacOS/iOS.

Apple doesn't allow Apple selling Apple devices with other operating systems.

Google doesn't allow other OEMs selling the OEMs' devices with other operating systems.

Big difference.

(Yes, pedantics: I know that OEMs could sell devices with other OSes, but not being able to sell GMS Android devices would lose them most of their customers.)

ajross [3 hidden]5 mins ago
> Big difference.

Not from the perspective of competition, as I see it. Like, if you want to compete with Apple by using part of its platform for your own stuff, you can't at all. But you can with Google, just not all of it and in all ways.

Point being: this is just another platform flame. People with one kind of phone in their pocket are outraged at the maker of the other thing.

NetMageSCW [3 hidden]5 mins ago
No, it is different. They are using their market power over Android to prevent OEMs from selling other mobile OSs.

Apple doesn’t prevent other OEMs from selling phones.

gertop [3 hidden]5 mins ago
[flagged]
someonebaggy [3 hidden]5 mins ago
Then they'll be breaching their contract with Google so they'll lose the benefits of the contract, such as being allowed to preinstall the play store or Google apps like Gmail, or to call them Android devices. They might also be required to pay Google millions or billions of dollars in compensation for lost revenue, such as the 30% play store tax Google would have received had the contract been upheld.
simoncion [3 hidden]5 mins ago
> If an OEM ships grapheneos then what? There's a quota? What's the source?

The linked comment was posted a day ago by what appears to be an account used for speaking officially about GrapheneOS.

So, like, you could go ask.

izacus [3 hidden]5 mins ago
Or you could also find a source and explain since the GrapeneOS dude does have a social media history full of accusations of conspiracy against them with tenuous connection to actual truth.
simoncion [3 hidden]5 mins ago
> Or you could also find a source and...

Nah. The guy who -presumably- has all the relevant information in his head can be reached by writing an HN comment. The proposed question is directly relevant to the comment you'd be replying to.

Regardless of how the guy replies... with a sensible story, bullshit, or silence, everyone saves a ton of effort by asking him.

Seems stupid to go redo a whole bunch of research when the primary source of the claims in question is figuratively sitting right next to you and obviously open for conversation, doesn't it?

alerighi [3 hidden]5 mins ago
If you say something about it you are accused to be a communist because you are against free market, from people that doesn't even know what the term free market means (yes, we need rules to make the market truly free, deregulation is not the way).
amelius [3 hidden]5 mins ago
A free market is like an OS without memory protection. Every process can scratch in memory everywhere they want. Some may like it, but for most people it's just terrible.
someonebaggy [3 hidden]5 mins ago
That's a deregulated market. A free market is more like an android phone (minus developer ID verification) where everyone gets a space, you can do what you want in your space, you can't intrude on others' spaces without consent, and the market is formed and boundaries are enforced by some higher power who is not part of the market and is out of reach of all market participants.

Or, you know, any actual market. Where I can sell whatever I want from my stall but I can't sabotage other people's stalls.

darkwater [3 hidden]5 mins ago
> Or, you know, any actual market. Where I can sell whatever I want from my stall but I can't sabotage other people's stalls.

Oh, if you sell in your stall oranges at 10c box, with plenty of stock, you will sabotage the other stall selling fruit. And you can do that because your actual business is another one.

someonebaggy [3 hidden]5 mins ago
But you don't because you don't have the money to afford infinite free oranges. If you did, you wouldn't be running a fruit stall.
amelius [3 hidden]5 mins ago
Yes, that's why we need regulation.
aftbit [3 hidden]5 mins ago
The Pixel 11 is the first Pixel phone to be released after the RAMpocolypse. It has made a lot of compromises in the name of lowering cost. I am definitely going to skip that generation. I tend to upgrade every 3 years, but there really isn't a big driver to do so right now. My Pixel 8 is holding up great. If I broke it and needed to buy a new phone today, I'd probably get a used Pixel 10 instead of a new 11.
76SlashDolphin [3 hidden]5 mins ago
Just be careful with the 8 because their motherboards tend to randomly fry themselves - both me and a friend had this happen around 2 years into owning ours and there are a decent number of people online with the same issue. Switched to the 10a on sale right before the price hike and man I'm glad I did. It'll probably be the last great Pixel if hardware costs keep getting worse and Google keeps shoving Gemini down everyone's throats.
randlet [3 hidden]5 mins ago
My Pixel 8 failed with the exact failure mode (supposedly) covered by an extended warranty [0] program after owning it for 18 months. I had a very frustrating back and forth with Google support and in the end they refused to fix it under warranty because it wasn't manufactured in a specific batch.

Flagship phone turned into a useless device after 18 months of ownership due to a manufacturing issue and I've got no recourse. I'm done with Pixel and Google in general.

[0] https://support.google.com/pixelphone/answer/15009955?hl=en

bpev [3 hidden]5 mins ago
I had this happen twice with pixel 5a's as well. Older, but just to say I'm not sure this is limited to the 8 line. One of them literally just died in my hand and was unfixable.
kolla [3 hidden]5 mins ago
So just use it until the motherboard dies, why switch before it dies?
hbn [3 hidden]5 mins ago
Just off the dome:

- Suddenly being without a phone while you're travelling or dealing with something important is generally not fun

- Anything stored locally that isn't backed up is gone

- You can't transfer over your eSIM yourself

- Probably going to be a pain in the ass to get into accounts where the now brick was set up for 2FA

__MatrixMan__ [3 hidden]5 mins ago
If you're worried about things like this you should probably switch to a physical sim and just earmark some money so you can buy a new phone when it happens and transfer the sim. Maybe get some yubikeys while you're at it.

Anything complex enough to get over the air updates could lose its trustworthiness at any time. If a device is going to contain your digital soul, it should be simple and pluggable.

epihelix [3 hidden]5 mins ago
I use an eSim adaptor in my physical sim slot. You can then transfer eSims effortlessly between phones. This seems the obvious solution to get the best of both worlds - all the good things about eSims, none of the bad.
hbn [3 hidden]5 mins ago
I do still use a physical SIM but I'm sure we're all on borrowed time. The last 3 generations of iPhones don't have a SIM tray at all in the US.
drnick1 [3 hidden]5 mins ago
> The last 3 generations of iPhones don't have a SIM tray at all in the US.

Another good reason not to buy an iPhone. As if there weren't enough good reasons already.

hbn [3 hidden]5 mins ago
Yeah I'm sure Android manufacturers aren't gonna follow suit, just like how they all have headphone jacks still right?
bigyabai [3 hidden]5 mins ago
Many of them do have a headphone jack, still. If you're the sort of person that wants hardware options, Android has 'em.
hbn [3 hidden]5 mins ago
If you want options, you go Android

If you want something good and reliable, you go iPhone

drnick1 [3 hidden]5 mins ago
> If you want something good and reliable, you go iPhone

Unless by "good" you mean being able to install software without Apple's blessing. Or send files to and from the device without iTunes or other similar monstrosity.

shermantanktop [3 hidden]5 mins ago
All the same applies if your phone is stolen…or lost…or seized at the airport.

Devices need to be considered disposable. Expensive but disposable.

hbn [3 hidden]5 mins ago
Okay but I try to prevent any of those things from happening, unlike the suggestion to use your phone with a high rate of failure until it dies.
SoftTalker [3 hidden]5 mins ago
All of those things are possibilities with any phone. If you're not prepared for the loss/damage/failure of your phone that's on you.
grahamburger [3 hidden]5 mins ago
Definitely a good idea to plan on this at all times. In my case this looks like:

* All photos auto upload to Google photos

* All other important files are in a syncthing folder with at least two other devices (laptop+desktop)

* 2fa in Authy with cloud-sync

* Passwords on Firefox sync

* Google Fi is my carrier, and pulls eSIM when I log in to the app even without my old phone

* Google voice number is my main phone number. I don't lose access to incoming or outgoing sms or voice calls if I lose my phone.

In a pinch, I can buy a cheap prepaid phone and sim while traveling and be fully functional and reachable. I've had to do this before, and while I probably wouldn't go to the trouble for work, I feel compelled to be at least reachable for family.

I've thought about de-googling this further; photos could go straight into syncthing and I could port my # to a generic SIP provider that offers SMS. So far neither have seemed quite worth the trouble.

I've always felt very uncomfortable treating my phone as anything other than a rather overpowered thin-client.

pimeys [3 hidden]5 mins ago
Yubikeys can store 2fa codes. You just install their app from F-Droid and show the NFC key to get the codes.

Now the codes are with you and not in your phone or in the cloud.

SoftTalker [3 hidden]5 mins ago
One flaw in that is that Google Voice or other VOIP provider numbers are often rejected for 2FA or account validation.
grahamburger [3 hidden]5 mins ago
Sometimes, yes, but not that often IME. Maybe 10-15% of the time.
mattwad [3 hidden]5 mins ago
I recommend you get off Authy - they don't have a browser extension or a desktop client, and surprise they don't have a way to export your codes either. I had to send them a GDPR data request, and then Claude decrypted the csv file they sent. I now use Ente and it's so nice having 2fa inside a browser extension. I can also export the secrets at will.
__aru [3 hidden]5 mins ago
Keepass is also a good alternative to Authy, caveat being you need some way to sync the db file between devices.

I personally use Keepass for 2FA, Bitwarden for passwords. It's worked great for me so far, and I expect to stay with this setup for the foreseeable future.

someonebaggy [3 hidden]5 mins ago
They are stronger possibilities once you know they are going to happen eventually, not just that they could theoretically happen.
hbn [3 hidden]5 mins ago
Yes but I don't want my phone to be lost or destroyed or stolen. So using a phone that will likely fail until it does so is not taking preventative measures.
doublepg23 [3 hidden]5 mins ago
I swear every Pixel model people write "well it's a good smartphone minus the 'kills itself for no reason' bug".
Cider9986 [3 hidden]5 mins ago
Yep, I got a 10 and the fingerprint sensor broke after a day. Pretty fortunately I got a refund with no return so I can't complain.

My 9 has had no hardware issues besides the designed ones.

havblue [3 hidden]5 mins ago
I fried my 8 pro wifi but I attributed it to listening to it inside my shower where it would get the full force of steam damage. So at least on my part I can admit that was a mistake.
ButlerianJihad [3 hidden]5 mins ago
I had an 8 Pro and it had a fantastic run, and it was probably the best phone I ever had until I upgraded to the 10 Pro.

Sadly I never, ever put the 8 Pro in any case or protective shell, and the damage of repeated minor drops took its toll. The screen was just cracked a tiny bit around the corners, but eventually the upper-right corner began a creeping black amoeba of darkness, and finally the entire touchscreen became unreliable, I suppose due to that damage, so I decided to bail out. Repairs were exorbitant so I decided to take Google's own trade-in deal.

gib444 [3 hidden]5 mins ago
> Just be careful with the 8

Don't forget the notorious vertical pink line issue! Luckily that had (has?) an extended warranty programme.

randlet [3 hidden]5 mins ago
My Pixel 8 failed with the exact failure mode (supposedly) covered by that extended warranty [0] program after owning it for 18 months. I had a very frustrating back and forth with Google support and in the end they refused to fix it under warranty because it wasn't manufactured in a specific batch.

Flagship phone turned into a useless device after 18 months of ownership due to a manufacturing issue and I've got no recourse. I'm done with Pixel and Google in general.

[0] https://support.google.com/pixelphone/answer/15009955?hl=en

gib444 [3 hidden]5 mins ago
Wow, that's shitty. There's certainly plenty of company in the 'never buying a Pixel again' crowd.

I've not heard anything good about Google's support in general.

Their partner repair company which did my screen replacement tried to refuse because it was running GOS - had to use all my charm to convince her to do it.

mystifyingpoi [3 hidden]5 mins ago
I have Pixel 9a and considered Pixel 10 for a while, but seeing Pixel 11 show up with absurdly microscopic improvements over 10 made me realize, that this smartphone line is just a solved problem since years ago.
sir_eliah [3 hidden]5 mins ago
Is there a point in changing a phone so often if it's not broken?
mystifyingpoi [3 hidden]5 mins ago
I know it's not really an argument, but I tend to change my devices also every 2-3 years, just so I can pass the "old" one to my less technical family.
nkingsy [3 hidden]5 mins ago
Att offered such good trade in rates for my phone that it’s been effectively free to upgrade to the last two generations.
chrismorgan [3 hidden]5 mins ago
I hear people say things like this about phones, laptops and cars, but anecdotally I have never once seen any sort of trade-in offer, and only rarely and arguably on any kind of lease or lease-to-buy arrangement, where I would consider that even remotely true.
fouc [3 hidden]5 mins ago
it's not free because it's priced into the phone plan (phone plan price is jacked up), unless you got grandfathered in w/ a good rate.
lucb1e [3 hidden]5 mins ago
Plus externalities. Producing things is never "free", even if the manufacturer were a charity and, you're right, they're not
tstenner [3 hidden]5 mins ago
Or even Google itself. I got a 150€ trade in rebate for an iPhone 8 with a cracked screen.
gib444 [3 hidden]5 mins ago
Whaaa? It gives me £65 even on an iPhone 12 in good condition. £50 for an 8 Plus. Same amount for 11 Pro or 10a

£50 for the 8 Plus isn't too bad though

(€150 = £127)

tstenner [3 hidden]5 mins ago
Well, back then when the Pixel 7a had just come out. So comparable to an iPhone 11 now
gib444 [3 hidden]5 mins ago
Oh I thought you meant recently. My bad
drnick1 [3 hidden]5 mins ago
Same thing here, I will keep my 10a for the foreseeable figure. It's unclear if future Pixels will support GOS at all, and the new Motorola is almost certainly going to be a $1000+ phone. Hopefully mid-range models will follow. I don't need a huge, expensive phone with five cameras.
regularfry [3 hidden]5 mins ago
Yeah, I've got a 10 Pro, jumped up from an 8. Looked briefly at upgrading to the 11 but it's clearly not worth it.
gregdeon [3 hidden]5 mins ago
Huh, good point. I wonder if this is the beginning of the end of constant phone upgrades. It used to be that new phones had much better hardware, so software that was only tested on new phones would make an older phone grind to a halt. But if the upgrades are much more incremental, perhaps a phone will last a lot longer?
lucb1e [3 hidden]5 mins ago
The people who I knew that upgraded every 2 years stopped doing that nearly ten years ago now. Smartphones barely get better, why get a 49€/month contract when you can get one for 15€ instead and not have to migrate phones every two years upon contract renewal when the new phones aren't significantly better anyway?
yaro330 [3 hidden]5 mins ago
To be fair, the trade in offers are larger this year than during P10 release window, at least where I live. So I was able to go from 10 Pro 16/256 to 11P 16/512 for something like 650 eur. It's a great deal IMHO as the SoC + modem combo is at least 30 to 40% more efficient. The phone runs faster, cooler and I don't have the battery anxiety that I got after 10 Pro.

I used the OP15 in the meantime and its ram management and (ironically enough) performance in day to day apps was somehow much worse. It unloaded apps, skipped notifications, apps took longer to open. Google have put in a lot of work into software ahead of the rampocalipse.

prism56 [3 hidden]5 mins ago
I'm not wanting to dispute or tell somebody what to spend their money on. I see this take a lot on reddit especially.

You bought arguably the same phone with marginal gains to CPU score and a little better battery. Paying €650 for that privaledge doesn't seem like a great deal to me...

coryrc [3 hidden]5 mins ago
Summed over all phones I've ever bought, I don't think I've spent €650.
mylasttour [3 hidden]5 mins ago
My Pixel 3 is still going strong! :)
yodsanklai [3 hidden]5 mins ago
I loved my 4a, but broke a couple due to water infiltration in rainy conditions. Modern phones are resistant to water which is a nice improvement.
INTPenis [3 hidden]5 mins ago
I tend to "upgrade" to the previous release, I always got them as their stocks dwindle and their prices are low. Did this with the last nexus, pixel 6, 7, and now I got a pixel 9 from work so the pattern is broken.
microtonal [3 hidden]5 mins ago
The Pixel 10 Pro is even fairly cheap in many countries if you can live with 128GB storage and the base model still has 16GB RAM.
ponector [3 hidden]5 mins ago
The only reason to update from my pixel 7 is to get more storage. Otherwise a perfect phone
tcfhgj [3 hidden]5 mins ago
why upgrade every 3 years when there are 7 years of updates?
yodsanklai [3 hidden]5 mins ago
I get new phones and computers from my company every 3 years, I don't even bother upgrading so often. The improvements aren't even worth me spending a few hours to set up and migrate data.
kakacik [3 hidden]5 mins ago
photos
metalliqaz [3 hidden]5 mins ago
I dropped my Pixel 8 and replaced it with a Pixel 10a. I'm perfectly happy and the lack of a camera bump is awesome. I don't intend to upgrade for quite some time.
sigbottle [3 hidden]5 mins ago
I never thought about it like that, damn.
rickdeckard [3 hidden]5 mins ago
Quite a bad signal-to-noise ratio in this link.

It's an emotional discussion about Google not supporting MTE on Pixel 11 (old news of August, GrapheneOS had to roll back that statement in September [0]).

Now the question is whether MTE will be enabled by Google as part of a future OS-upgrade, to which there is no definite answer AFAIK

[0] https://news.ycombinator.com/item?id=49536384

Luker88 [3 hidden]5 mins ago
> Now the question is whether MTE will be enabled by Google as part of a future OS-upgrade, to which there is no definite answer AFAIK

Still means that currently the phone has no support for MTE.

I have bought too many things on vague promises that did not happen.

It's not there now -> it's not supported. EOL.

JacobKfromIRC [3 hidden]5 mins ago
Why are we dependent on Google to enable MTE on the OS-side? If it's a hardware feature, why couldn't GrapheneOS enable it in GrapheneOS even if Google's OS wouldn't enable it?
croes [3 hidden]5 mins ago
> It still has at least bare minimum support for MTE at a hardware level. We think they removed most of the hardware acceleration from the CPU cache to save money. They ruined the performance so it ended up being fully disabled in firmware. It may still be usable.

MTE but slow

rickdeckard [3 hidden]5 mins ago
"We think", followed by a quite fueled accusation.

It has no MTE right now, okay. Is there any evidence on the rest?

gib444 [3 hidden]5 mins ago
I wonder what the comms would have been without the Motorola partnership
someonebaggy [3 hidden]5 mins ago
They would have either sucked it up and supported the 11, or shut down the GrapheneOS project completely.
izacus [3 hidden]5 mins ago
The comms have been like that for years now.
varispeed [3 hidden]5 mins ago
MTE support in itself says nothing as vendors usually obscure implementation details and also MTE is a perfect place to implant undocumented backdoors for security services to use.
brookst [3 hidden]5 mins ago
Any evidence of those backsoors?

This reads like “your front door lock is the perfect place for security services to have a master key.” True, but not strong as an argument against having a lock.

gruez [3 hidden]5 mins ago
>This reads like “your front door lock is the perfect place for security services to have a master key

Even that analogy fails because MTE is in addition to existing countermeasures against memory corruption attacks. In the worst case, compromising MTE just means you don't have MTE, not that you get arbitrary code execution.

jonaustin [3 hidden]5 mins ago
Most recent comment from them (9/30)

https://discuss.grapheneos.org/d/41564-pixel-11-doesnt-yet-m...

GrapheneOS:

``` We're not going to add support for the Pixel 11 series unless it ships MTE support. It has hardware level support for MTE but it shipped without firmware support for it. It's unknown why that's the case and it could be due to flaws in the hardware implementation which have to be worked around. It isn't yet clear if it's going to support MTE but we've decided we won't support it unless it ships. Android 17 QPR2 Beta launched for the Pixel 11 after we made our initial posts about this and added preliminary firmware support for MTE while keeping it fully disabled for the OS even as a developer option. It isn't clear if something is severely wrong with it or not yet so we can't make any commitment to supporting the Pixel 11 series. ```

rgblambda [3 hidden]5 mins ago
>It appears Google cut an important security feature to save money.

If you're doing comms for a serious project, it's probably best not to speculate on the justification of an internal decision at a different org, even if you're reasonably sure.

mgol94 [3 hidden]5 mins ago
>For example, non-Samsung Android OEMs aren't allowed to directly sell devices with GrapheneOS and Google will only permit it within a quota. It can and is being worked around and there will be devices sold with GrapheneOS as the stock OS without Google restricting how many can be sold.

I think at this point is too late for complicity, they are actively fighting against GrapheneOS anyway. You either fight back, or wait until you loose all the leverage

rgblambda [3 hidden]5 mins ago
My point isn't about fighting back vs rolling over. Just that it doesn't achieve anything to guess at why Google did a certain thing.

Edit: Maybe you replied to the wrong comment? I didn't say anything about complicity and neither did the GrapheneOS announcement in the part I quoted.

lucb1e [3 hidden]5 mins ago
The quote is from another thread, not sure why GP didn't link their source to avoid this confusion: https://news.ycombinator.com/item?id=49946698
pbhjpbhj [3 hidden]5 mins ago
>best not to

Because? The obvious implication is you're saying Google will abuse their monopoly to hurt you if you upset them. Is that what you're implying? Or is it user trust, or something else you think is improved by avoiding such speculation?

rgblambda [3 hidden]5 mins ago
I was actually just implying that it looks unprofessional. Say they cut an important security feature. Don't try to guess why.
fwn [3 hidden]5 mins ago
It entirely depends on the strategy you try to implement through your communication.

That is generally true: prior to any professional communication you have a goal, assumptions, messaging, etc. Why would you produce communication at all, if you had not?

Marketing people often think there is a cookie-cutter rulebook you should follow, but there is not.

We are living in the "the bird is freed" and "nice genes" era of corporate communication.

pbhjpbhj [3 hidden]5 mins ago
Well you clearly didn't realise what you did.

Oh, and I'm not going to tell you what it was, and 'don't try to guess'.

/s

rgblambda [3 hidden]5 mins ago
I'm not entirely sure what I "did". Given that I don't do comms for a serious open source project, mind letting me in on your secret?
jeffbee [3 hidden]5 mins ago
Innuendo about how large organizations make decisions, issued by people who have never had a job, are de rigueur for open source activists and catnip for HN.
realusername [3 hidden]5 mins ago
I think cutting it for saving money is the most charitable explanation you can give, the other ones would look much worse for Google.
hn_go_brrrrr [3 hidden]5 mins ago
Timeline pressure seems to me the most likely one, and that looks no worse than saving money.
lucb1e [3 hidden]5 mins ago
How could that be when previous models have it? In terms of timeline, it seems quicker not to remove a feature than to remove and test the new changes
podocarp [3 hidden]5 mins ago
Not surprised, since it wasn't used in Android to begin with they probably thought nobody will notice if it's removed. And indeed, for the vast majority of people nobody will notice.
Magicrafter13 [3 hidden]5 mins ago
The vast majority of people won't notice if you dilute their food/drink products to save money. Doesn't make it okay.
microtonal [3 hidden]5 mins ago
The field is certainly moving in the opposite direction. Apple has their own extension of MTE (MIE) and uses it in the kernel and a bunch of system processor. Samsung has had MTE support in flagship Exynos for some years now and they started experimenting with MTE in the OneUI 9 betas (not sure what the MTE status in the final release is).
MBCook [3 hidden]5 mins ago
I don’t really follow Android so my memory may be wrong but didn’t Google make a big deal about this when they rolled it out?

If so, it seems odd to cut it back.

pbhjpbhj [3 hidden]5 mins ago
So Arm built in MTE but Google have decided to prevent access to it at the firmware level?

Have they introduced some other mitigations, for eg UAF, to improve memory safety?

It seems possible that nixing MTE is to prevent stomping on some TLAs exploits?

surajrmal [3 hidden]5 mins ago
MTE requires several things to work well. Notably there is some missing hardware believed to be necessary for MTE to be performant on the pixel 11.

In terms of mitigation of UAF, a great deal of new code written for Android userspace these days is in memory safe languages such as rust. Also, a lot of testing with instrumented code sanitizers is still done before release. We don't know how much risk MTE actually mitigates.

t1234s [3 hidden]5 mins ago
Google would be smart to adopt and fully support Graphine as a "Pro" version of its phone OS.
Retr0id [3 hidden]5 mins ago
It's hard to tell, is this a new announcement?
arusahni [3 hidden]5 mins ago
Looks like that post was last edited August 30th. On Sept 1st they posted saying they think they found a way forward [1].

[1]: https://grapheneos.social/@GrapheneOS/117194007157499435

pavon [3 hidden]5 mins ago
The discussion in the post is on-going. Two days ago they posted that they will not support Pixel 11 unless Google adds MTE support in a future update. That may happen in an upcoming December update, but it is just a rumor.

[1] https://discuss.grapheneos.org/d/41564-pixel-11-doesnt-yet-m...

arusahni [3 hidden]5 mins ago
Ah - that would have been a more helpful post for the OP to have linked.
Medea [3 hidden]5 mins ago
It was posted 29 Aug
nubinetwork [3 hidden]5 mins ago
Old news
mistyvales [3 hidden]5 mins ago
Guess I should order the 10 to replace the 9a I dropped down the stairs.
jordand [3 hidden]5 mins ago
GrapheneOS last said they should be able to support Pixel 11 along with the Motorola phones
rkozik1989 [3 hidden]5 mins ago
Serious question about phone security: do phone application operating systems do anything to protect against the device's real-time OS from being able to access RAM/Disk that's being used by the application OS? Because if that cannot be controlled security at the application OS level is meaningless.
TheDong [3 hidden]5 mins ago
Security isn't just an absolute, it's also a multi-faceted series of defense-in-depth measures.

Can you get arbitrary code execution on the RTOS from another app? No? Then adding layers to protect apps from each other is meaningful.

What you're saying isn't too far from "Well, if the attacker has physical access they can just freeze and decap the memory to read all secrets, so like there's no point in even hashing passwords or fixing XSS"

gruez [3 hidden]5 mins ago
>do phone application operating systems do anything to protect against the device's real-time OS from being able to access RAM/Disk that's being used by the application OS? Because if that cannot be controlled security at the application OS level is meaningless.

If you're talking about the baseband, AFAIK it's already isolated on both iPhones and pixels. Not sure about other androids.

surajrmal [3 hidden]5 mins ago
There are several peripherals running their own OS. Those have their access to RAM limited by an iommu and they have no direct access to the primary storage (they may have some local ROM storage for firmware). If you're asking about the other OS that runs on the application processor such as the bootloaders, trusted firmware, trusted os, etc, then no, those have a superset of access to what the primary OS running on those cores have access to. This is by design.
jeffbee [3 hidden]5 mins ago
It's not just phones, either. All modern computers are full of non-architectural cores running all kinds of wacky stuff.
someonebaggy [3 hidden]5 mins ago
What's meant by "your device's real-time OS"? Heard several variations of this questioning recently and it seems more like FUD than anything else. I presume it's a telephone game away from the fact that some modem processors have DMA access and WAN-side exploits?
izacus [3 hidden]5 mins ago
Yes, at least Pixels and Apple devices do (the Titan/T security chips handle disk encryption and communication and are behind IOMMU which disallows direct acces from things like modems).
Pxtl [3 hidden]5 mins ago
My pixel 7 is starting to get long in the tooth, I know I'll run it into the ground but I'm starting to wonder where I'll go for the next one now that Google is increasingly locking down their platform.
microtonal [3 hidden]5 mins ago
Motorola Signature 27, since that seems to be the phone that is going to support GrapheneOS? I have a P10P, but I'm very excited that they are working with a manufacturer that actually supports them. I'll most likely buy the Signature 27 at some point, just to vote with my wallet (even if the P10P) is still fine.
someonebaggy [3 hidden]5 mins ago
Whatever Graphene or Lineage supports. Google doesn't even have magic power over all phone makers, let alone all ROMs.
ljhkkjl [3 hidden]5 mins ago
Relying on Google hardware seems like a very bad idea. GrapheneOS would have much more adoption if they weren't so Google-obsessed.
nicman23 [3 hidden]5 mins ago
noooooo it needs the secuureee coooproccesssorr or it is 1% easier to haaack

at least they went with something with snapdragon - the upcoming moto phone

DANmode [3 hidden]5 mins ago
Sorry kids, this is Hacker News,

not Lacker News.

Not tall enough, try again next year.

DANmode [3 hidden]5 mins ago
> GrapheneOS would have much more adoption if they weren't so Google-obsessed.

The GrapheneOS project would have lots of other devices to choose from (or any) if everyone making hardware (besides Google) weren’t so obsessed with selling cheap, insecure trash.

You don’t know what you’re talking about.

If you ever do: you’re free to build the project from source for whatever generic device - but will gain only small details over vanilla AOSP without proper hardware to make use of.

atlgator [3 hidden]5 mins ago
Why does the announcement focus so much on Apple when they exclusively support Android?
mrbn100ful [3 hidden]5 mins ago
Yes please buy the low volume phone from a 5% market share manufacturer.

Someone high up got tired to pull over every pixel user at the border.

With the new Motorola, TSA line are going to move faster that ever!

If you care about privacy, stay away for the moto release and stick with pixel.

lesspassiveobse [3 hidden]5 mins ago
English version: Yes, please buy the low volume phone from a 5% market share manufacturer. Someone high up got tired of having to pull over every pixel user at the border. With the new Motorola, TSA lines are going to move faster than ever! If you care about privacy, stay away from the moto release and stick with pixel.

For reference Pixels have about 1% market share, the graphene phones will be the same hardware as normal moto flagships and 99% of TSA agents won't be able to differentiate motorola models

gruez [3 hidden]5 mins ago
>For reference Pixels have about 1% market share,

You're off by a factor of 3, unless you count global market share, which includes random brands unlikely to be in the US like xiaomi or huawei.

https://counterpointresearch.com/en/insights/us-smartphone-m...

Moreover motorola flagships (ie. the only model that support grapheneos for now) are likely a fraction of the market share of motorola as a whole, so OP is still correct in that motorola grapheneos phones are more identifiable.

>the graphene phones will be the same hardware as normal moto flagships and 99% of TSA agents won't be able to differentiate motorola models

That argument could be used for pixels as well, which are also just generic black rectangles, especially the "a" models that lack the distinctive camera bump. Also if DHS/ICE really wanted to, they could avoid this problem altogether by requiring travelers to self-declare what phone they have. Sure, you can lie, but then you committed a federal offense by lying on immigration paperwork.

mrbn100ful [3 hidden]5 mins ago
Go on the Motorola website, over 40 SKUs! We all know that the most expensive one is not going to be the most popular.

Every Google Pixel model per generation ends up supported.

DO NOT UNDERESTIMATE TSA.

Social hardening is a real problem.

Pxtl [3 hidden]5 mins ago
> With the new Motorola, TSA line are going to move faster that ever!

I missed a news story. Context?

worldsavior [3 hidden]5 mins ago
Motorola has partnership with GrapheneOS.