We have a partial port of GrapheneOS to the Pixel 11 series after a week of work on it. We're unable to complete the port due to lack of support for ARM hardware memory tagging in software, firmware and near certainly hardware. It appears Google cut an important security feature to save money.
Wish they’d focus on phones NOT made by major corporations like Google and Motorola, and instead focus on small companies’ phones like Fairphone, Pine64, Purism, Jolla, etc.
They can’t. They require extremely up to date firmware and very short update cycles. Only large corporations with huge phone platforms are able to do satisfy that.
Can Graphene OS achieve their privacy targets and principles in different ways that encourage collaboration with non-corporations?
I refuse to believe that GOS can’t agree to graduated privacy provisions according to the capabilities of Linux and sustainable/repairable non-corpo companies and their phones.
The hardware requirements are public. Those manufacturers have chosen not to implement supported hardware, which is step 0.
There is also a maintenance burden for the GrapheneOS team. The ROM requires kernel patches and driver work that makes supporting additional phones intensive work.
Why would manufacturers choose to meet GOS’s extra requirements?
There needs to be a give and take. It seems like GOS’s mantra is their way or the high way, which isn’t collaborative in the slightest.
Can there not be discussions held between Linux and sustainable/repairable OEMs and GOS to start integrating each other’s requirements? Diplomacy/negotiations/working groups are just completely neglected?
GOS is designed for maximum security at its base. It uses all the hardware features it requires to minimize its attack surface against adversaries that have infinite resources to attack the device and get at the infirmation inside.
Lowering those standards means opening a vulnerability, which means someone with that vulnerability can have their data stolen from the device in particularly that way, since that vulnerability is well documented.
Using a widely-available phone with good performance, decent quality, and long term security support, meant that more people could access it. I still can’t buy a Fairphone without going through an overseas middleman, then hoping I have no warranty issues, because they don’t sell to Australia. If something goes wrong with my Pixel, the shop I bought it from is minutes away.
Wish they’d focus on phones NOT made by major corporations like Google and Motorola, and instead focus on small companies’ phones like Fairphone, Pine64, Purism, Jolla, etc.
They can’t. They require extremely up to date firmware and very short update cycles. Only large corporations with huge phone platforms are able to do satisfy that.
Can Graphene OS achieve their privacy targets and principles in different ways that encourage collaboration with non-corporations?
I refuse to believe that GOS can’t agree to graduated privacy provisions according to the capabilities of Linux and sustainable/repairable non-corpo companies and their phones.
Those also don’t meet the hardware requirements
But why can’t GrapheneOS work with those companies to ACQUIRE the right hardware requirements, rather than leaning on a corporation?
The hardware requirements are public. Those manufacturers have chosen not to implement supported hardware, which is step 0.
There is also a maintenance burden for the GrapheneOS team. The ROM requires kernel patches and driver work that makes supporting additional phones intensive work.
Why would manufacturers choose to meet GOS’s extra requirements?
There needs to be a give and take. It seems like GOS’s mantra is their way or the high way, which isn’t collaborative in the slightest.
Can there not be discussions held between Linux and sustainable/repairable OEMs and GOS to start integrating each other’s requirements? Diplomacy/negotiations/working groups are just completely neglected?
GOS is designed for maximum security at its base. It uses all the hardware features it requires to minimize its attack surface against adversaries that have infinite resources to attack the device and get at the infirmation inside.
Lowering those standards means opening a vulnerability, which means someone with that vulnerability can have their data stolen from the device in particularly that way, since that vulnerability is well documented.
Using a widely-available phone with good performance, decent quality, and long term security support, meant that more people could access it. I still can’t buy a Fairphone without going through an overseas middleman, then hoping I have no warranty issues, because they don’t sell to Australia. If something goes wrong with my Pixel, the shop I bought it from is minutes away.
Those that can purchase these Linux phones should.
Those that can’t purchase these Linux phones should purchase whatever is next best.