Pixel 11 尚未达到 GrapheneOS 的安全标准,因此可能会被跳过。
Pixel 11 doesn't yet meet the GrapheneOS security standards and may be skipped

原始链接: https://discuss.grapheneos.org/d/41564-pixel-11-doesnt-yet-meet-the-grapheneos-security-standards-and-may-be-skipped

GrapheneOS 表示,由于 Google 移除了 ARM 内存标记扩展(MTE),因此无法完成对 Pixel 11 的部分移植。MTE 是一项安全功能,整个操作系统广泛使用它来缓解远程和本地漏洞利用。尽管 Android 16 可以为选定的进程启用 MTE,但据报道 Pixel 11 缺少必要的软件、固件和硬件支持。 GrapheneOS 承认 Pixel 11 还有其他改进,例如后量子验证启动、AOSP IMS 以及更强的 Titan M3 防护,但认为这些改进带来的代价不值得,尤其是在首次解锁前(BFU)的安全性方面。该项目还批评 RAM 容量减少、GPU 性能不足、价格过高,以及 Google 在 Android 16 之后结束对 AOSP Pixel 设备的支持。 该项目推荐使用 Pixel 8 至 Pixel 10 设备,尤其是价格较低的 Pixel 10,并且可能完全跳过 Pixel 11,转而专注于即将推出的摩托罗拉硬件。它希望未来的 Pixel 11a 能够保留 MTE。

相关文章

原文

We have a partial port of GrapheneOS to the Pixel 11 series after a week of work on it. We're unable to complete the port due to lack of support for ARM hardware memory tagging in software, firmware and near certainly hardware. It appears Google cut an important security feature to save money.

ARM hardware memory tagging (MTE) is used by GrapheneOS across the entire base OS including the kernel and every standard base OS process. It's only temporarily disabled for a few device-specific processes. It greatly improves protection against nearly all remote exploits and many local exploits.

Pixel 8 launched with hardware MTE support in October 2023. We integrated it into our hardened_malloc project and began using it across the OS later that month. Android and the Pixel OS never started using it by default. Android Advanced Protection Mode in Android 16 enables it for a few processes.

Apple's Memory Integrity Enforcement (MIE) is an always enabled feature on the iPhone 17. It's simply a high quality implementation of MTE using the latest standard extensions. It uses MTE in the most secure mode in the kernel and a large portion of userbase. They did a very good job integrating it.

Apple's MIE and Android 16+ AAPM don't use MTE for user installed apps unless those explicitly opt in. GrapheneOS enables it for more apps automatically and has a toggle for users to opt-in for every user installed app. There's a per-app toggle to opt-out for incompatible apps which is uncommon.

Neither iOS or Android encourage app developers to opt into MTE and other more aggressive security features used in the base OS. Apple's docs warn developers of performance and stability issues. Our approach enables forcing using MTE in the standard allocators regardless.

Pixel 11 does have security improvements including moving to post-quantum secure verified boot (ML-DSA) and replacing Samsung Shannon IMS with AOSP IMS. Titan M3 should significantly improve protection against data extraction in Before First Unlock state. It's too bad they ruined it by cutting MTE.

Pixel 11 series is a lot more expensive for an incremental improvement to the CPU, the same underpowered GPU and reduced RAM for the Pro base models. They finally caught up to the last generation of Qualcomm cellular radio. It's overpriced, the upgrades aren't impressive and losing MTE is appalling.

Compared to the Pixel 11, a Snapdragon 8 Elite Gen 5 has 40% higher single threaded CPU performance, 80% higher multi threaded performance, over 100% higher GPU performance and a far better cellular radio. It also finally has MTE. The next gen is what will be in the first Motorola with GrapheneOS.

Pixel 9a and earlier (including Nexus devices) were the Android Open Source Project reference devices. Pixel support was removed from AOSP with Android 16. It's now harder to support Pixels than many other devices and massive progress towards open source firmware and driver libraries was discarded.

Compared to the stock Pixel OS, GrapheneOS ships AOSP patches months earlier and Linux kernel patches many months earlier. However, we rely on them for firmware and most driver updates. We also want to move to new kernel branches earlier. These things can be improved with our Motorola partnership.

We strongly recommend against buying Pixel 11 devices. Pixel 8, 9 and 10 have much better overall security for GrapheneOS. Pixel 10 is cheaper with similar hardware and MTE. Pixel 11's Titan M3 should improve BFU security for users without a strong passphrase, but losing MTE craters AFU security.

We haven't determined what to do about this situation. It may be best for us to skip the Pixel 11 series devices. We can shift our focus entirely to the upcoming Motorola devices instead. Pixel 10a was really a 9th gen Pixel, so hopefully the Pixel 11a does the same with 10th gen and includes MTE.


https://bsky.app/profile/grapheneos.org/post/3mua32q4ds22e
https://grapheneos.social/@GrapheneOS/117179231167297908
https://x.com/GrapheneOS/status/2093731615243411862

联系我们 contact @ memedata.com