7 ms·
GrapheneOS project: pixel 11 no longer supports hardware memory tagging (MTE)
- deleted 19d ago[deleted]
- perarneng 19d agoWhat, MTE is such a promising tech and for security and now that we need all security we can get. WTF this is terrible development. You cant go backwards when the world needs getting even more secure.
- prism56 19d agoSuch a shame. Google themselves barely utilised it in their stock builds. I wonder if there is some silicon or development overhead they decided to cut. I'm optimistic about the Motorola partnership and when my 9 Pro is EOL I'll definitely look at how that's played out.
- grapheneos 19d agoGoogle likely cut MTE to reduce the die space required by CPU cache. It saves them money on a feature they never deployed by default and only used for a few processes as part of Android Advanced Protection Mode (AAPM) without enabling it in the Linux kernel. Their security team should have gotten it deployed by default for a large portion of the OS by now and then it would have been much harder to justify removing it. The small performance impact of asymmetric mode is irrelevant for the vast majority of the OS and it can also be used in the near zero cost asynchronous mode. We use synchronous in the kernel for security reasons but they didn't have to do that. It's a completely different story for GrapheneOS where it means losing one of the main kernel and userspace security protections. This is one of the only ways we can significantly harden the Linux kernel with existing security features. The Linux kernel has always been a huge security liability for Android and AI models are making that much more obvious to everyone. Google will likely end up heavily using MTE in the future. Pixel 11 devices won't be able to benefit from it. They're at the start of 7 years of updates but they won't be getting the benefit of future updates enabling MTE. Pixel 8 and later will benefit from Google likely expanding use of MTE for AAPM and eventually beginning to use it by default. It's unlikely Google will stop working on expanding MTE due to the Pixel 11 hardware decision. Multiple other OEMs are interested in MTE for devices made for businesses and governments even if Google decided it wasn't worth the cost for Pixels.
- prism56 19d agoWeird omission then... Seems asinine...
- ChocolateGod 19d agoIronically the recent CVE that's being used to root Android phones (Ghostlock) running GKI images is mitigated by MTE.
- kuschku 19d agoIf there will be a GrapheneOS image for the Pixel 11 without MTE, could that open the door for GrapheneOS on a lot more phones that support AOSP?
- grapheneos 18d agoWe don't plan to make official GrapheneOS releases for any more devices without MTE. If we decided to provide support for the Pixel 11 series, it likely won't be branded as GrapheneOS to make it clear it isn't on the same level. It would be inconsistent to require Motorola to provide MTE support and then to support the Pixel 11 without it. There are no phones directly supported by AOSP. Motorola is helping us support their devices and port our features to them. We have to do an immense amount of work on it ourselves for Pixels and already did a lot of it for the Pixel 11 devices. Other devices are missing more than MTE.
- kuschku 18d agoRegarding the differentiated branding, I've been hoping for a GrapheneLite for many years now. Regarding direct AOSP support, there are many devices that work fine with just the generic system image, which I'd count as direct AOSP support.
- drabbiticus 18d agoI would argue that "works fine" != "direct support" when discussing vendors and platforms. Support is a commitment signal, not just a technical capability.
- WinstonSmith84 19d agoI don't understand much from MTE/Android or MIE/iOS but the explanation is also confusing when: - They claim Apple did a great job integrating MIE in iOS - iOS doesn't encourage to opt into MTE ... Apple's docs warn developers of performance and stability issues So it seems like even for iOS, this special security feature is only available for Apple own iOS app (at most?). Then also: > Even Signal doesn't opt-in. Our approach enables forcing using MTE in the standard allocators regardless. So does that mean that Signal and any other apps are enrolled in MTE on Graphene?
- brookst 19d agoI see a significant difference between making a security feature available but opt-in during a teething phase, and removing the feature altogether. Am I missing something?
- grapheneos 19d agoiOS uses MTE for nearly all of the important parts of the OS. It uses MTE within the kernel and for a substantial portion of the base OS processes. They focused on deploying it to the most security relevant processes first but it's deployed for a large portion of the OS beyond those. Apple has done a very good job protecting the OS with it. They've done a very poor job getting the app ecosystem to adopt it. Android has more app ecosystem adoption than iOS due to having a better open source app ecosystem where GrapheneOS users have asked apps to enable it by default. Many GrapheneOS users are also force enabling MTE for user installed apps via our recommended toggle for it. Those users are reporting invalid memory access to developers via our dedicated notification system for invalid memory accesses it catches. For Android app developers, not opting into MTE doesn't mean their app won't be used with MTE due to GrapheneOS. GrapheneOS uses MTE for the kernel and nearly every userspace process including all the base OS apps. We've had to fix many upstream Linux kernel and Pixel kernel driver bugs found by MTE. However, we aren't trying to fix the Pixel userspace drivers code ourselves so we have a few userspace processes excluded from MTE caused by userspace driver library/service bugs. We recommend users enable our toggle for enabling MTE by default for every user installed app not explicitly marked as incompatible in our compatibility database. GrapheneOS has user-facing notifications for invalid memory accesses caught by MTE providing a traceback to share with the app developers. Users can use the per-app toggle to work around it if it makes an app unusable. We take the same approach for other aggressive exploit protections provided by GrapheneOS. Exploit protections with only rare compatibility issues are enabled by default for apps with a per-app toggle to opt-out and no toggle for the global default.
- Limit5332 19d agoThis isn't terrible development, it's simply that GrapheneOS devs can't do miracles They can't just continue supporting phones if they have security downgrades, especially if it's an important feature.
- HybridStatAnim8 19d agoI think they mean "this is a terrible development" in the sense that this is terrible news/turn of events. They arent criticizing GrapheneOSs software development.
- bestouff 19d agoThey also say that the Pixel 11 is a very very tiny improvement wrt the Pixel 10, with less RAM and more expensive. So basically they say don't buy it, wait for the Motorola phones.
- grapheneos 19d agoPixel 11 has an incremental upgrade to the CPU, the same underpowered GPU and less RAM for the base Pro models. It has a new major version of the secure element (Titan M3) which likely greatly improves Before First Unlock state security for users without a strong passphrase. It has a better radio from a performance and efficiency perspective but it's still a more than yearly generation behind Qualcomm. The cellular radio firmware is also likely a security downgrade but the userspace code is more secure due to moving to AOSP IMS code. If these devices hadn't removed MTE, then they would have been a sidegrade with marginally better security. Removing MTE ruins these devices for GrapheneOS. We could still support the Pixel 11 series but it would be greatly rolling back overall security to before the Pixel 8. It does at least have PAC and BTI but MTE was the main improvement with the Pixel 8 rather than those.
- yaro330 19d ago> Pixel 11 has an incremental upgrade to the CPU You keep repeating this everywhere but this is just plainly wrong. They went from an old big.Little (with middle cores) arrangement that everyone abandoned for flagship chips generations ago, with core arches that were 2-3 generations behind competition, to a modern, up to date arrangement. There's literally nothing newer that they could've gotten from Arm, and other CPUs are releasing with C1 generation. And I don't get your angle on the GPU. GOS is not gaming oriented, Pixels are not gaming oriented, and never were. They have a decent NPU to handle AI, a decent ISP to handle cameras, what more do you need the GPU for? Why would they put in a PC grade monster like Qualcomm? Same for the modem, it's well known that Qualcomm are way ahead of the game, but they also charge like crazy for their SOCs and are a horrific partner to work with. They treat clients like shit, I get why Google ditched them when they were able to. And you keep recommending P10 when it's genuinely a non improvement over P9, with worse battery life and running hotter, and the same modem. What the f is your angle? Is Micay back to GOS?
- newsomix9xl 19d ago"Pixel 11 series is a lot more expensive for an incremental improvement to the CPU, the same underpowered GPU and reduced RAM for the Pro base models. They finally caught up to the last generation of Qualcomm cellular radio. It's overpriced, the upgrades aren't impressive and losing MTE is appalling." I guess that's a thumbs down then?
- ysnp 19d agoCan someone from AOSP/Pixel hardware security shed some light? This is strange timing, especially when the approach has been validated by Apple also.
- inigyou 19d agoProbably just that Google doesn't use it so why pay for it? They're not obligated to support whatever GrapheneOS wants.
- grapheneos 19d agoThey do make limited use of it for Android Advanced Protection Mode (AAPM) introduced in Android 16. It no longer provides this upgrade for protection against exploits on the Pixel 11. They could substantially expand AAPM to using it across much more of the OS and could also start using it without AAPM since there's no significant downside to using it for most of the userspace code outside of the kernel.
- inigyou 19d agoIt sounds like it was a failed experiment. Since it worked, it probably lost on a cost/benefit analysis. Which is fair enough.
- port11 19d agoFolks SWOTing everything in life like hubris ain’t a thing… all tech needs to be more secure, even more so as the asymmetry of attack and defence grows wider.
- inigyou 19d agoYou can't just say "we need security, this is security, therefore we must do it". That's the politician's fallacy. Did you know that preventing sideloading also improves security, but GrapheneOS is adamant that sideloading must be allowed?
- xizst94 19d agoLost any remaining respect for Pixel with the decisions they've made for Pixel 11. The product design and hardware teams have both tried to one up each other and who can deliver the bigger pile of steaming crap.
- sdcfgy 19d agoUrgh I was about to buy one for GOS. Maybe back to iPhone it is.
- grapheneos 19d agoYou can get a Pixel 10 or wait for the upcoming Motorola flagship with GrapheneOS support. Pixel 11 only has an incremental CPU upgrade and the same GPU as the Pixel 11 anyway. It isn't much of a hardware upgrade and is even a downgrade for RAM with the base Pro devices. It's more expensive than the Pixel 10 was too. The upcoming Motorola flagship will have a dramatically better CPU and GPU than the Pixel 11 and competitive cameras. It will still have 7 years of updates, MTE and a secure element with the features used by GrapheneOS. Motorola Signature (2026) is the predecessor not quite meeting our requirements mainly due to lack of MTE but also lack of other features which had to be developed.
- matheusmoreira 19d agoEagerly waiting for the Motorola flagship! Will it be released worldwide?
- grapheneos 19d agoIt should be more globally available than Pixels. Look at the availability of the existing Motorola Signature (2026) or the more recently launched Razr Fold (2026) and Razr Ultra (2026). Those 2026 devices won't support GrapheneOS, but the successor the Motorola Signature will. We don't know precise details about folding devices yet.
- WinstonSmith84 19d agoMotorola doesn't have a great track records for flagships smartphones. I will keep finger crossed that we won't have to choose again between security and features but either way it's a great news, and I truly hope that GrapheneOS will be adopted by more manufacturers in the future
- 19d ago
- dreamcompiler 19d agoGood riddance to Google. I'm happy GOS is no longer dependent on their hardware. My concern is that Motorola is a Chinese company. Sure, Pixel and Apple phones are made in China too, but they're overseen by American companies. How can we know these Motorola phones will not one day be placed on the "do not trust" list like e.g. Huawei phones?
- dackdel 19d agoplaced on the do not trust list?? who places them on this list? and why do you listen to the people who place them there.
- MattTheRealOne 19d agoThe US government puts them on the list. I don't care that they are on the list, but it does mean they can't sell the devices in the United States. If that ever happened to Motorola, and there were still no other devices that Graphene OS supports, then there would be no options left.
- grapheneos 19d agoPixel 10 has 6 years of support remaining and the more recently launched Pixel 10a has even more of the support time remaining. We're hoping the Pixel 12 series brings back MTE so that it's only 1 generation not meeting our requirements. We could support the Pixel 11 series if we wanted but we'd have to heavily recommend against it. We haven't fully decided on how to handle it yet.
- esseph 19d ago> placed on the do not trust list?? who places them on this list? The President of the United States, or members of the Federal Government that have the various levers of power. > and why do you listen to the people who place them there If they won't allow the devices to be imported then it's not really an option. Which also means they wouldn't be allowed to connect to the cell network. Or they could be barred from all Federal or State facilities, having to be left in a faraday bag upon entry. Federal grants and loans to states and companies could be denied if company policy allows the use of those devices for corporate communications and purchasing decisions, etc.
- aboringusername 19d agoIt's funny how much Google lies about Android being 'secure' [1] and how much GrapheneOS, for free, improves the security of everyone with their work. Google should be, immediately, merging all patches/changes GrapheneOS makes and releasing a new build of Android to AOSP. Instead, users are subject to weak efforts to protect their security and privacy while Google parade about how good and amazing they are. They mention [1] 'This unencrypted data can be used to build user profiles or, in the hands of malicious actors'...And can't see the irony. They ARE the malicious actor and they absolutely build profiles about everyone. Whatever happened to the 'privacy sandbox' initiative again? Anyone who values Graphene's work will purchase one of their Motorola devices, whatever the cost, otherwise it seems your choices are going to be giving up more data and control to Google, because they are clearly, obviously and systematically trying to remove GOS from Pixels (lack of source code, removing hardware features, making it purposely difficult to support pixels). I predict by 2030 GrapheneOS will not support any new pixels entirely. The existing pixels will eventually die off and that will be that. [1]: https://blog.google/security/new-android-network-security-protections/ https://blog.google/security/new-android-network-security-pr...
- inigyou 19d agoThey see the irony, they know the irony, they know their money comes from that irony being ignored so they will never lampshade it.
- aboringusername 19d agoIt's obvious they see open access to users data as a threat to their business model. No, they haven't suddenly decided to care about your privacy, they want to deny other actors access so you need to get data directly via them. They will obviously still collect it themselves via their numerous methods (play services, chrome, ad networks etc).
- palata 19d ago> Anyone who values Graphene's work will purchase one of their Motorola devices, whatever the cost Well the current Motorola Signature (2026) is 3 times the price of a Pixel. Not everyone can afford "whatever the cost". I hope Motorola will just get more and more phones to support GrapheneOS.
- Pfhortune 19d agoFeeling like my Pixel 9 Pro was the best timed hardware buy I've made in recent years. The 10 dropped the physical SIM slot and Google started with their device tree shenanigans that year, with little to no improvements in exchange. I've got 16GB of RAM and 512GB in an ecosystem that shows every sign of regressing in capacities due to component price inflation. Very interested to see what Motorola does next year, however.
- codethief 19d ago> The 10 dropped the physical SIM slot Not sure about the 10, but at least the 10 Pro still has one.
- MattTheRealOne 19d agoNot in the United States. Only the Fold still has a physical SIM slot.
- grapheneos 19d agoIt was removed from the whole non-folding Pixel 10 series in the US. It still has the SIM card slot elsewhere. We had to return a Pixel 10 bricked due to a firmware bug and it was the US model since we'd bought it in the US and sent it overseas with a forwarding service. Google's repair partner shop was quite confused about the lack of a SIM card slot to get the IMEI and we only had a serial number but they figured out using the serial number instead. There's still dual SIM support either way and you can store dozens of inactive eSIMs. The main downside of eSIMs is widespread lack of transfer support by carriers.
- Grombobulous 19d agoAfter switching providers with a recent phone with eSIM, I would say I’d never want to go back to physical SIMs ever again. They’re going to go away worldwide eventually, they’re just more easily removed in the US where the carriers are more bleeding edge on features and there are only 3 providers to think about in a very large homogenous market. The difference between waiting for a SIM card to arrive in the mail or traveling to a store, fiddling with a paperclip, tray, and impossibly tiny nano-SIM versus switching providers in 10 minutes via an app is night and day. Most SIM/dual SIM solutions also involve removing both SIM cards at once even to swap out one of two, and they tend to require device restarts. In the past I’ve also had network problems as a result of bad/damaged SIM cards.
- mentalgear 19d agoI wish ShiftPhone - which is fitting all my other needs - would offer a config that would work for GrapheneOS.
- palata 19d agoI just don't get why smaller OEMs don't seem to care about meeting Graphene's requirements. GrapheneOS has 500k users and growing, and most GrapheneOS users would be more than happy to leave the Pixels because of Google's bullshit.
- microtonal 18d agoBecause most of them don't really design their own phones, but instead sell what (mostly Chinese) ODMs give them with some small customizations. I don't know about ShiftPhone, but e.g. Volla just sells rebranded Daria and Gigaset phones, typically marked up by a few hundred Euros to sell some EU-made/privacy/degoogling dream. In reality they are just cheap phones that the ODM does not really care about with Linux kernel and firmware trees that haven't seen any (security) updates in years.
- palata 18d agoOh that makes sense. What about e.g. Fairphone?
- microtonal 18d agoMostly developed (both hardware and software) by their Chinese ODM T2Mobile. I think they probably have the sales volume where they could negotiate a compatible device with their ODM, but their priorities clearly lie elsewhere.
- grapheneos 18d agoT2Mobile is likely unable to meet our requirements. T2Mobile are not only designing the phone but even building/signing the firmware and device support code. Fairphone is putting together what they're given by Google (AOSP and GMS) and T2Mobile. Fairphone gets to make high level decisions among the choices T2Mobile is willing to offer. For example, their move to T2Mobile with the Fairphone 4 coincided with the removal of the 3.5mm audio jack.
- ahmadtbk 19d agoI'm guessing this is why the pixel 8-10 models have been in such high demand recently
- Cider9986 19d agohttps://discuss.grapheneos.org/d/41564-pixel-11-doesnt-meet-the-grapheneos-security-standards-and-may-be-skipped https://discuss.grapheneos.org/d/41564-pixel-11-doesnt-meet-...
- neilv 19d agoFediverse link: https://grapheneos.social/@GrapheneOS/117179231167297908 https://grapheneos.social/@GrapheneOS/117179231167297908
- CircuitSeuss 19d agoI have a pipe dream that Apple will pull a 180 and offer support for GrapheneOS.
- g-b-r 18d agoFor consistency, given all the phones GrapheneOS refused to support for not meeting their requirements, the Pixel 11 should not be supported, to my eyes. It does suck for those who already got one expecting GrapheneOS support
- grapheneos 18d agoPixel 11 does meet our past requirements and is more secure than the Pixel 6 and Pixel 7 which are still supported. Other devices don't meet the past requirements. We don't want to have an overall downgrade in security from the Pixel 8, Pixel 9 and Pixel 10. One approach would be using HWASan within the OS instead of MTE but the overhead is extreme and it only works for code instrumented with it.
- dennysora-main 18d agoWhen browsing through all the smartphone options, if you want something outside of Apple that gives you peace of mind, isn't bloated with strange apps, and takes security seriously, the Pixel is pretty much your only choice. Personally, I’d suggest avoiding Chinese smartphones as much as possible. Setting aside the cybersecurity risks for a moment, just look at how they cheat and manipulate benchmark scores—they will do whatever it takes just to look good on paper. Also, consider how phones in China can't use GMS (Google Mobile Services), so they build in countless "workaround" backdoors. Do you really think buying the global version makes it safe? As a software developer, let me tell you: we rarely maintain two completely different codebases for what is essentially the same OS. Those backdoors are still there—they're just disabled. That alone should set off alarm bells. If anyone is interested in diving deeper into the software issues behind Chinese phones, I can talk about that next time. Pixel’s raw performance is honestly terrible. But if you don't game, its day-to-day fluidity easily blows other brands—including Samsung—out of the water. It’s a phone you can actually use with peace of mind: practically no backdoors, near-stock Android, timely security updates, and an advanced OS. It really is the best option for daily use. That said, Google, I’m begging you: can you please take your hardware seriously? The current performance and overall state of Pixel phones are just embarrassing.
- ederhex 18d agoReasons I always bought pixels is because it's better to deal with one vendor bloat than two, the ease of installing OS-es like graphene (never had a bricked phone) and knowing that the hardware security is decent. Glad the people behind graphene are creating this discourse I probably would have ordered a new pixel because I was used to the reasons I give above. The moterola alternatives are noted thanks guys
- kangs 18d agoDisappointing news to say the least. this doesn't save that much space and power. Pixel series aren't the fastest- they're far behind. They're also not the cheapest, they're amongst the most expensive. The reason people still buy it is that they get a certain level of software quality and UX features, as well as security commitments that make Pixel and all of Android safer as it allows for fixing vulnerabilities quickly for everyone. MTE was one of these. When Google stops doing this, what's the point of buying a Pixel? I'm also not confident that Motorola will pick up the slack in practice.