Remix.run Logo
grapheneos a day ago

They do make limited use of it for Android Advanced Protection Mode (AAPM) introduced in Android 16. It no longer provides this upgrade for protection against exploits on the Pixel 11. They could substantially expand AAPM to using it across much more of the OS and could also start using it without AAPM since there's no significant downside to using it for most of the userspace code outside of the kernel.

inigyou a day ago | parent [-]

It sounds like it was a failed experiment. Since it worked, it probably lost on a cost/benefit analysis. Which is fair enough.

grapheneos a day ago | parent | next [-]

It wasn't a failed experiment. There was lack of serious investment in ever widely deploying it and then cost cutting by bean counters. Apple deployed MTE significantly after Google shipped it but Apple uses it in production for everyone. Apple developed very good integration of MTE into iOS and dealt with all of the issues it uncovered in order to ship it in production. Google has been entirely capable of doing that and also entirely capable of getting a better hardware implementation to reduce the overhead.

The nearly useless LED added to the back of the Pixel 11 likely costs significantly more than the extra die space for MTE support in the CPU cache. Google's LED feature is widely panned in reviews and will likely result in selling fewer devices than if they hadn't added it. They're also going to be widely panned for removing a very high impact security feature instead of making extensive use of it and improving it. It's a poor way to run a business. Pixel 11 has been poorly received in reviews and that was before people knew they downgraded security in a major way.

Google is marketing the Pixel 11 based on incrementing the version number for the security chip (with unclear improvements) and using post-quantum secure cryptography (ML-DSA) for verified boot. If they had followed through on open sourcing the firmware and hardware for the Titan M then we would already know in what way they improved it instead of finding out over time through people's reverse engineering efforts.

yaro330 14 hours ago | parent [-]

> The nearly useless LED added to the back of the Pixel 11 likely costs significantly more than the extra die space for MTE support in the CPU cache.

How is a bunch of LEDs more expensive than literal die space from TSMC? The chip is probably the most expensive part of the phone, a bunch of LEDs at a few cents per unit are infinitely cheaper than extra die space for a feature 99.99% of users won't use.

port11 a day ago | parent | prev [-]

Folks SWOTing everything in life like hubris ain’t a thing… all tech needs to be more secure, even more so as the asymmetry of attack and defence grows wider.

inigyou a day ago | parent [-]

You can't just say "we need security, this is security, therefore we must do it". That's the politician's fallacy. Did you know that preventing sideloading also improves security, but GrapheneOS is adamant that sideloading must be allowed?

grapheneos a day ago | parent [-]

> Did you know that preventing sideloading also improves security

Play Store is only the safest way to obtain apps solely distributed through the Play Store. It's safer to get other apps more directly from the developers considering how much malware there is on the Play Store. There are tons of apps impersonating other software on the Play Store. There are lots of useful open source apps for people focused on privacy and security not available through the Play Store too.