Comment by dnautics

21 hours ago

i dont get it, they are comparing eOS to graphene, not talking about the hardware.

this would be like grapheneOS not using pixel because the stock android that ships with it does not respect privacy.

am i missing something?

You still need to rely on the OEM to properly configure the bootloader, not leak the keys, and provide updated vendor blobs.

  • [flagged]

    • > I guess, my attack model for my personal phones doesn't really account for "my phone got stolen", I'm far more worried about impersonation and remote phone hijacking than needing to be safe from confiscation from feds.

      Even if you only care about "remote phone hijacking", not being able to provide timely vendor blob/drivers/kernel means you're wide open for EoP exploits.

      As for why they take such a hard line on physical security, well it's their project and they can have whatever high standards they want, especially if they want to project an image of being an absolute secure phone. The code's all open source so it's not too hard to port to another device, especially nowadays with AI.