Comment by ysnp
15 hours ago
Can someone from AOSP/Pixel hardware security shed some light? This is strange timing, especially when the approach has been validated by Apple also.
15 hours ago
Can someone from AOSP/Pixel hardware security shed some light? This is strange timing, especially when the approach has been validated by Apple also.
Probably just that Google doesn't use it so why pay for it? They're not obligated to support whatever GrapheneOS wants.
They do make limited use of it for Android Advanced Protection Mode (AAPM) introduced in Android 16. It no longer provides this upgrade for protection against exploits on the Pixel 11. They could substantially expand AAPM to using it across much more of the OS and could also start using it without AAPM since there's no significant downside to using it for most of the userspace code outside of the kernel.
It sounds like it was a failed experiment. Since it worked, it probably lost on a cost/benefit analysis. Which is fair enough.
4 replies →