← Back to context

Comment by inigyou

15 hours ago

Probably just that Google doesn't use it so why pay for it? They're not obligated to support whatever GrapheneOS wants.

They do make limited use of it for Android Advanced Protection Mode (AAPM) introduced in Android 16. It no longer provides this upgrade for protection against exploits on the Pixel 11. They could substantially expand AAPM to using it across much more of the OS and could also start using it without AAPM since there's no significant downside to using it for most of the userspace code outside of the kernel.

  • It sounds like it was a failed experiment. Since it worked, it probably lost on a cost/benefit analysis. Which is fair enough.

    • It wasn't a failed experiment. There was lack of serious investment in ever widely deploying it and then cost cutting by bean counters. Apple deployed MTE significantly after Google shipped it but Apple uses it in production for everyone. Apple developed very good integration of MTE into iOS and dealt with all of the issues it uncovered in order to ship it in production. Google has been entirely capable of doing that and also entirely capable of getting a better hardware implementation to reduce the overhead.

      The nearly useless LED added to the back of the Pixel 11 likely costs significantly more than the extra die space for MTE support in the CPU cache. Google's LED feature is widely panned in reviews and will likely result in selling fewer devices than if they hadn't added it. They're also going to be widely panned for removing a very high impact security feature instead of making extensive use of it and improving it. It's a poor way to run a business. Pixel 11 has been poorly received in reviews and that was before people knew they downgraded security in a major way.

      Google is marketing the Pixel 11 based on incrementing the version number for the security chip (with unclear improvements) and using post-quantum secure cryptography (ML-DSA) for verified boot. If they had followed through on open sourcing the firmware and hardware for the Titan M then we would already know in what way they improved it instead of finding out over time through people's reverse engineering efforts.

    • Folks SWOTing everything in life like hubris ain’t a thing… all tech needs to be more secure, even more so as the asymmetry of attack and defence grows wider.

      2 replies →