Comment by nosioptar

5 hours ago

I'm not about to trust a google branded device. Even if the Graphene folks are on the up and up, google sure as hell isn't.

That's not based in reality. Why would Google have a hardware backdoor when 99.9% of their users run their software giving them the data they want.

Google Pixels have no evidence of a hardware backdoor when a desktop is proven to be much less secure against remote and local exploitation.

It has been shown through leaks that Pixels running GrapheneOS are the most secure against Cellebrite in AFU. GrapheneOS was the first to implement a reboot timer feature which brings the device to BFU (much more secure) and then Android and iOS copied it (with longer, non-customizable duration).

You can inspect network traffic to see that GrapheneOS phones only connect to GrapheneOS-run services.

Here's a team member's thoughts: https://discuss.grapheneos.org/d/10150-not-your-average-why-...

  • But GrapheneOS relies on a proprietary, black-box security chip from Google... who pinky-promised to open-source it but never did, and that just doesn't sit well with me.

    I think it's entirely possible that a compromised Titan module (whether such code ships with the device or is updated at a later point) could leak keys via some covert method, and possibly transmit via the baseband or through some other application/method where the OS is not really aware of what's going on.

    • The government only gets to use this once, and they probably won't use it on you.