← Back to context

Comment by user2722

12 hours ago

Don't forget proprietary security patches are only open sourced 3 months after -- GOS has them due to their partnership with Motorola.

A sufficiently motivated threat actor will have them (the exploits) too.

GrapheneOS doesn't receive early access to security patches via Motorola. We receive those through a different partner. We were already doing security preview releases prior to Motorola giving us access to their repositories which don't contain those.

Unless you are using the most expensive flagship of a few Android brands, you are also vulnerable anyways

  • Pixels provide the same security features and updates for the budget 'a' series devices as the regular ones. Pixel 8a is one of the recommended devices for GrapheneOS since it still meets all the current era security standards and still has over 4.5 years of updates remaining despite being 3 generations old due to starting with 7 and launching after the initial set of 8th gen devices.

    Motorola will be working towards providing the same thing as part of our partnership with them, but we're starting out with the high end flagship devices due to those currently being required for it.

    • Interesting, I didn't know about that. Props to Google for bringing the security updates for the cheaper devices as well.