this post was submitted on 25 Aug 2026
1190 points (99.4% liked)
Technology
87598 readers
4165 users here now
This is a most excellent place for technology news and articles.
Our Rules
- Follow the lemmy.world rules.
- Only tech related news or articles.
- Be excellent to each other!
- Mod approved content bots can post up to 10 articles per day.
- Threads asking for personal tech support may be deleted.
- Politics threads may be removed.
- No memes allowed as posts, OK to post as comments.
- Only approved bots from the list below, this includes using AI responses and summaries. To ask if your bot can be added please contact a mod.
- Check for duplicates before posting, duplicates may be removed
- Accounts 7 days and younger will have their posts automatically removed.
Approved Bots
founded 3 years ago
MODERATORS
you are viewing a single comment's thread
view the rest of the comments
view the rest of the comments
That's all very nice but not many of us are willing to buy a $1000 phone (or an obsolete Pixel) to get Graphene. They soon won't be able to run it on new Pixels, and also the stuff about AOSP updates stops mattering since AOSP itself is nearly dead. The obsession with security chips (fighting the seized phone attack while comparatively ignoring much more relevant threats) is another misplaced priority. It's the old notion of "fence post security", putting a 100 foot fence post in the middle of the desert expecting the attacker to try to climb over it instead of going around it.^1^ Andd again, I'm amused at the idea of the US and Chinese governments allowing a Motorola (Lenovo) Graphene to be sold if it's really that secure.
We need a de-googled Android fork (maybe Lineage is that) on mass market phones using the hardware that those phones have. Otherwise we're acquiescing to the notion that Elon Musk deserves more privacy than Joe Schmoe when it should be the other way around.
^1^ hpmor.com chapter 115.
Pixel "a" series phones typically sell for under $500 and support GrapheneOS.
Source for this?
The obsession with security chips is what allows Pixels and iPhones to be the most secure devices on the planet. They have some of the most researched technologies being used here. You're literally just throwing it away based on...your link to a harry potter book? Seriously, look at the source you just shared. Its not even relevant ๐
What are they going to do, ban security chips like they tried to ban encryption in the 90s?
GrapheneOS and LineageOS are already degoogled.... LineageOS is extremely subpar when it comes to security since they dont enforce it onto their hardware. GrapheneOS actually enforces it and wont work unless it has those specific security features. LineageOS doesnt solve the problem you were concerned about in your post.
This is a start: https://grapheneos.social/@GrapheneOS/117140352254892456
I remember the govt trying to muscle Apple into unlocking someone's iphone, til they suddenly stopped because they found Cellebrite could unlock it instead. There have been several new iphone generations since then but I haven't heard about govt muscling anytime recently. So I have to infer they can still unlock iphones. As for Pixels, this is in Dutch but very recent: https://www.omroepbrabant.nl/nieuws/6023856/drievoudige-moord-in-oosterhout-telefoon-van-verdachte-gekraakt
Machine translation of main paragraphs:
So I think you're putting too much faith in this stuff. I will ask my crypto homies if they have any recent info about phone attacks though.
More relevantly, most secure devices AGAINST WHAT? You're talking about a locked phone attack which is the absolute least of most users' worries. The phone is so insecure in everyday use that the border patrol is near irrelevant. Plus users including paranoids like me don't have any opsec to speak of. When was the last time you crossed a border with an Android phone anyway? I don't think I've ever done that. Like most people I don't leave the country that often. Last time I did was before I switched to Android, IIRC. I might have had an analog or 2G flip phone or something. If I travel somewhere again it's not that big a deal to leave my Android phone at home, as I mentioned before.
Even in the border patrol picture, Graphene and TPM won't protect you from what used to be called rubber-hose cryptanalysis (xkcd.com/538). They're defending from the wrong threat.
Look, I understand the advantages of crypto hardware. I've programmed it and written simulators for it. But, the way to really keep cryptography in people's hands is to make it not require special hardware. Thus I'm skeptical that the government hates Graphene, but it really did hate PGP back in the day.
If I get to add new hardware to phones, TPM would be on my list but not at the top. First might be something like POCSAG (plus build out the pager network again) so you can receive text messages without transmitting anything or revealing your location. Second, third, etc. would be in a similar vein.
Your TPM concern here...
...is literally addressed in your post here:
They mention all the secure enclave type of stuff needed. They have the verified boot. They have the MTP. Its all there.
Were they using GrapheneOS?
Also, keep in mind that Cellebrite slides were leaked and they show that they arent able to tap into GrapheneOS on modern Pixel devices.
https://www.androidauthority.com/cellebrite-leak-google-pixel-grapheneos-security-platform
Until GrapheneOS breaks away from AOSP, which they have mentioned they could potentially do so once they have a solid hardware platform, we seem to at least be in a good place where even the DoJ is upset about people using GrapheneOS.
https://www.theguardian.com/us-news/2026/jul/23/cop-city-protester-phone