I think i’ve heard graphene-heads say the Pixels have some specific hardware features that make them more secure and is the reason graphene only works on them. Still i’m not gonna give google any money, i’d rather vote with my wallet and get an FP next
I don’t have a source (and am not who you replied to), but it could be that Google sells Pixels at a slight loss in an effort to get more people on the platform. Maybe not loss, in the traditional sense, but more so in that they build getting people into the Google ecosystem into the price.
For sure, and that’s where I thought they were going with it. But unless there is a source for how much it cost google to have the phone made, and how much they’re expecting to make back with users in their ecosystem, it’s just guess work.
I’d probably get a pixel for my next phone if this were the case, but I’d want to be sure.
An unlocked bootloader for a user that cares about physical security and privacy is a show-stopper. It basically gives up the keys to the kingdom, with a smile.
Yes, you can relock it. There is quite a bit of misinformation in this thread, I’m not sure why. As you can see from this chart, bootloader locking is available with iodéOS across multiple devices (including Fairphones), not just Pixels.
Unlocking the bootloader makes the entire system compromised - an adversary can install malware that persists through reboots or even factory resets, since the security regarding verified boot is disabled; they can decrypt the storage and read, copy it; it is relatively easy for a system to experience privilege escalation, and run admin commands - if the user is aware of it or not.
There’s a few other things, and some of it needs an additional step or two, but most things go from ‘impossible’ to ‘trivial’. And when you’re facing an adversary (be it a rootkit in an apk, law enforcement, or government agencies) that expect you to be knowledgeable about tech, they will take advantage of the potential holes users might make along the way.
Relocking the bootloader is incredibly rare on custom roms; I know of only one that supports it (gos). Every other rom I’ve ever used, so in the 50+ range, doesn’t worry about it. So usually the only way to relock is to revert to factory.
Pretty sure the Bootloader in unlockable (at least they were in the past?) and support(ed) mainline Linux kernel for an actual Linux mobile OS.
Idk, to me that sounds way better than staying on a google device.
The trouble is the bootloader is often not relockable with a custom avb key
The only OEM with official support for relocking the boot loader with a custom avb key is Google sadly
I think i’ve heard graphene-heads say the Pixels have some specific hardware features that make them more secure and is the reason graphene only works on them. Still i’m not gonna give google any money, i’d rather vote with my wallet and get an FP next
Buying a Google phone and then removing all the Google stuff actually costs Google money.
I wouldn’t be surprised if this were the case, but is there a source for this?
I don’t have a source (and am not who you replied to), but it could be that Google sells Pixels at a slight loss in an effort to get more people on the platform. Maybe not loss, in the traditional sense, but more so in that they build getting people into the Google ecosystem into the price.
For sure, and that’s where I thought they were going with it. But unless there is a source for how much it cost google to have the phone made, and how much they’re expecting to make back with users in their ecosystem, it’s just guess work.
I’d probably get a pixel for my next phone if this were the case, but I’d want to be sure.
An unlocked bootloader for a user that cares about physical security and privacy is a show-stopper. It basically gives up the keys to the kingdom, with a smile.
The ability to run true Linux is nice though.
E: word
Could you explain further please?
What is so bad about the unlocked bootloader? Can’t you relock it?
Yes, you can relock it. There is quite a bit of misinformation in this thread, I’m not sure why. As you can see from this chart, bootloader locking is available with iodéOS across multiple devices (including Fairphones), not just Pixels.
Yes, you can relock the bootloader, though only with official builds
https://doc.e.foundation/os/learn/bootloader-relocking#relocking
Unlocking the bootloader makes the entire system compromised - an adversary can install malware that persists through reboots or even factory resets, since the security regarding verified boot is disabled; they can decrypt the storage and read, copy it; it is relatively easy for a system to experience privilege escalation, and run admin commands - if the user is aware of it or not.
There’s a few other things, and some of it needs an additional step or two, but most things go from ‘impossible’ to ‘trivial’. And when you’re facing an adversary (be it a rootkit in an apk, law enforcement, or government agencies) that expect you to be knowledgeable about tech, they will take advantage of the potential holes users might make along the way.
Relocking the bootloader is incredibly rare on custom roms; I know of only one that supports it (gos). Every other rom I’ve ever used, so in the 50+ range, doesn’t worry about it. So usually the only way to relock is to revert to factory.
Thank you!
No problem :)