Pixel 11 doesn't yet meet the GrapheneOS security standards and may be skipped

Pixel 11 doesn’t yet meet the GrapheneOS security standards and may be skipped

Pixel 11 尚未达到 GrapheneOS 的安全标准,可能会被放弃支持

We have a partial port of GrapheneOS to the Pixel 11 series after a week of work on it. We’re unable to complete the port due to lack of support for ARM hardware memory tagging in software, firmware and potentially hardware. It appears Google cut an important security feature to save money.

经过一周的工作,我们已经完成了 GrapheneOS 对 Pixel 11 系列的部分移植。但由于软件、固件以及可能在硬件层面缺乏对 ARM 硬件内存标记(MTE)的支持,我们无法完成移植。谷歌似乎为了节省成本砍掉了一项重要的安全功能。

ARM hardware memory tagging (MTE) is used by GrapheneOS across the entire base OS including the kernel and every standard base OS process. It’s only temporarily disabled for a few device-specific processes. It greatly improves protection against nearly all remote exploits and many local exploits.

GrapheneOS 在整个基础操作系统(包括内核和每个标准基础系统进程)中都使用了 ARM 硬件内存标记(MTE)。它仅在少数特定于设备的进程中被暂时禁用。这极大地增强了对几乎所有远程漏洞和许多本地漏洞的防护能力。

Pixel 8 launched with hardware MTE support in October 2023. We integrated it into our hardened_malloc project and began using it across the OS later that month. Android and the Pixel OS never started using it by default. Android Advanced Protection Mode in Android 16 enables it for a few processes.

Pixel 8 于 2023 年 10 月发布时便支持硬件 MTE。我们在当月晚些时候将其集成到我们的 hardened_malloc 项目中,并开始在整个操作系统中使用它。而 Android 和 Pixel OS 从未默认启用该功能。Android 16 中的“高级保护模式”仅为少数进程启用了它。

Apple’s Memory Integrity Enforcement (MIE) is an always enabled feature on the iPhone 17. It’s simply a high quality implementation of MTE using the latest standard extensions. It uses MTE in the most secure mode in the kernel and a large portion of userbase. They did a very good job integrating it.

苹果的内存完整性强制执行(MIE)是 iPhone 17 上的一项常驻功能。它本质上是使用最新标准扩展对 MTE 的高质量实现。它在内核和大部分用户空间中以最安全模式使用 MTE。他们在集成方面做得非常出色。

Apple’s MIE and Android 16+ AAPM don’t use MTE for user installed apps unless those explicitly opt in. GrapheneOS enables it for more apps automatically and has a toggle for users to opt-in for every user installed app. There’s a per-app toggle to opt-out for incompatible apps which is uncommon.

苹果的 MIE 和 Android 16+ 的高级保护模式(AAPM)除非用户明确选择,否则不会为用户安装的应用程序使用 MTE。GrapheneOS 则会自动为更多应用启用它,并提供开关供用户为每个已安装的应用手动开启。此外,它还提供针对不兼容应用的单应用禁用开关,这在业界并不常见。

Neither iOS or Android encourage app developers to opt into MTE and other more aggressive security features used in the base OS. Apple’s docs warn developers of performance and stability issues. Our approach enables forcing using MTE in the standard allocators regardless.

iOS 和 Android 都没有鼓励应用开发者选择使用 MTE 以及基础操作系统中使用的其他更激进的安全功能。苹果的文档甚至警告开发者注意性能和稳定性问题。而我们的方法则是强制在标准分配器中使用 MTE,无论如何。

Pixel 11 does have security improvements including moving to post-quantum secure verified boot (ML-DSA) and replacing Samsung Shannon IMS with AOSP IMS. Titan M3 should significantly improve protection against data extraction in Before First Unlock state. It’s too bad they ruined it by cutting MTE.

Pixel 11 确实有一些安全改进,包括转向后量子安全验证启动(ML-DSA),并将三星 Shannon IMS 替换为 AOSP IMS。Titan M3 芯片应该能显著增强在“首次解锁前”(BFU)状态下对数据提取的防护。可惜的是,他们砍掉 MTE 的做法毁了一切。

Pixel 11 series is a lot more expensive for an incremental improvement to the CPU, the same underpowered GPU and reduced RAM for the Pro base models. They finally caught up to the last generation of Qualcomm cellular radio. It’s overpriced, the upgrades aren’t impressive and losing MTE is appalling.

Pixel 11 系列价格昂贵,但 CPU 仅有小幅提升,GPU 依然性能不足,Pro 基础型号的内存甚至有所减少。他们终于赶上了上一代高通蜂窝基带的水平。这款手机定价过高,升级乏善可陈,而失去 MTE 更是令人震惊。

Compared to the Pixel 11, a Snapdragon 8 Elite Gen 5 has ~40% higher single threaded CPU performance, ~80% higher multi threaded performance, over 100% higher GPU performance and a far better cellular radio. It also finally has MTE. The next gen is what will be in the first Motorola with GrapheneOS.

与 Pixel 11 相比,骁龙 8 Elite Gen 5 的单线程 CPU 性能高出约 40%,多线程性能高出约 80%,GPU 性能高出 100% 以上,且拥有更好的蜂窝基带。它最终也支持了 MTE。下一代产品将出现在首款搭载 GrapheneOS 的摩托罗拉手机中。

Pixel 9a and earlier (including Nexus devices) were the Android Open Source Project reference devices. Pixel support was removed from AOSP with Android 16. It’s now harder to support Pixels than many other devices and massive progress towards open source firmware and driver libraries was discarded.

Pixel 9a 及更早机型(包括 Nexus 设备)曾是 Android 开源项目(AOSP)的参考设备。从 Android 16 开始,Pixel 的支持已从 AOSP 中移除。现在支持 Pixel 比支持其他许多设备更困难,且在开源固件和驱动库方面取得的巨大进展也被抛弃了。

Compared to the stock Pixel OS, GrapheneOS ships AOSP patches months earlier and Linux kernel patches many months earlier. However, we rely on them for firmware and most driver updates. We also want to move to new kernel branches earlier. These things can be improved with our Motorola partnership.

与原生 Pixel OS 相比,GrapheneOS 发布 AOSP 补丁的时间早几个月,发布 Linux 内核补丁的时间则早许多个月。然而,我们仍依赖谷歌提供固件和大部分驱动更新。我们也希望更早地迁移到新的内核分支。通过我们与摩托罗拉的合作,这些问题有望得到改善。

We strongly recommend against buying Pixel 11 devices. Pixel 8, 9 and 10 have much better overall security for GrapheneOS. Pixel 10 is cheaper with similar hardware and MTE. Pixel 11’s Titan M3 should improve BFU security for users without a strong passphrase, but losing MTE craters AFU security.

我们强烈建议不要购买 Pixel 11 设备。对于 GrapheneOS 而言,Pixel 8、9 和 10 的整体安全性要好得多。Pixel 10 更便宜,且拥有相似的硬件和 MTE 支持。Pixel 11 的 Titan M3 虽然能为没有强密码的用户改善 BFU(首次解锁前)安全性,但失去 MTE 会严重削弱 AFU(首次解锁后)的安全性。

We haven’t determined what to do about this situation. It may be best for us to skip the Pixel 11 series devices. We can shift our focus entirely to the upcoming Motorola devices instead. Pixel 10a was really a 9th gen Pixel, so hopefully the Pixel 11a does the same with 10th gen and includes MTE.

我们尚未决定如何处理这种情况。也许最好的办法是放弃 Pixel 11 系列设备。我们可以将重心完全转移到即将推出的摩托罗拉设备上。Pixel 10a 实际上是第九代 Pixel,所以希望 Pixel 11a 能延续这一做法,采用第十代架构并包含 MTE。