I wonder how secure GrapheneOS is in that regard, and what the other contenders are?
I wonder how secure GrapheneOS is in that regard, and what the other contenders are?
(it's not magic. All big vendors have these details, just choose to take their sweet time to patch them. GOS has partnered with a major OEM vendor who provides them with access)
Other than the specific patches above, there's a list of generic GOS features: https://grapheneos.org/features#exploit-protection
All in all you're probably much safer.
Android's attack surface seems pretty jagged. For example there is only one webrender engine on iOS, where you can run anything you like on Android/GrapheneOS.
GrapheneOS really wants the software in the phone to not pwn the phone. This is good. Its a different, and much more difficult problem to secure the connection to the telco, and the larger internet, because the transport is attacker controlled.
Think of it this way: Say you use Qubes because security is valued very highly for you. Even if you run Qubes, if your router is controlled by your attacker, what kind of a security guarantee could you really get for yourself?
I do run Qubes, and a compromised router, e.g., will not get access to any passwords that I store in an offline VM as text, even with any previously known vulnerability since 2006.
In theory Pixel phones have IOMMU and GrapheneOS is using them, so even a compromised baseband doesn't result unrestricted access to the system.
A short list of the hardware security measures necessary to consider it "not a toy" ;) -- https://grapheneos.org/faq#future-devices
> If the hardware is an open book then no.
So you choose security through obscurity. I have no further questions.
QubesOS certainly has some good things going for it with isolation but the guest VMs which run traditional desktop OSes are generally much less secure than mobile OSes like Android OSes and iOS
Iirc it's not even possible to run QubesOS on hardware that has proper verified boot or non-meaningless secureboot.
With regards to security through obscurity, the Pixel firmware isn't obfuscated at all. It's closed source but it's easy to decompile the code and inspect it. They don't try to obfuscate it to make that difficult.
You cannot just say this without any links. Last escape from VT-d virtualization, which Qubes uses, was found in 2006 by the Qubes founder ("Blue Pill").
> Iirc it's not even possible to run QubesOS on hardware that has proper verified boot or non-meaningless secureboot.
You can run Qubes OS on something even better: Coreboot with Heads and with a hardware key. All based on FLOSS. Works for me.
> but the guest VMs which run traditional desktop OSes are generally much less secure than mobile OSes like Android OSes and iOS
First of all, you can in principle run any OS in Qubes VMs, including hardened ones. You can even disable the root account. Second, with such statement, you misinterpret the Qubes' approach to security. You isolate trusted workflows from untrusted ones, which gives you the strong security. You never open anything untrusted in trusted VMs, so their internal security plays no big role.
- dedicated, certified security coprocessor (Titan M2) - on pixel it's fused with verified boot, offers key storage, firmware isolation and anti rollback.
- verified boot: mandatory and backed by Titan, immutable boot from. Almost all laptops lack as much as anti rollback.
- strong hardware-backed key protection and actually isolated TEE. Yes, I know about Intel (SGX/TDX) and AMD (SEV/SME). Broken into many times over. How many commodity hardware devices offer comprehensive protections like Titan-backed TEE?
- secure hardware-backed disk encryption key derivation (with throttling of course)
- on-device attestation: complete verification of the entire chain. Dreaded Play Integrity or open AOSP / GrapheneOS hardware attestation. Which PC vendors can offer that? Perhaps Apple but that's not a pc and you won't run qubes on that?
- physical anti-tamper: which laptops wipe encryption keys stored in the secure hardware when you're trying to unlock the bootloader?
- physical memory tagging (see ARM MTE). Apple offers some but again, that's not for qubes. Intel promises MKTME in the future.
- does your laptop disable all the unconnected ports whilst the laptop is broken? Does your pin/password verification happen inside TEE/TPM, not in the OS?
- modes similar to PXN/SMEP, SMAP/PAN (to stop these pesky wifi/gpu firmware from reading userpace memory). There's some support for SMEP and SMAP on intel/amd
- microcode and firmware upgrades velocity
There are reasons GOS doesn't support any hardware other than pixels. Regrettably and thankfully that is about to change soon <3
Don't read me wrong, qubes is brilliant and on SOME hardware (business grade laptops with TPM 2.0, verified firmware upgrade process with some protections and proved track progress with rapid hardware drivers and firmware upgrades -- sure, brilliant choice. For pcs.
But is not even remotely close security-wise..
Best available would be probably Purism Libre (lacking TPM if I read it correctly, weak hardware but, oh well, pixel is not super fast either lol), or something with coreboot perhaps?
Whats the safest and still useful laptop hardware you cna think of? Let's compare with with pixel.
This does make a material difference, e.g.: https://x.com/MetroplexGOS/status/1982163802188575178
That said, if a state-level actor is up against you, then it's hard to defend yourself against that.