• TrollAccount69@lemmy.ml
      link
      fedilink
      English
      arrow-up
      1
      ·
      18 hours ago

      Maybe.

      I think graphene is so far removed from aosp in terms of goals and strategy that would be a pretty big commitment of resources.

      If you haven’t ever done upstreaming in an open source project, there’s a pretty big support commitment involved if the thing your work could be part of has insider scope than your own project.

      Which is pretty much the exact situation graphene is in.

      And if the graphene people are serious about security then giving aosp their (just my own hypothetical) emte enabled apps runs a good chance of providing a false sense of security to the users of those apps when not on graphene.

      This isn’t hypothetical btw, I had to dig through datasheets to prove that the old pixels don’t have emte to some random commenter a week or so ago even though just the most cursory understanding of arm mte versions and release schedules would make that obvious.

      The point isn’t to say people are stupid or that person was stupid, but that often people will assume the best even when it opens them up to a huge blind spot. One of the best security (and safety) practices is to make your secure component incompatible with insecure ones. That way it’s impossible for someone to point to the thick low awg nema 5-20 extension cord without acknowledging the cheater plug they used to get it into a two prong outlet with no wide neutral.