Pixel 11 doesn't yet meet the GrapheneOS security standards and may be skipped
- ID
- 31931
- Status
- summarized
- Published
- 05 Oct 2026, 9:02 PM
- Fetched
- 06 Oct 2026, 12:11 AM
- Provider
- Hacker News
- Category
- dev-community
- Original URL
- https://discuss.grapheneos.org/d/41564-pixel-11-doesnt-yet-meet-the-grapheneos-security-standards-and-may-be-skipped
- Source URL
- https://hnrss.org/best
Summary
- Score
- 6.0
- Created
- 06 Oct 2026, 12:24 AM
- Tags
- Audience
- developers
What happened
GrapheneOS says it has a partial port to the Pixel 11 after a week of work but cannot complete it because the device lacks ARM hardware memory tagging (MTE) support in software, firmware, and near certainly hardware, suggesting Google cut the feature to save money. GrapheneOS has used hardware MTE across its base OS, kernel, and hardened_malloc since the Pixel 8 launched with MTE in October 2023, while Android 16 Advanced Protection Mode enables it for only a few processes and Apple's iPhone 17 MIE is always on. GrapheneOS may skip the Pixel 11 if the security standard is not met; the Hacker News thread has 211 points and 115 comments.
Why it matters
If you ship Android apps to privacy/security-focused users, GrapheneOS's MTE approach can force MTE in standard allocators and auto-enable it for more apps with a per-app opt-out, so you should test for MTE-related crashes or performance issues and decide whether to opt in or document incompatibility. If you were considering a Pixel 11 for a hardened Android setup, the text says GrapheneOS may skip it, so wait for a completed port before buying. There is no explicit Malaysian or Southeast Asian angle in the text.
Discussion angle
Should Android developers opt into MTE for user-installed apps, and how do GrapheneOS's forced/auto-enabled MTE and per-app opt-out compare with Android 16 AAPM and Apple's always-on MIE for compatibility and security?