How does GrapheneOS defend against attacks on the cellular baseband, Wi-Fi baseband or other firmware / hardware?
reddit.com/r/GrapheneOS/c
By carefully choosing hardware targets since the OS is only part of what matters. OS mostly just needs to avoid screwing up IOMMU isolation.
Conversation
This Tweet was deleted by the Tweet author. Learn more
On past devices, it made some changes, but it isn't currently part of the downstream changes. It's an important area for research and improvements in GrapheneOS though. It's not desirable to end up maintaining security fixes downstream though but rather features with trade-offs.
