Conversation

How long after the Vax was discontinued by DEC did OpenBSD continue to support it? I lost track of the years/decades.
Quote Tweet
Extended support releases are not considered official GrapheneOS releases. These devices are no longer secure and don't meet our requirements anymore. It's a very low priority and we're not going to be investing significant resources. It'll probably end when we add new devices.
Show this thread
2
3
Replying to
No matter how much time and money we direct to supporting these devices, we'll still need to strongly recommend against using them. If Pixel 2 or Pixel 2 XL users contributed to development, they could be supported for longer. Either way, people should move to a secure device.
2
3
Pixel 2 and Pixel 2 XL don't have maintainers so I've been doing all of the work myself despite having tons of other work to do. It's unreasonable to expect 1 person to do everything for you. If people wanted these devices to be supported longer, they would contribute to that.
2
1
They could be supported this way for a long time but we'll need to delist them and more strongly discourage using them. Can take away time from other things to do these updates but there are diminishing returns. A million dollars wouldn't get them to the 2020-11-05 patch level.
1
1
Replying to
In the long term we're not going to be targeting Pixel devices anyway. It's what makes the most sense right now. We don't have a hardware partner able to produce something better. If there was something better, we'd use that instead of using Pixels.
2
1
Qualcomm supports their SoC for 3 years (soon 4) so that's the inherent limitation with a Qualcomm SoC device. Maybe that will be longer by the time we're in a position to do that. For now, it doesn't get any better. There are more important considerations than this one too.
2
1
For it to make sense to be targeting more specialized hardware, it needs to be better. Needs comparable hardware exploit mitigations, IOMMU isolation, radio security, secure element (with insider attack protection, Weaver, StrongBox, verified boot integration, etc.), encryption
2
1