Conversation

There are quite some discussion around Android 13 bumping the anti-rollback protection on Pixel 6, and people are shitting on Google for this. Not sure how much I'm allowed to disclose so I'll just say this: this decision is not made lightly; it's done because it's necessary.
38
845
Replying to
You can only realistically get into this state if you unlock the bootloader. When you unlock the BL, you’ve voluntarily forfeit warranty (at least for software related issues like this one). I’m 100% sure that if your device bricked after a normal OTA, you’ll get a replacement.
2
5
Rollback protection is part of verified boot. It has existed for the SoC boot chain, secure element and the OS itself for many years. Pixels have used it for the OS and secure element for years. It wasn't used in practice for SoC boot chain due to being a development annoyance.
1
2
The firmware needs to have the updated version. We already use verified boot with rollback protection for the OS. It's different for OS because it's verified by last stage of SoC boot chain based on rollback indexes stored in secure element, which in practice are the patch level.
1
Show replies
Not everyone using an aftermarket OS wants to roll back the security model and disable security features. Proper verified boot is a small part of what we expect potential hardware partners to implement. It's not proper verified boot if firmware bypasses aren't fixed like this.
1
Show replies