Conversation

Replying to
You can only realistically get into this state if you unlock the bootloader. When you unlock the BL, you’ve voluntarily forfeit warranty (at least for software related issues like this one). I’m 100% sure that if your device bricked after a normal OTA, you’ll get a replacement.
2
5
Rollback protection is part of verified boot. It has existed for the SoC boot chain, secure element and the OS itself for many years. Pixels have used it for the OS and secure element for years. It wasn't used in practice for SoC boot chain due to being a development annoyance.
1
2
An important security feature not being fully implemented due to it being a development annoyance is problematic. GrapheneOS is an aftermarket OS focused on Pixels and we wanted this feature to start being used properly and complained about it not being done on the past devices.
2
1
Not everyone using an aftermarket OS wants to roll back the security model and disable security features. Proper verified boot is a small part of what we expect potential hardware partners to implement. It's not proper verified boot if firmware bypasses aren't fixed like this.
1
You're welcome to use something other than GrapheneOS if you don't want the standard security model and hardware-based security features intact. Rollback protection is a basic security feature and has already been used for years, just not for the early SoC boot chain in practice.
2
Pixels were in theory supposed to be doing this already but were not doing it in practice due to the conflict between them being secure devices and being development devices where someone might want to flash an obsolete, insecure OS version to test app compatibility with it, etc.
2
On our own hardware, we'll also get to decide when we move to a new major OS version. On existing hardware, when a device moves to a new major OS version, we have to move to the new major OS version to continue providing basic privacy and security updates for the firmware, etc.
1
1
That's true regardless of whether there's anti-rollback protection for the boot chain firmware. On August 15th, Android 13 was released for Pixels. There was no August release for Android 12.1. The maximum obtainable patch level on Android 12.1 is 2022-08-01. We have to upgrade.
2
1
Show replies