The SoC appears to be a 7% CPU/GPU perf bump according to Qualcomm. No info on North American compatibility yet.

  • Midnight Wolf@lemmy.world
    link
    fedilink
    English
    arrow-up
    6
    arrow-down
    1
    ·
    4 days ago

    An unlocked bootloader for a user that cares about physical security and privacy is a show-stopper. It basically gives up the keys to the kingdom, with a smile.

    The ability to run true Linux is nice though.

    E: word

    • smiletolerantly@awful.systems
      link
      fedilink
      English
      arrow-up
      5
      ·
      3 days ago

      Not really… At least not generally. The privacy increase from switching from Android to proper Linux is, to me at least, more important than loosing a locked bootloader.

      That’s just my threat model. I know that Google & Co are extracting as much info about me as humanly possible, and I have no reason to believe that I am being targeted by someone with the capability to exploit the unlocked bootloader.

      Same for my PC btw - secure boot is disabled because it’s not worth the hassle. Again. In my threat model.

      (But I would wager that this goes for a lot of users.)

    • bananabread@lemmy.zip
      link
      fedilink
      English
      arrow-up
      2
      ·
      4 days ago

      Could you explain further please?

      What is so bad about the unlocked bootloader? Can’t you relock it?

      • Midnight Wolf@lemmy.world
        link
        fedilink
        English
        arrow-up
        9
        arrow-down
        1
        ·
        4 days ago

        Unlocking the bootloader makes the entire system compromised - an adversary can install malware that persists through reboots or even factory resets, since the security regarding verified boot is disabled; they can decrypt the storage and read, copy it; it is relatively easy for a system to experience privilege escalation, and run admin commands - if the user is aware of it or not.

        There’s a few other things, and some of it needs an additional step or two, but most things go from ‘impossible’ to ‘trivial’. And when you’re facing an adversary (be it a rootkit in an apk, law enforcement, or government agencies) that expect you to be knowledgeable about tech, they will take advantage of the potential holes users might make along the way.

        Relocking the bootloader is incredibly rare on custom roms; I know of only one that supports it (gos). Every other rom I’ve ever used, so in the 50+ range, doesn’t worry about it. So usually the only way to relock is to revert to factory.

            • Turret3857@infosec.pub
              link
              fedilink
              English
              arrow-up
              3
              ·
              4 days ago

              Yeah CalyxOS just came back from a hiatus due to some internal drama, and iodéOS is a French based ROM that is based on LineageOS.

              CalyxOS has made some pretty nice QoL changes in the last few years that I really appreciate (Seedvault backups, Per-app, per connection type firewalling, Work profile ootb, VPN sharing over all profiles)

              iodeOS offers bootloader relocking on devices that support it, and they support devices longer than Calyx & Graphene for Eco. sustainability, but you do still run the risk of the proprietary hardware drivers having vulnerabilities. I tried it out for a bit but it wasnt for me.

      • Ilandar@lemmy.today
        link
        fedilink
        English
        arrow-up
        3
        ·
        4 days ago

        Yes, you can relock it. There is quite a bit of misinformation in this thread, I’m not sure why. As you can see from this chart, bootloader locking is available with iodéOS across multiple devices (including Fairphones), not just Pixels.