84 comments

[ 0.20 ms ] story [ 92.7 ms ] thread
The upcoming Signature 27 which will be announced today and has been teased by Motorola on their socials and websites will have a likelihood of a US release because they've posted about it on US social accounts. It looks interesting...

The 2026 Signature, in the UK, was $1460 USD. In Brazil it is selling for $1230. The Pixel 11 pro XL, which the Signature beats on hardware in practically every way sells for $1300 on their website.

That’s not saying much. The selling point of pixels has always been the software.
What do you mean? It's stock Android. Other manufacturers are putting much more effort into UX in my opinion. Do you mean something else?
And here I am with my 26 Signature, still on Android 16 with Patch Level from January and the phone reporting happily, Looking Good! Everything up to date!

Get your update process working @Motorola!

Nevermind. I just need to remove my SIM card and use a VPN to Spain to get updates. wtf
Current street prices in Austria:

~750€ for the Motorola Signature, with 512 GB storage

~900€ for the Pixel 10 Pro XL, with 256 GB storage (the 11 Pro XL costs much more at ~1200€, since it just came out a month ago)

[delayed]
the thought of having a phone, which i touch all day, set on many surfaces, put in my pockets etc having a fabric enclosure is so gross to me. did they just forget that people use their phones on the toilet? or while they eat messy food? that gold/tan model is bound to look like a busy parent of 4's minivan interior within a month.
I don't think it's actually fabric. It's a "fabric-like polymer coating".
Might someone know whether banking apps worldwide will work?
Probably not, because of Google attestation, the cancer of Android.
My banks (in Europe) work fine. The primary thing that is missing is tap-to-pay because Google is abusing its monopoly position and not letting GrapheneOS pass remote attestation. There are some apps that have their own tap-to-pay, such as Curve in most of Europe and PayPal in Germany, but they don't work great everywhere (e.g. where I live, all payment terminals accept tap-to-pay based on debit cards, but more than 50% does not accept credit card-based tap-to-pay, so something like Curve or Garmin Pay doesn't work in many stores).

At any rate, there is a well-maintained list here: https://privsec.dev/posts/android/banking-applications-compa...

I didn't notice anything suggesting that Curve is "credit card-based" (from what I remember it was advertising debit in EMV). Curve worked for me everywhere in Poland, Czechia, Germany, Austria, Romania and Sweden.
Curve currently works great for me but I am hoping Walt will launch soon.

https://walt.is/

Deceptive marketing about privacy but it can't be worse than the other options.
Amongst the several banks I deal with, only one uses Google's attestation framework in a way that blocks GrapheneOS.

That said, the website still works fine for that one.

This site tracks the status of what apps work: https://privsec.dev/posts/android/banking-applications-compa...

The official GrapheneOS docs contains a developer guide on how to fix banking apps when they are not working. Bank app developers have been surprisingly receptive to making the changes, weirdly enough. You can see in some of the issues tracked on the site where people reached out and the developers eventually made the apps work.

I've been running GrapheneOS for a while (I have posts on the blog in my bio if you want to see some day-to-day info) and only one bank app gave me trouble. I had to toggle a setting and then everything worked.

Separate from this is wallet and payment apps which still have not had much traction on GrapheneOS.

Heh. USA user here. Several of the apps that say they work I have been unable to get to work.

So anyone reading this, be aware your experience may differ.

I'm on a pixel 10 pro and have never been able to get some of banking apps to work, despite the list saying they should.

It is likely a crapshoot, and while that list is informative it is necessarily a snapshot in time. FWIW, my banking apps have worked with no issues and have worked continuously since I migrated to GrapheneOS. I do have Play Services installed to be able to use Android Auto, and that required some fiddling with permissions before it started working, so your mileage may vary. By far the biggest annoyance for me is group text messages not being delivered while using an alternative user account, but that's a niche setup I guess.
I was also surprised by the banking app experience. After making me verify my identity about 10 times to prove I'm me and not a hacker, they finally let me use it...

I've heard some people had good results by going to their bank branch and demanding them to unblock their phone or they'll close their account. Apparently they have a checkbox to disable phone attestation requirements for a customer.

> Bank app developers have been surprisingly receptive to making the changes, weirdly enough

That's only weird if you live in a perpetual state of doomerism, or have bene influenced by those who are (youtube influencers, mostly)

Of course there was a simple explanation for banking apps not working the whole time. It's the doomers who turned it into a vast conspiracy with an all-powerful megacorp at the center.

I imagine that banking apps will begin to have better support for GrapheneOS as it rises in popularity.
Two clarifications:

- This is about preinstallation. For the planned models, you can install GrapheneOS yourself. This should be really simple, if it is similar to the current installation process for Pixels, which can be fully completed through their website.

- The preinstalled devices don't seem from Motorola themselves, as mentioned later in the thread: Probably not via their website but rather another company provided with the devices directly by Motorola. It could be us doing it ourselves but we aren't set up to deal with it.

Really excited for the Motorola GrapheneOS phones! (Currently have a P10P with GrapheneOS.)

I am not too sure about this. There is no company I trust to sell GrapheneOS-preinstalled phones other than GrapheneOS themselves.
We are going to be reinstalling GrapheneOS on the phones shipping with it.
You can verify the installation integrity via android attestation, which grapheneos uses
GrapheneOS is installed with their keys which you can verify, right?
I'd love to see the GrapheneOS team gaining enough resources to hire developers who can work to increase the number of supported devices. The more devices that are supported (even if security is not at the same level as Pixel/Motorola hardware), as the more popular GrapheneOS becomes, the harder it will be for governments to target it.
My understanding is that the problem is not on GrapheneOS' side. We need more manufacturers to care and build devices that meet GrapheneOS' requirements.

My hope is that Motorola will be very successful with that. GrapheneOS currently has half a million users and growing. The more users it gets, the more interesting it is for manufacturers to actually consider it.

Google being Google, if Motorola gets a relatively cheap phone to run GrapheneOS (the flagship is quite expensive IMHO), I think people will flock away from Pixels (I definitely will, and I will tell everyone and their dog that they should when they renew their phone).

> GrapheneOS currently has half a million users and growing

That is a total install base right? Unless all 500k of them are upgrading yearly, this number is miniscule. You are underestimating the R&D required to put out a new phone each year only to have 30% (high estimate) of users buying it. That's 150k devices, which is not worth any volume.

For a smaller manufacturer (e.g. Fairphone), that may mean a lot. If I remember correctly in 2021 Fairphone was selling 100k phones per year?

Also I am genuinely interested: is it that hard to meet GrapheneOS' requirements? Feels like it shouldn't take years of R&D for every new iteration. And also that it's about getting the right deals with the suppliers, which is not really an R&D issue?

Hardware-wise it seems to be doable now that more and more CPUs have MTE. (And secure processors exist, most OEMs outside Google/Samsung are just too cheap to add them.)

What does add ongoing cost is doing monthly driver/firmware/kernel/etc. updates. But IMO they should be required by law. Just doing the minimal ASB patching is not keeping your users secure.

It’s selling an additional 150k flagship devices. They are selling the Signature line with Google-certified Android by default and those 150k would buy a Pixel to run GrapheneOS otherwise. For smaller OEMs, selling 150k flagships extra yearly is a pretty sizable increase.

Also, the GrapheneOS user base is really growing rapidly, plus I’ve seen quite some people who want to run GrapheneOS, but don’t want to give money to Google, so they might switch when there is a Motorola alternative.

Outside raw user numbers, I think there may be other motivations for Motorola. First, the way they pitched it, the seem to want to position Motorola + GrapheneOS as a secure alternative for business users (so, they may bring in new users themselves). Plus there may be strategic reasons for them to do that. Google has been tightening the grip on Android. Supporting GrapheneOS as an alternative could also be a message to Google - we have an alternative if you tighten the grip too much. Kinda similar to how Samsung has their own App Store, etc. as a message to Google.

> For smaller OEMs, selling 150k flagships extra yearly is a pretty sizable increase.

It is but the cost of making that phone is nearly the same for Samsung and Motorola. You're discounting the fixed costs here.

If it takes $10M to produce a phone, the numbers need to make sense before it makes profit. And you need to have deep pockets to keep doing it until it becomes good.

So yes, 150k in first year might be red, but you must be willing to put up another $10M next year and another .. to slowly get to say $500k in year 5 before it turns profitable. Will Motorola have that appetite? maybe not.

Define cheaply.

Sub 200 is immediately off the table but a refurbished pixel last time I checked was about $400 post tax. They have long (7 years now) support windows now which is also a bonus.

Pixel A series are often under 400 here new.
Refurbished Pixel 7 pro (EOL next year) or Pixel 8 (EOL 2030) is £200-240 here.
Will this solve the issue of Google withholding Android security updates to provide Pixel devices running stock early access to patches?
I wish they will bring a €200 device with GrapheneOS out
Unfortunately the privacy/security features GrapheneOS requires as well as just the ability to replace the OS are only put on premium phones. You can buy an a series Pixel a few years behind to get it in the price point you want. But this won't save money long term because the price per year of support is worse than newer models like the 10a or 9a.

So, 7a at your pricepoint:

https://www.ebay.com/itm/820099695470

But, it's only supported for 1.6 more years.

So that puts it at $143 per year of support. While the 10a [1] will be supported for 6.4 more years, which puts it at $55 per year of support.

[1] https://www.ebay.com/itm/137767347717

Although if you just want a degoogled phone with some features and don't want to hide a criminal enterprise, I doubt an out-of-support Graphene phone is any worse than an out-of-support Huawei or Xiaomi or Realme or Motorola phone.
It wouldn't be worse than those but with AI, AOSP is patching way more vulnerabilities than before and people without technical skill can abuse vulnerabilities, and those with skill can abuse them even more. It simply is not wise to run out-of-date GrapheneOS.

I'm curious how many months/years before out-of-date GrapheneOS becomes the worse option security wise compared to various brands' stock Androids. Obviously it is nuanced and there's no clean answer but it would be interesting on average.

We could think of metrics in public patches, but GrapheneOS has exploit protections that prevent against 0-days which would be hard to factor in.

£200-ish for Pixel 8, 4 more years of support.
Even if they do sell graphene(android) devices there is still a good chance that it wont be enough to keep a full function linux phone off the market. I would sooner buy a trump phone then graphene, it's not as pretentious and it's more shiny.
Will you put a Linux phone on the market?
not linux, but I do have a WHOLE other idea for secure coms/data/financial devices but untill our late stage capitalist sceurity industrial theater complex realy starts to collapse in on itself, I'll stick to yelling at the most egrigious absurditys and try and further understand what were the factors that created the most decent and stable civilisations in our past.
> buy a trump phone then graphene

Did you mean "than"?

I love Linux (been using it as my daily desktop for decades), but we're a long ways off from a true Linux phone.

not true, there are several european projects that are delivering daily driver linux phones the real issue is to subvert the hiarhical security theater and fantasist mindset that is pushing the world into a seething techno fuedal shit show and start building user centric software and hardware for everything. graphene is the worst possible response in that it is only offering membership into an elete fiefdom, and the obscenity of paying for freedom©®™*

* terms and conditions most definitly apply and will change on the sole discretion of freedom©®™ inc.

>Probably not via their website but rather another company provided with the devices directly by Motorola. It could be us doing it ourselves but we aren't set up to deal with it.

I presume this bit is because Motorola can't sell devices with android builds that aren't certified by google (as per Google Mobile Services contracts)

nice

now give me a device with a mechanical switch that gaps the radio power physically

I'm only buying it if it comes with a secure raccoon feeder.
pinephone has this but it never really became a thing

Librem too

Good. Though i hope i'll see GOS for the P11A (expecting it will come out) so i can upgrade my 8A.

i really like the pixels, and haven't been fond of motorolas in recent years

The Pixel 11s have been a decent downgrade from the 10s. You might want to consider getting a 10 or 10a while they're still cheap.
Devices are sold with GrapheneOS preinstalled, just not by GrapheneOS. If your paranoia needs aren't high but you just want to get away from Google, it seems like a good idea.
Will the pre-installed GrapheneOS phones still show up as "rooted" to things like Microsoft Authenticator?
Depends how they implement their check, but if they do it correctly it would show the bootloader as locked and detect no su binary (no root).

If they use Google SafetyNet to basically block everything non-Google-certified™ then no.

Are there any GrapheneOS-capable devices that still have an SD card slot and a 3.5mm port? Bonus points if the battery is removable.

I will also accept "Sending my consciousness back to my 2016 body." Better yet, 1996. Got some things I wanna fix.

Since as of right now they only support Pixels, no. Who knows what the Motorola phone will have, though.
To whom it may concern, I want $100 grapheneos phone.
The DDR ram costs more than the phone now. Wish I was joking. =3
Pretty much, but you would be surprised at just how low some of these phone RAM setups can go.

I had a low end Oppo 'something', I remember the RAM had a 16bit data bus, the whole thing had a peak theoretical bandwidth at just over 4GB/sec. That phone sauntered through the workload at the best of times. The Mediatek chip was probably not the weaklink for once.

On the upside the battery could go well over a week between charges.

Would corporate BYOD and bank apps work, though?
I changed bank because they stopped supporting GrapheneOS for bullshit reasons (they support my completely unsecure and outdated /e/OS but not GrapheneOS, and they call that "security").

The only way a bank cares is if enough users complain and leave for another bank. Banks (like all companies, but especially banks) care about money and nothing else.

What I care about is banking app support. Both my credit unions (large, national ones) lock down their phones apps so they do not work on GrapheneOS. Yes, you can install certain Google packages to change that, but no guarantee that will work in the future.
Hoping GrapheneOS makes it onto the Motorola Razor (Ultra) soon.
The problem with those free OS is that they usually work on top models which cost like 4 ordinary smartphones. It is experimental software that doesn't work perfectly, and it makes no sense to pay that much for it. So with high prices they are push away potential users.

Also, I would like no DRM, no serial id, no support for device verification, no trusted environments, re-programmable IMEI, no locked bootloaders, no proprietary code and no telemetry in any form or shape.

This android distribution is very suspicious because of a lot of bad architectural decisions (that is one of them) and their famous refusal to disclose funding sources which go beyond common logic for open source projects.

There are other Android distributions that run on practically any Android phone you have, look for LineageOS. Even your phone is not explicitly listed as supported, using Claude is easy nowadays to adjust the distro to run on your phone perfectly.

[delayed]
Excuses. None of that is a reason to force users into high-profile hardware that is not audited and makes anyone buying them an automatic Person Of Interest.

Furthermore, sound cryptography isn't dependending on specific hardware to function, with that kind of reasoning we'd never get encrypted communications anywhere. So stop inventing excuses and for once in life look deep into how they are financed, which apparently is OK to be as opaque as possible as to whom is paying them so much money.

GrapheneOS is not a cryptography project, like a secure messenger would be. It's goal is practical security, which does depend on practical considerations: without MTE, similar memory security would cost an unreasonable performance penalty, without TPM conventional authentication methods like PIN-code and fingerprint would be vulnerable to bruteforce, without secure boot users would not be able to verify if their phone was physically tampered with in a brief window they were away from it... And if you have closed-source radio chips running their own untrusted software loaded over the air, integrated in such a way they can independently wiretap you, like most phones have, you'd already failed at protecting the user before you start.

Furthermore, Android's ecosystem is structured in a way even the most basic software security concerns, like not running a comically out of date kernel, depend on the vendor's blessing, and sadly most manufacturers, including very desirable ones like Fairphone, hadn't been keeping up with such duties. Porting new kernels to old hardware is an extremely inefficient time-consuming endeavor that will take up most of volunteer time to non-satisfactory results; I can testify to that as a former member of the Ubuntu Touch project, and our standards of security were comically lax.

Again, you CAN lower your standards of security and go for the lesser evil: many people run Lineage or Ubuntu Touch despite known gaps in their security models. But to make that choice, you have to be honest about what you're compromising. If you shut your eyes and plug your ears pretending everything is fine, you'll end up with someone killed because they listened to your uncritical advise.

Also, I struggle to see how it's GrapheneOS's fault choosing the most secure hardware on the consumer market because it might be deemed suspicious to own it. GOS could have chosen the most popular budget Samsung (ignoring the aforementioned security issues) and it would have the same effect. Besides Pixels aren't an obscure unusual hackerphone made in small quantities, shipped from out of the country; it's among the most popular phone brands, advertised from huge billboards I pass on my bus route to university. If they chose something like the PinePhone like Genode, this point would be somewhat defensible.

Finally, what's up with the repeated conspiratorial insinuations about financing? I admit I hadn't looked deeply into this question, even as a one-time small donor, but what are you expecting to find? Is it serious concern about the financial health of a project, or an attempt to manufacture a hysteria around some controversial donor, similar to the Tor Project?

You can buy new Pixel 7 quite cheap and install grapheneOS there.
They still cost like 2 ordinary phones. The cheapest version here costs $355 including import fee from China or Dubai.

I do not really need MTE (memory tagging) and other advanced features, I need freedom and no telemetry, no ads, no support for DRM, no cloud, no device keys, no attestation, etc. Anyway almost every phone has vulnerabilities so it makes little sense to keep there anything private.

Meh, too little and too late
Really excited about this! Google has truly fallen from grace with all their embrace, extend, extinguish.

I do hope the Motorola's are a bit repairable though, e.g. no screen glue. Does seem the next phone choice will be between Motorola or Fairphone. Sucks one is likely to choose between security or repairability...