AMAZINGINDEX.COM 日报快照
51.2
VOL. 2026.09
2026.09.03
← 返回 2026.09.03 日报
日报快照 · Daily Snapshot
NO. 015

Pixel 11 硬件级内存安全落地

#ARTICLE HackerNews 2026.09.03
推荐指数 48.0 NO. 015 · 2026.09.03
发布2026/09/02Score161Comments123

GrapheneOS 确认 Pixel 11 支持 MTE(Memory Tagging Extension),这是 ARM 的硬件级内存保护技术,可检测并阻止大量内存安全漏洞利用。对关注移动安全基线的 AI 工程师和隐私敏感型产品团队而言,这意味着端侧模型部署的硬件可信根又多了一层。

MTE 此前在 Pixel 8/9 上被谷歌以"兼容性"为由软件禁用,GrapheneOS 是少数强制开启的 ROM。这次 Pixel 11 的 MTE 支持从"能开"变成"原生支持",说明谷歌终于在 SoC 层解决了性能开销问题——此前 MTE 开启后部分场景有 5-10% 的 CPU 开销,对端侧 LLM 推理是致命伤。

如果你在做端侧 AI 且涉及敏感数据(医疗、金融 RAG),Pixel 11 + GrapheneOS 的组合可能是目前消费级设备里安全基线最高的选择,值得纳入测试矩阵。另外这也会倒逼其他 Android 厂商跟进 MTE 支持,否则企业级端侧 AI 采购会偏向 Pixel 生态。

意见分歧 114 条评论

核心争论:MTE 硬件已存在但默认禁用,性能损耗与生态兼容性成主要争议

user_7832

To clarify, regarding the confusion: it was disabled, leading them to think it didn't outright exist. Why disabled? Well, its performance is apparently quite poor. But why? ...Apparently to save money.

readthenotes1

The thread made it sound like it was more- that the actual release of pixel 11 did not have the firmware to support MTE, not that it was just disabled. Is the thread wrong or did I misread it?

user_7832

Nah sorry my bad. I mixed up "it's currently disabled" and "the hardware is there" into "it was earlier disabled".

替代方案: AddressSanitizerRustECC
查看原文 →