Toot

Written by GrapheneOS on 2025-01-16 at 19:38

Unlike the stock Pixel OS, we enable pointer authentication (PAC) return protection for userspace instead of only the kernel. Similar to BTI, this is easy to enable and doesn't cause regressions. Unlike the stock Pixel OS, we use Shadow Call Stack as an extra layer on top of PAC in the kernel.

=> More informations about this toot | View the thread | More toots from GrapheneOS@grapheneos.social

Mentions

Tags

Proxy Information
Original URL
gemini://mastogem.picasoft.net/toot/113839723135234363
Status Code
Success (20)
Meta
text/gemini
Capsule Response Time
212.225621 milliseconds
Gemini-to-HTML Time
0.211262 milliseconds

This content has been proxied by September (ba2dc).