Sorry for the slow reply. And wow, yeah, about Lineage, I checked yesterday and my current phone (Moto G Stylus 5G 2023) is now supported. This is new, it wasn't there last time I looked some months ago. Not all of the G models are there now, and not so many very recent ones, but it's nice that I now have a Lineage-capable phone. So I might switch over at some point, maybe after getting another phone in case the reinstall goes wrong.
About Graphene, I have trouble believing "governments hate this one weird OS" and "Motorola is about to mass produce phones with the weird OS pre-installed" at the same time. And while I can admire a phone that resists a "govt seizes my phone" attack, that's pretty far down my list of threats. Even skipping TPM vulnerabilities, the phone by design broadcasts its location everywhere it goes, spews metadata (even if not plaintext content) about everything it does on the network, is subject to supply chain attacks from every app getting periodic updates, etc. I've never understood how "frequent security patches" is supposed to indicate a secure app. If the app was secure it wouldn't need patches. Tbh I haven't travelled outside the US since before 2019, and if I do it again, I expect to leave my phone at home. I'll bring a burner or a flip phone or something like that. What does the Graphene user do when the govt says "unlock your phone or we'll arrest you"? See e.g. the guy being prosecuted for erasing his phone when border patrol wanted to examine it.
AMD's SEL stuff has vulnerabilities too. Intel put real effort into making SGX secure but oops. Even the IBM 4758 security processor, a very high end tamper reactive HSM that bricked itself on purpose if you breathed the wrong way, turned out to have protocol bugs. IDK about the current version if such a thing exists.
The Graphene folks themselves say that the Motorola Graphene phone is intended for corporate and government customers who currently by Apple and Google phones, fwiw: https://grapheneos.social/@AlexanderMars@mastodon.social/117136564050537120
Yes TPM in PC's was historically intended for DRM, thus the political opposition to it back in the day. "Trusted platform" meant that media companies could trust the machine to prevent the user from running unauthorized software, getting the keys out, etc. TPM's use in Graphene still seems to be key encapsulation, but I don't see the importance. I'd rather keep my file decryption key as a QR code on a slip of paper, so I unlock the phone by clicking the camera at the QR code. If I'm about to return from another country, I throw away the paper before getting on the plane, and then truthfully tell the border patrol that I have no way to unlock the phone there at the airport. They want the data after I unlock it at home? Fine, show me a warrant first. That's about the best you can hope for with a Graphene phone anyway.
Anyway if Moto makes a G series Graphene phone or other affordable model, I'm up for it, but I expect whatever they do will be closed and expensive.
This might also be of interest, predicting another iteration of govt demanding mandatory backdoors in eerything: https://blog.cryptographyengineering.com/2026/08/14/everything-is-about-to-go-dark/