If we are going to name something and say it's a problem like there is something that exists elsewhere, but not giving information about what that solution entails is not constructive nor useful. Did graphene make the claim they have resolved the issue? Has anything else? If not why single it out? If it's one of the better options out there at least fighting towards the goal of being more secure and it does exactly that then why the hate?
For as many people there are blindly slobbing all over grapheneos knob there are an equal amount of more blind haters.
While there is no currently not a complete solution officially released and on by default from grapheneos it does however, include:
- strict IOMMU isolation on the hardware level which restricts various radio firmwares into restricted memory spaces which prevents a rogue radio from reading and writing memory.
- firmware sandboxing and hardening which is additional firmware and other memory safe mitigations to prevent buffer overflow attacks and some other attack vectors
- per-app and system level toggles for radios
- baseband isolation verification making use of the hardware attestation tooling that verifies device firmware so that you can't rest easy that it's not been tampered with or modified with including at boot.
The issue is right now isn't graphene or any other competitor but a radio hardware issue to resolve further, which means no one has much better if at all. So while not complete or perfect it is however as far as I know one of the best attempts out there. For the US at least the FCC must explicitly approve whatever new hardware design they come up with using whatever hardware partner such as Motorola for radio fabrication. Currently Motorola Mobile (and not their evil sister company they split from who more likely does have patents) to my understanding does not have patents in this space which brings up another ma to or hurdle as the big dogs who design radios have anyone's balls in a vice grip that tries to enter it with lawsuit after lawsuit. Then we have the carriers own testing. Not saying this is impossible, but from the standpoint of graphene or any other security minded OS this is out of scope and just not realistic to ask of them. At least that was the case in the past. There is possible opportunity with the Motorola Mobile partnership, but I would not expect this in the first release.