<?xml version="1.0" encoding="utf-8" standalone="yes"?>
<rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom">
  <channel>
    <title>AOSP on Nalar</title>
    <link>https://nalar.dev/tags/aosp/</link>
    <description>Recent content in AOSP on Nalar</description>
    <generator>Hugo</generator>
    <language>en-us</language>
    <lastBuildDate>Sat, 19 Sep 2026 00:00:00 +0000</lastBuildDate>
    <atom:link href="https://nalar.dev/tags/aosp/index.xml" rel="self" type="application/rss+xml" />
    <item>
      <title>GrapheneOS Security Boundaries: Android Hardening, the Baseband, and IMEI</title>
      <link>https://nalar.dev/grapheneos-security-boundaries-android-hardening-baseband-and-imei/</link>
      <pubDate>Sat, 19 Sep 2026 00:00:00 +0000</pubDate>
      <guid>https://nalar.dev/grapheneos-security-boundaries-android-hardening-baseband-and-imei/</guid>
      <description>&lt;p&gt;GrapheneOS can change how Android isolates applications, how privileged services are exposed, how the operating system is verified at boot, and how much authority Google Play receives. It cannot turn every property of a phone into an operating-system setting.&lt;/p&gt;&#xA;&lt;p&gt;IMEI is a useful example of that boundary. GrapheneOS explicitly states that changing the IMEI is not possible on a production device and that the operating system cannot add support for it because the hardware does not support that operation. The distinction is architectural: Android controls a large software stack, but the cellular modem and device identity mechanisms are not ordinary application data stored inside the Android user space.&lt;/p&gt;</description>
    </item>
  </channel>
</rss>
