Project ideas from Hacker News discussions.

Pixel 11 doesn't yet meet the GrapheneOS security standards and may be skipped

📝 Discussion Summary (Click to expand)

Four prevalent themes in the discussion

  1. Uncertainty around MTE support on Pixel 11 and its impact on GrapheneOS
    Users debate whether Google will enable Memory Tagging Extension (MTE) in a future OS update, noting that GrapheneOS has stated it won’t support the Pixel 11 without MTE.

    “They will not support Pixel 11 unless Google adds MTE support in a future update.” – pavon

  2. Google’s anti‑competitive restrictions on OEMs selling devices with GrapheneOS
    Commenters highlight that Google blocks non‑Samsung OEMs from pre‑installing GrapheneOS, calling it monopolistic behavior.

    “The much more interesting recent news IMO is that Google is not allowing (non‑Samsung) OEMs to sell devices with GrapheneOS.” – microtonal

  3. Hardware reliability concerns and upgrade fatigue with Pixel phones
    Several users report motherboard failures, warranty denials, and frustration with short lifespans, leading them to skip new Pixel generations.

    “My Pixel 8 failed with the exact failure mode … after owning it for 18 months… Flagship phone turned into a useless device… I’m done with Pixel and Google in general.” – randlet

  4. Privacy‑security trade‑offs influencing phone and OS choices
    The conversation weighs the privacy benefits of GrapheneOS against practical concerns such as carrier support, device availability, and perceived security of hardware features.

    “If you care about privacy, stay away from the moto release and stick with pixel.” – lesspassiveobse (reflecting the ongoing debate over which device offers better privacy).


🚀 Project Ideas

MTEChecker

Summary

  • Detects Memory Tagging Extension (MTE) hardware and firmware support on Android devices, reporting whether it's enabled and usable.
  • Provides clear guidance on how to enable MTE via custom kernels or firmware updates, addressing Pixel 11 users' uncertainty.

Details

Key Value
Target Audience Privacy‑focused Android users, GrapheneOS enthusiasts, developers testing memory safety
Core Feature Reads CPU ID registers, checks firmware flags, and displays MTE status with actionable recommendations
Tech Stack Kotlin/Android Studio, optional native C++ via NDK for low‑level registers, Material Design
Difficulty Medium
Monetization Hobby
#### Notes
- HN commenters expressed frustration that Pixel 11 ships without MTE firmware and want a way to verify if it's actually present (e.g., “We think they removed most of the hardware acceleration…”).
- A simple diagnostic tool would give concrete data, reduce speculation, and help users decide whether to flash a custom kernel or wait for Google update.

GrapheneOS Flash Assistant

Summary

  • Cross‑platform desktop application that automates unlocking the bootloader, flashing GrapheneOS, and locking the bootloader again with verified attestation.
  • Includes encrypted local backup of user data before flashing, reducing fear of data loss when switching to a privacy‑focused OS.

Details

Key Value
Target Audience Users wanting to install GrapheneOS on Pixel or Motorola devices but wary of complex command‑line steps
Core Feature One‑click flow: backup → unlock → flash GrapheneOS → verify via Auditor app → relock
Tech Stack Electron (TypeScript/React), uses fastboot/adb binaries, optional Rust for secure backup
Difficulty Medium
Monetization Revenue‑ready: $19 one‑time purchase (pro version) with free basic tier
#### Notes
- Commenters mention the hassle of manual flashing and fear of bricking phones (e.g., “I had a very frustrating back and forth with Google support”).
- An guided tool would lower the barrier, increase GrapheneOS adoption, and address the pain point of painful migrations.
- The backup feature directly addresses concerns about losing 2FA, photos, etc., when a device fails.

PrivPhone Hub

Summary

  • A curated reseller that purchases unlocked Pixel/Motorola phones, flashes GrapheneOS, runs attestation verification, and ships them with a tamper‑evident seal.
  • Offers optional enterprise bulk orders with pre‑configured profiles (VPN, app allow‑list) for privacy‑conscious organizations.

Details

Key Value
Target Audience Journalists, activists, businesses, and privacy‑enthusiasts who want a ready‑to‑use GrapheneOS device without dealing with flashing
Core Feature Factory‑fresh GrapheneOS devices with attestation‑verified integrity, optional MDM‑style configuration
Tech Stack Web storefront (Next.js), inventory database (PostgreSQL), secure flashing pipeline (CI/CD using fastbot), attestation verification service
Difficulty High
Monetization Revenue‑ready: Device sale price + 15% margin; enterprise subscriptions for MDM features
#### Notes
- Discussion highlights Google’s restriction on OEMs selling GrapheneOS devices and the desire for a Motorola partnership that actually ships GrapheneOS out of the box.
- A third‑party reseller bypasses OEM limits by flashing after purchase, giving users a trusted source and reducing the “TSA line” identification worry.
- Provides a concrete solution to the frustration expressed about Google blocking OEM sales.

Attestation Verification API

Summary

  • A backend service that receives signed attestation reports from the GrapheneOS Auditor app and returns a simple trust score or verification badge.
  • Enables resellers, employers, or users to prove that a device is running unmodified GrapheneOS with locked bootloader, addressing trust concerns in secondary markets.

Details

Key Value
Target Audience Device resellers, enterprise IT, privacy‑conscious individuals selling or buying used GrapheneOS phones
Core Feature Verifies Auditor‑app JWT signatures against GrapheneOS keys, returns JSON trust object (verified, device ID, OS version)
Tech Stack Node.js/Express, uses GrapheneOS public verification keys, hosted on Cloudflare Workers or similar
Difficulty Low
Monetization Revenue‑ready: Free tier for 100 checks/day; paid plans $5/mo for unlimited checks
#### Notes
- Several users mention the Auditor app as a way to check for tampering but lack an easy way to share that proof with others (e.g., “I assume that it would be quickly discovered if Motorola were tampering with phones en masse”).
- An API would make attestation portable, increase confidence in the second‑hand market, and support the reseller idea above.
- Low difficulty because it mainly wraps existing verification logic.

Read Later