From 747616ae0a1db0bcf92c344973c96feadc4edda9 Mon Sep 17 00:00:00 2001 From: Daniel Micay Date: Wed, 5 Mar 2025 11:00:06 -0500 Subject: [PATCH] clarify hardware CFI requirement --- static/faq.html | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/static/faq.html b/static/faq.html index a568da8c..75f8efec 100644 --- a/static/faq.html +++ b/static/faq.html @@ -314,7 +314,7 @@
  • Hardware accelerated virtualization usable by GrapheneOS (ideally pKVM to match Pixels but another usable implementation may be acceptable)
  • Hardware memory tagging (ARM MTE or equivalent)
  • -
  • BTI/PAC, CET or equivalent
  • +
  • Hardware-based coarse grained Control Flow Integrity (CFI) for baseline coverage where type-based CFI isn't used or can't be deployed (BTI/PAC, CET IBT or equivalent)
  • PXN, SMEP or equivalent
  • PAN, SMAP or equivalent
  • Isolated radios (cellular, Wi-Fi, Bluetooth, NFC, etc.), GPU, SSD,