The fairly obvious answer here is "OEMs don't care about security because very few people will pay for it, either with $ or time". Benchmaxxing sells better.
Let's first start with y'all providing any proof that it was "benchmaxxing" that causes OEMs not to ship hardened allocators (and not - for example - breaking compatibility with users' software).
And then we can move the goalposts to "more secure distro with GrapheneOS" which isn't part of the conversation until you dragged it out.
I'm not going to play a game where you make up false shit and I do the work of disproving it while you move the goalposts with new false shit.
Android release notes are easy to find: <a href="https://source.android.com/docs/whatsnew/release-notes" rel="nofollow">https://source.android.com/docs/whatsnew/release-notes
So are marketing materials: <a href="https://blog.google/products-and-platforms/platforms/android/android-17-features/" rel="nofollow">https://blog.google/products-and-platforms/platforms/android...
and so are marketing materials: <a href="https://blog.google/products-and-platforms/devices/pixel/google-pixel-10-pro-xl/" rel="nofollow">https://blog.google/products-and-platforms/devices/pixel/goo...
and each of those shows that security is pretty much a constant focus for everyone.
Dismissing all the security work done by other people because they didn't jump on your feature is insane behaviour.
pjmlp · · focus · HN ↗
izacus · · focus · HN ↗
Groxx · · focus · HN ↗
izacus · · focus · HN ↗
nvme0n1p1 · · focus · HN ↗
izacus · · focus · HN ↗
And then we can move the goalposts to "more secure distro with GrapheneOS" which isn't part of the conversation until you dragged it out.
pessimizer · · focus · HN ↗
Your trivially proving things can't involve asking other people to prove the opposite of things. You've instantly backed down.
> And then we can move the goalposts
Why? You haven't done anything except ask others to do things. You've moved the goalposts from trivially falsifiable, and started begging.
izacus · · focus · HN ↗
Android release notes are easy to find: <a href="https://source.android.com/docs/whatsnew/release-notes" rel="nofollow">https://source.android.com/docs/whatsnew/release-notes
So are marketing materials: <a href="https://blog.google/products-and-platforms/platforms/android/android-17-features/" rel="nofollow">https://blog.google/products-and-platforms/platforms/android...
and so are marketing materials: <a href="https://blog.google/products-and-platforms/devices/pixel/google-pixel-10-pro-xl/" rel="nofollow">https://blog.google/products-and-platforms/devices/pixel/goo...
and each of those shows that security is pretty much a constant focus for everyone.
Dismissing all the security work done by other people because they didn't jump on your feature is insane behaviour.