Comment by Valodim
2 days ago
Not an expert, but I recently heard that apparently not everything is perfect in fairphone land: https://discuss.grapheneos.org/d/24134-devices-lacking-stand...
2 days ago
Not an expert, but I recently heard that apparently not everything is perfect in fairphone land: https://discuss.grapheneos.org/d/24134-devices-lacking-stand...
GrapheneOS is like a veteran and war zone expert: for them, not only the external environment is considered extremely hostile that you should leave your house only wearing an armor and with bodyguards, but also the internal environment is hostile: your bodyguards could be bribed and work against you, that's why you need to somehow be protected against that as well.
Just as physical security, digital security most of the time not as radical, and tradeoffs are usually accepted, especially when they are "invisible": hardware and software security features are usually not mentioned in the specs and the regular and even power user just don't know most of them and what do they do.
When GrapheneOS says "private" and "secure", they mean top-of-the-line security features, updates as soon as possible, all available mitigations against zero-days and insecure code which will limit the impact before the patch, etc. Security as in a killdozer.
When other say "private" and "secure", most of the time it means: "we've followed all the recommendations applicable to our development budget, device price point, and support life time". Graphene does not like that definition of these words.
For smartphone, chip manufacturer goal is not to protect the user at all costs, but to provide reasonable security features for the price.
BUT the goal of chip manufacturer to protect the device at all costs is for… game consoles! That's why Xbox, PlayStation, Switch all run on a custom silicon and not an ordinary chips!
> That's why Xbox, PlayStation, Switch all run on a custom silicon and not an ordinary chips!
Not really. Xbox and PlayStation both run on pretty standard AMD Zen 2 chips. Somewhat customized, but standard enough that people by binned playstation 5 motherboards to use as computers with normal OS'es (lookup BC-250). The last gen with more customized chips was the PS3/Xbox360 era, when both went with a variant of PowerPC, same as Gamecube/Wii/WiiU.
Switch runs on basically the same Nvidia Tegra CPU/GPU as multiple android tablets.
>but standard enough that people by binned playstation 5 motherboards to use as computers
That doesn't mean that all the features are enabled right from the factory, or that the compatibility with already existing features is lost.
Modern chip's security features are pretty complicated and include hardware patches, hardware debug authentication, multiple provisioning states (and multi-key hierarchy for that), RMA states to clear all the private information, etc.
>Switch runs on basically the same Nvidia Tegra CPU/GPU as multiple android tablets.
Yes, and the one which got cracked with a bootrom vulnerability ;)
That's a pretty working motivation for a chip company to improve their chip security when the company as beefy as Nintendo tells them that their chip is vulnerable they're losing money because the customers can play for free ;). I'm pretty sure patchable bootroms started to be common only after Switch hack.
I think you should listen to bringup of Linux on Playstation talk from CCC to understand that those platforms are much more than just "somewhat customized".
There are whole sections of peripheral chips missing and they behave quite a bit differently with how they bootstrap and where things are mapped in memory.
5 replies →
This is not an apt analogy.
A couple of the tenets of computing security are:
- Defense in depth - Principle of least privilege
It is a foundational reality that software (especially in unsafe languages) will invariably have vulnerabilities. Defense in depth and least privilege have compounding effects by forcing attackers to chain multiple exploits to achieve a compromised device, rather than a single vulnerability.
GrapheneOS shows how much can be accomplished on top of relatively secure platforms to begin with (AOSP, Pixel Stock OS, etc.) without sacrificing nearly any usability to the end user (barring manufactured hurdles like Play Integrity). It makes it more damning that many "privacy" OSes and devices cannot even meet the baseline level of privacy and security that AOSP provides, but degrade it.
Firmware and driver neglect and the lack of secure element utilization is not "reasonble security for the price".
On the other hand, my experience with /e/OS on a Fairphone was that it was 4 years behind in updates as compared to Stock Android on that Fairphone.
I don't think that expecting security updates it being an extremist, or is it?
>GrapheneOS is like a veteran and war zone expert: for them, not only the external environment is considered extremely hostile that you should leave your house only wearing an armor and with bodyguards, but also the internal environment is hostile: your bodyguards could be bribed and work against you, that's why you need to somehow be protected against that as well.
Yeah, iPhoens are made that way as well. It's just caring about the privacy of your users.
> When GrapheneOS says "private" and "secure", they mean top-of-the-line security features, updates as soon as possible, all available mitigations against zero-days and insecure code which will limit the impact before the patch, etc. Security as in a killdozer.
I think it's deceptive because people think they will get better privacy/security with a /e/ fairphone when it's actually much worse than an iPhone.
iPhone is top-of-the-line as well, because they control the whole software and the whole hardware (starting from basically all the chips). That's very rare in the industry.
There are just a bunch of companies which afford to do the same. Maybe Xiaomi will be the next one.
> I think it's deceptive because people think they will get better privacy/security with a /e/ fairphone when it's actually much worse than an iPhone.
That's just blatantly not true though - even iPhones collect way more telemetry and Ad data than /e/ OSes.
[flagged]
2 replies →
Fairphone makes their fair share of blunders. Software updates are a big issue, especially around the times that critical vulnerabilities need to be patched.
With the hardware I'm not impressed, and on their own forum I've seen plenty of people reporting issues with overheating on the Gen 6. Hopefully kinks have been ironed out on their 6+.
The current CEO also has a persona that would stir up any community (read a few of his AI-gened posts on their blog, if interested of context).
Still holding on to my FP4, but they are not of consideration on my future phone purchase, unless there is some kind of reality check over there and improvements materialize beyond words.
Ultimately, a lot of the “fairness” of the Fairphone is offered by “just buy a really popular manufacturer.”
Everyone and their dog can repair an iPhone because it’s the most popular phone on the planet. Are those repairs accessible to the consumer at home with amateur skills? No, not really. However, newer iPhone models are significantly easier to repair and come along with lower repair costs direct from the manufacturer compared to previous models.
You want years of software updates? Yeah, an iPhone has you covered there, too.
And of course, fairphone’s hardware and OS are nothing to write home about. For the freedom and security nerds they’re better off with GrapheneOS on Pixel or whatever upcoming Motorola phones will support it.
Who is the Fairphone for exactly? Who is buying it and why?
I think the fairbuds are their best product, but I also imagine AirPods Pro 3 are on a whole different level of sound quality, noise cancelation, voice quality/voice isolation, and firmware/software polish.
And let’s be honest about repairability with tiny earbuds: being able to replace the battery is has such a tiny impact on their footprint. If I have to throw out my AirPods Pro 3 every 5 years due to battery degradation, that’s such an insignificant quantity of material being wasted, so it’s probably worth it to get a better product. I could offset my environmental impact by eating a little less beef or riding my bike instead of driving a few times. You drive 30 miles and that’s an entire gallon of refined petroleum product, how much material and energy is used to make one pair of AirPods? I can’t imagine it’s a lot.
I don’t say any of this to be a big corporate or Apple shill. I am rooting for the little guys. But the little guys need to be realistic. You look at products like the Framework 13 Pro and you can actually say, okay, here’s a product with really legitimate benefits over its incumbent competition. There is a reason to buy this product for a certain buyer. I just don’t see that with Fairphone. I can’t think of a customer profile where that person is getting a better ownership experience with Fairphone products.
> For the freedom and security nerds they’re better off with GrapheneOS on Pixel or whatever upcoming Motorola phones will support it.
Not quite. The people who care about security first are better off with GOS, yes. However, GOS's threat model very specifically treats the user as a thing to defend against; the freedom-first crowd should avoid them.
5 replies →
I'm not big on this general line on argument, but one point in particular:
> And of course, fairphone’s hardware and OS are nothing to write home about. For the freedom and security nerds they’re better off with GrapheneOS on Pixel or whatever upcoming Motorola phones will support it.
For the "freedom nerds", FP is one of the only (if not the only?) vendor to have official support for microG-based operating systems, seamless OTA updates and everything included. The Murena e/OS offering in particular is simple enough that the non-nerds that (perhaps less outspokenly) care about freedom can just pick it up with little change in habits.
5 replies →
isn't the main point of Fairphone to not use conflict minerals?
by using FOSS only myself and hating monopolies like Apple etc., i still pretty much convinced that being "green" or "ethical" is more about participating/volunteering/doing-something towards a better world than off-loading your duty to other companies... one could easily make a point that Apple products despite locked down, are still green (Apple has a bunch of zero-emission and whatever policies) and much more if one uses their devices for a long while. i had a 2° hand iPhone SE 1° gen. till 2021? if stuff breaks despite your not being able to fix it's not like you can't hop into a specialized shop to change batteries or even pay the expensive service Apple offers... sure that allows exploitation and it's always nice to get rid of it, that's why somehow these emerging companies are important and/or policies like the right of repair will make them obsolete
3 replies →
The new Sennheiser earbuds have replaceable batteries too so the fairbuds are no longer unique in that regard. I haven't read comparisons on sound quality though
2 replies →
I have an FP4, and when it'll die, I will just buy an iphone. Security updates are slow, and after the bullshit of the android upgrade, yeah but no.
> and after the bullshit of the android upgrade
Fair enough, but note that it does not concern GrapheneOS. Hopefully soon available on Motorola phones :-). That would be my next phone (assuming it's not too expensive of course).
The GOS people really spend a lot of time of energy showing the worst sides of FairPhone to the world. I think it is because the conscientious technology user is really interested in the combination of ethically sourced, repairable hardware and a security and privacy (from big tech) focussed OS. Tbh I also like that sliders to switch to a simple mode. A well, we can’t have it all. I do prefer de-googled + freedom to do what I want over security (to a degree). So… I’m on the fence. As many vocal people are. A second hand pixel 10 is also a “green” choice.
I do have the feeling that many non-nerds can express the difference between all mentioned attributes, many just like FairPhone as an ethical phone. It’s not that simple, I agree.
So I have been on /e/OS on a Fairphone 3+ for 4.5 years. I was really into /e/OS when I got my Fairphone. When it stopped being usable (not because the hardware was not working anymore, just that the apps I want on my phone were lagging so much they were unusable), I looked into alternatives, including GrapheneOS.
And at that point I got quite disappointed by /e/OS, because I felt like their marketing had been abusing me for years. For instance, my Fairphone 3+ was 4 years behind the Fairphone Stock Android on some updates. /e/OS just wasn't forwarding them, they seemingly were just not maintaining the FP3. Though I bought it to /e/OS, under the promise that it would be supported!
Then I realised that all this time, not only my bootloader was unlocked (so the Android security model had been broken from the first day I powered the phone), but the system was signed with the Google test keys! When you are encouraged to install apps "from the internet" instead of the Play Store, on a phone that disabled the security model so that you're not protected against malware as on any Stock Android, would you say it's being a security nerd?
The thing that GrapheneOS keeps repeating and I realised is true is that many times, if you run a deGoogled alternative that is not GrapheneOS, you get worse security than if you were running Stock Android. It's not about "getting the best possible security", it's about getting the baseline. The truth with /e/OS (or LineageOS, which is pretty much what /e/OS ships, I believe?) is that it depends a lot on the phone. And with many phones, you get worse than the baseline you would get with Stock Android.
> I do prefer de-googled + freedom to do what I want over security (to a degree).
So I switched to GrapheneOS on a Pixel, and I feel like I get the best of both worlds: I get the privacy benefits of the sandboxed Play Services, and the better security. And it's not a "weird" system at all: I asked my family to use it and they didn't realise it was not a "normal Android". It is very different from running something like a Linux on mobile, which would be very very different.
> many just like FairPhone as an ethical phone
Yes, why not. If I was to get a Fairphone again, though, I would use the Stock Android.
And I wish Fairphone could get to the level where they can be supported by GrapheneOS. But it feels like my next phone will probably be a Motorola with GrapheneOS rather than a Fairphone.
Thanx for the thoughtful reply. You’re pulling me off the fence.
Seems you have to compromise on HW openness and ethics vs paranoia.
It's paranoia to want ≥ security than an iPhone or stock Pixel?
[flagged]
1 reply →
[flagged]
4 replies →
Fairphones are closed source hardware with closed source firmware and closed source userspace drivers. Fairphones are less open than Pixels, not more open.
It isn't truly known how a Fairphone compares to an iPhone or Pixel when it comes to environmental impact or fairness to workers. Fairphones are designed and built by T2Mobile since the Fairphone 4. T2Mobile barely has any public information available about it. There isn't information on the working conditions, pay and other aspects of of it. The same applies to the rest of the supply chain. Fairphone provides a list of companies involved in the supply chain without details.
[flagged]
> vs paranoia
I really would like to mention that many times, using /e/OS or LineageOS (or the likes) means that you get worse security than Stock Android.
It would be fine to run /e/OS or LineageOS on a Pixel, assuming those Android systems are not too slow with updates (my experience with my /e/OS phone was that they were 4 years behind as compared to Stock Android).
But really, if you have a Pixel, it doesn't really make sense to use something other than GrapheneOS IMO.
So to me it's really:
- GrapheneOS if you can
- Stock Android vs an alternative otherwise
> It would be fine to run /e/OS or LineageOS on a Pixel
Both /e/ and LineageOS lag far behind on current security updates on a Pixel. Neither is based on Android 17 yet which was released in June 2026. Neither has the June 2026 or later Pixel firmware, kernel, driver and HAL patches. Both also roll back the standard security of AOSP but /e/ does so much more than LineageOS.
1 reply →
[flagged]
> It's not like any other device meets their ridiculous standards either
I don't think it's ridiculous to want the ability to relock the bootloader, for instance? Do you realise that if you cannot do that, you just break the whole Android security model right away?
> neither will their own Motorola whenever they get around to actually making it
Source: You made it up
A quick search would basically disprove everything after your first sentence.
It's a reasonable extrapolation of the current state. They want up to date patches, Google is already winding down open support for that, and it'll release in what, a year or two? Basically guaranteed to have outdated security patches on launch or they'll have to start maintaining their own. Might happen, but it seems unlikely they can hack it, as it were.
[flagged]
There are devices meeting these basic standards right now, and the entire family of them, no less.
GOS are vocal about safety and security of all the devices, not just seriously insecure Fairphones, and this article is about something different altogether, that's misinformation they've been hit with several times.
Fair criticism is fair, but yours is fabrications.
[flagged]
7 replies →
[flagged]
Android Open Source Project userspace code runs on any devices with Treble. That means it runs on any certified Android devices with the ability to install another OS. Updates and security features for the Linux kernel, drivers, firmware and hardware are still needed.
Fairphone 5 and earlier have end-of-life Linux kernel branches without security support. Those lag multiple years behind on providing full Android security updates. The 1-2 month delays for partial security backports is compared to the Android security bulletins and is actually a much longer delay compared to when the patches are made available to ship by OEMs.
[flagged]
> they also compare the security to the "Android Open Source Project" as if it's a real thing
It is very much a real thing. You can build AOSP from sources and install it on a phone. Many Android devices run that (e.g. drone controllers).
> Is certainly much better than my Samsung flagship
Oh yeah, that's for sure. To share my experience, in terms of updates for me it has been GrapheneOS >>> Stock Android > /e/OS. I was running LineageOS/Cyanogen a decade ago but I don't remember and it was a different time anyway.
Fairphone's updates are definitely much worse than recent Samsung flagships. It's the other way around to an extreme. Samsung does monthly security patches for their flagships and includes a large subset of security preview patches. It's not as good as GrapheneOS security preview releases but they're ahead of the Android security bulletins.
Fairphone is 1-2 months behind the Android security bulletins which are themselves 2-4 months behind the security preview patches. Fairphone takes a year to port to a new OS version shortly after launch and then ends up taking increasingly more time.
No you can't, AOSP doesn't even include a functional keyboard not a functional call manager nowadays. And I'm not even talking about the firmware side of things
Sure that might be enough for very basic hardware like your drone controller example but not a phone
2 replies →