7 ms·
Fairphone does! https://www.fairphone.com/en/bootloader-unlocking-code-for-fairphone/ https://www.fairphone.com/en/bootloader-unlocking-code-for-f...
by pentamassiv 1y ago
Fairphone does!
https://www.fairphone.com/en/bootloader-unlocking-code-for-fairphone/ https://www.fairphone.com/en/bootloader-unlocking-code-for-f...
- lordofgibbons 1y agoDo anyone know why GrapheneOS doesn't support fairphone?
- aeonik 1y agoI can't find the link, but a couple days ago, they said in a thread here it was due to their lack of support of some important security features, and remarked that it didn't look like they were even interested in supporting them.
- sellerie 1y agoYou cant re-lock the bootloader with a custom key which grapheneos considers a cornerstone of their security model.
- gruez 1y agoYeah, otherwise the bad guys can just wait till you're not looking at your phone, reflash your it with a backdoored version, and wait for you to unlock it (evil maid attack).
- BobaFloutist 1y ago>the bad guys can just wait till you're not looking at your phone, reflash your it with a backdoored version I hate it when the bad guys do this to my phone
- Arch-TK 1y agoThe bad guys e.g. the police detaining you during a protest and temporarily seizing your property, or the border police "scanning" your phone.
- codedokode 1y agoIf your phone was in hands of police you better sell it anyway because they could install a physical GPS tracker, etc. So locked bootloader doesn't change much. Also if you live in a truly democratic country you don't even need to set the PIN code - your rights are protected by the law.
- ThePowerOfFuet 1y ago>a physical GPS tracker Every mobile phone already is one.
- Arch-TK 1y agoIt would be relatively difficult to add a physical GPS tracker to a modern phone. Also, it's unnecessary, the government just needs to take a note of the IMSI and/or IMEI and then use the cell tower records to track you (rather accurately I should add). The problem is not the tracking inherent in the design of mobile telephony networks, which you can circumvent by using burner phones. The problem is for example abuse of tools such as cellebrite to gain warrantless access to your phone at various opportunities. This is also why proper baseband isolation is important. Baseband firmware is unaudited and likely to have government backdoors. If the government wants to surveil me, they'll have to put in some actual effort instead of just taking opportunities.
- baybal2 1y ago[dead]
- plqbfbv 1y agohttps://www.androidauthority.com/fairphone-gen-6-us-grapheneos-criticism-3578792/ https://www.androidauthority.com/fairphone-gen-6-us-graphene...
- erremerre 1y agoThe curious thing is that being GrapheneOS open source, I would think that somebody could potentially create a ROM for them, even if it is not as secure as GrapheneOS would like. However, absolutely nobody has done it yet...
- NoGravitas 1y agoAXP.OS (axpos.org) is LineageOS-based (formerly DivestOS-based), but includes security backports from GrapheneOS and CalyxOS. No doubt it is less secure than GrapheneOS, but surely more secure than LineageOS, and supports bootloader relocking on some devices.
- strcat 1y agoIt's not a security upgrade over current AOSP overall and is definitely not a port of GrapheneOS to other devices. Someone could make a partial port of GrapheneOS to other devices but this is not that. > but includes security backports from GrapheneOS and CalyxOS It has a small portion of the GrapheneOS features, similar to DivestOS before it. However, it's not preserving or restoring the standard security reduced by LineageOS as much as DivestOS did. DivestOS was not a strict upgrade over AOSP either. CalyxOS isn't a hardened OS in the same space as GrapheneOS. It doesn't have similar exploit protections or privacy features. That's a misconception about it. They also haven't provided the June 2025 patches yet. https://eylenburg.github.io/android_comparison.htm https://eylenburg.github.io/android_comparison.htm > but surely more secure than LineageOS This doesn't imply it's as secure as AOSP though despite having additional security features. Starting from LineageOS as the baseline and adding more problematic changes makes it much messier than it just being AOSP with added security features. Android 16 is required for full Android privacy/security patches and the current privacy/security improvements. Soon there will be Android 16 QPR1.
- protimewaster 1y agoAs someone else mentioned, GOS requires that the bootloader properly support relocking with a custom key. Additionally, GOS has a rule that any device supported must keep up with all security and quarterly patches in a timely manner, and none of the Fairphone devices do.
- Tharre 1y agoNo secure element, no memory tagging support, no proper cellular baseband isolation, no verified boot, taking months to ship security updates .. the list is long. From a security/privacy perspective the fairphone is on the worse side of options unfortunately.
- IshKebab 1y ago> no memory tagging support That's not a security feature though... We established that. Fair enough on the other points.
- strcat 1y agoMemory tagging is an important security feature. The way GrapheneOS uses it is explained at https://news.ycombinator.com/item?id=44678704 https://news.ycombinator.com/item?id=44678704. Only having 16 possible tags doesn't impact the deterministic protections we provide. One of the tag values is reserved for free data, internal metadata, etc. and can also be used as a form of 16 byte guard page. For heap allocation, we also dynamically omit the most recent adjacent non-free tags and the previous non-free tag for the current slot. There are 15 possible random values but 3 are dynamically omitted. An attack often needs to use multiple invalid memory accesses where each one would have a 1/15 chance of success from probabilistic MTE alone. MTE gets combined with other probabilistic memory allocator protections. Our main memory allocator also has slot randomization and quarantine randomization. A future revision of MTE could be easily be increased to 8 bits and it paves the path to having much larger memory tagging in the future too.
- Tharre 1y agoFor people out of the loop, parent is referring to TikTag[0], a side-channel speculative execution attack breaking MTE in a probabilistic defense scenario, and the weird cope coming from some people that "MTE was only supposed to be a debugging feature anyway". However, you need some form of code execution beforehand already for this attack, and more importantly it doesn't affect any of the deterministic guarantees of MTE. And those are the main appeal to GrapheneOS in the first place, preventing things like use-after-free by tagging the memory such that it simply can't be accessed anymore. So it's very much a security feature. [0] https://news.ycombinator.com/item?id=40715018 https://news.ycombinator.com/item?id=40715018
- NoboruWataya 1y agoAs others have said they have some security concerns (I don't know enough about that stuff to know how justified or surmountable those concerns are). However with the big manufacturers all locking down their devices more than ever I wonder will they have much of a choice in the end. We're going to need a manufacturer (or preferably several) to actively stand behind the possibility to use custom ROMs, and at the moment Fairphone seem like the only one who might do that.
- microtonal 1y agoUnfortunately, it's hard to make Fairphone secure. No separate secure element (so much easier to do brute force PIN attacks) and always lags in monthly security bulletin patches and major OS releases (remember that the monthly patches typically only address high/critical vulnerabilities, for the rest you need OS updates, QPRs, etc.). Until Graphene works out the deal with the OEM that they are talking to, Pixel is pretty much the only secure phone that allows installing alternative firmware.
- karambanoonoo 1y agoDoes that mean Graphene plans to support phones from other manufacturers than Google?
- snvzz 1y agoFingers crossed that's what it means and that it succeeds. I'd likely buy that.
- strcat 1y agoYes, but they need to meet our official requirements: https://grapheneos.org/faq#future-devices https://grapheneos.org/faq#future-devices We're working with a major Android OEM and it's going well so far. It's still in an early phase where they've assigned a small amount of resources to it to determine everything which needs to be done and then make the case for a much larger investment of resources. We expect that to happen and for it to go well.
- karambanoonoo 1y agoAmazing. I just wish there was a device with an IPS display supported (for PWM flicker sensitive folks).