8 ms·
Not an expert, but I recently heard that apparently not everything is perfect in fairphone land: https://discuss.grapheneos.org/d/24134-devices-lacking-standard
by Valodim 13d ago
Not an expert, but I recently heard that apparently not everything is perfect in fairphone land: https://discuss.grapheneos.org/d/24134-devices-lacking-standard-privacysecurity-patches-and-protections-arent-private https://discuss.grapheneos.org/d/24134-devices-lacking-stand...
- jampekka 13d agoSeems you have to compromise on HW openness and ethics vs paranoia.
- Cider9986 13d agoIt's paranoia to want ≥ security than an iPhone or stock Pixel?
- eloisant 13d agoIt depends who you are. If you're Edward Snowden, or even a high ranking politician, it's a sane precaution. If you're just a rando like me yes, it's paranoia.
- MostlyStable 13d agoI think this has historically been true and is still approximately true now. But I think in the relatively near future (less than 5 years) there's a really good chance it won't be true anymore. Once open models catch up to the current frontier in vulnerability exploitation, the cost to target people will go way down. In the past, the cost to hack a random individual person was generally high enough that if there wasn't some special reason to hack you in particular, it wasn't worth it. That may no longer be the case in the near future. The floor of what is acceptable security for the General Public probably needs to rise quite a bit over the next few years.
- DaSHacka 13d agoWhy would you assume Google, Apple, and defense-oriented agencies like CISA wouldn't also have access to those same models, but using them to fix issues? Its just raising the bar across the board, I don't see how only attackers would benefit.
- upboundspiral 13d agoAttackers only need to win once, defenders need to win every time. The game is skewed in favor of the attackers, and AI only exarcebates this.
- OneDeuxTriSeiGo 13d agoI think it heavily depends. If you are concerned cops or CBP are going to try to take your phone and search it then wanting a phone like GOS is a very reasonable precaution. Even if you haven't done anything "wrong", you may have engaged in speech or activities that the current US admin has deemed problematic and will try to punish you for if they can find any evidence.
- grapheneos 10d agoGrapheneOS provides massive privacy and security benefits to regular people. That was always important to regular people due to regular devices being nowhere close to good enough to protect people well enough against common threads to their privacy. However, it's far clearer now that exploits have been made so widely available without having expertise. There are many publicly available Android local root exploits on GitHub usable on these devices.
- tcfhgj 13d agothose who give up freedom for security will end up losing both
- grapheneos 12d agoThe quote wasn't talking about personal security from governments and corporations. You're warping the meaning into a situation where it doesn't fit at all. Fairphones are closed source hardware with closed source firmware and closed source userspace drivers. Fairphones are less open than Pixels, not more open. It isn't truly known how a Fairphone compares to an iPhone or Pixel when it comes to environmental impact or fairness to workers. Fairphones are designed and built by T2Mobile since the Fairphone 4. T2Mobile barely has any public information available about it. There isn't information on the working conditions, pay and other aspects of of it. The same applies to the rest of the supply chain. Fairphone provides a list of companies involved in the supply chain without details.
- palata 12d ago> vs paranoia I really would like to mention that many times, using /e/OS or LineageOS (or the likes) means that you get worse security than Stock Android. It would be fine to run /e/OS or LineageOS on a Pixel, assuming those Android systems are not too slow with updates (my experience with my /e/OS phone was that they were 4 years behind as compared to Stock Android). But really, if you have a Pixel, it doesn't really make sense to use something other than GrapheneOS IMO. So to me it's really: - GrapheneOS if you can - Stock Android vs an alternative otherwise
- grapheneos 12d ago> It would be fine to run /e/OS or LineageOS on a Pixel Both /e/ and LineageOS lag far behind on current security updates on a Pixel. Neither is based on Android 17 yet which was released in June 2026. Neither has the June 2026 or later Pixel firmware, kernel, driver and HAL patches. Both also roll back the standard security of AOSP but /e/ does so much more than LineageOS.
- Vax- 11d agoAs you can see at pixel 9 pro's (https://download.lineageos.org/devices/caiman/changes https://download.lineageos.org/devices/caiman/changes)[los changes], it was updated around Aug 18th (or at least that's when the string bump happened), so although ~2 weeks late (assuming the security patch was released at August 1st, which I'm not sure if it really works this way), it's not as bad as you said. But yeah GOS is probably the better choice for pixels, depending on the user's prefs of course. Btw I noticed similar pattern for other devices that support los, like xiaomi ones.
- grapheneos 11d agoYour response doesn't address what we said. You linked to a page showing LineageOS had a release in August 2026 which does not show it has shipped all the recent standard Android and Pixel security patches, which it hasn't done. The latest releases of LineageOS for Pixels do not provide the June 2026 and later updates to the firmware, kernel, drivers and HALs because those have only been provided for Android 17 since it was released and LineageOS isn't yet based on Android 17. Separately from that, since Lineage is still based on Android 16 QPR2 it also doesn't include the many privacy and security patches not backported from Android 17. Android ships many security patches as part of the QPR2 and yearly releases which are not backported to older releases. The backports to older releases are increasingly incomplete. Years ago, they stopped backporting any Low and Moderate severity patches to older releases and more recently they've been scaling back the amount of High and Critical severity patches which are backported. An official policy announcement was made to OEMs that they'd no longer backport many High and Critical severity patches where an LLM discovered the vulnerability internally due to the large volume of patches. Pixels move to the latest OS releases and that means the firmware, kernel, driver and HAL code is only provided for those. It's most difficult for the major yearly releases due to the new API level but it's not trivial for QPR1, QPR2 and QPR3 either.
- grapheneos 12d agoFairphones are closed source hardware with closed source firmware and closed source userspace drivers. Fairphones are less open than Pixels, not more open. It isn't truly known how a Fairphone compares to an iPhone or Pixel when it comes to environmental impact or fairness to workers. Fairphones are designed and built by T2Mobile since the Fairphone 4. T2Mobile barely has any public information available about it. There isn't information on the working conditions, pay and other aspects of of it. The same applies to the rest of the supply chain. Fairphone provides a list of companies involved in the supply chain without details.
- warrantisall 12d agoPixels are not as close repairable as Fairphones.
- grapheneos 10d agoiPhones and Pixels have similar replacement parts available and much longer term support. It's harder to replace components but the phones last longer due to better hardware and updates.
- moffkalast 13d ago[flagged]
- armadyl 13d ago> neither will their own Motorola whenever they get around to actually making it Source: You made it up A quick search would basically disprove everything after your first sentence.
- fsflover 13d ago[flagged]
- moffkalast 13d agoIt's a reasonable extrapolation of the current state. They want up to date patches, Google is already winding down open support for that, and it'll release in what, a year or two? Basically guaranteed to have outdated security patches on launch or they'll have to start maintaining their own. Might happen, but it seems unlikely they can hack it, as it were.
- subscribed 13d agoThere are devices meeting these basic standards right now, and the entire family of them, no less. GOS are vocal about safety and security of all the devices, not just seriously insecure Fairphones, and this article is about something different altogether, that's misinformation they've been hit with several times. Fair criticism is fair, but yours is fabrications.
- moffkalast 13d ago[flagged]
- subscribed 12d agoAt the moment there is no other hardware manufacturer making similarly secure android phones. *NONE* There is no android hardware coming close. If there is, please name it. As far as I know it's only some unspecified, upcoming Motorola flagships. If you call the unwilling, pragmatic choice an "intense hypocrisy", it's pretty clear to me you're simply driven by emotions and tribalism, that the facts don't matter. Are you saying that using Google hardware equals using stock Google os? You must be a little more.... Coherent with your metaphors :)
- mhitza 13d agoFairphone makes their fair share of blunders. Software updates are a big issue, especially around the times that critical vulnerabilities need to be patched. With the hardware I'm not impressed, and on their own forum I've seen plenty of people reporting issues with overheating on the Gen 6. Hopefully kinks have been ironed out on their 6+. The current CEO also has a persona that would stir up any community (read a few of his AI-gened posts on their blog, if interested of context). Still holding on to my FP4, but they are not of consideration on my future phone purchase, unless there is some kind of reality check over there and improvements materialize beyond words.
- Grombobulous 13d agoUltimately, a lot of the “fairness” of the Fairphone is offered by “just buy a really popular manufacturer.” Everyone and their dog can repair an iPhone because it’s the most popular phone on the planet. Are those repairs accessible to the consumer at home with amateur skills? No, not really. However, newer iPhone models are significantly easier to repair and come along with lower repair costs direct from the manufacturer compared to previous models. You want years of software updates? Yeah, an iPhone has you covered there, too. And of course, fairphone’s hardware and OS are nothing to write home about. For the freedom and security nerds they’re better off with GrapheneOS on Pixel or whatever upcoming Motorola phones will support it. Who is the Fairphone for exactly? Who is buying it and why? I think the fairbuds are their best product, but I also imagine AirPods Pro 3 are on a whole different level of sound quality, noise cancelation, voice quality/voice isolation, and firmware/software polish. And let’s be honest about repairability with tiny earbuds: being able to replace the battery is has such a tiny impact on their footprint. If I have to throw out my AirPods Pro 3 every 5 years due to battery degradation, that’s such an insignificant quantity of material being wasted, so it’s probably worth it to get a better product. I could offset my environmental impact by eating a little less beef or riding my bike instead of driving a few times. You drive 30 miles and that’s an entire gallon of refined petroleum product, how much material and energy is used to make one pair of AirPods? I can’t imagine it’s a lot. I don’t say any of this to be a big corporate or Apple shill. I am rooting for the little guys. But the little guys need to be realistic. You look at products like the Framework 13 Pro and you can actually say, okay, here’s a product with really legitimate benefits over its incumbent competition. There is a reason to buy this product for a certain buyer. I just don’t see that with Fairphone. I can’t think of a customer profile where that person is getting a better ownership experience with Fairphone products.
- realusername 13d ago[flagged]
- palata 12d ago> they also compare the security to the "Android Open Source Project" as if it's a real thing It is very much a real thing. You can build AOSP from sources and install it on a phone. Many Android devices run that (e.g. drone controllers). > Is certainly much better than my Samsung flagship Oh yeah, that's for sure. To share my experience, in terms of updates for me it has been GrapheneOS >>> Stock Android > /e/OS. I was running LineageOS/Cyanogen a decade ago but I don't remember and it was a different time anyway.
- grapheneos 12d agoFairphone's updates are definitely much worse than recent Samsung flagships. It's the other way around to an extreme. Samsung does monthly security patches for their flagships and includes a large subset of security preview patches. It's not as good as GrapheneOS security preview releases but they're ahead of the Android security bulletins. Fairphone is 1-2 months behind the Android security bulletins which are themselves 2-4 months behind the security preview patches. Fairphone takes a year to port to a new OS version shortly after launch and then ends up taking increasingly more time.
- realusername 12d agoNo you can't, AOSP doesn't even include a functional keyboard not a functional call manager nowadays. And I'm not even talking about the firmware side of things Sure that might be enough for very basic hardware like your drone controller example but not a phone
- palata 11d agoWell then you install apps.
- realusername 11d ago
- ValdikSS 13d agoGrapheneOS is like a veteran and war zone expert: for them, not only the external environment is considered extremely hostile that you should leave your house only wearing an armor and with bodyguards, but also the internal environment is hostile: your bodyguards could be bribed and work against you, that's why you need to somehow be protected against that as well. Just as physical security, digital security most of the time not as radical, and tradeoffs are usually accepted, especially when they are "invisible": hardware and software security features are usually not mentioned in the specs and the regular and even power user just don't know most of them and what do they do. When GrapheneOS says "private" and "secure", they mean top-of-the-line security features, updates as soon as possible, all available mitigations against zero-days and insecure code which will limit the impact before the patch, etc. Security as in a killdozer. When other say "private" and "secure", most of the time it means: "we've followed all the recommendations applicable to our development budget, device price point, and support life time". Graphene does not like that definition of these words. For smartphone, chip manufacturer goal is not to protect the user at all costs, but to provide reasonable security features for the price. BUT the goal of chip manufacturer to protect the device at all costs is for… game consoles! That's why Xbox, PlayStation, Switch all run on a custom silicon and not an ordinary chips!
- Cider9986 13d ago>GrapheneOS is like a veteran and war zone expert: for them, not only the external environment is considered extremely hostile that you should leave your house only wearing an armor and with bodyguards, but also the internal environment is hostile: your bodyguards could be bribed and work against you, that's why you need to somehow be protected against that as well. Yeah, iPhoens are made that way as well. It's just caring about the privacy of your users. > When GrapheneOS says "private" and "secure", they mean top-of-the-line security features, updates as soon as possible, all available mitigations against zero-days and insecure code which will limit the impact before the patch, etc. Security as in a killdozer. I think it's deceptive because people think they will get better privacy/security with a /e/ fairphone when it's actually much worse than an iPhone.
- fsflover 13d ago
- deleted 13d ago[deleted]
- teekert 12d agoThe GOS people really spend a lot of time of energy showing the worst sides of FairPhone to the world. I think it is because the conscientious technology user is really interested in the combination of ethically sourced, repairable hardware and a security and privacy (from big tech) focussed OS. Tbh I also like that sliders to switch to a simple mode. A well, we can’t have it all. I do prefer de-googled + freedom to do what I want over security (to a degree). So… I’m on the fence. As many vocal people are. A second hand pixel 10 is also a “green” choice. I do have the feeling that many non-nerds can express the difference between all mentioned attributes, many just like FairPhone as an ethical phone. It’s not that simple, I agree.
- palata 12d agoSo I have been on /e/OS on a Fairphone 3+ for 4.5 years. I was really into /e/OS when I got my Fairphone. When it stopped being usable (not because the hardware was not working anymore, just that the apps I want on my phone were lagging so much they were unusable), I looked into alternatives, including GrapheneOS. And at that point I got quite disappointed by /e/OS, because I felt like their marketing had been abusing me for years. For instance, my Fairphone 3+ was 4 years behind the Fairphone Stock Android on some updates. /e/OS just wasn't forwarding them, they seemingly were just not maintaining the FP3. Though I bought it to /e/OS, under the promise that it would be supported! Then I realised that all this time, not only my bootloader was unlocked (so the Android security model had been broken from the first day I powered the phone), but the system was signed with the Google test keys! When you are encouraged to install apps "from the internet" instead of the Play Store, on a phone that disabled the security model so that you're not protected against malware as on any Stock Android, would you say it's being a security nerd? The thing that GrapheneOS keeps repeating and I realised is true is that many times, if you run a deGoogled alternative that is not GrapheneOS, you get worse security than if you were running Stock Android. It's not about "getting the best possible security", it's about getting the baseline. The truth with /e/OS (or LineageOS, which is pretty much what /e/OS ships, I believe?) is that it depends a lot on the phone. And with many phones, you get worse than the baseline you would get with Stock Android. > I do prefer de-googled + freedom to do what I want over security (to a degree). So I switched to GrapheneOS on a Pixel, and I feel like I get the best of both worlds: I get the privacy benefits of the sandboxed Play Services, and the better security. And it's not a "weird" system at all: I asked my family to use it and they didn't realise it was not a "normal Android". It is very different from running something like a Linux on mobile, which would be very very different. > many just like FairPhone as an ethical phone Yes, why not. If I was to get a Fairphone again, though, I would use the Stock Android. And I wish Fairphone could get to the level where they can be supported by GrapheneOS. But it feels like my next phone will probably be a Motorola with GrapheneOS rather than a Fairphone.