Live data from Hacker News

Fairphone is now officially available in the United States

fairphone.com

191–200 of 239 posts

Re: Fairphone is now officially available in the United States

#191

Earlier quoted context omitted.

>I want to like GrapheneOS, but the pettiness of its leadership is a real problem I used to feel a bit similarly. But I've since realized they are one of the very few software projects that actually make sensible privacy and security choices.

[flagged]

The privacy and security deficiencies of CalyxOS have nothing to do with compromises for usability. GrapheneOS provides much better usability including through having far broader app compatibility.

CalyxOS drastically reduces privacy and security compared to the Android Open Source Project. It recently went a whole year without privacy and security patches. They're currently months behind on providing current Pixel driver and firmware updates. It has never been a privacy or security hardened OS but rather the direct opposite.

Re: Fairphone is now officially available in the United States

#193

"[GrapheneOS] lost most interest in that hardware due to the poor way privacy, security, updates and marketing based on these things has been handled." https://discuss.grapheneos.org/d/28825-is-there-any-chance-o...

I'm sure their concerns are valid but just because GrapheneOS don't consider the Fairphone to meet their standards for security doesn't mean it is not worth considering for other people who may have different priorities. Fairphones have certain advantages over Pixels such as better repairability and more ethically sourced labour/components. IMO it's good to see the Fairphone do well (and I hope GrapheneOS's partnersh…

Fairphones have atrocious updates, privacy and security. They lag many months and even years behind on providing crucial standard privacy and security patches. They've failed to respond to the discovery of severe security issues including multiple of their devices using publicly available private keys for signing.

Fairphone lags months behind on providing Android Security Bulletin patches which are themselves delayed by months compared to when OEMs are first provided and allowed to ship the patches. They lag a year or more behind on major OS updates and count this as additional support time compared to other OEMs. For example, a final major OS update being delayed for 3 years is marketed as providing 3 more years of support compared to shipping it on time.

Fairphone 5 and earlier have an end-of-life kernel branch and the same fate awaits the Fairphone 6. Pixels move to newer kernel branches and are currently moving to 6.12 and then on to 6.18. Other OEMs are also beginning to use newer kernels and move to new branches. Linux LTS branches are only going to have 2 years of support going forward.

Fairphones are designed and assembled by an ODM. Fairphone has very limited involvement in engineering the devices. The working conditions and supply chain are also largely up to T2Mobile rather than Fairphone. Whether either of those are better than Pixels or especially iPhones should be demonstrated with evidence. There's extremely little information available on the working conditions, pay and other aspects of the assembly and supply chain for Fairphones.

Fairphone replaced their own open source OS without Google Mobile Services with /e/ as part of a close partnership with Murena. /e/ and Murena have repeatedly claimed highly private and secure devices mainly benefit criminals and pedophiles along with peddling other authoritarian talking points. They've falsely claimed GrapheneOS devices are mainly used by criminals and aren't useful to regular people.

https://www.clubic.com/actualite-604786-murena-e-os-intervie...

https://nitter.net/GrapheneOS/status/2040887784253141142

Despite the marketing, /e/ has very poor privacy and security. /e/ has their own invasive services with tracking, gives highly privileged access to default enabled Google services and doesn't keep up with basic updates. It greatly rolls back privacy and security compared to the Android Open Source Project.

https://codeberg.org/divested-mobile/divestos-website/raw/co...

https://eylenburg.github.io/android_comparison.htm

https://discuss.grapheneos.org/d/24134-devices-lacking-stand...

Re: Fairphone is now officially available in the United States

#194

Earlier quoted context omitted.

[flagged]

The privacy and security deficiencies of CalyxOS have nothing to do with compromises for usability. GrapheneOS provides much better usability including through having far broader app compatibility. CalyxOS drastically reduces privacy and security compared to the Android Open Source Project. It recently went a whole year without privacy and security patches. They're currently months behind on providing current Pixel d…

[flagged]

Re: Fairphone is now officially available in the United States

#195
post #89

Earlier quoted context omitted.

Not at running on sustainably produced, repairable hardware ;) (Wish it was though.)

You can buy used Pixels, e.g. from 8a up. I'd claim that this is much more ecological than buying a new Fairphone. I suppose that a Pixel is of a higher quality and has less defects than a Fairphone (which changed the ODM several times). -- This said, I would never use /e/ and Murena as I read too many things I don't like.

Fairphones have very poor updates with rapidly degrading privacy and security over their lifespan. They don't keep up with important updates from the beginning and it gets much worse over time. Updates are very important for sustainability. They're also missing important hardware-based security protections which are needed to protect user data in the real world. They've consistently had major issues such as using publicly available private keys for signing firmware and OS images which they've usually failed to acknowledge.

Fairphone 5 and earlier have an end-of-life Linux kernel branch with no movement to updating to a newer one. Fairphone 6 is set to end up in the same situation and it isn't far away. They nearly entirely stop providing Linux privacy and security patches once this happens.

Android patches come around half a year late since the Android Security Bulletins themselves are published very late and Fairphone lags 1-2 months or more behind those.

There's extremely little information available on Fairphone's ODM partner T2Mobile and their supply chain. The information is mainly a list of suppliers without information on working conditions, pay, environmental protection or nearly anything else. T2Mobile has been their ODM since the Fairphone 4 and earlier information is no longer relevant. They moved away from their original ODM partnership to another with the Fairphone 3 and then to T2Mobile with the Fairphone 4. It's unclear if pay and working conditions are better at T2Mobile for Fairphones than they are for their other products and in what way they're better. It's unclear how it comes to Foxconn for Apple and Google phones.

Apple and Google design their devices and handle the firmware and software. Fairphone is using hardware, firmware and software provided by T2Mobile. Fairphone is heavily reliant on what's provided by their ODM. For example, their move to T2Mobile coincided with dropping the 3.5mm audio jack. It's likely not something they wanted to do and many of their supporters were unhappy about it, but it's not really their phone hardware. The phones are essentially T2Mobile devices and there's not a lot of information available. It isn't clear why they switched to T2Mobile with the Fairphone 4 or why the earlier switch to another ODM happened with the Fairphone 3.

Re: Fairphone is now officially available in the United States

#197
post #29

Earlier quoted context omitted.

That does not seem like pettiness to me. That seems like a very good reason to not work with someone.

[flagged]

Fairphones continue to have awful updates, privacy and security. /e/ sending user speech data to OpenAI without consent for years never had anything to do with why Fairphones don't meet our requirements.

https://news.ycombinator.com/item?id=49354807

Re: Fairphone is now officially available in the United States

#198

"[GrapheneOS] lost most interest in that hardware due to the poor way privacy, security, updates and marketing based on these things has been handled." https://discuss.grapheneos.org/d/28825-is-there-any-chance-o...

i dont get it, they are comparing eOS to graphene, not talking about the hardware. this would be like grapheneOS not using pixel because the stock android that ships with it does not respect privacy. am i missing something?

Fairphones have awful updates for the firmware and drivers with months of delays. They end up with an end-of-life Linux kernel and hardware components. Fairphone 5 and earlier have end-of-life kernels which aren't receiving the vast majority of important privacy and security patches.

They're missing crucial industry standard hardware security features. They don't provide proper encryption protecting user data for the vast majority of users not setting a very strong passphrase.

The main hardware and update requirements for GrapheneOS are listed here:

https://grapheneos.org/faq#future-devices

We left another reply at https://news.ycombinator.com/item?id=49354807 with more details on how Fairphone doesn't meet those requirements.

Re: Fairphone is now officially available in the United States

#199
post #134

Earlier quoted context omitted.

You still need to rely on the OEM to properly configure the bootloader, not leak the keys, and provide updated vendor blobs.

[flagged]

Fairphone lags many months behind on Android privacy/security patches. They also end up with an end-of-life Linux kernel without the vast majority of the most important patches which is the case for the Fairphone 5 and earlier. It's not far away for the Fairphone 6. Moving to new Linux kernel branches is an expectation by Google and the upstream Linux kernel for OEMs but Fairphone isn't doing it.

Fairphone replaced their own open source OS with /e/ as part of a close partnership with Murena. That's why those are relevant. Fairphones without /e/ still lack reasonable privacy and security, but they're a lot worse with it.

/e/ and Murena have very poor privacy and security for their products combined with very inaccurate marketing. They've repeatedly portrayed private and secure devices as mainly benefiting and being used by criminals and pedophiles. Those are their own explicit choices of words. They've claimed this dozens of times about GrapheneOS including alongside France's national agencies making these inaccurate claims. More information with sources:

https://nitter.net/GrapheneOS/status/2081837057433915603

Re: Fairphone is now officially available in the United States

#200

Earlier quoted context omitted.

The privacy and security deficiencies of CalyxOS have nothing to do with compromises for usability. GrapheneOS provides much better usability including through having far broader app compatibility. CalyxOS drastically reduces privacy and security compared to the Android Open Source Project. It recently went a whole year without privacy and security patches. They're currently months behind on providing current Pixel d…

[flagged]

An operating system going a year without providing privacy and security patches is much worse than many options on that basis alone. It's currently months behind on updates. It's hardly the only other option available.
Post reply on HN