Live data from Hacker News

How Fairphone built the Fairphone Gen 6+

arstechnica.com

181–190 of 253 posts

Re: How Fairphone built the Fairphone Gen 6+

#181
post #167

Earlier quoted context omitted.

> For the "freedom nerds", FP is one of the only (if not the only?) vendor to have official support for microG-based operating systems, seamless OTA updates and everything included. I am not sure what you are trying to say here. I have never had an Android system that did not have OTA updates. Everything included... I usually like to install the apps I want? As for microG, I think it's debatable. Is it better to have…

[flagged]

> How about microG not contacting Google servers at all?

I already addressed that in my comment, right after the line you quoted.

> Letting Google handle push notifications is different from using them as your location provider, and both are different from letting all Play Services lose on your system.

And what would you say GrapheneOS does of those? Do you know, or do you just assume that GrapheneOS does the worse there?

Re: How Fairphone built the Fairphone Gen 6+

#182
post #159

Happy FairPhone 4 user here. Running 3+ years, only replaced the battery once. Aim to keep it 7-10 years, barring unforeseen events like theft. Not going to replace it just because a newer model is released.

> Aim to keep it 7-10 years Security updates will end 01 Sep 2028. https://endoflife.date/fairphone

Many important security updates will end much earlier. The table is based on how long Fairphone will provide incomplete security updates, not how long the device will truly receive security support.

Fairphone 5 and earlier have end-of-life Linux kernel branches without security support. Fairphone's more recent devices are headed to the same situation. In practice, the same thing happens with other components beyond the Linux kernel.

Re: How Fairphone built the Fairphone Gen 6+

#183

Earlier quoted context omitted.

[flagged]

While yes I am on GrapheneOS' side on these issues, I'm surprised nobody clones the GrapheneOS repo and simply disables the minimal handful of features which block it from working on devices. Maybe calling the clone CarbonOS? If MTE is required to boot GrapheneOS and Fairphones don't have MTE, then Fairphone clones GrapheneOS and disables MTE for its images. Graphene has so many features beyond just hardware security…

I think it would just be a lot of work. And if you went down that road, you would be against other teams with bigger marketing and a bigger community.

As in: people who do care enough to understand the technical arguments tend to go for GrapheneOS when they can. But if you build a "degraded GrapheneOS", you are not targetting those. For someone who doesn't care about what GrapheneOS brings, why would they use your system versus /e/OS?

DivestOS was a thing at some point, which was technically very interesting. But there wasn't much of a differentiator since the people who already cared about what DivestOS was doing were probably already looking at getting GrapheneOS.

Re: How Fairphone built the Fairphone Gen 6+

#184

I suppose it's a testament to their success, but, I have a fairphone 3 from almost 6 years now, and I'm a bit annoyed that they're basically "sunsetting it" (no more software updates, no more spare parts.) My fairphone 2 had lasted 5 years, but was completely unusable at the end. My current phone works very well (again, huge kudos to the team if anyone is reading this), and I would not mind trying to reach the decade…

Fairphone 5 are already in a similar situation due to the kernels no longer having security support with no plan to take it over or move to a newer branch. Fairphone's more recent devices are headed to the same situation. The same thing happens with other components beyond the Linux kernel. People are using the devices with the belief they're receiving security support that's not being provided.

Re: How Fairphone built the Fairphone Gen 6+

#185
post #10

Not an expert, but I recently heard that apparently not everything is perfect in fairphone land: https://discuss.grapheneos.org/d/24134-devices-lacking-stand...

[flagged]

Android Open Source Project userspace code runs on any devices with Treble. That means it runs on any certified Android devices with the ability to install another OS. Updates and security features for the Linux kernel, drivers, firmware and hardware are still needed.

Fairphone 5 and earlier have end-of-life Linux kernel branches without security support. Those lag multiple years behind on providing full Android security updates. The 1-2 month delays for partial security backports is compared to the Android security bulletins and is actually a much longer delay compared to when the patches are made available to ship by OEMs.

Re: How Fairphone built the Fairphone Gen 6+

#186
post #173

Earlier quoted context omitted.

[flagged]

> they also compare the security to the "Android Open Source Project" as if it's a real thing It is very much a real thing. You can build AOSP from sources and install it on a phone. Many Android devices run that (e.g. drone controllers). > Is certainly much better than my Samsung flagship Oh yeah, that's for sure. To share my experience, in terms of updates for me it has been GrapheneOS >>> Stock Android > /e/OS. I…

Fairphone's updates are definitely much worse than recent Samsung flagships. It's the other way around to an extreme. Samsung does monthly security patches for their flagships and includes a large subset of security preview patches. It's not as good as GrapheneOS security preview releases but they're ahead of the Android security bulletins.

Fairphone is 1-2 months behind the Android security bulletins which are themselves 2-4 months behind the security preview patches. Fairphone takes a year to port to a new OS version shortly after launch and then ends up taking increasingly more time.

Re: How Fairphone built the Fairphone Gen 6+

#187

[flagged]

Linux is a kernel. Embedded, server and mobile Linux distributions without glibc, gcc, GNU coreutils, systemd, D-Bus, Wayland, Pipewire, etc. are Linux too. Linux is not a specific desktop software stack that's largely used on FreeBSD and elsewhere too. Android Open Source Project and GrapheneOS are Linux distributions.

Re: How Fairphone built the Fairphone Gen 6+

#188

Earlier quoted context omitted.

MTE is not the only blocker here. Pixel 7 series do not have it and are currently supported by GrapheneOS. There are other concerns regarding things like a proper secure element implementation and timely firmware/binary blob updates.

Right, but still my CarbonOS idea ('degraded' GrapheneOS) is better than /e/, Lineage, Calyx, and stock. By 'degraded' I mean the minimal changes to current GrapheneOS needed to get it working on a given GrapheneOS-unsupported device.

An incomplete port of GrapheneOS to Fairphones will be missing many of the core security features and won't have reasonable security updates. Fairphones are nowhere close to reasonably secure devices.

Most people expect to have decent encryption without a strong passphrase, at least 5 years of security updates and a lot more. Fairphone says they provide updates far longer than they do for many components, and those come with substantial delays. Fairphone 5 and earlier have end-of-life kernels without security support. That's a very bad situation and is widely ignored. The more recent devices are headed to the same situation for the Linux kernel and other components.

Re: How Fairphone built the Fairphone Gen 6+

#189

Earlier quoted context omitted.

[flagged]

MTE is not the only blocker here. Pixel 7 series do not have it and are currently supported by GrapheneOS. There are other concerns regarding things like a proper secure element implementation and timely firmware/binary blob updates.

GrapheneOS requires MTE for any newly added devices. Pixel 6 and Pixel 7 series devices do not meet the current requirements. Pixel 8 and later are the devices meeting the full requirements.

Devices are supported until end-of-life rather than being dropped when they no longer meet the requirements. Pixel 6 is nearly end-of-life and Pixel 7 will be end-of-life in a bit over a year. Both have 5 years of updates from launch as opposed to 7 years for the Pixel 8 and later.

We want to require 7 years of updates for new devices rather than 5 but have left it at 5 to help budget devices meet our requirements.

Re: How Fairphone built the Fairphone Gen 6+

#190
post #166

Earlier quoted context omitted.

The GOS people really spend a lot of time of energy showing the worst sides of FairPhone to the world. I think it is because the conscientious technology user is really interested in the combination of ethically sourced, repairable hardware and a security and privacy (from big tech) focussed OS. Tbh I also like that sliders to switch to a simple mode. A well, we can’t have it all. I do prefer de-googled + freedom to…

So I have been on /e/OS on a Fairphone 3+ for 4.5 years. I was really into /e/OS when I got my Fairphone. When it stopped being usable (not because the hardware was not working anymore, just that the apps I want on my phone were lagging so much they were unusable), I looked into alternatives, including GrapheneOS. And at that point I got quite disappointed by /e/OS, because I felt like their marketing had been abusin…

Thanx for the thoughtful reply. You’re pulling me off the fence.
Post reply on HN