Earlier quoted context omitted.
Peripheral chips, non-standard bootloaders, custom hypervisors and similar is not what people mean when they say "run on a custom silicon".
? Even Steam Deck has a custom APU made specifically for it. Call it "customized" if you don't like "custom".
How Fairphone built the Fairphone Gen 6+
191–200 of 265 posts
Re: How Fairphone built the Fairphone Gen 6+
#192Earlier quoted context omitted.
I believe the GrapheneOS team demands, in particular, a security feature called Memory Tagging Extensions (MTE). This feature has a phone's processor attach a "tag" to each memory location saying what's stored there and requires accesses to that memory to bear a matching tag. Buffer overflow type attacks are effectively prevented because a read into the adjoining region having a different tag gets rejected. This feat…
While yes I am on GrapheneOS' side on these issues, I'm surprised nobody clones the GrapheneOS repo and simply disables the minimal handful of features which block it from working on devices. Maybe calling the clone CarbonOS? If MTE is required to boot GrapheneOS and Fairphones don't have MTE, then Fairphone clones GrapheneOS and disables MTE for its images. Graphene has so many features beyond just hardware security…
MTE is required for the majority of the additional protection provided by GrapheneOS against memory corruption exploits. Nearly all remote exploits and most local exploits involve memory corruption. MTE is only going to become more important as we implement deeper integration for it.
Re: How Fairphone built the Fairphone Gen 6+
#193Earlier quoted context omitted.
Peripheral chips, non-standard bootloaders, custom hypervisors and similar is not what people mean when they say "run on a custom silicon".
No, they mean customized SoCs which what those chips are as well
If that is true then a lot (or most) of android phones run on "custom silicon" and the term is meaningless.
Re: How Fairphone built the Fairphone Gen 6+
#194Earlier quoted context omitted.
Lack of MTE is not the only huge reason why the GrapheneOS team refuses most devices. Most vendors' lack of timely bugfixes for device-specific drivers and firmware, and no commitment to keep providing bugfixes for a number of years is another major factor.
Still, a 'degraded' GrapheneOS as my proposed CarbonOS, beats /e/, Lineage, Calyx, and stock. Not doing CarbonOS is throwing the baby (non-hardware hardening and features) out with the bathwater (the lack of hardware hardening). I for one do not wholly rely on Titan and use a long alphanumeric password on my primary profile to ensure BFU disk encryption isn't violated, while living in secondary daily-driver profiles…
The vast majority of users do not use a strong passphrase. The recommended high security setup is a strong passphrase and 2-factor fingerprint+PIN secondary unlock for convenience. Using a weaker PIN for secondary users for convenience is not our recommended approach.
Re: How Fairphone built the Fairphone Gen 6+
#195Earlier quoted context omitted.
I am a user. What does Android 17 do for me that 16 doesn't?
Since about 12 or so, it's been a series of cosmetic changes, bugfixes, and "AI" features.
You would be missing out on:
- Minimum Target SDK Enforcement Blocks installation of apps that target ancient versions of Android and legacy APIs.
- Restricted settings for sideloaded apps
- Null-Cipher rejection and 2G disabling
- Cell Network Surveillence Alerts
- Platform Rust Migration
- Scoped Media
Among many many unpatched Med and Low severity CVEs that don't get backported.
Re: How Fairphone built the Fairphone Gen 6+
#196Anyone have any updates on why this device can’t support or get behind Graphene OS? A repairable and secure phone is my desired option for a phone that’s truely mine and I’m sure this is true for many others also. From my understanding it’s not there as the Graphene team says that fairphone haven’t taken security hardware seriously and there’s key hardware security features missing that means they are not even intere…
I believe the GrapheneOS team demands, in particular, a security feature called Memory Tagging Extensions (MTE). This feature has a phone's processor attach a "tag" to each memory location saying what's stored there and requires accesses to that memory to bear a matching tag. Buffer overflow type attacks are effectively prevented because a read into the adjoining region having a different tag gets rejected. This feat…
Traditional desktop computers have atrocious privacy and security throughout hardware, firmware and software. That isn't a relevant comparison for GrapheneOS. Recent Mac hardware does support MTE and so will non-Mac devices using Snapdragon chips. Qualcomm has added MTE support for their latest flagship mobile SoC platform and will bring it elsewhere. MediaTek and Exynos have also added MTE support.
MTE does not have the substantial performance or battery life impact you're portraying it as having. It's also far more useful than you're portraying it as being. Apple would not have extensively integrated MTE if they had to give up significant performance or battery life. iPhones have a lot of focus on security but aren't willing to make significant sacrifices in those areas for it, at least for the default settings. Their Memory Integrity Enforcement entirely based on MTE is always enabled in the kernel and the large portion of userspace where they deployed it. It's not only used for Lockdown Mode.
Re: How Fairphone built the Fairphone Gen 6+
#197Not an expert, but I recently heard that apparently not everything is perfect in fairphone land: https://discuss.grapheneos.org/d/24134-devices-lacking-stand...
Seems you have to compromise on HW openness and ethics vs paranoia.
It isn't truly known how a Fairphone compares to an iPhone or Pixel when it comes to environmental impact or fairness to workers. Fairphones are designed and built by T2Mobile since the Fairphone 4. T2Mobile barely has any public information available about it. There isn't information on the working conditions, pay and other aspects of of it. The same applies to the rest of the supply chain. Fairphone provides a list of companies involved in the supply chain without details.
Re: How Fairphone built the Fairphone Gen 6+
#198Earlier quoted context omitted.
> I am not sure what you are trying to say here. I have never had an Android system that did not have OTA updates. Everything included... I usually like to install the apps I want? The last bit of my sentence could easily be misread as an enumeration of three things ("microG", "OTA updates", "everything included"), but it was actually an elaboration: FP is the only vendor to support microG, and (in contrast to "unoff…
> How about microG not contacting Google servers at all? I already addressed that in my comment, right after the line you quoted. > Letting Google handle push notifications is different from using them as your location provider, and both are different from letting all Play Services lose on your system. And what would you say GrapheneOS does of those? Do you know, or do you just assume that GrapheneOS does the worse t…
Where? You suggested it would go through Murena instead, but you can fully disable third party services by disabling external push providers and by using on-device databases for GPS. e/OS directly offers this configuration during initial setup.
> And what would you say GrapheneOS does of those? Do you know, or do you just assume that GrapheneOS does the worse there?
I'm not necessarily trying to present either as "better" or "worse" since they both have their merits depending what exactly you're after (which I don't feel this is the right time/place to have a detailed rundown of). It was the root comment that posited e/OS was strictly inferior for people who care about freedom.
Re: How Fairphone built the Fairphone Gen 6+
#199Earlier quoted context omitted.
Seems you have to compromise on HW openness and ethics vs paranoia.
> vs paranoia I really would like to mention that many times, using /e/OS or LineageOS (or the likes) means that you get worse security than Stock Android. It would be fine to run /e/OS or LineageOS on a Pixel, assuming those Android systems are not too slow with updates (my experience with my /e/OS phone was that they were 4 years behind as compared to Stock Android). But really, if you have a Pixel, it doesn't real…
Both /e/ and LineageOS lag far behind on current security updates on a Pixel. Neither is based on Android 17 yet which was released in June 2026. Neither has the June 2026 or later Pixel firmware, kernel, driver and HAL patches. Both also roll back the standard security of AOSP but /e/ does so much more than LineageOS.
Re: How Fairphone built the Fairphone Gen 6+
#200Earlier quoted context omitted.
It's paranoia to want ≥ security than an iPhone or stock Pixel?
those who give up freedom for security will end up losing both
Fairphones are closed source hardware with closed source firmware and closed source userspace drivers. Fairphones are less open than Pixels, not more open.
It isn't truly known how a Fairphone compares to an iPhone or Pixel when it comes to environmental impact or fairness to workers. Fairphones are designed and built by T2Mobile since the Fairphone 4. T2Mobile barely has any public information available about it. There isn't information on the working conditions, pay and other aspects of of it. The same applies to the rest of the supply chain. Fairphone provides a list of companies involved in the supply chain without details.