Live data from Hacker News

How Fairphone built the Fairphone Gen 6+

arstechnica.com

221–230 of 252 posts

Re: How Fairphone built the Fairphone Gen 6+

#221
post #168

Earlier quoted context omitted.

> However, GOS's threat model very specifically treats the user as a thing to defend against Can you elaborate? GOS mostly honours the Android security model, which many alternatives don't do (many times they don't have a choice because the device doesn't allow them to relock the bootloader, so they just defeat the whole security model from the moment you install). There is absolutely nothing that can be done on a St…

[flagged]

Since we're steelmanning, I would like to add a bit more.

GrapheneOS will never be closed source/proprietary because they believe code freedom (and user freedom by extension) is paramount. They have repeatedly said they don't have the resources to build a ChromeOS-esque firmware authentication and warning flow for ephemeral user-accessible root and support those builds alongside the existing production environment. They have NOT said it is something they have no interest in even discussing. They have also repeatedly said that where the utility is clearly demonstrated and can be architected in a maintainable way, they are open to contributions (and continued maintenance) that properly enable functions that people unnecessarily need to abuse root privileges for.

The main goal of their project is a system that can protect your personal thoughts, associations and memories to the best of its ability (against thieves, attackers, surveillance etc.) while preserving your interaction with the world. Current OSes (including GrapheneOS and iOS) are already far behind where they should be given the wealth of privacy enhancing technology, computer hardware security, systems engineering and OS design knowledge that has existed for decades- so their work is cut out for them and they are putting everything they have into leading the industry. Their hands are already full. For clear use cases the path of least resistance would be to contribute and commit to maintaining features everyone would benefit from.

If it is a feature/function someone understands they would benefit from personally but do not see the value to impose on others, we can circle back to the original fact which is that GrapheneOS is open source and can be bent/built to your will.

Re: How Fairphone built the Fairphone Gen 6+

#222

Earlier quoted context omitted.

I had the same experience. Repeatedly. IMO it's the software, not the hardware. The issues always start/get worse with a big update to Android or the main Google apps.

running the official bloatware (firmware) I presume? It happened to me when I was using shitty brands like Xiaomi that include a lot of malware and spyware in their official firmwares. Not anymore on grapheneOS (and /e/os on my daughter's phone).

The official firmware, yes, but also Fairphones for years, not Xiaomi or the like (FP2 -> FP3 -> FP5 now). So the "bloat" in question is the Google stuff.

Re: How Fairphone built the Fairphone Gen 6+

#223
post #176

Earlier quoted context omitted.

[flagged]

A problem I see is that GrapheneOS has a history of being extremely blunt about the shortcomings of alternatives, and of course alternatives (and users of alternatives) don't like getting that feeling that maybe they have been compromising on... something . At least that's how I felt when I starting reading more after a few years of using /e/OS on my Fairphone 3. And the more I read, the more I realised that Graphene…

Yeah it's hard to argue that their points are technically incorrect, after all this is the mobile ARM ecosystem we're talking about, with buggy ass locked down binary blobs with more security holes than swiss cheese that are never updated, as the industry standard. And in regards to Fairphone, user reviews have generally shown that their disregard for keeping their software updated by far eclipses any gains made by the repairability aspect. And I can sort of respect being brash about pointing the flaws out.

My main source of contention with Graphene is more ideological in the way they've gone about doing something about it: by using the Pixel. To quote that old batman comic meme: "This is the weapon of the enemy. We do not need it. We will not use it." At the end of the day, Google gets $1k or thereabouts for every GrapheneOS install which they can use to further advance the cause of mass surveillance, as an adware firm they have the most misaligned incentives of any manufacturer in existence. The company that is almost too eager to cave to every whim of the fascist in chief in hopes of it benefiting their bottom line. That's what I see as insanely hypocritical. By being this exclusive, it counts as a complete endorsement.

Re: How Fairphone built the Fairphone Gen 6+

#225

Earlier quoted context omitted.

Going from separate ports to one port, when its easy to yank the headphone cord and ruin the usb-c so now you can't charge your phone is great. I've tried those dongles and they are all a huge hassle compared to just having a headphone jack built in.

Well yes, I agree, but the option is there.

I think I'd rather stick with a phone that has a separate headpones port.

Re: How Fairphone built the Fairphone Gen 6+

#226
post #101
post #84

Earlier quoted context omitted.

How do you charge your phone while listening to music?

put this on your music device: https://images.thalia.media/-/BF2000-2000/939d34e30a3d4f6587...

How is that better than having a dedicated headphones port?

Re: How Fairphone built the Fairphone Gen 6+

#227
post #159

Earlier quoted context omitted.

> Aim to keep it 7-10 years Security updates will end 01 Sep 2028. https://endoflife.date/fairphone

Many important security updates will end much earlier. The table is based on how long Fairphone will provide incomplete security updates, not how long the device will truly receive security support. Fairphone 5 and earlier have end-of-life Linux kernel branches without security support. Fairphone's more recent devices are headed to the same situation. In practice, the same thing happens with other components beyond t…

[deleted]

Re: How Fairphone built the Fairphone Gen 6+

#228
Fairphone issue an annual director's report, has financial audits and list the titles of each director. You can easily find the name of and information about the CEO. They have an Impressum section on their site along with many other legal documents.

This is more than can be said about other projects in this space

Re: How Fairphone built the Fairphone Gen 6+

#229

Earlier quoted context omitted.

At the moment there is no other hardware manufacturer making similarly secure android phones. *NONE* There is no android hardware coming close. If there is, please name it. As far as I know it's only some unspecified, upcoming Motorola flagships. If you call the unwilling, pragmatic choice an "intense hypocrisy", it's pretty clear to me you're simply driven by emotions and tribalism, that the facts don't matter. Are…

> NONE That's exactly my point. Imagine for a second that there's no Pixel. What would GOS do? They could either ship nothing at all because suddenly nothing fits their made up standards, or they would have to lower them to fit reality. The standards are there only because the Pixel exists to fit them. I think it's highly suspicious that they've set their demands up so that only one device fits the bill, if this wasn…

Huh, that one is funnier than I thought it could be.

There's absolutely no love for Google in the GOS crowd. None at all.

Now quick TL;DR so you can't pretend you missed something:

- It seems that GOS will support the new, secure Motorola flagships from the day 1. There's been an extensive support from vendor and much energy in the GOS team. There's hope Pixels can be abandoned - GOS exists because there's a secure hardware from a vendor that releases all the necessary patches and offers long support. That's the secret. Please suggest the alternative hardware. - Since you claim they “make up standards”, I invite you to list security features that are in your opinion superficial

- - -

LOL, all your suspicions are already answered, probably hundreds of times, starting from the very document you allude you read, https://grapheneos.org/faq#future-devices

And silly as it might be, chances are that all the devices that will fit these requirements will be supported.

>> NONE > That's exactly my point. Imagine for a second that there's no Pixel. What would GOS do?

Or, imagine your family woke up and turns out you never existed, what do they do now?

They develop the OS because there were secure devices they could develop their OS on. If you discuss based on the facts (I have my suspicions), you probably seem a list of the past devices no longer supported, but something they worked on

> They could either ship nothing at all

If there's no pixel they can't ship for pixel

> because suddenly nothing fits their made up standards,

Are you referring to the modest expectations for the mobile devices holding all the personal information and often access to whole live of the owner?

When you're buying a lock or alarm system for your home, what are your expectations? To me it seems you'd settle for the “absolute worst, something that can be bypassed with a butter knife, can't make life of the criminals too hard”

>made up standards,

Which one are made up? I'd like to see which one would you like to go.

- Making patches available quickly? Firmware patches? Frequent AOSP code releases? - 5+ years of updates? Modern Linux kernel? - Isolated radios, hardware secure element with throttling, protecting from attacks known from 90s? - Full verified boot support with A/B slots, rollback protection (so the attacker cannot trivially just flash the ancient, vulnerable firmware), custom keys and relockable bootloader? Absolute bog standard, yet still not provided by MOST android hardware vendors - Or, I don't know, MTE? Disk encryption? Protection for brute forcing disk encryption?

Which ones are “made up”, can you list the exact ones?

>or they would have to lower them to fit reality.

what reality? Vendors that allow, in 2026, to brute force PIN at the full speed? Or those who do not support custom signing keys, so the verified boot cannot be turned on? Or maybe these who do not offer relockable bootloader at all? Or maybe vendors known for delaying critical patches for months or don't offer any patches AT ALL (like one vendor still selling Android 15 devices, 6 months after the release of 17, when it's well known most bugs don't get backported patches)?

Can you give us a list of 2-3 modern devices that should have official GOS support?

>The standards are there only because the Pixel exists to fit them.

And this is a barefaced lie, need to call a spade a spade.

>I think it's highly suspicious that they've set their demands up so that only one device fits the bill,

Also lie, and a lazy one, it's 21 devices today. Oh well, I'll be charitable - maybe you just didn't check.

>if this wasn't FOSS people would be calling up anti-trust and asking how much Google paid them for regulatory capture.

By gods, what regulatory capture :D Do you just smash words together? Can you explain how GOS does, eeee, regulatory capture? :)

Oh, or maybe you're saying GOS forbids anyone from literally forking their repos and building own images?

What is that GOS does that stops you from adapting their releases to your own insecure, unpatched device? I really need some specifics.

>Similarly, if there was a device that's more secure than the Pixel, would GOS support both, or reowise their rules so it only fits whatever they want? I guess we'll see once the Motorola lands.

And this is the passage that tells me you're not discussing in a good faith. Work with Motorola on their flagships (plural) are well advanced, the expectation is they will be supported from the day of the release.

>But no, I'm saying using Google hardware is directly financially supporting the closed ecosystem of corporate control they're trying to fight against.

What? :D OK, so how much of the revenue Google has from the Pixel phone sales and what percentage of their revenue is that (I'm especially curious how it looks like next to ad earnings (direct and admob, etc), Google Cloud and Search.

What is the value of this argument? In % of Google revenue or B USD.

>And if we do go down speculation lane

No, not we, you do.

>I wouldn't find it impossible for Google to build in their own hardware level backdoors.

And THIS precisely is why GrapheneOS standards are so high, so if the crooked engineers or hardware exploits exist, the device still remain as secure as possible.

At this moment we either have to choose between a remote possibility of the highly sophisticated hardware backdoors that might be exploited by a nation state, or a hardware that is so insecure every thief can break into it in minutes.

I know which one I prefer. Which one do you want everyone to prefer? Seeing you're vocally against GOS on pixels, why do you insist on everyone moving to much less devices?

>Given that Snowden is still alive, I suppose it's unlikely,

And now we're at Dan Brown level of suspense

>but the conflict of interest is clear as day here.

Only if you've been staring into the sun for too long.

None of your allegations are new, they've been extensively addressed already.

Re: How Fairphone built the Fairphone Gen 6+

#230
post #63

Earlier quoted context omitted.

Since about 12 or so, it's been a series of cosmetic changes, bugfixes, and "AI" features.

This is largely untrue. You would be missing out on: - Minimum Target SDK Enforcement Blocks installation of apps that target ancient versions of Android and legacy APIs. - Restricted settings for sideloaded apps - Null-Cipher rejection and 2G disabling - Cell Network Surveillence Alerts - Platform Rust Migration - Scoped Media Among many many unpatched Med and Low severity CVEs that don't get backported.

> Minimum Target SDK Enforcement Blocks installation of apps that target ancient versions of Android and legacy APIs.

Funny to list a user-hostile change as the first “improvement” that comes to mind.

I guess GP should have said “series of cosmetic changes, and breaks in your UI habbits and a few of your apps deemed too old”.

Post reply on HN