Earlier quoted context omitted.
It's paranoia to want ≥ security than an iPhone or stock Pixel?
It depends who you are. If you're Edward Snowden, or even a high ranking politician, it's a sane precaution. If you're just a rando like me yes, it's paranoia.
How Fairphone built the Fairphone Gen 6+
261–270 of 271 posts
Re: How Fairphone built the Fairphone Gen 6+
#262Earlier quoted context omitted.
>GrapheneOS is like a veteran and war zone expert: for them, not only the external environment is considered extremely hostile that you should leave your house only wearing an armor and with bodyguards, but also the internal environment is hostile: your bodyguards could be bribed and work against you, that's why you need to somehow be protected against that as well. Yeah, iPhoens are made that way as well. It's just…
> people think they will get better privacy/security with a /e/ fairphone when it's actually much worse than an iPhone Does /e/OS illegally collect users' data for ads and sends a lot of telemetry to their servers like Apple? https://news.ycombinator.com/item?id=34299433 , https://news.ycombinator.com/item?id=26639261
Re: How Fairphone built the Fairphone Gen 6+
#263Earlier quoted context omitted.
Android Open Source Project userspace code runs on any devices with Treble. That means it runs on any certified Android devices with the ability to install another OS. Updates and security features for the Linux kernel, drivers, firmware and hardware are still needed. Fairphone 5 and earlier have end-of-life Linux kernel branches without security support. Those lag multiple years behind on providing full Android secu…
In theory you can try to do that with Treble but in practice the experience will be horrible, there's not even a functional keyboard nor a functional call manager in there. And yes all the Linux side of things is still missing.
Linux does not mean glibc, systemd, Bash, GNU coreutils, Wayland/X11, Pulseaudio/Pipewire, etc. Android distributions are Linux distributions and are not missing what makes it Linux. The same goes for embedded and server Linux distributions without those components.
Re: How Fairphone built the Fairphone Gen 6+
#264The recently released Fairphone 6+ runs on Android 16. I had to look that up on Wikipedia, their website doesn't even clearly state that. Android 16 is 14 months old at the moment. Android 17 was released to manufacturers 6 months ago and had a general release 2 months ago. So why does a brand new phone run an operating system from over a year ago? Does it really take over 6 months to update a phone to a new version…
this is 100% in the hands of the SoC manufacturer. Android versions are locked to kernel versions, which are locked to binary drivers to run your hardware. there's no way around that and you can't reverse engineer or do anything if you want that SoC vendor to continue to fulfill your orders (which you're already at the bottom of the fulfilment list because of low volumes)
Android versions are not locked to kernel versions. In general, new Android versions do not require new kernel versions.
In practice, all kernel drivers are open source including for Snapdragon, Exynos and MediaTek. The kernel drivers can be ported to new major kernel versions regardless of whether the firmware and drivers are still supported. The benefit of updating the kernel and kernel drivers without firmware and userspace driver updates is very low. Rewriting the userspace driver code as open source code on top of the kernel drivers is also entirely possible. It's a lot of work and there's a lack of a security motivation to do it due to needing up-to-date firmware with patches for serious remote vulnerabilities and other issues.
Re: How Fairphone built the Fairphone Gen 6+
#265Ethical phone maybe only hardware wise, software wise with Google it is far from ethical
Nobody is suggesting Fairphone has also replaced Google/Android re SW/OS. What they've arguably done I'd improve the existing situation - surely that counts for something ? There is also nothing precluding them from dropping Android in the future and putting effort into something like Sailfish OS.
Unlike AOSP, SailfishOS has a largely closed source user interface and application layer. They still have their own UI and application layer so it's strange to portray Android using a different one than desktop Linux as a problem and a closed source alternative to it as a solution. SailfishOS drastically reduces privacy, security, usability, battery life and app compatibility compared to simply using AOSP. It's not possible to build a project like GrapheneOS on top when so much of the OS code is closed source rather than only many mainstream apps people want to use.
Re: How Fairphone built the Fairphone Gen 6+
#266Earlier quoted context omitted.
It doesn't because AOSP itself is unusable on a modern phone. It's just a low level technical building block nowadays and everybody is chosing the parts they want. Comparing your OS to AOSP itself made sense in 2016, it doesn't anymore in 2026. It make sense to compare the OS between each other, what you can actually install and use on the phone.
Do we agree that the Android security model is baked into AOSP? Or would you say that the Play Services bring the security model to Google-certified Android, GrapheneOS implements its own security model from scratch, and LineageOS as well? Assuming they share a big part of the security model, how would it "not make sense" to compare them? If AOSP is the baseline, saying that /e/OS is often weakening the security mode…
Yes I would say that most of the security decisions are not baked into AOSP and every rom brings their own decisions.
Re: How Fairphone built the Fairphone Gen 6+
#267Earlier quoted context omitted.
In theory you can try to do that with Treble but in practice the experience will be horrible, there's not even a functional keyboard nor a functional call manager in there. And yes all the Linux side of things is still missing.
That's not true. AOSP has a functional keyboard and Dialer app. There are also many third party apps for both available. Linux does not mean glibc, systemd, Bash, GNU coreutils, Wayland/X11, Pulseaudio/Pipewire, etc. Android distributions are Linux distributions and are not missing what makes it Linux. The same goes for embedded and server Linux distributions without those components.
Re: How Fairphone built the Fairphone Gen 6+
#268Earlier quoted context omitted.
Nobody is suggesting Fairphone has also replaced Google/Android re SW/OS. What they've arguably done I'd improve the existing situation - surely that counts for something ? There is also nothing precluding them from dropping Android in the future and putting effort into something like Sailfish OS.
Fairphone provides very poor updates much worse than iPhone, Pixel, Samsung flagship or many other devices. They lag far behind partial backports of security patches to older releases of Android. They lag a year or more behind full security patches which are not all backported to older Android releases, similarly to iOS. Fairphone 5 and earlier have an end-of-life kernel without security support and the same fate awa…
How can we verify all those claims?
Re: How Fairphone built the Fairphone Gen 6+
#269Earlier quoted context omitted.
> people think they will get better privacy/security with a /e/ fairphone when it's actually much worse than an iPhone Does /e/OS illegally collect users' data for ads and sends a lot of telemetry to their servers like Apple? https://news.ycombinator.com/item?id=34299433 , https://news.ycombinator.com/item?id=26639261
/e/ does have services collecting data on their users which isn't disclosed including user tracking via unique identifiers in the update client. They also spent years sending user speech data to OpenAI without informing users beyond fine print in the terms of use. It's presented as not using Google services but has a whole bunch of Google services with privileged access enabled by default. It even downloads and runs…
Source? And what else?
Re: How Fairphone built the Fairphone Gen 6+
#270Earlier quoted context omitted.
Do we agree that the Android security model is baked into AOSP? Or would you say that the Play Services bring the security model to Google-certified Android, GrapheneOS implements its own security model from scratch, and LineageOS as well? Assuming they share a big part of the security model, how would it "not make sense" to compare them? If AOSP is the baseline, saying that /e/OS is often weakening the security mode…
> Or would you say that the Play Services bring the security model to Google-certified Android, GrapheneOS implements its own security model from scratch, and LineageOS as well? Yes I would say that most of the security decisions are not baked into AOSP and every rom brings their own decisions.