Live data from Hacker News

How Fairphone built the Fairphone Gen 6+

arstechnica.com

261–265 of 265 posts

Re: How Fairphone built the Fairphone Gen 6+

#261

Earlier quoted context omitted.

It's paranoia to want ≥ security than an iPhone or stock Pixel?

It depends who you are. If you're Edward Snowden, or even a high ranking politician, it's a sane precaution. If you're just a rando like me yes, it's paranoia.

GrapheneOS provides massive privacy and security benefits to regular people. That was always important to regular people due to regular devices being nowhere close to good enough to protect people well enough against common threads to their privacy. However, it's far clearer now that exploits have been made so widely available without having expertise. There are many publicly available Android local root exploits on GitHub usable on these devices.

Re: How Fairphone built the Fairphone Gen 6+

#262

Earlier quoted context omitted.

>GrapheneOS is like a veteran and war zone expert: for them, not only the external environment is considered extremely hostile that you should leave your house only wearing an armor and with bodyguards, but also the internal environment is hostile: your bodyguards could be bribed and work against you, that's why you need to somehow be protected against that as well. Yeah, iPhoens are made that way as well. It's just…

> people think they will get better privacy/security with a /e/ fairphone when it's actually much worse than an iPhone Does /e/OS illegally collect users' data for ads and sends a lot of telemetry to their servers like Apple? https://news.ycombinator.com/item?id=34299433 , https://news.ycombinator.com/item?id=26639261

/e/ does have services collecting data on their users which isn't disclosed including user tracking via unique identifiers in the update client. They also spent years sending user speech data to OpenAI without informing users beyond fine print in the terms of use. It's presented as not using Google services but has a whole bunch of Google services with privileged access enabled by default. It even downloads and runs Google Play executables such as droidguard by default with privileged access far beyond the regular app sandbox.

Re: How Fairphone built the Fairphone Gen 6+

#263

Earlier quoted context omitted.

Android Open Source Project userspace code runs on any devices with Treble. That means it runs on any certified Android devices with the ability to install another OS. Updates and security features for the Linux kernel, drivers, firmware and hardware are still needed. Fairphone 5 and earlier have end-of-life Linux kernel branches without security support. Those lag multiple years behind on providing full Android secu…

In theory you can try to do that with Treble but in practice the experience will be horrible, there's not even a functional keyboard nor a functional call manager in there. And yes all the Linux side of things is still missing.

That's not true. AOSP has a functional keyboard and Dialer app. There are also many third party apps for both available.

Linux does not mean glibc, systemd, Bash, GNU coreutils, Wayland/X11, Pulseaudio/Pipewire, etc. Android distributions are Linux distributions and are not missing what makes it Linux. The same goes for embedded and server Linux distributions without those components.

Re: How Fairphone built the Fairphone Gen 6+

#264

The recently released Fairphone 6+ runs on Android 16. I had to look that up on Wikipedia, their website doesn't even clearly state that. Android 16 is 14 months old at the moment. Android 17 was released to manufacturers 6 months ago and had a general release 2 months ago. So why does a brand new phone run an operating system from over a year ago? Does it really take over 6 months to update a phone to a new version…

this is 100% in the hands of the SoC manufacturer. Android versions are locked to kernel versions, which are locked to binary drivers to run your hardware. there's no way around that and you can't reverse engineer or do anything if you want that SoC vendor to continue to fulfill your orders (which you're already at the bottom of the fulfilment list because of low volumes)

Qualcomm provides 8 years of support from platform launch.

Android versions are not locked to kernel versions. In general, new Android versions do not require new kernel versions.

In practice, all kernel drivers are open source including for Snapdragon, Exynos and MediaTek. The kernel drivers can be ported to new major kernel versions regardless of whether the firmware and drivers are still supported. The benefit of updating the kernel and kernel drivers without firmware and userspace driver updates is very low. Rewriting the userspace driver code as open source code on top of the kernel drivers is also entirely possible. It's a lot of work and there's a lack of a security motivation to do it due to needing up-to-date firmware with patches for serious remote vulnerabilities and other issues.

Re: How Fairphone built the Fairphone Gen 6+

#265
post #40
post #28

Ethical phone maybe only hardware wise, software wise with Google it is far from ethical

Nobody is suggesting Fairphone has also replaced Google/Android re SW/OS. What they've arguably done I'd improve the existing situation - surely that counts for something ? There is also nothing precluding them from dropping Android in the future and putting effort into something like Sailfish OS.

Fairphone provides very poor updates much worse than iPhone, Pixel, Samsung flagship or many other devices. They lag far behind partial backports of security patches to older releases of Android. They lag a year or more behind full security patches which are not all backported to older Android releases, similarly to iOS. Fairphone 5 and earlier have an end-of-life kernel without security support and the same fate awaits the newer devices.

Unlike AOSP, SailfishOS has a largely closed source user interface and application layer. They still have their own UI and application layer so it's strange to portray Android using a different one than desktop Linux as a problem and a closed source alternative to it as a solution. SailfishOS drastically reduces privacy, security, usability, battery life and app compatibility compared to simply using AOSP. It's not possible to build a project like GrapheneOS on top when so much of the OS code is closed source rather than only many mainstream apps people want to use.

Post reply on HN