I am still waiting for Fairphone and Graphene OS collaboration. This is match made in heaven. Any Fairphone/GrapheneOS developer reading this? Just do it, document if something is not secure enough for you, but do it. Nothing to think about, you fit together like hand and a glove and any seconds thoughts are depriving the planet of THE PHONE! Pick the cash we will throw at you and make second generation with the cpu…
I recently suggested that GrapheneOS support devices with average security on Mastodon. Much like yourself, I think "moderately okay security" is better than "just use Google's spyware infested OS". The GrapheneOS folks replied in disagreement, insisting that this is a terrible idea because security would be less than perfect. They then started making up stories about me and throwing around unfounded accusations. I d…
People involved with the project you're working on have a history of making attacks on GrapheneOS, but what I mostly want to focus on is your suggestion because my goal here isn't to get in a back-and-forth with you or convince you, but rather provide context for others reading this.
Our hardware requirements are not arbitrary. They are what we need in order to be able to provide usable security to people who depend on it. There's no "average security" for devices that are missing patches for known vulnerabilities for months. That's a non-starter, not something imperfect that an OEM can work on improving. Multiple OEMs have reached out to us and actually want to do the work of improving their devices so that we can use them to provide security for people. It's very weird for people to be fixated on this idea that GrapheneOS should instead be supporting devices which can't actually provide what the OS is known for.
Without a secure element, a 6 digit PIN is no longer secure and can be bruteforced. What average person is using a long diceware passphrase to unlock their phone? Our device requirements are reasonable, and can be found at https://grapheneos.org/faq#future-devices. Every time people ask us to support another device, we have to point to that explain that we cannot, because to date, no other devices meet them, and those who do purposefully go out of their way to cripple third-party OS support (Samsung chief among them). Then, we ask people which of our requirements we should drop in order to support that other device, and why people think that requirement is unreasonable. To date, we have received no convincing reply to that.
You think we're chasing "perfection" but Pixels are just the best that exists right now and is extremely far from perfect. Our requirements aren't a wishlist, they're based on what is possible and reasonable today, not in the future.