Live data from Hacker News

Fairphone 6 wide camera experimental Linux support

nondescriptpointer.com

81–90 of 90 posts

Re: Fairphone 6 wide camera experimental Linux support

#81

Earlier quoted context omitted.

[flagged]

Different priorities. GrapheneOS prioritizes very strong security (inside a very specific model that includes treating the user as an attack vector to be protected against). Fairphone prioritizes repairable hardware (and actually makes their own hardware). On a finite budget (of both money and time and people), prioritizing either one of these will undermine the other.

No, GrapheneOS is a privacy project. Privacy depends on security which is the only reason we work on security too. /e/ and Fairphone both have much worse privacy than the standard Android Open Source Project on decent hardware. They go in the opposite direction from AOSP which GrapheneOS does for privacy.

Privacy depends on fixing widely abused privacy weaknesses by patching privacy vulnerabilities and shipping major privacy improvements. /e/ is missing many standard Android privacy patches and protections. Privacy also depends on security to avoid it being bypassed. It's also missing many of the standard Android security patches and protections. GrapheneOS preserves the baseline and makes major privacy and security improvements along with being far better at patching vulnerabilities rather than far worse.

/e/ and Fairphone don't do the bare minimum to protect user privacy and security by keeping up with updates. Both are missing crucial standard patches and protections needed against many real world adversaries including widespread privacy abuse by apps.

Re: Fairphone 6 wide camera experimental Linux support

#82
post #78

Earlier quoted context omitted.

Yeah, but I thing the best security is very important to the GrapheneOS developers, so I don't think they will ever compromise on MTE (except pre-Pixel 8) and a secure enclave. Of course, someone could fork GrapheneOS to support phones that don't fulfill the requirement. Also, I think fighting for the user is also true for e.g. LineageOS. As far as I know they are also a non-profit.

It is. But you can get almost all of the benefits on hardware without that. Someone has to port it, though - Graphene won't. Yes, it's also true for LineageOS and you can use that too.

No, you can't obtain almost all of the benefits of GrapheneOS on other hardware. Many of the benefits depend on having current privacy and security patches along with hardware-based security features.

Re: Fairphone 6 wide camera experimental Linux support

#83
post #71

Earlier quoted context omitted.

Sure, but then you have to run a different OS. That's completely fine of course, between Graphene, Sailfish, etc. there is a lot of interesting stuff happening.

The most important part of Graphene for most users isn't the super security - it's that it fights for the user, not for some corporation.

GrapheneOS is a privacy project making major privacy improvements. Privacy depends on security so that's why it improves that too.

Re: Fairphone 6 wide camera experimental Linux support

#84
post #46

Earlier quoted context omitted.

Fairphone 6 does not fulfill the hardware requirements (secure enclave, MTE, etc.), nor software requirements (monthly firmware updates, etc.). So there is nothing that GrapheneOS can do at this point. The ball is in Fairphone's court if they want this, but Fairphone seems more interested to cooperate with /e/OS, whose CEO proclaims security hardening is for pedophiles and spies (thereby fueling the narratives that s…

At this point in time any open source phone is a great improvement. Theoretically, we can add the security features ourselves.

It's not an open source phone. It's closed source hardware with closed source firmware. The closed source userspace drivers/services could be rewritten but the hardware and firmware isn't in the same situation.

Hardware and firmware level protections can't be added by software.

Software features based on hardware security features also can't simply be added without those. Translating code to add a software equivalent to MTE could theoretically be done but would make the code require several times more CPU cycles and several times more memory. You would need far higher performance hardware and a bigger battery for that to be practical. MTE is what GrapheneOS uses rather than that.

Re: Fairphone 6 wide camera experimental Linux support

#85

have fairphone looked into supporting GrapheneOS? what exactly is missing there other than "it's not Pixel"?

[flagged]

/e/ goes in the opposite direction from AOSP for privacy and security compared to GrapheneOS. It lags far behind on providing standard privacy/security patches and protections. It bundles their own privacy invasive services and has many built in Google services with privileged access. /e/ devices do not have reasonable privacy or security. People are much better off with an iPhone if they care about privacy.

https://discuss.grapheneos.org/d/24134-devices-lacking-stand...

Re: Fairphone 6 wide camera experimental Linux support

#86
post #23

have fairphone looked into supporting GrapheneOS? what exactly is missing there other than "it's not Pixel"?

A team of people patching and releasing firmware and hardware drivers to the public on a monthly basis.

It would need to provide that for around 7 years. It would need to avoid getting increasingly delayed over time. It would also need to provide the hardware-based security features required by GrapheneOS. That includes a proper secure element with the features we need and fully functional hardware memory tagging usable for all of the kernel and userspace. Motorola Mobility is working on providing what we need for next generation devices. Fairphone repeatedly expressed disinterest and is partnered with a company taking AOSP in the opposite direction from us for privacy and security. Fairphone replaced their own OS with that and it was a major downgrade moving them further away from possibly ever providing what we need.

Re: Fairphone 6 wide camera experimental Linux support

#87
post #9

Earlier quoted context omitted.

[flagged]

That's a pretty concrete list so it's unclear to me what you mean. They're also going to support some of the upcoming Motorola phones so it's not just pixels. I think the short answer of what they'd need to do in a practical way is to release a phone that uses one of the latest Qualcomm processors (those have the required hardware security features), make sure they have at least 5 years of driver support and commit t…

We say 5 years in the requirements but we want 7 and are starting to expect it. Pixels have provided 7 years since the Pixel 8. Qualcomm provides 8 years of support for new platforms and non-Pixel OEMs are using it to begin claiming to provide 7 years of support. However, we need the updates delivered on time and not becoming less frequent over time. For example, Samsung moving to quarterly updates for older devices isn't what we expect.

Re: Fairphone 6 wide camera experimental Linux support

#88

Earlier quoted context omitted.

[flagged]

It turns out that companies also 'attack' your phones to get your data. E.g. at some point Facebook/Yandex apps opened localhost sockets for tracking pixel code to connect to: https://localmess.github.io/

GrapheneOS largely prevented it for Vanadium before this came to light and fully fixed it long before Chromium did. Android 17 prevents cross-profile loopback connections, which is one of many important privacy improvements in it. Android 17 fixed a massive number of privacy weaknesses including vulnerabilities which will not have patches backported. Only a subset of High and Critical severity patches are backported to older Android releases. Only a subset of that subset are shipped by /e/ despite claiming to provide the latest patch level.

Re: Fairphone 6 wide camera experimental Linux support

#89

Earlier quoted context omitted.

The phrase "standing on the shoulders of giants" comes to mind. So what happened here? Shouldn't there be at minimum a framework for making a camera driver? Nope. They're gluing everything together and hoping it works.. Again. This is not standing on the shoulders of those that came before. It's the same issues year over year over year. It isn't trolling, it is calling out the highly non-optimal, "reinvent the wheel…

Linux on desktop and Linux on phone hardware are entirely different beasts. Phones have literally never been open. Historically telecommunications has kept a tight, tight grip on everything, hardware and software included. Even android, which is open source and based on Linux, cannot boot on any devices on earth without propriety blobs for the hardware. There is not UEFI or ACPI for phones, it doesn’t exist. The enti…

What are you talking about? Phones have been open for a very long time. Hundreds of thousands of Linux IoT devices are already on the air. Again, it is the Linux community that has never bothered to organize and put in the work to meet FCC and carrier standards for a consumer-grade phone. Here's v43 of the open guide that nobody from the Linux community wants to even begin working on: https://opendevelopment.verizonwireless.com/open-access/arti...

Re: Fairphone 6 wide camera experimental Linux support

#90

Another dev has been hard at work bringing Fairphone 6 Linux support for calls, audio, microphone, NFC, GPS, and IMU: https://blorp.piefed.zip/inbox/u/https%3A%2F%2Fani.social%2F... It's now probably the most modern well-supported pmOS phone.

Link broken... https://lemmy.ca/post/68231524
Post reply on HN