Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

For those of us out of the loop, could someone summarize the situation?
 help



  > Fairphone has said they don't plan to add a secure element. It can be seen from their current devices that they don't fully keep up with privacy/security backports and lag a year behind on shipping yearly OS releases. They skip over the monthly and quarterly releases entirely. They replaced their own non-GMS Fairphone OS with a dramatically less secure /e/OS option in partnership with Murena. They clearly demonstrate that security and even privacy are not the priorities.
https://grapheneos.social/@GrapheneOS/114733211017800480

They replaced their own non-GMS Fairphone OS with a dramatically less secure /e/OS

it sounds like they are saying that /e/OS is less secure than fairphone's own OS. with all criticism against /e/OS taken into account, i highly doubt that fairphone would have been able to make their own version of android more secure than /e/OS when they are not even interested in working on that.


It starts with simply rolling major releases out earlier than /e/OS. Remember that to get security fixes for vulnerabilities not marked high/critical, you need the QPR/major updates. Those vulnerabilities may not be an immediate RCE, but they might get used in exploit chains after an RCE. Also, Fairphone and /e/OS will have many known RCEs, because they do not roll out embargoed patches like GrapheneOS and to some extend Samsung & Pixel do.

as if fairphone ever did that: they don't fully keep up with privacy/security backports and lag a year behind on shipping yearly OS releases

so, again, how is /e/OS being behind on updates any worse than fairphone's own OS?


Android 16 was released on Fairphone 6 on March 16 2026. Yes, I know, way too late. The Android 16 build of /e/OS for Fairphone 6 was released on July 20 2026. Four months later. This was exactly the point of my comment.

fairphone probably rolls out a stock android release with little change whereas /e/OS has to forward port all its changes and patches on all the phones they support. maybe taking 4 months is to much for that, but that's most likely a resource problem that can probably best be solved by buying more murena phones.

It should be noted that GrapheneOS had similar criticisms about almost every smartphone vendor, including Motorola before their upcoming cooperation IIRC.

Most of their criticisms are valid, but they seem to be absolutely unwilling to make any compromise at all.

Not sure if they want to protect their brand, if any of those criticised issues would increase the work needed by them significantly, or why they are like that.

But I would prefer to have a slightly less secure GrapheneOS on many phones, that helps many many more users than just Pixel owners, over the current all or nothing situation.


> Most of their criticisms are valid, but they seem to be absolutely unwilling to make any compromise at all.

Making no compromise to security is the entire point of it's existence.


You can achieve the best security without compromises by not using any technology.

GrapheneOS making compromises on their requirements would signal that vendors producing low quality, less secure hardware and software is OK. On something as important as a secure and private smartphone, GrapheneOS not making compromises is actually beneficial to everyone. Maybe it is pushing these vendors to actully care a little more about secure hardware and software. The good thing is that if you actually want a good secure smartphone, you can buy a Pixel and install GrapheneOS.

One of the reasons I haven't switched to Graphene is this kind of drama. I wish there was more middle ground. I don't think the post is in any way constructive and will lead to fairphone to consider adding a secure element.

I don't see their post as 'drama' or nonconstructive at all. It's simply a list of well-founded criticisms of Fairphone's extremely lax position on security that is incompatible with Graphene's. If being critiqued for it doesn't lead to them considering adding a secure element, that's a problem on Fairphone's side imo.

The core criticism to the vendor is the missing security element. This is a fair point.

However, calling out on e/OS in the same post, seems to me very counter-productive. We need more OS vendors and less infighting. Calling all custom ROMs insecure and claiming to be the only one is IMHO 'drama'. Particular there are contributions of me microG that are helpful if you want to de-Google ones phone. Graphene has a different approach: fair. People will use GrapheneOS if they share their goals.

Fairphone is about sustainability and a bit about not supporting major tech like Google. I don't think this hurts. In an ideal world we could have both. But sustainability seems to be a non-goal of GrapheneOS.


I think in this context it's fair to call out /e/.

In some ways /e/ and GOS are trying to achieve different things (/e/ is not hardened and does not claim to be), but /e/ is severely lacking security wise compared to AOSP.

This [0] is, in my opinion, a fair review that mentions many of the issues. That Fairphone is ok with these is telling about their position on privacy and security.

[0] https://www.kuketz-blog.de/e-datenschutzfreundlich-bedeutet-...


> Calling all custom ROMs insecure and claiming to be the only one is IMHO 'drama'.

No, what it is is true. microG lets you de-Google a phone, but the resulting phone is provably less secure. If stating the truth causes "drama", the problem isn't the person or entity saying the true thing. If that truth shakes people, if it upsets them, they should look into the problem that truth has revealed (not created, as truth isn't something that exists only after someone speaks it) rather than blame those who are speaking it.

Can you provide evidence that GrapheneOS is less secure than LineageOS or other custom ROMs? Because GrapheneOS (and even leaked documentation from commercial adversarial phone hacking tools) provide a hell of a lot of evidence that it is, in fact, considerably more secure than just about every other phone OS in existence.


I am not saying that what they say is wrong. However, this is about current phones. If your goal is supporting aftermarket phones the case looks very different. It is the only way to get a decent level of security. The problem is IMHO how graphene communicates. It is mixing tons of different things to always make their communication more 'bold'. Then they complain about people complaining about their communication style. It is my personal choice, but I accept less security while not having to care about GrapheneOS announcements. I value their work in a similar way that I value WikiLeaks.

Imo i think actually naming the problems is a lot more productive than walking around them

To them Murena seems to be the biggest problem.



Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: