Hacker Timesnew | past | comments | ask | show | jobs | submitlogin

What do they need to support to convince you? Providing all hardware features required by GrapheneOS is not feasible for a small company.


Fairphone doesn't design or make their smartphones. The devices are designed and made by a large ODM. It's entirely feasible to use a modern SoC with current generation security features and provide proper updates. Their ODM isn't doing it to cut costs.

Fairphone quickly stops providing Linux kernel updates and has months of delay for Android userspace backports along with driver/firmware backports. The delay for yearly updates typically starts at a year and gets longer as devices get older and they've always skipped the quarterly updates.

Using a modern SoC, properly configuring it, using proper signing keys (Fairphone has repeatedly used publicly available sample private keys) and providing proper updates is most of what's needed to meet the requirements. That's entirely doable by the few OEMs designing their devices in-house such as Motorola Mobility. Samsung and Google along with many of the ODMs making devices for Nothing, Fairphone, etc.

https://discuss.grapheneos.org/d/24134-devices-lacking-stand...


> What do they need to support to convince you?

I know you're already aware of this because it's been provided to you before, but for the folks reading at home, here are the device requirements: https://grapheneos.org/faq#future-devices


You completely missed the context here. my comment was not about skipping the security features of GrapheneOS. The original parent comment was

> No, them supporting e/OS corroborates the claim that their goal is not privacy or security.

and I asked how they could be convinced about Fairphone's intentions given that the company is tiny and can't develop Pixel-level hardware.


I didn't miss the context.

You can't simultaneously claim (incorrectly) that they're incapable of shipping secure hardware while claiming that they intend to ship a secure and private device. (Maybe Fairphone 7 will be the one.) Even if that is is their intention, they're doing a good job keeping it a secret, as their site's main traffic drivers talk solely about environmental ethics and the climate.

Several companies are shipping devices with worthwhile hardware security, and the standards are fairly well enumerated at the link I provided. If Fairphone's intention is to ship reasonably secure hardware then they're failing miserably at it. Same goes for their choice of OS.

Again, that link wasn't for you. You've been told all this stuff for many years. It's for anyone who trips over the thread without already knowing the sheer tonnage of misleading and often downright factually false statements you continually dump in these threads.


Your accusations and personal attacks already go beyond any limits here. Please stop, as this is explicitly against the HN Guidelines. Especially, without clear links/evidence, as here. Anyone who trips over the thread should know this, too.

Fairphone has a very clear goal of sustainability, which doesn't contradict cutting-edge security per se, but given how tiny the company is, makes it practically impossible. This doesn't mean they wouldn't add the security features if they could. You also like to falsely accuse all vendors producing alternative hardware to Google Pixels, like this one or, earlier, Librem 5 (which btw has the same problem with the small company and big goals).


You can't call comprehensive replies "disingenuous walls of text" and then later complain about a lack of thoroughness when people stop finding it worth the time. You've done it extensively with me and others. That's not an attack or accusation, it's there to see with years of history of you doing the same things to people from casual observers (me) to some of the most qualified participants in the industry.

I'm comfortable with others taking in everything and drawing their own conclusions. That's my only motivation for engaging at this point.

For example, Fairphone has something approaching 200 employees. They're punching well below their weight on the security side, both in terms of hardware and software. Defend them all you want but their approach to security is objectively poor. Repairability and sustainability are good concepts, but not if the device fails at being a decently secure device, which it does. If there's a good reason they can't spec out a better device to be made for them and properly support it, I haven't seen them state it. I wish they would because they've made some pretty neat devices over the years. But a neat device with poor hardware security is an absurd build target to burn finite dev hours on. Something which has been explained to you many times.

Purism, on the other hand, likely can't produce a phone that has security remotely approaching any one of a number of contemporary phone options (beyond just Apple/Google). As you say, they're too small and probably spread too thin. They could stand to dial back their claims to match their reality. They still haven't made a dent on significant issues they themselves flagged more than a half decade ago. Its modem runs on a bus so untrustworthy you probably run a disposable sys-usb Qube on your computer. But that's OK, because you only run trusted software, etc. To each their own.


> You can't call comprehensive replies "disingenuous walls of text" and then later complain about a lack of thoroughness when people stop finding it worth the time.

It doesn't matter how bad a comment looks in your opinion - you have no right for an unsubstantiated personal attack, ever. I though this was common sense, but it turns out, for some people, it's important to remind that.

I never complain about the length of comments but about how much substance they have relative to their length. For example, in this comment, you have expressed your opinion reasonably well* only after two paragraphs of unrelated venting. I have the impression that you consider any opinion that differs from yours as an attack on GrapheneOS and yourself.

Look, I am not against GrapheneOS and I don't care about you. I recommend GrapheneOS to my friends when they want maximal security (yes, really!). I upvote posts like this for visibility. I do not consider GOS an enemy of GNU/Linux phones. I don't like some of GOS decisions, but this is fine, it is just not for me. I don't claim that Librem 5 is more secure or more private. This depends on the user goals and threat model. There are people like me who value different things than GOS developers, and to such people I recommend to consider GNU/Linux phones. I do not post comments saying that GOS has "atrocious freedom" or anything like that. It has more freedom than the default. It's really good at what it does. But it can't cover all preferences and use cases. Whenever people ask for something that GOS doesn't want to provide, I suggest an alternative. I don't understand why you start a fight every time this happens. These are not the target audience of GrapheneOS, let it go.

*I disagree, but I don't expect to convince you. Let us just agree to disagree here.


> Providing all hardware features required by GrapheneOS is not feasible for a small company.

Supporting all hardware required by fsflover is not feasible for a small project.




Consider applying for YC's Fall 2026 batch! Applications are open till July 27.

Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: