• toph@feddit.uk
    link
    fedilink
    English
    arrow-up
    0
    ·
    22 days ago

    It still sucks for security. If you own this phone you should consider that the authorities and pretty much anyone who really wants to can get into your phone at will. I wish they could meet Graphene’s hardware requirements.

      • FeelThePower@lemmy.dbzer0.com
        link
        fedilink
        English
        arrow-up
        0
        ·
        22 days ago

        nah. grapheneos requires open source drivers and immediate security updates from the oems as well as an unlockable bootloader. pixel just happens to be the only one who fits the bill for all of those. as an example, the Samsung I had before my pixel wouldn’t get security updates for months after an Android release which was really annoying. Motorola will soon comply with these standards too, but they have their own line of flock camera alternatives so I won’t be touching their products with a 10 foot pole.

      • toph@feddit.uk
        link
        fedilink
        English
        arrow-up
        0
        ·
        edit-2
        21 days ago

        No lol, they have a list of specific hardware security requirements for a device to have, the biggest one being a secure element. Without a secure element there is no hardware-backed key derivation throttling, so it’s much more possible for an attacker to brute force your phone’s PIN.

        Support for using alternate operating systems including full hardware security functionality
        Complete monthly Android Security Bulletin patches without any regular delays longer than a week for device support code (firmware, drivers and HALs)
        At least 5 years of updates from launch for device support code with phones (Pixels now have 7) and 7 years with tablets
        Device support code updated to new monthly, quarterly and yearly releases of AOSP within several months to provide new security improvements (Pixels receive these in the month they're released)
        Linux 6.1, 6.6 or 6.12 Generic Kernel Image (GKI) support
        Hardware accelerated virtualization usable by GrapheneOS (ideally pKVM to match Pixels but another usable implementation may be acceptable)
        Hardware memory tagging (ARM MTE or equivalent)
        Hardware-based coarse grained Control Flow Integrity (CFI) for baseline coverage where type-based CFI isn't used or can't be deployed (BTI/PAC, CET IBT or equivalent)
        PXN, SMEP or equivalent
        PAN, SMAP or equivalent
        Isolated radios (cellular, Wi-Fi, Bluetooth, NFC, etc.), GPU, SSD, media encode / decode, image processor and other components
        Support for A/B updates of both the firmware and OS images with automatic rollback if the initial boot fails one or more times
        Verified boot with rollback protection for firmware
        Verified boot with rollback protection for the OS (Android Verified Boot)
        Verified boot key fingerprint for yellow boot state displayed with a secure hash (non-truncated SHA-256 or better)
        StrongBox keystore provided by secure element
        Hardware key attestation support for the StrongBox keystore
        Attest key support for hardware key attestation to provide pinning support
        Weaver disk encryption key derivation throttling provided by secure element
        Insider attack resistance for updates to the secure element (Owner user authentication required before updates are accepted)
        Inline disk encryption acceleration with wrapped key support
        64-bit-only device support code
        Wi-Fi anonymity support including MAC address randomization, probe sequence number randomization and no other leaked identifiers
        Support for disabling USB data and also USB as a whole at a hardware level in the USB controller
        Reset attack mitigation for firmware-based boot modes such as fastboot mode zeroing memory left over from the OS and delaying opening up attack surface such as USB functionality until that's completed
        Debugging features such as JTAG or serial debugging must be inaccessible while the device is locked
        
        

        Until the collaboration with Motorola produces a device, only the recent Pixels meet the requirements.

        Fairphone is also one of the worse OEM’s when it comes to how slowly they patch and releases security vulnerabilities, and they are known to be quite sloppy, in the past they have published their private keys. I wouldn’t trust keeping anything remotely private or sensitive on a Fairphone.

    • majster@lemmy.zip
      link
      fedilink
      English
      arrow-up
      0
      ·
      22 days ago

      You probably aren’t safe from Pegasus but at least you are not streaming your location and IRL contacts to Google 24/7.

    • dastanktal@lemmy.ml
      link
      fedilink
      English
      arrow-up
      0
      ·
      22 days ago

      Look, at least this way I don’t have to worry about all the software back doors phoning home.

      I just don’t take the phone out with me when I think I’m going to be arrested or something.

      • Buddahriffic@lemmy.world
        link
        fedilink
        English
        arrow-up
        0
        ·
        22 days ago

        Everyone? The group of people that includes those who can’t use their computer after their desktop icons get sorted?

        It still takes some skills, but those skills might just be “desoldering chips to stick them in a chip reader device” and doing that on the storage chips. Or maybe tapping a trace to read the signals that are sent over it to grab a key or something. “Not hard” doesn’t mean “you don’t need skill to do it”, it means “someone who has some skills won’t have difficulty applying them”.

    • Bahnd Rollard@lemmy.world
      link
      fedilink
      English
      arrow-up
      0
      ·
      22 days ago

      This

      My dream phone is made by Fairphone, runs Graphene and has pin-board power switches like the Pinephone (its got good ideas, but its running a 2013 chipset, its a dev device for making linux mobile work better)

      … Wishful thinking.

  • Schwim Dandy@piefed.zip
    link
    fedilink
    English
    arrow-up
    0
    ·
    23 days ago

    This is incredibly exciting news. It will hopefully be quite some time before I need a new phone but I’ve always wanted the option of this brand when I finally do.

  • Staff@piefed.world
    link
    fedilink
    English
    arrow-up
    0
    ·
    23 days ago

    €600 is the minimum for a Fairphone. A new cheap one by a major brand would be €150.

    I’d definitely like some privacy on my phone but damn.

    • Scrubbles@poptalk.scrubbles.tech
      link
      fedilink
      English
      arrow-up
      0
      ·
      23 days ago

      It’s 150 because they’re subsidizing the phone so you’ll pay for service, addons, and so they can sell your data and bloatware. Fairphone isn’t expensive, the other phone is artificially cheap.

      • Staff@piefed.world
        link
        fedilink
        English
        arrow-up
        0
        ·
        23 days ago

        You’re right. They do get us with all the bloatware and other nefarious stuff. Time to start saving.

      • BlaestEgnen@feddit.dk
        link
        fedilink
        English
        arrow-up
        0
        ·
        23 days ago

        They’re kinda comparing apples and oranges, fairphone doesn’t really have a budget phone.

        They just have one model, which they gradually upgrade the hardware of and gives a new number.

        Right now there’s barely any sellers of a Fairphone 4 as an example, and you’re able to get it for ~400 euroes from refurbished condition sellers.

        Most brands, continues to sell old models. Which ends up as the budget phone 3 generations down the line. But fairphone doesn’t, they only sell a fairly powerful phone from new condition.

    • HerbGrower@slrpnk.net
      link
      fedilink
      English
      arrow-up
      0
      ·
      23 days ago

      If you are looking for budget phones, get a FF3/4 second hand. That is what I did and its great.

    • late_pessimistic@slrpnk.net
      link
      fedilink
      English
      arrow-up
      0
      ·
      23 days ago

      Fairphone costs cheapest in carbon footprint and disruption caused to copper mining communities.

      It’s more expensive for you, sure, but it’s the least costly option in grand scheme of things.

    • 666dollarfootlong@lemmy.world
      link
      fedilink
      English
      arrow-up
      0
      ·
      23 days ago

      What phone can you get for 150 that has a user replaceable battery, that is made with sustainable materials and that pays the workers over minimum wage?

    • Eager Eagle@lemmy.world
      link
      fedilink
      English
      arrow-up
      0
      ·
      23 days ago

      It’s the cheapest they have, but not really a cheap model. Those are pretty decent specs for the price. Unfortunately I don’t know any smartphone selling for under 200$/€ that doesn’t suck.

      • HerbGrower@slrpnk.net
        link
        fedilink
        English
        arrow-up
        0
        ·
        23 days ago

        FF3 can be bought for under £200 second hand and that doesn’t suck. FF4 if you are lucky may fit into that price range too.

        • AmbitiousProcess (they/them)@piefed.social
          link
          fedilink
          English
          arrow-up
          0
          ·
          23 days ago

          It wasn’t just the update cycle either, it’s that they don’t have the physical hardware chips to support Graphene’s minimum requirements for security, which would severely weaken any benefits you actually get from GrapheneOS.

            • AmbitiousProcess (they/them)@piefed.social
              link
              fedilink
              English
              arrow-up
              0
              ·
              23 days ago

              Entirely lacking disk encryption for typical users due to not having a secure element is a pretty major flaw.

              It’s also missing hardware accelerated virtualization which is necessary for much of GrapheneOS’s sandboxing, has weak security for other keys in the OS keystore, is missing hardware memory tagging which makes it much easier for apps to use overflow attacks, doesn’t have proper verified boot support once a custom alternative OS is flashed, and leaves exposed debugging APIs even when the phone is locked.

              This breaks:

              • Secure app spawning
              • Memory corruption protection
              • Integer overflow protection
              • Most of Graphene’s kernel hardening
              • Much of Graphene’s attack surface reduction abilities
              • Hardware-based attestation and security monitoring
              • Quick tile protection pre-unlock
              • Debugging access prevention
              • Verified Boot
              • The security of your PIN against any automated attack

              At that point, GrapheneOS can’t physically provide you essentially any security anymore.

              • WhyJiffie@sh.itjust.works
                link
                fedilink
                English
                arrow-up
                0
                ·
                22 days ago

                Entirely lacking disk encryption for typical users due to not having a secure element is a pretty major flaw.

                all android devices have been using file based disk encryption since several Android versions now.

                the others are all good to have security features, but lets be honest, a proper sensors permission toggle does not require any of that, just like a dozen other features only GrapheneOS has. storage scopes, contact scopes, pin scrambling and the requirement of fingerprint + pin for unlocking the lock screen, duress pin, the user profile improvements

                all this does not require any hardware support.

                https://grapheneos.org/features

                • Ek-Hou-Van-Braai@piefed.social
                  link
                  fedilink
                  English
                  arrow-up
                  0
                  ·
                  22 days ago

                  While that is true yes, their whole brand is built on being secure.

                  If they release to Fairphone it won’t be long before the news is flooded with “Police easily bypass supposedly secure GraphoneOS”

                  And that’s not a look they’d want.

                  I like their stance on All or Nothing.

                  Motorola is shipping with GraphineOS soon.

                • AmbitiousProcess (they/them)@piefed.social
                  link
                  fedilink
                  English
                  arrow-up
                  0
                  ·
                  22 days ago

                  all android devices have been using file based disk encryption since several Android versions now.

                  All Android devices are supposed to support it, but not all do. (or at least, not all do effectively without compromising the cryptographic root of trust by not implementing proper hardware security chips)

                  I’ll grant it to you on the scopes, PIN changes, etc, but realistically I just don’t think anyone can justify GrapheneOS being something that should be supported on Fairphone given how absolutely desolate the phone looks with regard to any attempt at all to hardware security.

              • devfuuu@lemmy.world
                link
                fedilink
                English
                arrow-up
                0
                ·
                23 days ago

                It really depends on what security level you want out of a phone. Most people are concerned with a pickpocket stealing and being able to access everything. Most of the world doesn’t need the security level required to pass through the united states border control. Which they will just force to put the pin anyways or put you in jail for even having a secure device.

                • rumba@lemmy.zip
                  link
                  fedilink
                  English
                  arrow-up
                  0
                  ·
                  23 days ago

                  Well sans duress password being a good idea now, when you get to the border, you can either unlock it or they’ll just confiscate it. You don’t get to be on their list and go through with a phone because they can’t manage to decrypt it.

                • AmbitiousProcess (they/them)@piefed.social
                  link
                  fedilink
                  English
                  arrow-up
                  0
                  ·
                  23 days ago

                  It really depends on what security level you want out of a phone

                  It does, but that’s exactly my point. GrapheneOS will provide you essentially no more security than any other alternative Android operating system, should it have to operate on a Fairphone with all those features not supported by a Fairphone stripped away.

                  Unless Fairphone adds more hardware security features that are standard on most other phones, and highly supported on Pixels, installing a heavily crippled GrapheneOS on a Fairphone would get you essentially none of the benefits of GrapheneOS in the first place.

      • Zedd_Prophecy@lemmy.world
        link
        fedilink
        English
        arrow-up
        0
        ·
        23 days ago

        I haven’t heard of this. Looking into it there’s at least a year wait. I’d consider it - though my Edge 2022 battery may not make it until then. Damn thing was crap from day 1.

        • lokalhorst@feddit.org
          link
          fedilink
          English
          arrow-up
          0
          ·
          23 days ago

          I am pretty sure Motorola plans to sell flag ship devices with GrapheneOS preinstalled. They won’t support old devices. Also the manufacturer needs to still ship firmware updates for a specific duration for GrapheneOS to support it.

          • halcyoncmdr@piefed.social
            link
            fedilink
            English
            arrow-up
            0
            ·
            23 days ago

            GrapheneOS already announced a direct partnership with Motorola, so they clearly already figured that out officially.

            Motorola also promises 5 main Android version updates for their phones now.

    • jumperalex@lemmy.world
      link
      fedilink
      English
      arrow-up
      0
      ·
      23 days ago

      There is Verizon service, you have to buy from the US store. But then it is Android and not /e/OS … it took me a while and a fair number of AI tokens to full figure that out.

      trl;dr it is a hardware cert problem why the EU version is T-Mobile and the US is VZW/ATT. I still couldn’t figure out why the US-VZW/ATT version can’t have /e/OS but it still smelled like obtaining certification is the problem and there doesn’t appear to be any public statements on a timeline for it.

      If you want privacy, buy a pixel and flash GrapheneOS.

      If you want modularity/repairability buy a Fairphone.

      • If you want modularity/repairability and privacy, buy an /e/OS Fairphone from the EU store but accept only T-Mobile
      • If you want modularity/repairability and ATT/VZW, buy a Fairphone from the US store but accept no extra privacy
      • If you want it all, guess we gotta wait.
        • jumperalex@lemmy.world
          link
          fedilink
          English
          arrow-up
          0
          ·
          23 days ago

          Yes you can put whatever COMPATIBLE OS you want on it. Sadly GrapheneOS isn’t one of them. But again, you’re not wrong. I was just highlighting what I found about the options and their trade-offs.

      • thagoat@lemmy.dbzer0.com
        link
        fedilink
        English
        arrow-up
        0
        ·
        23 days ago

        According to the fairphone website, the reason it’s incompatible is because the hardware does not support the lte channel that us Verizon service operate on, leading to unreliable service. No Ai tokens necessary.

    • COASTER1921@lemmy.ml
      link
      fedilink
      English
      arrow-up
      0
      ·
      21 days ago

      Fairphone or not T-Mobile isn’t anything like what it used to be. If you’re in a major city or suburb it’s worth taking a serious look at T-Mobile. I’m on US mobile which is a MVNO that allows you to freely switch between all 3 networks with two simultaneously active at any given time. 90% of the time T-Mobile has far better and faster coverage than either of Verizon or ATT. It used to be that Verizon was by far the best, but their network capacity hasn’t kept pace with T-Mobile’s growth, even if your Verizon plan has priority data (as mine does). This difference shows most when network capacity is limited.

      T-Mobile’s rural coverage isn’t as great as either of Verizon’s or ATT’s, but it’s absolutely good enough for every road trip I’ve done. And when visiting family in rural northern Wisconsin only T-Mobile and ATT have reasonable coverage in their area. You can use a Mint Mobile trial SIM to see for yourself.

      I think Verizon knows this too, all of the cheapest MVNOs have been switching to use Verizon’s network in recent years. The ISP mobile networks you can often get a year of for free also nearly all run on Verizon now. If you’re paying for your service, the Total Wireless $20/mo BYO plan with unlimited priority data and 10GB/mo of international data is the best deal out there by far. Verizon certainly wouldn’t be providing MVNOs with the lowest cut rate pricing if they thought they had the best network.

        • COASTER1921@lemmy.ml
          link
          fedilink
          English
          arrow-up
          0
          ·
          20 days ago

          I don’t use Fairphone, but I am a bit of a mobile network nerd. I’m on US Mobile which is a unique MVNO that allows you to move between any 2 of the 3 US networks as you please. You have to have signal to initiate a network change and sometimes it takes a day, but for premium mobile service they’re great. I mostly just stay on ATT and T-Mobile, but depending on the rural area you visit Verizon and T-Mobile is also a reasonable combination. My point in the comment above is to not discount T-Mobile, their network capacity in cities and suburbs is miles ahead of Verizon and ATT (I’m ignoring UWB since it requires you to be outside and line of sight to a tower, it’s not practical for the vast majority of cell phone usage which occurs in a building).

          The Fairphone is the only modern phone I know of that has limited bands, so you’ll need to use a T-Mobile based MVNO. The best deal on the T-Mobile network is Mint Mobile, providing 1yr of unlimited service for $180 if you port in a number. They’re directly owned by T-Mobile and I used them for several years quite happily before switching to US mobile. Google Fi also occasionally runs promos bringing their plans into the $15/mo range. The only reason I’m not still on them is the requirement to port in a number to get that $15/mo price for a year. I tend to change network every single year to always get the best deal.

          The absolute best phone plan deal recently is the Total Wireless $20/mo 5g BYO plan. Uniquely the price is guaranteed for 5yr and it includes unlimited priority data + 10GB international roaming every month. But it’s on Verizon’s network.

    • Benaaasaaas@group.lt
      link
      fedilink
      English
      arrow-up
      0
      ·
      21 days ago

      Graphene OS needs a hardware level chip, that enables secure encryption of data so far only pixels have that. They are working with Motorola though.

      • Hiro8811@lemmy.world
        link
        fedilink
        English
        arrow-up
        0
        ·
        21 days ago

        Somehow after being repeatedly told that they still ask it. But GOS team did make a post detailing why they won’t support nor partnership with fairphone 97829

        97830

        97831

        • Pika@sh.itjust.works
          link
          fedilink
          English
          arrow-up
          0
          ·
          21 days ago

          I personally think that the GOS team is intentionally not wanting to, not due to the requirements, but due to the water so to speak.

          There was a lot of bad blood between a company that Fairphone closely partners with, so therefore they don’t want to even think about the concept of it. I think that shows quite well when you look at their post considering that their post goes into detail on the supply chain aspects of it and who they’re partnered with instead of focusing on the actual issues with the device.

          Being said, I understand their points on the software updates and the hardware requirement. But, ostensibly I don’t think they are rejecting it due to those concerns.

  • pasdechance@jlai.lu
    link
    fedilink
    English
    arrow-up
    0
    ·
    23 days ago

    Cool. But, which repair centre has the contract for bricked phones. In Europe only one place has the vendor key thing if you fuck up while flashing the device, they won’t let users or other repair places have it so I assume it works the same in the US.

    If I needed a new phone, I might get one of these. Repairable phones are cool.

  • arc99@lemmy.world
    link
    fedilink
    English
    arrow-up
    0
    ·
    21 days ago

    Fairphones seem okay from a hardware POV but the software is a bit lacking in terms of security and support.