Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

"[GrapheneOS] lost most interest in that hardware due to the poor way privacy, security, updates and marketing based on these things has been handled."

https://discuss.grapheneos.org/d/28825-is-there-any-chance-o...



I'm sure their concerns are valid but just because GrapheneOS don't consider the Fairphone to meet their standards for security doesn't mean it is not worth considering for other people who may have different priorities. Fairphones have certain advantages over Pixels such as better repairability and more ethically sourced labour/components. IMO it's good to see the Fairphone do well (and I hope GrapheneOS's partnership with Motorola also goes well).


Unfortunately it looks like it's not just a issue of missing hardware security features:

> Their partnership with Murena along with promoting it themselves with misleading marketing means no possibility of working with us.

I want to like GrapheneOS, but the pettiness of its leadership is a real problem for the long term prospect of the project.


Is it pettiness or just sticking to their morals? Murena, as they mentioned, forwards data to OpenAI which is against pretty much everything Graphene stands for.


Only for one voice to text feature which is completely optional to use and can be replaced with something else.

As another commenter mentioned, this voice to text feature is now an offline feature and no longer sends data outside the device.

As another note, this Fairphone can be purchased without /e/OS at all. It’s now being sold in the US without Murena being involved at all.


/e/ has other privacy invasive services which are enabled by default. It gives highly privileged access to Google services which are always active and has user tracking in their update client.

/e/ and Murena repeatedly claiming privacy/security hardened devices mainly benefit criminals and falsely claiming they're mainly used by criminals shows what they believe:

https://www.clubic.com/actualite-604786-murena-e-os-intervie...

https://nitter.net/GrapheneOS/status/2040887784253141142

/e/ lacks many crucial standard privacy/security patches and protections:

https://nitter.net/GrapheneOS/status/2081837057433915603

Fairphones don't provide a reasonable level of privacy and security without /e/ either:

https://news.ycombinator.com/item?id=49354807


> Murena, as they mentioned, forwards data to OpenAI which is against pretty much everything Graphene stands for.

How? In what way? Source?



June 2025

Someone else shared the up to date info about this feature: https://doc.e.foundation/os/apps/voice-to-text

> The earlier Voice to Text was a Premium-only, online feature: it streamed your speech to a third-party AI transcription service through an anonymising proxy, so it required a Murena Workspace Premium subscription and an internet connection.

> The new Voice to Text is free, offline and on-device


/e/ has other privacy invasive services which are enabled by default. It gives highly privileged access to Google services which are always active and has user tracking in their update client.

/e/ and Murena repeatedly claiming privacy/security hardened devices mainly benefit criminals and falsely claiming they're mainly used by criminals shows what they believe:

https://www.clubic.com/actualite-604786-murena-e-os-intervie...

https://nitter.net/GrapheneOS/status/2040887784253141142

/e/ lacks many crucial standard privacy/security patches and protections:

https://nitter.net/GrapheneOS/status/2081837057433915603


You can stick to your morals without blowing things out of proportion.

“We are the only acceptable way to do things and no tradeoffs are acceptable” is fairly petty.

“We have a difference of opinion” isn’t.


[flagged]


It is not petty to correct misinformation. You are downplaying the seriousness of the situation by painting it as some kind of drama. /e/OS objectively has poor privacy and security for numerous reasons, there was no "falling out", and GrapheneOS is not critiquing it based on emotion.

GrapheneOS is a privacy project first, does not come bundled with any google services, and only makes connections to 1st party services by default. /e/OS includes many google services with privileged OS integration. GrapheneOS is far more effective at the goal you state /e/OS has than /e/OS.


And yet GrapheneOS is better at everything that /e/ claims.


Not at running on sustainably produced, repairable hardware ;)

(Wish it was though.)


You can buy used Pixels, e.g. from 8a up. I'd claim that this is much more ecological than buying a new Fairphone. I suppose that a Pixel is of a higher quality and has less defects than a Fairphone (which changed the ODM several times). --

This said, I would never use /e/ and Murena as I read too many things I don't like.


Fairphones have very poor updates with rapidly degrading privacy and security over their lifespan. They don't keep up with important updates from the beginning and it gets much worse over time. Updates are very important for sustainability. They're also missing important hardware-based security protections which are needed to protect user data in the real world. They've consistently had major issues such as using publicly available private keys for signing firmware and OS images which they've usually failed to acknowledge.

Fairphone 5 and earlier have an end-of-life Linux kernel branch with no movement to updating to a newer one. Fairphone 6 is set to end up in the same situation and it isn't far away. They nearly entirely stop providing Linux privacy and security patches once this happens.

Android patches come around half a year late since the Android Security Bulletins themselves are published very late and Fairphone lags 1-2 months or more behind those.

There's extremely little information available on Fairphone's ODM partner T2Mobile and their supply chain. The information is mainly a list of suppliers without information on working conditions, pay, environmental protection or nearly anything else. T2Mobile has been their ODM since the Fairphone 4 and earlier information is no longer relevant. They moved away from their original ODM partnership to another with the Fairphone 3 and then to T2Mobile with the Fairphone 4. It's unclear if pay and working conditions are better at T2Mobile for Fairphones than they are for their other products and in what way they're better. It's unclear how it comes to Foxconn for Apple and Google phones.

Apple and Google design their devices and handle the firmware and software. Fairphone is using hardware, firmware and software provided by T2Mobile. Fairphone is heavily reliant on what's provided by their ODM. For example, their move to T2Mobile coincided with dropping the 3.5mm audio jack. It's likely not something they wanted to do and many of their supporters were unhappy about it, but it's not really their phone hardware. The phones are essentially T2Mobile devices and there's not a lot of information available. It isn't clear why they switched to T2Mobile with the Fairphone 4 or why the earlier switch to another ODM happened with the Fairphone 3.


[flagged]


You can always flash and factory reset. I’d bet 99.9% of phones on eBay are by and for general public and not some esoteric zero days in the wild that your comment makes it sound like.


Fairphones have atrocious updates which means they aren't sustainable devices. They use a multiple generation old SoC from the beginning with an artificially shortened lifespan. Fairphones are currently designed and assembled by T2Mobile. T2Mobile even signs the firmware on the devices. Prior to the Fairphone 4, they had 2 previous ODM partnerships. They're limited to what their ODM offers which was likely the reason they dropped the 3.5mm audio jack when they moved to T2Mobile for the Fairphone 4. The working conditions and supply chain management are largely up to T2Mobile rather than Fairphone.

There's a severe lack of actual evidence for Fairphones having a more ethical or sustainable assembly and supply chain than Apple. It's likely each one takes more resources to produce and they definitely don't provide comparable updates.


The e/OS/ CEO said during an interview [1] that GrapheneOS, being a security hardened product, was especially useful for p*ophiles to evade justice. This is totally unacceptable. People defending e/OS/ (and Murena, same people, just branding for devices) are either dishonest or useful idiots.

[1] https://grapheneos.social/@GrapheneOS/116353973732143171 (full interview at https://www.youtube.com/watch?v=jQV7498NRQw)


[flagged]


In the current version of /e/OS, Voice to Text runs offline.

> The earlier Voice to Text was a Premium-only, online feature: it streamed your speech to a third-party AI transcription service [...] The new Voice to Text is free, offline and on-device

https://doc.e.foundation/os/apps/voice-to-text


/e/ has other privacy invasive services which are enabled by default. It gives highly privileged access to Google services which are always active and has user tracking in their update client.

/e/ lacks many crucial standard privacy/security patches and protections:

https://nitter.net/GrapheneOS/status/2081837057433915603

/e/ and Murena repeatedly claiming privacy/security hardened devices mainly benefit criminals and falsely claiming they're mainly used by criminals shows what they believe. Here are 2 clear examples:

https://nitter.net/GrapheneOS/status/2040887784253141142

https://www.clubic.com/actualite-604786-murena-e-os-intervie...


>I want to like GrapheneOS, but the pettiness of its leadership is a real problem

I used to feel a bit similarly. But I've since realized they are one of the very few software projects that actually make sensible privacy and security choices.


[flagged]


The privacy and security deficiencies of CalyxOS have nothing to do with compromises for usability. GrapheneOS provides much better usability including through having far broader app compatibility.

CalyxOS drastically reduces privacy and security compared to the Android Open Source Project. It recently went a whole year without privacy and security patches. They're currently months behind on providing current Pixel driver and firmware updates. It has never been a privacy or security hardened OS but rather the direct opposite.


[flagged]


An operating system going a year without providing privacy and security patches is much worse than many options on that basis alone. It's currently months behind on updates. It's hardly the only other option available.


As someone that swapped from fairphone 5 to a pixel9a with graphene.

I have to side with graphene. Fairphone is a cool concept, but its a expensive phone, early on i had problem with the speakers and mic. Security updates are extremely slow, support is extremely slow.

Their missions is to make a fair phone, but is it fair if you are then forced to buy more ewaste because your phone breaks? Look at pixel software support, its really good, and eu made batteries replacement mandatory.


That does not seem like pettiness to me. That seems like a very good reason to not work with someone.


[flagged]


Fairphones continue to have awful updates, privacy and security. /e/ sending user speech data to OpenAI without consent for years never had anything to do with why Fairphones don't meet our requirements.

https://news.ycombinator.com/item?id=49354807


I'm not sure how you can read my comment to imply that.


Refusing to work with organizations or individuals that are detrimental to privacy and security is not petty.

Murena does not provide private or secure products and has positioned itself to be against what GrapheneOS provides. A partnership with a company opposed to GrapheneOS and spreading misinformation about it would not be beneficial, and it is not petty to make the smart choice for the benefit of privacy and security.


The Graphene devs can be a bit obsessive about security, but with a starting price above $600, I think the average user is probably better off with a Pixel 10a bought on sale closer to $300. The stock Fairphone OS seems to include Google services, which is kind of surprising and at odds with the focus on user control and all that.


Fairphones don't provide bare minimum privacy and security. Expecting that is not being obsessive. The flaws are increasingly glaring and easier than ever to exploit thanks to advances in AI models. People should care about this and should get a device with reasonable privacy and security such as an iPhone instead.

Fairphone 5 and earlier having an end-of-life Linux kernel with the Fairphone 6 coming up next is a disaster. Many months of delays for standard Android userspace patches from when they can first be shipped and years of delays for the full patches is also a major problem. An increasingly small portion of the patches is backported to older releases and they have months of delays for those.

Fairphones are also missing crucial industry standard hardware security features. People have come to expect their device will provide strong encryption with a random 6 digit PIN rather than a very strong passphrase but that's not the case with a Fairphone.

More information:

https://news.ycombinator.com/item?id=49354623


Fairphones have atrocious updates, privacy and security. They lag many months and even years behind on providing crucial standard privacy and security patches. They've failed to respond to the discovery of severe security issues including multiple of their devices using publicly available private keys for signing.

Fairphone lags months behind on providing Android Security Bulletin patches which are themselves delayed by months compared to when OEMs are first provided and allowed to ship the patches. They lag a year or more behind on major OS updates and count this as additional support time compared to other OEMs. For example, a final major OS update being delayed for 3 years is marketed as providing 3 more years of support compared to shipping it on time.

Fairphone 5 and earlier have an end-of-life kernel branch and the same fate awaits the Fairphone 6. Pixels move to newer kernel branches and are currently moving to 6.12 and then on to 6.18. Other OEMs are also beginning to use newer kernels and move to new branches. Linux LTS branches are only going to have 2 years of support going forward.

Fairphones are designed and assembled by an ODM. Fairphone has very limited involvement in engineering the devices. The working conditions and supply chain are also largely up to T2Mobile rather than Fairphone. Whether either of those are better than Pixels or especially iPhones should be demonstrated with evidence. There's extremely little information available on the working conditions, pay and other aspects of the assembly and supply chain for Fairphones.

Fairphone replaced their own open source OS without Google Mobile Services with /e/ as part of a close partnership with Murena. /e/ and Murena have repeatedly claimed highly private and secure devices mainly benefit criminals and pedophiles along with peddling other authoritarian talking points. They've falsely claimed GrapheneOS devices are mainly used by criminals and aren't useful to regular people.

https://www.clubic.com/actualite-604786-murena-e-os-intervie...

https://nitter.net/GrapheneOS/status/2040887784253141142

Despite the marketing, /e/ has very poor privacy and security. /e/ has their own invasive services with tracking, gives highly privileged access to default enabled Google services and doesn't keep up with basic updates. It greatly rolls back privacy and security compared to the Android Open Source Project.

https://codeberg.org/divested-mobile/divestos-website/raw/co...

https://eylenburg.github.io/android_comparison.htm

https://discuss.grapheneos.org/d/24134-devices-lacking-stand...


Here's a post with more specific allegations:

https://discuss.grapheneos.org/d/24134-devices-lacking-stand...


One thing in the story is that the SPU - the secure enclave on Qualcomm chips that is separate from just running on TrustZone on the main processor - is only available on Snapdragon 8 and X tier products. It's market segmented away from 7 series and below.


Also, I think Qualcomm has only started supporting MTE on Snapdragon 8 Elite Gen 5. Older and cheaper SoCs do not support it yet. Outside that, I think only Google Tensor, recent Exynos generations, and Apple A-series support MTE (though IIRC Apple has an improved extension of it).


Snapdragon 8 Elite Gen 5 has at support for MTE. It doesn't yet support running the whole kernel and userspace with it in practice as GrapheneOS requires but we're going to be working on it with Motorola and Qualcomm.


i dont get it, they are comparing eOS to graphene, not talking about the hardware.

this would be like grapheneOS not using pixel because the stock android that ships with it does not respect privacy.

am i missing something?


Fairphones have awful updates for the firmware and drivers with months of delays. They end up with an end-of-life Linux kernel and hardware components. Fairphone 5 and earlier have end-of-life kernels which aren't receiving the vast majority of important privacy and security patches.

They're missing crucial industry standard hardware security features. They don't provide proper encryption protecting user data for the vast majority of users not setting a very strong passphrase.

The main hardware and update requirements for GrapheneOS are listed here:

https://grapheneos.org/faq#future-devices

We left another reply at https://news.ycombinator.com/item?id=49354807 with more details on how Fairphone doesn't meet those requirements.


You're making me want one.


You still need to rely on the OEM to properly configure the bootloader, not leak the keys, and provide updated vendor blobs.


It should be doable with cooperation between the two, right?

If we add that FSF aims to provide free alternatives to some vendor blobs the landscape begins to look promising.[0]

One party to provide needed specs for hardware, one party to free the hardware from vendor blobs and another party to merge this into a working product.

[0] https://www.fsf.org/campaigns/librephone


[flagged]


> I guess, my attack model for my personal phones doesn't really account for "my phone got stolen", I'm far more worried about impersonation and remote phone hijacking than needing to be safe from confiscation from feds.

Even if you only care about "remote phone hijacking", not being able to provide timely vendor blob/drivers/kernel means you're wide open for EoP exploits.

As for why they take such a hard line on physical security, well it's their project and they can have whatever high standards they want, especially if they want to project an image of being an absolute secure phone. The code's all open source so it's not too hard to port to another device, especially nowadays with AI.


Fairphone lags many months behind on Android privacy/security patches. They also end up with an end-of-life Linux kernel without the vast majority of the most important patches which is the case for the Fairphone 5 and earlier. It's not far away for the Fairphone 6. Moving to new Linux kernel branches is an expectation by Google and the upstream Linux kernel for OEMs but Fairphone isn't doing it.

Fairphone replaced their own open source OS with /e/ as part of a close partnership with Murena. That's why those are relevant. Fairphones without /e/ still lack reasonable privacy and security, but they're a lot worse with it.

/e/ and Murena have very poor privacy and security for their products combined with very inaccurate marketing. They've repeatedly portrayed private and secure devices as mainly benefiting and being used by criminals and pedophiles. Those are their own explicit choices of words. They've claimed this dozens of times about GrapheneOS including alongside France's national agencies making these inaccurate claims. More information with sources:

https://nitter.net/GrapheneOS/status/2081837057433915603


Fairphone also had the publicly available test key flagged as trusted by the boot loader at one point, which probably discourages projects like GOS, since it makes it harder to trust the hardware to not be a weak link in security.


Fairphones lack the updates and hardware-based security features expected by GrapheneOS.

They're missing hardware security features needed to provide strong encryption for the vast majority of users not using a very strong passphrase. They're similarly missing hardware-based protections heavily used in GrapheneOS to protect from exploitation including remote attacks.

Fairphones have atrocious updates, privacy and security. They lag many months and even years behind on providing crucial standard privacy and security patches. They've failed to respond to the discovery of severe security issues including multiple of their devices using publicly available private keys for signing.

Fairphone lags months behind on providing Android Security Bulletin patches which are themselves delayed by months compared to when OEMs are first provided and allowed to ship the patches. They lag a year or more behind on major OS updates and count this as additional support time compared to other OEMs. For example, a final major OS update being delayed for 3 years is marketed as providing 3 more years of support compared to shipping it on time.

Fairphone 5 and earlier have an end-of-life kernel branch and the same fate awaits the Fairphone 6. Pixels move to newer kernel branches and are currently moving to 6.12 and then on to 6.18. Other OEMs are also beginning to use newer kernels and move to new branches. Linux LTS branches are only going to have 2 years of support going forward.

Fairphones are designed and assembled by an ODM. Fairphone has very limited involvement in engineering the devices. The working conditions and supply chain are also largely up to T2Mobile rather than Fairphone. Whether either of those are better than Pixels or especially iPhones should be demonstrated with evidence. There's extremely little information available on the working conditions, pay and other aspects of the assembly and supply chain for Fairphones.

Fairphone replaced their own open source OS without Google Mobile Services with /e/ as part of a close partnership with Murena. /e/ and Murena have repeatedly claimed highly private and secure devices mainly benefit criminals and pedophiles along with peddling other authoritarian talking points. They've falsely claimed GrapheneOS devices are mainly used by criminals and aren't useful to regular people. Fairphone has chosen to stand with this company included when contacted by the media about criticism.

https://nitter.net/GrapheneOS/status/2040887784253141142

https://clubic.com/actualite-604786-murena-e-os-interview.ht...

Despite the marketing, /e/ has very poor privacy and security. /e/ has their own invasive services with tracking, gives highly privileged access to default enabled Google services and doesn't keep up with basic updates. It greatly rolls back privacy and security compared to the Android Open Source Project.

https://codeberg.org/divested-mobile/divestos-website/raw/co...

https://eylenburg.github.io/android_comparison.htm

https://discuss.grapheneos.org/d/24134-devices-lacking-stand...




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: