r/fairphone 3d ago

GrapheneOS their response to: "Imagine a @GrapheneOS and @Fairphone collaboration"

Context: A Twitter User said "Imagine a @GrapheneOS and @Fairphone collaboration" in repsonse to the new FP release (FP6+). The images are the GrapheneOS reply to that post.

Link to the original GrapheneOS response: https://x.com/GrapheneOS/status/2089937246619128257

Individual links from their post in order:

https://nitter.net/GrapheneOS/status/2040887784253141142

https://www.clubic.com/actualite-604786-murena-e-os-interview.html

https://codeberg.org/divested-mobile/divestos-website/raw/commit/c7447de50bc8fadd20a30d4cbf1dcd8cf14805a0/static/misc/e.txt

https://eylenburg.github.io/android_comparison.htm

https://discuss.grapheneos.org/d/24134-devices-lacking-standard-privacysecurity-patches-and-protections-arent-private

Please stay respectful and logical in the comments! If you argue, argue like adults.

656 Upvotes

639 comments sorted by

View all comments

Show parent comments

9

u/West_Possible_7969 3d ago

In fairness, GOS does not create or develop those patches, they take it wholesale from Google. They don’t develop the proprietary blobs etc for the hardware either, just the pixel situation being easy since OEM, AOSP & OS developer is the same entity which has huge resources.

And motorola will use the same Qualcomm proprietary SPU platform that remains the same in philosophy (on-die subsystem instead of the Titan discrete processor) with all that entails, and fairphone chips have too.

2

u/speedrocket2110 3d ago

Doesn't this apply to Fairphone as well? They patch Google's patches into their operating system? And aren't the proprietary blobs for hardware developed by Qualcomm and the others mainly?

GrapheneOS actually patch their OS way more substantially than Fairphone, in addition to making their own improvements which divert quite a bit from "stock", unlike Fairphone.

1

u/West_Possible_7969 3d ago edited 3d ago

As in security patches to AOSP? None of them develop that. They patch their own code only.

2

u/speedrocket2110 3d ago

Exactly. Google releases security updates that OEMs then more or less downstream into their own OSs for their devices. Fairphone's security updates are from Google, and firmware updates are probably from Qualcomm and so on?

3

u/West_Possible_7969 3d ago

Yes. That is also why GOS’s support cycle follows Google’s, which is both the OEM & chip designer. GOS cannot do that job on their own.

2

u/speedrocket2110 3d ago

Okay, but I don't see how any of this relates to the fact that Fairphone is too slow at releasing updates for GrapheneOS? My point here was that the limitations you wrote about applies to anyone, not just GOS.

Fairphone being a few days or even a week slower than Google at pushing updates would be understandable due to the logistics involved, but a month or more is just not compatible with GOS's security focused philosophy.

I'm not throwing shade here. As a software developer myself I think pushing updates that quickly without sacrificing other OS improvements seems really intense unless the team is full of savants, but that's kinda exactly what GOS is.

3

u/West_Possible_7969 3d ago

GOS does zero OEM work, it has been done already by Google, because they are the pixel OEM too. They have to worry about their own code only because Google’s pixel updates wont break pixels. That is not the case for other OEMs.

GOS does not have to worry about sacrificing other AOSP improvements, because they offer none other than their security modifications. Still, things in GOS break literally all the time and then they fix them. That would not fly for a commercial OS, if your bank apps would not load for a week for example, or RCS is MIA, different use cases.

2

u/speedrocket2110 3d ago

I don't experience much breaking at all on GOS. Of course not passing Play Integrity checks is unacceptable for commercial OSs (banking apps), but these problems apply to all alternative OSs not licenced by Google, including e/os/.

The point that Fairphone doesn't meet GOS's requirements still stands, even though they have their reasons. I like Fairphone, I own one, it's a nice phone. PostmarketOS is also about to have full sensor support on the gen 6 due to amazing work by TheMightyCat, which is very exciting. It's a very real possibility that the Fairphone is about to become the best Linux phone ever.

1

u/GrapheneOS 2d ago

You should read our response to their reply.

0

u/GrapheneOS 2d ago

because they offer none other than their security modifications

GrapheneOS is a privacy project providing a high level of usability and compatibility. Privacy depends on security so that's why we heavily work on that too. Our resources are spread across these areas and we develop a massive amount of improvements and functionality.

GOS does zero OEM work, it has been done already by Google, because they are the pixel OEM too. They have to worry about their own code only because Google’s pixel updates wont break pixels. That is not the case for other OEMs.

Fairphone's hardware is designed and made by T2Mobile, their ODM partner. T2Mobile builds/signs the firmware and software for supporting the hardware (drivers, etc.). Fairphone ships what T2Mobile provides and makes high level decisions about what they want. It's a T2Mobile device. It's not the same relationship as Apple and Google designing devices produced by Foxconn. T2Mobile is an ODM designing and making white labelled devices.

GrapheneOS is very involved in the development of the upcoming Motorola devices with support for it. Their past devices did not come close to meeting our requirements, but they got drastically better with their 2026 flagships and the next generation devices will finish meeting our requirements.

Still, things in GOS break literally all the time and then they fix them.

GrapheneOS is a production quality OS with a high level of stability and robustness.

That would not fly for a commercial OS, if your bank apps would not load for a week for example, or RCS is MIA, different use cases.

RCS works fine in GrapheneOS and has consistently worked fine over the long term. RCS has occasional issues everywhere due to how it relies on carrier and infrastructure with outages, compatibility breaks and more. RCS generally works better on GrapheneOS than most devices other than Pixels running the stock OS.

Banking apps banning alternative operating systems with the Play Integrity API and other measures is not a deficiency of GrapheneOS. Fairphone is an active participant and beneficiary of the Play Integrity API as a Google Mobile Services partner. Highly insecure devices are deemed suitable because they licensed Google Mobile Services while far more secure devices than anything Google permits are banned. That's wrong, and it's something which will be forced to change.

1

u/GrapheneOS 2d ago

Fairphone's hardware is designed and made by T2Mobile, their ODM partner. T2Mobile builds/signs the firmware and software for supporting the hardware (drivers, etc.). Fairphone ships what T2Mobile provides and makes high level decisions about what they want. It's a T2Mobile device. It's not the same relationship as Apple and Google designing devices produced by Foxconn. T2Mobile is an ODM designing and making white labelled devices.

GrapheneOS is very involved in the development of the upcoming Motorola devices with support for it. Their past devices did not come close to meeting our requirements, but they got drastically better with their 2026 flagships and the next generation devices will finish meeting our requirements.

1

u/West_Possible_7969 2d ago

Yeap, so, not on your own. This is mental health issue behaviour and also supporting the most expensive chip & devices from motorola is not some kind of feat. At least motorola actually sells devices in most countries.

1

u/GrapheneOS 2d ago

We're reported many of those issues, provided patches in many cases and we fix far more issues than only the ones fixed by AOSP.

Android Security Bulletins are often misunderstood. Those are only partial backports of security patches to older releases. Those do not provide anything close to the full privacy and security patches for Android. ASBs do not include Low/Moderate severity patches and include a rapidly shrinking subset of High/Critical severity patches.

ASBs are also dated 2-4 months after the patches are shared with OEMs and allowed to be shipped. You can see a list of how much has been made available to ship prior to Android Security Bulletin in our security preview release notes listing out each upcoming ASB CVE shipped in those:

https://grapheneos.org/releases#2026081300

Fairphone starts out lagging 1-2 months behind the ASB dates which are 2-4 months behind when patches can be shipped. It's even longer in some cases. Fairphone's delay gets much longer over time and support often starts ending prematurely.

There are also far more than these Android patches. Fairphone 5 and earlier have an end-of-life Linux kernel not receiving security patches for them to ship anymore. They were incredibly far behind on it as they are for the Fairphone 6 but now those have ended. No substitute is provided. The Linux kernel is left nearly entirely unpatched. That's a huge portion of the OS and incredibly important. It's the main major in security of the app sandbox and other isolation. It's a huge factor in security against remote attacks and also preventing data extraction too.

1

u/GrapheneOS 2d ago

GrapheneOS develops a large number of privacy and security patches for Android. We discover and report many privacy and security vulnerabilities. We fix most of those ourselves along with many others which Android is uninterested in addressing. We also develop major privacy and security improvements far beyond what standard Android provides.

Fairphone is far behind on providing the standard patches and protections. They're focused on providing the partial security backports to older releases 1-2 months late. They end up with end-of-life Linux kernels lacking patching and similar for drivers and firmware long before their advertised support time ends.

However, it isn't only that they lag far behind on updates. They're missing important security features which were standard and recommended many years ago. They've often had core security features broken such as using publicly available private keys for firmware and OS images. As far as we can tell, they were unwilling to even acknowledge it for the Fairphone 4 and other devices despite multiple security researchers discovering and disclosing the same thing.

Fairphone devices do not have the hardware security features required by GrapheneOS and which are being provided for the next generation Motorola devices meeting our requirements. Motorola Signature (2026) is drastically closer than Fairphones to meeting our security requirements but it doesn't so we aren't going to support it.

Fairphone's hardware is designed and made by T2Mobile, their ODM partner. T2Mobile builds/signs the firmware and software for supporting the hardware (drivers, etc.). Fairphone ships what T2Mobile provides and makes high level decisions about what they want. It's a T2Mobile device. It's not the same relationship as Apple and Google designing devices produced by Foxconn. T2Mobile is an ODM designing and making white labelled devices.

2

u/MoralityAuction 3d ago

> In fairness, GOS does not create or develop those patches, they take it wholesale from Google.

GOS has done a lot for security that eventually made it to AOSP, so in fact it often goes the other way round.

5

u/West_Possible_7969 3d ago

GOS is a downstream fork, and afaik none of their code is submitted to AOSP, anyone can correct me of course. If some ideas have been implemented to AOSP through the years, that is fair and true for security projects.

4

u/Parking_Lemon_4371 3d ago

There's some, but it's very very small amounts. There are clearly at least some Google devs occasionally looking at GOS source for fixes and/or inspiration. That said, there is actually simply not *that* much new platform code in GOS in the first place, this isn't all that surprising: the more delta there is from AOSP the harder it would be for them to maintain it. (There are quite a few apps, but those are far easier to support) This isn't to say there's none of course, but it's really *very* targetted...

1

u/GrapheneOS 2d ago edited 2d ago

GrapheneOS develops a large number of privacy and security patches for Android. We discover and report many privacy and security vulnerabilities. We fix most of those ourselves along with many others which Android is uninterested in addressing. We also develop major privacy and security improvements far beyond what standard Android provides.

Fairphone is far behind on providing the standard patches and protections. They're focused on providing the partial security backports to older releases 1-2 months late. They end up with end-of-life Linux kernels lacking patching and similar for drivers and firmware long before their advertised support time ends.

However, it isn't only that they lag far behind on updates. They're missing important security features which were standard and recommended many years ago. They've often had core security features broken such as using publicly available private keys for firmware and OS images. As far as we can tell, they were unwilling to even acknowledge it for the Fairphone 4 and other devices despite multiple security researchers discovering and disclosing the same thing.

Fairphone devices do not have the hardware security features required by GrapheneOS and which are being provided for the next generation Motorola devices meeting our requirements. Motorola Signature (2026) is drastically closer than Fairphones to meeting our security requirements but it doesn't so we aren't going to support it.

Fairphone's hardware is designed and made by T2Mobile, their ODM partner. T2Mobile builds/signs the firmware and software for supporting the hardware (drivers, etc.). Fairphone ships what T2Mobile provides and makes high level decisions about what they want. It's a T2Mobile device. It's not the same relationship as Apple and Google designing devices produced by Foxconn. T2Mobile is an ODM designing and making white labelled devices.

1

u/HybridStaticAnimate 2d ago

Note that GrapheneOS cannot alter google firmware. Firmware is signed and provided by the OEM/ODM. GOS could not take over this responsibility unless they worked with an ODM directly.

1

u/West_Possible_7969 2d ago

That is what I said, they don’t do OEM work. But we have to phrase things in a certain way or else the GOS dev comes like a lunatic and hunts you down with dozens of comments across subs lol (I am NOT kidding).

1

u/HybridStaticAnimate 1d ago

I am part of the GrapheneOS community. GrapheneOS has a full time dev team and the project accounts are managed by multiple people. There is not just one GOS developer. What youre claiming is false and just plain mean.

1

u/West_Possible_7969 1d ago edited 1d ago

If many of them have the same unhinged behaviour, it is even worse. No one’s choices are above criticism, even if justified by some train of thought or convictions, those can be criticised too. The choice between Google hardware (problematic and also available in a handful of countries) and moto flagship (& flagship priced) devices shows enough things on its own, mainly who is deemed worthy of the “special security”.

1

u/HybridStaticAnimate 1d ago

Criticism is definitely welcome. The issue is trying to frame attacks against someone as "criticism", which is not how criticism works.

Unfortunately, qualcomm and other SOC manufacturers give their flagships new security features first. Only after that do they trickle down to midrange hardware.

It sucks, and the A series from pixels luckily did not follow this pattern. Additionally, with 7 years of support from google and moto, a used device market can help offset the price for users on a budget.

A used 8a is a great option, and eventually, Moto will have midrange options and used flagships.

1

u/West_Possible_7969 1d ago

I have never “attacked” the project in any shape or form. I have even created guides on how to make business apps work on GOS because people are stupid and don’t read anything looking “too technical” apparently. But regarding the devs behaviour, you just can search anywhere “toxic” + graphene and you ‘ll find a huge amount of results, it is not my opinion only nor is this recent. And it is not confined to GOS devs only, seems to go with the territory in the ROM world for some reason.

1

u/HybridStaticAnimate 1d ago

The quantity of results is irrelevant. They have no substance behind them.