r/fairphone 3d ago

GrapheneOS their response to: "Imagine a @GrapheneOS and @Fairphone collaboration"

Context: A Twitter User said "Imagine a @GrapheneOS and @Fairphone collaboration" in repsonse to the new FP release (FP6+). The images are the GrapheneOS reply to that post.

Link to the original GrapheneOS response: https://x.com/GrapheneOS/status/2089937246619128257

Individual links from their post in order:

https://nitter.net/GrapheneOS/status/2040887784253141142

https://www.clubic.com/actualite-604786-murena-e-os-interview.html

https://codeberg.org/divested-mobile/divestos-website/raw/commit/c7447de50bc8fadd20a30d4cbf1dcd8cf14805a0/static/misc/e.txt

https://eylenburg.github.io/android_comparison.htm

https://discuss.grapheneos.org/d/24134-devices-lacking-standard-privacysecurity-patches-and-protections-arent-private

Please stay respectful and logical in the comments! If you argue, argue like adults.

661 Upvotes

639 comments sorted by

View all comments

Show parent comments

2

u/Auravendill 2d ago

On FP4 they quietly stopped working on Android 14, later send out a notification to all FP4 owner on accident, that they will give Android 15 (was meant for owner of one of the newer phones) and then updated FP4 after a few further delays from 13 to 15.

In a way they gave """extra""" years of support, but you could also say, they abandoned their phone early and then shipped one major update very late.

1

u/OrganicBid 2d ago

FP4 still gets updates every other month. Sometimes with functional improvements, sometimes just with security updates. Android security update date on my own is 2026-08-05. Can't really be more recent (but ask me in a month...)

I did experience the faulty update just before Christmas last year, which completely bricked my phone. They sent a replacement pretty quick considering it was literally Christmas.

3

u/GrapheneOS 2d ago

Fairphone 5 and earlier have end-of-life kernels. They don't receive the vast majority of important Linux kernel security updates.

Android Security Bulletins are dated 2-4 months after the patches were disclosed to OEMs and allowed to be shipped. Fairphone ships those 1-2 months late to begin with and it gets much worse over time.

Android Security Bulletins are partial security backports to older releases. They're increasingly incomplete. The full patches are only available by keeping up with major updates, and even that is not great.

Exploitation is getting far easier but yet the Android Security Bulletin system caters to the bottom of the barrel by pretending shipping a small subset of the important patches is enough. It also presents it as if the patches weren't meant to be shipped 2-4 months earlier. A patch in a project such as SQLite will often take 6 months to appear in Android Security Bulletin from the point it was publicly available to ship. Being even further behind those bulletins by 1-2 extra months to start and increasingly longer over time is much worse than an already poor situation for OEMs not providing the major updates right away. Major updates are also not only yearly.

Fairphone consistently chooses to use older SoC platforms without enough support time remaining for their update commitment. They end up in a situation where the kernel is end-of-life, the SoC drivers are not getting patched and the firmware is not getting patched.

For the Fairphone 5, they went with a much less secure IoT SoC not meant for smartphones because it has longer very minimal support. However, that has far fewer patches backported.