• mnemonicmonkeys@sh.itjust.works
      link
      fedilink
      English
      arrow-up
      1
      ·
      2 hours ago

      It doesn’t sound possible on the FP6 or FP6+. But maybe in the future? If people keep asking them (politely!) they might consider adding support for the 7 or 8

      • spectrums_coherence@piefed.social
        link
        fedilink
        English
        arrow-up
        62
        ·
        edit-2
        21 hours ago

        No I think you are thinking of calyx. Graphene repeatedly asserted that they won’t support fairphone because of the slow update.

        • AmbitiousProcess (they/them)@piefed.social
          link
          fedilink
          English
          arrow-up
          60
          arrow-down
          1
          ·
          19 hours ago

          It wasn’t just the update cycle either, it’s that they don’t have the physical hardware chips to support Graphene’s minimum requirements for security, which would severely weaken any benefits you actually get from GrapheneOS.

            • AmbitiousProcess (they/them)@piefed.social
              link
              fedilink
              English
              arrow-up
              66
              arrow-down
              1
              ·
              19 hours ago

              Entirely lacking disk encryption for typical users due to not having a secure element is a pretty major flaw.

              It’s also missing hardware accelerated virtualization which is necessary for much of GrapheneOS’s sandboxing, has weak security for other keys in the OS keystore, is missing hardware memory tagging which makes it much easier for apps to use overflow attacks, doesn’t have proper verified boot support once a custom alternative OS is flashed, and leaves exposed debugging APIs even when the phone is locked.

              This breaks:

              • Secure app spawning
              • Memory corruption protection
              • Integer overflow protection
              • Most of Graphene’s kernel hardening
              • Much of Graphene’s attack surface reduction abilities
              • Hardware-based attestation and security monitoring
              • Quick tile protection pre-unlock
              • Debugging access prevention
              • Verified Boot
              • The security of your PIN against any automated attack

              At that point, GrapheneOS can’t physically provide you essentially any security anymore.

              • WhyJiffie@sh.itjust.works
                link
                fedilink
                English
                arrow-up
                3
                ·
                9 hours ago

                Entirely lacking disk encryption for typical users due to not having a secure element is a pretty major flaw.

                all android devices have been using file based disk encryption since several Android versions now.

                the others are all good to have security features, but lets be honest, a proper sensors permission toggle does not require any of that, just like a dozen other features only GrapheneOS has. storage scopes, contact scopes, pin scrambling and the requirement of fingerprint + pin for unlocking the lock screen, duress pin, the user profile improvements

                all this does not require any hardware support.

                https://grapheneos.org/features

                • Ek-Hou-Van-Braai@piefed.social
                  link
                  fedilink
                  English
                  arrow-up
                  3
                  ·
                  8 hours ago

                  While that is true yes, their whole brand is built on being secure.

                  If they release to Fairphone it won’t be long before the news is flooded with “Police easily bypass supposedly secure GraphoneOS”

                  And that’s not a look they’d want.

                  I like their stance on All or Nothing.

                  Motorola is shipping with GraphineOS soon.

                  • WhyJiffie@sh.itjust.works
                    link
                    fedilink
                    English
                    arrow-up
                    2
                    arrow-down
                    1
                    ·
                    8 hours ago

                    While that is true yes, their whole brand is built on being secure.

                    but if calyx would take their features they would be screaming loudly how unfair that is

                    If they release to Fairphone it won’t be long before the news is flooded with “Police easily bypass supposedly secure GraphoneOS”

                    that part I can understand. maybe release it under a different name, but they are probably not interested in that.

                    their code is open source, but they were so hostile with every other part of the free android community that nobody wants to deal with the shitstorm that would happen if they took patches from graphene.

                • AmbitiousProcess (they/them)@piefed.social
                  link
                  fedilink
                  English
                  arrow-up
                  1
                  ·
                  8 hours ago

                  all android devices have been using file based disk encryption since several Android versions now.

                  All Android devices are supposed to support it, but not all do. (or at least, not all do effectively without compromising the cryptographic root of trust by not implementing proper hardware security chips)

                  I’ll grant it to you on the scopes, PIN changes, etc, but realistically I just don’t think anyone can justify GrapheneOS being something that should be supported on Fairphone given how absolutely desolate the phone looks with regard to any attempt at all to hardware security.

              • devfuuu@lemmy.world
                link
                fedilink
                English
                arrow-up
                10
                arrow-down
                3
                ·
                18 hours ago

                It really depends on what security level you want out of a phone. Most people are concerned with a pickpocket stealing and being able to access everything. Most of the world doesn’t need the security level required to pass through the united states border control. Which they will just force to put the pin anyways or put you in jail for even having a secure device.

                • AmbitiousProcess (they/them)@piefed.social
                  link
                  fedilink
                  English
                  arrow-up
                  14
                  arrow-down
                  1
                  ·
                  16 hours ago

                  It really depends on what security level you want out of a phone

                  It does, but that’s exactly my point. GrapheneOS will provide you essentially no more security than any other alternative Android operating system, should it have to operate on a Fairphone with all those features not supported by a Fairphone stripped away.

                  Unless Fairphone adds more hardware security features that are standard on most other phones, and highly supported on Pixels, installing a heavily crippled GrapheneOS on a Fairphone would get you essentially none of the benefits of GrapheneOS in the first place.

                  • WhyJiffie@sh.itjust.works
                    link
                    fedilink
                    English
                    arrow-up
                    2
                    arrow-down
                    1
                    ·
                    8 hours ago

                    once again, that is completely false. I’m fed up with all the people pretending that all grapheneos adds is hardware security.

                • rumba@lemmy.zip
                  link
                  fedilink
                  English
                  arrow-up
                  3
                  arrow-down
                  1
                  ·
                  18 hours ago

                  Well sans duress password being a good idea now, when you get to the border, you can either unlock it or they’ll just confiscate it. You don’t get to be on their list and go through with a phone because they can’t manage to decrypt it.

      • Zedd_Prophecy@lemmy.world
        link
        fedilink
        English
        arrow-up
        5
        arrow-down
        1
        ·
        20 hours ago

        I haven’t heard of this. Looking into it there’s at least a year wait. I’d consider it - though my Edge 2022 battery may not make it until then. Damn thing was crap from day 1.

        • lokalhorst@feddit.org
          link
          fedilink
          English
          arrow-up
          8
          ·
          19 hours ago

          I am pretty sure Motorola plans to sell flag ship devices with GrapheneOS preinstalled. They won’t support old devices. Also the manufacturer needs to still ship firmware updates for a specific duration for GrapheneOS to support it.

          • halcyoncmdr@piefed.social
            link
            fedilink
            English
            arrow-up
            5
            ·
            edit-2
            17 hours ago

            GrapheneOS already announced a direct partnership with Motorola, so they clearly already figured that out officially.

            Motorola also promises 5 main Android version updates for their phones now.

          • anon_8675309@lemmy.world
            link
            fedilink
            English
            arrow-up
            1
            ·
            16 hours ago

            I thought the deal was they shipped with normal OS because of existing deals with Google over Android but that they would have unlocked bootloaders so that the end user can install it.

            Also it’s limited to their very high end so expect $1000+ USD.

          • Zedd_Prophecy@lemmy.world
            link
            fedilink
            English
            arrow-up
            1
            ·
            17 hours ago

            I meant more like if I am forced to get another phone before it comes out. I should at least try to put a new battery into my edge and I’ve done it for several phones but there’s always that 10 percent chance you might bork your phone.