ZH version is available. Content is displayed in original English for accuracy.
Advertisement
Advertisement
⚡ Community Insights
Discussion Sentiment
74% Positive
Analyzed from 3612 words in the discussion.
Trending Topics
#fairphone#security#android#phone#parts#years#more#https#actually#still

Discussion (76 Comments)Read Original on HackerNews
I am waiting for the next FP model where I can use a USB-C/dp external display and then I'm all over it.
Just as physical security, digital security most of the time not as radical, and tradeoffs are usually accepted, especially when they are "invisible": hardware and software security features are usually not mentioned in the specs and the regular and even power user just don't know most of them and what do they do.
When GrapheneOS says "private" and "secure", they mean top-of-the-line security features, updates as soon as possible, all available mitigations against zero-days and insecure code which will limit the impact before the patch, etc. Security as in a killdozer.
When other say "private" and "secure", most of the time it means: "we've followed all the recommendations applicable to our development budget, device price point, and support life time". Graphene does not like that definition of these words.
For smartphone, chip manufacturer goal is not to protect the user at all costs, but to provide reasonable security features for the price.
BUT the goal of chip manufacturer to protect the device at all costs is for… game consoles! That's why Xbox, PlayStation, Switch all run on a custom silicon and not an ordinary chips!
Not really. Xbox and PlayStation both run on pretty standard AMD Zen 2 chips. Somewhat customized, but standard enough that people by binned playstation 5 motherboards to use as computers with normal OS'es (lookup BC-250). The last gen with more customized chips was the PS3/Xbox360 era, when both went with a variant of PowerPC, same as Gamecube/Wii/WiiU.
Switch runs on basically the same Nvidia Tegra CPU/GPU as multiple android tablets.
That doesn't mean that all the features are enabled right from the factory, or that the compatibility with already existing features is lost.
Modern chip's security features are pretty complicated and include hardware patches, hardware debug authentication, multiple provisioning states (and multi-key hierarchy for that), RMA states to clear all the private information, etc.
>Switch runs on basically the same Nvidia Tegra CPU/GPU as multiple android tablets.
Yes, and the one which got cracked with a bootrom vulnerability ;)
That's a pretty working motivation for a chip company to improve their chip security when the company as beefy as Nintendo tells them that their chip is vulnerable they're losing money because the customers can play for free ;). I'm pretty sure patchable bootroms started to be common only after Switch hack.
Yeah, iPhoens are made that way as well. It's just caring about the privacy of your users.
> When GrapheneOS says "private" and "secure", they mean top-of-the-line security features, updates as soon as possible, all available mitigations against zero-days and insecure code which will limit the impact before the patch, etc. Security as in a killdozer.
I think it's deceptive because people think they will get better privacy/security with a /e/ fairphone when it's actually much worse than an iPhone.
Does /e/OS illegally collect users' data for ads and sends a lot of telemetry to their servers like Apple? https://news.ycombinator.com/item?id=34299433, https://news.ycombinator.com/item?id=26639261
There are just a bunch of companies which afford to do the same. Maybe Xiaomi will be the next one.
With the hardware I'm not impressed, and on their own forum I've seen plenty of people reporting issues with overheating on the Gen 6. Hopefully kinks have been ironed out on their 6+.
The current CEO also has a persona that would stir up any community (read a few of his AI-gened posts on their blog, if interested of context).
Still holding on to my FP4, but they are not of consideration on my future phone purchase, unless there is some kind of reality check over there and improvements materialize beyond words.
Everyone and their dog can repair an iPhone because it’s the most popular phone on the planet. Are those repairs accessible to the consumer at home with amateur skills? No, not really. However, newer iPhone models are significantly easier to repair and come along with lower repair costs direct from the manufacturer compared to previous models.
You want years of software updates? Yeah, an iPhone has you covered there, too.
And of course, fairphone’s hardware and OS are nothing to write home about. For the freedom and security nerds they’re better off with GrapheneOS on Pixel or whatever upcoming Motorola phones will support it.
Who is the Fairphone for exactly? Who is buying it and why?
I think the fairbuds are their best product, but I also imagine AirPods Pro 3 are on a whole different level of sound quality, noise cancelation, voice quality/voice isolation, and firmware/software polish.
And let’s be honest about repairability with tiny earbuds: being able to replace the battery is has such a tiny impact on their footprint. If I have to throw out my AirPods Pro 3 every 5 years due to battery degradation, that’s such an insignificant quantity of material being wasted, so it’s probably worth it to get a better product. I could offset my environmental impact by eating a little less beef or riding my bike instead of driving a few times. You drive 30 miles and that’s an entire gallon of refined petroleum product, how much material and energy is used to make one pair of AirPods? I can’t imagine it’s a lot.
I don’t say any of this to be a big corporate or Apple shill. I am rooting for the little guys. But the little guys need to be realistic. You look at products like the Framework 13 Pro and you can actually say, okay, here’s a product with really legitimate benefits over its incumbent competition. There is a reason to buy this product for a certain buyer. I just don’t see that with Fairphone. I can’t think of a customer profile where that person is getting a better ownership experience with Fairphone products.
by using FOSS only myself and hating monopolies like Apple etc., i still pretty much convinced that being "green" or "ethical" is more about participating/volunteering/doing-something towards a better world than off-loading your duty to other companies... one could easily make a point that Apple products despite locked down, are still green (Apple has a bunch of zero-emission and whatever policies) and much more if one uses their devices for a long while. i had a 2° hand iPhone SE 1° gen. till 2021? if stuff breaks despite your not being able to fix it's not like you can't hop into a specialized shop to change batteries or even pay the expensive service Apple offers... sure that allows exploitation and it's always nice to get rid of it, that's why somehow these emerging companies are important and/or policies like the right of repair will make them obsolete
> And of course, fairphone’s hardware and OS are nothing to write home about. For the freedom and security nerds they’re better off with GrapheneOS on Pixel or whatever upcoming Motorola phones will support it.
For the "freedom nerds", FP is one of the only (if not the only?) vendor to have official support for microG-based operating systems, seamless OTA updates and everything included. The Murena e/OS offering in particular is simple enough that the non-nerds that (perhaps less outspokenly) care about freedom can just pick it up with little change in habits.
If you're just a rando like me yes, it's paranoia.
And for the updates I could comment that
> Fairphone 6 with stock OS has very lacking security due to delayed patches (1-2 months for partial backports, much longer for full Android patches)
Is certainly much better than my Samsung flagship
Source: You made it up
A quick search would basically disprove everything after your first sentence.
If this is so simple, you surely can demonstrate it and present the links. Meanwhile there are still no phones acceptable for GrapheneOS except from Google, and it's a known fact that Google is restricting Android step by step:
https://news.ycombinator.com/item?id=49364745
https://news.ycombinator.com/item?id=47091419
GOS are vocal about safety and security of all the devices, not just seriously insecure Fairphones, and this article is about something different altogether, that's misinformation they've been hit with several times.
Fair criticism is fair, but yours is fabrications.
So why does a brand new phone run an operating system from over a year ago? Does it really take over 6 months to update a phone to a new version of Android?
How am I supposed to believe a company is committing to supporting a phone for a long time when at release it already runs outdated software?
But Google being Google, this release is pretty much useless until Samsung et al deal with all bugs and performance issues, which will take 2-4 months.
Android versions are locked to kernel versions, which are locked to binary drivers to run your hardware. there's no way around that and you can't reverse engineer or do anything if you want that SoC vendor to continue to fulfill your orders (which you're already at the bottom of the fulfilment list because of low volumes)
to promise 5 year of security updates your SoC needs to also have that support for that time frame + part of your developmeant/production time (as you can't the last steps of development/production before that chip is released). Lastly you need to add the duration during which you promise the 5 years security updates.
to put it simple for a 5 year guarantee you need ~8 better 10 year support for the SoC, measured from is release date
a lot of phone SoC (which tend to get Android porting priority by their producer) have shorter support. Hence why the fp5 had a SoC from a product line designed for industrial embedded appliances instead of a phone SoC...
but the main reason is likely simpler:
They are relatively small and likely will updated FP5, 6,6+ to Android 16 roughly at the same time to not have to support multiple major Android versions for the same time.
Still as long as Android 15 still gets security this doesn't matter too much. Recent major Android version IMHO often have been more disruptive then helpful. At least for me, but my guess it's this applies widely for the kind of audience which pay more because they plan to actual have the same smartphone in use for more the 3 years ;)
Still only on my second smartphone, so I'm not worried about producing more e-waste.
https://www.shift.eco/en/shiftphone-8/
I'd be interested in the list, the website you've linked is super sparse (the full menu is like shop, some feel-good pages about device deposit and impact, blog, and contact us - no knowledge base, documentation, or somewhere where you'd expect to find OS info or even downloads)
After 4-5 years, on every phone I've ever had, user interactions begin to lag noticeably. Apps launch much more slowly. Intense graphical apps like maps become frustrating to use. At some point I can't take it anymore and replace the phone, long before its physical parts or battery have worn out.
Then I've decided that is worth either spending money on phones whose replacement parts doesn't cost half of the phone itself, or just buying the cheapest Xiaomi or similar chineese brand phone and when it breaks buy a new one or repair it (funny enough cheap phones are more repairable than expensive ones, so I usually repair them).
For sure it isn't the snappiest, but my only real performance issue is loading gifs on Signal, which takes several seconds for some reason.
Just tried maps now, actually still fairly fine for me.
There is also nothing precluding them from dropping Android in the future and putting effort into something like Sailfish OS.
There's no additional DAC involved, the analog audio is already on a USB-C pins.
> to fit other features in
what exactly, one would ask. If there are tradeoffs, if would be nice if the customers can decide what to have, in a modular product.
Only issue is some very cheap ones are actually bluetooth headphones in disguise where the usb-c connection only exist to power the bt recepter inside the headphone. I find this completely stupid.
A "modular product" has tradeoffs in and of itself (such as size, price, water resistance, …), which presumably would not fly for a majority of customers.
I applaud the concept but to see how well this actually holds up in the real world, let's check the Fairphone web site.
Where are the parts to repair any version prior to Gen 6? I don't see them listed anywhere.
So it would appear that "longevity" is actually pretty limited.
Fairphone 5 (2023) parts: https://www.fairphone.com/shop/category/spare-parts-4?catego...
Parts for the Fairphone 2 (2015) and Fairphone 3 (2019) aren't available anymore, but I suppose that's not all that surprising after 11 respective 7 years.
Afair, they started running out of some Fairphone 3 spare parts around 2024 and kept the ones they still had for warranty repairs. Source: I own one (and switched to the Fairphone 6 early this year).
So "longevity" is actually about 5 years. Or less if you live in the USA.
https://us.fairphone.com/repairs
https://www.ifixit.com/Device/Fairphone
Reminds me of the cold steel throwing axe that I bought that specifically has replaceable handles in case you break one. No one actually sells the handles though!
I bought one a few years ago. Good device, too big for my hands (back then, there were still smaller options so I bought one of those smaller ones in second-hand). Not having spare parts available would make me hesitate since that's like 50% of the point (fair sourcing being the other half), but besides that it's a (big) phone like any other
Here are the ones for the fairphone 4: https://www.fairphone.com/shop/category/spare-parts-4?catego...
I however couldn't find the ones for the fairphone 3. The fairphone 4 is from 2021, which is not that old.
For the American piece, the FP6 was the first available from OEM in the US.
Yes, that goes against most of Fairphone's own advertising, but it was consistent with my experience of the phone and discussions on the forum: security updates frequently so far out of date that some software could not be run, flimsy components inconsistent with advertising (yes, the battery was nominally swappable, but the snaps on the back would break easily, and support would claim that it was not intended to be removed regularly), parts that were frequently out of stock, and of course, whole new phone designs every generation rather than Framework-like component upgrades.
It seems like they may have improved since then, but those problems, along with the atrocious security (FP4 used AOSP's public test signing keys, with publicly-available private keys, for its firmware) and sketchiness around specs, standards and openness (especially for the camera), generally turned me off the company.