I don’t like smartphones. I use a dumbphone.

But this is a wonderful initiative.

  • TacticalCheddar@lemm.ee
    link
    fedilink
    English
    arrow-up
    25
    arrow-down
    5
    ·
    15 hours ago

    /e/os is a security dumpster fire. It’s even worse than stock Android. Stay away from it.

      • NotForYourStereo@lemmy.world
        link
        fedilink
        English
        arrow-up
        18
        arrow-down
        4
        ·
        13 hours ago

        Every other version of Android gets security updates out within a couple weeks of release at most.

        /e/OS users are lucky if they get them within a couple months.

        • sudneo@lemm.ee
          link
          fedilink
          English
          arrow-up
          13
          arrow-down
          3
          ·
          7 hours ago

          No offense, but that’s not what a security dumpster fire is. Security updates are important, of course, but they are also not the biggest deal.

          In fact, I bet that the vast majority of users (on Android or otherwise) are lagging way behind in updates anyway.

          • TacticalCheddar@lemm.ee
            link
            fedilink
            English
            arrow-up
            3
            arrow-down
            1
            ·
            edit-2
            4 hours ago

            That is not the only issue, it’s just one of the more major ones that shouldn’t be dismissed like it’s nothing. Another major one is the unlocked bootloader. You can take a look at all the Android ROMS here.

            I think people should treat carefully when changing the OS of a mobile device. Changing your OS to something less secure just because you want to shove it to Google and Apple is not enough to warrant it. Better to stay with something safe that you know than with something insecure like /e/OS.

            Luckily we have Graphene so you can actually switch to a more secure and private OS that is not made by an American corporation hungry for data.

            • sudneo@lemm.ee
              link
              fedilink
              English
              arrow-up
              2
              arrow-down
              1
              ·
              35 minutes ago

              I am not dismissing it, I am saying that is not as big as you make it to be. Most users lag behind in updates anyway, besides using minimal and trusted applications, the outside exposure to exploitation is relatively small, for a device without a public address. I am not the one APTs are going to use the SMS no-click 0-day against.

              Similarly for the bootloader issue. The kind of attacks mitigated by this are not in most people threat models. They just are not. As someone else wrote, it’s possible to relock the bootloader anyway with official builds (such as my FP3). But anyway, even for myself the chance that my phone gets modified by physical access without my knowledge is a fraction of a fraction compared to the chance that someone will snatch the phone in my hand while unlocked, for example (a recent pattern).

              If these two issues are what prompts you to call a “security dumpster fire”, I would say we at least have very different risk perceptions.

          • lostbit@feddit.nl
            link
            fedilink
            English
            arrow-up
            2
            arrow-down
            1
            ·
            4 hours ago

            good on you for asking the question. OP does not know what he is talking about

        • stephen01king@lemmy.zip
          link
          fedilink
          English
          arrow-up
          4
          ·
          13 hours ago

          Thanks for the answer. How does it compare against other Android forks in terms of security update speed?

          Also, isn’t Fairphone once also criticised for falling behind on Android security updates or was I misremembering this?