Read the whole thread

However, we don’t have a “hardened security” approach, we aren’t developing a phone for pedo(censored) so they can evade justice.

    • PolarKraken@lemmy.dbzer0.com
      link
      fedilink
      English
      arrow-up
      1
      ·
      2 months ago

      Honestly by now it’s becoming reasonable to assume “projection” as a baseline, to then change based on evidence, when someone has a take like this guy’s.

      I don’t mean the political tactic, just the garden-variety kind of projection. “Probably ~everyone thinks the way I do, and boy, we better not give everyone the tools to act on that…”

      Deeply wrong about how most folks think, because of how they themselves do, and believing they’re therefore helping. Likewise a self-admission, because they don’t realize they’re admitting anything.

      Maybe not the case with this guy, I’m not gonna dive in.

      But I do sincerely believe that’s a somewhat charitable take toward anyone making a claim like this today. Charitable in the sense of acknowledging a misunderstanding and desire to help.

      The less charitable one being - just obviously complicit. Fuck this noise.

  • blackbrook@mander.xyz
    link
    fedilink
    arrow-up
    1
    ·
    2 months ago

    I can’t believes he’s intentionally anti-privacy. Occam’s razor suggests he’s instead a fucking idiot.

  • Blackbeard@europe.pub
    link
    fedilink
    arrow-up
    0
    ·
    2 months ago

    Interesting conversation with GrapheneOS. Didn’t know they essentially hate each other. I’m using e/os but just because I cannot run graphene on my device.

    • Danitos@reddthat.com
      link
      fedilink
      arrow-up
      0
      ·
      edit-2
      2 months ago

      GrapheneOS’s leadership hates basically any other ROM. If you say something negative about GrapheneOS, he will probably call you out as part of CalyxOS team in a hate raid party, or something of the like.

      They make an amazing OS, but you’re better off not giving them much attention in their constant drama.

      • youmaynotknow@lemmy.zip
        link
        fedilink
        arrow-up
        1
        ·
        2 months ago

        Calling others on their bullshit does not equal hating on them. Why do you think CalyxOS had to ‘take a break’? Why do you think that The only thing these ‘privacy’ focused OSs can do about GrapheneOS is say it’s geared towards criminals? They have no other way to try and smear them because they’re all garbage in comparison.

        Get your shit straight. GrapheneOS is so fucking awesome that they plugged an actual Linux kernel hole within hours of it being found, whereas it took Google weeks, never mind these Murena and Calyx morons.

        • eldavi@lemmy.ml
          link
          fedilink
          English
          arrow-up
          0
          arrow-down
          1
          ·
          edit-2
          2 months ago

          … bullshit … criminals … smear … garbage … get your shit straight … morons.

          more expletives, than sentences; this reads like it was written by micay himself. lol

          • DisgruntledGorillaGang@reddthat.com
            link
            fedilink
            arrow-up
            1
            ·
            2 months ago

            People curse. Get over it. Just goes to show that you don’t have anything to say about the actual point of their comment when you clutch pearls like that.

  • FEIN@lemmy.world
    link
    fedilink
    arrow-up
    0
    ·
    2 months ago

    Kind of shameful of /e/ to blatantly disregard user privacy like that. Is Graphene our last stand against Orwellian surveillance?

    • lennee@lemmy.world
      link
      fedilink
      arrow-up
      0
      arrow-down
      1
      ·
      2 months ago

      i honestly dont care much about privacy in the sense that i dont rlly need it to be provided by an OS, just give me max freedom and let me handle privacy myself. That being said I am on grapheneOS atm but still hoping for librephone to enable me to have an arch linux like phone experience that i can customize to hell

    • SatyrSack@quokk.au
      link
      fedilink
      English
      arrow-up
      0
      ·
      edit-2
      2 months ago

      So you don’t have to give Reddit clicks:

      Dutch hardware, French open-source OS, no Google services.

      Apologies for repeating this in pretty much every topic on Fairphone and /e/OS, but there is a lot of misinformation about this. The Fairphone hardware and software is developed by a Chinese company called T2Mobile (this is no secret, it is in Fairphone’s documentation).

      Switching to /e/OS does not really change that, because they use the same kernel trees, binary firmware blobs, and device trees maintained by the same Chinese company. So you replaced opaque blobs coming from a South Korean company to those from a Chinese company and Qualcomm (pick your poison I guess).

      Besides that /e/OS does not really decouple you from Google. It starts talking to Google pretty much the moment you first set up the device [1]. The device will download proprietary Google SafetyNet blobs that run as part of the privileged microG. /e/OS also contacts Google for assisted GPS, eSIM provisioning, WideVine provisioning, etc. Then if you install certain Google Apps, /e/OS gives them elevated privileges, breaking the regular sandbox model. For instance, if you install Android Auto because you want to use it in your car, some of the dependencies (e.g. Google Maps) have privileged access [2]. It does not stop at Google, e.g. for speech-to-text, Murena does not have any scrupules uploading your voice to OpenAI (and hide it somewhere in the terms that no-one reads) [4].

      Besides that, both Fairphone and /e/OS have a history of abysmal security. E.g., both used to sign system images with Android testing keys (which meant that malware could hide in your system image without you noticing). Fairphone is absolutely terrible at maintaining kernel trees - e.g. Fairphone 4 is still using a Linux version that has not been updated since 2020, Fairphone 6 is still on firmware blobs from June 2025 despite Qualcomm pushing out monthly fixes for vulnerabilities since then. The Fairphone 6 is also shipping a Linux kernel that hasn’t been updated since September 2024.

      Both the Fairphone stock OS and /e/OS are way behind on Android security updates. The Android Security Bulletins are only backports of security issues marked high or critical. On those they are typically 1-2 months behind and the ASB vulnerabilities are already known for 3 months by vendors due to Google’s new security embargo system. That means that Fairphone’s stock OS and /e/OS are usually 4-5 months behind on patching high/critical vulnerabilities. It is even worse for other vulnerabilities, which are commonly used as part of exploit chains. /e/OS and the stock OS are still on Android 15. Since they do not roll out other security updates than ASBs, it means that they are now 1.5 years behind in non-high/critical security updates (since Android 15 was released in September 2024).

      And then we haven’t even talked about shady things like the /e/OS App Lounge getting F-Droid packages [3] through a MITM server (cleanapk) for at least 6 years now that often serves outdated package versions. To make it more fun, they do not want to reveal who is actually maintaining this service.

      Similarly, hardware security is not great. In contrast to your old S24, the Fairphone 6 does not have separate secure enclave. They only use TrustZone, which basically uses the same CPU/RAM for the TEE (the OS gets isolated by secrets running it in a VM-like environment). TrustZone is vulnerable to side-channel attacks and PINs are easily brute-forced (so, on Fairphone you probably want to use a long passphrase).

      Some people will say: who cares, I’m not the target of a state level actor. Remember that in the days of Cellebrite, etc. device security is important to anyone who ever goes to a demonstration or crosses international borders.

      I understand that everyone is looking for European alternatives, please think twice if you want to replace them by Chinese blobs, very outdated software, and a security disaster.

      [1] https://www.kuketz-blog.de/e-datenschutzfreundlich-bedeutet-nicht-zwangslaeufig-sicher-custom-roms-teil6/

      [2] https://eylenburg.github.io/android_comparison.htm

      [3] https://forum.f-droid.org/t/e-foundation-using-f-droid-with-middle-man-website/7162

      [4] https://forum.fairphone.com/t/e-os-betrays-users-privacy-openai-being-integrated-directly-into-core-os/119381

  • 5PACEBAR@piefed.ca
    link
    fedilink
    English
    arrow-up
    0
    arrow-down
    1
    ·
    2 months ago

    Take this with a grain of salt: GrapheneOS is always stirring shit with other players in the privacy space and they try to paint them in the worst light possible.