More than a decade after launching in Europe, the Netherlands company is now selling its repairable phones in the US, starting with the Fairphone (Gen 6+).
It wasn’t just the update cycle either, it’s that they don’t have the physical hardware chips to support Graphene’s minimum requirements for security, which would severely weaken any benefits you actually get from GrapheneOS.
It’s also missing hardware accelerated virtualization which is necessary for much of GrapheneOS’s sandboxing, has weak security for other keys in the OS keystore, is missing hardware memory tagging which makes it much easier for apps to use overflow attacks, doesn’t have proper verified boot support once a custom alternative OS is flashed, and leaves exposed debugging APIs even when the phone is locked.
This breaks:
Secure app spawning
Memory corruption protection
Integer overflow protection
Most of Graphene’s kernel hardening
Much of Graphene’s attack surface reduction abilities
Hardware-based attestation and security monitoring
Quick tile protection pre-unlock
Debugging access prevention
Verified Boot
The security of your PIN against any automated attack
At that point, GrapheneOS can’t physically provide you essentially any security anymore.
It really depends on what security level you want out of a phone. Most people are concerned with a pickpocket stealing and being able to access everything. Most of the world doesn’t need the security level required to pass through the united states border control. Which they will just force to put the pin anyways or put you in jail for even having a secure device.
It really depends on what security level you want out of a phone
It does, but that’s exactly my point. GrapheneOS will provide you essentially no more security than any other alternative Android operating system, should it have to operate on a Fairphone with all those features not supported by a Fairphone stripped away.
Unless Fairphone adds more hardware security features that are standard on most other phones, and highly supported on Pixels, installing a heavily crippled GrapheneOS on a Fairphone would get you essentially none of the benefits of GrapheneOS in the first place.
Well sans duress password being a good idea now, when you get to the border, you can either unlock it or they’ll just confiscate it. You don’t get to be on their list and go through with a phone because they can’t manage to decrypt it.
No I think you are thinking of calyx. Graphene repeatedly asserted that they won’t support fairphone because of the slow update.
It wasn’t just the update cycle either, it’s that they don’t have the physical hardware chips to support Graphene’s minimum requirements for security, which would severely weaken any benefits you actually get from GrapheneOS.
not any, but some benefits, and GrapheneOS maintainers are perfectionists
Entirely lacking disk encryption for typical users due to not having a secure element is a pretty major flaw.
It’s also missing hardware accelerated virtualization which is necessary for much of GrapheneOS’s sandboxing, has weak security for other keys in the OS keystore, is missing hardware memory tagging which makes it much easier for apps to use overflow attacks, doesn’t have proper verified boot support once a custom alternative OS is flashed, and leaves exposed debugging APIs even when the phone is locked.
This breaks:
At that point, GrapheneOS can’t physically provide you essentially any security anymore.
It really depends on what security level you want out of a phone. Most people are concerned with a pickpocket stealing and being able to access everything. Most of the world doesn’t need the security level required to pass through the united states border control. Which they will just force to put the pin anyways or put you in jail for even having a secure device.
It does, but that’s exactly my point. GrapheneOS will provide you essentially no more security than any other alternative Android operating system, should it have to operate on a Fairphone with all those features not supported by a Fairphone stripped away.
Unless Fairphone adds more hardware security features that are standard on most other phones, and highly supported on Pixels, installing a heavily crippled GrapheneOS on a Fairphone would get you essentially none of the benefits of GrapheneOS in the first place.
Well sans duress password being a good idea now, when you get to the border, you can either unlock it or they’ll just confiscate it. You don’t get to be on their list and go through with a phone because they can’t manage to decrypt it.