GrapheneOS is like a veteran and war zone expert: for them, not only the external environment is considered extremely hostile that you should leave your house only wearing an armor and with bodyguards, but also the internal environment is hostile: your bodyguards could be bribed and work against you, that's why you need to somehow be protected against that as well.
Just as physical security, digital security most of the time not as radical, and tradeoffs are usually accepted, especially when they are "invisible": hardware and software security features are usually not mentioned in the specs and the regular and even power user just don't know most of them and what do they do.
When GrapheneOS says "private" and "secure", they mean top-of-the-line security features, updates as soon as possible, all available mitigations against zero-days and insecure code which will limit the impact before the patch, etc. Security as in a killdozer.
When other say "private" and "secure", most of the time it means: "we've followed all the recommendations applicable to our development budget, device price point, and support life time". Graphene does not like that definition of these words.
For smartphone, chip manufacturer goal is not to protect the user at all costs, but to provide reasonable security features for the price.
BUT the goal of chip manufacturer to protect the device at all costs is for… game consoles! That's why Xbox, PlayStation, Switch all run on a custom silicon and not an ordinary chips!
> That's why Xbox, PlayStation, Switch all run on a custom silicon and not an ordinary chips!
Not really. Xbox and PlayStation both run on pretty standard AMD Zen 2 chips. Somewhat customized, but standard enough that people by binned playstation 5 motherboards to use as computers with normal OS'es (lookup BC-250). The last gen with more customized chips was the PS3/Xbox360 era, when both went with a variant of PowerPC, same as Gamecube/Wii/WiiU.
Switch runs on basically the same Nvidia Tegra CPU/GPU as multiple android tablets.
I think you should listen to bringup of Linux on Playstation talk from CCC to understand that those platforms are much more than just "somewhat customized".
There are whole sections of peripheral chips missing and they behave quite a bit differently with how they bootstrap and where things are mapped in memory.
The steam decks APU was designed for Magic Leap 2. It is one of the worst examples you could choose for a chip specifically designed for the thing it is in.
>but standard enough that people by binned playstation 5 motherboards to use as computers
That doesn't mean that all the features are enabled right from the factory, or that the compatibility with already existing features is lost.
Modern chip's security features are pretty complicated and include hardware patches, hardware debug authentication, multiple provisioning states (and multi-key hierarchy for that), RMA states to clear all the private information, etc.
>Switch runs on basically the same Nvidia Tegra CPU/GPU as multiple android tablets.
Yes, and the one which got cracked with a bootrom vulnerability ;)
That's a pretty working motivation for a chip company to improve their chip security when the company as beefy as Nintendo tells them that their chip is vulnerable they're losing money because the customers can play for free ;). I'm pretty sure patchable bootroms started to be common only after Switch hack.
It is a foundational reality that software (especially in unsafe languages) will invariably have vulnerabilities. Defense in depth and least privilege have compounding effects by forcing attackers to chain multiple exploits to achieve a compromised device, rather than a single vulnerability.
GrapheneOS shows how much can be accomplished on top of relatively secure platforms to begin with (AOSP, Pixel Stock OS, etc.) without sacrificing nearly any usability to the end user (barring manufactured hurdles like Play Integrity). It makes it more damning that many "privacy" OSes and devices cannot even meet the baseline level of privacy and security that AOSP provides, but degrade it.
Firmware and driver neglect and the lack of secure element utilization is not "reasonble security for the price".
>GrapheneOS is like a veteran and war zone expert: for them, not only the external environment is considered extremely hostile that you should leave your house only wearing an armor and with bodyguards, but also the internal environment is hostile: your bodyguards could be bribed and work against you, that's why you need to somehow be protected against that as well.
Yeah, iPhoens are made that way as well. It's just caring about the privacy of your users.
> When GrapheneOS says "private" and "secure", they mean top-of-the-line security features, updates as soon as possible, all available mitigations against zero-days and insecure code which will limit the impact before the patch, etc. Security as in a killdozer.
I think it's deceptive because people think they will get better privacy/security with a /e/ fairphone when it's actually much worse than an iPhone.
It's amazing how people still fall for the marketing. Apple is an ad company, just like Google. Advertising and data collection is baked into their OS, store, and core apps. They're just trailing behind revenue-wise by a few years.
/e/ does have services collecting data on their users which isn't disclosed including user tracking via unique identifiers in the update client. They also spent years sending user speech data to OpenAI without informing users beyond fine print in the terms of use. It's presented as not using Google services but has a whole bunch of Google services with privileged access enabled by default. It even downloads and runs Google Play executables such as droidguard by default with privileged access far beyond the regular app sandbox.
Privacy and security from what is the question. From big tech or from criminals and governments that take your device and plug it into cellebrite machines?
I for one prefer to be protected from big tech. Sure GrapheneOS does both, but Apple does not.
iPhone is top-of-the-line as well, because they control the whole software and the whole hardware (starting from basically all the chips). That's very rare in the industry.
There are just a bunch of companies which afford to do the same. Maybe Xiaomi will be the next one.
Fairphone makes their fair share of blunders. Software updates are a big issue, especially around the times that critical vulnerabilities need to be patched.
With the hardware I'm not impressed, and on their own forum I've seen plenty of people reporting issues with overheating on the Gen 6. Hopefully kinks have been ironed out on their 6+.
The current CEO also has a persona that would stir up any community (read a few of his AI-gened posts on their blog, if interested of context).
Still holding on to my FP4, but they are not of consideration on my future phone purchase, unless there is some kind of reality check over there and improvements materialize beyond words.
Ultimately, a lot of the “fairness”
of the Fairphone is offered by “just buy a really popular manufacturer.”
Everyone and their dog can repair an iPhone because it’s the most popular phone on the planet. Are those repairs accessible to the consumer at home with amateur skills? No, not really. However, newer iPhone models are significantly easier to repair and come along with lower repair costs direct from the manufacturer compared to previous models.
You want years of software updates? Yeah, an iPhone has you covered there, too.
And of course, fairphone’s hardware and OS are nothing to write home about. For the freedom and security nerds they’re better off with GrapheneOS on Pixel or whatever upcoming Motorola phones will support it.
Who is the Fairphone for exactly? Who is buying it and why?
I think the fairbuds are their best product, but I also imagine AirPods Pro 3 are on a whole different level of sound quality, noise cancelation, voice quality/voice isolation, and firmware/software polish.
And let’s be honest about repairability with tiny earbuds: being able to replace the battery is has such a tiny impact on their footprint. If I have to throw out my
AirPods Pro 3 every 5 years due to battery degradation, that’s such an insignificant quantity of material being wasted, so it’s probably worth it to get a better product. I could offset my environmental impact by eating a little less beef or riding my bike instead of driving a few times. You drive 30 miles and that’s an entire gallon of refined petroleum product, how much material and energy is used to make one pair of AirPods? I can’t imagine it’s a lot.
I don’t say any of this to be a big corporate or Apple shill. I am rooting for the little guys. But the little guys need to be realistic. You look at products like the Framework 13 Pro and you can actually say, okay, here’s a product with really legitimate benefits over its incumbent competition. There is a reason to buy this product for a certain buyer. I just don’t see that with Fairphone. I can’t think of a customer profile where that person is getting a better ownership experience with Fairphone products.
I'm not big on this general line on argument, but one point in particular:
> And of course, fairphone’s hardware and OS are nothing to write home about. For the freedom and security nerds they’re better off with GrapheneOS on Pixel or whatever upcoming Motorola phones will support it.
For the "freedom nerds", FP is one of the only (if not the only?) vendor to have official support for microG-based operating systems, seamless OTA updates and everything included. The Murena e/OS offering in particular is simple enough that the non-nerds that (perhaps less outspokenly) care about freedom can just pick it up with little change in habits.
I guess that’s true, although we could possibly split that camp into two sides: the folks who believe that Play Store sandboxing is going to be more functional, and the folks who prefer microG are willing to accept the issues that come along with it.
To be fair on either side of that debate, getting a phone that comes with /e/OS installed from the factory is going to be easier than flashing GrapheneOS on a Pixel or LineageOS with microG on another device.
Devices are sold with GrapheneOS installed. Installing it with the web installer is very easy and safe so that's the recommendation for nearly everyone.
> For the "freedom nerds", FP is one of the only (if not the only?) vendor to have official support for microG-based operating systems, seamless OTA updates and everything included.
I am not sure what you are trying to say here. I have never had an Android system that did not have OTA updates. Everything included... I usually like to install the apps I want?
As for microG, I think it's debatable. Is it better to have microG contacting the Google servers or sandboxed Play Services going through a Graphene-powered proxy? And say you have microG going through a Murena proxy (do they do that?), is that significantly better than sandboxed Play Services? At the end of the day, your system is made mostly of code written by Google (AOSP).
> The Murena e/OS offering in particular is simple enough that the non-nerds
Yes, I think it's what makes Murena successful. It's surprisingly simple to install GrapheneOS on a Pixel (you follow a wizard on a Chromium browser and click "next" a bunch of times), but many people are scare just by the idea.
> I am not sure what you are trying to say here. I have never had an Android system that did not have OTA updates. Everything included... I usually like to install the apps I want?
The last bit of my sentence could easily be misread as an enumeration of three things ("microG", "OTA updates", "everything included"), but it was actually an elaboration: FP is the only vendor to support microG, and (in contrast to "unofficial" microG setups) it doesn't require sacrifices in convenience because standard features like OTA updates work just like with your average Android. Perhaps that's clearer?
(Notably "Everything included" does not mean it ships a thousand apps or something. To the contrary, FP stock OS is mostly vanilla Android)
Point being: I could install LineageOS on my last phone, but it was a poorly documented process, updates were a hassle (having to flash through custom recovery for lack of OTA), and I had virtually no confidence in data integrity when running major updates.
> Is it better to have microG contacting the Google servers or sandboxed Play Services going through a Graphene-powered proxy?
How about microG not contacting Google servers at all?
In any case you're presenting an unnecessarily binary argument though. Letting Google handle push notifications is different from using them as your location provider, and both are different from letting all Play Services lose on your system.
> How about microG not contacting Google servers at all?
I already addressed that in my comment, right after the line you quoted.
> Letting Google handle push notifications is different from using them as your location provider, and both are different from letting all Play Services lose on your system.
And what would you say GrapheneOS does of those? Do you know, or do you just assume that GrapheneOS does the worse there?
> I already addressed that in my comment, right after the line you quoted.
Where? You suggested it would go through Murena instead, but you can fully disable third party services by disabling external push providers and by using on-device databases for GPS. e/OS directly offers this configuration during initial setup.
> And what would you say GrapheneOS does of those? Do you know, or do you just assume that GrapheneOS does the worse there?
I'm not necessarily trying to present either as "better" or "worse" since they both have their merits depending what exactly you're after (which I don't feel this is the right time/place to have a detailed rundown of). It was the root comment that posited e/OS was strictly inferior for people who care about freedom.
isn't the main point of Fairphone to not use conflict minerals?
by using FOSS only myself and hating monopolies like Apple etc., i still pretty much convinced that being "green" or "ethical" is more about participating/volunteering/doing-something towards a better world than off-loading your duty to other companies... one could easily make a point that Apple products despite locked down, are still green (Apple has a bunch of zero-emission and whatever policies) and much more if one uses their devices for a long while. i had a 2° hand iPhone SE 1° gen. till 2021? if stuff breaks despite your not being able to fix it's not like you can't hop into a specialized shop to change batteries or even pay the expensive service Apple offers... sure that allows exploitation and it's always nice to get rid of it, that's why somehow these emerging companies are important and/or policies like the right of repair will make them obsolete
I have been wondering and I first got a Fairphone 3+ because I thought, among others, it was "greener".
Then I realised that:
- Fairphone 3 was already "slow" when it was released in 2019
- Fairphone 3+ was pretty much exactly the same hardware, but I bought it 2.5 years later
- My Fairphone 3+ was annoyingly slow from the moment I bought it (I was using it less than a normal phone because of that, and I just completely gave up on using the camera and asked other people to take photos instead).
- My Fairphone 3+ became painfully after 1.5 - 2 years.
I did not change phone because the hardware was not running anymore. I changed because I just couldn't use the few apps I needed because they were unusable (lagging and crashing). I don't mean games: banking apps, weather forecasts, public transports. Pretty much only Signal/WhatsApp were fine (slow, but fine).
So I painfully kept my Fairphone 3+ for a little more than 4 years.
Then I realised that people who buy an iPhone routinely keep it 6-8 years, without it being painful at all. Is it "greener" if I buy one iPhone/Pixel, or 2 Fairphones? I'm not so sure anymore. What I know is that the iPhone/Pixel are not painful to use.
I think your story also points to the idea that business ethics or other tertiary benefits will only sell a product to a limited extent. They help, but the product being fit for its core purpose is still most important.
> For the freedom and security nerds they’re better off with GrapheneOS on Pixel or whatever upcoming Motorola phones will support it.
Not quite. The people who care about security first are better off with GOS, yes. However, GOS's threat model very specifically treats the user as a thing to defend against; the freedom-first crowd should avoid them.
> However, GOS's threat model very specifically treats the user as a thing to defend against
Can you elaborate?
GOS mostly honours the Android security model, which many alternatives don't do (many times they don't have a choice because the device doesn't allow them to relock the bootloader, so they just defeat the whole security model from the moment you install).
There is absolutely nothing that can be done on a Stock Android and that I cannot do on GrapheneOS. Or at least I haven't found it.
Yes, GOS is probably a direct improvement over stock android; I would also describe that as suboptimal from a user freedom perspective. Really, most of my beef with GOS is that its developers strongly object to user-controlled root. On my phone, I can run a backup app, give it root access, and backup/restore any app at will. Or, I can run a file manager with root access and inspect any data in the system. The GOS devs object to this on the grounds that any user-installed app getting root undermines their entire security model (and some other arguments that I'm going to skip because I'm trying to steel-man). And that's actually a perfectly valid argument; handing root access to apps does break their security model, but if the user doesn't have root then I'd contest the idea that the user is in control. And of course there is the fact that I have actual uses for root that GOS doesn't provide. (There are some other variants of this basic tension, like bootloader locking, but I think root is the biggest instance and representative.)
> And that's actually a perfectly valid argument; handing root access to apps does break their security model, but if the user doesn't have root then I'd contest the idea that the user is in control.
First, "protecting against an app running with user permissions" does not mean "considering that the human owning the device is malevolent", right?
The idea is that if the human installs a malware, we don't want that malware to own the system. I think it is completely fair, and for most people it is the better deal.
Second, your complaint about GOS is that you want root access, and they don't provide it. You want a feature they don't provide, sure, but that happens. And that's probably a good reason to use an alternative system. But turning "I want feature X" into "if you don't provide the feature I want, then you are not free software" is manipulative IMO. GrapheneOS is as open source as it gets, you can fork it and install it on your Pixel. It is free software. Maybe not the software you want (that's okay, different people have different preferences), but free software nonetheless.
That doesn't come across as steelmanning our position at all but rather the opposite. It omits the most important points.
Providing app accessible root in the OS greatly reduces security without people ever using it. It gives root access to a huge portion of the OS by having it around as a feature even if it's never used. It fundamentally breaks a large portion of the security model for verified boot, which can no longer defend against attackers maintaining privileged access after a compromise
In addition to the inherent reduction in security from providing it, nearly all apps built around using full unconstrained root access don't need anywhere close to that. In nearly all cases, it's used as a shortcut instead of doing things securely. Following the principle of least privilege by only granting the required privileges is a core part of security. For example, an app for managing low-level firewall rules only needs an API for doing so in netd and netd only needs CAP_NET_ADMIN rather than full root. Doing this by giving full root access to a graphical application which is not properly integrated into the standard firewall management is not a secure approach. Giving full root access to a large portion of the rest of the OS in a way that can be hijacked in many attack vectors to make it possible to dynamically grant it makes it a lot worse.
GrapheneOS does have user-accessible root access in userdebug builds. Those aren't the main production builds of the OS but people who believe they know better and want to have it can build, sign and use those instead. Building the OS also gives an opportunity to include safe implementations of features instead of insecure hacks.
Every app can be backed up as part of the baseline. Apps can exclude specific data but are nearly all doing so because that data is a cache or can't be used elsewhere. For example, Signal encrypts their database with the hardware keystore and bypassing them excluding it from backups to back up all the files for it will not result in the data being possible to restore elsewhere.
How about having full access to /data? Or full system backups GrapheneOS still lacks? One might object granting root access to apps, but the device owner should at least have full FS access via adb.
That's available in userdebug builds of GrapheneOS via ADB. A userdebug build can be done with ro.adb.secure=1 to keep the ADB authentication model intact which is disabled in userdebug builds by default for early boot debugging.
Since we're steelmanning, I would like to add a bit more.
GrapheneOS will never be closed source/proprietary because they believe code freedom (and user freedom by extension) is paramount. They have repeatedly said they don't have the resources to build a ChromeOS-esque firmware authentication and warning flow for ephemeral user-accessible root and support those builds alongside the existing production environment. They have NOT said it is something they have no interest in even discussing. They have also repeatedly said that where the utility is clearly demonstrated and can be architected in a maintainable way, they are open to contributions (and continued maintenance) that properly enable functions that people unnecessarily need to abuse root privileges for.
The main goal of their project is a system that can protect your personal thoughts, associations and memories to the best of its ability (against thieves, attackers, surveillance etc.) while preserving your interaction with the world. Current OSes (including GrapheneOS and iOS) are already far behind where they should be given the wealth of privacy enhancing technology, computer hardware security, systems engineering and OS design knowledge that has existed for decades- so their work is cut out for them and they are putting everything they have into leading the industry. Their hands are already full. For clear use cases the path of least resistance would be to contribute and commit to maintaining features everyone would benefit from.
If it is a feature/function someone understands they would benefit from personally but do not see the value to impose on others, we can circle back to the original fact which is that GrapheneOS is open source and can be bent/built to your will.
Well said. I would say in general there isn't "the best" OS for everyone and never will be, because each OS makes different trade-offs. I for one want primarily what is understood to be "general purpose computer". Other people rightly don't care about that and want a maximum security device, one that even protects users from their own mistakes (of course putting more trust in the makers of the OS). What we should care about is that people have a choice and can get whatever they prefer.
To answer GPs point, I think Fairphone doesn't primarily target either of the two audiences. I think they primarily target the people that care about the ethics of the creation of the hardware. Basically people who would like to minimize the invisible human cost that their phone creates.
The new Sennheiser earbuds have replaceable batteries too so the fairbuds are no longer unique in that regard. I haven't read comparisons on sound quality though
And of course, wired headphones still exist as an alternative for those who really don’t like the battery aspect, and it’s not even terribly inconvenient for phones without a headphone jack.
I suspect that the venn diagram of the kind of person who takes issue with Bluetooth audio batteries and the kind of person willing to use wired headphones or prefers them outright has a lot of overlap.
Fair enough, but note that it does not concern GrapheneOS. Hopefully soon available on Motorola phones :-). That would be my next phone (assuming it's not too expensive of course).
The GOS people really spend a lot of time of energy showing the worst sides of FairPhone to the world. I think it is because the conscientious technology user is really interested in the combination of ethically sourced, repairable hardware and a security and privacy (from big tech) focussed OS. Tbh I also like that sliders to switch to a simple mode. A well, we can’t have it all. I do prefer de-googled + freedom to do what I want over security (to a degree). So… I’m on the fence. As many vocal people are. A second hand pixel 10 is also a “green” choice.
I do have the feeling that many non-nerds can express the difference between all mentioned attributes, many just like FairPhone as an ethical phone. It’s not that simple, I agree.
So I have been on /e/OS on a Fairphone 3+ for 4.5 years. I was really into /e/OS when I got my Fairphone. When it stopped being usable (not because the hardware was not working anymore, just that the apps I want on my phone were lagging so much they were unusable), I looked into alternatives, including GrapheneOS.
And at that point I got quite disappointed by /e/OS, because I felt like their marketing had been abusing me for years. For instance, my Fairphone 3+ was 4 years behind the Fairphone Stock Android on some updates. /e/OS just wasn't forwarding them, they seemingly were just not maintaining the FP3. Though I bought it to /e/OS, under the promise that it would be supported!
Then I realised that all this time, not only my bootloader was unlocked (so the Android security model had been broken from the first day I powered the phone), but the system was signed with the Google test keys! When you are encouraged to install apps "from the internet" instead of the Play Store, on a phone that disabled the security model so that you're not protected against malware as on any Stock Android, would you say it's being a security nerd?
The thing that GrapheneOS keeps repeating and I realised is true is that many times, if you run a deGoogled alternative that is not GrapheneOS, you get worse security than if you were running Stock Android. It's not about "getting the best possible security", it's about getting the baseline. The truth with /e/OS (or LineageOS, which is pretty much what /e/OS ships, I believe?) is that it depends a lot on the phone. And with many phones, you get worse than the baseline you would get with Stock Android.
> I do prefer de-googled + freedom to do what I want over security (to a degree).
So I switched to GrapheneOS on a Pixel, and I feel like I get the best of both worlds: I get the privacy benefits of the sandboxed Play Services, and the better security. And it's not a "weird" system at all: I asked my family to use it and they didn't realise it was not a "normal Android". It is very different from running something like a Linux on mobile, which would be very very different.
> many just like FairPhone as an ethical phone
Yes, why not. If I was to get a Fairphone again, though, I would use the Stock Android.
And I wish Fairphone could get to the level where they can be supported by GrapheneOS. But it feels like my next phone will probably be a Motorola with GrapheneOS rather than a Fairphone.
GrapheneOS provides massive privacy and security benefits to regular people. That was always important to regular people due to regular devices being nowhere close to good enough to protect people well enough against common threads to their privacy. However, it's far clearer now that exploits have been made so widely available without having expertise. There are many publicly available Android local root exploits on GitHub usable on these devices.
I think it heavily depends. If you are concerned cops or CBP are going to try to take your phone and search it then wanting a phone like GOS is a very reasonable precaution.
Even if you haven't done anything "wrong", you may have engaged in speech or activities that the current US admin has deemed problematic and will try to punish you for if they can find any evidence.
I think this has historically been true and is still approximately true now. But I think in the relatively near future (less than 5 years) there's a really good chance it won't be true anymore.
Once open models catch up to the current frontier in vulnerability exploitation, the cost to target people will go way down. In the past, the cost to hack a random individual person was generally high enough that if there wasn't some special reason to hack you in particular, it wasn't worth it. That may no longer be the case in the near future. The floor of what is acceptable security for the General Public probably needs to rise quite a bit over the next few years.
Why would you assume Google, Apple, and defense-oriented agencies like CISA wouldn't also have access to those same models, but using them to fix issues?
Its just raising the bar across the board, I don't see how only attackers would benefit.
The quote wasn't talking about personal security from governments and corporations. You're warping the meaning into a situation where it doesn't fit at all.
Fairphones are closed source hardware with closed source firmware and closed source userspace drivers. Fairphones are less open than Pixels, not more open.
It isn't truly known how a Fairphone compares to an iPhone or Pixel when it comes to environmental impact or fairness to workers. Fairphones are designed and built by T2Mobile since the Fairphone 4. T2Mobile barely has any public information available about it. There isn't information on the working conditions, pay and other aspects of of it. The same applies to the rest of the supply chain. Fairphone provides a list of companies involved in the supply chain without details.
Fairphones are closed source hardware with closed source firmware and closed source userspace drivers. Fairphones are less open than Pixels, not more open.
It isn't truly known how a Fairphone compares to an iPhone or Pixel when it comes to environmental impact or fairness to workers. Fairphones are designed and built by T2Mobile since the Fairphone 4. T2Mobile barely has any public information available about it. There isn't information on the working conditions, pay and other aspects of of it. The same applies to the rest of the supply chain. Fairphone provides a list of companies involved in the supply chain without details.
iPhones and Pixels have similar replacement parts available and much longer term support. It's harder to replace components but the phones last longer due to better hardware and updates.
I really would like to mention that many times, using /e/OS or LineageOS (or the likes) means that you get worse security than Stock Android.
It would be fine to run /e/OS or LineageOS on a Pixel, assuming those Android systems are not too slow with updates (my experience with my /e/OS phone was that they were 4 years behind as compared to Stock Android).
But really, if you have a Pixel, it doesn't really make sense to use something other than GrapheneOS IMO.
> It would be fine to run /e/OS or LineageOS on a Pixel
Both /e/ and LineageOS lag far behind on current security updates on a Pixel. Neither is based on Android 17 yet which was released in June 2026. Neither has the June 2026 or later Pixel firmware, kernel, driver and HAL patches. Both also roll back the standard security of AOSP but /e/ does so much more than LineageOS.
As you can see at pixel 9 pro's (https://download.lineageos.org/devices/caiman/changes)[los changes], it was updated around Aug 18th (or at least that's when the string bump happened), so although ~2 weeks late (assuming the security patch was released at August 1st, which I'm not sure if it really works this way), it's not as bad as you said.
But yeah GOS is probably the better choice for pixels, depending on the user's prefs of course.
Btw I noticed similar pattern for other devices that support los, like xiaomi ones.
Your response doesn't address what we said. You linked to a page showing LineageOS had a release in August 2026 which does not show it has shipped all the recent standard Android and Pixel security patches, which it hasn't done.
The latest releases of LineageOS for Pixels do not provide the June 2026 and later updates to the firmware, kernel, drivers and HALs because those have only been provided for Android 17 since it was released and LineageOS isn't yet based on Android 17. Separately from that, since Lineage is still based on Android 16 QPR2 it also doesn't include the many privacy and security patches not backported from Android 17.
Android ships many security patches as part of the QPR2 and yearly releases which are not backported to older releases. The backports to older releases are increasingly incomplete. Years ago, they stopped backporting any Low and Moderate severity patches to older releases and more recently they've been scaling back the amount of High and Critical severity patches which are backported. An official policy announcement was made to OEMs that they'd no longer backport many High and Critical severity patches where an LLM discovered the vulnerability internally due to the large volume of patches.
Pixels move to the latest OS releases and that means the firmware, kernel, driver and HAL code is only provided for those. It's most difficult for the major yearly releases due to the new API level but it's not trivial for QPR1, QPR2 and QPR3 either.
> It's not like any other device meets their ridiculous standards either
I don't think it's ridiculous to want the ability to relock the bootloader, for instance? Do you realise that if you cannot do that, you just break the whole Android security model right away?
It's a reasonable extrapolation of the current state. They want up to date patches, Google is already winding down open support for that, and it'll release in what, a year or two? Basically guaranteed to have outdated security patches on launch or they'll have to start maintaining their own. Might happen, but it seems unlikely they can hack it, as it were.
There are devices meeting these basic standards right now, and the entire family of them, no less.
GOS are vocal about safety and security of all the devices, not just seriously insecure Fairphones, and this article is about something different altogether, that's misinformation they've been hit with several times.
Fair criticism is fair, but yours is fabrications.
A problem I see is that GrapheneOS has a history of being extremely blunt about the shortcomings of alternatives, and of course alternatives (and users of alternatives) don't like getting that feeling that maybe they have been compromising on... something.
At least that's how I felt when I starting reading more after a few years of using /e/OS on my Fairphone 3. And the more I read, the more I realised that GrapheneOS was usually technically correct (their communication used to be a different story, but recently I feel like it has become a lot more professional, focusing on the technical side).
Really, the vast majority of technical criticisms I see against GrapheneOS are misinformed. I'm not saying that the commenters purposely say lies. Just that it all is technically non-trivial, and I totally understand that most people don't really understand how the Android security model works, for instance.
All that to say: I don't think that there is hypocrisy on the GrapheneOS side. They are very consistent on what they are trying to do.
Yeah it's hard to argue that their points are technically incorrect, after all this is the mobile ARM ecosystem we're talking about, with buggy ass locked down binary blobs with more security holes than swiss cheese that are never updated, as the industry standard. And in regards to Fairphone, user reviews have generally shown that their disregard for keeping their software updated by far eclipses any gains made by the repairability aspect. And I can sort of respect being brash about pointing the flaws out.
My main source of contention with Graphene is more ideological in the way they've gone about doing something about it: by using the Pixel. To quote that old batman comic meme: "This is the weapon of the enemy. We do not need it. We will not use it." At the end of the day, Google gets $1k or thereabouts for every GrapheneOS install which they can use to further advance the cause of mass surveillance, as an adware firm they have the most misaligned incentives of any manufacturer in existence. The company that is almost too eager to cave to every whim of the fascist in chief in hopes of it benefiting their bottom line. That's what I see as insanely hypocritical. By being this exclusive, it counts as a complete endorsement.
> By being this exclusive, it counts as a complete endorsement
I disagree. The only way they can prove that they can build a good system is to prove it on good hardware, and the Pixels are the only ones that meet the criteria. If GrapheneOS was running on random phones like LineageOS does, with unlocked bootloaders and/or signing with the Google test keys, then GrapheneOS would be no different from LineageOS (and wrappers on top of LineageOS like /e/OS).
Said differently, your complaint about GrapheneOS is the very thing that gives a reason to exist to GrapheneOS.
And I think GrapheneOS is proving its point: more and more users and finally got interest from Motorola. I am quite impressed and I hope it will continue growing and getting more and more interest by other manufacturers.
At the moment there is no other hardware manufacturer making similarly secure android phones.
*NONE*
There is no android hardware coming close. If there is, please name it. As far as I know it's only some unspecified, upcoming Motorola flagships.
If you call the unwilling, pragmatic choice an "intense hypocrisy", it's pretty clear to me you're simply driven by emotions and tribalism, that the facts don't matter.
Are you saying that using Google hardware equals using stock Google os?
You must be a little more.... Coherent with your metaphors :)
That's exactly my point. Imagine for a second that there's no Pixel. What would GOS do?
They could either ship nothing at all because suddenly nothing fits their made up standards, or they would have to lower them to fit reality. The standards are there only because the Pixel exists to fit them.
I think it's highly suspicious that they've set their demands up so that only one device fits the bill, if this wasn't FOSS people would be calling up anti-trust and asking how much Google paid them for regulatory capture.
Similarly, if there was a device that's more secure than the Pixel, would GOS support both, or rewise their rules so it only fits whatever they want? I guess we'll see once the Motorola lands.
But no, I'm saying using Google hardware is directly financially supporting the closed ecosystem of corporate control they're trying to fight against. And if we do go down speculation lane, I wouldn't find it impossible for Google to build in their own hardware level backdoors. Given that Snowden is still alive, I suppose it's unlikely, but the conflict of interest is clear as day here.
Huh, that one is funnier than I thought it could be.
There's absolutely no love for Google in the GOS crowd. None at all.
Now quick TL;DR so you can't pretend you missed something:
- It seems that GOS will support the new, secure Motorola flagships from the day 1. There's been an extensive support from vendor and much energy in the GOS team. There's hope Pixels can be abandoned
- GOS exists because there's a secure hardware from a vendor that releases all the necessary patches and offers long support. That's the secret. Please suggest the alternative hardware.
- Since you claim they “make up standards”, I invite you to list security features that are in your opinion superficial
- - -
LOL, all your suspicions are already answered, probably hundreds of times, starting from the very document you allude you read, https://grapheneos.org/faq#future-devices
And silly as it might be, chances are that all the devices that will fit these requirements will be supported.
>> NONE
> That's exactly my point. Imagine for a second that there's no Pixel. What would GOS do?
Or, imagine your family woke up and turns out you never existed, what do they do now?
They develop the OS because there were secure devices they could develop their OS on. If you discuss based on the facts (I have my suspicions), you probably seem a list of the past devices no longer supported, but something they worked on
> They could either ship nothing at all
If there's no pixel they can't ship for pixel
> because suddenly nothing fits their made up standards,
Are you referring to the modest expectations for the mobile devices holding all the personal information and often access to whole live of the owner?
When you're buying a lock or alarm system for your home, what are your expectations? To me it seems you'd settle for the “absolute worst, something that can be bypassed with a butter knife, can't make life of the criminals too hard”
>made up standards,
Which one are made up? I'd like to see which one would you like to go.
- Making patches available quickly? Firmware patches? Frequent AOSP code releases?
- 5+ years of updates? Modern Linux kernel?
- Isolated radios, hardware secure element with throttling, protecting from attacks known from 90s?
- Full verified boot support with A/B slots, rollback protection (so the attacker cannot trivially just flash the ancient, vulnerable firmware), custom keys and relockable bootloader? Absolute bog standard, yet still not provided by MOST android hardware vendors
- Or, I don't know, MTE? Disk encryption? Protection for brute forcing disk encryption?
Which ones are “made up”, can you list the exact ones?
>or they would have to lower them to fit reality.
what reality? Vendors that allow, in 2026, to brute force PIN at the full speed? Or those who do not support custom signing keys, so the verified boot cannot be turned on? Or maybe these who do not offer relockable bootloader at all? Or maybe vendors known for delaying critical patches for months or don't offer any patches AT ALL (like one vendor still selling Android 15 devices, 6 months after the release of 17, when it's well known most bugs don't get backported patches)?
Can you give us a list of 2-3 modern devices that should have official GOS support?
>The standards are there only because the Pixel exists to fit them.
And this is a barefaced lie, need to call a spade a spade.
>I think it's highly suspicious that they've set their demands up so that only one device fits the bill,
Also lie, and a lazy one, it's 21 devices today. Oh well, I'll be charitable - maybe you just didn't check.
>if this wasn't FOSS people would be calling up anti-trust and asking how much Google paid them for regulatory capture.
By gods, what regulatory capture :D Do you just smash words together? Can you explain how GOS does, eeee, regulatory capture? :)
Oh, or maybe you're saying GOS forbids anyone from literally forking their repos and building own images?
What is that GOS does that stops you from adapting their releases to your own insecure, unpatched device? I really need some specifics.
>Similarly, if there was a device that's more secure than the Pixel, would GOS support both, or reowise their rules so it only fits whatever they want? I guess we'll see once the Motorola lands.
And this is the passage that tells me you're not discussing in a good faith. Work with Motorola on their flagships (plural) are well advanced, the expectation is they will be supported from the day of the release.
>But no, I'm saying using Google hardware is directly financially supporting the closed ecosystem of corporate control they're trying to fight against.
What? :D OK, so how much of the revenue Google has from the Pixel phone sales and what percentage of their revenue is that (I'm especially curious how it looks like next to ad earnings (direct and admob, etc), Google Cloud and Search.
What is the value of this argument? In % of Google revenue or B USD.
>And if we do go down speculation lane
No, not we, you do.
>I wouldn't find it impossible for Google to build in their own hardware level backdoors.
And THIS precisely is why GrapheneOS standards are so high, so if the crooked engineers or hardware exploits exist, the device still remain as secure as possible.
At this moment we either have to choose between a remote possibility of the highly sophisticated hardware backdoors that might be exploited by a nation state, or a hardware that is so insecure every thief can break into it in minutes.
I know which one I prefer. Which one do you want everyone to prefer? Seeing you're vocally against GOS on pixels, why do you insist on everyone moving to much less devices?
>Given that Snowden is still alive, I suppose it's unlikely,
And now we're at Dan Brown level of suspense
>but the conflict of interest is clear as day here.
Only if you've been staring into the sun for too long.
None of your allegations are new, they've been extensively addressed already.
> it's pretty clear to me you're simply driven by emotions and tribalism, that the facts don't matter.
Hmm I think this is a little unfair. GrapheneOS has technical reasons to support only Pixels, that's true. But those technical reasons are not trivial. Many people don't understand the Android security model, for instance. And if you don't understand it, without being in bad faith it's easy to not understand why it is important.
Android Open Source Project userspace code runs on any devices with Treble. That means it runs on any certified Android devices with the ability to install another OS. Updates and security features for the Linux kernel, drivers, firmware and hardware are still needed.
Fairphone 5 and earlier have end-of-life Linux kernel branches without security support. Those lag multiple years behind on providing full Android security updates. The 1-2 month delays for partial security backports is compared to the Android security bulletins and is actually a much longer delay compared to when the patches are made available to ship by OEMs.
In theory you can try to do that with Treble but in practice the experience will be horrible, there's not even a functional keyboard nor a functional call manager in there.
And yes all the Linux side of things is still missing.
That's not true. AOSP has a functional keyboard and Dialer app. There are also many third party apps for both available.
Linux does not mean glibc, systemd, Bash, GNU coreutils, Wayland/X11, Pulseaudio/Pipewire, etc. Android distributions are Linux distributions and are not missing what makes it Linux. The same goes for embedded and server Linux distributions without those components.
> they also compare the security to the "Android Open Source Project" as if it's a real thing
It is very much a real thing. You can build AOSP from sources and install it on a phone. Many Android devices run that (e.g. drone controllers).
> Is certainly much better than my Samsung flagship
Oh yeah, that's for sure. To share my experience, in terms of updates for me it has been GrapheneOS >>> Stock Android > /e/OS. I was running LineageOS/Cyanogen a decade ago but I don't remember and it was a different time anyway.
There are many vendors that are even worse than /e/OS in terms of updates. This is one of several reasons why Play Integrity is a farce, it has very little to do with security when vendors can be months late with critical vulnerabilities and still get to pass Play Integrity.
Basically anything that is not GrapheneOS, Pixel, or Samsung is in a deplorable state (Samsung not only rolls out security patches during the embargo period, they also do QPR2s).
Fairphone's updates are definitely much worse than recent Samsung flagships. It's the other way around to an extreme. Samsung does monthly security patches for their flagships and includes a large subset of security preview patches. It's not as good as GrapheneOS security preview releases but they're ahead of the Android security bulletins.
Fairphone is 1-2 months behind the Android security bulletins which are themselves 2-4 months behind the security preview patches. Fairphone takes a year to port to a new OS version shortly after launch and then ends up taking increasingly more time.
No you can't, AOSP doesn't even include a functional keyboard not a functional call manager nowadays. And I'm not even talking about the firmware side of things
Sure that might be enough for very basic hardware like your drone controller example but not a phone
Do we agree that the Android security model is baked into AOSP? Or would you say that the Play Services bring the security model to Google-certified Android, GrapheneOS implements its own security model from scratch, and LineageOS as well?
Assuming they share a big part of the security model, how would it "not make sense" to compare them? If AOSP is the baseline, saying that /e/OS is often weakening the security model and GrapheneOS is hardening it is a way to compare them. That makes complete sense to me.
> Or would you say that the Play Services bring the security model to Google-certified Android, GrapheneOS implements its own security model from scratch, and LineageOS as well?
Yes I would say that most of the security decisions are not baked into AOSP and every rom brings their own decisions.