How Fairphone built the Fairphone Gen 6+(arstechnica.com) |
How Fairphone built the Fairphone Gen 6+(arstechnica.com) |
I am waiting for the next FP model where I can use a USB-C/dp external display and then I'm all over it.
Security updates will end 01 Sep 2028.
Fairphone 5 and earlier have end-of-life Linux kernel branches without security support. Fairphone's more recent devices are headed to the same situation. In practice, the same thing happens with other components beyond the Linux kernel.
Just as physical security, digital security most of the time not as radical, and tradeoffs are usually accepted, especially when they are "invisible": hardware and software security features are usually not mentioned in the specs and the regular and even power user just don't know most of them and what do they do.
When GrapheneOS says "private" and "secure", they mean top-of-the-line security features, updates as soon as possible, all available mitigations against zero-days and insecure code which will limit the impact before the patch, etc. Security as in a killdozer.
When other say "private" and "secure", most of the time it means: "we've followed all the recommendations applicable to our development budget, device price point, and support life time". Graphene does not like that definition of these words.
For smartphone, chip manufacturer goal is not to protect the user at all costs, but to provide reasonable security features for the price.
BUT the goal of chip manufacturer to protect the device at all costs is for… game consoles! That's why Xbox, PlayStation, Switch all run on a custom silicon and not an ordinary chips!
Not really. Xbox and PlayStation both run on pretty standard AMD Zen 2 chips. Somewhat customized, but standard enough that people by binned playstation 5 motherboards to use as computers with normal OS'es (lookup BC-250). The last gen with more customized chips was the PS3/Xbox360 era, when both went with a variant of PowerPC, same as Gamecube/Wii/WiiU.
Switch runs on basically the same Nvidia Tegra CPU/GPU as multiple android tablets.
A couple of the tenets of computing security are:
- Defense in depth - Principle of least privilege
It is a foundational reality that software (especially in unsafe languages) will invariably have vulnerabilities. Defense in depth and least privilege have compounding effects by forcing attackers to chain multiple exploits to achieve a compromised device, rather than a single vulnerability.
GrapheneOS shows how much can be accomplished on top of relatively secure platforms to begin with (AOSP, Pixel Stock OS, etc.) without sacrificing nearly any usability to the end user (barring manufactured hurdles like Play Integrity). It makes it more damning that many "privacy" OSes and devices cannot even meet the baseline level of privacy and security that AOSP provides, but degrade it.
Firmware and driver neglect and the lack of secure element utilization is not "reasonble security for the price".
I don't think that expecting security updates it being an extremist, or is it?
Yeah, iPhoens are made that way as well. It's just caring about the privacy of your users.
> When GrapheneOS says "private" and "secure", they mean top-of-the-line security features, updates as soon as possible, all available mitigations against zero-days and insecure code which will limit the impact before the patch, etc. Security as in a killdozer.
I think it's deceptive because people think they will get better privacy/security with a /e/ fairphone when it's actually much worse than an iPhone.
With the hardware I'm not impressed, and on their own forum I've seen plenty of people reporting issues with overheating on the Gen 6. Hopefully kinks have been ironed out on their 6+.
The current CEO also has a persona that would stir up any community (read a few of his AI-gened posts on their blog, if interested of context).
Still holding on to my FP4, but they are not of consideration on my future phone purchase, unless there is some kind of reality check over there and improvements materialize beyond words.
Everyone and their dog can repair an iPhone because it’s the most popular phone on the planet. Are those repairs accessible to the consumer at home with amateur skills? No, not really. However, newer iPhone models are significantly easier to repair and come along with lower repair costs direct from the manufacturer compared to previous models.
You want years of software updates? Yeah, an iPhone has you covered there, too.
And of course, fairphone’s hardware and OS are nothing to write home about. For the freedom and security nerds they’re better off with GrapheneOS on Pixel or whatever upcoming Motorola phones will support it.
Who is the Fairphone for exactly? Who is buying it and why?
I think the fairbuds are their best product, but I also imagine AirPods Pro 3 are on a whole different level of sound quality, noise cancelation, voice quality/voice isolation, and firmware/software polish.
And let’s be honest about repairability with tiny earbuds: being able to replace the battery is has such a tiny impact on their footprint. If I have to throw out my AirPods Pro 3 every 5 years due to battery degradation, that’s such an insignificant quantity of material being wasted, so it’s probably worth it to get a better product. I could offset my environmental impact by eating a little less beef or riding my bike instead of driving a few times. You drive 30 miles and that’s an entire gallon of refined petroleum product, how much material and energy is used to make one pair of AirPods? I can’t imagine it’s a lot.
I don’t say any of this to be a big corporate or Apple shill. I am rooting for the little guys. But the little guys need to be realistic. You look at products like the Framework 13 Pro and you can actually say, okay, here’s a product with really legitimate benefits over its incumbent competition. There is a reason to buy this product for a certain buyer. I just don’t see that with Fairphone. I can’t think of a customer profile where that person is getting a better ownership experience with Fairphone products.
I do have the feeling that many non-nerds can express the difference between all mentioned attributes, many just like FairPhone as an ethical phone. It’s not that simple, I agree.
And at that point I got quite disappointed by /e/OS, because I felt like their marketing had been abusing me for years. For instance, my Fairphone 3+ was 4 years behind the Fairphone Stock Android on some updates. /e/OS just wasn't forwarding them, they seemingly were just not maintaining the FP3. Though I bought it to /e/OS, under the promise that it would be supported!
Then I realised that all this time, not only my bootloader was unlocked (so the Android security model had been broken from the first day I powered the phone), but the system was signed with the Google test keys! When you are encouraged to install apps "from the internet" instead of the Play Store, on a phone that disabled the security model so that you're not protected against malware as on any Stock Android, would you say it's being a security nerd?
The thing that GrapheneOS keeps repeating and I realised is true is that many times, if you run a deGoogled alternative that is not GrapheneOS, you get worse security than if you were running Stock Android. It's not about "getting the best possible security", it's about getting the baseline. The truth with /e/OS (or LineageOS, which is pretty much what /e/OS ships, I believe?) is that it depends a lot on the phone. And with many phones, you get worse than the baseline you would get with Stock Android.
> I do prefer de-googled + freedom to do what I want over security (to a degree).
So I switched to GrapheneOS on a Pixel, and I feel like I get the best of both worlds: I get the privacy benefits of the sandboxed Play Services, and the better security. And it's not a "weird" system at all: I asked my family to use it and they didn't realise it was not a "normal Android". It is very different from running something like a Linux on mobile, which would be very very different.
> many just like FairPhone as an ethical phone
Yes, why not. If I was to get a Fairphone again, though, I would use the Stock Android.
And I wish Fairphone could get to the level where they can be supported by GrapheneOS. But it feels like my next phone will probably be a Motorola with GrapheneOS rather than a Fairphone.
It isn't truly known how a Fairphone compares to an iPhone or Pixel when it comes to environmental impact or fairness to workers. Fairphones are designed and built by T2Mobile since the Fairphone 4. T2Mobile barely has any public information available about it. There isn't information on the working conditions, pay and other aspects of of it. The same applies to the rest of the supply chain. Fairphone provides a list of companies involved in the supply chain without details.
I really would like to mention that many times, using /e/OS or LineageOS (or the likes) means that you get worse security than Stock Android.
It would be fine to run /e/OS or LineageOS on a Pixel, assuming those Android systems are not too slow with updates (my experience with my /e/OS phone was that they were 4 years behind as compared to Stock Android).
But really, if you have a Pixel, it doesn't really make sense to use something other than GrapheneOS IMO.
So to me it's really:
- GrapheneOS if you can
- Stock Android vs an alternative otherwise
My fairphone 2 had lasted 5 years, but was completely unusable at the end. My current phone works very well (again, huge kudos to the team if anyone is reading this), and I would not mind trying to reach the decade with it - but in a few months, someone (my bank, a shop, a 2FA, whatever) will ask for an unsupported android feature.
I know people will give me names of exotic non-android distros, but will they run my bank's app :/ ?
I'd be interested in the list, the website you've linked is super sparse (the full menu is like shop, some feel-good pages about device deposit and impact, blog, and contact us - no knowledge base, documentation, or somewhere where you'd expect to find OS info or even downloads)
So why does a brand new phone run an operating system from over a year ago? Does it really take over 6 months to update a phone to a new version of Android?
How am I supposed to believe a company is committing to supporting a phone for a long time when at release it already runs outdated software?
From my understanding it’s not there as the Graphene team says that fairphone haven’t taken security hardware seriously and there’s key hardware security features missing that means they are not even interested to look at supporting the device.
Keen for latest updates on this, happy to be corrected.
Still only on my second smartphone, so I'm not worried about producing more e-waste.
After 4-5 years, on every phone I've ever had, user interactions begin to lag noticeably. Apps launch much more slowly. Intense graphical apps like maps become frustrating to use. At some point I can't take it anymore and replace the phone, long before its physical parts or battery have worn out.
You always have the right to a minimum 2-year guarantee from the moment you received the goods. However, national rules in your country may give you extra protection.[1]
[1] https://europa.eu/youreurope/citizens/consumers/shopping/gua...
This is more than can be said about other projects in this space
I applaud the concept but to see how well this actually holds up in the real world, let's check the Fairphone web site.
Where are the parts to repair any version prior to Gen 6? I don't see them listed anywhere.
So it would appear that "longevity" is actually pretty limited.
For those not aware, Android Security Bulletins only cover high/critical vulnerabilities. There are also rumors that Google will soon stop fixing vulnerabilities in not-actual versions that were discovered by Google in LLM-driven vulnerability discovery. There was recently a GrapheneOS thread about it.
But Google being Google, this release is pretty much useless until Samsung et al deal with all bugs and performance issues, which will take 2-4 months.
Fairphones have 1-2 months of delay for partial security backports to older releases from the beginning and much longer delays for full updates. Android 17 is required for full Android security updates. Only a subset of patches are backported to older versions and that subset is decreasing.
Android 17 is also required for the latest and greatest privacy/security protections which are not backported. There have been massive privacy and security improvements in each yearly Android release.
Then I've decided that is worth either spending money on phones whose replacement parts doesn't cost half of the phone itself, or just buying the cheapest Xiaomi or similar chineese brand phone and when it breaks buy a new one or repair it (funny enough cheap phones are more repairable than expensive ones, so I usually repair them).
For sure it isn't the snappiest, but my only real performance issue is loading gifs on Signal, which takes several seconds for some reason.
Just tried maps now, actually still fairly fine for me.
Sent from my Galaxy S10 running LOS
There's no additional DAC involved, the analog audio is already on a USB-C pins.
My main problem with USB-C headphones on my Android phone is how unreliable they are. But if the USB-C port can just pass through an analog audio connection, that should work much better, I expect.
Edit: This feature is apparently deprecated (removed?) in newer versions of the USB spec! https://en.wikipedia.org/wiki/USB-C#Analog_Audio_Adapter_Acc...
> to fit other features in
what exactly, one would ask. If there are tradeoffs, if would be nice if the customers can decide what to have, in a modular product.
Only issue is some very cheap ones are actually bluetooth headphones in disguise where the usb-c connection only exist to power the bt recepter inside the headphone. I find this completely stupid.
A "modular product" has tradeoffs in and of itself (such as size, price, water resistance, …), which presumably would not fly for a majority of customers.
On that note, I remember reading how some phones were able to use the headphone jack as a serial debug port, which is pretty neat.
https://wiki.postmarketos.org/wiki/Serial_debugging/Cable_sc...
Fairphone 5 (2023) parts: https://www.fairphone.com/shop/category/spare-parts-4?catego...
Parts for the Fairphone 2 (2015) and Fairphone 3 (2019) aren't available anymore, but I suppose that's not all that surprising after 11 respective 7 years.
Afair, they started running out of some Fairphone 3 spare parts around 2024 and kept the ones they still had for warranty repairs. Source: I own one (and switched to the Fairphone 6 early this year).
So "longevity" is actually about 5 years. Or less if you live in the USA.
https://www.ifixit.com/Device/Fairphone
Reminds me of the cold steel throwing axe that I bought that specifically has replaceable handles in case you break one. No one actually sells the handles though!
I bought one a few years ago. Good device, too big for my hands (back then, there were still smaller options so I bought one of those smaller ones in second-hand). Not having spare parts available would make me hesitate since that's like 50% of the point (fair sourcing being the other half), but besides that it's a (big) phone like any other
Here are the ones for the fairphone 4: https://www.fairphone.com/shop/category/spare-parts-4?catego...
I however couldn't find the ones for the fairphone 3. The fairphone 4 is from 2021, which is not that old.
Yes, that goes against most of Fairphone's own advertising, but it was consistent with my experience of the phone and discussions on the forum: security updates frequently so far out of date that some software could not be run, flimsy components inconsistent with advertising (yes, the battery was nominally swappable, but the snaps on the back would break easily, and support would claim that it was not intended to be removed regularly), parts that were frequently out of stock, and of course, whole new phone designs every generation rather than Framework-like component upgrades.
It seems like they may have improved since then, but those problems, along with the atrocious security (FP4 used AOSP's public test signing keys, with publicly-available private keys, for its firmware) and sketchiness around specs, standards and openness (especially for the camera), generally turned me off the company.
There are just a bunch of companies which afford to do the same. Maybe Xiaomi will be the next one.
That's just blatantly not true though - even iPhones collect way more telemetry and Ad data than /e/ OSes.
Fair enough, but note that it does not concern GrapheneOS. Hopefully soon available on Motorola phones :-). That would be my next phone (assuming it's not too expensive of course).
Both /e/ and LineageOS lag far behind on current security updates on a Pixel. Neither is based on Android 17 yet which was released in June 2026. Neither has the June 2026 or later Pixel firmware, kernel, driver and HAL patches. Both also roll back the standard security of AOSP but /e/ does so much more than LineageOS.
You would be missing out on:
- Minimum Target SDK Enforcement Blocks installation of apps that target ancient versions of Android and legacy APIs.
- Restricted settings for sideloaded apps
- Null-Cipher rejection and 2G disabling
- Cell Network Surveillence Alerts
- Platform Rust Migration
- Scoped Media
Among many many unpatched Med and Low severity CVEs that don't get backported.
Funny to list a user-hostile change as the first “improvement” that comes to mind.
I guess GP should have said “series of cosmetic changes, and breaks in your UI habbits and a few of your apps deemed too old”.
These are not rumors. It's an official announcement from Google to OEMs and we have access to it.
Aren't those back-ported for a while?
Android Security Bulletins do not cover the vast majority of Linux kernel security patches. They only cover an extremely small subset tied to Android. The Linux kernel has a massive tsunami of security patches on an ongoing basis. Fairphone 5 and earlier have an end-of-life Linux kernel without security support. They're close to not updating the kernel at all anymore. Their more recent devices will end up in the same situation.
The Linux kernel is not the only component ending up unmaintained while the devices are still presented as supported.
https://grapheneos.social/@GrapheneOS/114101511604296440
You need new releases or QPRs to get other patches.
That doesn't mean that all the features are enabled right from the factory, or that the compatibility with already existing features is lost.
Modern chip's security features are pretty complicated and include hardware patches, hardware debug authentication, multiple provisioning states (and multi-key hierarchy for that), RMA states to clear all the private information, etc.
>Switch runs on basically the same Nvidia Tegra CPU/GPU as multiple android tablets.
Yes, and the one which got cracked with a bootrom vulnerability ;)
That's a pretty working motivation for a chip company to improve their chip security when the company as beefy as Nintendo tells them that their chip is vulnerable they're losing money because the customers can play for free ;). I'm pretty sure patchable bootroms started to be common only after Switch hack.
There are whole sections of peripheral chips missing and they behave quite a bit differently with how they bootstrap and where things are mapped in memory.
That is how your car radio could display the name of the current track.
If that is true then a lot (or most) of android phones run on "custom silicon" and the term is meaningless.
It happened to me when I was using shitty brands like Xiaomi that include a lot of malware and spyware in their official firmwares. Not anymore on grapheneOS (and /e/os on my daughter's phone).
For the American piece, the FP6 was the first available from OEM in the US.
Besides, the phone software is highly optimised for the specific hardware. It is not a generic software like Windows
But there's also nothing to stop you simply building the latest kernel from source and using that - it's pretty easy and it will work fine.
Seriously, why can't Android just be installed? Are they building it like the old-timey kernel before modules and embedding drivers in a giant monolith or something ridiculous?
Not even Fairphone can repair your phone if it's out of parts.
Generally with Apple, you can: https://support.apple.com/self-service-repair
https://ae-pic-a1.aliexpress-media.com/kf/Sfa5566c711b14a4aa...
I've tried those dongles and they are all a huge hassle compared to just having a headphone jack built in.
https://images.thalia.media/-/BF2000-2000/939d34e30a3d4f6587...
Not quite. The people who care about security first are better off with GOS, yes. However, GOS's threat model very specifically treats the user as a thing to defend against; the freedom-first crowd should avoid them.
Can you elaborate?
GOS mostly honours the Android security model, which many alternatives don't do (many times they don't have a choice because the device doesn't allow them to relock the bootloader, so they just defeat the whole security model from the moment you install).
There is absolutely nothing that can be done on a Stock Android and that I cannot do on GrapheneOS. Or at least I haven't found it.
> And of course, fairphone’s hardware and OS are nothing to write home about. For the freedom and security nerds they’re better off with GrapheneOS on Pixel or whatever upcoming Motorola phones will support it.
For the "freedom nerds", FP is one of the only (if not the only?) vendor to have official support for microG-based operating systems, seamless OTA updates and everything included. The Murena e/OS offering in particular is simple enough that the non-nerds that (perhaps less outspokenly) care about freedom can just pick it up with little change in habits.
To be fair on either side of that debate, getting a phone that comes with /e/OS installed from the factory is going to be easier than flashing GrapheneOS on a Pixel or LineageOS with microG on another device.
I am not sure what you are trying to say here. I have never had an Android system that did not have OTA updates. Everything included... I usually like to install the apps I want?
As for microG, I think it's debatable. Is it better to have microG contacting the Google servers or sandboxed Play Services going through a Graphene-powered proxy? And say you have microG going through a Murena proxy (do they do that?), is that significantly better than sandboxed Play Services? At the end of the day, your system is made mostly of code written by Google (AOSP).
> The Murena e/OS offering in particular is simple enough that the non-nerds
Yes, I think it's what makes Murena successful. It's surprisingly simple to install GrapheneOS on a Pixel (you follow a wizard on a Chromium browser and click "next" a bunch of times), but many people are scare just by the idea.
by using FOSS only myself and hating monopolies like Apple etc., i still pretty much convinced that being "green" or "ethical" is more about participating/volunteering/doing-something towards a better world than off-loading your duty to other companies... one could easily make a point that Apple products despite locked down, are still green (Apple has a bunch of zero-emission and whatever policies) and much more if one uses their devices for a long while. i had a 2° hand iPhone SE 1° gen. till 2021? if stuff breaks despite your not being able to fix it's not like you can't hop into a specialized shop to change batteries or even pay the expensive service Apple offers... sure that allows exploitation and it's always nice to get rid of it, that's why somehow these emerging companies are important and/or policies like the right of repair will make them obsolete
Then I realised that:
- Fairphone 3 was already "slow" when it was released in 2019
- Fairphone 3+ was pretty much exactly the same hardware, but I bought it 2.5 years later
- My Fairphone 3+ was annoyingly slow from the moment I bought it (I was using it less than a normal phone because of that, and I just completely gave up on using the camera and asked other people to take photos instead).
- My Fairphone 3+ became painfully after 1.5 - 2 years.
I did not change phone because the hardware was not running anymore. I changed because I just couldn't use the few apps I needed because they were unusable (lagging and crashing). I don't mean games: banking apps, weather forecasts, public transports. Pretty much only Signal/WhatsApp were fine (slow, but fine).
So I painfully kept my Fairphone 3+ for a little more than 4 years.
Then I realised that people who buy an iPhone routinely keep it 6-8 years, without it being painful at all. Is it "greener" if I buy one iPhone/Pixel, or 2 Fairphones? I'm not so sure anymore. What I know is that the iPhone/Pixel are not painful to use.
Do you know how the Sennheiser's compare? I'm looking for some for using at the gym, but wanted something I can easily fix if needed.
The Fairbuds are also quite a bit cheaper
I suspect that the venn diagram of the kind of person who takes issue with Bluetooth audio batteries and the kind of person willing to use wired headphones or prefers them outright has a lot of overlap.
GrapheneOS will never be closed source/proprietary because they believe code freedom (and user freedom by extension) is paramount. They have repeatedly said they don't have the resources to build a ChromeOS-esque firmware authentication and warning flow for ephemeral user-accessible root and support those builds alongside the existing production environment. They have NOT said it is something they have no interest in even discussing. They have also repeatedly said that where the utility is clearly demonstrated and can be architected in a maintainable way, they are open to contributions (and continued maintenance) that properly enable functions that people unnecessarily need to abuse root privileges for.
The main goal of their project is a system that can protect your personal thoughts, associations and memories to the best of its ability (against thieves, attackers, surveillance etc.) while preserving your interaction with the world. Current OSes (including GrapheneOS and iOS) are already far behind where they should be given the wealth of privacy enhancing technology, computer hardware security, systems engineering and OS design knowledge that has existed for decades- so their work is cut out for them and they are putting everything they have into leading the industry. Their hands are already full. For clear use cases the path of least resistance would be to contribute and commit to maintaining features everyone would benefit from.
If it is a feature/function someone understands they would benefit from personally but do not see the value to impose on others, we can circle back to the original fact which is that GrapheneOS is open source and can be bent/built to your will.