Replying to @⁨TheTechnician27@lemmy.world⁩

The team behind GrapheneOS want it to be really secure so they have specific requirements that the phones from Fairphone sadly doesn’t meet.

For a phone to meet all of these requirements AND still being everything that a Fairphone is would make the phone more expensive than the average consumer would be willing to pay. I know several enthusiasts (me included) that would pay for one, but there are simply just to few of us.

GrapheneOS logoGrapheneOSGrapheneOS Frequently Asked QuestionsAnswers to frequently asked questions about GrapheneOS.

Replying to @⁨TheTechnician27@lemmy.world⁩

It’s mostly a thing of what’s available for your phone. For pixels 6 and newer (and I think some new motorolas as of recently) you can use graphene. If you are on fairphone or a bunch of other devices, you have support for e/OS. In general, graphene is a bit more secure than e/OS, so if you have the choice, it’s probably the way to go but if you don’t have a pixel and don’t want to buy one, e/OS is probably one of the better maintained degoogled android versions out there.
Here you can find a list with a feature comparison.

Replying to @⁨accideath@feddit.org⁩

no motorollas are supported yet by GrapheneOS. only new ones projected to come next year will be.

/e/OS is just a fork of LineageOS, with dubious software choices and practices. LOS is available for many more devices and is the cleaner almost-degoogled (like /e/ and other LOS forks) basic AOSP-like experience with lots of customization to use even in old devices that keep running modern android this way.

GOS is much more secure than LOS or any of its forks (including /e/), even more so when the latter is running in old devices that no longer have firmware updates. and it’s properly degoogled, with the option to use Google Services in the best way possible - without it having root access to your system and isolated from other apps, if you so wish

so, GrapheneOS is your best option. if you can’t or won’t, use LineageOS

Replying to @⁨TheTechnician27@lemmy.world⁩

I never used /e/ but I used iode (iode.tech) and it worked really well. Main differences:

  • Graphene doesn’t support pattern unlock because they claim PIN is more secure. This is stupid because you can just as easily see what PIN someone typed as the pattern. Since PIN is less convenient most people will use finger print unlock which means you can be easily forced to unlock your phone against your will

  • iode has support for shortcuts when using 3 button navigation, Graphene doesn’t for some reason

  • iode has really nice tracker blocker which can run next to a VPN, Graphene doesn’t

  • Graphene let’s you install Google Services in a separate work profile and separate apps that have access to them from other apps. In iode you will have microG installed system wide

For me that were the biggest differences. When it comes to app support they worked pretty much the same. I’m on Graphene now and it would be too much work to change now but for my next phone I will most likely go with iode.

iodéiodéBe Smarter Than Your Phone

Replying to @⁨ExLisper@lemmy.curiana.net⁩

In defense of Graphene for the first point:

Graphene has a pin scrambler, so the numbers are in a different position everytime you have to enter them.

It isn’t hard at all to get used to it, and it circumvents the pattern recognition bit.

Fingerprint unlock…that’s a different discussion especially with biometrics not being protected under the law, but for first unlock you always have to enter in a pin

Quickly looking at my phone, you can enter in a passphrase (though personally I think that’s too cumbersome). There’s also a swipe option, I THINK that might be pattern, but I’m not sure. I can’t test it, because it means deleting the already in place measures, and I don’t wnat to do that at the moment.

Replying to @⁨somereaduser@reddthat.com⁩

Graphene has a pin scrambler, so the numbers are in a different position everytime you have to enter them.

It doesn’t matter. When I’m inserting my PIN on a bus or while standing or line with people behind me or something I know that anyone interested can clearly see my screen and learn my PIN, scrambler or not. Also, scrambler is not mandatory (I don’t have it enabled) so Graphene OS devs explanation that “we will not enable patter ulock because it’s not secure” while normal PIN can be enabled still doesn’t hold.

This is actually a broader problem with Graphene OS. The devs often fixate on some minor security issues that don’t impact 99% of their users at all and refuse to introduce features that they request. It’s exactly the same with supporting phones other than Pixel. 99% of users would be completely fine using Graphene on a different phone (CIA is not going to hack them) but the devs prefer to directly reject all those users.

Replying to @⁨muusemuuse@sh.itjust.works⁩

Also, scrambler is not mandatory (I don’t have it enabled) so Graphene OS devs explanation that “we will not enable patter ulock because it’s not secure” while normal PIN can be enabled still doesn’t hold.

Also, who are “they”? Yes, someone in some situation can figure out the patter from smudges. In other situations someone can see your PIN. If Grapehene dev are so worried about screen unlock security they should implement the system BlackBerry had which was super convenient and impossible to figure out even when looking directly at someone’s screen.

Replying to @⁨Zedd_Prophecy@lemmy.world⁩

Yes, steel pipe to the knee will work equally well against all unlock methods. Graphene OS is supposed to be extra secure to better protect you against tools used by government agencies and law enforcement. It’s used by activists and such. IMHO using fingerprint on Graphene OS makes all this extra security meaningless because police can just force you to unlock and it will be legal:

techtimes.com/…/court-rules-thumbprint-phone-unlo…

Police would not be able to unlock this phone if the guy used pattern unlock.

Fingerprint UnlockTech TimesUS Court Rules Police Can Force Suspects to Unlock Phones via ThumbprintThe US Court is now allowing cops to force thumbprint unlocks on your phones if you are a suspect. The US Court of Appeals ruled against defendant Jeremy Travis Payne for his legal team’s appeal to suppress evidence after it was found that police officers forced him to unlock his phone using his

Replying to @⁨Alaknar@sopuli.xyz⁩

Yes, agencies with more power will have more ways to force you. CIA will be able to fly to a dark site and put a car battery to your balls until you give them the PIN. Normal cops during a traffic stop will not have much ways to influence you beyond detaining/arresting you but any cop will be able to take your hand and forcefully place your thumb on a fingerprint reader. And courts say it’s legal.

reason.com/…/appeals-court-rules-that-cops-can-ph…

Replying to @⁨ExLisper@lemmy.curiana.net⁩

Fair enough - I’m aware it’s not. I was still thinking of the American release since this is the first one officially supported in the USA, and I had just read another article focused upon that a couple days ago - which probably primed me for staying in that mindset. Apologies for being tunnel-visioned. I’m just very frustrated since I’d like to get one, but can’t use it under these limitations.

Replying to @⁨thisbenzingring@lemmy.today⁩

I dont have this newest gen6 plus, just the slightly less new gen6 with e/os, but I wouldn’t imagine the difference is huge. Has generally worked about as well as any regular android phone Ive had, with a few minor annoyances like the “paste” button for text often being invisible, such that I just have to press where it should be to make it work.

Replying to @⁨ExLisper@lemmy.curiana.net⁩

I get the sense this is sarcastic lol. In my opinion though, privacy without security isn’t very useful. Yes I can avoid corporate or government spying when I’m in physical control of a device like this, but what if I get arrested on some false pretenses and they use cellebrite to gain access? Or the same at an airport when traveling? If you’re any form of political dissident, activist, or a member of a marginalized group, being targeted this way is a very real possibility. And as soon as that insecure but “private” device is out of your hands, all that data is free game for the govt.

Replying to @⁨NewOldGuard@lemmy.ml⁩

This is why threat modeling is important.

but what if I get arrested on some false pretenses and they use cellebrite to gain access?

Chances are they can clone the eMMC and wait for a CVE. Or threaten or hold you until you cave. If a lawsuit is your only recourse, I would expect any constitutional barriers to be ignored in practice. Your best bet is to never end up being an explicit target, which may be more difficult for certain individuals.

My threat model considers dragnet surveillance as the primary threat, so I’d compromise on surviving dirty maid type attacks in favor of reducing the information my device gives out.

Obviously if your device is being actively exploited, you cannot be private. But your security requirements increase greatly if your data footprint indicates to them that you warrant targeted scrutiny.

Replying to @⁨NuclearDolphin@lemmy.ml⁩

100% agree with you, for who I am and what I do I know that I need a device that is as tamper resistant as possible with the smallest attack surface feasible. That goes for remote execution as much as the evil maid scenario. But this is entirely catered to my threat model and risk tolerance. And sure there is the possibility of the rubber hose cryptanalysis but that doesn’t mean we should give up on securing as much as possible on the device side. It’s the swiss cheese model and we’re plugging a hole at a time lol

I advocate for everybody to use as secure a device as practical, and for these mitigations to be the default, but I’m fundamentally speaking for myself in this thread with my stance on fairphone and /e/OS right now. I want to support repairability and ethical supply chains too without compromising on my more core tech needs

Replying to @⁨murena@lemmy.world⁩

I’ve been using /e/OS on a FP6 for a few months now and I’m very happy with it (edit: for context I’m in Europe). I had doubts about whether it could run certain apps like bank or government apps but they work just fine. Most of the default apps work well, but I did replace the launcher because the one that comes with /e/OS doesn’t have as many features as I would like.

Battery life is also better than previous phones I’ve used. I don’t know if that’s because of the hardware or because the OS is less resource hungry.

One thing to watch out for is it doesn’t have a headphone jack, though you can get a separate adapter that plugs into the charging port.

Replying to @⁨CountVlad47@feddit.org⁩

My expetiences differ.

The default launcher regularly breaks, so I need to clean the cache, or wait until it succeeds. So for what I can, I use droidify or obtainium. Some apps also dont work properly as they are reliant on google services. Netflix comes to mind first.

Bank works, but governmental app (ID & payment) dont work, so I am still relyant on work phone for those. Check forums, theres a list for these crucial apps and their status.

Other than that it’s been mostly smooth experience.

Replying to @⁨murena@lemmy.world⁩

I have the Fairphone 6 with /e/os (dumbest name and annoying to type IMHO) and though i love it, I don’t trust the business side of Murena. In one recent patch, they removed the seedvault backup app and replaced it with their own backup solution that depends on their own cloud service. Another point is that the support overall is chaotic between Fairphone (the hardware) and Murena. I literally was told to raise tickets to both companies when my WiFi stopped working properly because of the mentioned patch (still no fix - only a the compromises privacy).