this post was submitted on 18 Aug 2026
995 points (99.0% liked)

Technology

87649 readers
3262 users here now

This is a most excellent place for technology news and articles.


Our Rules


  1. Follow the lemmy.world rules.
  2. Only tech related news or articles.
  3. Be excellent to each other!
  4. Mod approved content bots can post up to 10 articles per day.
  5. Threads asking for personal tech support may be deleted.
  6. Politics threads may be removed.
  7. No memes allowed as posts, OK to post as comments.
  8. Only approved bots from the list below, this includes using AI responses and summaries. To ask if your bot can be added please contact a mod.
  9. Check for duplicates before posting, duplicates may be removed
  10. Accounts 7 days and younger will have their posts automatically removed.

Approved Bots


founded 3 years ago
MODERATORS
you are viewing a single comment's thread
view the rest of the comments
[–] WhyJiffie@sh.itjust.works 33 points 1 week ago (14 children)

not any, but some benefits, and GrapheneOS maintainers are perfectionists

[–] AmbitiousProcess@piefed.social 87 points 1 week ago (13 children)

Entirely lacking disk encryption for typical users due to not having a secure element is a pretty major flaw.

It's also missing hardware accelerated virtualization which is necessary for much of GrapheneOS's sandboxing, has weak security for other keys in the OS keystore, is missing hardware memory tagging which makes it much easier for apps to use overflow attacks, doesn't have proper verified boot support once a custom alternative OS is flashed, and leaves exposed debugging APIs even when the phone is locked.

This breaks:

  • Secure app spawning
  • Memory corruption protection
  • Integer overflow protection
  • Most of Graphene's kernel hardening
  • Much of Graphene's attack surface reduction abilities
  • Hardware-based attestation and security monitoring
  • Quick tile protection pre-unlock
  • Debugging access prevention
  • Verified Boot
  • The security of your PIN against any automated attack

At that point, GrapheneOS can't physically provide you essentially any security anymore.

[–] WhyJiffie@sh.itjust.works 4 points 1 week ago (5 children)

Entirely lacking disk encryption for typical users due to not having a secure element is a pretty major flaw.

all android devices have been using file based disk encryption since several Android versions now.

the others are all good to have security features, but lets be honest, a proper sensors permission toggle does not require any of that, just like a dozen other features only GrapheneOS has. storage scopes, contact scopes, pin scrambling and the requirement of fingerprint + pin for unlocking the lock screen, duress pin, the user profile improvements

all this does not require any hardware support.

https://grapheneos.org/features

all android devices have been using file based disk encryption since several Android versions now.

All Android devices are supposed to support it, but not all do. (or at least, not all do effectively without compromising the cryptographic root of trust by not implementing proper hardware security chips)

I'll grant it to you on the scopes, PIN changes, etc, but realistically I just don't think anyone can justify GrapheneOS being something that should be supported on Fairphone given how absolutely desolate the phone looks with regard to any attempt at all to hardware security.

load more comments (4 replies)
load more comments (11 replies)
load more comments (11 replies)