4 ms·
A GrapheneOS phone is just as open as the Librem 5. They both use proprietary blobs and hardware. Librem just tries to hide that fact. https://news.ycombinator
by kuhsaft 5mo ago
A GrapheneOS phone is just as open as the Librem 5. They both use proprietary blobs and hardware. Librem just tries to hide that fact.
https://news.ycombinator.com/item?id=47935853#47943179 https://news.ycombinator.com/item?id=47935853#47943179
GrapheneOS is probably more secure also.
- fsflover 5mo ago> A GrapheneOS phone is just as open as the Librem 5. No, it's not. Try to run a completely free OS on you hardware (like Replicant) and watch the lack of camera, GPS and more. Related discussion for other: https://news.ycombinator.com/item?id=47942070 https://news.ycombinator.com/item?id=47942070
- 555244466 5mo agoThe Librem 5 uses a bottom of the barrel, standard industrial CPU from 2017 with no updates. It is no more open than a Google Pixel or any other mobile device. it lacks proper updates, isolated radios, and any form of hardening. The kill switches are also useless if your device is fully compromised and turned into a spying device, all of your data is already gone. The only thing the switches do as a last resort is block voice recording, which is an improper way of doing it since speakers are essentially just microphones in reverse.
- fsflover 5mo ago> CPU from 2017 with no updates This is false. Please stop writing false statements without any links. NXP promises to produce the i.MX 8M Quad until Jan. 2033. The support will be even longer. > it lacks proper updates This is FUD. > isolated radios They are isolated with USB. This might be slightly weaker than IOMMU, but for me the benefit of freedom is worth it. There is no shared memory. > it lacks proper updates, isolated radios, and any form of hardening FUD and false information. Please stop this. > The kill switches are also useless if your device is fully compromised This is false again. It doesn't matter how much my device might be compromised. The attacker will not get any access to the shut down sensors, radios or voice/video, if I use the three kill switches. > since speakers are essentially just microphones in reverse Librem 5 speakers do not support this.
- kuhsaft 5mo agoNot OP, but > This is false. Please stop writing false statements without any links. NXP promises to produce the i.MX 8M Quad until Jan. 2033. The support will be even longer. I think they meant that the processor itself is old. It supports ARMv8 and is lacking the enhanced memory protection and execution features of the ARMv9-A processors on newer phones. > This is false again. It doesn't matter how much my device might be compromised. The attacker will not get any access to the shut down sensors, radios or voice/video, if I use the three kill switches. The problem is that your device can be compromised quite easily and without you knowing. The kill switches are moot at that point.
- fsflover 5mo agoThe kill switches will work independently on a compromise. Why are they moot? Also, it's possible to completely reflash the device in case of doubt. "quite easily" strongly depends on what exactly you are doing. For example, if I use Firefox with NoScript, then it is not very easy.
- kuhsaft 5mo ago> The kill switches will work independently on a compromise. Why are they moot? Kill switches only work as a security feature when you activate them before you know you're compromised. But that's impossible. It's a reactive "security" feature not a proactive one. > For example, if I use Firefox with NoScript, then it is not very easy. Security vulnerabilities aren't only JS related. https://www.mozilla.org/en-US/security/advisories/mfsa2026-30/#CVE-2026-6746 https://www.mozilla.org/en-US/security/advisories/mfsa2026-3... https://www.mozilla.org/en-US/security/advisories/mfsa2026-30/#CVE-2026-6761 https://www.mozilla.org/en-US/security/advisories/mfsa2026-3... Adding an extension that can access all your browsing data doesn't seem very secure either. Required permissions: - Access browser tabs - Access browser activity during navigation - Access your data for all websites
- fsflover 5mo agoGood links, thank you. I agree that my protection is not perfect in general. Fortunately I do not open random websites on my phone; I have my laptop with Qubes OS for that. > Adding an extension that can access all your browsing data doesn't seem very secure either. This is not just a random extension but an officially recommended one, https://support.mozilla.org/en-US/kb/recommended-extensions-program https://support.mozilla.org/en-US/kb/recommended-extensions-.... It's also regularly verified by the community. I trust it as I trust Firefox.
- TommyTran732 5mo agoQuite frankly, the whole Librem ecosystem is significantly less "open" than GrapheneOS or any desktop Linux variant to anyone who look at things objectively instead of using weird FSF semantics. Instead of loading firmware in sensible manner like GrapheneOS or desktop Linux distros with the linux-firmware package, they keep PureOS "free of blobs" by having the bootloader inject all of the blobs into memory in an extremely shady manner. Since when was having the bootloader tamper with system memory about freedom and openness? Oh, and they even have the audacity to market this as the "firmware jail" as if it is any more contained than the linux-firmware package too. Truly impressive stuff.
- fsflover 5mo ago> Quite frankly, the whole Librem ecosystem is significantly less "open" than GrapheneOS or any desktop Linux variant to anyone who look at things objectively instead of using weird FSF semantics. You will have a point when your Google phone runs Replicant. Now this is just empty words, i.e., FUD. Which blobs are running on the Librem 5 CPU? Which blobs are running on GrapheneOS CPU?
- kuhsaft 5mo ago> Which blobs are running on the Librem 5 CPU? https://source.puri.sm/Librem5/fw https://source.puri.sm/Librem5/fw https://source.puri.sm/Librem5/fw/firmware-librem5-nonfree https://source.puri.sm/Librem5/fw/firmware-librem5-nonfree https://source.puri.sm/Librem5/librem5-fw-jail/-/tree/pureos/byzantium?ref_type=heads https://source.puri.sm/Librem5/librem5-fw-jail/-/tree/pureos... > Which blobs are running on GrapheneOS CPU? Depends on the phone. Arguably though, GrapheneOS has the legacy of years of thousands of security researchers working to secure Android from third-party network and GNSS modules. --- Just so you know, I'm not using Librem or GrapheneOS. I'm looking at this objectively and have no skin in the game.
- fsflover 5mo agoIn this case I do not understand why you are ignoring the words of a Librem 5 developer saying that no blobs are running on the main CPU: https://news.ycombinator.com/item?id=47943487 https://news.ycombinator.com/item?id=47943487