{"id":18537,"date":"2026-08-24T10:39:23","date_gmt":"2026-08-24T17:39:23","guid":{"rendered":"https:\/\/jasonsblog.ddns.net\/?p=18537"},"modified":"2026-08-24T10:39:23","modified_gmt":"2026-08-24T17:39:23","slug":"fairphone-6-is-repairable-is-it-private-and-secure","status":"publish","type":"post","link":"https:\/\/jasonsblog.ddns.net\/index.php\/2026\/08\/24\/fairphone-6-is-repairable-is-it-private-and-secure\/","title":{"rendered":"Fairphone 6+ Is Repairable. Is It Private and Secure?"},"content":{"rendered":"\n<p class=\"wp-block-paragraph\">This is a good article for the overview of the privacy phone options. Consequently, if your threat level is nation states or their connected megacorps (whistleblower or lobbying against unethical government policies&#8230;) a GrapheneOS phone is mandatory, especially if you travel internationally. Myself, I&#8217;m comfortable with cheap phones that run LineageOS, and if I was traveling internationally I&#8217;d just wipe my phone and set it up when I arrived in country (same with laptop) to bypass the illegal rifling through my property, which isn&#8217;t acceptable without a warrant. Also, these alternative privacy operating systems based on LineageOS are a little suspect, especially as I believe \/e\/OS\/ is based out of France. My belief is they&#8217;re meant to compete with GrapheneOS so goverrnments can still break into your phone, though they should offer you some privacy from Google&#8217;s data harvesting in default Android and Google apps.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\"><a href=\"https:\/\/reclaimthenet.org\/fairphone-6-is-repairable-is-it-private-and-secure\" target=\"_blank\" rel=\"noopener\">https:\/\/reclaimthenet.org\/fairphone-6-is-repairable-is-it-private-and-secure<\/a><\/p>\n\n\n<div class=\"wp-block-ub-divider ub_divider ub-divider-orientation-horizontal\" id=\"ub_divider_3106dd78-227b-4ca9-b370-de33c09928c9\"><div class=\"ub_divider_wrapper\" style=\"position: relative; margin-bottom: 2px; width: 100%; height: 2px; \" data-divider-alignment=\"center\"><div class=\"ub_divider_line\" style=\"border-top: 2px solid #ccc; margin-top: 2px; \"><\/div><\/div><\/div>\n\n\n<h5 class=\"wp-block-heading\">Americans have been buying the Fairphone for a reason Fairphone never advertised. It&#8217;s time to see whether the phone agrees.<\/h5>\n\n\n\n<figure class=\"wp-block-image\"><img decoding=\"async\" src=\"https:\/\/media.reclaimthenet.org\/images\/2026\/08\/aAIMwDSkmzvL.jpg\" alt=\"\"\/><\/figure>\n\n\n\n<p class=\"wp-block-paragraph\">By Rick Findlay<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">This week, Fairphone&nbsp;<a href=\"https:\/\/www.fairphone.com\/stories\/the-fairphone-gen-6-is-all-about-giving-you-more\">announced the Fairphone 6+<\/a>, its first phone to be released directly in the United States. It has 12GB of RAM, a Snapdragon 7s Gen 4 chipset, and comes with Android 16 out of the box. The company promises OS updates through 2032. The phone is on sale now in the States through Fairphone&#8217;s own store and Amazon for $649 (or \u20ac649 in Europe).<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">The phone&#8217;s insides are accessible behind a removable battery, and Fairphone says that&nbsp;<a href=\"https:\/\/techcrunch.com\/2026\/08\/18\/fairphone-is-launching-its-latest-repairable-phone-in-the-us-too\/\">12 parts are swappable<\/a>&nbsp;by the owner. Fairphone&#8217;s warranty runs for five years, and software support runs for eight years, out to 2033. (You can also buy&nbsp;<a href=\"https:\/\/reclaimthenet.org\/de-googled-smartphone-murena-fairphone-4-hits-the-market-in-the-us\">a de-Googled \/e\/OS version of the Fairphone through Murena<\/a>, which sells for the same price.) While Fairphone has sold some phones in the States before, this is the first time it has actively marketed a device in the country. The US customer base has skewed toward people buying it as a privacy phone, rather than for its environmental credentials, though the company says that may change as it becomes more widely available.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Fairphone OS is close to unmodified Android, Google Mobile Services included. But running the latest version of Android is not the same as having the latest security updates, and even a new Fairphone doesn&#8217;t come with the very latest version of Android. The Fairphone 6 shipped on Android 15 in June 2025, despite Android 16 already being available.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Its first major Android update took more than eight months to arrive,&nbsp;<a href=\"https:\/\/9to5google.com\/2026\/03\/16\/android-16-begins-rolling-out-to-fairphone-6\/\">landing in March 2026<\/a>. At least the Fairphone 6+ launches on Android 16\u2014though with Android 17 approaching, it will be interesting to see how long the update takes. Fairphone promises eight years of support, but&nbsp;<a href=\"https:\/\/support.fairphone.com\/hc\/en-us\/articles\/24463713641234-The-Fairphone-Gen-6-Gen-6-Release-Notes\">its release notes also say<\/a>&nbsp;that means monthly security updates for roughly three years, followed by bi-monthly security updates from June 2028 until support ends in June 2033.<\/p>\n\n\n\n<figure class=\"wp-block-image is-resized\"><img decoding=\"async\" src=\"https:\/\/media.reclaimthenet.org\/images\/2026\/08\/R8n2frDXs9NL.jpg\" alt=\"A lineup of various smartphones in different colors and designs, displayed on a wooden surface with a green background.\" style=\"aspect-ratio:1.49625468164794;width:799px;height:auto\"\/><\/figure>\n\n\n\n<p class=\"wp-block-paragraph\">That support period is nothing to sneeze at, but it&#8217;s also not the same as what you get with a Pixel. Pixels get Android Security Bulletin patches the month they land; Fairphone takes longer. Hardened OS provider GrapheneOS often argues, and it&#8217;s true, that a fast support window is what actually protects you: A patch that arrives two months after the vulnerability is public is two months in which the exploit is known, and your phone is not fixed.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Furthermore, the Fairphone 6&#8217;s kernel is not as up-to-date as the Pixel&#8217;s. Fairphone&#8217;s&nbsp;<a href=\"https:\/\/code.fairphone.com\/projects\/fairphone-gen-6\/kernel.html\">kernel repositories page<\/a>&nbsp;for the Fairphone 6 points developers at AOSP documentation for the GKI android14-6.1 branch. That means the Fairphone 6 sits on the Linux 6.1 kernel branch, which has a&nbsp;<a href=\"https:\/\/www.kernel.org\/releases.html\">projected end-of-life on kernel.org<\/a>. In the time since the Fairphone 6 was released, Pixels have moved through kernel versions 6.6 and 6.12. The Fairphone 6+ might be different, since it uses a new chipset, but as of now, there&#8217;s no indication it will be updated more frequently.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Fairphone treats an&nbsp;<a href=\"https:\/\/support.fairphone.com\/hc\/en-us\/articles\/10492476238865-How-to-unlock-and-re-lock-the-bootloader\">unlockable bootloader as a feature<\/a>, and supplies the system binaries that community OS projects need to run on its handsets. As a result, the FP6 family has options for \/e\/OS, iod\u00e9OS (which&nbsp;<a href=\"https:\/\/community.iode.tech\/t\/fairphone-6-is-now-supported\/7631\">added FP6 support around January<\/a>&nbsp;2026), and LineageOS (\/e\/OS is based on Lineage \u2013 \/e\/OS 3.5, for instance,&nbsp;<a href=\"https:\/\/alternativeto.net\/news\/2026\/2\/-e-os-3-5-released-with-lineageos-22-2-base-webassembly-support-and-fairphone-6-upgrades\">uses a LineageOS 22.2 base<\/a>). CalyxOS is available on the older FP4 and FP5, while Ubuntu Touch and postmarketOS are available on Fairphone devices generally.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">One option you won&#8217;t find, however, is GrapheneOS \u2013&nbsp;<a href=\"https:\/\/reclaimthenet.org\/an-introduction-to-grapheneos\">a project often pointed to by serious security researchers<\/a>. While you can install GrapheneOS on a Fairphone, it&#8217;s not officially supported, and for good reason. On a Pixel, GrapheneOS has verified boot: the phone cryptographically verifies its own software at every boot, and relocks the bootloader with the OS&#8217;s own signing key, keeping a full chain of trust. This is not possible on Fairphone devices running third-party OSes, which do not have verified boot or working hardware attestation.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">The stock bootloaders on the FP3 and FP4 actually trusted the public AVB signing key \u2013 meaning they would boot an alternative OS with no warning at all. The FP6 improves on this, but still lacks a secure element capable of providing working disk encryption (a secure element enforces PIN-attempt rate-limiting in hardware, so an attacker can&#8217;t brute-force your PIN). GrapheneOS only officially supports devices with Weaver, the Pixel&#8217;s secure-element-backed throttling.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">GrapheneOS&nbsp;<a href=\"https:\/\/grapheneos.org\/faq\">publishes a device requirements list<\/a>, including isolated radios, A\/B firmware and OS updates with rollback, verified boot with rollback protection, recent GKI kernel branches and hardware virtualisation. The Fairphone does not meet this list, nor does every current Motorola device (including 2026 models).<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">One episode should be told in full. It concerns a vulnerability that wasn&#8217;t specific to Fairphone but affected several Android devices, including the Fairphone 5. The story begins with&nbsp;<a href=\"https:\/\/rtx.meta.security\/exploitation\/2024\/01\/30\/Android-vendors-APEX-test-keys.html\">Meta&#8217;s Red Team X<\/a>, a group of security researchers who hack products to find bugs. They discovered that several Android devices were shipping APEX (Android Package EXtension) modules signed with private keys that are publicly available in the AOSP source tree. In other words, the devices were shipping with their own updates signed with publicly available keys. Since anyone can get those keys from the source code, anyone can forge an update and take near-total control of the device.<\/p>\n\n\n\n<figure class=\"wp-block-image is-resized\"><img decoding=\"async\" src=\"https:\/\/media.reclaimthenet.org\/images\/2026\/08\/m9tSzyutt1qT.jpg\" alt=\"Back view of a Fairphone showing its internal components, including the battery and camera modules.\" style=\"aspect-ratio:1;width:800px;height:auto\"\/><\/figure>\n\n\n\n<p class=\"wp-block-paragraph\">Meta reported the issue to Google, which assigned it the designation CVE-2023-45779. The Fairphone 5 was among the affected devices. Fairphone ran its own investigation and found that the flaw wasn&#8217;t limited to its newest model; the FP3, FP3+, and FP4 were also vulnerable. The day the disclosure went live, Fairphone&nbsp;<a href=\"https:\/\/www.fairphone.com\/en\/2024\/01\/30\/security-update-apex-modules-vulnerability-fixed\/\">published its own post<\/a>&nbsp;about the vulnerability. The flaw had been present for years, carried by four device generations, and handed near-total control to anyone who noticed it. It took an outside researcher at another company to notice it.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Fairphone&#8217;s security track record isn&#8217;t perfect, then. But it should be noted that the company&#8217;s transparency about its supply chain may actually be part of the reason we know about this vulnerability. If Fairphone didn&#8217;t document that its hardware and software come from a supplier, it would be harder to understand how this vulnerability ended up on so many Fairphone devices. And it&#8217;s possible that other, less transparent companies may have been affected by the same issue without anyone ever knowing.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Peer-reviewed academic work has also found security issues in Fairphone&#8217;s products. One paper found that&nbsp;<a href=\"https:\/\/www.android-device-security.org\/publications\/2025-leierzopf-spices\/Leierzopf_2025_SPICES_AVBTestKeyInTheWild.pdf\">the FP3&#8217;s vbmeta partition<\/a>&nbsp;covers multiple partitions without signing them separately, and that there was a bootloader lock-state handling flaw that meant these partitions could be flashed without a userdata wipe. But this flaw was discussed in the academic literature, not by a rival OS project trying to make Fairphone look bad.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Dig a little deeper, however, and it becomes clear that Fairphone&#8217;s openness has its limits. The company&#8217;s open-source site&nbsp;<a href=\"https:\/\/code.fairphone.com\/projects\/fairphone-gen-6\/odm.html\">publishes the ODM&#8217;s Android source<\/a>&nbsp;tree, but this can&#8217;t be built from source because it depends on proprietary toolchains and sources. According to&nbsp;<a href=\"https:\/\/us.fairphone.com\/the-fairphone-gen-6-plus\">Fairphone&#8217;s product page<\/a>, final assembly happens in a factory supporting living wages and worker wellbeing. But that factory is owned by T2Mobile \u2013 the very same ODM that designs the device and writes the low-level software that Fairphone can&#8217;t, or won&#8217;t, make available.<\/p>\n\n\n\n<figure class=\"wp-block-image is-resized\"><img decoding=\"async\" src=\"https:\/\/media.reclaimthenet.org\/images\/2026\/08\/e5cy2TMrb5AU.jpg\" alt=\"Fairphone with its back cover removed, showing the battery and internal components.\" style=\"aspect-ratio:1;width:800px;height:auto\"\/><\/figure>\n\n\n\n<p class=\"wp-block-paragraph\">The \/e\/OS partnership is where the marketing question gets sharpest. In April 2026,&nbsp;<a href=\"https:\/\/grapheneos.social\/@GrapheneOS\/116353973732143171\">GrapheneOS publicly called out<\/a>&nbsp;<a href=\"https:\/\/reclaimthenet.org\/murena-eos-2025-new-products-privacy-tools-business-solutions\">\/e\/ Foundation president and Murena CEO Ga\u00ebl Duval<\/a>&nbsp;for what it saw as security shortcomings in \/e\/OS. Duval responded that \/e\/ doesn&#8217;t take a &#8220;hardened security&#8221; approach and isn&#8217;t building a phone for pedophiles to evade justice\u2014a framing that, coincidentally, is the exact argument law-enforcement lobbies use against encryption everywhere: &#8220;Strong security is mainly for criminals.&#8221; (In November 2025,&nbsp;<a href=\"https:\/\/reclaimthenet.org\/grapheneos-quits-france-citing-unsafe-climate-for-open-source-tech\">the French publication Le Parisien linked both GrapheneOS and Pixel phones to narcotraffickers<\/a>.)<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Duval was responding to claims GrapheneOS had made in July 2025. Murena&nbsp;<a href=\"https:\/\/community.e.foundation\/t\/e-os-and-security-updates\/72384\">said in a blog post<\/a>&nbsp;at the time that it takes security seriously and accused GrapheneOS of making misleading claims. It said its workflow integrates the previous month&#8217;s Android security patches, which means its phones are never more than a month behind on security updates. In the worst case, it said, that&#8217;s around nine weeks. It also pointed to Qualcomm&#8217;s secure processing unit as a strong layer of protection: Without it, it said, recovering a 6-digit PIN could take years.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Despite the GrapheneOS claims, Fairphone has kept its partnership with \/e\/OS, selecting it as the software for its de-Googled devices. It did not respond to a request for comment.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">If you&#8217;re willing to do the work (and you&#8217;re reading this, so you might be), there are ways to opt out. Here are three honest recommendations:<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">If you want a phone that&#8217;s easier on the planet, with better repairability, longevity, and less e-waste, buy a Fairphone. If you also want to de-Google your life, putting \/e\/OS or iod\u00e9OS on a Fairphone is your best bet for a reasonably convenient, relatively private phone. Just know that in opting out of Google&#8217;s ecosystem, you&#8217;re also opting out of some security features like verified boot and hardware attestation. If you want a phone with hardened security, your best choice is a Pixel running GrapheneOS. (And if you&#8217;re due for an upgrade, hold off for a bit:&nbsp;<a href=\"https:\/\/reclaimthenet.org\/the-deal-that-could-change-de-googled-phones-forever\">Motorola just announced a partnership with the GrapheneOS Foundation at MWC 2026<\/a>, and we should see official GrapheneOS support on select 2027 Motorola devices.)<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">All of these options require some trade-offs, and none of them are perfect. But at least they&#8217;re honest. The Fairphone 6+ is a good phone, and Fairphone sells you something even more valuable: sustainability and independence from the throwaway cycle. That it&#8217;s finally going on sale directly in America is a big deal. Just don&#8217;t confuse what you&#8217;re buying; the \/e\/OS version of the Fairphone has marketing that invites buyers to believe they&#8217;ve bought hardened privacy and security. That&#8217;s not true for every use case. (The irony of buying Google hardware to escape Google should be said out loud.) In terms of security and privacy, a Fairphone and a Pixel running GrapheneOS are two different products.<\/p>\n","protected":false},"excerpt":{"rendered":"<p>This is a good article for the overview of the privacy phone options. Consequently, if your threat level is nation states or their connected megacorps (whistleblower or lobbying against unethical government policies&#8230;) a GrapheneOS phone is mandatory, especially if you travel internationally. Myself, I&#8217;m comfortable with cheap phones that run LineageOS, and if I was [&hellip;]<\/p>\n","protected":false},"author":1,"featured_media":0,"comment_status":"closed","ping_status":"","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[6],"tags":[],"class_list":["post-18537","post","type-post","status-publish","format-standard","hentry","category-tech"],"blocksy_meta":{"styles_descriptor":{"styles":{"desktop":"","tablet":"","mobile":""},"google_fonts":[],"version":7}},"featured_image_src":null,"author_info":{"display_name":"Jason","author_link":"https:\/\/jasonsblog.ddns.net\/index.php\/author\/jturning\/"},"_links":{"self":[{"href":"https:\/\/jasonsblog.ddns.net\/index.php\/wp-json\/wp\/v2\/posts\/18537","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/jasonsblog.ddns.net\/index.php\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/jasonsblog.ddns.net\/index.php\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/jasonsblog.ddns.net\/index.php\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/jasonsblog.ddns.net\/index.php\/wp-json\/wp\/v2\/comments?post=18537"}],"version-history":[{"count":1,"href":"https:\/\/jasonsblog.ddns.net\/index.php\/wp-json\/wp\/v2\/posts\/18537\/revisions"}],"predecessor-version":[{"id":18538,"href":"https:\/\/jasonsblog.ddns.net\/index.php\/wp-json\/wp\/v2\/posts\/18537\/revisions\/18538"}],"wp:attachment":[{"href":"https:\/\/jasonsblog.ddns.net\/index.php\/wp-json\/wp\/v2\/media?parent=18537"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/jasonsblog.ddns.net\/index.php\/wp-json\/wp\/v2\/categories?post=18537"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/jasonsblog.ddns.net\/index.php\/wp-json\/wp\/v2\/tags?post=18537"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}