Hacker Newsnew | past | comments | ask | show | jobs | submit | Halan's commentslogin

Ethical phone maybe only hardware wise, software wise with Google it is far from ethical


Nobody is suggesting Fairphone has also replaced Google/Android re SW/OS. What they've arguably done I'd improve the existing situation - surely that counts for something?

There is also nothing precluding them from dropping Android in the future and putting effort into something like Sailfish OS.


Fairphone provides very poor updates much worse than iPhone, Pixel, Samsung flagship or many other devices. They lag far behind partial backports of security patches to older releases of Android. They lag a year or more behind full security patches which are not all backported to older Android releases, similarly to iOS. Fairphone 5 and earlier have an end-of-life kernel without security support and the same fate awaits the newer devices.

Unlike AOSP, SailfishOS has a largely closed source user interface and application layer. They still have their own UI and application layer so it's strange to portray Android using a different one than desktop Linux as a problem and a closed source alternative to it as a solution. SailfishOS drastically reduces privacy, security, usability, battery life and app compatibility compared to simply using AOSP. It's not possible to build a project like GrapheneOS on top when so much of the OS code is closed source rather than only many mainstream apps people want to use.


> Fairphone provides very poor updates much worse than iPhone, Pixel, Samsung flagship or many other devices. They lag far behind partial backports of security patches to older releases of Android. They lag a year or more behind full security patches which are not all backported to older Android releases, similarly to iOS.

How can we verify all those claims?


Easy to see they don't have Android 17 yet on their website so cannot get all security patches. The claimed patch level is about a month late.

Search online and see reports updates slow down cause they're busy. Maybe newer phones get faster updates for a year then slow down to every few months. I found that by googling.

Found a post on the FP forum. FP4 was released with support for 5 years but SoC was only going to be supported for 2 more years so no firmware updates for 3 of them.

idk why you ask GOS these questions. They know their stuff and shouldnt have to do research for people like a LLM. I didn't know and used Google and found enough to believe what they say.


They lag 1-2 months behind the Android Security Bulletins which are months behind when patches can first be shipped by vendors. Verifying their kernels for the FP5 and earlier are end-of-life can be done by looking at the code. It's straightforward to verify they're a year or more behind on major updates and that those are required for full security patches. It's clear from a basic glance at the Android Security Bulletins that Low and Moderate severity patches are not backported. It's harder to demonstrate they don't backport all High and Critical severity patches but it's true and the gap of what's not backported is growing with recent changes. They made an announcement to OEMs about only the most recent 2 major yearly versions getting most High and Critical severity backports along with even those no longer getting a large portion of High and Critical internally found bugs which were found with LLMs.

> idk why you ask GOS these questions

It's called a discussion forum. This isn't GOS' personal press release website. They can use their own website for that.

> They know their stuff

They can link to sources then to show their confidence, as any decent academic would do


You can run postmarketOS on it, although some features are not supported yet: https://wiki.postmarketos.org/wiki/Fairphone_(Gen._6)_(fairp...


Now that Fairphone officially sells phones in the United States, I am likely going to get one specifically because it supports postmarketOS. My Pinephone is so slow that I have never really used it for anything beyond testing.


Why are the comments below flagged/dead?


I’ve studied CS in Italy and most if not all exams were both written and oral some also had labs. I thought it was the same for other degrees too.


RIP any hope for an Apple alternative to Samsung Dex. An iPhone 16 pro running the same specs will never be able to run macOS. We already knew it but this made official


A phone you could just plug into a USB dockand it becomes your mac would be so cool


Why would anyone buy this over a good as new refurb 16 pro with 100% battery and likely few months of Apple care left? Here they can be found for $650 or less


They will be bought in bulk by businesses. The same for some of the laptops what you might find in a strange place within the lineup.


How does a potential positive contributor pierce through? If they are not contributing to something already and are not in the network with other contributors? They might be a SME on the subject and legit have something to bring to the table but only operated on private source.

I get that AI is creating a ton of toil to maintainers but this is not the solution.


In my OSS projects I appreciate if someone opens an issue or discussion with their idea first rather than starting with a PR. PRs often put me in an awkward position of saying "this code works, but doesn't align with other directions I'm taking this project" (e.g. API design, or a change making it harder to reach longer term goals)


He answered it in the thread: Basically, the system has no opinion on that, but in his projects he will vouch anyone who introduces themselves like a normal human being when opening a PR.


One solution is to have a screensharing call with the contributor and have them explain their patch. We have already caught a couple of scammers who were applying for a FOSS internship this way. If they have not yet submitted anything non-trivial, they could showcase personal projects in the same way.

FOSS has turned into an exercise in scammer hunting.


I'm not sure if I follow, are the PRs legitimate and they are just being made to buff their resume, or are PRs malicious?


The patches are not malicious, but the submitters are unable to explain them. We require submitting a non-trivial patch in order for someone to be considered for a FOSS internship. As there is money involved, this attracts scammers now more than ever.


They are becoming AI slop more and more likely in an attempt to buff their resumes by making it look like they contribute to a bunch of open source. Basically low effort low quality submissions for silly things that just waste maintainers time.


It seems like it depends on how the authors have configured Vouch. They might completely close the project except to those on the vouch list (other than viewing the repo, which seems always implied).

Alternatively they might keep some things open (issues, discussions) while requiring a vouch for PRs. Then, if folks want to get vouched, they can ask for that in discussions. Or maybe you need to ask via email. Or contact maintainers via Discord. It could be anything. Linux isn't developed on GitHub, so how do you submit changes there? Well you do so by following the norms and channels which the project makes visible. Same with Vouch.


Looking at this, it looks like it's intended to handle that by only denying certain code paths.

Think denying access to production. But allowing changes to staging. Prove yourself in the lower environments (other repos, unlocked code paths) in order to get access to higher envs.

Hell, we already do this in the ops world.


So basically we are back at tagging stuff as good for first contributors like we have been doing since the dawn of GitHub


Honestly, the entire process of open-source contribution is broken. People should just fork and compete on the free 'market'. If you have a good idea / PR, just keep patchsets. People should mix and match the patch sets as they like. Maintainers who want to keep their version active will be forced to merge proper patch sets. The key argument against this is the difficulty integrating patch sets.

This should be easier with AI. Most LLMs are pretty good at integrating existing code.


It already is a free market. Aggregation effects improve value.


How is this news? A lot of airports in Europe had had this for years and even in England there were terminals within the major hubs where this was already the norm


Heathrow is by far the largest airport in the UK, with several times more flights per day than any other, and flights to a broader range of destinations. So it affects a lot more prospective fliers. I looked up European airports and found some mention that Rome and Milan also have this new equipment, but they're both still significantly smaller than Heathrow.


Gatwick already had it too, at least a part of it.

The fact Heathrow got 30/40% more traffic than other airports in the same continent already having it doesn’t make the news worth all this noise.


Yes but Heathrow has around twice as many departures per day (edit after your edit:) than Gatwick.

This is on BBC news. Heathrow is twice as busy as any other airport in the UK. It's the easiest major airport to reach from London (other than LCY which is not that "major"). I literally know people who are leaving from Heathrow this week and are affected by this. C'mon, it's newsworthy.


Yeah and 50% more than Rome, but overall less than all airports already doing it in Europe. This news made front page out of two things:

1) English people do not know anything about continental Europe

2) Americans do not know anything about Europe


Oh okay, you're asking why is it on HN front page rather than more generally why is it newsworthy. That's a fair point. I suppose it's a big feat of logistics and engineering to manage a switchover at such a large airport with so many terminals


Schiphol had this for a while (several years I think, I don't fly often), but they reversed it a couple of years ago because European regulators didn't agree for some reason, and now liquids are forbidden again (discussed elsewhere in thread). So this surprises me and is news to me.


Because Heathrow markets itself as a world class airport and they have been woefully behind the times with regards to updating their security tech


Reading the blog post and comments here from fellow UK inhabitants I am shocked to see how phone lines are considered common when I always ever lived in places with only one of them for the entire place (3+ bedroom houses on two floors).


GitHub already charges organisations to fund open source features. Otherwise it wouldn't lack so many enterprise level features, it wouldn't have half baked solution that do not take into consideration enterprise requirements. GH Actions for example is still not there yet after years


Always fingerpick test if the monitor throws a number you don’t feel.

Any diabetic person must have heard and read this recommendation a thousand times.

The actual scenario to worry about is if the number is too high and a close loop system make so the pump injects too much insulin.


If you think about societies still in English colonial hangover and ChatGPT you might find that they have similar reasons to speak the way they speak.

Both aim at using an English that is safe, controlled and policed for fear of negative evaluation.


Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: