I like the devices, but I've stuck with Pixel devices for the better security practices. Honestly, I'm a little surprised that a university wouldn't be concerned about late security updates and the like.
I like the devices, but I've stuck with Pixel devices for the better security practices. Honestly, I'm a little surprised that a university wouldn't be concerned about late security updates and the like.
The security capabilities of their hardware are what makes GrapheneOS incompatible to target the phone, Not any specific security practices of the developers of Fairphone.
Having said that: if there’s a way to MDM GrapheneOS, I’d be looking at that also!
The n+ patch interval on Lineage, /e/ and the rest of them, that’s plain and simply more days your administrators are at risk of giving up the keys to your castle - and that’s a tough pill to swallow!
It doesn't matter if their os gets security updates late, becase security updates depend on the rom maker this case grapheneos.
The security issues stemming from such things are likely real, as well. There was a paper released some time back, about binary blobs, that found:
> Our results reveal that device manufacturers often neglect vendor blob updates. About 82% of firmware releases contain outdated GPU blobs (up to 1,281 days). A significant number of blobs also rely on obsolete LLVM core libraries released more than 15 years ago. To analyze their security implications, we develop a performant fuzzer that requires no physical access to mobile devices. We discover 289 security and behavioral bugs within the blobs. We also present a case study demonstrating how these vulnerabilities can be exploited via WebGL.