Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

It starts with simply rolling major releases out earlier than /e/OS. Remember that to get security fixes for vulnerabilities not marked high/critical, you need the QPR/major updates. Those vulnerabilities may not be an immediate RCE, but they might get used in exploit chains after an RCE. Also, Fairphone and /e/OS will have many known RCEs, because they do not roll out embargoed patches like GrapheneOS and to some extend Samsung & Pixel do.
 help



as if fairphone ever did that: they don't fully keep up with privacy/security backports and lag a year behind on shipping yearly OS releases

so, again, how is /e/OS being behind on updates any worse than fairphone's own OS?




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: