Live data from Hacker News

GrapheneOS migrates server infrastructure from France

privacyguides.org

91–100 of 151 posts

Re: GrapheneOS migrates server infrastructure from France

#91
post #69

Earlier quoted context omitted.

The evidence is not "news articles", but the contents of those articles where a high-ranking prosecutor threatened to go after GrapheneOS "if they don't cooperate with the law". No matter your feelings about the creator, I think this was entirely the rational choice. France is pro-Chat Control. For about a year now there's been an anti-drug trafficking fervor among legislators and government, in which they've pushed…

Didn't France intercept Telegram's CEO to force him to backdoor the app while in country? Yes. Yes they did.

They didn't. TG has never defaulted to e2ee and TG refused to provide the non-e2ee data they had. That is refusing to comply with the law.

You guys hurt your argument so much by straight up lying so you can feel self righteous anger over it

Re: GrapheneOS migrates server infrastructure from France

#92
post #71

Earlier quoted context omitted.

Durov runs an app where slave trade was known and documented, and did nothing.

Can you believe that the cash Euro is used in crime, human trafficking, and exploitatiom everywhere, and the US hasn't invaded Europe to stop them from supporting human rights violations all over the earth?

The 500 euro bill, it used to be the Canadian 1000 dollar bill.

Re: GrapheneOS migrates server infrastructure from France

#93
post #57
post #36

Earlier quoted context omitted.

There is not. In fact, many users will gladly give away any notion of privacy whatsoever in exchange for a Candy Crush lootbox.

I have felt great pity for Snowden all these years, his personal sacrifice was all for nothing, a short news cycle later and nobody cared.

People care but lots of people were brainwashed by politicians and the media to think it's no big deal, and even that Snowden is a bad guy. I've met somewhat intelligent people in real life who have zero appreciation for his disclosure, seemingly oblivious to the fact that whistleblowers are unwanted by the establishment. Does anyone seriously think they didn't know that what they were doing was highly illegal and inappropriate?

Re: GrapheneOS migrates server infrastructure from France

#94
post #21

Earlier quoted context omitted.

> it sends the message that GrapheneOS can be pushed around and manipulated: A slight hint of a threat and they flee. Somehow I doubt France thinks they "won". What they wanted was a back door into the OS. Not only did they not get that but they lost what little bargaining power they had when gOS left France. > it sends a message of inexperience in business, negotiation You don't negotiate with terrorists. Obviously…

If you want my opinion GrapheneOS isn't on the radar of the French government at all, so they don't think they "won" or "lost". It's kind of a "I don't think about you at all" Mad Men Meme. It's just a few cops who said "I don't like that we can't crack it", and a journalist who asked the prosecutor who got Durov arrested and she said "well sure if they break the law we could sue them". The only party that is getting…

GrapheneOS also lost something. Whatever they are shutting down in France has some value, or it wouldn't have existed in the first place. Also they lose access to future opportunities in France.

Re: GrapheneOS migrates server infrastructure from France

#95
post #43
post #7

I understand the concerns and anger of GrapheneOS's leadership, but the hyper-escalation tactic doesn't do what they hope: First, it sends a message of inexperience in business, negotiation, and conflict resolution: 'I'm going to take my ball and leave' - it looks like an emotional overreaction without strategic thinking. These days you sometimes see powerful parties making similar threats - e.g., Uber threatening to…

> self-advertised as uncompromising privacy focused OS > didn't even compromise even a bit (negotiation is already a compromise) against a country who is notorious for advocating for privacy-invasive policies in recent years > get lectured by yc high-horse rider on the obligation blah blah, even when by and large this move doesn't materially affect the end-users in any substantial way I used 4chan style because most…

GP here. Why have three people now said I commented on obligations? I said nothing about it (and thought nothing about it).

Re: GrapheneOS migrates server infrastructure from France

#96
post #61
post #2

They should consider making their primary site a .onion and then have clear-web portals in many countries that serve as a secondary class site or cache . The physical location of the primary site should be unknown.

How does this increase security? The actual code is distributed over github and is digitally signed. Same goes for the installers/updates. Attempts to replace the contents would be easily detected, and would won't do much, aside from maybe compromising someone installing in that short time frame. Moreover darknet sites have an identity problem. It's easy to validate that "grapheneos.org" is the official site, not lea…

> It's easy to validate that "grapheneos.org"

Is it? Why not graphene-os.org? Why not graphene.org? Why not grapheneos.com? Why not grapheneos.io? How do you validate it, really?

Also who REALLY controls that domain in the end? Someone with access to `.org` nameservers. Do you trust that person? What's their name?

Re: GrapheneOS migrates server infrastructure from France

#97
post #12

Earlier quoted context omitted.

This is the second time people responded to a post about GrapheneOS strategy with an argument about obligations. It's hard to even explain how vastly different those issues are. I didn't say anything about GrapheneOS's obligations; I talked about strategy and tactics to serve their goals. If you do want to talk about obligations - yes, we all have obligations to our communities, societies, etc., whether we like it or…

> I talked about strategy and tactics to serve their goals. I am skeptical that there is any lesser step that they can take consistent with their goal of an uncompromised OS. Or that France would be satisfied with anything less than access. Security is not a side feature of GrapheneOS that they can compromise on, it's their core mission. It's like telling Frodo to see the sights in Mordor, but stay away from Mount Do…

This is part of the overreaction I described. Nothing the government of France has said publicly indicates any interest in GOS, beyond one quote from one prosecutor. Has there been any direct communication between someone from the government and GOS regarding this issue?

I get that people are outraged, etc. but it's actually damaging the cause. GOS looks like an unreliable partner.

Re: GrapheneOS migrates server infrastructure from France

#98
post #61

Earlier quoted context omitted.

How does this increase security? The actual code is distributed over github and is digitally signed. Same goes for the installers/updates. Attempts to replace the contents would be easily detected, and would won't do much, aside from maybe compromising someone installing in that short time frame. Moreover darknet sites have an identity problem. It's easy to validate that "grapheneos.org" is the official site, not lea…

> It's easy to validate that "grapheneos.org" Is it? Why not graphene-os.org? Why not graphene.org? Why not grapheneos.com? Why not grapheneos.io? How do you validate it, really? Also who REALLY controls that domain in the end? Someone with access to `.org` nameservers. Do you trust that person? What's their name?

You plug it into Google and hope they got it right

Re: GrapheneOS migrates server infrastructure from France

#99

Earlier quoted context omitted.

> Which makes me think they haven't thought this through and are just overreacting. You're contradicting yourself. If "they haven't thought this through" they clearly haven't been paranoid enough but in that case they aren't overreacting, they're under-reacting. They need to transfer development out of the EU, not just out of France. That's one unexpected benefit of Brexit, btw.

> You're contradicting yourself. If "they haven't thought this through" they clearly haven't been paranoid enough There is no contradiction between "being paranoid" and "not being rational". Oh my mistake, you intentionally put "benefit" and "Brexit" in the same sentence; yes, there's absolutely a contradiction there, well done lad.

> you intentionally put "benefit" and "Brexit" in the same sentence

My comment wasn't an endorsement of Brexit, UK or EU. I was only thinking that if a quick change to a nearby jurisdiction was needed, the UK would be a place to consider, at least in the short term.

Re: GrapheneOS migrates server infrastructure from France

#100
post #61

Earlier quoted context omitted.

How does this increase security? The actual code is distributed over github and is digitally signed. Same goes for the installers/updates. Attempts to replace the contents would be easily detected, and would won't do much, aside from maybe compromising someone installing in that short time frame. Moreover darknet sites have an identity problem. It's easy to validate that "grapheneos.org" is the official site, not lea…

> It's easy to validate that "grapheneos.org" Is it? Why not graphene-os.org? Why not graphene.org? Why not grapheneos.com? Why not grapheneos.io? How do you validate it, really? Also who REALLY controls that domain in the end? Someone with access to `.org` nameservers. Do you trust that person? What's their name?

>Also who REALLY controls that domain in the end? Someone with access to `.org` nameservers. Do you trust that person? What's their name?

Same way you trust/verify that you got Tor Browser from the right domain, and the organization behind it hasn't backdoored it (didn't the tor project recieve government funding?).

Post reply on HN