Live data from Hacker News

Original GrapheneOS responses to WIRED fact checker

discuss.grapheneos.org

231–240 of 343 posts

Re: Original GrapheneOS responses to WIRED fact checker

#231

[flagged]

Agreed.

I like the product, and even recommend GOS to those who want a hardened phone OS. But goddamn, their social media gives me major red flags and I hate remembering that they exist.

I genuinely think that the information in this post is accurate, and at the same time, I think that it is painted in a way that feels off. Like the data is correct, but there are aspects that are clearly emotionally manipulative and combative.

I also have had some less than great interactions with GrapheneOS devs, when I was not seeking out interaction from them on social media (they came to my post and were combative) and played victim that I bullied them and was in league with the harassment campaign when I just asked them to leave me alone.

Overall, I just think that GrapheneOS is a good product, but unless you want to join their cult, just never talk about it neutrally or negatively unless you are ready for weird interactions.

Re: Original GrapheneOS responses to WIRED fact checker

#232

Earlier quoted context omitted.

Personally, I like that they come across as a little paranoid. That's exactly the attitude I want in the people protecting my privacy and security. I hope the developers lie awake at night, unable to fall asleep because terrified that someone somewhere is plotting to attack and exploit them

There's healthy paranoia and there's treating even casual commentary/criticism from anyone as an existential threat & coordinated attack...and responding to that with sustained, coordinated attack campaigns online. That's what Micay's history is. That's not healthy for any project.

not true at all...

There's no coordinated attacks on anyone or projects by GrapheneOS. They respond to misinformation, that's about it.

There have been many attacks on privacy/security projects, not just GOS, recently. If you keep up with the GOS forum you can see posts saying GOS was hacked without evidence. Other claims that GOS is only used by criminals. Theyre not true. Misinformation that aims to destroy the reputation of the project should be responded to.

Re: Original GrapheneOS responses to WIRED fact checker

#233

[flagged]

I think this is the case of a lot of successful OSS. Intrigued people of all horizons comes and interact with few people building something meaningful, mostly on their free time, and expect to be welcomed as customers by the company spokesman. Torvalds had a famous way to express himself freely and hurt some feeling on the Linux mailing list, yet Linux is still a successful OSS project.

I would go on a stretch to say that people that express themselves naturally, without detour, are maybe more trustful than the usual silver-tongued corpo.

Re: Original GrapheneOS responses to WIRED fact checker

#234

Earlier quoted context omitted.

What they said here is accurate, not sure what youre trying to show?

What exactly is accurate? Have you seen my reply to that? Hardware kill switches cut power and prevent any recording.

You have been saying this sort of stuff on the Qubes forum and a bunch of other places for awhile now.

Hardware kill switches are nice-to-have, but they are significantly less important than the OS actually protecting the mic. With your Librem/PinePhone, you cannot even reasonably expect your calls with end-to-end encrypted apps like Signal and Element to be protected. Any app with access to the PulseAudio socket (which happens to be anything that you want to have audio playback with) can snoop on your mic at any moment in time. This does not even require an OS compromise.

This has been pointed out to you repeatedly and yet you choose to ignore it, and instead you just do character assassination whenever a post regarding GrapheneOS or Daniel Micay shows up because what Micay says goes against your favorite ideological products...

Re: Original GrapheneOS responses to WIRED fact checker

#235

Earlier quoted context omitted.

What exactly is accurate? Have you seen my reply to that? Hardware kill switches cut power and prevent any recording.

You have been saying this sort of stuff on the Qubes forum and a bunch of other places for awhile now. Hardware kill switches are nice-to-have, but they are significantly less important than the OS actually protecting the mic. With your Librem/PinePhone, you cannot even reasonably expect your calls with end-to-end encrypted apps like Signal and Element to be protected. Any app with access to the PulseAudio socket (wh…

> Any app with access to the PulseAudio socket (which happens to be anything that you want to have audio playback with) can snoop on your mic at any moment in time.

I said multiple times that I exclusively run trusted apps on the phone. I use Qubes for untrusted staff. Do you understand that threat models can vary?

> Hardware kill switches are nice-to-have, but they are significantly less important than the OS actually protecting the mic.

I never said they were more important. I only said they could reliably protect in sensitive cases.

> instead you just do character assassination

I choose to dispute false information. I don't care about any personalities. And I would be happy to be proven wrong, too.

Re: Original GrapheneOS responses to WIRED fact checker

#236
post #86

Earlier quoted context omitted.

[flagged]

One common personality disorder I see is being extremely defensive when encountering any discussion of human psychology. This comes from a deep psychological fragility. Classic OAD (Obvious Asshole Disorder)

>being extremely defensive when encountering any discussion of human psychology

You just have paranoidal schizophrenia and attributing imaginable things to random people you don't like.

Re: Original GrapheneOS responses to WIRED fact checker

#237

Earlier quoted context omitted.

> I'm more concerned that Signal incorporated in US is having easy life. To add - ironically, it was Durov (Telegram founder) who got arrested in Paris.

I don't find it ironic at all. Zero trust for anything Russia related.

Zero trust does not mean government pressure is okay

Re: Original GrapheneOS responses to WIRED fact checker

#238
post #230

Earlier quoted context omitted.

All of the defensiveness is warranted. They speak neutrally and objectively. The project is not going to relinquish control to any 3rd party. Not even the Motorola partnership is given control over the GOS project. The hypothetical you describe is not possible by design. The GOS project takes no issue with critical thinking, and encourages it. But that is often used as an excuse to handwave attacks. There is a very b…

I'm sure you realize that confident assurances of a random new pseudonymous account on a Web site isn't sufficient for anything of importance. Is there an authoritative source of information about how a takeover like that isn't possible by design, which people can verify, analyze, hold parties accountable for the pieces that require it, etc.?

I am a GrapheneOS user and community member, and I am active in the chat rooms. I made this account to assist with misinformation.

As for how such a thing would not be possible;

-GrapheneOS updates do not trust the network, so any compromise of update servers for OS and app updates would not be able to push malicious updates. Only those who hold the signing keys are capable of pushing updates that will be accepted.

-Multiple people review the code that gets included in the OS. There is not one point of failure when it comes to social engineering.

-GOS supports reproducible builds, so the code that is published can be verified to be the code that is built for the official builds.

So in other words, you would need to convince multiple people who are consciously protecting against this, and who have a proven track record of burning the keys if the privacy and security of their users are in jeopardy. On top of that, you need to conceal this from every developer, moderator, and community member who would raise the alarm at the slightest indication of compromise.

Re: Original GrapheneOS responses to WIRED fact checker

#239

Earlier quoted context omitted.

You have been saying this sort of stuff on the Qubes forum and a bunch of other places for awhile now. Hardware kill switches are nice-to-have, but they are significantly less important than the OS actually protecting the mic. With your Librem/PinePhone, you cannot even reasonably expect your calls with end-to-end encrypted apps like Signal and Element to be protected. Any app with access to the PulseAudio socket (wh…

> Any app with access to the PulseAudio socket (which happens to be anything that you want to have audio playback with) can snoop on your mic at any moment in time. I said multiple times that I exclusively run trusted apps on the phone. I use Qubes for untrusted staff. Do you understand that threat models can vary? > Hardware kill switches are nice-to-have, but they are significantly less important than the OS actual…

> I said multiple times that I exclusively run trusted apps on the phone. I use Qubes for untrusted staff. Do you understand that threat models can vary?

By that logic, you might as well just not have the killswitch at all. Everything is magically "trusted", right?

Yes, I do understand that threat models can vary. Please give an example of a threat model where it makes more sense to use a phone which cannot protect any private calls over a functioning phone that has real protection.

If you are going to say "oh, when you never talk on the phone at all" then you might as well just remove the mic. It's not hard.

As usual, there is nothing that GrapheneOS or Micay says regarding the Librem or Pinephone that is inaccurate. You are just saying stuff that doesn't even remotely make any sense. Perhaps you are being deliberately disingenuous. Perhaps you are just so blinded by an ideology that you cannot see that what you say is just nonsense. I wouldn't know.

> I choose to dispute false information. I don't care about any personalities.

Doesn't seem to be what you are doing here.

Re: Original GrapheneOS responses to WIRED fact checker

#240

Earlier quoted context omitted.

> Any app with access to the PulseAudio socket (which happens to be anything that you want to have audio playback with) can snoop on your mic at any moment in time. I said multiple times that I exclusively run trusted apps on the phone. I use Qubes for untrusted staff. Do you understand that threat models can vary? > Hardware kill switches are nice-to-have, but they are significantly less important than the OS actual…

> I said multiple times that I exclusively run trusted apps on the phone. I use Qubes for untrusted staff. Do you understand that threat models can vary? By that logic, you might as well just not have the killswitch at all. Everything is magically "trusted", right? Yes, I do understand that threat models can vary. Please give an example of a threat model where it makes more sense to use a phone which cannot protect a…

> there is nothing that GrapheneOS or Micay says regarding the Librem or Pinephone that are inaccurate.

This is completely false:

> Their microphone kill switch also doesn't prevent audio recording

Post reply on HN