Live data from Hacker News

Original GrapheneOS responses to WIRED fact checker

discuss.grapheneos.org

211–220 of 343 posts

Re: Original GrapheneOS responses to WIRED fact checker

#212

Earlier quoted context omitted.

Understandable wishes, but you might have to put something from yourself into it if this is a pressing concern. Or you will be left to your own corporate devices.

What exactly are you suggesting? If i go help out at the graphene os project, that won’t change their leadership. Should I make my own fork?

The leadership is great. Persistent, patient and friendly.

They were able to improve. I don't think many of the often negative and ad-hominem critics would be able to endure such a pressure as they had in the past.

Re: Original GrapheneOS responses to WIRED fact checker

#213
post #11

> Donaldson, now 42, is a self-taught hacker who never finished school, was briefly unhoused, and spent most of his twenties in a “positive hardcore punk band.” “It’s cool being smart,” he told me. “But if you can’t pay your bills, you’re a dumbass.” > The domain “Copperhead.co” was registered by Donaldson in 2014 and incorporated in 2015 under both Donaldson’s and Micay’s names. The idea was that shares would be spl…

> They "handle the business" while someone else does 99% of the actual work, then ask to split 50/50. As a response, Micay decided to destroy the update signing keys for all the CopperheadOS devices out in the wild. Resulting in financial damages to Donaldson. Hardly a level-headed response, even if you disagree about the financial share of something.

Hey! On a quick introductory note, I'm the community manager and the person who was interviewed. Please, read questions 17, 25 and 26 and our respective answers to them in the linked forum thread. In particular the following parts that I'm pasting here for convenience:

Question 17: Did your and Donaldson values begin to diverge? Was Donaldson more concerned with making money than you were?

Answer: [...] In 2018, matters between Micay and Donaldson came to a head over Donaldson’s desire to pursue business deals with criminal organizations, and his attempts to compromise the security of CopperheadOS, including by proposing license enforcement and remote updating systems that would allow third-parties to have access to users’ phones. As part of this process, Donaldson began to demand that Micay provide Donaldson with the “signing keys” - i.e. the credentials required to verify the authenticity of releases of CopperheadOS. Donaldson advised that, in order to secure certain new business, potential customers required access to the Keys.

The keys had been in continuous use by Micay, in his personal capacity, since before the incorporation of Copperhead. However, more importantly, any party with the keys could mark malicious software as “authentic”, and thereby infiltrate devices using CopperheadOS.

Micay was unwilling to participate in that kind of security breach. Since Donaldson had control over certain infrastructure for the open source project, he would be able to incorporate (or hire others to incorporate) the privacy-damaging features described above for all future releases of CopperheadOS. Micay therefore deleted the keys permanently and severed ties with Copperhead and Donaldson.

Question 25: Did things between you and Donaldson devolve when he approached you about a compliance audit? Did he tell you that he needed to know how the signing keys were stored?

From Wired:

We understand that Daniel's recollection was not that James wanted to know more information about how the signing keys were stored, but that he wanted direct access to them.

Question 26: Did you suspect his request was tied to a deal he was brokering with a large defense contractor? Did you believe this would put the entirety of CopperheadOS’ user base at risk?

Answer: Yes and yes.

The large defense contractor in question was Raytheon. The decision to destroy the signing keys was not based on a financial disagreement, but an existential one. Every single CopperheadOS user back then would have been compromised otherwise. It's of course a big deal given the implications, but it acted as a last resort for Daniel to stop a hostile takeover attempt fueled by greed, which he ultimately took because there was no other way out.

Re: Original GrapheneOS responses to WIRED fact checker

#214

Earlier quoted context omitted.

The claim anyone on the GrapheneOS team is paranoid is unsubstantiated.

[flagged]

I gathered you were being facetious, but I do not appreciate being called a sockpuppet.

I am a GOS community member and I have been for several years. I am active in the GrapheneOS chatrooms, and I choose to volunteer my time assisting others.

Re: Original GrapheneOS responses to WIRED fact checker

#216
post #196
post #135

Earlier quoted context omitted.

Durov has been going hard against censorship because the pressure on Russians to switch to MAX might consign his own app to oblivion. But to call Durov “anti-Russia” when Telegram development and servers remained in Russia, is to ascribe to him a dissident status that he doesn’t actually deserve. (Durov himself is known to regularly visit Russia, while denying he ever visits Russia. Telegram opened a Dubai office cla…

Do you have a source for any of this? Wikipedia and news that I can find support that he fled Russia after government conflicts. It’s also well known that he keeps his and the dev team’s location secret, so anybody going knocking on incorporation addresses in Dubai then feigning surprise is acting in bad faith.

This was all over the news a couple of years ago when Russian entry/exit records were leaked. Doing a Google search for “durov visited russia frequently” will get you plenty of reportage.

"so anybody going knocking on incorporation addresses in Dubai" The point is that Telegram has repeatedly countered claims that it is a Russian app with "Actually, Telegram is a Dubai company”. People reasonably interpret that as more than a mere incorporation address, and it isn’t being emphasized enough that development is still largely done from Russia, and servers are also located there.

Re: Original GrapheneOS responses to WIRED fact checker

#217

Earlier quoted context omitted.

Maybe true, but but the flip side is that sometimes what is called an attack is actually criticism. That's how it appears to a lot of us from the outside.

GrapheneOS wants to post more positive things, rather than just defensive replies. But they have very little choice in the matter. If the inhumane levels of attacks werent happening, they would have more time to discuss future features, how they choose to approach features, etc. But ignoring the attacks only make it worse. The suggestions to ignore it, even if genuine, arent helpful.

I'm thinking about this a bit more.

It may be the case that Daniel and the project are so under siege that they need to take a hostile attitude toward some of the people they interact with as a matter of self preservation. They may have no other option. But taking this posture while also being fair to all of the people around them (i.e. some people who aren't actually attacking them) may be difficult or even impossible. I can see this behavior in myself sometimes. I just don't have the energy to be fair. "F U".

I wouldn't want to see friendly corporate slop either. I appreciate how down to nuts and bolts the communiques are on Mastodon and how deadly serious they take everything. That part of the communication style makes me trust them more.

I think a good step in the right direction might be acknowledging that being defensive necessarily leads to erring on the side of assuming bad faith rather than good, which leads to some mis-judgements. So far you said that GrapheneOS is open to all criticisms, which (though I haven't followed the space very recently so my memory on specifics is hazy) just does not seem to match my interpretation. I think that if we were having this conversation on Twitter or Mastodon, Daniel would have blocked me by now (if he hadn't already blocked me years ago).

Re: Original GrapheneOS responses to WIRED fact checker

#218

Earlier quoted context omitted.

[flagged]

I gathered you were being facetious, but I do not appreciate being called a sockpuppet. I am a GOS community member and I have been for several years. I am active in the GrapheneOS chatrooms, and I choose to volunteer my time assisting others.

[flagged]

Re: Original GrapheneOS responses to WIRED fact checker

#219
post #60
post #26

Earlier quoted context omitted.

Graphene is not a consumer brand and they do not intend to be a consumer brand. They do one thing: make as secure a phone OS as they can. That’s it. If you’re expecting them to do anything in a friendly way, it ain’t gonna happen, that’s not who they are or what they do. That will absolutely limit their scope and reach, but it also allows them to focus on the one thing they’re trying to do without making compromises.…

[flagged]

All the stuff about members of our team not being stable is ridiculous and only works in favor of people or organizations that don't like us or want to damage GrapheneOS.

GrapheneOS has multiple people helping out. Many developers as well as people who help out with non-development work. It's a big claim to say that the whole team is unstable.

I'd suggest reading the article again. Considering the situation, the party about deleting the keys should be a good sign for anyone reading it. It shows that the project's leadership cares about doing things the right way. Members of the team are similarly dedicated to helping build and support an OS that improves people's privacy and device security, not to scam users by making a flashy product and rake in cash. Or, in Donaldson's case, work with shady companies and even possibly criminals.

Privacy and security projects like GrapheneOS are important considering the political landscape these days. People really need to stop repeating inaccurate claims about us, like that we're criminals, unstable, crazy, etc.

Re: Original GrapheneOS responses to WIRED fact checker

#220

Earlier quoted context omitted.

What exactly is accurate? Have you seen my reply to that? Hardware kill switches cut power and prevent any recording.

Their entire post regarding pinephones is accurate. Hardware kill switches need to be correctly implemented. A kill switch cutting off mics and not sensors or speakers is incomplete and privacy theater. Not to mention kill switches assume the device is already compromised, at which point everything on it is likely compromised as well.

> Their entire post regarding pinephones is accurate.

I never mentioned Pinephones, although I do believe that the attack on them is still too harsh. Their security is about as good as the one for Linux. And it's not exactly "atrocious". Especially if you only use software from the official repositories. Let's agree that it should be improved though. (I prefer Qubes OS myself.)

> Hardware kill switches need to be correctly implemented.

Are you saying they aren't for Librem 5?

> A kill switch cutting off mics and not sensors or speakers is incomplete and privacy theater.

I explained in the link above that cutting all sensors is exactly what happens if you choose it.

> Not to mention kill switches assume the device is already compromised

This is not accurate. Kill switches imply that even if the device is compromised (which you can never 100% verify, even on GrapheneOS), your location etc is still private, when you need it.

Post reply on HN