Live data from Hacker News

Original GrapheneOS responses to WIRED fact checker

discuss.grapheneos.org

241–250 of 343 posts

Re: Original GrapheneOS responses to WIRED fact checker

#241

Earlier quoted context omitted.

I gathered you were being facetious, but I do not appreciate being called a sockpuppet. I am a GOS community member and I have been for several years. I am active in the GrapheneOS chatrooms, and I choose to volunteer my time assisting others.

[flagged]

I must emphasise I am not associated with GrapheneOS.

Re: Original GrapheneOS responses to WIRED fact checker

#242

Earlier quoted context omitted.

GrapheneOS wants to post more positive things, rather than just defensive replies. But they have very little choice in the matter. If the inhumane levels of attacks werent happening, they would have more time to discuss future features, how they choose to approach features, etc. But ignoring the attacks only make it worse. The suggestions to ignore it, even if genuine, arent helpful.

I'm thinking about this a bit more. It may be the case that Daniel and the project are so under siege that they need to take a hostile attitude toward some of the people they interact with as a matter of self preservation. They may have no other option. But taking this posture while also being fair to all of the people around them (i.e. some people who aren't actually attacking them) may be difficult or even impossib…

People can accidentally be spreading attacks with loaded/presumptuous statements even when their intentions are pure. Unfortunately, pure intentions can still cause harm that needs to be countered.

Take your reply as an example, the GrapheneOS accounts are managed by multiple people, so the fixation on one specific project member may not even be accurate to the discussion. Having ones character attacked is immensely harmful on its own, but being attacked for something one may not even be doing is also immensely harmful.

The unfortunate reality is that people tend to believe the first thing they read, and without something countering it, will roll with it, intentionally or otherwise. So countering misinfo efficiently and quickly is vital.

Re: Original GrapheneOS responses to WIRED fact checker

#243

Earlier quoted context omitted.

> I said multiple times that I exclusively run trusted apps on the phone. I use Qubes for untrusted staff. Do you understand that threat models can vary? By that logic, you might as well just not have the killswitch at all. Everything is magically "trusted", right? Yes, I do understand that threat models can vary. Please give an example of a threat model where it makes more sense to use a phone which cannot protect a…

> there is nothing that GrapheneOS or Micay says regarding the Librem or Pinephone that are inaccurate. This is completely false: > Their microphone kill switch also doesn't prevent audio recording

> Their microphone kill switch also doesn't prevent audio recording

It doesn't prevent audio recording in the super paranoid "oh, the whole phone has been compromised" scenario because it is bypassable via the sensors.

In fact, it doesn't even protect the phone in normal operation, because apps with device=all can access the sensors without the whole phone being compromised.

It doesn't prevent audio recording with any normal usage either because the OS is incapable of protecting private conversations thanks to the PulseAudio socket. "Exploiting" this is significantly easier than any of the stuff involving the sensors.

Re: Original GrapheneOS responses to WIRED fact checker

#244

Earlier quoted context omitted.

> They "handle the business" while someone else does 99% of the actual work, then ask to split 50/50. As a response, Micay decided to destroy the update signing keys for all the CopperheadOS devices out in the wild. Resulting in financial damages to Donaldson. Hardly a level-headed response, even if you disagree about the financial share of something.

Hey! On a quick introductory note, I'm the community manager and the person who was interviewed. Please, read questions 17, 25 and 26 and our respective answers to them in the linked forum thread. In particular the following parts that I'm pasting here for convenience: Question 17: Did your and Donaldson values begin to diverge? Was Donaldson more concerned with making money than you were? Answer: [...] In 2018, matt…

Raytheon literally asked for the signing keys of CopperheadOS? After all this vagueposting around it, I find that hard to believe.

Or is it just that Raytheon went against what he thought CopperheadOS stood for?

Re: Original GrapheneOS responses to WIRED fact checker

#246
post #122

Earlier quoted context omitted.

[flagged]

Phantom Secure is directly named as one of the parties Donaldson was dealing with, with others being suspected: > Donaldson tried to make a deal with Phantom Secure, which ultimately didnt work out. Micay suspected other counterparties were linked to organized crime, but we cannot confirm those identities or ties on short notice. Donaldson began pursuing such deals before Micay left and continued afterward. https://d…

[flagged]

Re: Original GrapheneOS responses to WIRED fact checker

#247

Earlier quoted context omitted.

> They "handle the business" while someone else does 99% of the actual work, then ask to split 50/50. As a response, Micay decided to destroy the update signing keys for all the CopperheadOS devices out in the wild. Resulting in financial damages to Donaldson. Hardly a level-headed response, even if you disagree about the financial share of something.

Hey! On a quick introductory note, I'm the community manager and the person who was interviewed. Please, read questions 17, 25 and 26 and our respective answers to them in the linked forum thread. In particular the following parts that I'm pasting here for convenience: Question 17: Did your and Donaldson values begin to diverge? Was Donaldson more concerned with making money than you were? Answer: [...] In 2018, matt…

Have any pieces of evidence to support this?

Re: Original GrapheneOS responses to WIRED fact checker

#248
post #29

[flagged]

Just read the article again and I'd suggest also reading responses we sent to fact checkers (many answers didn't even show up in the article). James' side of the story is riddled with lies. So, if you read the article with that in mind, you can see that Copperhead got steered in the wrong direction by James. Daniel has been the owner of the open source project from the beginning and Copperhead was never in control of…

[flagged]

Re: Original GrapheneOS responses to WIRED fact checker

#249

Earlier quoted context omitted.

That is a perfectly level-headed response. Signing keys must be protected. In the event of a hostile takeover, where a malicious party seeks to compromise the privacy and security of your userbase, destroying the keys is a sensible decision. Failure to do so, and successful compromise of the keys, will let the malicious party push whatever update they want, and it will be accepted due to being signed correctly. It wa…

Exactly. It was a bold and necessary move to defend the users and the project. Some users got bricked OSes, but had he handed over the keys it would have put those users at risk and would have destroyed the credibility of the project. Also, and as from what I understood from the GOS response he was not an employee of the company and had the ownership of his OS, and CopperOS would have been able to use their own signi…

Important to note that users only stopped getting updates, the phones were not bricked and they can reinstall the OS signed with the new key.

CopperheadOS was always's Micay's project and used his own signing key. The key never belonged to Copperhead the company afaik.

Re: Original GrapheneOS responses to WIRED fact checker

#250
post #47

Earlier quoted context omitted.

If they were doing that one thing, they would not have posted this. It's fine not to market to consumers, but this raises additional concerns about the founder's judgement. Someone else claimed that they deleted update signing keys for copperhead devices. That's seriously concerning if true; possibly bad enough to switch away from grapheneOS.

He deleted the signing keys because it looked like the other owner of Copperhead OS wanted to make the signing keys available to government agencies and/or criminal organizations. He deleted the signing keys to protect their users against malicious updates, which is the right thing to do and should increase trust in him and the project. It's worth actually reading the linked post. Relevant segment: In 2018, matters b…

Is it that Donaldson wanted to pursue deals with criminals or he wanted to backdoor an OS for a defense contractor or that he was a government spy? From the article it seems like none. Claims need receipts or they are blind assertions.

Me? I was a CopperheadOS user from the 2021 rebuild era before GrapheneOS existed in its state. All I've seen from GrapheneOS and Micay are claims without evidence and over-moderation of points they don't agree with.

Post reply on HN