Live data from Hacker News

France threatens GrapheneOS with arrests / server seizure for refusing backdoors

mamot.fr

281–290 of 399 posts

Re: France threatens GrapheneOS with arrests / server seizure for refusing backdoors

#281
post #240

Earlier quoted context omitted.

And how do you hack a single phone without a backdoor in every phone?

You use the signing keys for GrapheneOS to push an update to a single user.

How is this different from a backdoor in every phone?

Some authority compels me to give them signing keys so now they can push anything they want, to any device they want?

Re: France threatens GrapheneOS with arrests / server seizure for refusing backdoors

#282

Earlier quoted context omitted.

I've been saying this for years: the more power you have the higher standard you should be held in. In most societies on the planet it's the other way around.

I've been saying this too but lately I think the fundamental notion of power is wrong. There's 2 perspectives which are 2 sides of the same coin: --- All social relationships should be consensual. This means based on _fully-informed_ consent which can be revoked at any time. This already marks employment as exploitative because one side of the negotiation has more information and therefore more bargaining power. Not…

Fuck yeah preach.

If someone claims to be "representing" me (whatever the fuck that means)...

...even more so if they are "representing" me alongside millions of others, i.e. in a very abstract sense (what do a million people have in common? everything and nothing)...

...and especially if the "representation" is concluded in "winning" a ritual bureaucratic gauntlet which gives you the right to send organized murderers after exactly the people whom you fail to "represent"...

...then it sure sounds like we all deserve instant access to a real-time sub-second, molecular-level feed of your entire present existence before it's anywhere near a fair bargain and not a totalizing coercive arrangement.

Granted, this sounds a little unfeasible from a technical or security perspective.

Although if the global media capacity was redirected to doing primarily this, instead of inventing ever fancier narratives to distract people from paying attention to the circumstances of their own lives, it just might be able to handle the full surveillance of a few thousand global volunteers: the real exemplary humans who set the real standards in real dialog with the entirety of sovereign society. Governance by inverse big brother. Sure gonna be cheaper than all the effort that goes into convincing every subsequent generation that "democracy" is what's going on...

Alternatively, that entire exercise can be sidestepped by Dunbar-compliant representation, i.e. let's introduce a pervasive social norm that dictates the following: (1) nobody has the right to represent more than their 100 closest people in the world (2) representation doesn't stack to form multi-tiered institutions - representatives only connect horizontally in a territory-spanning mesh. so if N * 100 people vibe with your idea you'll have to either split your personality N-wise (doesn't go very far with current theories of mind) or give N-1 people the right to their own interpretation of your idea to communicate with 100 others.

[to the tune of https://www.youtube.com/watch?v=Xk4QLlV-WLQ :]

I think they tried that about 100 years ago and it worked well enough for organized metasubversive parasites to core it and wear its husk for the better part of a century. Maybe if it was started less overtly in the first place it would've worked better. But cosplaying German Idealistm to your pet serfs cosplaying worker's council doesn't really leave space for a whole lot of subtlety. If you're interested in the workings of power this is commendable, there is much to learn from just the last 150years (which are relatively well documented). They're such a cause-and-effect pinball; but like and subscribing to any of those ideologies just lets the ghost of the ball drag you along. Kinda sad that they're one of the things the Net died into, no?

Re: France threatens GrapheneOS with arrests / server seizure for refusing backdoors

#283
post #130

Remember when they arrested Pavel Durov? I don't buy their official reasoning. Dear European friends, our leaders are tightening the screws. If we don't make our voices heard this is only going to get worse. https://x.com/durov/status/1976420399970701543

You know I didn't use to understand libertarians, but after years of watching boundaries being overstepped again and again I think I see the appeal of burning it all down and living in a cabin in the woods. Like, in Europe we already live in a completely safe society in historical and geographic terms, what more do you fucking want? Security is beyond a laughable excuse for things like chat control. Power tripping el…

> I think I see the appeal of burning it all down and living in a cabin in the woods.

AFAIK, you're not allowed to live in a cabin in the woods in Europe.

Re: France threatens GrapheneOS with arrests / server seizure for refusing backdoors

#284

Earlier quoted context omitted.

Wouldn't be hard to hide a backdoor in a multi million line codebase ...

Unless you think the same backdoor is hiding in AOSP, you can just check the diff and some extra lines for context.

People in this thread are very explicitly claiming that Android and iOS are backdoored, yes.

Re: France threatens GrapheneOS with arrests / server seizure for refusing backdoors

#285
post #240

Earlier quoted context omitted.

You use the signing keys for GrapheneOS to push an update to a single user.

How is this different from a backdoor in every phone? Some authority compels me to give them signing keys so now they can push anything they want, to any device they want?

They can't bypass disk encryption that way:

https://news.ycombinator.com/item?id=46038241

It does appear to be what they want from us, but it's not possible to bypass the Weaver disk encryption throttling via compromised OS updates or even secure element updates. It's fully not possible to bypass the security of a strong passphrase, which we encourage via optional 2-factor authentication support for fingerprint+PIN as the main way people unlock to make using a passphrase as the primary lock method after booting or 48h timeout much more convenient.

Re: France threatens GrapheneOS with arrests / server seizure for refusing backdoors

#286

HN title: "France threatens GrapheneOS with arrests / server seizure for refusing backdoors" LQDN: "Dans ces articles, la cheffe de la section cybercriminalité du parquet de Paris – à l'origine de l'arrestation de Pavel Durov – menace également les développeurs·es de GrapheneOs. Interviewée, elle prévient qu'elle ne s'« empêchera pas de poursuivre les éditeurs, si des liens sont découverts avec une organisation crimi…

France has made it clear they expect to have a backdoor in end-to-end encryption apps and disk encryption. They've been saying that it's unacceptable not to have a backdoor in a bunch of these news stories they've gotten published by contacting the media. They've said if we don't cooperate with that, they'll take similar actions against us as they did SkyECC and Encrochat meaning hijacking our servers and trying to have us arrested.

Le Parisien has 2 articles about this, not only one, and https://archive.is/UrlvK is one of the places they talk about going after us if we don't cooperate with providing them access to devices. It's not possible for us to provide an update which bypasses the throttling for brute force protection so what they're asking isn't even helping them break into specific devices but helping them compromise security for everyone in anticipation of rare cases of criminals using devices. https://news.ycombinator.com/item?id=46038241 explains lack of technical ability to compromise security after the fact. Titan M2 is specifically designed with insider attack resistance so that Google making an update disabling the brute force protection won't be accepted by the secure element without the Owner user successfully unlocking first. We don't have the signing key for the Titan M2 firmware anyway. This is part of our required hardware-based security features which we're working on providing in a Pixel alternative with a major Android OEM working with us right now. We talked to them about the France situation already and it does not negatively impact our partnership. It may be a good idea to speed up an official announcement with them to counter the narrative being pushed by France's law enforcement agencies now.

Re: France threatens GrapheneOS with arrests / server seizure for refusing backdoors

#287

https://grapheneos.social/@GrapheneOS/115589833471347871 > The FBI ran a sting operation in Europe where they created their own 'secure' phone and messaging platform. Their OS used portions of our code and was heavily marketed as being GrapheneOS or based on GrapheneOS. So how do we know GrapheneOS itself isn't a honeypot? It's run by a mystery org and heavily marketed as being a secure platform. https://en.wikipedia…

It's disappointing to see such blatant misinformation on HN. There has been a wave of these low quality trolls and it's increasing everyday

I'm not a troll. Everyone thinks we should trust GrapheneOS...why? Because they're loud and aggressive?

They claim they are audited... by whom? When? Where are the results?

https://grapheneos.org/faq#audit

https://discuss.grapheneos.org/d/5527-who-has-audited-graphe...

> We've built relationships with security researchers and organizations interested in GrapheneOS or using it which results in a lot of this kind of collaboration.

Re: France threatens GrapheneOS with arrests / server seizure for refusing backdoors

#290
post #286

HN title: "France threatens GrapheneOS with arrests / server seizure for refusing backdoors" LQDN: "Dans ces articles, la cheffe de la section cybercriminalité du parquet de Paris – à l'origine de l'arrestation de Pavel Durov – menace également les développeurs·es de GrapheneOs. Interviewée, elle prévient qu'elle ne s'« empêchera pas de poursuivre les éditeurs, si des liens sont découverts avec une organisation crimi…

France has made it clear they expect to have a backdoor in end-to-end encryption apps and disk encryption. They've been saying that it's unacceptable not to have a backdoor in a bunch of these news stories they've gotten published by contacting the media. They've said if we don't cooperate with that, they'll take similar actions against us as they did SkyECC and Encrochat meaning hijacking our servers and trying to h…

Le Parisien is not the french state. I doubt you had any interaction with the french authorities at all.

You are unable to any legal recourse because none of your rights have been violated (yet).

Post reply on HN