Earlier quoted context omitted.
Rossmann made a thread on Kiwi Farms because Kiwi Farms members support him, and they support harassing his targets. Rossmann has an account on Kiwi Farms for the purpose of engaging with his supporters on the site. He acts friendly with them and they choose to actively support him. Rossmanns thread on the site is in support of him, not a harassment thread against him.
>Rossmann has an account on Kiwi Farms for the purpose of engaging with his supporters on the site. He acts friendly with them and they choose to actively support him Once again. Okay and? Kiwifarms is a legal site in the us. He is engaging in no harassment or doxxing of anyone just talking to people that talk about him. Does micay talking on twitter with other people mean he supports musk or anything else anybody do…
Original GrapheneOS responses to WIRED fact checker
301–310 of 343 posts
Re: Original GrapheneOS responses to WIRED fact checker
#302Earlier quoted context omitted.
> Their microphone kill switch also doesn't prevent audio recording It doesn't prevent audio recording in the super paranoid "oh, the whole phone has been compromised" scenario because it is bypassable via the sensors. In fact, it doesn't even protect the phone in normal operation, because apps with device=all can access the sensors without the whole phone being compromised. It doesn't prevent audio recording with an…
> because it is bypassable via the sensors. Did you even look in my link, which we are discussing? My quote from there: > Sensors are also switched off on Librem 5 by the three kill switches: https://puri.sm/posts/lockdown-mode-on-the-librem-5-beyond-h...
Does that really sound like a functioning "killswitch"?
Re: Original GrapheneOS responses to WIRED fact checker
#303Earlier quoted context omitted.
Why the scare quotes? Being right is the literal opposite of bad behavior.
If you have zero consideration for other people, sure. "I can't believe you wrote this terrible code. You clearly don’t understand how concurrency works. Do it again." Technically right, but when you run out of people who actually want to work with you, you'll be writing the code yourself.
Re: Original GrapheneOS responses to WIRED fact checker
#304Earlier quoted context omitted.
Mental health and wellness issues in high tech research and development are everywhere. I would suggest that you focus on the product and what it can/cannot do for you.
Suggest away. It’s still a factor in my decision making, because if I can’t trust the developers to behave well, i can’t trust the product to continue to do what it says it can do for me.
So you'd be willing to give up Linux because Linus cannot stop verbally abusing people to this day? Because that's what I did. I decided that any project where the main dev(s) openly abuse people in public, is the line I draw.
I know that is an extremely controversial choice that many people will disagree with, but it's my choice to make and I don't regret it.
Re: Original GrapheneOS responses to WIRED fact checker
#305Earlier quoted context omitted.
Calyx Institute and GrapheneOS are both really great projects. I support them both. I rely on products from both. You're not doing either project any favors by pretending that hastily generalizing nerd dramas and autism over-corrections is somehow a broad statement on the neutrality and objectivity of GrapheneOS's team or the high-quality product it produces. This kind of bad faith posting is bad for the whole FOSS/l…
[flagged]
Let me tell you something. I personally reached out to them just a few weeks ago. I didn't argue, I didn't blame them. That was not my intention and I communicated that clearly. Those were not empty words, I went into it with a genuine open mind and with the goal of finding a solution. After all they consider themselves an open source enthusiast.
It didn't go anywhere. They did not seem willing to discuss anything at all really. You see, even if we assume they are 100% in the right, i.e. they did nothing wrong, why would they oppose our attempt at resolving the conflict? I've come to the conclusion there is no good faith argument to be made here. They spread their post all over the internet, heck they even linked it on Facebook.
Re: Original GrapheneOS responses to WIRED fact checker
#306Earlier quoted context omitted.
> Their microphone kill switch also doesn't prevent audio recording It doesn't prevent audio recording in the super paranoid "oh, the whole phone has been compromised" scenario because it is bypassable via the sensors. In fact, it doesn't even protect the phone in normal operation, because apps with device=all can access the sensors without the whole phone being compromised. It doesn't prevent audio recording with an…
> because it is bypassable via the sensors. Did you even look in my link, which we are discussing? My quote from there: > Sensors are also switched off on Librem 5 by the three kill switches: https://puri.sm/posts/lockdown-mode-on-the-librem-5-beyond-h...
But as you consistently slide any adjacent topic you can into a discussion about the Librem 5 (no matter how tortured a segue), let's go with that and revisit it.
I looked at your puri.sm link, and it mostly served to lower my estimation of the Librem 5's kill switch system. You can't disable the sensors in a trustworthy way without disengaging every kill switch at the same time, entering it into their Lockdown Mode. At that point it's just a still insufficiently air-gapped, highly underpowered Linux device which remains poorly secured against other side-channel attacks. The speaker which, by everything I could find, is still functional, the OS remains poorly secured against software attacks, it lacks proper hardware security, and so on.
It fails in terms of human factors, too. Joe Consumer thinks flipping off the mic switch prevents audio recording, but it doesn't in multiple regards. Even putting it into Lockdown Mode doesn't disable the speaker, which can be used to record audio despite your insistence that the device is fully secured when all switches off. Speakers can also be used to exfil data over short distances, demonstrated to work through walls.
Poor misinformed Joe Consumer is also still left with the same issues the other commenter has already identified in terms of the difficulty of securing any Linux computer.
But that's okay, because you only run trusted software. Until one of those trusted pieces of software include a compromised library, which happens often. You are, at that point, relying on the OS and its relationship to its hardware, which, flawed switch system aside, is highly insufficient. The device offers very little protection at that point. You know all this because you run Qubes OS, but hand-wave that away by appealing to trusted software as soon as the Librem 5 becomes the subject.
If I was modeling threats around protecting sensitive files on the device, not falling victim to attacks that could record audio and/or exfil data or otherwise leak, I'd still go with GrapheneOS on a Pixel 8 or later.
The Librem 5 wins for anyone who just wants a phone which runs Linux (which is a great thing and I wish we had more options which did that), but the security theater of that device is just goofy from top to bottom, as are its more vocal and less reasoned supporters. If one's threat model is, one sometimes wants to be able to turn off all radios and sensors, leaving the speaker functioning, with an otherwise poorly secured device, then, great. It's the device for you. But it's a threat model which will be practically beneficial to very few people, if any.
If your holy grail is having the radios off without other hardware or software considerations, great, you've found the phone for you. It's a brilliantly marketed device for well meaning but poorly informed people with underdeveloped threat models, and, I guess, for someone in your situation who's happy to make all of the above compromises to be able to physically disconnect radios.
Do you always enter Lockdown Mode before typing anything sensitive, due to the attack vector they highlighted about deriving typed data via sensor data? ('No, because I only run trusted software.' See above.) You literally can't disable the sensors without disabling all radios. They acknowledge that sensors are an attack vector worth addressing, yet don't put sensors on a discrete circuit. Like I said, great marketing. Otherwise pretty goofy.
Would I complain if the upcoming Motorola GrapheneOS phone had physical hardware switches? Sure, I'd take an additional layer of containment if all of the fundamentals are addressed properly.
But your argument is like bolting the world's best seat belts onto a motorcycle, and never missing an opportunity to tell the world about your belts, wonderful though they truly are.
Re: Original GrapheneOS responses to WIRED fact checker
#307Earlier quoted context omitted.
> because it is bypassable via the sensors. Did you even look in my link, which we are discussing? My quote from there: > Sensors are also switched off on Librem 5 by the three kill switches: https://puri.sm/posts/lockdown-mode-on-the-librem-5-beyond-h...
And what good is the phone when 3 switches are off? You think that people buy a phone with a "mic killswitch" expects to have to turn off practically everything including internet to make sure that their mics aren't snooped on? Does that really sound like a functioning "killswitch"?
On a long enough timeline he'll probably cite this comment chain as proof you were unable to respond to his concerns, like everyone else who's ever tried.
Re: Original GrapheneOS responses to WIRED fact checker
#308Earlier quoted context omitted.
> I said multiple times that I exclusively run trusted apps on the phone. I use Qubes for untrusted staff. Do you understand that threat models can vary? By that logic, you might as well just not have the killswitch at all. Everything is magically "trusted", right? Yes, I do understand that threat models can vary. Please give an example of a threat model where it makes more sense to use a phone which cannot protect a…
> there is nothing that GrapheneOS or Micay says regarding the Librem or Pinephone that are inaccurate. This is completely false: > Their microphone kill switch also doesn't prevent audio recording
>> Their microphone kill switch also doesn't prevent audio recording
More dangerous advice. The microphone kill switch prevents audio recording via the mic, not via the sensors or speaker. A Librem 5 user needing to secure against audio attacks would need to switch all kill switches off, not just the mic one (by Librem 5's own estimation), but would still be vulnerable to the speaker.
The effect of your participation in threads about projects you claim to care about is harmful. Please do better.
Re: Original GrapheneOS responses to WIRED fact checker
#309Re: Original GrapheneOS responses to WIRED fact checker
#310[flagged]
When you have years-long public forum dox threads dedicated to doxing you with people openly calling for your physical harm, all with some non-zero degree of complicity and/or support by a YouTuber with millions of subscribers, let us know if it still seems like paranoia to you.