Live data from Hacker News

Original GrapheneOS responses to WIRED fact checker

discuss.grapheneos.org

331–340 of 343 posts

Re: Original GrapheneOS responses to WIRED fact checker

#331
post #83

I personally can't understand why anyone bothers doing open source anything. This Micay guy spends so much time and does something hugely beneficial and we're arguing about how he responds to criticism? I'd rather direct and blunt rather than the weasel words and lies most companies put out.

Some of us embrace our humanity and have an ethical and moral need to engage with the world we want to live in rather than the world dominant economic forces would prefer us to engage in.

I can understand that, but for me he doesn't come across as a "bad" person. He hasn't come out with racism, sexism, etc. he just comes across a bit rude and blunt IMO.

I'm much more concerned with companies that claim to support LGBQT+ and then stick a flag up for 10 minutes once a year, or companies who make 10% of their workforce redundant because they want to pay themselves more, or companies who on one hand support green initiatives and then behind the scenes do the complete opposite.

Re: Original GrapheneOS responses to WIRED fact checker

#332

Earlier quoted context omitted.

On Qubes forum, you had replies from far more knowledgeable people than me. You never could answer to them. You only talk about the lack of security of Pureboot and never showed the code breaking it. "Talk is cheap, show me the code".

> You never could answer to them. I did reply to them plenty of times. Here you go doing the exact same thing again - ignoring 100% of what's being said, then claiming "no one can respond". > You only talk about the lack of security of Pureboot and never showed the code breaking it. If you think a piece of code is needed to understand why it's a joke, then I don't even understand what is wrong with you. LMAO. The who…

Thank you for your kind advice, but I prefer to trust a developer of Heads and many Qubes contributors instead of a loud Internet commenter criticizing everything and everyone.

Re: Original GrapheneOS responses to WIRED fact checker

#333

Earlier quoted context omitted.

I trust you didn't mean it that way, but it's totally improper to go to speculations about mental health in response to discussions about communication styles and maturity. While I appreciate the second line and think it's generally the right answer with FOSS projects, your speculation poisons the well.

> > Daniel Micay has a history of absolutely unhinged behavior online That quotation is from another comment in this discussion. Sadly, it is the sort of personal attack on his mental state that has been commonplace here at HN and elsewhere for a long time. I caution all to avoid such commentary. My long experience in tech r&d has firmly convinced me that mental health and wellness challenges are widespread, and shou…

It does, thank you.

Re: Original GrapheneOS responses to WIRED fact checker

#334

Earlier quoted context omitted.

> You never could answer to them. I did reply to them plenty of times. Here you go doing the exact same thing again - ignoring 100% of what's being said, then claiming "no one can respond". > You only talk about the lack of security of Pureboot and never showed the code breaking it. If you think a piece of code is needed to understand why it's a joke, then I don't even understand what is wrong with you. LMAO. The who…

Thank you for your kind advice, but I prefer to trust a developer of Heads and many Qubes contributors instead of a loud Internet commenter criticizing everything and everyone.

Unless it's Qubes OS team members' valid, rigorous and consistent criticisms of Purism over the years, that is.

Re: Original GrapheneOS responses to WIRED fact checker

#335

Earlier quoted context omitted.

> You never could answer to them. I did reply to them plenty of times. Here you go doing the exact same thing again - ignoring 100% of what's being said, then claiming "no one can respond". > You only talk about the lack of security of Pureboot and never showed the code breaking it. If you think a piece of code is needed to understand why it's a joke, then I don't even understand what is wrong with you. LMAO. The who…

Thank you for your kind advice, but I prefer to trust a developer of Heads and many Qubes contributors instead of a loud Internet commenter criticizing everything and everyone.

The developer of Heads admitted that if someone tampers with the boot block and falsifies the measurements Heads cannot protect the device right on the Qubes forum. Why won't you listen to him then? Is he not trustworthy enough for you?

Re: Original GrapheneOS responses to WIRED fact checker

#336

Earlier quoted context omitted.

Man, if this entirely thread of people calling out how ridiculous the implementation is and the killswitch not actually working in practice isn't enough to convince you, nothing ever will. I don't even feel like arguing against the absurdity of your arguments anymore. This is my last attempt at dumping it down a notch: A "microphone killswitch" is supposed to protect the user against having their convos being snooped…

> A "microphone killswitch" is supposed to protect the user against having their convos being snooped on when it's toggled and still be able to use the phone in a meaningful manner LOL, it's hard to imagine a more ridiculous and self-contradicting statement than this. 1. It's just physically impossible to defend from tracking, when the phone has networking connections on. Not even on all-mighty GrapheneOS. 2. I am us…

> It's just physically impossible to defend from tracking, when the phone has networking connections on. Not even on all-mighty GrapheneOS.

I can use GrapheneOS with the global mic toggled off and sensors toggled off/denied to apps. I can still text, browse the internet, and check my emails while talking to my friends. I can go about my day, receive notifications, be a productive member of society while being reasonably sure that no apps on my phone is snooping on my convos.

This is what most people expect of a "microphone killswitch". Unfortunately, the hardware killswitches on the Librem cannot provide even remotely the same level of assurances as even a software killswitch.

The Librem 5 is either fully offline or something can snoop on the convos while internet is on. How is that a sensible implementation?

> I am using a phone with the kill switches off in a meaningful manner all the time. It is a full computer running a desktop OS and can run any apps, including listening to music from a microSD card, reading saved text/pdf files, showing presentations with original LibreOffice, programming in any language with standard tools, and so on.

Yeah, I am sure this is what a sane person expects a functioning phone with a "microphone killswitch" to be - an offline pocket sized computer instead of a device for communication 99% of the time.

> Even though the phone in the lockdown mode (with all three kill switches off) has no connections, if I'm ever in emergency and need some help, I can turn the phone functionality back on and call for the help I need. Obviously, privacy in such case would be secondary after health.

Yes, I am sure the purpose of the phone is to make a call instead of being used for texting/receiving notifications when you are out and about.

> Unlike for GrapheneOS, there is no way to hack my kill switches for any money. I can be 100% certain that they work as intended, even if a state actor is against me. Yes, everything else might be compromised in such case but not the tracking and listening to me when I need true location and microphone privacy.

Ever considered that maybe, just maybe, a valid use case for most people is not necessarily to hide their location from the carriers 24/7 but to not have their private conversation snooped on?

Or perhaps, another valid use case that some people might want is the ability to be connected to the internet via Wifi while not having their location tracked by the carrier or their private conversations snooped on? I can give you another detailed explanation as to how standard Android has a location toggle that works while your desktop-Linux-in-a-phone can easily have the location tracked when Wifi is on (and without an OS compromise) if you'd like ;)

Re: Original GrapheneOS responses to WIRED fact checker

#337

Earlier quoted context omitted.

Thank you for your kind advice, but I prefer to trust a developer of Heads and many Qubes contributors instead of a loud Internet commenter criticizing everything and everyone.

Unless it's Qubes OS team members' valid, rigorous and consistent criticisms of Purism over the years, that is.

Qubes team never criticized Purism laptops for their lack of security. At least I didn't see that. They criticized other things, which may be important for some and less important for others. The phone is off-topic on the Qubes forum, so its security was never thoroughly discussed.

Re: Original GrapheneOS responses to WIRED fact checker

#338

Earlier quoted context omitted.

Thank you for your kind advice, but I prefer to trust a developer of Heads and many Qubes contributors instead of a loud Internet commenter criticizing everything and everyone.

The developer of Heads admitted that if someone tampers with the boot block and falsifies the measurements Heads cannot protect the device right on the Qubes forum. Why won't you listen to him then? Is he not trustworthy enough for you?

@TommyTran732, you are going to a great length to downplay everything about devices/companies promoting freedom, including Librem 5, Purism, and laptops with Heads. And you are promoting proprietary staff instead. This looks like trolling or astroturfing. For observers, here is the actual quote from the heads developer, not in the (incorrect) interpretation of TommyTran732:

As I pointed before @TommyTran732 and to anyone thinking compromising measured boot is trivial, I layed down the tooling for anyone wanting to further protection / prove measured boot not enough to understand and break it once and for all under WiP: introspection - replicate TPM PCRs measurements directly from measured content (TCPA/TPM Event log) by tlaurion · Pull Request #1568 · linuxboot/heads · GitHub

Just use it for the bad to faster the development of something good/better.

Until then, it was proven non trivial.

https://forum.qubes-os.org/t/discussion-on-purism/2627/187

Re: Original GrapheneOS responses to WIRED fact checker

#339

Earlier quoted context omitted.

The developer of Heads admitted that if someone tampers with the boot block and falsifies the measurements Heads cannot protect the device right on the Qubes forum. Why won't you listen to him then? Is he not trustworthy enough for you?

@TommyTran732, you are going to a great length to downplay everything about devices/companies promoting freedom, including Librem 5, Purism, and laptops with Heads. And you are promoting proprietary staff instead. This looks like trolling or astroturfing. For observers, here is the actual quote from the heads developer, not in the (incorrect) interpretation of TommyTran732: As I pointed before @TommyTran732 and to an…

Yeah, why are you selectively reading? This is after he admitted what I said was true. His only contention is that he thinks it's hard to know what the PCR values should be to fake, so he calls that "security". You are being extra ordinarily disingenuous here.

The actual admission (requires a login): https://forum.qubes-os.org/t/how-exactly-is-heads-pureboot-s...

His words, not mine:

> The goal of Heads is to bring reasonably trustworthy firmware on reasonably open platforms to boot reasonably secure OS, enforcing best effort user controlled atteststion, compartmentalization and prevention. Never is it written anywhere that the firmware is tampering resistant or tampering proof: we lack open source implementation in hardware to have root of trust in hardware. Heads is best approach on what is available, the anchor of trust being in the bootblock, not in hardware. The chain of trust lies there. Of course an evil maid could craft a firmware that would lie about its measurements in the bootblock, raminit, romstage and the payload. But as today, no PoC has even been made public, showing it being actoinnable, and by nature of TPM extend operations is nothing easy to realize, while possible.

I am just gonna highlight the critical part here one more time, since I sent you the same thing before and you didn't read:

> *Of course an evil maid could craft a firmware that would lie about its measurements in the bootblock, raminit, romstage and the payload.*

Yeah, I wouldn't call heads "best approach on what is available" and I do think Boot Guard is better, but at least he is honest about the actual mechanism and the very obvious attack vector.

Re: Original GrapheneOS responses to WIRED fact checker

#340
post #135

Earlier quoted context omitted.

Durov is about as anti-Putin and russia in general as one can get. He go fucked hard in russia and has been going extremely hard against the censorship in russia. TG is one of the few chat apps that can avoid russia's suppression measures, when everything else working over internet fails.

Durov has been going hard against censorship because the pressure on Russians to switch to MAX might consign his own app to oblivion. But to call Durov “anti-Russia” when Telegram development and servers remained in Russia, is to ascribe to him a dissident status that he doesn’t actually deserve. (Durov himself is known to regularly visit Russia, while denying he ever visits Russia. Telegram opened a Dubai office cla…

He's been against it way before MAX was a thing. He visited russia, yes, like a lot of expats with families that are stuck back there. His last visit was in 2021, again, way before MAX was a thing.

If you ever actually lived under the regime where censorship was real - you'd be on Telegram too. When internet goes down and nothing works - Telegram keeps working.

Post reply on HN