4 ms·
Out of the loop here... What whistle did he blow? Anyone have a tldr?
by djschnei 8y ago
Out of the loop here... What whistle did he blow? Anyone have a tldr?
- shittyadmin 8y agoDetails and discussion here: https://news.ycombinator.com/item?id=17289536 https://news.ycombinator.com/item?id=17289536 EDIT: Further details as I'm reading... Big reddit post from the developer here: https://www.reddit.com/r/CopperheadOS/comments/8oq1l3/cos_future_questions_and_concerns_from_a_customer/e06a4cr/ https://www.reddit.com/r/CopperheadOS/comments/8oq1l3/cos_fu... It seems there was a falling out between the developer and CEO over how the business was run - the CEO wanted to license Android security improvements to others, the developer wanted to go make custom hardware and sell secure devices with an entirely non-Linux based stack that still could run Android apps. Seems like reddit has now suspended the developers account, likely due to threats of a libel lawsuit from the CEO... seems like a really bad move on reddit's part, but they're no strangers to bad moves in my book.
- AdmiralAsshat 8y agoCopperheadOS was spearheaded by two people (to my understanding): the founder, and the lead developer. They had a falling out. The developer felt that the founder had compromised their ideals in order to make money (how this was done has not been detailed). The founder told the developer that he's out. The developer, in turn, deleted the signing keys so that no new software can be published under the CopperheadOS name. The developer alleges now that the founder has gotten Reddit to delete his (the developer's) account.
- bhouston 8y agoI thought both were founders or that the developer is actually the founder and the other guy was brought in to run the business side.
- icebraining 8y agoThey are both co-founders with 50% of the company each - at least that's what the dev said on Twitter.
- toyg 8y agoBut the developer started the project before he even knew the other guy. One of the issues is that, reportedly, the developer never actually assigned any copyright to the company, so he's (allegedly) the actual owner of the code.
- numbsafari 8y agoIt was never a very secure OS / product / distro if a single individual was able to destroy the signing keys in this fashion. If this personal battle is enough for folks to say the whole thing is now compromised, and one person held all the keys, how do you know he hadn’t been compromised before? If the code has no third party audits, or a web of trust, then it was never secure to begin with.
- TheAceOfHearts 8y agoThere's always a chain of trust. What alternative would you suggest? I think I remember reading that in Google there's like 5 people that have the master keys and are able to deploy any kind of change at any moment without any review or oversight. They're the top of the chain of trust.
- twblalock 8y agoThere is a big difference between a chain of trust with multiple people involved and corporate oversight, and a chain of trust that consists of one person who wields absolute power. So yeah, there is always a chain of trust, but some are better than others. In the Google case, if one of those 5 people started doing bad things, the others would presumably be able to stop him and undo the damage.