3 ms·
Has anyone deeply audited the security features you mentioned?
by lvs 5y ago
Has anyone deeply audited the security features you mentioned?
- kaba0 5y agoSome of them are separate projects (eg. hardened malloc), also many of the implemented features later got merged by upstream AOSP itself. I think some independent audit also happened, but not sure about the details. Nonetheless, the project has an absolutely stellar track record, where the main guy behind it even revoked the signing keys of the OS upon a failed for-profit company overtake attempt. The project doesn’t accept any for-profit company offers since then and is independent and open-source.
- joemazerino 5y agoFor the readers: the aforementioned "takeover attempt" has never been substantiated or validated. Using the past (and rather trite) CopperheadOS dispute to justify present misgivings is disingenuous.
- detaro 5y agoIf you think "an absolute stellar track record" is "misgivings", I'm curious what you think a positive opinion would look like.