5 ms·
> They "handle the business" while someone else does 99% of the actual work, then ask to split 50/50. As a response, Micay decided to destroy the update signin
by Avamander 6mo ago
> They "handle the business" while someone else does 99% of the actual work, then ask to split 50/50.
As a response, Micay decided to destroy the update signing keys for all the CopperheadOS devices out in the wild. Resulting in financial damages to Donaldson.
Hardly a level-headed response, even if you disagree about the financial share of something.
- margalabargala 6mo ago[flagged]
- Avamander 6mo ago[flagged]
- dmbche 6mo agoIf you own something you can do what you want with it including rendering it useless
- Avamander 6mo ago[flagged]
- deleted 6mo ago[deleted]
- HybridStatAnim8 6mo agoThats a characteristic all modern OSs and modern apps have. You need to trust the key holders, always. Some people make their own builds for this reason. Depends on the threat model.
- Avamander 6mo ago[flagged]
- amalcon 6mo agoIf you own all of it, yes. If you only own most of it, the minority owners do have some rights -- just fewer than you do.
- dmbche 6mo agoSure!
- HybridStatAnim8 6mo agoMicay owns the whole project. Ownership of the project was not exchanged or divided, part of the explicit terms of the agreement were that Micay would hold the keys and ownership of the project just as they always have.
- HybridStatAnim8 6mo agoMore like the coordinates of a home were burned to protect its occupants. It was a practical choice, not an ideological one.
- kennywinker 6mo ago> Immature maybe Yeah, that’s the issue. I don’t want people who behave immaturely, impulsively, or vindictively, having a key role in something as important as my phone os. I want stability, maturity, and thoughtfulness.
- cf100clunk 6mo agoMental health and wellness issues in high tech research and development are everywhere. I would suggest that you focus on the product and what it can/cannot do for you.
- kennywinker 6mo agoSuggest away. It’s still a factor in my decision making, because if I can’t trust the developers to behave well, i can’t trust the product to continue to do what it says it can do for me.
- HybridStatAnim8 6mo agoDestroying the signing keys in the midst of a hostile takeover is the responsible thing to do. Its for the safety of their users. Thats a commendable trait to have.
- latable 6mo agoWhat does it means to "behave well" for you in this case ?
- aphorism 6mo agoSame, which is why I'm glad he deleted the signing key in this case. It was the only right play given the situation. I'd have done the same and I'd expect anyone with integrity to do likewise.
- majorchord 6mo ago> if I can’t trust the developers to behave well, i can’t trust the product to continue to do what it says it can do for me. So you'd be willing to give up Linux because Linus cannot stop verbally abusing people to this day? Because that's what I did. I decided that any project where the main dev(s) openly abuse people in public, is the line I draw. I know that is an extremely controversial choice that many people will disagree with, but it's my choice to make and I don't regret it.
- ryanmcbride 6mo agoThings aren't only bad if they're illegal. There's plenty of bad things one can do that are perfectly legal, and plenty of good things one can do that are totally illegal.
- abnercoimbre 6mo agoAnd there are legal remedies to create deterrents without a court. Boycotts, journalism or new competition.
- margalabargala 6mo agoIt's not clear to me that causing "financial damages" to the person described is even a bad thing. If you prevent your grandparent from getting scammed, you've caused financial damages to the scammer.
- deleted 6mo ago[deleted]
- HybridStatAnim8 6mo agoDeleting the signing keys for the sake of protecting ones users is the mature and responsible thing to do.
- ForHackernews 6mo agoSometimes deleting it all is the only principled action https://www.theguardian.com/technology/2013/aug/08/lavabit-email-shut-down-edward-snowden https://www.theguardian.com/technology/2013/aug/08/lavabit-e...
- torvoborvo 6mo agoIMO its a lovely paradox that no one can argue against such a deletion. Either the party choosing deletion is reasonable so there are grounds for deletion or unreasonable and they are the grounds for deletion.
- DANmode 6mo agoThe keys got wiped for way spookier reasons than Micay wanting money. Intelligence wanted in, and Donaldson seemingly would have been happy to oblige.
- Avamander 6mo ago[flagged]
- DANmode 6mo agoFrom the story you’re commenting on: > From Wired: > We understand that Daniel's recollection was not that James wanted to know more information about how the signing keys were stored, but that he wanted direct access to them. > Did you suspect his request was tied to a deal he was brokering with a large defense contractor? Did you believe this would put the entirety of CopperheadOS’ user base at risk? > Yes and yes.
- Avamander 6mo ago[flagged]
- lostmsu 6mo agoFrom a security-minded user perspective it makes sense to destroy keys when instead of a single entity I receive updates from I get another entity that is not equivalent, and half of my previous entity thinks that the other half is sus.
- Avamander 6mo ago[flagged]
- HybridStatAnim8 6mo agoIt wasnt intelligence agency compromise, it was a business partner compromise, who intended to violate the privacy and security of their users. Nothing about this is done out of spite. Im not sure where youre getting that from. You just seem to be attacking peoples character for making the right choice given the circumstances.
- freehorse 6mo ago> Hardly a level-headed response, even if you disagree about the financial share of something According to the linked responses, the keys were not deleted because of disagreement over financial share, but over how the keys were to be used (in particular, in potentially dangerous security-wise ways), for which he did not want personal responsibility over (the keys belonged and used by him even before that project)
- Avamander 6mo ago[flagged]
- ysnp 6mo agoPhantom Secure is directly named as one of the parties Donaldson was dealing with, with others being suspected: >Donaldson tried to make a deal with Phantom Secure, which ultimately didnt work out. Micay suspected other counterparties were linked to organized crime, but we cannot confirm those identities or ties on short notice. Donaldson began pursuing such deals before Micay left and continued afterward. https://discuss.grapheneos.org/d/34369-original-grapheneos-responses-to-wired-fact-checker https://discuss.grapheneos.org/d/34369-original-grapheneos-r...
- joemazerino 6mo ago[flagged]
- ysnp 6mo agoFrom what I've read I understand it is more like: /e/OS (recipient of EU funding) and iodéOS are European projects that have not been singled out by the French government in smearing despite them having the similar self-professed goals to GrapheneOS. That they had any influence at all on the French government directly is speculated but not asserted. CalyxOS/Techlore are blamed for being complicit in escalating the animosity and furore around what were initially low-key fallouts/disagreements. This led to GrapheneOS/Micay escalating to defend themselves which unchecked fuelled a spiral of influencer content, vile spamming of CSAM in GrapheneOS rooms (I can personally attest these were some of the biggest on Matrix at the time and led to the team giving up on Matrix moderation and self-protection capabilities), intense public speculation/accusations about Micay's character/mental health etc. which eventually resulted in the swatting attempts. F-Droid project members have publicly aired their dislike of Daniel as a result of direct or indirect disagreements and did have a software quirk that caused an issue for GrapheneOS/possibly other custom OSes' users due to their added permission (which the two parties again disagreed on). Conspires is loaded wording. But I do not think it is productive for me to dredge up posts and potentially cause more misunderstandings as a complete outsider for something that is directly affecting someone's life like this. They (Micay/GrapheneOS) have posted detailed contextual snippets and information about what has happened so please contact them directly for reference to the original posts and discuss if you really wish to find out more.
- HybridStatAnim8 6mo agoThat is a perfectly level-headed response. Signing keys must be protected. In the event of a hostile takeover, where a malicious party seeks to compromise the privacy and security of your userbase, destroying the keys is a sensible decision. Failure to do so, and successful compromise of the keys, will let the malicious party push whatever update they want, and it will be accepted due to being signed correctly. It was not a disagreement about shares, it was a hostile takeover. Someone who never owned the project sought to steal it.
- latable 6mo agoExactly. It was a bold and necessary move to defend the users and the project. Some users got bricked OSes, but had he handed over the keys it would have put those users at risk and would have destroyed the credibility of the project. Also, and as from what I understood from the GOS response he was not an employee of the company and had the ownership of his OS, and CopperOS would have been able to use their own signing keys but they never did which is strange, so even legally it looks like a "level-headed" response.
- TommyTran732 6mo agoImportant to note that users only stopped getting updates, the phones were not bricked and they can reinstall the OS signed with the new key. CopperheadOS was always's Micay's project and used his own signing key. The key never belonged to Copperhead the company afaik.
- spring-onion 6mo agoHey! On a quick introductory note, I'm the community manager and the person who was interviewed. Please, read questions 17, 25 and 26 and our respective answers to them in the linked forum thread. In particular the following parts that I'm pasting here for convenience: Question 17: Did your and Donaldson values begin to diverge? Was Donaldson more concerned with making money than you were? Answer: [...] In 2018, matters between Micay and Donaldson came to a head over Donaldson’s desire to pursue business deals with criminal organizations, and his attempts to compromise the security of CopperheadOS, including by proposing license enforcement and remote updating systems that would allow third-parties to have access to users’ phones. As part of this process, Donaldson began to demand that Micay provide Donaldson with the “signing keys” - i.e. the credentials required to verify the authenticity of releases of CopperheadOS. Donaldson advised that, in order to secure certain new business, potential customers required access to the Keys. The keys had been in continuous use by Micay, in his personal capacity, since before the incorporation of Copperhead. However, more importantly, any party with the keys could mark malicious software as “authentic”, and thereby infiltrate devices using CopperheadOS. Micay was unwilling to participate in that kind of security breach. Since Donaldson had control over certain infrastructure for the open source project, he would be able to incorporate (or hire others to incorporate) the privacy-damaging features described above for all future releases of CopperheadOS. Micay therefore deleted the keys permanently and severed ties with Copperhead and Donaldson. Question 25: Did things between you and Donaldson devolve when he approached you about a compliance audit? Did he tell you that he needed to know how the signing keys were stored? From Wired: We understand that Daniel's recollection was not that James wanted to know more information about how the signing keys were stored, but that he wanted direct access to them. Question 26: Did you suspect his request was tied to a deal he was brokering with a large defense contractor? Did you believe this would put the entirety of CopperheadOS’ user base at risk? Answer: Yes and yes. The large defense contractor in question was Raytheon. The decision to destroy the signing keys was not based on a financial disagreement, but an existential one. Every single CopperheadOS user back then would have been compromised otherwise. It's of course a big deal given the implications, but it acted as a last resort for Daniel to stop a hostile takeover attempt fueled by greed, which he ultimately took because there was no other way out.
- 6mo ago