3 ms·
> Calling all custom ROMs insecure and claiming to be the only one is IMHO 'drama'. No, what it is is true. microG lets you de-Google a phone, but the resultin
by scheeseman486 20d ago
> Calling all custom ROMs insecure and claiming to be the only one is IMHO 'drama'.
No, what it is is true. microG lets you de-Google a phone, but the resulting phone is provably less secure. If stating the truth causes "drama", the problem isn't the person or entity saying the true thing. If that truth shakes people, if it upsets them, they should look into the problem that truth has revealed (not created, as truth isn't something that exists only after someone speaks it) rather than blame those who are speaking it.
Can you provide evidence that GrapheneOS is less secure than LineageOS or other custom ROMs? Because GrapheneOS (and even leaked documentation from commercial adversarial phone hacking tools) provide a hell of a lot of evidence that it is, in fact, considerably more secure than just about every other phone OS in existence.
- riedel 19d agoI am not saying that what they say is wrong. However, this is about current phones. If your goal is supporting aftermarket phones the case looks very different. It is the only way to get a decent level of security. The problem is IMHO how graphene communicates. It is mixing tons of different things to always make their communication more 'bold'. Then they complain about people complaining about their communication style. It is my personal choice, but I accept less security while not having to care about GrapheneOS announcements. I value their work in a similar way that I value WikiLeaks.
- scheeseman486 18d agoWhat I've seen (that doesn't outwardly appear astroturfed) is largely people getting their feelings hurt because of an opinion they've expressed about the qualities of project they're involved in, or just a user/fan of. Their dislike of the Linux kernel or the relative insecurity of desktop Linux projects in general tends to piss people off, even though the negative points they make are invariably detailed and well communicated. Because of that, instead of refuting the actual argument being made, discussion always swings towards their tone. What it is, exactly, that is objectionable? Are there personal attacks being made? Yeah. Towards the GrapheneOS developers. It's something I've seen for myself and if you get into these threads on HN early, you can see how the comment deletions pile up. When they say they are the target of organized disinfo and targeted attacks by malignant third parties, it's pretty easy to believe them. It is in the best interests of many, many very powerful people that GrapheneOS is destroyed. No one who takes infosec seriously cares about GOS' PR filling their communication with tummy rubs and head pats. Infosec is a nightmare, adversaries are everywhere, all anyone should want to know is whatever is as close to the truth as possible.
- microtonal 16d agoTo be honest, I am happy that a somewhat influential account is raising these issues. I have tried to explain for probably two decades now that the Linux desktop has poor security and the Linux kernel has issues. But somehow a significant portion of the Linux community lives with the delusion that the Linux desktop is the most secure OS. The whole idea that a vulnerability in some image parser that their Mastodon client uses could give an attacker access to their full user account, simply doesn't occur to them. I want the open source desktop to succeed, but we can only make progress if we accept that there are a lot of security, UX, and UI issues and start tackling them. When they say they are the target of organized disinfo and targeted attacks by malignant third parties, it's pretty easy to believe them. It is in the best interests of many, many very powerful people that GrapheneOS is destroyed. Yeah. There it's clear that there is a lot of organized disinformation, probably by government actors and certainly by other open source and phone vendors that try to sell privacy/eurowashed phones (one Volla astroturfer outed themselves accidentally on Mastodon by sharing information only an employee could know).