One person controls the single global signing key.
Every update pushed to 400000 devices is signed by Daniel Micay. He already proved in 2018 he will destroy signing keys and brick thousands of users devices on purpose when he feels wronged. That same key can push any code, silently, automatically, to any phone, at any time. verified boot guarantees the device will accept it.
You would have no way to know what was added
Talking shit about the only phone OS feds can't crack? I wonder who this could be?
>He already proved in 2018 he will destroy signing keys and brick thousands of users devices on purpose when he feels wronged.
Src?
>>34017btw use dola. it is extremely good in finding sources.
>>34018>still vagueposting about what the actual issue is>still hasn't offered any kind of alternativelet's see an alternative point of view shall we?
https://news.ycombinator.com/item?id=19502209<He didn't destroy [the keys] out of malice. He destroyed them because (from his point of view) they were about to be compromised. If users trust the key because they trust updates coming from Daniel and if Daniel is about to lose control of the key to someone else, then destroying the key before it becomes compromised is the responsible and right thing to do.it is of course ultimately up to the user to trust this or that set of keys, which ultimately means trusting this or that set of people. I trust the Debian team for example
>>34021>I trust the Debian team for examplebut why?
>>34021isn't it interesting that tech is all about blind belief?
>>34022why not? you have to trust a whole lot of people to even do anything with computers. or maybe you think it's possible to write literally everything from scratch?
>>34023it's not blind belief. it's belief in the process
Holy shit they use a key by the developer to verify the images???? Stop the presses!!
>>34017>>34019Deleting the keys didn't brick the phones. It just delayed updates for a few months, iirc.
>>34310na und? nehmen wir an, man würde es schaffen den ruf von grapheneos komplett durch FUD zu zerstören. was wäre daran so schlimm? wenn grapheneos wirklich gut ist, dann ändert sich trotzdem nichts an der qualität des produkts. die verbliebenen leute die von grapheneos überzeugt sind, werden grapheneos weiterhin nutzen. es würde sich nichts ändern. deswegen verstehe ich nicht, warum die grapheneos kultisten so obsessiv versuchen den ruf von grapheneos zu schützen. geld werden die devs immer haben, denn man braucht nicht viele spender, sondern man kann auch mit wenigen reichen spendern gut auskommen. grapheneos wurde von millionären wie jack dorsey aufgebaut.
>>34314>still no alternative offeredrather than telling people not to use graphene, how about you tell us what should be used instead?
>>34315>what should be used instead?das hängt von deinem persönlichen usecase ab. nur danach lässt sich die frage beantworten.
>>34316still not seeing any alternatives offered, buddy
>>34317You should only use operating systems that the United States federal authorities are able to access. In phones that means anything other than GrapheneOS.
>>34318yes. this is why we shouldn't use tor either
>>34317alternative wofür genau? ich sage nicht, dass graphene os komplett nutzlos ist. aber es ist keine lösung für alles und es gibt viele dinge, die man über graphene is sehr kritisch sehen muss. ich benutze grapheneos nicht, weil es mir nicht das liefert was ich haben will und weil es zu teuer ist (man muss ein pixel kaufen). mein problem (tracking durch vpn anbieter, isp, plattformen) kann übrigens kein OS lösen.
darum benutze ich ein ganz normales android handy. weil ich auf diesem gerät genauso getrackt werde wie mit einem graphene os handy.
meine grundsätzliche privacy/security philospohie beruht auf totalem misstrauen. ich gehe grundsätzlich davon aus, dass alle böse sind: bigtech, die foss community, "die guten"….
ich benutze computer und handy so, dass ich davon ausgehe non stop überwacht zu werden.
alles ist korrumpiert. ich bewerte tools nur nach ihrem direkten nutzen. ich kann erkennen, ob ein adblocker funktioniert oder nicht. doch bei einem produkt das vorgibt meine privatsphäre zu schützen, kann ich nichts selbst überprüfen ob es das tut was es verspricht.
heute gibt es nur noch zwei sorten an leuten die immer noch an der privacy illusion festhalten: 1. naive leute die keine ahnung haben und 2. grifter die es tatsächlich besser wissen, aber mit "privacy" ihr geld verdienen.
>Chinese state influence
Based
>>34331>Supporting more phones is badOK, buddy.
>>34331>>34334Stop spreading FUD. Lenovo and Google are good and trustworthy companies. You are just poor.
GrapheneOS is just making the poison taste better, that's all it does.
The whole point of this project isn't to get people away from smartphones. It's the opposite. It's there to normalize smartphones and the surveillance that comes with them. It targets the people who are actually critical, the ones who should know better, and gives them an excuse to finally carry one.
"See? It's hardened. It's secure. This one is fine."
It doesn't challenge the idea that everyone needs to carry a tracking device 24/7. It saves that idea. It takes the most invasive tool ever created and makes it palatable for people who would otherwise resist.
The poison is still there. You just don't notice the taste as much.
Here is the official guide for graphene cultists:
- Never question that smartphones themselves are the ultimate surveillance device.
- Never criticize Google or Lenovo/Motorola.
- Every success belongs to GrapheneOS; every problem is Android’s fault.
- The user is always to blame, even when devs hide important info.
- Any criticism of GrapheneOS is “harassment.”
- Don’t ask questions; questioning is betrayal.
- Move the goalposts when facts disagree.
- Never talk about PRISM.
- Insiders owe absolute loyalty; outsiders owe impossible purity.
- Never admit error; double down and call critics shills.
Unique IPs: 17