You shouldn't get info about GrapheneOS from Hacker News comments especially when multiple regulars here are part of the attacks on GrapheneOS. Hacker News permits people to freely engage in libel and harassment towards me on nearly every post about GrapheneOS.
If I may make a suggestion: as GrapheneOS becomes more popular, perhaps it's time to better establish users' trust in the control over it.
When the project was primarily you, who was already known for technical prowess and a principled exit from a different project, that was enough for many enthusiasts.
But as both the team and the user base have grown (and, secondarily, the outside world has become less stable), a new infusion of confidence in trustworthiness would help.
I'm not sure how to do that, but it may include communicating who is involved (not just names, but why they should be trusted), and what safeguards there are against mistakes and compromised/rogue individuals.
I say this because GrapheneOS may be the best candidate for a trustworthy smartphone platform right now, and I hope for the best followthrough and success of that.
We're an entire industry of liars and poseurs.
It would be easy to make even a completely bad-actor company with years of stellar reputation.
Either as a sleeper for some future big attack, or one that only rarely and secretly takes action against very high value targets.
Two examples of people who have established some trust over the years: Linus Torvalds and RMS.
Joking scenario to illustrate...
Badguy: "This is it, Torvalds! Give us the Linux launch codes, or I shoot you!"
Torvalds: "Launch codes? I'm angry that you are wasting everyone's time, when clearly you don't know what you are doing, and are not bothering to get help to do it properly."
Badguy: "How about your friend! Give us the codes, or I shoot Stallman!"
Stallman: "Excuse me, but when you say Linux, I think you mean GNU/Linux, since Linux is a kernel, which is only one piece of the operating system, and used with--"
Badguy: "Argh! I can't take you nerds anymore!" shoots self in head
There was no principled exit from a project but rather from a company. GrapheneOS started in 2014 and was previously called CopperheadOS. We still use multiple of the 2015 era GitHub repositories.
A company which I co-founded in 2015 where I still own 50% of the voting shares was taken over and many illegal actions were taken in an attempt to take over my open source project and then spent years trying to destroy it when that failed. The company was then used as a weapon to wage a war against myself and GrapheneOS for years. A large of donations were stolen and repurposed for attacks on the project people made those donations to. Meanwhile, the company entirely depended on repeatedly forking GrapheneOS to sell it as a project. We stopped them from doing it through legal action and it's essentially over. It took a very long time to rebuild GrapheneOS and the attacks they started never stopped.
I continued working on the same project after the failed takeover attempt and it turned into a much bigger project where I'm no longer anywhere close to the most active developer. I mostly do organization tasks including giving developers tasks and system administration, not development. It's quite hard to do development when you're harassed throughout the day, every day, to an extreme level. It took away my ability to do the kind of creative work involved in development for the most part. I leave that up to others now. I don't even do much code review anymore but rather delegated that to others too. I don't know why people continue claiming otherwise when it's plainly not the case.
> I'm not sure how to do that, but it may include communicating who is involved (not just names, but why they should be trusted), and what safeguards there are against mistakes and compromised/rogue individuals.
We have to protect our team from relentless harassment including swatting attacks. Our moderators aren't allowed to use accounts tied to their real name since otherwise they'd be heavily targeted. The same applies to our community manager. We generally recommend developers avoid using their real name unless they're able to tolerate being tolerated. We avoid having people's names tied to things when we can. It was a mistake to do it in the beginning and can't be undone for myself but others can avoid being targeted. I don't think many people would be willing to work as a community manager or any other public-facing role in GrapheneOS if they had to use their real name. That's especially true if they're part of around half of the people who are women or many other groups who would be targeted specifically for their identity alone.
> I say this because GrapheneOS may be the best candidate for a trustworthy smartphone platform right now, and I hope for the best followthrough and success of that.
Continued success unfortunately enrages people who have been trying to harm us for years as can be seen throughout this thread. It's not getting better and I don't think many people want to be exposed to it.
Most people are cavalier about tech trust, because that's easy or they don't know any better, and often they really don't care.
But it seems the base for GrapheneOS is people who care, and a lot of them (not all) care about trustworthiness (not just annoyances).
Funnily enough that same social media person has some odd ideas about trust and PKIs.
Can you explain what you mean?
https://x.com/Avamander/status/2025719336552284161
The fact is that if you use the org TLD then you trust whoever runs it to issue certificates for your website and the same for your domain registrar. There's no point in pretending otherwise. It's very clearly how the system works. WebPKI does not truly add value over a TLSA record and DNSSEC beyond Certificate Transparency which is reactive and is NOT part of MTA-STS. MTA-STS also doesn't have mandatory encryption but rather opportunistic and can be stopped from using it. Gmail, the service which MTA-STS was created to be used with, has 1 day max-age for it.
Gmail has a lot of quite blatant security weaknesses and phishing weaknesses. People largely repeat the mantra of it being secure because Google account login security is decent including an option to make it harder to hijack accounts via customer support missing elsewhere.
Not really interested in a debate about it where someone repeats talking points often visible here and gets angry with us for not agreeing including getting angry because people like our replies.
DNSSEC is a *bad* PKI, with infallible roots of trust, terrible adoption rate and horrible transparency. If someone misbehaves, you will have no idea, there will be no recourse and absolutely nobody is enforcing any standards on how things should be ran.
Bringing DMARC and phishing into this topic is a desperate grasp at straws if I have ever seen one.
DNSSEC defenders should actually know what they're talking about first.
(I opted to donate via bank transfer instead, because that is at least addressed at the GrapheneOS Foundation, not one specific member.)
You shouldn't get info about GrapheneOS from Hacker News comments especially when multiple regulars here are part of the attacks on GrapheneOS. Hacker News permits people to freely engage in libel and harassment towards me on nearly every post about GrapheneOS.
And from a director themselves! strcat is one of the directors in case you didn't know (Daniel). Which makes his reply quite bizarre
They asked a reasonable question and you barely even responded to anything they asked. The community deserves a response to the question.
What with this new chapter, it might be better for someone else to handle PR and comms for the project
(Signed, passionate GrapheneOS user of a few years)
You use GrapheneOS which we provide to you free of any cost but yet you're being nasty towards us throughout this thread. Why do you think you deserve anything from us?
Why should we participate on this platform at all when we have name calling, bullying and links to harassment content directed towards us with nothing being done about it?
You seem to have a persecution complex. Ironically, baseless accusations of nastiness and harassment and weaponising language is also bullying. I'm out. Best of luck to the project, and to you personally.
We badly need alternative(s) like GrapheneOS, and I want to see it succeed. I hope as the project matures, the sense of professionalism and stability it projects will strengthen. For what it's worth, I personally feel the business partnership is a step toward that end, and am really happy to see some manufacturer diversity.
FWIW, https://ised-isde.canada.ca/cc/lgcy/fdrlCrpDtls.html?p=0&cor... lists three directors for the GrapheneOS Foundation: Khalykbek Yelshibekov, Daniel Micay, and Dmytro Mukhomor.
I've been a Signal/TextSecure user since day one and have convinced many dozens of people to switch to Signal but, man, they don't exactly make it easy to be a fan.