5 ms·
Fine by me. My example illustrates their incompetence if they are willing to let a user with an OS that hasn't received any updates in half a decade, then clear
by axegon_ 21d ago
Fine by me. My example illustrates their incompetence if they are willing to let a user with an OS that hasn't received any updates in half a decade, then clearly, they don't give a single crap about security.
- tonyhart7 21d agoNoo, it’s the other way around lmao. A financial security audit is one of the most thorough security audits you can ask for in software. GrapheneOS gets blocked because it doesn’t follow the secure system requirements (root).
- inexcf 21d agoWhat requirements does it not follow? >(root) GrapheneOS is not rooted.
- nekusar 20d agoYep, GrapheneOS is anti-user-freedom. They do their damndest to prevent owners from having full control of their property, over claims of 'insecurity'. And complaints of this nature get inane drivel responses of "lol just fork Graphene"
- DANmode 20d ago> GrapheneOS is anti-user-freedom. This is a really, really poor-quality take. > complaints of this nature get inane drivel responses of "lol just fork Graphene" It’s a fork of AOSP, which you can just…use.
- nekusar 20d agoUh, no. Shaming a "take" is just tone policing. Owners should own the hardware along with the software both. Its only since the smartphone era (2008) with locked down shit devices has this view changed. And people challenging this are somehow defective, tone policed, shamed, or likewise. GrapheneOS users are treated as 'rooted phones', at the exact same time tools that would attack and prevent corporate surveillance (xprivacy, etc) are withheld cause they would involve root. Even this thread is full of a lot of anti-owner hand wavey shit that amounts to 'we don't trust our users, and fork you'. https://discuss.grapheneos.org/d/18953-why-the-stigma-against-rooting/15 https://discuss.grapheneos.org/d/18953-why-the-stigma-agains...
- DANmode 20d agoNobody’s shaming you, reddit refugee. It is a common userspace decision to lock things to userspace. It’s good hygiene. If you want less-secure software, use AOSP or one of its many forks. You’re not defective: you just have different needs and threat model, and you’re harassing and degrading the public image of a project that’s opinionated in a very welcome way by folks in the security community - especially those who value stability and usability.
- dingaling 20d ago"It is a common userspace decision to lock things to userspace" Yes, running in userspace for the majority of tasks is good hygiene. Preventing the user from ever escalating beyond that layer on their own devices, however, is restricting their freedom to control their device. When that happens with tractors, cars or other gadgets that's considered anti-user. The same attitude should extend to phones.
- DANmode 20d agoYou can wipe the device and reinstall whatever at any time. You have complete control of the device. You choose to lock certain things when using GrapheneOS. That’s their security model. If you want to argue that, go study it and argue that. If your threat model is different, if your desired security model is different, then: it’s not for you, use one of many other options. Like all software projects, it doesn’t necessarily exist for you - or anyone specifically. It’s not harming you for it to exist.
- axegon_ 21d agoI suggest you read up the graphene documentation.
- ruszki 21d agoAs several others have already said here, GrapheneOS is not necessarily rooted. So that's a lie. Also, I've seen such audits internally, and they don't care about security at all. They care about the theatrics of security waaaaay more. For example, I was at Santander in 2024, during its huge data breach. Here is the list of actions which are supposed to prevent the same kind of attacks again in the future: - Yeah, it's an empty list. But of course, they made our life more difficult. In the end, I literally had more permission than before, because they were even sloppier than before. But of course, I had to change my password more frequently, and I had to type it about 5x more.
- fluidcruft 20d agoAudits are primarily about liability and safe harbors in lawsuits. Companies get audits on record so that if something happens they have someone to throw under the bus and pass damages off onto.