It's not a matter of being paranoid and the GrapheneOS project members are not paranoid. It is simply a matter of Murena/eOS/Gael Duval making claims about their products that are misleading, false, and harmful to users.
Skorp
CalyxOS is not hardened in any way and is in some ways less secure than stock AOSP. They are also on a hiatus and have discontinued updates: https://discuss.grapheneos.org/d/24791-departure-of-calyx-calyxos-leadership-and-discontinuation-of-calyxos-updates
He lied about stopping use of GrapheneOS. He can be seen in videos long after still using GrapheneOS on his Pixel. Also, the reasons he stated for not using/trusting it were nonsense. There was not, and is not, a technical way to target a user with malicious OTA updates.
He was also one of 3 owners of a for-profit telecom that included Nick Merrill (Founder of Calyx). https://sec.gov/Archives/edgar/data/2009536/000200953624000001/xslFormDX01/primary_doc.xml is the SEC filing for shares issued in February 2024 .
They have officially stated that they can support the 10 now, but it will have to wait until after the port to QPR1. https://xcancel.com/GrapheneOS/status/1960792610114511190#m
That device didn't meet the requirements for GrapheneOS even when it was supported by the OEM. As of now, it is an EOL device and is highly insecure. https://grapheneos.org/faq#future-devices
LineageOS also significantly regresses security compared to barebones AOSP.
- Userdebug builds
- No locked bootloader or verified boot
- Incomplete backports of patches
The blog post is false. You can verify it by looking at the repos. This person was being childish in their attempts to get GrapheneOS and other projects to accept the feature request. They were told "No". Now whether they or anyone else feels the reason behind that decision is valid or not is separate from the fact that this person then went out of their way to make noise and trouble for the project (by opening the repo, pinging the developers, etc.). We'll call it "entitlement". When they were blocked, instead of moving on and accepting that the feature wouldn't be implemented, they wrote up this blog post and spread it around the internet so that it would stir up drama, and direct more attacks towards the project. I'd call that a vendetta.
Other companies and projects have a tendency to take criticisms coming from the project as directed attacks. I take less issue with the project making objective criticisms. To respond to that criticism by pointing a finger back calling the founder "delusional", "insane", etc., doesn't seem appropriate. Even if it were true (which no one has evidence to claim), it would still be completely unacceptable to talk about someone like that. Your comments about them or the community "needing therapy" perpetuates that sentiment.
Intensity is one thing. That is arguably true and the OS may not be the leading AOSP fork in terms of security and privacy (see: Capabilities against forensic extraction) if it weren't the case. It is the projects unwillingness to compromise in this area that makes it stand out in that regard.
Other projects and companies make claims about and market their projects/devices/services. Not that I'm arguing that GrapheneOS should be the only ones able to comment on or evaluate those claims, but they are certainly some of the most qualified to. We shouldn't give them a pass because they claim to protect us against "big tech". Those things should be critically evaluated because it matters so much.
GrapheneOS evaluates other's primarily based on their technical merits and against their claims they make. How many of those who oppose do the same? Or do they just call them divisive, crazy, and incendiary?
Thank you for the civil discussion. I hope it can continue.
Hi, I'm a community member which can easily be verified, not Micay. Feel free to visit the chatrooms and look for my name.
This blog post is verifiably false. All it takes is looking at the actual GitHub repos to see it. This person wasn't "banned from GrapheneOS". They were blocked on the repo because they were repeatedly pinging the developers and acting in an immature way because they didn't get the feature request fulfilled.
It was posted across as many socials as they could to stir up drama and harassment towards the project. It's completely transparent.
Here is the information about Spender and GRsecurity copied from my other post:
It was after GRsecurity became private that they had an issue with people making upstream security contributions, particularly upstreaming anything from the GRsecurity patches. They had disagreements about that, and then moved past it and are on good terms now.
It's absolutely ridiculous to claim that Micay has anything to do with them making things private.
https://grsecurity.net/announce
https://news.ycombinator.com/item?id=10126319
It was Wind River, owned by Intel, which was the main offender for upstreaming the patches. Micay was the one who introduced GRsecurity in Arch Linux and did all the integration it had for PaX exceptions and the start of RBAC support (systemd was an issue at the time). It was afterwards once it became private that it was awkward because they didn't want people upstreaming or maintaining ports of their work but at the time Micay was maintaining GRsecurity in Arch Linux and GrapheneOS (then called CopperheadOS) was using the PaX subset for kernel hardening, so there were existing uses of it to try to keep going in some way.
So, you're not taking issue with the obviously fabricated things in this blog post, which this person shared across over a dozen Lemmy communities, Reddit, LinkedIn, Mastadon, etc., but you are taking offense that community members might come to where this is being posted to address/correct/refute it?
You seem to feel comfortable lobbing statements that GrapheneOS community members or even just people that might disagree with lies and targeted drama being posted aren't well adjusted, but not the person who posted the lies across the fediverse?
This all seems backwards.
This is a blatant and complete fabrication that you are spreading. The project is on good terms with Spender and you have no evidence to support what you are claiming.
It was after GRsecurity became private that they had an issue with people making upstream security contributions, particularly upstreaming anything from the GRsecurity patches. They had disagreements about that, and then moved past it and are on good terms now.
It's absolutely ridiculous to claim that Micay has anything to do with them making things private.
https://grsecurity.net/announce https://news.ycombinator.com/item?id=10126319
It was Wind River, owned by Intel, which was the main offender for upstreaming the patches. Micay was the one who introduced GRsecurity in Arch Linux and did all the integration it had for PaX exceptions and the start of RBAC support (systemd was an issue at the time). It was afterwards once it became private that it was awkward because they didn't want people upstreaming or maintaining ports of their work but at the time Micay was maintaining GRsecurity in Arch Linux and GrapheneOS (then called CopperheadOS) was using the PaX subset for kernel hardening, so there were existing uses of it to try to keep going in some way.
You understand that in those chats, Micay had been the victim of ongoing harassment, perpetuated by Rossman and Calyx leadership, which culminated in doxxing and then a SWAT attack which is a threat on their life.
They didn't lie about stepping down. They took a back seat to development work and the public eye because of these experiences. It was an enormous toll on their mental and physical health.
Now does that excuse Rossman for mislabeling na individual with mental diagnoses? Does that excuse them and other people for dismissing what they say based on these false labels?