Read the whole thread
However, we don’t have a “hardened security” approach, we aren’t developing a phone for pedo(censored) so they can evade justice.
The full translation of the clip of Gaël Duval provided by GrapheneOS:
There’s the attack surface, on that front we’re not security specialists here, so I couldn’t answer you precisely, but from the discussions I’ve had, it seems that everything we do reduces attack surface.
However, we don’t have a “hardened security” approach, we aren’t developing a phone for pedo(censored) so they can evade justice. So there aren’t difficult things to check if the memory is corrupted, really hardened security stuff that could clearly be useful for executives, in the secret service, or whatever.
That’s not our goal, our goal is to start from an observation: today our personal data is constantly being plundered and that wouldn’t be legal in real life with the mail or the telephone, we want to change that. So we are making you a product that changes that by default for anyone.
As a french speaker, I can attest that the translation is fairly accurate.
While I don’t agree with the characterisation Gaël Duval makes here, I believe the statement from GrapheneOS here:
Duval and his organizations have consistently taken a stance against protecting users from exploits. In this video, he once again claims protecting against exploits is for only useful pedophiles and spies.
Is a bit disingenuous. It sounds like they do make some efforts to secure their device, but it’s not their main focus. Theirs is to improve privacy first and foremost.
I would take anything GrapheneOS devs says with a grain of salt, as we all know that they have quite an adversarial relationship with… well… everyone. But especially other OS makers.
It sounds like they do make some efforts to secure their device, but it’s not their main focus. Theirs is to improve privacy first and foremost.
I don’t have any issue with that: different OSes have different priorities and that’s okay. However, I feel like he’s basically saying that users of hardened secure devices are pedos, and I have a very big issue with that. I don’t know if maybe in French it doesn’t sound that way, but the English translation does for me.
That’s how it sounds. So, I’m a pedophile because I run GrapheneOS on my phone? I guess I better tell my wife, and my kids.
Pedophiles use their work emails and gmail. Making a secure phone OS won’t make a difference.
I think it’s fair they support way more phones than GrapheneOS, even if the security is way worse. But it’s a whole other thing to call people who want secure phones pedophiles.
I am skeptical how worthwile it is to use /e/os over OEM Android at this point
You keep access to non-verified apps no matter what Google wants since it uses microG.
It’s openness vs security.
“anyone who wants privacy from their government is a pedophile” is a hell of a stance…
Honestly by now it’s becoming reasonable to assume “projection” as a baseline, to then change based on evidence, when someone has a take like this guy’s.
I don’t mean the political tactic, just the garden-variety kind of projection. “Probably ~everyone thinks the way I do, and boy, we better not give everyone the tools to act on that…”
Deeply wrong about how most folks think, because of how they themselves do, and believing they’re therefore helping. Likewise a self-admission, because they don’t realize they’re admitting anything.
Maybe not the case with this guy, I’m not gonna dive in.
But I do sincerely believe that’s a somewhat charitable take toward anyone making a claim like this today. Charitable in the sense of acknowledging a misunderstanding and desire to help.
The less charitable one being - just obviously complicit. Fuck this noise.
some people in this thread still dont get it, so:
you cant expect privacy while also having poor security practices. ideally you’d have both and most of these privacy projects are not much more than just a lineage fork with a dns blocker
apparently in duval’s mind, you can always trust even a fascist government to never try to exploit your phone and to give you privacy. or something idk
Anyone telling you the list isn’t graphene -> ios -> good custom android -> aosp-> google stock -> samsung stock is lying to you.
How is iOS - a proprietary OS owned by a big tech company - second in your list?
It can be made very good from a security and privacy perspective.
If you know you know I guess.
There’s good reason to suspect that it’s very terrible from its privacy and security perspective.
I have a huge problem with GrapheneOS: they rely too much on Google hardware. That is why I never used Graphene and probably never will.
Just wondering, do you have a problem in the sense that you don’t want to support Google or more that you’re worried the actual hardware is not safe or trustworthy?
Google is the exact opposite of privacy and security.
I find it very dishonest that GrapheneOS was advertising itself as the secure option while tying itself so closely to Google.
The Pixel phones were the only devices with secure enough hardware to make GrapheneOS viable, that’s why they developed it for them.
It wasn’t because of some deal with google or anything like that.
Hardware security guarantees are irrelevant for most people, including myself. A very small segment of the popularion needs them.
What matters infinitely more is who has access to your data. And Google is one of the worst offenders.
I don’t really see the issue. So you don’t really care about robust and trustworthy hardware. That I get to some extent considering you’re more worried about your data itself. But if you’re flashing your device with GOS, there is no data being shared to Google unless you specifically want to use Google Play Services or the Play Store. Both of which don’t come pre-installed
Edit: I added the ifRobust and trustworthy hardware does not matter if the apps you need for daily life (like banking or public transportation) are so integrated with Google’s ecosystem that they leak everything.
Breaking Google’s hold over Android is the most important security topic of all time. Everything else is secondary. GrapheneOS is not real security.
But how does this tie back to your original statement about GOS security and tying itself with Google? The issues you’re raising aren’t even a GOS specific one. I also find it strange to not call it secure because services themselves are reliant on Google’s services. That is not an issue any OS can solve. I say this as someone who does not rely on any Google services on my phone. I also believe you might be conflating security with privacy.
Buying a phone from Google (HTC really) does not give Google access to your data.
There are no Google services installed by Graphene, you have the option of running Google services if you choose, but even if you choose to do so they are kept in a sandbox and not given privileged information on the system.
There are no Google services installed by Graphene, you have the option of running Google services if you choose, but even if you choose to do so they are kept in a sandbox and not given privileged information on the system.
Using Google hardware results in financial gain for Google, which is one of the worst companies out there for privacy and security. I do not like that GrapheneOS is working to propagate Google’s monopoly.
You’re moving the goalposts, you said:
What matters infinitely more is who has access to your data. And Google is one of the worst offenders.
That’s completely different than who benefits financially from your phone purchase.
Kind of shameful of /e/ to blatantly disregard user privacy like that. Is Graphene our last stand against Orwellian surveillance?







