Fine by me. My example illustrates their incompetence if they are willing to let a user with an OS that hasn't received any updates in half a decade, then clearly, they don't give a single crap about security.
Uh, no. Shaming a "take" is just tone policing. Owners should own the hardware along with the software both.
Its only since the smartphone era (2008) with locked down shit devices has this view changed. And people challenging this are somehow defective, tone policed, shamed, or likewise.
GrapheneOS users are treated as 'rooted phones', at the exact same time tools that would attack and prevent corporate surveillance (xprivacy, etc) are withheld cause they would involve root.
You shared your opinion, someone else shared there’s that just so happened to be “I disagree with you” and suddenly that’s some type of censorship? Nobody is shaming you, either.
Leave the abusive relationship with those entities. Don’t lay this at the feet of the GrapheneOS Project.
If you read their FAQ, you’ll see how limited the OS actually is in retaining your privacy if you still insist on using these providers that don’t respect you.
Said another way: stop trying to solve human problems with technical means.
and definitely stop trying to get others to do it for you for free.
It is a common userspace decision to lock things to userspace. It’s good hygiene.
If you want less-secure software, use AOSP or one of its many forks.
You’re not defective: you just have different needs and threat model,
and you’re harassing and degrading the public image of a project that’s opinionated in a very welcome way by folks in the security community - especially those who value stability and usability.
"It is a common userspace decision to lock things to userspace"
Yes, running in userspace for the majority of tasks is good hygiene.
Preventing the user from ever escalating beyond that layer on their own devices, however, is restricting their freedom to control their device. When that happens with tractors, cars or other gadgets that's considered anti-user. The same attitude should extend to phones.
As several others have already said here, GrapheneOS is not necessarily rooted. So that's a lie.
Also, I've seen such audits internally, and they don't care about security at all. They care about the theatrics of security waaaaay more.
For example, I was at Santander in 2024, during its huge data breach. Here is the list of actions which are supposed to prevent the same kind of attacks again in the future:
-
Yeah, it's an empty list.
But of course, they made our life more difficult. In the end, I literally had more permission than before, because they were even sloppier than before. But of course, I had to change my password more frequently, and I had to type it about 5x more.
Audits are primarily about liability and safe harbors in lawsuits. Companies get audits on record so that if something happens they have someone to throw under the bus and pass damages off onto.
With the way today's economy works, they probably wouldn't even care if they lost 1/4 of their customers in just one year. Maybe their share price would jump!
I don't think they care at all about the size of graphene os market share
if its jeopardize entire userbase then its not worth it