Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

"Safe way to make sure I will stop being your customer - also YES!"

I don't think they care at all about the size of graphene os market share

if its jeopardize entire userbase then its not worth it



Fine by me. My example illustrates their incompetence if they are willing to let a user with an OS that hasn't received any updates in half a decade, then clearly, they don't give a single crap about security.


Noo, it’s the other way around lmao.

A financial security audit is one of the most thorough security audits you can ask for in software.

GrapheneOS gets blocked because it doesn’t follow the secure system requirements (root).


I suggest you read up the graphene documentation.


What requirements does it not follow?

>(root)

GrapheneOS is not rooted.


Yep, GrapheneOS is anti-user-freedom.

They do their damndest to prevent owners from having full control of their property, over claims of 'insecurity'.

And complaints of this nature get inane drivel responses of "lol just fork Graphene"


> GrapheneOS is anti-user-freedom.

This is a really, really poor-quality take.

> complaints of this nature get inane drivel responses of "lol just fork Graphene"

It’s a fork of AOSP, which you can just…use.


Uh, no. Shaming a "take" is just tone policing. Owners should own the hardware along with the software both.

Its only since the smartphone era (2008) with locked down shit devices has this view changed. And people challenging this are somehow defective, tone policed, shamed, or likewise.

GrapheneOS users are treated as 'rooted phones', at the exact same time tools that would attack and prevent corporate surveillance (xprivacy, etc) are withheld cause they would involve root.

Even this thread is full of a lot of anti-owner hand wavey shit that amounts to 'we don't trust our users, and fork you'. https://discuss.grapheneos.org/d/18953-why-the-stigma-agains...


> Shaming a “take” is just tone policing

No, that’s called sharing your opinion.

You shared your opinion, someone else shared there’s that just so happened to be “I disagree with you” and suddenly that’s some type of censorship? Nobody is shaming you, either.


> prevent corporate surveillance

Leave the abusive relationship with those entities. Don’t lay this at the feet of the GrapheneOS Project.

If you read their FAQ, you’ll see how limited the OS actually is in retaining your privacy if you still insist on using these providers that don’t respect you.

Said another way: stop trying to solve human problems with technical means.

and definitely stop trying to get others to do it for you for free.

Or, continue: I’m not a cop.


Nobody’s shaming you, reddit refugee.

It is a common userspace decision to lock things to userspace. It’s good hygiene.

If you want less-secure software, use AOSP or one of its many forks.

You’re not defective: you just have different needs and threat model,

and you’re harassing and degrading the public image of a project that’s opinionated in a very welcome way by folks in the security community - especially those who value stability and usability.


"It is a common userspace decision to lock things to userspace"

Yes, running in userspace for the majority of tasks is good hygiene.

Preventing the user from ever escalating beyond that layer on their own devices, however, is restricting their freedom to control their device. When that happens with tractors, cars or other gadgets that's considered anti-user. The same attitude should extend to phones.


You can wipe the device and reinstall whatever at any time.

You have complete control of the device.

You choose to lock certain things when using GrapheneOS. That’s their security model.

If you want to argue that, go study it and argue that.

If your threat model is different, if your desired security model is different, then: it’s not for you, use one of many other options.

Like all software projects, it doesn’t necessarily exist for you - or anyone specifically.

It’s not harming you for it to exist.


[flagged]


Hey, stop wrecking my favorite community with non-debates, it’s done better here.

https://news.ycombinator.com/newsguidelines.html

Thanks.


As several others have already said here, GrapheneOS is not necessarily rooted. So that's a lie.

Also, I've seen such audits internally, and they don't care about security at all. They care about the theatrics of security waaaaay more.

For example, I was at Santander in 2024, during its huge data breach. Here is the list of actions which are supposed to prevent the same kind of attacks again in the future:

-

Yeah, it's an empty list.

But of course, they made our life more difficult. In the end, I literally had more permission than before, because they were even sloppier than before. But of course, I had to change my password more frequently, and I had to type it about 5x more.


Audits are primarily about liability and safe harbors in lawsuits. Companies get audits on record so that if something happens they have someone to throw under the bus and pass damages off onto.


With the way today's economy works, they probably wouldn't even care if they lost 1/4 of their customers in just one year. Maybe their share price would jump!


I'm sure their automatic bans have happened to more people than the number of grapheneOS users




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: