The GrapheneOS developers are giving me concerns about the future of GrapheneOS

The drama and accusations the GrapheneOS developers are spewing and engaging in are giving me a bad taste in the mouth and make me doubt the OS’s reliability am I the only one?

65 points · 73 comments · view on lemmy.world

73 Comments

upstroke4448@lemmy.dbzer0.com · 87 pts · 260d (10 replies)

Not as bad a taste as the French government is giving me.

If its do I trust GOS or a confirmed pro chat control governments side of the story, its an easy choice.

artyom@piefed.social · 10 pts · 260d (9 replies)

There are many more sides than those 2. GOS is screaming about a new "harrassment" campaign every week.

pdxfed@lemmy.world · 12 pts · 260d (2 replies)

Knowing nothing of the situations details, when you're a thorn in the side of the most powerful interests on the planet,it seems reasonable that a small group would face deliberate, concentrated pressure from business to legal and the state and any other mechanism. That's generally what power does, assuming the little guy isn't subsumed.

What is the evidence of foul play by GOS, or why would they not have a pretty extreme bias of support?

PiraHxCx@lemmy.ml · 8 pts · 260d
[ removed ]
artyom@piefed.social · 3 pts · 260d

from business to legal and the state and any other mechanism.

I'm not referring to any of those "mechanisms", I'm referring to basically the entirety of the privacy/security/sovereign communities. They disparage other Android "privacy" platforms and communities on a regular basis, then claim to be victims of "targeted attacks" from those communities. Louis Rossman and Techlore are also 2 people who have also been accused of "harassment" without evidence. Just for starters.

Corridor8031@lemmy.ml · 0 pts · 259d (3 replies)
[ removed ]
artyom@piefed.social · 0 pts · 259d (2 replies)

Who said anything about a forum?

Corridor8031@lemmy.ml · 1 pts · 259d (1 reply)
[ removed ]
artyom@piefed.social · 4 pts · 259d

Look at their social accounts. Half their posts are complaining about some sort of "harrassment". They claim their branding was being used to sell these devices without any evidence. They claim this is a "state-sponsored attack" without any evidence.

upstroke4448@lemmy.dbzer0.com · 0 pts · 259d (1 reply)

Their past dramas are irrelevant to this issue.

Giving into a straw man argument such as their other dramas somehow devalue what's going on now, only plays into the French propaganda campaign.

artyom@piefed.social · 1 pts · 259d

They're not irrelevant, they're both symptoms of the same problem. The Developer Who Cried Wolf.

Neptr@lemmy.blahaj.zone · 52 pts · 260d (8 replies)

While I do find GOS drama a bit annoying, they aren't wrong about the lacking security of many AOSP forks. iode and /e/OS have a history late patches for security vulnerabilities in both the OS (https://web.archive.org/web/20241231003546/https://divestos.org/pages/patch_history) and for the forked apps they bundle with it. Each Android monthly and Chromium patches usually contains dozens High Risk CVEs, so taking a month or 2 is unacceptable. Neither are good for privacy or security.

See a comparison between some Android ROMs here, especially noting the update speed section: https://eylenburg.github.io/android_comparison.htm

majster@lemmy.zip · 6 pts · 260d (6 replies)

I understand security implications but I'll be getting Fairphone 6 with /e/OS over Pixel with GrapheneOS. For me FOSS ranks higher than HW security features, and buying Google device goes against FOSS principles.

FG_3479@lemmy.world · 9 pts · 260d (1 reply)

Buying a used Pixel lets you use the hardware without funding Google.

pdxfed@lemmy.world · 8 pts · 260d

*Directly funding Google. You are certainly participating in a secondary market for their product you purchase used.

Corridor8031@lemmy.ml · 2 pts · 259d (3 replies)
[ removed ]
majster@lemmy.zip · 1 pts · 259d (2 replies)

No, there is no modern smartphone like that, yet AFAIK.

Corridor8031@lemmy.ml · 1 pts · 259d (1 reply)
[ removed ]
majster@lemmy.zip · 1 pts · 259d

Google itself. GrapheneOS bridgea the gap but still...

Scirocco@lemmy.world · 1 pts · 259d

Not being familiar with the controveries referenced in this thread....

All of this reminds me very much of OpenBSD and Theo de Radt (?) back in the 98-02 era.

OpenBSD is certainly not the most popular *nix today, but it's probably the most secure.

privacydingus@lemmy.ml · 50 pts · 260d (2 replies)

Two things can simultaneously be true, Daniel can be an individual who engages in very problematic behaviours and GrapheneOS can still be the most-secure and reliable OS out there.

Scirocco@lemmy.world · 5 pts · 259d (1 reply)

Can we get a tldr of the "problematic behaviours"?

As a casual who bought a pixel 9 specifically for Graphene, I not too embedded in the culture/dramas, and surely many others reading here are similarly unfamiliar

kilgore_trout@feddit.it · 4 pts · 259d

His «problematic behaviour» is simply callingäoutäthings for what they are, with no soft wording.

limer@lemmy.ml · 50 pts · 260d (15 replies)

I would prefer my privacy software to be developed by people like this, rather than people who are calm and flexible

paper_moon@lemmy.world · 31 pts · 260d (1 reply)

Its all fine until their approach of privacy or security differs with what's best for the project, then there's no reasoning with them to fix it because they're not calm and flexible. Then ya gotta fork it and get everyone to transition to the new fork, and get developers back onboard, etc.

A crazy, but pointed example of something like this could be: the dude could just claim grapheneos going forward will not have networking anymore because thats an attack vector, and at that point the project doesn't even suite anyone's needs to be used as a smartphone anymore. How are you gonna reason with someone like this that, while keeping networking in the project is an attack vector, its necessary to be able to use the project for it's intended use case? You probably aren't

Corridor8031@lemmy.ml · 4 pts · 259d
[ removed ]
PiraHxCx@lemmy.ml · 14 pts · 260d (12 replies)
[ removed ]
ganymede@lemmy.ml · 5 pts · 260d (5 replies)

admittedly i'm not up to date on all the drama, but i thought that graphene saw themselves as victims of alt attacks?

PiraHxCx@lemmy.ml · 15 pts · 260d (4 replies)
[ removed ]
Corridor8031@lemmy.ml · 2 pts · 259d (2 replies)
[ removed ]
PiraHxCx@lemmy.ml · 0 pts · 259d (1 reply)
[ removed ]
Corridor8031@lemmy.ml · 2 pts · 259d
[ removed ]
Supervisor194@lemmy.world · 1 pts · 260d

Strange, I put the same link in one of my comments and a mod removed it.

JamesBoeing737MAX@sopuli.xyz · 0 pts · 259d (5 replies)

Yes, the minority is harassing the majority. Hmm, very logical.

PiraHxCx@lemmy.ml · 1 pts · 259d (4 replies)
[ removed ]
deacon3484@infosec.exchange · 1 pts · 259d (3 replies)
[ removed ]
PiraHxCx@lemmy.ml · 1 pts · 259d (2 replies)
[ removed ]
deacon3484@infosec.exchange · 2 pts · 259d (1 reply)
[ removed ]
PiraHxCx@lemmy.ml · 1 pts · 259d
[ removed ]
majster@lemmy.zip · 42 pts · 260d (2 replies)

Its nutjobs like them that are pushing progress further. State security apparatus doesn't want to work by law. That can be observed worldwide.

French went after Telegram even though it doesn't market itself primarily for security. It was just that some public channels went against their strategic objectives and they felt the need to bruteforce their way.

So GrapheneOS is very right to be nervous and pack their bags before they come knocking at the door.

FG_3479@lemmy.world · 18 pts · 260d (1 reply)

They literally said that French police are being told to treat Pixel phones as suspicious, which if true, shows why they're concerned.

leftascenter@jlai.lu · 10 pts · 259d

Having a secure phone / secure messaging has been seen as suspicious by the police in france for several years now.

This has already been used against eco activists to detain them preemptively and a few times to increase charges towards terrorism / organized crime when possible.

Corridor8031@lemmy.ml · 40 pts · 259d (1 reply)
[ removed ]
freedickpics@lemmy.ml · 1 pts · 258d

Exactly. The lead dev can come across as frustrated or confrontational on his social media posts but really the amount of noobs criticising Graphene for nonsense reasons or repeatedly bringing up other 'secure' OSes to him that he's already thoroughly debunked again and again like e/OS would drive me insane

Catalyst_A@lemmy.ml · 39 pts · 260d (3 replies)

They're being threatened by the entire French government. Its not drama. This is a very real situation. 

leftascenter@jlai.lu · 8 pts · 259d (2 replies)

All secured OSes and messaging systems are threatened by European governments / EU institutions at the moment, and the French government has been doing so for a few years.

This is not a grapheneOS only issue and it is not new.

Jakeroxs@sh.itjust.works · 5 pts · 259d (1 reply)

I don't think it's in any way limited to the EU lol

leftascenter@jlai.lu · 3 pts · 259d

Being French, I am not knowledgeable enough beyond Europe 😁.

For context, Germany recently did a last minute blockage of a European move towards mass surveillance of messaging (called chat control), and a v2 is already being prepared for another attack on privacy at European level.

We are living in interesting times.

sheinar@feddit.uk · 35 pts · 260d (2 replies)

I've accepted for a while that the lead developer is extremely paranoid and could probably genuinely do with healthcare intervention. Like in much open source development I think it isn't helped by overwork and burnout, so I hope that at some point Graphene gets a better governance structure which spreads responsibility and which hopefully will limit the incessant drama that only harms the project. I don't see him being willing to give up his grip, but I can always hope.

I'll continue to use Graphene unless things go entirely off the rails though, as it is a great OS and I don't really think there are many great alternatives.

Corridor8031@lemmy.ml · 2 pts · 259d (1 reply)
[ removed ]
sheinar@feddit.uk · 2 pts · 259d

Thanks for pointing that out, looks like I'm a bit behind the times when it comes to the inner goings on at GOS!

RodgeGrabTheCat@sh.itjust.works · 32 pts · 260d

Such drama has been going on for years. I wouldn't read too much into it.

daniskarma@lemmy.dbzer0.com · 27 pts · 259d

I wouldn't trust a sane person to do a ultra private phone OS.

You need the paranoia, you need to see the shadows move to do it right.

CoyoteFacts@piefed.ca · 23 pts · 260d (4 replies)

It mainly makes me pine for linux phones. I think Graphene is the best we have at the moment in the mobile space, but that's far more of a testament to our lack of options than how valuable Graphene is. I have no doubts that we'll eventually kick Graphene to the curb when it stops being useful, so I'm not overly concerned with its future. Worst-case, I think many of us would be just fine on any other AOSP rom for a few extra years until linux phones can come save us all.

kkj@lemmy.dbzer0.com · 14 pts · 260d

pine for linux phones

I see what you did there.

sobchak@programming.dev · -2 pts · 260d (2 replies)

I could be wrong, but I think Linux would be horrible for the kind of security you'd want in a smartphone. At least that's what I read from the GrapheneOS folks...

gtr@programming.dev · 6 pts · 260d

Depends on what your threat model is. Sure a fully locked down mobile OS is more secure, but I also care about freedom and privacy. It's not all black and white.

CoyoteFacts@piefed.ca · 5 pts · 260d

As far as I'm aware this is true (same with a lot of desktop linux distros), but I'm more interested in freeing myself from Android at the moment. I'm sure we can get there eventually w/r/t security, but it takes time, and we'll never get there if we don't start moving.

warm@kbin.earth · 19 pts · 260d (2 replies)

GrapheneOS has always had a massive PR problem and crazy leadership unfortunately.

pdxfed@lemmy.world · 1 pts · 260d (1 reply)

Unlike say Google? Why is there an expectation that a group working completely against some of the most powerful actors on the planet, openly, against the grain of mainstream society often and having to bear that responsibility would be charming, at ease?

I cannot even begin to imagine the mental stress from constantly having to think ahead, in a global David and Goliath, in a maze designed to get you to give up. I probably have half the issues the GOS team does and I can't claim it's for doing anything on the scale of what they are.

warm@kbin.earth · 2 pts · 260d

You are mistaking what I am saying. I have nothing against the project as whole and the mission is fantastic.

They just have zero PR skills, don't know when to keep their mouth shut or how to communicate properly when they need to. A little bit of consultation would go a long way for them. Obviously I am not expecting Google levels of PR/marketing, but it's not great to see just ranting Discord/matrix messages. If it wasn't an issue, these posts wouldn't exist at all.

l3db3tt3r@piefed.social · 19 pts · 260d (2 replies)

Who benefits?

Who benefits from sowing a narrative around "drama", "accusation", and/or "paranoia". Seriously.

I think given the following circumspect; GrapheneOS's reaction, to move project pieces out of potential hostile environments/jurisdiction, is perfectly reasonable.

  1. France's Support for EU “Chat Control”, scanning proposals. France has been one of the governments most supportive of EU‑level proposals that would require scanning of communications and devices for illegal content.

  2. The general French framing and approach to cybercrime. As in other EU countries, French authorities are pushing for: Expanded powers to compel cooperation from service providers, and developers. Strong rhetoric against tools that are seen as systematically obstructing investigations.

exu@feditown.com · 5 pts · 260d

The main GrapheneOS dev creates beef with a bunch of other projects. It's not some shadowy organisation, it's him having stupid takes in GitHub issues and spreading false claims about other projects.

Supervisor194@lemmy.world · 4 pts · 260d
[ removed ]
FauxLiving@lemmy.world · 14 pts · 260d (1 reply)

Unless there’s drama in my updates I don’t particularly care too much about drama.

SomeAmateur@sh.itjust.works · 4 pts · 260d

The drama can be so minor too

"How can he run our department when his favorite color is INDIGO!? I can't BELIEVE that guy!"

erebion@news.erebion.eu · 11 pts · 259d (3 replies)

I also feel concerned about GrapheneOS. Here's why.

I got banned from the GrapheneOS Matrix chat simply for asking a question, it was worded similar to this:

"Hey there! GrapheneOS is cool. I noticed CalyxOS added support for eSIM, are you planning to add that as well?"

The post got deleted, I thought I had not sent it and posted it again. It was deleted again. I asked something along the lines of "Wait, where has my question regading eSIM support and doing the same as CalyxOS gone? Seems to have disappeared, lol".

THAT was also deleted.

Then I posted something along the lines of "Huh, my questions seem to be disappearing".

That was NOT deleted.

Then I asked something like "Anyway, are there plans to add eSIM support just like CalyxOS? :)".

That was ALSO deleted.

I got a private message from a mod saying I was banned.

That was alle the interaction I ever had with the GrapheneOS project. I might have started contributing, but I could not even ask a simple question. It seems that they don't like it if you mention any other custom ROM, I guess.

(This has been a while ago, so I don't remember my precise wording)

jaypatelani@lemmy.ml · 1 pts · 259d (1 reply)

Which channel on Matrix ? They seems to have many ones so mods in general if questions get asked in wrong channels ban which is weird I would expect them to reply that go to #relevant room and ask there

erebion@news.erebion.eu · 1 pts · 259d

I'm pretty sure it was a general GrapheneOS room, but as said it's been a while, so idk.

At least asking the question did not seem wrong.

kilgore_trout@feddit.it · -3 pts · 259d

It seems you were rightfully banned.

DieserTypMatthias@lemmy.ml · 10 pts · 260d

I don't care about the community, I just care about the experience of using it.

freeman@sh.itjust.works · 10 pts · 260d (14 replies)

In my opinion both the evident ego of of the project lead as well as his naivety (tethering the project to Google) are huge red flags despite any assumed technical superiority.

FG_3479@lemmy.world · 10 pts · 260d (2 replies)

They chose Google because they are the only major OEM to allow you to relock the bootloader after installing a custom ROM. Samsung, Motarola, Huawei, Xiaomi etc all don't.

communism@lemmy.ml · 3 pts · 259d

In addition to this, they are working with an OEM to produce their own Graphene phones. It sounds like they've made significant progress on that front so I'm hopeful.

timbuck2themoon@sh.itjust.works · 1 pts · 259d

Pretty sure calyx relocks the bootloader on moto phones.

TheOneCurly@feddit.online · 7 pts · 260d (9 replies)

They're literally working with a manufacturer to make non-google phones. Tethered to google is a wild mischaracterization.

freeman@sh.itjust.works · 7 pts · 260d (8 replies)

No it's not. This is a recent development that has not yet actually come to fruition. It may exist in 2026.

Before that GrapheneOS dismissed any idea of targeting other phones than the ones build by one of the most anti-privacy companies on earth, that seeks to consolidate control of Android.

NewOldGuard@lemmy.ml · 6 pts · 260d (1 reply)

This isn’t true, they’ve supported other devices in the past. They’ve been Pixel-focused for the security features that other manufacturers haven’t offered

freeman@sh.itjust.works · 4 pts · 260d

Yes, before Google made phone on it's own they supported some Nexus devices (google-partnered) and the Samsung Galaxy S4.

Corridor8031@lemmy.ml · 2 pts · 259d (5 replies)
[ removed ]
freeman@sh.itjust.works · 1 pts · 259d (4 replies)

I don't need a phone, GrapheneOS needs one now that Google is trying to force them out. I wonder if their new phone will actually meet all the requirements, if it comes out.

As for complaining, GrapheneOS is the one bitching about other Android versions existing since forever. Now, they 've started making unsubstantiated claims of them attacking them somehow.

Corridor8031@lemmy.ml · 2 pts · 259d (3 replies)
[ removed ]
freeman@sh.itjust.works · 3 pts · 259d (2 replies)

No GrapheneOS is not just calling them out on lack of security.

It's apparently from their discord, so it took me a while to find it again.

It's not about the personality of it's directors, it's about it's effect on the (alternative) Android ecosystem as a whole, which is not just about security but also privacy and user control.

Even with regards to security, their choice of limiting devices apparently makes their users targets for extra scrutiny and harassment. That does have actual implications for people whose threat model includes authorities unless they already are guaranteed to be targets.

Corridor8031@lemmy.ml · 2 pts · 259d
[ removed ]
Corridor8031@lemmy.ml · 1 pts · 259d
[ removed ]
exu@feditown.com · 8 pts · 260d (2 replies)

You're not the only one. It's one of my biggest reasons for staying away from it

12plus1plus12@midwest.social · 3 pts · 260d (1 reply)

What do you use instead?

exu@feditown.com · 0 pts · 260d

LineageOS with microg

Truscape@lemmy.blahaj.zone · 6 pts · 260d (2 replies)

The source code's just as transparent, and the fundamental concepts and implementations aren't going to vanish at all. If we get a future CarbonOS, so be it, but I doubt that will be in any near future scenario.

Auli@lemmy.ca · -3 pts · 260d (1 reply)

Why is it transparent? Cause its open source. Yes there has never been anything a bug or backdoor in open source code before ever.

artyom@piefed.social · 5 pts · 260d

Bing transparent is not the same thing as being secure. The difference is that closed source code can be audited by no one except its' developers, and open source code can be audited by anyone.

ganymede@lemmy.ml · 4 pts · 260d

some of it is kind of inevitable when you see how far ahead from everyone else they are technically and when people shitting on their work just aren't at their (technical) level it seems to be very draining. and eventually lead to dramas.

VampirePenguin@lemmy.world · 4 pts · 259d

GOS is a great project. This is a FUD campaign.

ABetterTomorrow@sh.itjust.works · 1 pts · 260d

Too be fair (not French but aware of their culture and government) the French are pretty smart, for people and don’t fuck around with serious issues. I bet you if they got access, it wouldn’t be long till issue a long warning before a ban if it were to cause harm to others.

Fanfare2217@lemmy.world · 1 pts · 260d
[ removed ]
Libb@piefed.social · -2 pts · 260d

The main reason why I decided not to use it, despite it being an obvious choice. But I'm also that kind of old dude that is not very receptive to drama... this may explain ;)

stupud@lemmy.zip · -6 pts · 259d
[ removed ]