logoalt Hacker News

g-b-ryesterday at 11:46 PM1 replyview on HN

It's not about a middle ground, their idea of security is wrong.

They largely ignore any threat that could come from US agencies, and are very presumptuous about some of their convictions (e.g. that open source is irrelevant for security).

There is a balance to be made, given that there often isn't any ideal option, but they often get that balance assessment wrong, in my opinion.

I appreciate exposing the security weaknesses of other products, but they end up adding threats that they don't have with some of their drastic views.


Replies

ysnptoday at 9:12 AM

They (GrapheneOS development team) live and breathe the principled stance you seem to be describing.

They are staunchly against authoritarianism and mechanisms that are vulnerable to government coercion which is why they promote Android IAR and criticise Play App Signing for being mandatory.

I have understood their position to be that software is not automatically secure because it is open source, but being open source is one of the best ways to ensure to maximise attack resiliency (they believe in kerchoff's principle, shallow bugs, collaboration as a pragmatic help to get there not taken for granted or a guarantee). You'd probably be interested to know the founder once proclaimed publicly that they would never work on proprietary software.

Don't pay too much heed to how community members frame things, they are human and get things wrong in service of trying to reduce conversation to specific facts and technical assurances instead of discussing the bigger picture.