GNU social JP
  • FAQ
  • Login
GNU social JPは日本のGNU socialサーバーです。
Usage/ToS/admin/test/Pleroma FE
  • Public

    • Public
    • Network
    • Groups
    • Featured
    • Popular
    • People

Notices by GrapheneOS (grapheneos@grapheneos.social), page 2

  1. Embed this notice
    GrapheneOS (grapheneos@grapheneos.social)'s status on Monday, 11-May-2026 01:35:43 JST GrapheneOS GrapheneOS
    in reply to

    Play Integrity API is highly insecure and it isn't particularly hard to temporarily bypass it. There are frameworks for spoofing the software checks and leaked keys for bypassing hardware attestation can be purchased. However, bypasses are getting harder and are becoming increasingly short lived.

    In conversation about 3 months ago from grapheneos.social permalink
  2. Embed this notice
    GrapheneOS (grapheneos@grapheneos.social)'s status on Monday, 11-May-2026 01:35:42 JST GrapheneOS GrapheneOS
    in reply to

    It doesn't provide a useful security feature, but it does lock out competition very well. Services requiring Apple App Attest or Google Play Integrity are primarily helping to lock in Apple and Google having a duopoly for mobile devices. Play Integrity is more relevant due to AOSP being open source.

    In conversation about 3 months ago from grapheneos.social permalink
  3. Embed this notice
    GrapheneOS (grapheneos@grapheneos.social)'s status on Monday, 11-May-2026 01:35:41 JST GrapheneOS GrapheneOS
    in reply to

    Instead of governments stopping Apple and Google from engaging in egregiously anti-competitive behavior, they're directly participating in locking out competition via their own services. Requiring people to have an Apple device or Google-certified Android device is anti-competition, not security.

    In conversation about 3 months ago from grapheneos.social permalink
  4. Embed this notice
    GrapheneOS (grapheneos@grapheneos.social)'s status on Monday, 11-May-2026 01:35:41 JST GrapheneOS GrapheneOS
    in reply to

    Governments are increasingly mandating using Apple's App Attest and Google's Play Integrity for not only their own services but also commercial services. The EU is leading the charge of making these requirements for digital payments, ID, age verification, etc. Many EU government apps require them.

    In conversation about 3 months ago from grapheneos.social permalink
  5. Embed this notice
    GrapheneOS (grapheneos@grapheneos.social)'s status on Friday, 08-May-2026 09:37:46 JST GrapheneOS GrapheneOS

    GrapheneOS isn't vulnerable to the 3 recently disclosed Linux kernel vulnerabilities named Copy Fail, Copy Fail 2 and Dirty Frag. Current Android Open Source Project SELinux policies block exploiting all 3 bugs. Standard AOSP GKI kernel configuration also has 2/3 of the vulnerable features disabled.

    In conversation about 3 months ago from grapheneos.social permalink
  6. Embed this notice
    GrapheneOS (grapheneos@grapheneos.social)'s status on Friday, 01-May-2026 04:03:05 JST GrapheneOS GrapheneOS

    @becomethewaifu That's why we only mentioned it being the chosen attack vector for exploiting it. It's a common attack surface and attack vector for exploits which is why it was removed from Android. It's the SELinux policy disallowing access to AF_ALG outside of dumpstate which blocks exploiting it along with a standard GKI not having the userspace crypto API enabled. AOSP, stock Pixel OS and GrapheneOS don't have the relevant API enabled at all though, which we didn't realize until today.

    In conversation about 3 months ago from grapheneos.social permalink
  7. Embed this notice
    GrapheneOS (grapheneos@grapheneos.social)'s status on Friday, 01-May-2026 04:00:48 JST GrapheneOS GrapheneOS

    GrapheneOS is immune to the Copy Fail vulnerability due to the deep integration of SELinux in the Android Open Source Project (AOSP). AOSP only permits using specific types of sockets throughout the OS. It only permits the dumpstate process used to create bug report zips to access AF_ALG sockets.

    In conversation about 3 months ago from grapheneos.social permalink
  8. Embed this notice
    GrapheneOS (grapheneos@grapheneos.social)'s status on Saturday, 11-Apr-2026 23:53:09 JST GrapheneOS GrapheneOS
    in reply to

    @aral @Framasoft @fla @aral @Framasoft @fla We've already posted numerous replies addressing why the statements they're making about GrapheneOS are extremely inaccurate. Mots of it hasn't been acknowledged. The only part which was acknowledged is the existence of Contact Scopes. Nothing has been done about the egregiously false claims of GrapheneOS not being a privacy project and not working much on privacy. It's completely backwards and in fact applies to what they're trying to promote instead.

    In conversation about 4 months ago from grapheneos.social permalink
  9. Embed this notice
    GrapheneOS (grapheneos@grapheneos.social)'s status on Saturday, 11-Apr-2026 23:40:09 JST GrapheneOS GrapheneOS
    in reply to
    • Aral Balkan
    • Framasoft
    • Fla

    @aral @Framasoft @fla He made one small correction. However, the article is still claiming GrapheneOS isn't a privacy project and that we don't work much on privacy which is thoroughly wrong. GrapheneOS has a bunch of major privacy enhancements both through adding important privacy features and fixing Android privacy vulnerabilities including VPN leaks. We have multiple privacy features and additional VPN leak fixes in progress. We posted a thread responding to that at https://grapheneos.social/@GrapheneOS/116382616003990894.

    In conversation about 4 months ago from grapheneos.social permalink

    Attachments

    1. No result found on File_thumbnail lookup.
      GrapheneOS (@GrapheneOS@grapheneos.social)
      from GrapheneOS
      @fla@mastodon.social @projetslibres_podcast@piaille.fr @Framasoft@framapiaf.org Contact Scopes is one of the core features of GrapheneOS and is shown in any prompt for contacts access. Storage Scopes is a similar feature for the media and storage permissions. Similar features for Camera, Microphone and Location are being developed by us. Android has a standard Mock Location feature but we want to replace that with a per-app Location Scopes implementation. The podcast and article still wrongly claim GrapheneOS isn't a privacy project.
  10. Embed this notice
    GrapheneOS (grapheneos@grapheneos.social)'s status on Saturday, 11-Apr-2026 23:40:08 JST GrapheneOS GrapheneOS
    in reply to
    • Aral Balkan
    • Framasoft
    • Fla

    @aral @Framasoft @fla There's a comparison between AOSP-based operating systems at https://eylenburg.github.io/android_comparison.htm which has comparisons of privacy features and default connections. It's far from complete and only covers default connections which come from AOSP. /e/ adds multiple additional connections to Google not present in AOSP by default along with other problematic connections. They've made decisions such as adding a random unique ID to their update client connections, etc.

    In conversation about 4 months ago from grapheneos.social permalink

    Attachments

    1. Domain not in remote thumbnail source whitelist: eylenburg.github.io
      Comparison of Android ROMs
      from Alphonse Eylenburg
      Comparison of Android ROMs
  11. Embed this notice
    GrapheneOS (grapheneos@grapheneos.social)'s status on Saturday, 11-Apr-2026 23:40:07 JST GrapheneOS GrapheneOS
    in reply to
    • Aral Balkan
    • Framasoft
    • Fla

    @aral @Framasoft @fla The most egregious inaccurate claims made about GrapheneOS haven't been addressed. Nothing has been done about the content of the podcast itself.

    It's also important to note there are widespread attacks on the GrapheneOS project and our team which are largely tied to Framasoft including using their Mastodon instance. Framasoft's Mastodon instance has been a massive source of attacks on the GrapheneOS project and team including harassment for quite some time now.

    In conversation about 4 months ago from grapheneos.social permalink

    Attachments

    1. No result found on File_thumbnail lookup.
      itself.it
      This domain may be for sale!
  12. Embed this notice
    GrapheneOS (grapheneos@grapheneos.social)'s status on Saturday, 11-Apr-2026 15:42:54 JST GrapheneOS GrapheneOS
    in reply to
    • Aral Balkan
    • Framasoft
    • Fla

    @aral @Framasoft There hasn't been any correction to the outrageous claims made by @fla that GrapheneOS isn't a privacy and isn't doing much about privacy. That's extraordinarily inaccurate and dismisses the massive amount of work we've done to advance privacy. Meanwhile, he's promoting operating systems which haven't done similar work to advance privacy. They aren't fixing VPN leaks, aren't implementing comparable privacy features and don't keep up with standard privacy patches/protections.

    In conversation about 4 months ago from grapheneos.social permalink
  13. Embed this notice
    GrapheneOS (grapheneos@grapheneos.social)'s status on Saturday, 11-Apr-2026 05:14:06 JST GrapheneOS GrapheneOS
    in reply to
    • Aral Balkan
    • Framasoft

    @aral @Framasoft He directly responded to the thread we published 4 days ago addressing Murena once again claiming the kind of privacy and security hardening work done by GrapheneOS and iPhones is only useful to criminals and spies. In that thread, we directly addressed these repeated inaccurate claims about the purpose, goals and approach of GrapheneOS which wrongly portray it as a security project rather than a privacy project. His claims in the interview are more than egregiously inaccurate.

    In conversation about 4 months ago from grapheneos.social permalink
  14. Embed this notice
    GrapheneOS (grapheneos@grapheneos.social)'s status on Saturday, 11-Apr-2026 02:22:20 JST GrapheneOS GrapheneOS

    The claims made about GrapheneOS in this interview are extremely inaccurate. It heavily misrepresents the purpose of GrapheneOS and what we've worked on for years. The claim GrapheneOS is a security project rather than a privacy project is misinformation. Contacts are specifically brought up and yet our Contact Scopes feature is ignored. @fla knows GrapheneOS is a privacy project. He replied to a thread with our response to this misinformation only 4 days ago...

    https://piaille.fr/@projetslibres_podcast/116379561169492214

    In conversation about 4 months ago from grapheneos.social permalink
  15. Embed this notice
    GrapheneOS (grapheneos@grapheneos.social)'s status on Monday, 06-Apr-2026 19:54:03 JST GrapheneOS GrapheneOS
    in reply to

    > with the mail or the telephone, we want to change that. So we are making you a product that changes that by default for anyone.

    In conversation about 4 months ago from grapheneos.social permalink
  16. Embed this notice
    GrapheneOS (grapheneos@grapheneos.social)'s status on Monday, 06-Apr-2026 19:53:59 JST GrapheneOS GrapheneOS
    in reply to

    Transcription in French:

    > Il y a la surface d'attaque, là pour le coup on est pas des spécialistes de la sécurité, donc je ne pourrais pas te répondre avec précision, mais des discussions que j'ai eu, il semblerait que tout ce qu'on fait, ça réduit la surface d'attaque. Donc oui, probablement ça aide. Par contre, on a pas une approche "sécurité durcie", on développe pas un téléphone pour les pédo(bip) pour qu'ils puissent échapper à la justice. Donc il y a pas des trucs pas possibles pour voir

    In conversation about 4 months ago from grapheneos.social permalink
  17. Embed this notice
    GrapheneOS (grapheneos@grapheneos.social)'s status on Monday, 06-Apr-2026 19:53:56 JST GrapheneOS GrapheneOS
    in reply to

    > si la mémoire est pas corrompue, des trucs de sécu vraiment durcis qui pourraient être utiles clairement pour des dirigeants, dans les services secrets ou que sais-je. C'est pas notre but, notre but c'est de partir d'un constat, aujourd'hui nos données personnelles sont pillées en permanence et ça serait pas légal dans la vraie vie avec le courrier ou le téléphone, on veut changer ça. Donc on vous fait un produit qui change ça par défaut pour n'importe quelle personne.

    In conversation about 4 months ago from grapheneos.social permalink
  18. Embed this notice
    GrapheneOS (grapheneos@grapheneos.social)'s status on Monday, 06-Apr-2026 19:53:52 JST GrapheneOS GrapheneOS
    in reply to

    GrapheneOS exists to protect users from having their privacy invaded by arbitrary individuals, corporations and states. Privacy depends on security. GrapheneOS heavily improves both privacy and security while providing a high level of usability and near perfect app compatibility.

    In conversation about 4 months ago from grapheneos.social permalink
  19. Embed this notice
    GrapheneOS (grapheneos@grapheneos.social)'s status on Monday, 06-Apr-2026 19:52:26 JST GrapheneOS GrapheneOS
    in reply to

    > we do reduces attack surface. However, we don't have a "hardened security" approach, we aren't developing a phone for pedo(censored) so they can evade justice. So there aren't difficult things to check if the memory is corrupted, really hardened security stuff that could clearly be useful for executives, in the secret service, or whatever. That's not our goal, our goal is to start from an observation: today our personal data is constantly being plundered and that wouldn't be legal in real life

    In conversation about 4 months ago from grapheneos.social permalink
  20. Embed this notice
    GrapheneOS (grapheneos@grapheneos.social)'s status on Monday, 06-Apr-2026 19:51:41 JST GrapheneOS GrapheneOS

    Gaël Duval is the founder and president of the /e/ foundation along with the CEO of Murena. Duval and his organizations have consistently taken a stance against protecting users from exploits. In this video, he once again claims protecting against exploits is for only useful pedophiles and spies.

    Translation to English:

    > There's the attack surface, on that front we're not security specialists here, so I couldn't answer you precisely, but from the discussions I've had, it seems that everything

    In conversation about 4 months ago from grapheneos.social permalink

    Attachments


  • After
  • Before

User actions

    GrapheneOS

    GrapheneOS

    Open source privacy and security focused mobile OS with Android app compatibility.

    Tags
    • (None)

    Following 0

      Followers 0

        Groups 0

          Statistics

          User ID
          99224
          Member since
          17 Feb 2023
          Notices
          567
          Daily average
          0

          Feeds

          • Atom
          • Help
          • About
          • FAQ
          • TOS
          • Privacy
          • Source
          • Version
          • Contact

          GNU social JP is a social network, courtesy of GNU social JP管理人. It runs on GNU social, version 2.0.2-dev, available under the GNU Affero General Public License.

          Creative Commons Attribution 3.0 All GNU social JP content and data are available under the Creative Commons Attribution 3.0 license.