Remix.run Logo
nunobrito 4 days ago

[flagged]

SigRed 4 days ago | parent | next [-]

So you were called out over on Nostr by Final regards the Tor app which you mistakenly took to be integrated when they simply showed the app and it running on the OS, not IN it and decided to come to HN for an anti-Graphene sympathetic ear?

The reply you were called out for, for other people's benefit: It's not bundled. It isn't going to be bundled. This is a post showing a work in progress beta app that most users have not seen before. This app is developed officially by Tor to hopefully replace Orbot, it is informational content.

"GrapheneOS has long been suspicious about the revenue values it receives." GrapheneOS Foundation is a registered Canadian non profit that declares it's accounts and has filed accounts registered against them for this year and last year too. Nothing is suspicious.

From a forensic perspective? You don't provide ANY forensic basis or evidence for anything you claim.

You prefer Chinese devices? Suggesting people use something known to be objectively less secure on a technical level and known to be closely tied to the Chinese government/military and not legally able to refuse their requests is strange. Even if US gov is the only threat you consider, this makes little to no sense. Especially when it has been revealed that forensic analysis firms used by the US LE agencies have revealed that they see GrapheneOS Pixel devices to be the hardest if not impossible to extract especially in BFU state. There is a reason European LE agencies and their media have gone to extra lengths to smear users as criminals due to how stymied they are in extracting data. A job you want to make easier by making ludicrous hypersensationalised claims based solely in the realm of fantasy.

nunobrito 4 days ago | parent [-]

Why would I ever trust a gov agency whose expertise is deceiving their oponents when they publicly announce/leak that a specific hardware is more secure than others for them to break? That is the all the more reason to keep distance.

> Tor app which you mistakenly took to be integrated when they simply showed the app and it running on the OS

Putting the two things together and endorsing is the same as placing a knife and a tomate on the kitchen table and not expecting them to be used together.

That distro is willingly promoting that journalists and other critical crafts use a service directly created/maintained/funded by the same governments they are trying to hide from. There exists I2P which solves all those attack vectors without ambiguities, but for "reasons" it isn't adopted. Ah.. "licensing model" was the reason last time we talked.

> "GrapheneOS has long been suspicious about the revenue values it receives." GrapheneOS Foundation is a registered Canadian non profit that declares it's accounts and has filed accounts registered against them for this year and last year too. Nothing is suspicious.

Is it public somewhere? If not: that is pretty suspicious for a non-profit. Because you endorse Tor (US intelligence-sponsored tool), you endorse Signal (US intelligence sponsored tool) so why don't you go public about where your money is coming from?

About chinese devices let's be realistic: Google™ Pixel devices are also built in China by Foxconn. Reusing your argument: I'm choosing to be spied only by one side of the globe rather than both sides. Yes, my personal preference is to be spied by eastern powers rather than western ones when possible to choose between bad choices.

I'm not alone on this criticism about the hardware and you know it.

bri3d 4 days ago | parent | prev | next [-]

This is a deeply horrible take.

“From a forensic perspective” if one uses a cheap Chinese phone, as you suggest, anyone with one of tens of forensic extraction tools (including the US government!) will immediately own your phone as soon as they plug into it (seriously, as a very public example MediaTek SOCs until very recently all have fatal flaws in the boot ROM).

If you use a Google phone, maybe a deeply embedded secret NSA implant will eventually activate late one night under the glow of your tinfoil hat, but by and large most people will not be able to extract all of your data in ten seconds by plugging into your phone.

nunobrito 4 days ago | parent [-]

Your opinion comes as security expert working for a group whose hardware leaked the data for 400 000 people just a few months ago: https://www.techzine.eu/news/security/127456/volkswagen-data...

Maybe your cars could use that tinfoil hat and avoid leaking personal data.

Now on a serious note: there are better odds of staying hidden between the noise of thousand cheap chinese manufacturers than willingly get yourself into the hardware of a very suspicious supplier.

You are correct that it is game over once there is physical access to your hardware, the thing we try to avoid here is guaranteed remote access from the comfort of some servers in Utah.

Retr0id 4 days ago | parent | prev | next [-]

> Tor ... a known VPN

This is like freaking out about dihydrogen monoxide in the water supply.

nunobrito 4 days ago | parent [-]

[dead]

Luker88 4 days ago | parent | prev | next [-]

This is kinda paranoid speech. GrapheneOS and Tor remain two of the best projects out there for privacy. I'd love to hear of other open alternatives, if any.

..."I don't trust google hardware, but I trust hardware from a dictatorial controlling regime" also does not really help your argument, sorry.

Besides, they seem to be working with some OEM to get their own phone out.

I'd love to receive daily updates on this, but it's a new development, updates are scarce and this things take time.

I hope sometime they'll collaborate with fairphone and others.

nunobrito 4 days ago | parent [-]

Nice try. First you call names, then you complain about phones with dictatorial origins while both of them come from exactly the same origin, that point is moot.

Even worse security practice to use the software and hardware from exactly the same OEM in terms of security. There is a reason why open implementations are important on the cybersec field, precisely to avoid "trust" but move into the side of "verify" since they need to inter-operate.

Scrubbed4426 4 days ago | parent | prev | next [-]

GrapheneOS does not have Tor "directly on the operating system". You are terribly misinformed about all of this it seems.

nunobrito 4 days ago | parent [-]

Wrong: https://primal.net/e/nevent1qqsq9lsf88umpdunkdzpdthyffys275z...

9029 4 days ago | parent [-]

Where does it say the app comes with Graphene???

nunobrito 4 days ago | parent [-]

Those are semantics. When you put a knife next to a tomato in the kitchen table, it cannot be argued they are separated. Same thing for directly supporting and even recommending the Tor usage on the phone.

Let's please avoid semantic word games. Thank you.

q3k 4 days ago | parent | prev [-]

Speaking of social media FUD...