> How is this mainstream security, if GrapheneOS are the only ones offering it?
Not their fault. I should probably say "reasonable security". Settling for anything less is folly, seeing how malvertising isn't the only danger to the normal users. Broad availability of the powerful LLMs increases the amount of the vulnerabilities found and exploited in the wild.
Anything can carry an RCE now, web font, image, background audio on the cute website, attachment in the MMS or WhatsApp message.
I guess all those with "nothing to hide" (except their text messages, financial data, money on their bank accounts) are happy to have their lives sold in the open on more and more darknet marketplaces, their devices to mine some obscure crypto and serve as proxy for some nefarious actors.
You're using Qubes, I guess not because you like slower and less streamlined experience, but because you want security.
> My Qubes laptop runs coreboot with Heads with disabled and neutralized Intel ME.
Congrats, then, really.
Oh, wait, Qubes openly supports "CPU-vendor-provided blobs for silicon and memory initialization as well as other internal operations" -- which means you either strike "reliance on numerous non-auditable, proprietary drivers and firmware" from GOS (which runs it on the hardware that guarantees the separation), or raise the same for Qubes OS.
And actually, while we're at it, does your phone OS rely on the "numerous non-auditable, proprietary drivers and firmware" or not? Because if yes, why would you even complain that a very secure platform does that too?
Re: Coreboot: for me it would mean that I cannot use Qubes OS with hardware I want, because mean someone doesn't provide coreboot fw for my laptop, and even worse still, Qubes doesn't support my laptop.
I guess it's their fault then, seeing as some people throw a hissy fit that GrapheneOS doesn't want to officially support a phone they want to be supported :)
> I specifically mentioned that the GOS crowd comments on every single topic of other projects,
Will all due respect, this is just raging BS requiring extraordinary evidence.
> This is why I chose to word it that this is akin to me attacking every GOS post with their own flaws, which are the result of the chosen (mostly fair but real) tradeoffs
But you didn't list even one actual, objective flaw.
Not releasing firmware patches impacts everyone is objective, clearly negative. Not allowing to use custom keys is objective flaw. Not allowing to relock the bootloader is a flaw. Not having a secure element that processes PIN is a flaw.
Running privileged Google services isn't an objective flaw, if it's openly disclosed and benefits some users (so their handset can pass Play Integrity). No, GOS don't do it, for me it's an example what is and what isn't objective.
Supporting only one family of the phones is not an objective flaw if that's the only hardware platform that can back the security posture. And with the upcoming Motorola handsets support it's proved beyond doubt it's a flaw of the hardware manufacturers, not of the project trying to provide a secure platform for the increasingly dangerous Internet.
Maybe you remember how the freshly installed Windows XP without firewall couldn't get connected to the internet or it'd get immediately infected. Maybe you've seen logs from the Linux servers showing endless attempts to break in.
We're approaching the same for mobile devices, just worse, because most of these devices are grossly insecure, and the LLMs will be able to prepare custom exploits for all the common ones en masse.
> I do not want to attack every GOS discussion.
You do you. If you have actual flaws, by all mean, you're good.
But you didn't show a single one yet. You shared your opinion on how you believe that not supporting root is somewhat bad, or complained that GOS does something ALL the other vendors do (like reliance on AOSP, not changing licensing, or using fw blobs (at least in their case - securely))
> I want to demonstrate how ridiculous their actions are, dividing projects that in the end have the same goals: to fight with megacorps and reclaim user freedom and security.
I think it's a mistake to project your own position or understanding on all the projects.
Like, LineageOS supports a very broad range of hardware increasing security for many of these abandoned by their vendors (f*k Sony, for example, for releasing security patches for barely year-and-a-half for so-called flagship).
GOS has different goals. They result in the similar gains (i.e. ensuring security benefits privacy), but it's a result, not goal per se.
> Librem 5
So you don't have source code of the firmware for your chosen phone but you're attacking GOS for using firmware they don't have source of? I'm confused.
> (2) I do not believe that AOSP developed by Google will provide the necessary freedom in the future
Wait, wait, but you said "full dependence on Google's direction of Android development and how fast Google shares the source code with others" as presumably an evidence/example of specifically GrapheneOS flaw.
You "accused" AOSP-based operating systems team of being fully dependent on the AOSP.
And now you're saying it was about your *feelings*?
Do you attack projects stating your feelings as an "evidence" of the project's shortcomings?
Can you see how it's hard to have a fact-based, neutral discussion with that? It's broadly pointless because you either confuse facts and evidence with feelings or you equate these two.
> Librem 5 is less secure than a GrapheneOS phone today, but nothing prevents the community to change that
If the hardware is secure, sure. You can even backport a lot of GOS improvements back to Linux.
But if the hardware is not secure, then no, community cannot make it as secure as GOS phone today.
> GrapheneOS supports the option of using the phone against its users with DRM
I'm confused, first I don't know what specifically you're talking about (not saying it's untrue but throwing "DRM" randomly doesn't help much), and is it something unique to GrapheneOS that is NOT shared by other projects? Because, seriously, you're singling out the safest, most private and most secure project listing things that are probably done by everyone else but its somehow only GOS issue?
(Also, is it a safety issue or only privacy? GOS never promised a focus on privacy)
> [Fairphone] AFAIK they follow the upstream patches, i.e., just like GOS, they are at the mercy of the corporations with their security.
They're always late by many months. Months. They're free to do what GrapheneOS do, to keep requesting these patches.
But what are we talking about, they didn't even do as much as move to Android 17, which in itself is the evidence they don't follow upstream, because most patches are not backported by Google. Raising that is not "attacking" any more than listing unsafe features of a a specific car.
>> [about not supporting root] Why do you expect a project focused on the reasonable security of all the reasonably safe handsets to bow to you exactly?
> I did not demand that GOS does this.
But you specifically complained: "(4) complete lack of flexibility concerning the user's threat model, e.g., intentional lack of support for root for whitelisted apps"
They openly support users building their own images (with root. It's trivial to build the image with root enabled), and you actually complain they do not support root. They do not in their official images.
So you are now saying that by complaining that GrapheneOS do not support root in the official image, which you provided as (presumably) objective flaw of the OS, isn't in fact you demanding they support it officially and build it in, thus bowing to the request?
I'm utterly confused here.
About as much as when you send me to FSF website to read about some licence when I ask you how the project's decision to stick to the parent licence in order to not impose limitations on the users is imposing the limitations on the users.