• 3 Posts
  • 136 Comments
Joined 2 years ago
cake
Cake day: July 24th, 2023

help-circle




  • Depends on what your definition of winning is. If we reach a state where it is literally impossible to run your own software without heavy hardware modification, which would exclude 99.9% of users, that would be like big tech winning in my book. That’s why right to repair is important, and we probably also need laws to prevent OEMs from disallowing the use of alternate OS.




  • Short TL;DR: nothing burger

    Longer TL;DR: Linus sees bad changes to the git tree by Kees Cook that he interprets as being of human origin and intentional, calls them “malicious” changes and orders that Kees Cook’s privileges be revoked. Turns out that the “git-filter-repo” tool being used was actually the culprit as it is very powerful and incorrect usage explains the changes. Discussion then moves toward implementing safety checks in the tooling. Kees gets his permissions back.




  • Let’s be careful to remember that there are different levels of effort and understanding required for different levels of security and privacy. GrapheneOS has taken the approach of offering harm reduction, with sane defaults and options that allow advanced users to take near-complete control over their device (within the limits of the Pixel hardware). This is obvious by their inclusion of the sandboxed Google Play Store as a major feature of the OS, as it is much better than the situation on Google’s Android. It is also not installed by default, forcing users to at least somewhat educate themselves in order to install it.

    Accrescent is right in line with this philosophy, and is also not installed by default. Of course if your threat model (or desire) is to achieve the highest level of online anonymity and to have a completely FOSS system, you should not use it… of course you probably shouldn’t use FDroid either, in that case, and should build from source. However, you are clearly in a situation where your threat model does not require those lengths, and FDroid is more of a principled choice.

    I think its pointlessly inflammatory to call Accrescent “dangerous” just because it allows for non-FOSS software. Now if you want to criticize whether or not it is fulfilling its stated goals, that is another story.




  • Have you guys reached out to Nothing? Looks like they run Android, and are a relatively new company (founded by the former OnePlus founder) that is just starting sales to the US. Maybe an angle GrapheneOS could take is to be an alternate OS install option, they are very focused on growth and attracting the privacy and security community might benefit them as they aim to squeeze out more ROI. They also seem to be cranking out new phone designs at a pretty good rate, so perhaps they could accommodate hardware requests, who knows? business@nothing.tech to inquire