• 0 Posts
  • 31 Comments
Joined 1 year ago
cake
Cake day: July 1st, 2023

help-circle





  • Not according to the article at the top of this thread:

    Proton does also offer a VPN service of its own — and Yen has claimed that Swiss law does not allow it to log its VPN users’ IP addresses. So it’s interesting to speculate whether the activists might have been able to evade the IP logging if they had been using both Proton’s end-to-end encrypted email and its VPN service.

    “If they were using Tor or ProtonVPN, we would have been able to provide an IP, but it would be the IP of the VPN server, or the IP of the Tor exit node,” Yen told TechCrunch when we asked about this.












  • GrapheneOS aims to provide reasonably private and secure devices. It cannot do that once device support code like firmware, kernel and vendor code is no longer actively maintained. Even if the community was prepared to take over maintenance of the open source code and to replace the rest, firmware would present a major issue, and the community has never been active or interested enough in device support to consider attempting this. Unlike many other platforms, GrapheneOS has a much higher minimum standard than simply having devices fully functional, as they also need to provide the expected level of security. It would start to become realistic to provide substantially longer device support once GrapheneOS controls the hardware and firmware via custom hardware manufactured for it. Until then, the lifetime of devices will remain based on manufacturer support.

    From https://grapheneos.org/faq#legacy-devices

    Basically they don’t want to support devices if they can’t make them secure, which is something that requires at least some input from the manufacturer. I imagine a GrapheneOS dev would say that CalyxOS’s updates to a device where the manufacturer isn’t providing kernel updates isn’t a worthwhile update.


  • There was a good discussion in the degoogle community last week which can give much more specific details, but the short version is that GrapheneOS’s main focus is security (and you get a lot of privacy stuff too), whereas CalyxOS’s main focus seems to be privacy but it lacks on the security side. For instance CalyxOS uses MicroG instead of Google Play Services, which keeps you private from Google but is still a black box that you have to give privileged access, whereas GrapheneOS has nothing by default (and that can work fine for some users), but you can install real Google Play Services within a sandbox where it has no privileged access.



  • Discord is terrible for both public and private communications. It locks public discussions (which would otherwise happen somewhere open like a traditional forum) away somewhere you can’t search without logging in, meaning you can’t get quick answers without already knowing where you need to look. It also offers no E2EE on its ‘private’ chats, so presumably datamines everything you type.