> Thanks for the first link. I think I agree with everything written there.
You're welcome, happy to help.
> This is just the opinion of the GrapheneOS team.
I don't think it can be dismissed as mere opinion, but even if it were, that's their prerogative: it's their project. A lot of people seem to think they should take counsel from everyone with an opinion about their free OS, even if it fundamentally changes the basic nature of the project, wihle people who are free to fork it and do what they like with it.
If we're going to invoke the concept that FOSS fundamentally means it's somehow more secure because we are free to audit it (a premise I find faulty but not for any relevant purposes here), we should expand that view to include the concept that anyone who publishes their FOSS project is under no obligation to increase their workload and change the fundamental nature of their project to satisfy requests they don't view as being in harmony with the project.
Anyone who's capable of auditing FOSS code is a thousand times more capable than they need to be to follow instructions to build a rooted GrapheneOS installation, and some do.
> I've never seen any actual data supporting it.
What kind of data are you envisioning that would support it?
> Also it contradicts to the security approach of Qubes OS, doesn't it?
That's an interesting question, but I want to make sure I'm understanding it right. In what way would it contradict it? Is it a case of, Qubes OS gives you root access in dom0, TemplateVMs and AppVMs, by GrapheneOS's logic, doesn't that undermine its security?
You're welcome, happy to help.
> This is just the opinion of the GrapheneOS team.
I don't think it can be dismissed as mere opinion, but even if it were, that's their prerogative: it's their project. A lot of people seem to think they should take counsel from everyone with an opinion about their free OS, even if it fundamentally changes the basic nature of the project, wihle people who are free to fork it and do what they like with it.
If we're going to invoke the concept that FOSS fundamentally means it's somehow more secure because we are free to audit it (a premise I find faulty but not for any relevant purposes here), we should expand that view to include the concept that anyone who publishes their FOSS project is under no obligation to increase their workload and change the fundamental nature of their project to satisfy requests they don't view as being in harmony with the project.
Anyone who's capable of auditing FOSS code is a thousand times more capable than they need to be to follow instructions to build a rooted GrapheneOS installation, and some do.
> I've never seen any actual data supporting it.
What kind of data are you envisioning that would support it?
> Also it contradicts to the security approach of Qubes OS, doesn't it?
That's an interesting question, but I want to make sure I'm understanding it right. In what way would it contradict it? Is it a case of, Qubes OS gives you root access in dom0, TemplateVMs and AppVMs, by GrapheneOS's logic, doesn't that undermine its security?
Or were you going a different direction with it?