‹ BackHN Continuity

Thread

GrapheneOS has fixed the Android 17 QPR1 kernel performance regression

142 points · 102 comments · Cider9986

  1. mmooss · · focus · HN ↗

    [dead]

    1. palata · · focus · HN ↗
      > But they often choose to denigrate others, which is destructive, damages relationships

      It used to be like that (and to be fair, all the similar communities were contributing to the drama, not just GOS), I agree, but I genuinely feel like it has become a lot more professional lately. Like I haven't seen drama in... at least 6 months?

      Now I almost exclusively see them explain their technical decisions, which is very interesting.

      1. mmooss · · focus · HN ↗
        The OP denigrates Google.
        1. olyjohn · · focus · HN ↗
          Maybe it's well deserved. Google have been real pricks.
        2. palata · · focus · HN ↗
          Oh sorry, I thought you were talking about something else. Well... yeah IMO Google deserves it as it (as a company) is predatory.

          Don't get me wrong, there are brilliant engineers at Google and I'm glad they are paid to contribute to open source projects like Android. But it doesn't make Google less evil.

          And criticising a company is very different from "denigrating people". I don't think that the Google entity has feelings, does it?

          1. mmooss · · focus · HN ↗
            If you have a relationship with a business, try publicly denigrating them and see what the response is. Google the entity has a reputation, and that affects their revenue and reflects strongly on the people who work there - 'Google' means something on a resume.
            1. palata · · focus · HN ↗
              What relationship does GrapheneOS have with Google? My understanding is that they fork the open source stuff made by Google, and as a response Google (the entity) does everything they can to screw GrapheneOS.

              > Google the entity has a reputation

              Yep: "EvilCorp"

            2. microtonal · · focus · HN ↗
              Google’s relation with GrapheneOS is: make their lives harder by moving kernel trees from Git to Google Drive with a form that sometimes doesn’t get processed in weeks; block tap-to-pay and a bunch of apps with Play Integrity; closing the AOSP trees and only do major release and QPR2 drops; remove Pixel device trees etc. from AOSP even though they were sold as reference devices.
            3. HybridStatAnim8 · · focus · HN ↗
              GrapheneOS has no relationship with Google.
            4. grapheneos · · focus · HN ↗
              Google has been increasingly hostile towards GrapheneOS over the past several years despite our substantial contributions upstream. We've spent years helping Google with vulnerability reports, improvements submitted upstream and multiple proposals for security protections which were implemented for both Android and Pixels. We've been treated incredibly poorly by Google despite our contributions.

              They're trying to limit how many devices can be sold with GrapheneOS by Android OEMs, reduced the number of AOSP releases from 12 to 2 per year with 10 of those now being Pixel exclusive, removed Pixel support from AOSP, unsuccessfully tried to cut us off from early access to security patches which are now allowed to be shipped early by OEMs while under embargo (which we do), are trying to convince app developers to ban using GrapheneOS via the Play Integrity API and even recently funded an AI slop paper with misinformation about GrapheneOS falsely claiming it missed security patches that it did not based on an entirely false premise that it has diverged from AOSP in a way that it hasn't and has to port patches to a diverged fork of the OS which isn't how it works.

              Many of the things Google has done to hinder open source projects based on Android are illegal and they continue doubling down on it despite a lot of regulatory and legal actions already taken against them.

              More info at <a href="https:&#x2F;&#x2F;news.ycombinator.com&#x2F;edit?id=49946698">https:&#x2F;&#x2F;news.ycombinator.com&#x2F;edit?id=49946698.

        3. antonvs · · focus · HN ↗
          “Denigrate” implies unfair criticism. Whether the OP is doing that is a matter of opinion, but it’s certainly possible to read it as straight criticism, i.e. not unfair and not denigrating.
        4. grapheneos · · focus · HN ↗
          Google has been increasingly hostile towards GrapheneOS over the past several years despite our substantial contributions upstream. We&#x27;ve spent years helping Google with vulnerability reports, improvements submitted upstream and multiple proposals for security protections which were implemented for both Android and Pixels. We&#x27;ve been treated incredibly poorly by Google despite our contributions.

          They&#x27;re trying to limit how many devices can be sold with GrapheneOS by Android OEMs, reduced the number of AOSP releases from 12 to 2 per year with 10 of those now being Pixel exclusive, removed Pixel support from AOSP, unsuccessfully tried to cut us off from early access to security patches which are now allowed to be shipped early by OEMs while under embargo (which we do), are trying to convince app developers to ban using GrapheneOS via the Play Integrity API and even recently funded an AI slop paper with misinformation about GrapheneOS falsely claiming it missed security patches that it did not based on an entirely false premise that it has diverged from AOSP in a way that it hasn&#x27;t and has to port patches to a diverged fork of the OS which isn&#x27;t how it works.

          Many of the things Google has done to hinder open source projects based on Android are illegal and they continue doubling down on it despite a lot of regulatory and legal actions already taken against them.

          More info at <a href="https:&#x2F;&#x2F;news.ycombinator.com&#x2F;edit?id=49946698">https:&#x2F;&#x2F;news.ycombinator.com&#x2F;edit?id=49946698.

      2. fsflover · · focus · HN ↗

        [dead]

        1. subscribed · · focus · HN ↗
          Why do you even call the detailed, verifiable claims about a product a &quot;drama&quot;?

          So it&#x27;s impossible now to list the bad features or shortcomings without come one calling drama?

          Why do you call it drama?

          1. fsflover · · focus · HN ↗
            One thing is to present the advantages of your system. Entirely different thing is to enter every discussion of alternative systems saying they have &quot;atrocious&quot; security. Also, the second link is an empty accusation, as it has no proofs.
            1. subscribed · · focus · HN ↗
              They have listed a very long, concrete list of issues with Fairphone in the (sub)thread about Fairphone.

              A very long list of severe issues. This is not presenting the advantages, it&#x27;s listing of the problems.

              When did that become a &quot;drama&quot;, and not a fact-based criticism?

              Re: second link - I don&#x27;t have time to waste on digging through the code, I&#x27;d rather count pebbles in my garden, but I&#x27;m happy to bet £100 that it&#x27;s fully facts based. I didn&#x27;t even comment on the second link previously, BTW.

              1. fsflover · · focus · HN ↗
                Imagine that I would enter every conversation about GrapheneOS saying how atrocious their freedom is, including (1) reliance on numerous non-auditable, proprietary drivers and firmware; (2) full dependence on Google&#x27;s direction of Android development and how fast Google shares the source code with others, as well as reliance on remote attestation [0]; (3) their disregard of GPLv3 that protects the user more [1]; (4) complete lack of flexibility concerning the user&#x27;s threat model, e.g., intentional lack of support for root for whitelisted apps and lack of full user control over the running apps [2,3].

                - would you call the above &quot;a very long, concrete list of issues&quot; or &quot;attack and drama&quot;?

                [0] <a href="https:&#x2F;&#x2F;news.ycombinator.com&#x2F;item?id=45232164">https:&#x2F;&#x2F;news.ycombinator.com&#x2F;item?id=45232164

                [1] <a href="https:&#x2F;&#x2F;news.ycombinator.com&#x2F;item?id=49594324">https:&#x2F;&#x2F;news.ycombinator.com&#x2F;item?id=49594324

                [2] <a href="https:&#x2F;&#x2F;news.ycombinator.com&#x2F;item?id=49543420">https:&#x2F;&#x2F;news.ycombinator.com&#x2F;item?id=49543420,

                [3] <a href="https:&#x2F;&#x2F;news.ycombinator.com&#x2F;item?id=48767841">https:&#x2F;&#x2F;news.ycombinator.com&#x2F;item?id=48767841

                1. subscribed · · focus · HN ↗
                  LOL?

                  I don&#x27;t see how the evidence of the project unwilling to keep up with the mainstream security or a statement that their hardware doesn&#x27;t come close to the top would be relevant to this:

                  (1) and how do you imagine releasing the OS for the hardware not owned by the project? Does your Fairphone release source code of all the firmware? Do you have source code of the BIOS, firmware and microcode of your chosen Qubes OS pc? :D

                  (2) LOL, Google pretty much owns AOSP, how do you imagine GOS project takes the helm? Please explain. I read these as the strategic decision of GrapheneOS project, or unwillingness to take action. Please explain.

                  [0] what are you even on with remote attestation? This is an optional feature for the OS provider to prove the whole chain of custody hasn&#x27;t been broken. Can you explain how the GOS project providing an option for the software developers to check that the OS hasn&#x27;t been tampered with is a downside.

                  Of course in the light of the Fairphone unable to do as much as peivide timely patches or the OS available for over 6 months now.

                  (3) they explained they &quot;want GrapheneOS to have no additional restrictions beyond AOSP. AOSP uses GPLv2 but not GPLv3&quot;. I don&#x27;t understand what the charge is? How does GPLv3 benefit end user more? Why aren&#x27;t you complaining to Google?

                  (And why are we even talking about that? Are you trying to stoke some drama, LOL?)

                  (4) lack of support for root becomes what, a proof they&#x27;re stoking drama?! what are you even on? They prove source code, build instructions and more details, you&#x27;re free to build your own images with root, it&#x27;s actually super simple - the only things you lose is their signature and remote attestation you hate anyway.

                  Why do you expect a project focused on the reasonable security of all the reasonably safe handsets to bow to you exactly?

                  Because frankly it looks like you&#x27;re trying to cause some drama. None of your &quot;charges&quot; carry any weight. Quoting the team explaining why they chose GPLv2 over v3 as the &quot;evidence&quot; of drama?

                  What&#x27;s your angle? What i#&#x2F;your post really about? Yeah, I see you see all the above as a serious charges against the project, and you&#x27;re free to throw these every time.

                  But.... Do you really think they&#x27;re approximately the same weight?

                  1. fsflover · · focus · HN ↗
                    &gt; mainstream security

                    How is this mainstream security, if GrapheneOS are the only ones offering it? Cutting edge, maybe. Except Qubes OS of course.

                    &gt; Do you have source code of the BIOS, firmware and microcode of your chosen Qubes OS pc? :D

                    My Qubes laptop runs coreboot with Heads with disabled and neutralized Intel ME. It does not offer the full user freedom, but it comes as close as possible.

                    &gt; or a statement that their hardware doesn&#x27;t come close to the top

                    I specifically mentioned that the GOS crowd comments on every single topic of other projects, which to me is just attacking them. They have different tradeoffs, just like GOS itself. This is why I chose to word it that this is akin to me attacking every GOS post with their own flaws, which are the result of the chosen (mostly fair but real) tradeoffs. I do not want to attack every GOS discussion. I want to demonstrate how ridiculous their actions are, dividing projects that in the end have the same goals: to fight with megacorps and reclaim user freedom and security.

                    (1) I do not. And I do not have a Fairphone. I just hate drama and fight against it. I have a Librem 5 though. All its drivers are free and all its firmware sits on external, removable devices. If (when) a certain vendor starts to misbehave and use their power against the user, we can replace the device.

                    (2) I do not believe that AOSP developed by Google will provide the necessary freedom in the future, at all. Google have shown again and again how they use their power against the users and against GrapheneOS. If you can&#x27;t develop it independently, just don&#x27;t. I use Librem 5, because I do not believe in the future of AOSP. Linux though doesn&#x27;t obey a single megacorp: Its development is distributed over many organizations, greatly reducing the danger of misbehavior against users. Librem 5 is less secure than a GrapheneOS phone today, but nothing prevents the community to change that.

                    [0] GrapheneOS supports the option of using the phone against its users with DRM. People who value freedom are not okay with that.

                    &gt; Of course in the light of the Fairphone unable to do as much as peivide timely patches or the OS available for over 6 months now.

                    AFAIK they follow the upstream patches, i.e., just like GOS, they are at the mercy of the corporations with their security. This is not exactly their fault, as they chose different main goals, which are important, too. Attacking them does not help anyone except the megacorps.

                    &gt; Why aren&#x27;t you complaining to Google?

                    Google do not promise privacy or control to their users. But they should definitely be fought against.

                    &gt; How does GPLv3 benefit end user more?

                    You can read all the reasoning at gnu.org.

                    &gt; (And why are we even talking about that? Are you trying to stoke some drama, LOL?)

                    I am trying to stop some drama by explaining why the GOS crowd should not do as they do.

                    (4) You completely missed my point. Read the above.

                    &gt; you&#x27;re free to build your own images

                    &gt; Why do you expect a project focused on the reasonable security of all the reasonably safe handsets to bow to you exactly?

                    I did not demand that GOS does this.

                    &gt; None of your &quot;charges&quot; carry any weight.

                    I did not suggest changes. I do understand the GOS choices. I demand that they, too, understand the choices of others.

                    &gt; Quoting the team explaining why they chose GPLv2 over v3 as the &quot;evidence&quot; of drama?

                    The choices have nothing to do with drama. The inability of GOS to understand the choices of others and attacking these choices every single time something is posted is drama.

                    Thanks for the genuinely trying to understand me.

                    1. subscribed · · focus · HN ↗
                      &gt; How is this mainstream security, if GrapheneOS are the only ones offering it?

                      Not their fault. I should probably say &quot;reasonable security&quot;. Settling for anything less is folly, seeing how malvertising isn&#x27;t the only danger to the normal users. Broad availability of the powerful LLMs increases the amount of the vulnerabilities found and exploited in the wild.

                      Anything can carry an RCE now, web font, image, background audio on the cute website, attachment in the MMS or WhatsApp message.

                      I guess all those with &quot;nothing to hide&quot; (except their text messages, financial data, money on their bank accounts) are happy to have their lives sold in the open on more and more darknet marketplaces, their devices to mine some obscure crypto and serve as proxy for some nefarious actors.

                      You&#x27;re using Qubes, I guess not because you like slower and less streamlined experience, but because you want security.

                      &gt; My Qubes laptop runs coreboot with Heads with disabled and neutralized Intel ME.

                      Congrats, then, really.

                      Oh, wait, Qubes openly supports &quot;CPU-vendor-provided blobs for silicon and memory initialization as well as other internal operations&quot; -- which means you either strike &quot;reliance on numerous non-auditable, proprietary drivers and firmware&quot; from GOS (which runs it on the hardware that guarantees the separation), or raise the same for Qubes OS.

                      And actually, while we&#x27;re at it, does your phone OS rely on the &quot;numerous non-auditable, proprietary drivers and firmware&quot; or not? Because if yes, why would you even complain that a very secure platform does that too?

                      Re: Coreboot: for me it would mean that I cannot use Qubes OS with hardware I want, because mean someone doesn&#x27;t provide coreboot fw for my laptop, and even worse still, Qubes doesn&#x27;t support my laptop.

                      I guess it&#x27;s their fault then, seeing as some people throw a hissy fit that GrapheneOS doesn&#x27;t want to officially support a phone they want to be supported :)

                      &gt; I specifically mentioned that the GOS crowd comments on every single topic of other projects,

                      Will all due respect, this is just raging BS requiring extraordinary evidence.

                      &gt; This is why I chose to word it that this is akin to me attacking every GOS post with their own flaws, which are the result of the chosen (mostly fair but real) tradeoffs

                      But you didn&#x27;t list even one actual, objective flaw.

                      Not releasing firmware patches impacts everyone is objective, clearly negative. Not allowing to use custom keys is objective flaw. Not allowing to relock the bootloader is a flaw. Not having a secure element that processes PIN is a flaw.

                      Running privileged Google services isn&#x27;t an objective flaw, if it&#x27;s openly disclosed and benefits some users (so their handset can pass Play Integrity). No, GOS don&#x27;t do it, for me it&#x27;s an example what is and what isn&#x27;t objective.

                      Supporting only one family of the phones is not an objective flaw if that&#x27;s the only hardware platform that can back the security posture. And with the upcoming Motorola handsets support it&#x27;s proved beyond doubt it&#x27;s a flaw of the hardware manufacturers, not of the project trying to provide a secure platform for the increasingly dangerous Internet.

                      Maybe you remember how the freshly installed Windows XP without firewall couldn&#x27;t get connected to the internet or it&#x27;d get immediately infected. Maybe you&#x27;ve seen logs from the Linux servers showing endless attempts to break in.

                      We&#x27;re approaching the same for mobile devices, just worse, because most of these devices are grossly insecure, and the LLMs will be able to prepare custom exploits for all the common ones en masse.

                      &gt; I do not want to attack every GOS discussion.

                      You do you. If you have actual flaws, by all mean, you&#x27;re good.

                      But you didn&#x27;t show a single one yet. You shared your opinion on how you believe that not supporting root is somewhat bad, or complained that GOS does something ALL the other vendors do (like reliance on AOSP, not changing licensing, or using fw blobs (at least in their case - securely))

                      &gt; I want to demonstrate how ridiculous their actions are, dividing projects that in the end have the same goals: to fight with megacorps and reclaim user freedom and security.

                      I think it&#x27;s a mistake to project your own position or understanding on all the projects.

                      Like, LineageOS supports a very broad range of hardware increasing security for many of these abandoned by their vendors (f*k Sony, for example, for releasing security patches for barely year-and-a-half for so-called flagship).

                      GOS has different goals. They result in the similar gains (i.e. ensuring security benefits privacy), but it&#x27;s a result, not goal per se.

                      &gt; Librem 5

                      So you don&#x27;t have source code of the firmware for your chosen phone but you&#x27;re attacking GOS for using firmware they don&#x27;t have source of? I&#x27;m confused.

                      &gt; (2) I do not believe that AOSP developed by Google will provide the necessary freedom in the future

                      Wait, wait, but you said &quot;full dependence on Google&#x27;s direction of Android development and how fast Google shares the source code with others&quot; as presumably an evidence&#x2F;example of specifically GrapheneOS flaw.

                      You &quot;accused&quot; AOSP-based operating systems team of being fully dependent on the AOSP.

                      And now you&#x27;re saying it was about your *feelings*?

                      Do you attack projects stating your feelings as an &quot;evidence&quot; of the project&#x27;s shortcomings?

                      Can you see how it&#x27;s hard to have a fact-based, neutral discussion with that? It&#x27;s broadly pointless because you either confuse facts and evidence with feelings or you equate these two.

                      &gt; Librem 5 is less secure than a GrapheneOS phone today, but nothing prevents the community to change that

                      If the hardware is secure, sure. You can even backport a lot of GOS improvements back to Linux.

                      But if the hardware is not secure, then no, community cannot make it as secure as GOS phone today.

                      &gt; GrapheneOS supports the option of using the phone against its users with DRM

                      I&#x27;m confused, first I don&#x27;t know what specifically you&#x27;re talking about (not saying it&#x27;s untrue but throwing &quot;DRM&quot; randomly doesn&#x27;t help much), and is it something unique to GrapheneOS that is NOT shared by other projects? Because, seriously, you&#x27;re singling out the safest, most private and most secure project listing things that are probably done by everyone else but its somehow only GOS issue?

                      (Also, is it a safety issue or only privacy? GOS never promised a focus on privacy)

                      &gt; [Fairphone] AFAIK they follow the upstream patches, i.e., just like GOS, they are at the mercy of the corporations with their security.

                      They&#x27;re always late by many months. Months. They&#x27;re free to do what GrapheneOS do, to keep requesting these patches.

                      But what are we talking about, they didn&#x27;t even do as much as move to Android 17, which in itself is the evidence they don&#x27;t follow upstream, because most patches are not backported by Google. Raising that is not &quot;attacking&quot; any more than listing unsafe features of a a specific car.

                      &gt;&gt; [about not supporting root] Why do you expect a project focused on the reasonable security of all the reasonably safe handsets to bow to you exactly?

                      &gt; I did not demand that GOS does this.

                      But you specifically complained: &quot;(4) complete lack of flexibility concerning the user&#x27;s threat model, e.g., intentional lack of support for root for whitelisted apps&quot;

                      They openly support users building their own images (with root. It&#x27;s trivial to build the image with root enabled), and you actually complain they do not support root. They do not in their official images.

                      So you are now saying that by complaining that GrapheneOS do not support root in the official image, which you provided as (presumably) objective flaw of the OS, isn&#x27;t in fact you demanding they support it officially and build it in, thus bowing to the request?

                      I&#x27;m utterly confused here.

                      About as much as when you send me to FSF website to read about some licence when I ask you how the project&#x27;s decision to stick to the parent licence in order to not impose limitations on the users is imposing the limitations on the users.

              2. fsflover · · focus · HN ↗
                &gt; I&#x27;m happy to bet £100 that it&#x27;s fully facts based

                Quote:

                &gt; a random identifier, generated on your device the first time it boots (a random UUID prefixed with anon), used to pick the wave.

                &gt; About this identifier:

                &gt; it is random: it is not computed from the IMEI, the serial number, the MAC address, an account or any other data of your device or of you;

                &gt; it is not linked to any account: you do not need an account to use &#x2F;e&#x2F;OS and the Updater does not know about it;

                &gt; it is reset by a factory reset: after one, your device gets a new identifier and is considered a new device;

                &gt; it is used to pick the wave.

                <a href="https:&#x2F;&#x2F;doc.e.foundation&#x2F;os&#x2F;learn&#x2F;staged-rollout&#x2F;" rel="nofollow">https:&#x2F;&#x2F;doc.e.foundation&#x2F;os&#x2F;learn&#x2F;staged-rollout&#x2F;

                No evidence that it is used or can be used for tracking. The accusation is strongly overstated. (You can keep your £100 though.)

                1. subscribed · · focus · HN ↗
                  GOS&gt;&gt; &#x2F;e&#x2F; does have services collecting data on their users which isn&#x27;t disclosed including user tracking via unique identifiers in the update client.

                  &gt; a random identifier, generated on your device the first time it boots

                  So it&#x27;s a persistent, unique identifier, is it?

                  &gt; No evidence that it is used or can be used for tracking.

                  It&#x27;s even worse than Google&#x27;s Advertising ID that at least can be easily reset.

                  &gt; The accusation is strongly overstated

                  &gt; (You can keep your £100 though.)

                  I don&#x27;t think how you disproved anything. You even confirmed the phone ID is immutable until factory reset.

                  I was talking about all four claims.

                  GOS&gt;&gt; They also spent years sending user speech data to OpenAI without informing users beyond fine print in the terms of use.

                  Here&#x27;s the discovery by the user and confirmation from the owner of the project: <a href="https:&#x2F;&#x2F;community.e.foundation&#x2F;t&#x2F;voice-to-text-feature-using-open-ai&#x2F;70509&#x2F;10" rel="nofollow">https:&#x2F;&#x2F;community.e.foundation&#x2F;t&#x2F;voice-to-text-feature-using...

                  (This is sharing users&#x27; biometric data with third party without express consent, then shared further with unspecified )

                  GOS&gt;&gt; It&#x27;s presented as not using Google services but has a whole bunch of Google services with privileged access enabled by default.

                  <a href="https:&#x2F;&#x2F;eylenburg.github.io&#x2F;android_comparison.htm" rel="nofollow">https:&#x2F;&#x2F;eylenburg.github.io&#x2F;android_comparison.htm

                  GOS&gt;&gt; It even downloads and runs Google Play executables such as droidguard by default with privileged access far beyond the regular app sandbox.

                  <a href="https:&#x2F;&#x2F;doc.e.foundation&#x2F;os&#x2F;learn&#x2F;calls-to-google-servers&#x2F;" rel="nofollow">https:&#x2F;&#x2F;doc.e.foundation&#x2F;os&#x2F;learn&#x2F;calls-to-google-servers&#x2F;

                  I believe it also enables Safetynet checks by default which downloads and executes proprietary code straight from Google.

                  So you didn&#x27;t disprove the first one and you didn&#x27;t touch remaining three.

                  I&#x27;ll keep my £100 indeed.

        2. palata · · focus · HN ↗
          This is not drama, this is a technical opinion about their competitors. Happy to have Fairphone and &#x2F;e&#x2F;OS do it constructively as well. And I mean constructively. When the founder of &#x2F;e&#x2F;OS says &quot;we are not one of those hardened systems for pedophiles&quot;, it is not constructive. If they said (I&#x27;m inventing here, not sure if they did): &quot;The problem of GrapheneOS is that they only run on Pixels. We try to run on more phones in a best-effort basis&quot;, that would be valid.
          1. fsflover · · focus · HN ↗
            I agree that e&#x2F;OS&#x2F; weren&#x27;t constructive. However see this: <a href="https:&#x2F;&#x2F;news.ycombinator.com&#x2F;item?id=49947080">https:&#x2F;&#x2F;news.ycombinator.com&#x2F;item?id=49947080

            P.S. Flagging my comments, as the GrapheneOS fans do, is also far from constructive.

      3. subscribed · · focus · HN ↗

        [dead]

      4. grapheneos · · focus · HN ↗
        We&#x27;ve been defending ourselves from intense attacks aimed at destroying GrapheneOS and personally harming our team members since 2018. We now have a lot more project members, community members, money, legal representation and other resources to protect ourselves. We don&#x27;t feel the need to defend ourselves nearly as much from non-technical attacks since even many people who don&#x27;t use GrapheneOS are defending us. No need for us to directly address it if others have already done it. We&#x27;ll still directly defend ourselves in cases where other people aren&#x27;t aware or aren&#x27;t doing it.
        1. warrantisall · · focus · HN ↗
          Now that you have &quot;money, legal representation and other resources to protect ourselves&quot;, will you take legal action against Google&#x27;s anti-competitive practices?
Open on Hacker News to reply ↗

Unofficial Hacker News client; not affiliated with Y Combinator.