Encrochat and their ilk explicitly marketed towards criminals and sold products to them. That's why they fell the way they did. We do neither. They operated a messaging service knowing what users were up to and continued to provide them service. We don't provide a messaging service and any person who makes themselves known to be involved in universally illegal activities is banned on our public support platforms without any form of appeal.
ANOM was a genuine honey pot from the beginning but the key indicators were there from the start. It had no public facing team, a non profit, no open source code. GrapheneOS has all of these. You'll also find this is the exact same for SkyECC, Matrix (not the open source chat project) and more. They often also steal the work of other projects and people or bundle the software of others unauthorized. ANOM took parts of GrapheneOS open source code, which, given the nature of open source, is something impossible to control.
The people behind EncroChat were not at all experts in security. They designed their service to be entirely dependent on their servers / infrastructure. Their goal was to make money off of paranoid crooks who knew even less about technology, NOT to protect at risk individuals. We have been attacked by people previously affiliated with EncroChat and other devices before and called them out on social media. They hate us because they can't scam innocent people believing they are protected with exorbitant price tags that they then use the money to fund illicit activities with. Major example of GrapheneOS actually preventing a crime.
GrapheneOS only uses the minimum amount of data required to download an update (the device model and update stream) and updates must be verified as being signed by the GrapheneOS team from the device, which is signed by keys not available to the servers. Any malicious update would be rejected and any fresh first install that was malicious would be obvious.
Login to reply
Replies (2)
Yes, I am not comparing you to encrochat by any means or measures.
It's just the way the mass media is promoting you as a silver bullet to the criminals that makes me wonder what is off. Typically, they would rather never mention you at all. Hence my suspicion they might have a zero day at hand.
GrapheneOS looks like a very valuable project.
But this text makes it sound as if you can trust a phone with GrapheneOS installed if only the keys/signatures were verified on boot.
Seems naive to me to trust a hardware device with probably hundreds of opaque blobs even when it has the best open-source OS installed.