-15
top 15 comments
sorted by: hot top new old
[-] Turret3857@infosec.pub 6 points 1 day ago

the fuck is a sovereignOS?

[-] lemmysmash@beehaw.org 3 points 15 hours ago

Judging by the name alone — some hype-exploiting crap, possibly with some backdoors in it, and certainly created for the sole purpose of milking either some public money or naïve users money, whichever would be easier.

[-] moonpiedumplings@programming.dev 17 points 1 day ago* (last edited 1 day ago)

Sovereign OS is pointed out to be source available only in the comments.

GrapheneOS replies to many of the addressed points, and notes that SovereignOS is actually really just a fork that seems to charge for some bs features and preinstalled apps.

[-] LodeMike@lemmy.today 14 points 1 day ago
[-] IceFoxX@lemmy.world -2 points 23 hours ago
[-] LodeMike@lemmy.today 2 points 23 hours ago
[-] IceFoxX@lemmy.world 0 points 22 hours ago* (last edited 21 hours ago)

Just a small sample Qualcomm CVEs – August 2026

CVE-2026-25289
CVE-2026-21366
CVE-2026-24079
CVE-2026-24080
CVE-2026-24084
CVE-2026-25288
CVE-2026-24076
CVE-2026-24078
CVE-2026-24077
CVE-2026-25292

Additional Qualcomm CVEs Affecting Snapdragon

CVE-2022-40514
CVE-2022-40512
CVE-2022-33232
CVE-2022-33279
CVE-2022-25729
CVE-2022-25728
CVE-2022-33216
CVE-2022-33233
CVE-2022-33248
CVE-2022-33225
CVE-2022-33246

(There are probably even more by now anyway) This doesn’t include any of the CVEs from GrapheneOS itself, and those exist as well. Then the GrapheneOS team is explicitly developing for Google hardware or smartphones with closed-source software from Qualcomm—where they have absolutely no access, can’t fix anything at all, etc. They’re explicitly choosing hardware we can't trust.

Since the brainwashed GrapheneOS cult followers just blindly dismiss any criticism anyway, I'm not even going to bother anymore here in the community. You guys won't accept it either way. True to the motto "Hail GrapheneOS"

You blindly trust the underlying hardware, which has its own real-time operating system (RTOS). There's no point in arguing with you about this.

[-] LodeMike@lemmy.today 4 points 22 hours ago

Ah yes I'm sure there's a better alternative /s

These don't prove your point. They're not backdoors. If they were they would have never Bern assigned a CVE.

[-] IceFoxX@lemmy.world -2 points 22 hours ago* (last edited 21 hours ago)

The better alternative? Don't trust any hardware where the software and hardware aren't 100% open. You simply can't trust anything else at all. Hard to understand, isn't it?
I don't feel like arguing with the grapheneOS cult either, because it's pointless. Stay in your bubble.

Project Ara would have been an alternative at one time... That's why Google bought it and put it on hold.

Then there’s the ultimate argument that applies to everything that uses cellular networks... the SS7 protocol Class 1 (normal SMS) CLASS 0 (flash SMS) TYPE 0/Stealth Ping <
( • Technical identifier: The TP-PID byte is set exactly to 0x40 (Short Message Type 0). • Protocol behavior: When this SMS reaches the phone, the baseband (the Qualcomm/Samsung modem chip) reads the header. The standard mandates the following for Type 0: “The device must acknowledge receipt of the message but must neither display the content nor store it in memory.” • The effect: The cell phone receives the SMS. The display remains black, no sound is heard, and the GrapheneOS interface is completely unaware of it. However, the modem chip automatically sends an acknowledgment (ACK) back to the sender via the SS7 network. This cannot be blocked by the GrapheneOS team, etc.

Oh, right—encryption in mobile communications itself ends as soon as the connection switches from a cell tower to satellite communication. In other words, the connection goes from cell phone < encrypted > to cell tower < unencrypted > to satellite. ( https://youtu.be/fM5w7bFNvWI ) However, this applies only to the encryption of the cellular network itself.

GrapheneOS may be the best, but you should treat it as untrustworthy.

BTW, I use Chinese stuff. They're more interested in state secrets and such, and less in my religion, sexual orientation, etc.—the kinds of things the West is increasingly using against its own citizens... I wonder why that Chinese stuff was banned in the U.S.... Yeah, I wonder why...
But you could also, for example, use a Fairphone and remove certain modules yourself.

[-] degen@midwest.social 2 points 13 hours ago* (last edited 13 hours ago)

This is why I just yell everything out the window like a truly rational person

[-] IceFoxX@lemmy.world 1 points 12 hours ago

Keep your cynical sarcasm and keep deluding yourself that grapheneOS is the secure OS, even though it runs exclusively on that specific hardware. Like I said, I’m not interested in the cult—just stay in your bubble.

[-] pmk@piefed.ca 1 points 12 hours ago

If you say "GrapheneOS may be the best, but you should treat it as untrustworthy.", is it fair to single it out as the "BackdoorOS"? It seems more like your position is that no closed source hatdware can be trusted? On that level we also can't trust any software because of Ken Thompsons "Reflections on trusting trust". So is your point that phones/computers can't be trusted in general, or that GrapheneOS is especially unsafe compared to available alternatives?

[-] IceFoxX@lemmy.world 1 points 10 hours ago

In the long run, I’m pinning my hopes on the LibrePhone project, which is reverse-engineering firmware blobs to eventually offer open-source alternatives. I hope to be able to combine that with the Fairphone at some point (which, as I mentioned, already allows you to remove modules like the microphone, camera, etc.). But right now, there simply isn’t any alternative free, open-source firmware yet. So, yes, it’s the best option for now—though it’s still not trustworthy. Especially since old cross-device tracking methods, such as uXDT, continue to play a role there as well.

With PCs and laptops, there isn’t anything completely open-source either, but it’s still easier to run them in a completely isolated environment, because a smartphone that’s completely isolated loses its purpose—that’s the difference.

[-] LodeMike@lemmy.today 1 points 22 hours ago

Why would they use closed source Qualcomm blobs? Are there no Qualcomm modules in the phone?

[-] IceFoxX@lemmy.world 1 points 22 hours ago* (last edited 22 hours ago)

Because the Firmware etc is only closed source xD Qualcom is not a good guy/company Google is not a good company..

this post was submitted on 09 Oct 2026
-15 points (22.2% liked)

Privacy

5266 readers
346 users here now

Icon base by Lorc under CC BY 3.0 with modifications to add a gradient

founded 3 years ago
MODERATORS