GrapheneOS

@GrapheneOS

Open source privacy and security focused mobile OS with Android app compatibility. Community at Freenode and .

Toronto, Ontario, Canada
Joined March 2019

Tweets

You blocked @GrapheneOS

Are you sure you want to view these Tweets? Viewing Tweets won't unblock @GrapheneOS

  1. Pinned Tweet
    23 Apr 2019

    Follow lead developer and owner of the project for regular details on GrapheneOS development and research. This handle will be used for official announcements including releases of GrapheneOS and standalone sub-projects like Auditor. It'll be low volume.

    Undo
  2. 10 minutes ago

    Look at the underhanded way they attempted to get him in trouble with his university and endanger his work on obtaining a doctorate. Meanwhile, they depend on the work of developers like this so they can leech off it and sell and expensive product funding their attacks on them.

    Show this thread
    Undo
  3. 18 minutes ago

    is an earlier example of them threatening a developer (a student) for porting code published by our lead developer in 2015 under the Apache 2 license. We never had any copyright assignment and the work was not done for Copperhead or attributed to them.

    Show this thread
    Undo
  4. 38 minutes ago

    They're dependent on the past and present work of the open source project they're so desperate to harm and destroy. They fraudulently claim ownership and credit for our work. They're building a business based on masquerading as the open source project they're trying to wipe out.

    Show this thread
    Undo
  5. 49 minutes ago

    They're ripping off customers with expensive products putting them at risk rather than protecting them. They're in the business of marketing and branding, not privacy and security. They mislead with fraudulent claims and their response to criticism is misdirection and more lies.

    Show this thread
    Undo
  6. 54 minutes ago

    Copperhead sells an expensive, closed source OS product almost entirely based on forking our past work. The main thing they've done is adding dangerous tracking to the update system to enforce licensing. It seriously lags behind security and OS updates and is not truly hardened.

    Show this thread
    Undo
  7. 1 hour ago

    You can donate to help cover our legal fees: . You can donate via PayPal, Bitcoin or with recurring donations through GitHub Sponsors to the lead developer. PayPal and GitHub Sponsors donations are currently just barely enough to cover ongoing legal fees.

    Show this thread
    Undo
  8. 2 hours ago

    Copperhead filed a baseless lawsuit against our lead developer based on false claims. We've filed counterclaims against them and we're filing our own lawsuit against them based on their fraud. Can read our initial legal response here: Spread the word.

    Show this thread
    Undo
  9. 5 hours ago

    In the meantime, you can manually add the battery optimization exemption via Settings ➔ Apps & notifications ➔ Special app access ➔ Battery optimization where you can select "All apps", scroll down to the Clock app and manually add an exemption. Should get this added upstream.

    Show this thread
    Undo
  10. 5 hours ago

    We're working on a new release fixing another upstream issue with the Clock app from the Android Open Source Project. Our last release fixed many issues with it but introduced some new problems due to moving to a newer target API level. It needs a battery optimization exemption.

    Show this thread
    Undo
  11. Nov 3

    Pixel 2 and 2 XL may get the full November/December security updates in December. There were already firmware security fixes and improvements this month for newer generation devices including GPU firmware with better IOMMU isolation. Our recommendation is moving to a Pixel 4a.

    Show this thread
    Undo
  12. Nov 3

    Pixel 2 and 2 XL are nearing end-of-life and we're be switching to supporting them via separate extended support releases. They've been marked as obsolete instead of legacy devices. Lack of firmware updates this month means they'll be stuck at the 2020-11-01 security patch level.

    Show this thread
    Undo
  13. Nov 3

    GrapheneOS 2020.11.03.03 release: .

    Show this thread
    Undo
  14. Oct 30

    Despite now sending the attestation root with the other certificates in the response, the QR codes will be less dense thanks to an improved static DEFLATE dictionary. It'd still be nice if the new official root was ECDSA rather than RSA or if there were separate roots for each.

    Show this thread
    Undo
  15. Oct 30

    Auditor now has support for the Pixel 4a with either the stock OS or GrapheneOS. It also supports the new key attestation root which may be required for new batches of existing devices. This required changing AttestationServer database and a new version of the Auditor protocol.

    Show this thread
    Undo
  16. Oct 30

    Auditor app version 22 released: . Check the linked release notes for a summary of the notable changes and a link to the full list of commits. See and for info about the app and optional monitoring service.

    Show this thread
    Undo
  17. Oct 25

    Our mail server has used DANE from the beginning. Unlike browsers, there's broad support for it among mail servers. Gmail doesn't support it for political reasons. MTA-STS only provides an equivalent to HSTS without preloading. It relies on DNS security regardless, as do CAs.

    Show this thread
    Undo
  18. Oct 25

    We've replaced the obsolete HPKP header with DANE TLSA records pinning our keys for our important web servers (, , ). Sadly, browsers don't support DANE, but it's trivial to set up and maintain, so why not?

    Show this thread
    Undo
  19. Oct 25

    Experimental releases of GrapheneOS for the Pixel 4a (sunfish) are now available: Auditor doesn't support verifying the Pixel 4a yet. Other problems should be reported to our issue tracker: .

    Undo
  20. Oct 24

    GrapheneOS 2020.10.23.04 release: .

    Undo
  21. Oct 6

    GrapheneOS 2020.10.06.02 release: .

    Undo

Loading seems to be taking a while.

Twitter may be over capacity or experiencing a momentary hiccup. Try again or visit Twitter Status for more information.

    You may also like

    ·