Would you trust an open source software maintained by a developer who you disagree with politically (or otherwise don't like the developer)?
other8026 @ other8026 @lemmy.ml Posts 0Comments 5Joined 1 yr. ago

other8026 @ other8026 @lemmy.ml
Posts
0
Comments
5
Joined
1 yr. ago
Well, the fact is it is impossible to target someone with a modified update. The update client sends no IDs to the server, it just fetches static files and determines whether it needs to update or not. The server only has static files.
That would be very obvious in the code. And how would devices be targeted if GrapheneOS project members don't know the unique IDs because they're not sent in the first place? There are also community members who build GrapheneOS on their own and check if the builds match because GrapheneOS builds are reproducible. It just isn't possible. But even if people don't believe all of that, they can still disable the updater app and sideload updates manually. Instructions are on the website.