

GrapheneOS won’t be affected. The developer verification thing will be handled by another app and won’t be part of the OS. That app won’t have permission to block app installs or anything like that.


GrapheneOS won’t be affected. The developer verification thing will be handled by another app and won’t be part of the OS. That app won’t have permission to block app installs or anything like that.


GrapheneOS will be fine without F-Droid.


At this point GrapheneOS is big enough that there are people who do pay attention to changes and forks that would notice as well.


Well, the fact is it is impossible to target someone with a modified update. The update client sends no IDs to the server, it just fetches static files and determines whether it needs to update or not. The server only has static files.
thet could, in theory, make a single OTA that everybody gets, but checks for a specific IMEI or other device ID and only there enables some malicious payload.
That would be very obvious in the code. And how would devices be targeted if GrapheneOS project members don’t know the unique IDs because they’re not sent in the first place? There are also community members who build GrapheneOS on their own and check if the builds match because GrapheneOS builds are reproducible. It just isn’t possible. But even if people don’t believe all of that, they can still disable the updater app and sideload updates manually. Instructions are on the website.
I may be misunderstanding, but which push? The open source project was started in 2014 and was named GrapheneOS sometime in 2019. You may be seeing more about GrapheneOS because of the Motorola partnership, CalyxOS dying/being on hiatus (so many of their users switched to GrapheneOS), and recent news pushing people to use more private OSes.