石墨烯操作系统 迁出法国
GrapheneOS Moving Out of France

原始链接: https://xcancel.com/GrapheneOS/status/1993035936800584103

该项目正在积极迁移基础设施,远离OVH和法国,原因是日益增长的对政府要求加密后门和设备访问的担忧,认为该国对注重隐私的开源工作不安全。 迁移包括轮换安全密钥(TLS、Let's Encrypt、DNSSEC)以及加强应用商店、系统更新(具有多层加密验证和降级保护)和更新镜像的安全措施。目前的镜像托管在ReliableSite和Tempest,并计划扩展。DNS和网站基础设施正在迁移到Vultr和BuyVM。 剩余服务(电子邮件、Matrix、论坛、Mastodon)目前位于OVH加拿大服务器上,短期内将迁移到Netcup,然后迁移到多伦多的机房。该团队也面临日益增加的骚扰和破坏,影响了像Pixel 10支持等计划中的开发,并欢迎在此困难时期提供支持。

## GrapheneOS 与法国法律 - Hacker News 讨论 最近一篇 Hacker News 帖子讨论了 GrapheneOS 决定离开法国,引发了关于数字权利法律差异的争论。核心问题在于保持沉默和自证其罪的权利。 加拿大和美国保护个人不提供密码或 PIN 以避免自证其罪的权利,而法国则将拒绝提供视为犯罪。用户指出法国目前有一宗案件,被告因拒绝提供加密密码而被判藐视法庭,这凸显了与北美已建立权利之间的冲突。 讨论质疑这种法律立场是否反映了“民主价值观”的差异,从而引发了关于民主定义和不同法律系统重要性的进一步辩论。最终,该帖子强调了在一个被认为对数字隐私具有限制性的法律框架内运营 GrapheneOS 等安全项目所带来的担忧。
相关文章

原文

We no longer have any active servers in France and are continuing the process of leaving OVH. We'll be rotating our TLS keys and Let's Encrypt account keys pinned via accounturi. DNSSEC keys may also be rotated. Our backups are encrypted and can remain on OVH for now. Our App Store verifies the app store metadata with a cryptographic signature and downgrade protection along with verification of the packages. Android's package manager also has another layer of signature verification and downgrade protection. Our System Updater verifies updates with a cryptographic signature and downgrade protection along with another layer of both in update_engine and a third layer of both via verified boot. Signing channel release channel names is planned too. Our update mirrors are currently hosted on sponsored servers from ReliableSite (Los Angeles, Miami) and Tempest (London). London is a temporary location due to an emergency move from a provider which left the dedicated server business and will move. More sponsored update mirrors are coming. Our ns1 anycast network is on Vultr and our ns2 anycast network is on BuyVM since both support BGP for announcing our own IP space. We're moving our main website/network servers used for default OS connections to a mix of Vultr+BuyVM locations. We have 5 servers in Canada with OVH with more than static content and basic network services: email, Matrix, discussion forum, Mastodon and attestation. Our plan is to move these to Netcup root servers or a similar provider short term and then colocated servers in Toronto long term. France isn't a safe country for open source privacy projects. They expect backdoors in encryption and for device access too. Secure devices and services are not going to be allowed. We don't feel safe using OVH for even a static website with servers in Canada/US via their Canada/US subsidiaries. We were likely going to be able to release experimental Pixel 10 support very soon and it's getting disrupted. The attacks on our team with ongoing libel and harassment have escalated, raids on our chat rooms have escalated and more. It's rough right now and support is appreciated.

联系我们 contact @ memedata.com