# GrapheneOS accuses Murena & iodé of sabotage, pulls servers from France

**URL:** https://discuss.privacyguides.net/t/grapheneos-accuses-murena-iode-of-sabotage-pulls-servers-from-france/33069
**Category:** News
**Tags:** article
**Created:** 2025-11-21T15:48:36Z
**Posts:** 70

## Post 1 by @yes — 2025-11-21T15:48:36Z

> **[GrapheneOS accuses Murena & iodé of sabotage, pulls servers from France...](https://piunikaweb.com/2025/11/21/grapheneos-accuses-murena-iode-of-sabotage-pulls-servers-from-france-over-police-threats/)**
>
> GrapheneOS accuses Murena & iodé of sabotage, pulls servers from France over police "threats," and threatens to "burn" exploit markets by directly helping Google harden Android.

> The drama surrounding GrapheneOS has escalated from a debate over security patches to what looks like full-blown corporate and geopolitical warfare. Following heavy scrutiny in the French press, where the OS was branded a “tool for traffickers,” the GrapheneOS team has initiated a scorched-earth response.

> They are pulling their server infrastructure out of France, openly naming the competitors they believe are orchestrating a smear campaign, and threatening to ruin the exploit market for everyone by contributing directly to Android (AOSP).

> In a series of posts on X (formerly Twitter), the team explicitly named Murena and iodé (the team behind iodéOS) as the likely instigators of the recent negative press in France.

> “It’s very possible Murena and/or iodé are involved. Both are French companies selling products with extraordinarily poor privacy/security. Both are useful to official state plans of locally hosted services with encryption backdoors.”

> GrapheneOS announced it is moving all server infrastructure hosted by OVH (a major French cloud provider) out of the country.

> While the project is a Canadian non-profit, they have historically used OVH for mirrors and discussion servers. That ends now. The team cited a specific passage in the Le Parisien coverage as a “direct threat” from French law enforcement leadership (OFAC), implying that tech providers who do not provide backdoors will face legal consequences.

> The team is moving services to providers in Canada, Germany (Netcup), and the US. They also stated they will no longer travel to France for conferences or hire staff located in the country, citing the French government’s support for “Chat Control” (EU mass surveillance legislation) and “authoritarian” tendencies.

---

## Post 2 by @anonymous480 — 2025-11-21T15:56:29Z

I am conflicted by this story. It seems to me GrapheneOS, as well intentioned as they are, manufactures some sort of drama every 6-12 months so, there is a bit of “cried wolf” aspect to this for me but…

I also think murena & iode are bad faith actors in the privacy space and would not be surprised if these allegations are true.

---

## Post 3 by @jonah — 2025-11-21T15:57:35Z

Interesting, but definitely the right move for them. I was just [saying](https://x.com/privacy_guides/status/1990150298610897395?s=46) it was cool they are hopping on the _actual_ self-hosting train more :blush:

> [@anonymous480](#):
>
> I also think murena & iode are bad faith actors in the privacy space

I haven’t seen much evidence of this but I also don’t pay attention to these two, so who knows. I’d take it with a pinch of salt for sure.

It’s best to just focus on the things GrapheneOS **does** and not pay much mind to the accusations they make. Probably worth looking into deeper sometime, but historically GOS _never_ has the receipts to back up these claims so they’re not worth stressing over.

---

## Post 4 by @anonymous480 — 2025-11-21T16:01:08Z

> [@jonah](#):
>
> It’s best to just focus on the things GrapheneOS **does** and not pay much mind to the accusations they make. Probably worth looking into deeper sometime, but historically GOS _never_ has the receipts to back up these claims so they’re not worth stressing over.

Yeah, after they got embarrassed by [Rossman](https://www.youtube.com/watch?v=4To-F6W1NT0) (where he did have the receipts) its been hard for me take their claims to seriously, so I think its a fair approach to recommend.

---

## Post 5 by @jonah — 2025-11-21T16:02:17Z

> Earlier this week, we reported that GrapheneOS [slammed an unnamed “small company”](https://piunikaweb.com/2025/11/18/grapheneos-slams-unnamed-small-company-over-misinformation-libel-attacks-after-failed-partnership/) for spreading libel and misinformation after a failed partnership. At the time, we speculated that Murena, the company behind /e/OS, might be the company in question.

This article also at least has _some_ of the facts wrong, because we all know here that the “small company” is NovaCustom, so I would take this reporting with a pinch of salt as well.

> **[NovaCustom announces SHIFTphone with iodéOS: Security community concerned](https://www.privacyguides.org/news/2025/11/20/novacustom-announces-shiftphone-with-iodeos-security-community-concerned/)**
>
> Dutch-based computer manufacturer NovaCustom announced that they are selling a configurable version of the SHIFTphone 8.1, a modular smartphone similar to the Fairphone, with iodéOS.

---

## Post 6 by @anonymous480 — 2025-11-21T16:05:05Z

I am stunned you would put into question the integrity of the fine folks at piunikaweb :joy:

---

## Post 7 by @jonah — 2025-11-21T16:05:35Z

Well, not integrity, but research skills. Perhaps they mean well :rofl:

---

## Post 8 by @anonymous480 — 2025-11-21T16:05:53Z

I am sure they spent atleast 15 minutes googling it, sir!

---

## Post 9 by @plus-subzero — 2025-11-21T17:24:34Z

They don’t manufacture any “drama”. They might be a bit reactive or premature in their comms but their decision to ditch OVH and limit other exposure to France is what anyone who uses GrapheneOS would expect them to do.

GrapheneOS just threatens both law enforcement and the cottage industry of “secure,” “privacy‑focused” bottom of the barrel devices peddled to unsuspecting buyers. I wouldn’t bet on it, but it sounds plausible, and competitors do it to each other all the time.

They’re also a great source of knowledge on security, privacy, and Android, and their (repackaged) X threads drive traffic to publications like the one above at no cost, hence all the noise.

---

## Post 10 by @jonah — 2025-11-21T17:59:58Z

> [@plus-subzero](#):
>
> their decision to ditch OVH and limit other exposure to France

This is very obviously not the “drama” that’s being commented on here :slight_smile:

---

## Post 12 by @anon57441094 — 2025-11-21T18:48:33Z

I was reading this on their Mastodon instance, and it really is an example of “separate the creator from the creation.” I use GOS, I really like they add more security and privacy features than stock Android (and are currently using patches up to March 2026), but their lashing out really leaves a sour taste for potential users. They do have some receipts for Murena and iode in a forum post, where they show that those companies faked the level of their security patches while being several months behind. There have also been a few articles that misquoted or distorted their quotes, which they also have shown the receipts for (this latest article about them being used for criminals in France is an example of this happening). Is their tone unprofessional? Absolutely. Are they the most secure and private mobile OS, that has helped countless people? Also absolutely. I’m sure this will push some people off using GOS, but if you can ignore stuff like this, there really isn’t another choice for Android users who value their security and privacy.

---

## Post 13 by @Pragmatic — 2025-11-21T19:12:20Z

I love GOS, I support them wholeheartedly and I am very active on their forums and networks.

But I feel like they spend every month complaining on social media as if the whole world is against them specifically, making allegations or wanting the GOS project to fail (I don’t understand why) and overreacting (the fact that they left the French market following a smear piece written by the newspaper Le Parisien).

I don’t understand why they don’t just ignore these allegations. It gives the impression that they are always trying to justify themselves, and I think that gives them a bad image.

---

## Post 14 by @anon36227541 — 2025-11-21T19:30:22Z

> [@jonah](#):
>
> It’s best to just focus on the things GrapheneOS **does** and not pay much mind to the accusations they make

> [@jonah](#):
>
> historically GOS _never_ has the receipts to back up these claims so they’re not worth stressing over

I love GOS, and I use it for my private phone. But I think we all agree that they should be held accountable for these kinds of attacks. They’ve attacked Techlore, from what I remember. It is not best to let it go. But I do not know the best way to proceed with this in mind.

---

## Post 15 by @Anvil — 2025-11-21T19:40:43Z

> [@Pragmatic](#):
>
> smear piece written by the newspaper Le Parisien

I don’t speak French so some of the meaning may have been lost after being run through translation software, but [this article](https://www.leparisien.fr/faits-divers/google-pixel-et-grapheneos-la-botte-secrete-des-narcotrafiquants-pour-proteger-leurs-donnees-de-la-police-19-11-2025-NTGPQE4JCNGEHLF7XGIQ3CCA2I.php) didn’t really seem that bad to me? Apart from the clickbait headline I suppose. The quotes from the police are pretty questionable, but it seems clear to me that that’s the police talking and not the author. They reached out to GrapheneOS for comment and represented their side of the story decently well I thought.

Am I missing something?

---

## Post 16 by @jonah — 2025-11-21T19:50:35Z

I think GrapheneOS’s (valid tbf) point is that when a Ford F-150 is used in a bank heist you don’t see Ford mentioned in the headlines, or when a ring of hackers is caught and they’re using MacBooks there aren’t stories about how Apple enabled them.

If _true_ security and privacy are your _focus_ as a project, you get a bad rap in the media. Unfortunately it is hard to take GrapheneOS seriously on this topic because they do the same to other security/privacy projects instead of uplifting the community, but it is a serious problem in general nonetheless.

---

## Post 17 by @anon51983832 — 2025-11-21T20:10:12Z

Unpopular opinion:  
GrapheneOS doesn’t do good marketing, but I imagine they simply don’t care. They only aim to tell the truth and defend their principles/philosophy. Their approach isn’t always optimal and could be more constructive, but I believe they already do enough with what they do (it’s too much to additionally demand that they should be empathetic and didactic). On the other hand, I find that level of paranoia logical: no one wants to be targeted by governments or by the largest oligopoly ever to exist (the tech giants) who maintain surveillance levels we’ve never seen before.

Therefore, they are neither a company nor politicians; their goal is not profit, so they are free to say whatever they want. And this is precisely what hurts most to those who seek profit at the expense of their users’ privacy and security (sometimes even lying). I can imagine, at times, the frustration caused by seeing certain projects marketed as something they are not.

---

## Post 18 by @anon36227541 — 2025-11-21T20:15:18Z

> [@anon51983832](#):
>
> They only aim to tell the truth

I don’t think they gave adequate proof that Murena and Iode worked to sabotage/smear their image wrt to the France government. If they did, IDK. But the tweet they posted did not provide any from the looks of the article.

> [@anon51983832](#):
>
> I find that level of paranoia logical: no one wants to be targeted by governments or by the largest oligopoly ever to exist

Their paranoia is justified wrt to oligarchic and government surveillance. I think that’s clear as day, since we are in a digital privacy forum. We all know that our privacy is in danger to some extent. The issue is that they claimed someone is smearing them. That may or may not be true, but they go a step further to give out specifics without good justification.

---

## Post 19 by @jonah — 2025-11-21T20:17:04Z

If GrapheneOS only told the truth then I don’t think anyone would have a problem with them. The problem is their constant speculation, not to mention the verifiable lies they tell to “defend their principles/philosophy.”

They need to do **both** of those things, not **only** the defense part. It’s fantastic when they actually do both things, which they _do_ all the time, just not consistently enough. When they do both things we see an outpouring of support from this community and others for their statements, so it would be a huge improvement for them if that were the case every time they wanted to get a message out :slight_smile:

---

## Post 20 by @plus-subzero — 2025-11-21T20:51:42Z

> [@jonah](#):
>
> Unfortunately it is hard to take GrapheneOS seriously on this topic because they do the same to other security/privacy projects instead of uplifting the community

They have never blanket-talked down other security and privacy projects without backing up their claims. It’s not their job to lift all boats with their tide just because other organizations purport to have the same mission. If something has merit, they’ll endorse it. If it doesn’t, they have a habit of shining a light on the issue. Moxie blocked them for criticizing features based on SGX, but they continue to endorse Signal. Proton has backed them financially and I believe even offered legal help at one time or another, but they criticize them for relying solely on FCM for push messaging and for unresolved memory corruption bugs uncovered by their MTE implementation.

Yes, they may not offer all the receipts vis-à-vis one drama or another, but that’s beside the point.

---

## Post 21 by @privacy.slouchy — 2025-11-21T21:02:02Z

This is pretty much my takeaway. I don’t expect GOS wastes money on PR or marketing specialists. And I don’t doubt these statements come from an honest, well intentioned place. They’re just unpolished, occasionally reactionary

Perceive an external attack against GOS, throw some words online in response, get back to coding. This process doesn’t upset me

---

## Post 22 by @anon57862721 — 2025-11-21T21:06:24Z

Reading this comment inspired me to ask a better question as I see it here [How to best evaluate privacy tech/products and the company/team behind them?](https://discuss.privacyguides.net/t/how-to-best-evaluate-privacy-tech-products-and-the-company-team-behind-them/33080) in order to have a more holistic discussion about the matter at large here.

What do you think?

---

## Post 23 by @plus-subzero — 2025-11-21T21:13:37Z

> [@anon36227541](#):
>
> I don’t think they gave adequate proof that Murena and Iode worked to sabotage/smear their image wrt to the France government.

I believe [“possible”](https://xcancel.com/GrapheneOS/status/1991610031478042948#m) qualifies as a statement of speculation here, not an accusation, in a mere reply to another user, too

Edit: typo

---

## Post 24 by @Quantum — 2025-11-21T21:17:12Z

> [@plus-subzero](#):
>
> They have never blanket-talked down other security and privacy projects without backing up their claims

I can think of two examples immediately. Their attacks on Techlore and Trail of Bits/iVerify were baseless.

---

## Post 25 by @anon36227541 — 2025-11-21T21:21:11Z

Perhaps my issue, then, is how the article frames their speculation: “GrapheneOS _accuses_ [emphasis mine] Murena & iodé of sabotage”, as per Jonah:

> [@jonah](#):
>
> This article also at least has _some_ of the facts wrong, because we all know here that the “small company” is NovaCustom, so I would take this reporting with a pinch of salt as well.

I still stand my ground that they should be held accountable for the accusations they throw at other people, outside of this article. They have a history of this, with accusations involving Techlore and Privacy Guides, among others.

But this is a very different topic, not related to the article at all. We should make a new thread if anything to discuss their overall history of accusations and how rightful or wrongful, helpful or hurtful it is.

---

## Post 26 by @jonah — 2025-11-22T02:28:04Z

Yes, this is just not a good article to be honest lol

---

## Post 27 by @byesun — 2025-11-22T04:29:28Z

> Unfortunately it is hard to take GrapheneOS seriously on this topic because they do the same to other security/privacy projects instead of uplifting the community

I think the issue here is that GrapheneOS is focused on security. Privacy is secondary. In contrast, Murena and friends are less secure but more private than stock (not sure to what degree in terms of privacy since IIUC they have their own services and I haven’t really looked into them because their devices are insecure). IMO the main problem is they’re talked about as if they’re the same, so GrapheneOS and Murena and friends get brought up together pretty often, which I’m guessing really annoys GrapheneOS.

---

## Post 28 by @privacy.slouchy — 2025-11-22T05:15:04Z

> I think the issue here is that GrapheneOS is focused on security. Privacy is secondary

I feel this is very untrue. Privacy is GOS’s main goal, as per their stated goals on the [their own site](https://grapheneos.org/). Security hardening is a close second.

Im unfamiliar with Murena, so I can’t speak towards any comparisons

---

## Post 29 by @byesun — 2025-11-22T05:39:15Z

> I feel this is very untrue. Privacy is GOS’s main goal, as per their stated goals on the their own site. Security hardening is a close second.

Where on their website does it say privacy is their main goal? The home page that you linked always says “privacy and security.” If you’re just judging by the order they are presented, the FAQ says “security and privacy,” and privacy comes before security alphabetically.

If there were a situation where they had to choose between privacy or security for a specific feature, I fully expect that they would choose security. A basic example is microG vs. sandboxed Google Play, or how they recommend using the Play Store instead of alternatives.

---

## Post 30 by @privacy.slouchy — 2025-11-22T06:15:44Z

[Here is a list](https://grapheneos.org/features) of GOS features. Many focus on privacy to an extent I haven’t seen in alternatives

[Here’s a good thread](https://discuss.techlore.tech/t/how-private-is-using-the-sandboxed-google-play-services/454) on MicroG. Users have less control over the data it can access, opposed to GOS sandboxed Play services. It’s less private

Im not sure what you mean with the installer note. The only stores recommended after Play are Aurora & F-Droid. That’s a debate I don’t care to explore. But I think Accrescent is their first recommendation

---

## Post 31 by @byesun — 2025-11-22T07:45:07Z

I am not saying they don’t care about privacy, I am saying they care about security _more_ than privacy. Note that I think this is a _good_ thing.

Regarding microG, from what I understand (I don’t use it), you can choose to simply not use a number of features that require network connections. You can sort of do this with sandboxed Play Services, but if you enable network access, you don’t really know what it’s sending to Google.

For the installers, they recommend using the Play Store followed by Accrescent (which has nearly no apps, so it’s pretty much insignificant atm), and they do not recommend F-Droid or Aurora (I don’t recommend Aurora either, just FYI). The Play Store requires a Google account, and it requires giving Play Services network access, among other negatives (some of which also apply to Aurora). They recommend the Play Store because it is more secure than using Aurora. They recommend grabbing apps from GitHub directly (which may require a token identifying your GitHub account if you have a lot of apps and use Obtainium) rather than using F-Droid because it is more secure (at least in their opinion, don’t want to argue about this).

---

## Post 32 by @privacy.slouchy — 2025-11-22T07:52:40Z

Alright yeah I agree with all of this, have an internet point. I don’t have a quantitative method to compare the weight they put on privacy vs security

---

## Post 33 by @anon61753997 — 2025-11-22T09:30:52Z

> [@byesun](#):
>
> In contrast, Murena and friends are less secure but more private than stock (not sure to what degree in terms of privacy since IIUC they have their own services and I haven’t really looked into them because their devices are insecure).

[GrapheneOS’s developers have accused Munera of sending user speech data to OpenAI](https://discuss.grapheneos.org/d/24134-devices-lacking-standard-privacysecurity-patches-and-protections-arent-private). However, I’m not sure if this was/is true or not because I also don’t use their services.

> The Murena voice-to-text service included in /e/OS even sends user speech data to OpenAI with no local option compared to Apple and Google both offering offline speech-to-text support via local models which users can make sure is always used.

* * *

> [@byesun](#):
>
> Regarding microG, from what I understand (I don’t use it), you can choose to simply not use a number of features that require network connections. You can sort of do this with sandboxed Play Services, but if you enable network access, you don’t really know what it’s sending to Google.

From the GrapheneOS’s developers’ eyes, the problem is not microG per se.

> DivestOS, which has been discontinued, had mostly (not fully) unprivileged integration for microG unlike /e/OS and CalyxOS where it’s privileged. /e/OS and CalyxOS also have privileged integration for Android Auto and other Google apps/services. If you install Android Auto on /e/OS or CalyxOS, it’s a highly privileged app not running in the regular app sandbox and also receives extensive privileged access via special permissions only available to OS components. microG is similar.

TLDR: DivestOS using microG is fine because it has unprivileged access. Others using microG is not fine because it has privileged access.

* * *

> [@byesun](#):
>
> For the installers, they recommend using the Play Store followed by Accrescent (which has nearly no apps, so it’s pretty much insignificant atm), and they do not recommend F-Droid or Aurora (I don’t recommend Aurora either, just FYI). The Play Store requires a Google account, and it requires giving Play Services network access, among other negatives (some of which also apply to Aurora). They recommend the Play Store because it is more secure than using Aurora. They recommend grabbing apps from GitHub directly (which may require a token identifying your GitHub account if you have a lot of apps and use Obtainium) rather than using F-Droid because it is more secure (at least in their opinion, don’t want to argue about this).

Believe it or not, [Privacy Guides generally concur with this](https://www.privacyguides.org/en/android/obtaining-apps/), except for the Play Store part.

---

## Post 34 by @TinFoilHat — 2025-11-22T10:23:21Z

GOS team always emphasize no true privacy without security.

It is definitely true, but the true privacy they refer to is not what nomies like us think or desperately need.

The threat model hey used to develop GOS, assumes user will be facing the worest adversaries anyone could have, government.

So in their sense, yes, security does come first, and it is a good thing for everyone, cause we have a golden standard to follow.

* * *

I wont be too caught up by GOS TEAM’s way of saying things, and quite often they force their own pride and idea on others. We only need to focus and discuss on what they say, not how they say it.

---

## Post 35 by @anon59241451 — 2025-11-22T12:53:37Z

> GrapheneOS is a privacy project above everything else. Our work on security is to protect privacy, so it’s not a separate thing.

> **[Pixel 10 - production support for GrapheneOS coming soon!: Page 10 -...](https://discuss.grapheneos.org/d/25099-pixel-10-production-support-for-grapheneos-coming-soon/199)**
>
> GrapheneOS discussion forum

Privacy without the security to enforce it is like [shōji](https://en.wikipedia.org/wiki/Shoji)—it only works if everyone plays along.

---

## Post 36 by @privacyisconsent — 2025-11-22T13:24:02Z

> [@privacy.slouchy](#):
>
> I don’t expect GOS wastes money on PR or marketing specialists.

If I am not mistaken, didn’t they hire a community manager? Or are they not a paid member of the team?

---

## Post 37 by @anon32162901 — 2025-11-22T14:55:21Z

> [@Quantum](#):
>
> I can think of two examples immediately. Their attacks on Techlore and Trail of Bits/iVerify were baseless.

I missed the Trail of Bits attack. What was that about?

Not sure how I feel about Trail of Bits. Their Algo script was useful back in the day when I needed to roll my own WireGuard tunnel, but that’s the only interaction I’ve had with their products. Recently read something somewhere about them (allegedly) working with Palantir, which didn’t sound so good.

---

## Post 38 by @Quantum — 2025-11-22T14:58:32Z

PalantIr is a customer of their iVerify product. Which is related to the GOS baseless attack when they called iVerify malware because they were upset with iVerify making a big deal of a default app on Pixel devices that had admin access.

The offending app was a defunct demo app for Verizon branded Pixels that somehow was kept in all Pixel production software at the time. iVerify running on PalantIr company Pixels flagged it as a security concern. PalantIr then banned Pixels from their use as company phones and went all iPhone. Which further enraged GOS…

---

## Post 39 by @dngray — 2025-11-22T15:44:24Z

> The accusations from GrapheneOS come in response to articles by _Le Parisien_ and _Le Figaro_, which claimed criminals use a version of GrapheneOS equipped with a “fake Snapchat” page that wipes data when accessed.

:rofl: :rofl: I have been using GrapheneOS on Pixel 3A XL, and 7 Pro, and now 9 Pro XL, and this has never been a feature. Just sloppy reporting, because like it would have like taken them really no effort to actually try GrapheneOS.

> The team cited a specific passage in the _Le Parisien_ coverage as a “direct threat” from French law enforcement leadership (OFAC), implying that tech providers who do not provide backdoors will face legal consequences.

If that’s the case they did the right thing, because by the sound of it this backdoor would not be a targeted approach because there is no login or unique identifiers to use GrapheneOS. These agencies do not at all sound legitimate with these requests, guess that’s why its done with secrecy. This kind of behavior is exactly the same as what you can expect [over here](https://discuss.privacyguides.net/t/hands-on-with-north-korea-s-illegal-phones/).

> By hardening the base Android code, GrapheneOS would effectively “burn” the expensive exploits used by police and forensic firms like Cellebrite, making _all_ Android phones harder to crack, [not just Pixels running GrapheneOS](https://piunikaweb.com/2025/10/31/google-pixel-more-secure-with-grapheneos-than-stock-android/).

As they should, as these are used by all criminals, including criminal authorities in criminal states (If you need to know about which ones I am thinking of, just think about the worst most restrictive places on earth).

---

## Post 40 by @judgeadam — 2025-11-22T16:04:15Z

Realistically though, if I had to choose between someone making a security focused OS that thinks the world is against them or loves everyone in the world, I’m going to pick the former every time LOL.

I use GOS and specifically got the Pixel for it after all the shit in Britain. If they think everyone is out to get them it can only be better for us, the GOS user. Besides it may be true at least in part.

Whats the saying? Just because youre paranoid doesn’t mean they aren’t out to get you.

---

## Post 41 by @Labfox — 2025-11-22T20:17:58Z

FIY national french television (France Info) just aired a small documentary on the “drug dealer dual use phone” (Not the exact title but this was pretty much what it meant), relaying the police’s information and treating it as the absolute truth.

---

## Post 42 by @anon39279085 — 2025-11-22T20:19:21Z

well I guess Graphene had every right to be paranoid at this point

big OOF that’s bad for GrapheneOS’s reputation

---

## Post 43 by @anon57862721 — 2025-11-22T20:24:54Z

Personally, I don’t think reputation is what “sells” their product. They are a non profit with a sharp tongue and questionable bedside manners at times. When it comes to a threat model for which they make software, no one using it for what it is built cares about reputation but only quality.

This relates to a post I made about how to evaluate products and people behind them. Always depends on where each stands for what they value.

---

## Post 44 by @Labfox — 2025-11-22T20:25:17Z

I don’t think they mentioned GrapheneOS, but their logo was definitely shown several times

---

## Post 45 by @anon39279085 — 2025-11-22T20:26:13Z

I get it but put the shoes of a boomer where you dont even know anything and your boomer person just now has the mindset that GrapheneOS = Bad, that’s the problem, also only because they “saw it on TV”

---

## Post 46 by @anon57862721 — 2025-11-22T20:26:41Z

Yeah, you have a point about it. Optics is not great. But what I said still stands though.

---

## Post 47 by @mrprivac — 2025-11-23T10:26:45Z

BTW, I’ve looked up [piunikaweb.com](http://piunikaweb.com) Whois and joining that information with the fact that AFAIK, that’s not a noteworthy news source, to me [piunikaweb.com](http://piunikaweb.com) looks like a façade / propaganda news site.

We may be discussing _nothing._

---

## Post 48 by @dngray — 2025-11-23T13:46:50Z

> [@Labfox](#):
>
> relaying the police’s information and treating it as the absolute truth

When media does that they just become a propaganda arm of the state. Those organizations most certainly have political agendas, usually to be granted more power because they think it will make their job easier. Responsible media does fact checking and doesn’t facilitate lies regardless of who they are from.

---

## Post 49 by @Labfox — 2025-11-23T14:15:42Z

France Info is indirectly state-owned media (according to [Wikipedia](https://en.wikipedia.org/wiki/France_Info), all of the owners are public companies), so it isn’t _that_ surprising of them.

---

## Post 50 by @Labfox — 2025-11-23T14:19:46Z

Here’s the written counterpart: [Narcotrafic : la traque des services de police se heurte à l'innovation technologique](https://www.franceinfo.fr/societe/drogue/narcotrafic-la-traque-des-services-de-police-se-heurte-a-l-innovation-technologique_7634603.html) . (There’s part of the video documentary on top, but IIRC it was longer)

---

## Post 51 by @slinky3486 — 2025-11-24T01:33:51Z

Here another article (in french, if you need full context no problem i speak french too) [« Nous ne nous sentons plus en sécurité en France » : pourquoi GrapheneOS retire ses serveurs de France suite à un article du Parisien](https://www.frandroid.com/android/2881329_nous-ne-nous-sentons-plus-en-securite-en-france-pourquoi-grapheneos-retire-ses-serveurs-de-france-suite-a-un-article-du-parisien) They explain quickly what is GrapheneOS for those that don’t know, explain where the confusion between GrapheneOS and Le Parisien/the french police steam from and that basically both actors (Le Parisien and french police) just don’t understand GrapheneOS and blame them for something totally out of their control, the drug dealers use a heavily modified version of GOS since its open-source. And with the support of France for “Chat Control” i think the reaction of GOS is understandable.

---

## Post 52 by @anon57621611 — 2025-11-25T20:42:00Z

I just wish GrapheneOS team published just one official blog post or social media post and ignored all the trolls that are baiting them to over-react. As far as I can see, there is a reply from their official account on all of their social media every 10-20 minutes. Just chill. People already think that Daniel Micay is the guy writing all of that and I really wish that they would slow down and act more serious.

Moving out of France (where I live) is a smart choice and I’m all in team GOS here. But please, hire someone to do the official PR because the current situation is bad and it stains the entire project for some people.

I know couple of my friends who uninstalled GOS because of this.

---

## Post 53 by @KevPham — 2025-11-25T21:36:32Z

I’m surprised that they haven’t done that already. There is nothing wrong with writing up a professional press release or a series of blogs debunking these rumors. GrapheneOS has a significant enough presence to warrant one.

---

## Post 54 by @anon57621611 — 2025-11-25T21:44:31Z

I did write the same thing on the official GOS forum and the reply was that they are a team and not a company. They aim to respond fast and engage directly and they don’t do corporate PR.

Fair enough.

“I” would feel safer if they spend less time engaging with every troll out there but I can see the point that they are trying to make.

---

## Post 55 by @Anonymous95 — 2025-11-26T02:45:45Z

I don’t know why GrapheneOS can’t just play nice. They seem to regularly stir up unnecessary drama and create hostility. GOS seems like a great product, but I wish the people involved who are responsible for this sort of internecine mudslinging would cut it out.

---

## Post 56 by @Menkork — 2025-11-26T03:12:59Z

The folks over there are doing great work, and I’m absolutely not questioning that part. The issue is that they really need a publicist. A lot of the messaging can come across as offputting, and without someone who actually understands how to shape and deliver that message, it ends up looking like you’re talking trash in a Counter Strike lobby instead of speaking to people in good faith.

It does serious damage to how people see them. When the quality of what you’re building and the tone of how you talk about it are that far apart, people stop focusing on the work and only remember the attitude. It’s not only what you say, it’s also how you say it.

Getting someone in their corner who knows how to communicate would do wonders for their credibility. Because again, they legitimately are doing good work, and do have good intentions. And if you don’t have any media training, oh boy, is that ever going to come back to bite you.

Like others have said, they should start putting together proper press releases and bring in a small team that can present what they’re doing with more care and clarity.

---

## Post 57 by @farmwithme021 — 2025-11-26T03:26:43Z

> [@anonymous480](#):
>
> I am conflicted by this story. It seems to me GrapheneOS, as well intentioned as they are, manufactures some sort of drama every 6-12 months so, there is a bit of “cried wolf” aspect to this for me but…

Tbh this drama shit is one of the selling points for me. Imho you cant be an ultra paranoide security specialist/enthusiast (not save job at uni and a bit of pentesting as side, I mean conviction like GOS project) without being a bit loony in the head and maybe drama queen :grin:

---

## Post 58 by @jonah — 2025-11-26T03:32:23Z

> [@anon57621611](#):
>
> they don’t do corporate PR.

> [@Menkork](#):
>
> And if you don’t have any media training

This makes it sound like people are demanding some big ordeal from GrapheneOS. Plenty of people communicate without media training. I can write all sorts of stuff for _Privacy Guides_ just being a normal guy from Minnesota without creating constant tension, and it’s not like I’m formally trained on this.

PR and media training for GrapheneOS would be extreme overkill, IMO. The bar can be much lower than that.

---

## Post 59 by @deimos — 2025-11-26T03:53:47Z

I agree with everyone that they need to write a single technical response, at the time of their choosing, and get back to work. Nothing good comes from engaging the ignorant.

In my experience, being 1) de-banked, 2) having to defend why we shouldn’t be put on the OFAC Sanctions list, 3) charged with criminal violation of US encryption export laws, GrapheneOS needs to stop running from bullies and fight. Stand your ground and fight. Running away from a bully just encourages them to bully others. Running from France just confirms the French government is correct; whether they are behind this or not. All users of GOS in France are now suspect because GOS couldn’t be bothered to fight. Support your users and they will support you.

If you’re going to produce privacy enhancing technologies, then be prepared to fight those who rather wish you didn’t exist. I found a groundswell of quiet support from people in the fight 15 years ago.

No one cares what some blogger or some talking head claims while trying to sell ads. They do now because GOS legitimized the dumbest arguments. Not everyone is going to like you, and you’ll die a hopeless death trying to make everyone happy. Pick your battles and stand your ground. You will be amazed how many paper tigers there are out there.

All this nonsense shows the world that 1) GOS is scared, 2) they aren’t smart enough to pick their battles, 3) they run at the dumbest feints. As was said earlier in this thread, GOS really needs a professional publicist and media manager.

Those who matter don’t mind. Those who mind don’t matter.

---

## Post 60 by @dngray — 2025-11-26T04:14:57Z

> [@deimos](#):
>
> All this nonsense shows the world that 1) GOS is scared, 2) they aren’t smart enough to pick their battles, 3) they run at the dumbest feints. As was said earlier in this thread, GOS really needs a professional publicist and media manager.

To be honest I doubt they had any real infrastructure in France to begin with, so changing server location for hosting a website is a lot cheaper than legal costs for fighting something which isn’t particularly useful to them anyway.

I think its that the french media outlets wrote some uninformed trash and didn’t really bother to do any real research.

---

## Post 61 by @jonah — 2025-11-26T04:22:26Z

> [@dngray](#):
>
> I think its that the french media outlets wrote some uninformed trash and didn’t really bother to do any real research.

I can’t share a link because GrapheneOS hasn’t unblocked me yet, but that is not at all what they are claiming on X.

---

## Post 62 by @dngray — 2025-11-26T04:37:04Z

I mean the bit about:

> The accusations from GrapheneOS come in response to articles by _Le Parisien_ and _Le Figaro_, which claimed criminals use a version of GrapheneOS equipped with a “fake Snapchat” page that wipes data when accessed.

Obviously we know no such feature exists.

> French police are likely conflating the official OS with illegal, closed-source forks sold on the black market, similar to the Anom sting operation, where the FBI distributed compromised devices running a custom OS to catch criminals.

There may very well be grifters trying to sell closed sourced forks of GrapheneOS. I think also it probably could have been cleared up in a simple email that no such feature exists and that is not a part of GrapheneOS. It’s unclear whether or not GrapheneOS has been approached by the French specifically in relation to introducing a backdoor.

---

## Post 64 by @whoami4 — 2025-11-27T15:50:39Z

Why was my post hidden? I just stated that I don’t use GOS because I think they are not stable and trustworthy. And I think so because again they are accusing that somebody is targeting them (without proof). Why can’t I voice my opinion?

---

## Post 65 by @anon57862721 — 2025-11-27T15:57:04Z

> [@whoami4](#):
>
> I just stated that I don’t use GOS because I think they are not stable and trustworthy.

This is objectively incorrect because they are functioning just fine and make a great OS that speaks for itself regarding trustworthiness. They are FOSS - they can’t be more transparent than they already are.

I don’t know how else you meant it but that’s what it reads like so that’s how people are going to take it.

Also, it is not inaccurate that the French are indeed behind them to get GOS back doored. The story was still developing when this post was originally posted.

You can voice your opinion, just don’t wrote it as a conclusive claim. It would read like misinformation otherwise. You wrote your first comment differently.

–

Anyways, that’s just my assessment. I could be wrong.

---

## Post 66 by @whoami4 — 2025-11-27T16:09:27Z

You know what, it doesn’t matter. On re-read I wrote it kind of passively aggresively. Thank you for the reply I appreciate it. I think it is important what character are people behind a project and that FOSS is not a guarantee of safety (though its a big plus for sure). With that I will leave it be. Once again thanks for the reply.

---

## Post 67 by @anon57862721 — 2025-11-27T16:21:49Z

> [@whoami4](#):
>
> I didn’t explain why my opinion is the above. I thought it was clear since I am commenting under the

It’s not always obvious what’s an opinion and what’s a claim - choice or words and lexicon matters along with context. You not explaining in the first comment was likely why.

---

## Post 68 by @whoami4 — 2025-11-27T16:28:50Z

You are right, I was not fully focused on what I wanted to say and I kinda half-assed that post.

---

## Post 69 by @Menkork — 2025-12-08T04:13:01Z

Oh, absolutely. The work you do is phenomenal. Under normal circumstances, the average Joe can handle this kinda of thing easily. It’s a layup. Not everyone is a good communicator, and that’s totally OK. PR still isn’t even necessary at that point at all. But when multiple people and sources start saying someone is actively a hostile communicator, that’s when we need to start taking a step back.

I might be biased viewing this as a publicist, they don’t need someone on a permanent retainer, but they at least need a one month campaign to tidy things up, get the ball rolling, and work on communication skills. There are small firms, that aren’t expensive at all, even for mom and pop shops, fundraisers, and local bands, and they do absolute incredible work for them.

It doesn’t have to be overly corporate or anything like that to make it overkill. But if they are not going to designate someone with social skills and who’s good at communicating within the team, they would benefit from it significantly. Like I said, not everyone’s a good talker. Even though I’ve done PR, I think a dying porpoise could slap its fin on the keyboard and sometimes make a more coherent sentence than me.

It isn’t just the current situation with how they communicated about the stuff in France. It’s the aggressive messaging on forums, the Gecko situation, the developer make quite the accusation suggesting Techlore faked screenshots, and those message logs to Rossmann were wild.

It is a wonderful product, but the communication inflicts severe damage to the brand unless you truly are a die hard. Which you can make the argument if you’re using this OS, you already are and that’s fair to say.

Heck, I can see why some firms might refuse them as clients. Again, looking at this from a PR perspective, their communication is exceptionally bad, and it risks doing real harm at a time when the media is already unfairly labeling them.

This isn’t even a new issue with them, there’s already historic liability here from other projects. They’re probably going to have to put out statements and respond to some crazy allegations. You want someone sounding professional, not someone who sounds like they’re on Xbox Live.

Because when you’re dealing with journalist, you’re walking through a minefield. Even well intentioned steps can blow up, but stomping around angrily guarantees an explosion.

---

## Post 70 by @coldiron — 2025-12-08T20:54:44Z

Hang on, they blocked you on X? Why lol. I’m confused–I’m in the process of maybe switching to GOS and am just not happy about some things like this.

Related, are you an iPhone or GOS user?

---

## Post 71 by @jonah — 2026-06-29T19:45:26Z


