Edge Rewrite
// HTMLRewriter · presentation

This page was redesigned at the edge.

Cloudflare fetched the original article and streamed it through HTMLRewriter to apply an entirely new visual system without rebuilding the source page.

// request.cf · coarse context

A page that knows where it met you.

Only coarse request metadata is shown. This demo does not display or persist visitor IP addresses.

Country
US
Cloudflare location
CMH
Connection
HTTP/2
Language
Not provided

Ray ID: a21d0d8469ae8682

Jump to content

Talk:CopperheadOS

Page contents not supported in other languages.
Add topic
From Wikipedia, the free encyclopedia
Latest comment: 2 months ago by Nemov in topic GrapheneOS hatnote

Letters and filings, how to use?

[edit]

What if anything can be taken from these PDFs of letters and filings from Graphene and Copperhead? -- Yae4 (talk) 13:43, 5 February 2021 (UTC)Reply

I think we should hold off from including any of the legal issues until they appear in secondary sources; at the moment I don't think we can include them without conducting original research. — Mr. Stradivarius  talk  13:52, 26 February 2021 (UTC)Reply

Insecure since Micay's departure

[edit]

Copperhead OS's page should be clearly divided into historical parts before Micay's departure and their current closed source distribution after Micay's departure. As Micay said, Copperhead is clearly compromized in its current form, so users should adopt Graphene or another distribution like Lineage. This should be made clear in the introduction, perhaps by making closed source appear in the first sentence, and delaying any spurious security claims until the body.  Preceding unsigned comment added by 212.25.6.87 (talk) 12:38, 7 February 2021 (UTC)Reply

"Insecure" that bit is unsubstantiated. Although as of writing this, the technology they use to enforce their licensing to users hasn't been disclosed publicly, no third party review, in other words it's still a black box only the OS creator knows what's in it. What is concerning though is a tweet from the company CEO: "...CopperheadOS does NOT track our users. We track licenses." Source:https://web.archive.org/web/20210221162422/https://nitter.fdn.fr/_copperj/status/1362455547149189126#  Preceding unsigned comment added by 190.184.199.3 (talk) 10:05, 22 February 2021 (UTC)Reply
User:Mr. Stradivarius User:Yae4 I believe this requires further discussion. Until the company publish audit of the latest CopperheadOS by reputable third party, any claims of privacy is rather questionable. Case in point is what method the company behind the CopperheadOS uses to track it's licences. We simply can't verify the innards of the latest CopperheadOS with old published articles anymore.  Preceding unsigned comment added by 190.184.199.3 (talk) 18:51, 22 February 2021 (UTC) Reply
@190.184.199.3: It isn't Wikipedia's job to verify the innards of CopperheadOS. That would be the job of independent researchers, who hopefully will have their work covered by journalists. Once this kind of thing is covered in news articles or books, we can include it. Until then, we'll have to stick with facts that have already been published in news articles and books, etc. For the Wikipedia policy on this, see Wikipedia:No original research. — Mr. Stradivarius  talk  14:00, 26 February 2021 (UTC)Reply
@212.25.6.87: Looking at the history presented by the sources in the article, I see several different pertinent events:
  • The change of licence from GPL to CC BY-NC-SA
  • The decision not to publish image downloads for Pixel phones
  • The departure of Micay
  • The removal of the sources from GitHub and of all image downloads from the website
Rather than a black-and-white change from pre-Micay to post-Micay, I see this as shades of grey - a gradual transition from a more open to a less open business model. — Mr. Stradivarius  talk  14:08, 26 February 2021 (UTC)Reply
As for being "clearly compromised", we aren't in a position to judge that, as it would be original research. We would need sources (and good ones, too) to back up that claim. — Mr. Stradivarius  talk  14:09, 26 February 2021 (UTC)Reply

CopperheadOS is still active

[edit]

As of 15 February 2021, the OS still is being developed. copperhead.co/android/ shows "Latest Stable: 2021.02.15". Peaceray (talk) 16:59, 9 March 2021 (UTC)Reply

A Commons file used on this page or its Wikidata item has been nominated for speedy deletion

[edit]

The following Wikimedia Commons file used on this page or its Wikidata item has been nominated for speedy deletion:

You can see the reason for deletion at the file description page linked above. —Community Tech bot (talk) 05:07, 23 September 2022 (UTC)Reply

It would be nice to have an updated screenshot, but since recent versions of CopperheadOS have a non-commercial licence, screenshots of it cannot be uploaded to Commons unless Copperhead specifically releases a screenshot under a compatible licence (see c:Commons:Screenshots). If someone wants to get in touch with Copperhead and get a screenshot licenced from them, then that would work. They could release a freely licenced screenshot on their website, or they could contact Commons via email to say that the image is freely licenced (see c:Commons:Volunteer Response Team). — Mr. Stradivarius  talk  02:37, 24 September 2022 (UTC)Reply

A couple Micay primary sources for history

[edit]

A lot of the history centers on Micay. I saw a couple primary sources that may be of interest for the article.

In 2017, Micay said maintaining hardened Android kernels was part of "my job" and he spent "far more than 40 hours a week on CopperheadOS". This was in context of stopping support of Arch packages PaX and grsecurity.

In 2012 Micay posted an application for Arch Linux Trusted User, and gave other background. -- Yae4 (talk) 01:33, 7 December 2022 (UTC)Reply

Yae4 (talk) 01:33, 7 December 2022 (UTC)Reply

GrapheneOS hatnote

[edit]

@Spiral6800: Re. this edit, I see that you are justifying the addition of the hatnote to GrapheneOS with WP:HATNOTERULES #3, "Mention other topics and articles only if there is a reasonable possibility of a reader arriving at the article either by mistake or with another topic in mind." If a reader wanted to reach the GrapheneOS article, why would they be searching for CopperheadOS? These are totally different terms. — Mr. Stradivarius  talk  06:01, 2 May 2026 (UTC)Reply

Because the CopperheadOS project was founded and run by Daniel Micay for a few years.
GrapheneOS is the direct continuation of Daniel Micay's open source work (although it was called AndroidHardening for a short time before being renamed to GrapheneOS). The old CopperheadOS GitHub issue tracker, as well as other old Copperhead repos, are owned by the GrapheneOS-Archive account. https://github.com/GrapheneOS-Archive/legacy_bugtracker
TextSecure and Signal are also totally different terms, but the hatnote explains the relation between them.— Spiral6800 talk contributions09:57, 2 May 2026 (UTC)Reply
@Spiral6800: There is no question that CopperheadOS and GrapheneOS are strongly related, but this is immaterial; the issue is whether a reader could confuse CopperheadOS with GrapheneOS when trying to get to the GrapheneOS article. The point of hatnotes is to get the reader to where they want to go as quickly as possible when they land on the wrong page, but there is no direct reason to assume that someone landing on the CopperheadOS article would actually be trying to get to the GrapheneOS article. The names are not similar, and there are no redirects of terms similar to GrapheneOS that point to the CopperheadOS article. In other words, I would say that including a hatnote to GrapheneOS from CopperheadOS is a textbook example of WP:RELATED.

You mentioned the hatnote at TextSecure as being a precedent, but I think that hatnote should also be removed as WP:RELATED. Just because that hatnote exists doesn't mean that it follows the hatnote guidelines.

For someone who is reading the CopperheadOS article and is curious to learn about GrapheneOS, the links in the article body should be enough to get them there. I noticed that there isn't any link to GrapheneOS in the lead section, which is perhaps something we should remedy. If we do decide to add a mention in the lead, it should only be brief to avoid adding undue weight to GrapheneOS in this article. Being neutral here is especially important given the history of the two projects.

By the way, why do you say that CopperheadOS is discontinued? I see that the last release was for Android 14 which is now a few years old, but I don't see anything on the CopperheadOS website to indicate that they are no longer selling the product. — Mr. Stradivarius  talk  15:15, 2 May 2026 (UTC)Reply

> the issue is whether a reader could confuse CopperheadOS with GrapheneOS when trying to get to the GrapheneOS article
I think that this is the case because GrapheneOS used to be CopperheadOS, and the new, post-2018 CopperheadOS has nothing to do with the open source project started by Daniel Micay. So if someone missed the entire 2018 Copperhead fiasco, they might not know that the FOSS project founded by Micay is now called GrapheneOS. They're not just related, there's a real possibility for confusion between the two. So yes, I think the hatnote is justified.
> You mentioned the hatnote at TextSecure as being a precedent, but I think that hatnote should also be removed as WP:RELATED
I think the TextSecure hatnote makes a lot of sense. It immediately lets the reader know that TextSecure is discontinued and now part of Signal. Keep in mind that infoboxes are collapsed by default in the mobile app, so readers don't immediately see the "Successor" entry in the infobox. The hatnote is a clean and easy solution to informing users about such crucial facts without requiring them to read the entire article.
> I see that the last release was for Android 14 which is now a few years old, but I don't see anything on the CopperheadOS website to indicate that they are no longer selling the product.
There haven't been any updates from Copperhead. Neither OS updates, GitHub commits, blog posts, social media posts, nor any other signs of life since December 2023. I highly doubt they're still selling licenses. This matches GrapheneOS's claim of having "wiped out their closed source fork by forbidding them using our code". https://grapheneos.social/@GrapheneOS/116302098491388353
Post-2018 CopperheadOS used a bunch of GrapheneOS code. Whether it could be considered a "proprietary fork" of GOS is of course questionable. Overall details about this are sparse, but GrapheneOS's claim of having "wiped out" post-2018 Copperhead definitely matches the fact that there's been radio silence from the company since December 2023. — Spiral6800 talk contributions22:00, 3 May 2026 (UTC)Reply
This is apparently what they are referring to. https://github.com/GrapheneOS/platform_manifest/blob/16-qpr2/COPPERHEAD-NOTICE
The GrapheneOS manifest repository contains a COPPERHEAD-NOTICE file which reads as follows:
> Copperhead Limited (Canadian security company formerly sponsoring our project
> prior to 2018), Copperhead business partners and James Donaldson (CEO of
> Copperhead) have consistently violated the terms of our licenses (including
> but not limited to lack of attribution, lack of compliance with copyleft
> licensing and more) and fraudulently claimed to have written our code. Our
> open source licenses are not extended to them, and they have retroactively
> lost all rights to use any GPLv2 licensed code via the GPLv2 termination
> clause. This is the result of their continued fraud, baseless lawsuits and
> involvement in harassment targeting the GrapheneOS team including spreading
> fabricated stories and engaging in doxxing which have directly led to serious
> swatting attacks aimed at killing the founder of GrapheneOS. — Spiral6800 talk contributions22:11, 3 May 2026 (UTC)Reply

3O Response: Hatnotes are intended to resolve likely reader confusion between similar or ambiguous titles, and that does not seem to apply here. CopperheadOS and GrapheneOS are distinct names, and there is little reason to believe readers searching for GrapheneOS would commonly arrive at CopperheadOS by mistake. Their historical relationship alone is not enough to justify a hatnote, particularly when readers can easily reach the correct article by searching the actual project name. Thanks! Nemov (talk) 21:08, 12 May 2026 (UTC)Reply