# Iodé and security

**URL:** <https://community.iode.tech/t/iode-and-security/278>\
**Category:** General Discussion\
**Created:** [28 December 2021 11:17 UTC](https://community.iode.tech/t/iode-and-security/278 "2021-12-28T11:17:54Z")\
**Posts on this page:** 1\
**Showing post:** 3

<div class="post-metadata">

**Author:** ![io\_d](https://community.iode.tech/letter_avatar_proxy/v4/letter/i/57b2e6/32.png) [@io\_d](https://community.iode.tech/u/io_d)\
**Post date:** [3 January 2022 14:28 UTC](https://community.iode.tech/t/iode-and-security/278/3 "2022-01-03T14:28:55Z")

</div>

Hi,

Some of these statements sound very worrisome to me:

1. _“security decreased by Lineage” claim: this is a point of vue[sic] that one can share or not_: this does not make sense. Something is either secure or it is not, it’s no belief. What can vary however is the security model one is interested in and on which the outcome (secure or not secure) will be based.
2. _We primarily focused on privacy aspects, but we are definitely interested in increasing the security level too._: Security is prerequisite to privacy. (Privacy is defined by your security model. Breaking the security of a DNS implementation will break a certain definition of privacy.)
3. _OTA updates are actually stored on github and accessed through https, so we can I think consider that it has reasonable security level._: What is https actually supposed to bring in terms of security?
4. who are “we”? I did not find much information behind the iodé os entity. It’s a very nice security feature to have the builds signed by a _trusted_ entity. Can we (the users going to flash iodé os) trust this entity?

Best, and looking forward to your great contributions to more security (and then privacy!)

---

_[View the full topic](https://community.iode.tech/t/iode-and-security/278)._
