7 ms·
> According to that, if Apple accidentally ships any GPLv3 on iOS then they'll have to release their root signing keys to the world, which would be disastrous (
by bobcallme 9y ago
> According to that, if Apple accidentally ships any GPLv3 on iOS then they'll have to release their root signing keys to the world, which would be disastrous (it would destroy the security model of the OS).
Stop spreading this FUD. They would not need to release their root singing keys in this case, just provide a mechanism to allow for other keys to be used (there are various ways to go about doing this without compromising security). The main requirement is that the compiled software can be run on the device.
- eridius 9y agoThis is not FUD. This is the actual position of Apple Legal.
- Moocat87 9y agoThose can both be true.
- EGreg 9y agoHow exactly?
- chungy 9y agoIt's not the position of the FSF who actually wrote the license. GPLv3 requires that users be able to install their own copies of the program onto the device. The device can allow a user-settable key in order to accomodate the requirement. No Apple keys need to be published.
- eridius 9y agoUser-settable keys also compromise the security of the device. The most plausible approach is one outlined in another comment in this thread wherein you get a new key when factory-resetting the device and if you don't write it down it's gone forever, but even that approach will likely cause problems with Activation Lock. And in general it's risky to introduce stuff like this because the potential for unforeseen security compromises is very high, and the upside is very low (the number of people who'd actually take advantage of this is extremely low relative to the number of iPhone users).
- bobcallme 9y ago> User-settable keys also compromise the security of the device. Not if a physical modification to the hardware, a set of button presses, a hardware token or a fuse is needed to set said keys. > And in general it's risky to introduce stuff like this because the potential for unforeseen security compromises is very high There is little to no risk if physical interaction with the hardware is required for setting keys. If you have physical access and enough time, all bets are off anyway. > ...and the upside is very low (the number of people who'd actually take advantage of this is extremely low relative to the number of iPhone users). There are many people who dream of having the freedom to roll their own firmware on a particular device and it can be done without compromising the security of said device. This was not just about iThing users (who might/not take advantage of this), this was about people spreading FUD about the tivoization part of the GPLv3. Root signing keys don't need to be shared and the only requirement is that the user can take the sources, compile them and then run the result on the target device. As long as the OEM distributing the GPLv3'ed program gives a clear path for running the compiled code on the target device, then it is not a problem.
- natch 9y agoYou and others like you who take this line of argument are either ignorant of, or willfully pretend away, the abusive/spying household member problem.
- frenchy 9y agoA walled garden OS doesn't do much to stop the abusive/spying household member problem. They can just beat you up until your give them your password, or spy on you and catch you entering it.
- mseebach 9y agoBut they can't compromise the device without the victim knowing about it. Not all abusive relationships are violent or even directly coercive like that.
- SeanLuke 9y ago> It's not the position of the FSF who actually wrote the license. The author of a license is not the person with the legal authority to interpret its meaning.
- thomastjeffery 9y agoSo you are saying that Apple would want to enforce it in a way that is less convenient for Apple than the way the license author would enforce it? That is just as absurd.
- tylerhou 9y agoNo, he’s saying that if Apple chooses to trust the license author when they say that they interpret it in a specific way, they might get screwed if the license author changes their mind. Should that happen, a court of law would have the authority of legal interpretation.
- mseebach 9y agoNo, they're saying that the people actually having to defend the position, the people with actual skin in the game, (Apple legal) believes this. The opinion of the writer of a legal document carries only tangential weight next to the actual written words of this document.
- gsnedders 9y agoAnd of course Apple is going to take the conservative position until a court rules on how to interpret the license; it's just not worth the risk to them.
- crististm 9y agoHow do you know what they actually believe?
- mseebach 9y agoI don't, as such. But a grandparent made a claim of their position: "It's not the position of the FSF who actually wrote the license."
- andrepd 9y agoWhat does it matter what the legal position of Apple is? Of course if they aren't interested they would say that, wouldn't they? I'd say what matters is the licence text and FSF's statements in that matter.
- Joky 9y agoWhere can I read the statement from Apple legal?
- trapperkeeper74 9y agoIt's still FUD.
- cyphar 9y agoAssuming that Apple Legal is not lying (a big ask, as they have an incentive to spread FUD around GPLv3 and blame the license so to discourage projects from using it so they aren't forced to develop their own variants of more GPLv3 projects) there's also a possibility that they are misinformed or have come to a wrong conclusion. Also, there's nothing stopping an opinion from a lawyer from being FUD. Apple Legal isn't your lawyer, they don't have a responsibility to tell you the whole truth or give you information that is in your best interest.
- eridius 9y agoThat's absurd. There's literally no reason for Apple Legal to lie. If Apple Legal was lying about the downsides of GPLv3, then that means there's no reason why Apple would care about software being GPLv3, which means there's no incentive to try and convince people to stop using it! Also, it's not like Apple Legal is telling anyone outside the company about this. Apple's not releasing any public statements asking people not to use GPLv3. So how exactly are they supposed to be discouraging its use when the people using it don't know what Apple Legal thinks about it?
- cyphar 9y ago> There's literally no reason for Apple Legal to lie. Yes there is. Apple doesn't want to use GPLv3 for other reasons (they don't want users to have full control over their machines -- which they've proven time and time again with the iThings). But rather than saying "sorry, we don't want you to be able to control your machines" (which would be bad PR) they spread rumors about "GPLv3 means your software cannot be secure against certain attacks". > Also, it's not like Apple Legal is telling anyone outside the company about this. Hence this whole comment thread is a discussion about theoretical views of Apple Legal. My whole point is predicated on "someone actually knows for sure that this is the opinion of legal".
- eridius 9y ago> they don't want users to have full control over their machines Oh come on. You sound like a caricature now. "Not having control over their machines" is not a goal and it makes you sound like a crazy conspiracy theorist to claim it is. Security is a goal, and unfortunately security often conflicts with having complete control over the device. But that's different than saying Apple actively wants to prevent users from having control over their devices. > they spread rumors No they aren't. Apple doesn't make any public statements about GPLv3, period. Apple can't possibly be spreading rumors if they're not talking to people. > My whole point is predicated on "someone actually knows for sure that this is the opinion of legal". I do. I know for sure this is the position of Apple Legal. Which is why I said this was their position in the first place.