5 ms·
To show the kind of real respect for privacy, we need to access every piece of code that we are running. If you don't have time or technical ability to do that,
by chj 8y ago
To show the kind of real respect for privacy, we need to access every piece of code that we are running. If you don't have time or technical ability to do that, there are enough eyeballs out there.
Can apple do that? Or are you going to simply trust?
- sjwright 8y agoIf you want to run entirely open source software on entirely open source hardware with every software component compiled by a personally verified compiler and with every hardware component manufactured under your personal scrutiny then you might have a point. Otherwise you are ultimately forced to trust someone—probably many someones—and I'd rather place that trust in as few entities as possible. For myself I've chosen an entity that I believe has an economic incentive to respect my privacy and has proven with their actions that they deserve my trust.
- saagarjha 8y agoAll things being equal thought, it’s always better to have access to source code rather than none at all.
- sjwright 8y agoAbsolutely. And it's great that the option exists for anyone who has the technical literacy to understand how to benefit from that openness. But as soon as you encourage grandma to download Android roms, you can be certain that the internet will be flooded with dangerously exploited copies. These things seem simple for us because we deal with them every day. We understand how to interpret the components of a URL. We understand the reason why these critical downloads are paired with sha256 hashes. For most people on Earth, understanding computer security and the modes of trust in open source software is as likely as speaking Esperanto.
- saagarjha 8y agoYes, I’m well aware of the trade off here, and unfortunately I have not yet been able to find a solution that combines both benefits. As a technical user, I’d love to be able to mess with my device, but I can see the problems it can cause and why Apple might not want this to be available to their users.
- sjwright 8y agoAgreed.
- zAy0LfpBZLC8mAC 8y agoYou are equivocating additional weak points and additional verifiers when you are using the word "trust" for both. Having an additional entity the failure of which would lead to a failure of the system/product is an additional weak point. Obviously, you want as few of those as possible that you have to trust. Having an additional entity that watches/checks what is going on is an additional verifier. Obviously, you want as many of those as possible that you can build your trust on. You argument is essentially that you want fewer verifiers in order to have fewer weak points. That's just nonsense. By the same logic, you should prefer an intransparent dictatorship to a transparent democracy, because there are "fewer poeple to trust".