3 ms·
why shouldn't, in this case, security be binary? either there is a threat or there isn't. if someone in china is adding additional monitoring malware to libre
by ir77 7y ago
why shouldn't, in this case, security be binary? either there is a threat or there isn't. if someone in china is adding additional monitoring malware to librem's phones then isn't the whole privacy/security thing out the window?
either they believe in their chinese supply chain or they don't. and it's not like their usa manufacturing is done in-house by librem so they still don't have 'control over the entire assembly process" because they depend on a 3rd party to make their boards for them.
- danShumway 7y agoThey have a nonbinary degree of confidence in the Chinese supply chain, while keeping in mind that the risk is slightly higher than it would be if it was assembled closer to them within an imperfect, but at least less openly hostile government that has less access to directly control business operations. The likelihood of China compromising the Librem 5 is very low, and there are safeguards in place to prevent that. But no safeguard is absolute. Even manufacturing in the US isn't absolute security -- it's just a bit less dangerous than China. Whether that reduced risk is important enough to be worth $1300... I tend to think it's not, but I assume there are a few people who will care enough to pay that. The same situation applies to companies like Apple, Samsung, etc... the only difference is that those companies have judged that the potential market benefits of catering to people who have extremely strict privacy requirements is too low to justify starting up US operations. The hardware switches are also a good example of what I'm talking about here. There is a small risk of malicious firmware or a bug in software allowing a camera to be turned on without your knowledge. Does this mean the iPhone is insecure? There's not a yes or no answer. It means there is a specific subset of users who would be served by a stricter (but still imperfect) extra security control -- a physical kill switch. An even safer policy would be to remove the camera entirely -- then you could be certain that the physical hardware isn't defective and allowing the camera to be flipped back on. But even that wouldn't be binary security. There is no such thing as binary security.
- isantop 7y agoYou place a lot of faith on the ability of US-based companies to resist control by the US Government.