6 ms·
Genuinely, I really want to see Purism succeed and increasing numbers of competitors in that space, because we need tools that don't require so much blind trust
by sammorrowdrums 6y ago
Genuinely, I really want to see Purism succeed and increasing numbers of competitors in that space, because we need tools that don't require so much blind trust. Whether caused by inept software devs, scope for malicious code / backdoors in firmware, analytics spyware, and whether this stuff is well intentioned or not, if it can be abused, it will be.
Open source and verifiable down to the firmware is the only chance we have at any real level of trust, otherwise as is always apparent in these conversations, it often falls otherwise to who you think could compromise your device and making your bed with it, like USA not China or vice versa
- cosmodisk 6y agoThe problem is that purism doesn't pay as much as all the tracking, preinstalled bloatware, random 3rd party utilities and other stuff. This will never ever be solved through competition,because people either don't care, or there aren't enough of those who do. Legislation is the only way to make it work, but then again, that's hardly an option for most of the world.
- javajosh 6y agoThere is clearly at least a niche market for "transparent devices". See https://www.crowdsupply.com/sutajio-kosagi/precursor https://www.crowdsupply.com/sutajio-kosagi/precursor for example.
- fsflover 6y agoPurism are trying to lobby for the legislation [0] and to change the industry [1]. [0] https://puri.sm/posts/purisms-ceo-todd-weaver-testifies-at-state-senate/ https://puri.sm/posts/purisms-ceo-todd-weaver-testifies-at-s... [1] https://wp.puri.sm/posts/breaking-ground/ https://wp.puri.sm/posts/breaking-ground/
- africanboy 6y agoas much as I am eager to see open source mobile OS succeed, tracking happens at the app level. What happens when I install the FB app on a Purism enabled device? My way to go until now has been installing as many OSS apps on my smartphone as possible, to the point that even the keyboard and the launcher on my smartphone are installed through f-droid. That's the main reason why I prefer Android phones over Apple ones.
- robotbikes 6y agoI don't think Facebook is likely to release a Linux based app. If they did it would likely be electron style. There also lots of Facebook apps that wrap the mobile website inside of a stand-alone "app" available on F-Droid. I also wonder what type of permissions API even exist that would allow you to view contacts as an app inside of Purism. Maybe Gnome has something kind of API already for apps to access built-in contents but this far there hasnt been a lot of proprietary software released for Linux that embeds spyware because of the low # of users and increased difficulty and general lack of distribution platform. But Purism is also really far away from being a viable platform for non-techies at this point.
- giantrobot 6y agoPurism is never going to end up with fully open source baseband firmware. It's not going to happen because the radios are subject to several regulations which means customers can't be able to modify that firmware. There's going to always be a trust hole.
- phkahler 6y agoYou can still make the code and tool chain open source. Then require a key to write to the device. Reading could be allowed. This can work where everything is in the open except a private firmware signing key.
- baybal2 6y agoWho said you cannot? Just do it, and see.
- giantrobot 6y agoEvery radio regulation agency on the planet? Most radio hardware is capable of operating outside of regulated limits. The device firmware is usually what keeps the devices running within their regulated limits and gets those components licenses to be sold. Anyone selling regulated devices running outside of their regulated envelope faces fines and even criminal charges. Cell phones only work because the millions of devices run within strict limits and behave reasonably. There's not a lot of difference between a properly operating radio and a radio jammer. Purism isn't going to find a baseband vendor that's going to risk their licenses by allowing for open source firmware.
- baybal2 6y agoNo, pretty of radio transmitting equipment are fully open soft modems. As far as I know, there is no licensing whatsoever for baseband makers? Where did you get that it is?
- giantrobot 6y agoIn the US a baseband processor's entire software stack that controls the radio front end must be certified. They'll also have the modems to talk to the cellular networks. BPs use their own CPU(s) and an RTOS firmware that's FCC certified. This is why a baseband processor is a fully separate component from a device's application processor(s). Since the AP doesn't talk directly to the radio it doesn't need to be certified and can be updated without recertification. The BP can also get certification and any manufacturer using that BP doesn't need to re-certify it. The interfaces are also such that the AP can't (or shouldn't be able to) tell the BP firmware to boost the output power above legal limits or something. Radios that have "open" soft modems don't typically have fully software controlled radio front ends. The radio front end will have its statutory limits baked in electrically or have very limited software control. The modulation on the back end isn't as important as the front end. Broken modulation just means you can't talk to anyone, an overdriven transmitter is effectively a radio jammer or can give someone an RF burn.
- euske 6y ago> Open source and verifiable down to the firmware While I agree with your intent, the problem is that, many open source software is not verifiable. Remember that a Kaggle competitor was openly cheating with his published code? (cf. https://www.theregister.com/2020/01/21/ai_kaggle_contest_cheat/ https://www.theregister.com/2020/01/21/ai_kaggle_contest_che... ) Eventually he got caught, but it's sometimes extremely difficult to spot a well-hidden malicious code in a plain sight. We need to be much better at analyzing software.
- sammorrowdrums 6y agoYeah, you are definitely correct on the lack of verification tools and I hope research on that one day breaks out of academia and into more common usage. The Kaggle story is great. One mildly related thing is Purism's bootloader tampering detection with their "librem key". Naturally it does nothing to verify the running code, but it does feel like knowing you're running the code you thought you were has some merit. I think maybe some replies have interpreted my comment as naively assuming that open source firmware would would mean complete trust. I just think it is a good step on the journey.
- fsflover 6y ago> many open source software is not verifiable Open source software is more verifiable than closed source though.
- ShroudedNight 6y agoWhile having the source available is not a panacea, it would seem that, at least in the case you mentioned, not having the source code would have allowed for the cheating to continue with impunity, as there would have been no way for anyone to begin to discover what had been going on. That would suggest that having the source available is a necessary part of establishing real trust, even if it's not sufficient. > While I agree with your intent, the problem is that, many open source software is not verifiable. To me, this sentence reads as "That a nice idea, but untenable in practice." rather than "Open source is necessary, but shouldn't be considered sufficient." which strikes me as counter-productive to the objective of easily verifiable software.
- matheusmoreira 6y ago> we need tools that don't require so much blind trust Completely agree. > Open source and verifiable down to the firmware is the only chance we have at any real level of trust The hardware itself could be compromised though. There's just no way to know what's really inside these black boxes. https://youtu.be/_eSAF_qT_FY https://youtu.be/_eSAF_qT_FY We'll never have real trust until we get the ability to fabricate our own processors in our own home just like we already have the ability to write our own software.
- mohaine 6y agoThis doesn't help completely unless you fabricated the fabricator on trusted parts as well. Unless you trust it there is nothing to prove that the fabricator isn't inserting back doors into whatever it prints.
- biglost 6y agohttps://wiki.c2.com/?TheKenThompsonHack https://wiki.c2.com/?TheKenThompsonHack https://www.win.tue.nl/~aeb/linux/hh/thompson/trust.html https://www.win.tue.nl/~aeb/linux/hh/thompson/trust.html
- hutzlibu 6y agoWell, I would love to print out my own cpu in the garage, but until then, I would also be happy, if the factories producing security critical HW, get frequent audits by qualified personel. Certifying and reviewing the build process. Not very likely on a broader scale, though.