4 ms·
The key takeaway to me is that developing mobile apps for the Librem 5 on the Librem 5 is a first class development workflow. This is great. Not having to worr
by jodoherty 5y ago
The key takeaway to me is that developing mobile apps for the Librem 5 on the Librem 5 is a first class development workflow.
This is great. Not having to worry about setting up toolchains on a separate platform, cross-compiling, and then signing/transferring apps and running remote debugging sessions makes it easy to just build and test apps.
- sneak 5y agoNo signing also means that the workflow for developing malware for the platform is exactly the same, too. :) My issue with the Apple ecosystem is not the cryptographic protections - it's with the fact that the keys aren't mine.
- simias 5y agoI'm not sure I understand. Crypto won't protect you from malware by itself, it just creates a chain of custody. App store apps are not secure because they're signed, they're secure because they're signed by Apple. For the librem it's just like a desktop computer, don't install software from untrusted sources, keep your stuff updated and you should be fine.
- swiley 5y agoMeh, signing by Apple really doesn't mean more than Apple looked (visually) at a running instance of the app and said "eh it doesn't look like it's breaking the rules." They don't do any instrumentation and often the developers themselves don't even understand what all the binary dylibs they're including do.
- simias 5y agoI don't own an Apple device myself but don't they have a pretty good track record when it comes to the security of their apps? Plus all the guidelines they've been enforcing lately when it comes to user tracking etc... At any rate my general point still stands I think, it doesn't really matter whether librem apps are signed or not, what matters is where you put your trust. I'm sure some package managers (first party or otherwise) will be able to provide a curated experience if the platform is successful, like what linux distros offer.
- sneak 5y agoBeing able to outsource the decision about what is or isn't an "untrusted source" to a security expert is valuable. Platforms that only run signed code permit that.
- fsflover 5y ago> Platforms that only run signed code permit that. Like GNU/Linux repositories?
- sneak 5y agoNo, those only distribute signed code. If unsigned code makes its way on to your system outside of those repositories, your GNU/Linux system will happily execute it, unsandboxed save for outdated POSIX uid/gid permissions.
- fsflover 5y agoExcept restricting what a user can do with their system does not significantly improve security. It removes the freedom and powers walled gardens.
- andrepd 5y agoPlatforms that don't run only sign code also permit that.
- paxys 5y agoThe real reason iPhone apps are safe is because they run in a controlled sandbox with a very limited set of device APIs available to them. You could take away the app store and signing and things would mostly be the same.
- franga2000 5y agoYou're mixing developing and distribution. You don't need any (meaningful) signing to develop for Android and not even for iOS (although testing is harder there). App signing comes in only when end-users are installing your apps. As for malware installation on Librem, that is a separate question. If you don't give apps root access and only install from the repos, you're about as secure as on Android or iOS. Once you start installing from unknown sources, however, it's true that you're screwed - but that's because of the permission system, not signing.
- turblety 5y agoI don't understand this line of thinking. There is loads of malware in the Apple Appstore. https://www.techradar.com/news/apple-app-store-is-apparently-still-littered-with-malicious-apps https://www.techradar.com/news/apple-app-store-is-apparently...
- hakube 5y agothere are tons of apps on iOS and Android app stores that are malware and they are signed
- deleted 5y ago[deleted]
- atat7024 5y agoCan anyone explain to me the benefits of staying native, and not switching everything to web apps that use properly implemented web APIs for everything?