5 ms·
Fuchsia has separated the drivers from the kernel[1], enabling proprietary drivers that are never updated to become acceptable. This can result in Blueborne[2],
by posguy 5y ago
Fuchsia has separated the drivers from the kernel[1], enabling proprietary drivers that are never updated to become acceptable. This can result in Blueborne[2], GPU vulnerabilities[3], and any other proprietary driver remaining permanently vulnerable as the hardware manufacturer has no incentive to update the driver.
In Fuchsia's model, you can run the latest OS with these vulnerable, non-updated drivers, or your device ODM could even release nothing and you don't have the GPLv2 to fall back on to get the Board Support Package for your hardware to build your own updates with.
1 - https://www.theverge.com/2020/12/8/22163225/google-fuchsia-os-call-contributors-mailing-list-governance https://www.theverge.com/2020/12/8/22163225/google-fuchsia-o...
2 - https://en.wikipedia.org/wiki/BlueBorne_(security_vulnerability) https://en.wikipedia.org/wiki/BlueBorne_(security_vulnerabil...
3 - https://redd.it/s48lz https://redd.it/s48lz
- spankalee 5y agoThose types of driver vulnerabilities are exactly why Fuchsia's sandboxed driver model is needed.
- kelnos 5y agoI see that as a sort of capitulation. What is actually needed is manufacturers who remain responsible and responsive when it comes to the quality of their drivers. They need to support them much longer than they currently do, and they need to release security fixes promptly. I think having a sandboxed driver model is a great idea in general, but this will only encourage hardware manufacturers to care even less about supporting their drivers beyond the initial more-or-less-working release.
- zepto 5y ago> What is actually needed is manufacturers who remain responsible and responsive when it comes to the quality of their drivers. They need to support them much longer than they currently do, and they need to release security fixes promptly. That requires a level of investment in engineering competence that they aren’t doing because there is little incentive. How would you suggest changing that?
- fsflover 5y agoWhen the support ends, drivers must be open-sourced.
- zepto 5y agoThat’s just a wish. How do you create the incentive for it?
- fsflover 5y agoI think that just must be a law. I see no other possibility.
- zepto 5y agoHow would the law define ‘support ends’? Also seizing source code at gunpoint seems antithetical to the notion of free software.
- fsflover 5y agoThis is the question of security, see https://news.ycombinator.com/item?id=27387169 https://news.ycombinator.com/item?id=27387169. > How would the law define ‘support ends’? Whenever the company refuses to fix security bugs.
- zepto 5y agoWhat if they don’t refuse - but are just slow or inefficient or produce bad fixes?
- fsflover 5y agoThere exist more or less standard times for fixing security bugs. Let's say 90 days. If a company cannot provide security for their customers in a reasonable time, they must be held accountable.