6 ms·
> Yet since then, I have personally lost control of many of the computing devices I use. No, you haven't. Or rather, you didn't lose control because of any sof
by dvzk 4y ago
> Yet since then, I have personally lost control of many of the computing devices I use.
No, you haven't. Or rather, you didn't lose control because of any software license. We lost control because of cryptography and enforced signature verification. Just because software is licensed as open source doesn't mean it allows for third-party firmware modification.
Maybe it's because I came up through the RE scene, but the false association between open source and ownership or security has always stood out to me. Many of the modding and hacking communities that orbit proprietary software are/were more vibrant than anything that exists in the totally open source space.
- mxkopy 4y ago> Or rather, you didn't lose control because of any software license. We lost control because of cryptography and enforced signature verification. I'm not sure what you mean by this. It's the law that's a barrier, not cryptography. If you break the DRM on a game you can still face legal consequences, even if the company that licenses it doesn't support it anymore.
- dvzk 4y agoCopyright laws are not what is stopping custom firmware projects on many devices. It’s the inability to flash non-signed firmware. Legal considerations in general have minor pragmatic relevance for modding projects that are not lazily redistributing copyrighted assets or circumventing copyright protection. If you’re engaging in piracy then you’re not just giving people more control over what they own.
- mxkopy 4y ago> or circumventing copyright protection Exactly, you just named a subset of all the things you could do to a machine, partitioned by copyright protection. I'd agree with your general point in the context of power users, but it's worth noting that the average Joe will try to faithfully follow company policy as well as the law.
- dvzk 4y agoDRM protection sometimes rears its ugly head, and that is worth objecting to, but as someone who has written unpackers and game mods, it’s rare nowadays that DRM prevents modding, unless you’re creating unethical multiplayer hacks. Code that is relevant to modders is usually contained in unprotected script and library assets. To run afoul of the DMCA a modder needs to (1) strip a binary of its copyright protection (2) distribute the unpacked executable or the unpacker tool (3) likely facilitate mass third-party piracy (more damages = more lawsuit potential). It’s principally warez and hacking groups that meet these criteria, and they probably ought to be sued. I’ll add a point in your favor and say that for non-games DRM is often a big problem when reversing or patching code.
- pxc 4y agoFree software licenses are just an imperfect mechanism for trying to secure software freedom, which is the real thing the movement has always been after. And the GP's point that the loss of software freedom, even in the abstract, has led to more and more losses of control over particular behaviors on our devices. The technical means by which this encroachment is enacted are insignificant. The substance of the issue is political.
- trelane 4y ago> We lost control because of cryptography and enforced signature verification. Yes, the term for this is "tivoization." It is a large part of why the GPLv3 exists. > Just because software is licensed as open source doesn't mean it allows for third-party firmware modification. Yep, "open source" and many copyleft licenses are insufficient for this job.
- csande17 4y agoYup, GPLv3 specifically requires manufacturers to provide any signing keys needed to get code to run: > “Installation Information” for a User Product means any methods, procedures, authorization keys, or other information required to install and execute modified versions of a covered work in that User Product from a modified version of its Corresponding Source. The information must suffice to ensure that the continued functioning of the modified object code is in no case prevented or interfered with solely because modification has been made. > If you convey an object code work under this section in, or with, or specifically for use in, a User Product, and the conveying occurs as part of a transaction in which the right of possession and use of the User Product is transferred to the recipient in perpetuity or for a fixed term (regardless of how the transaction is characterized), the Corresponding Source conveyed under this section must be accompanied by the Installation Information. But this requirement does not apply if neither you nor any third party retains the ability to install modified object code on the User Product (for example, the work has been installed in ROM). (https://www.gnu.org/licenses/gpl-faq.html#GiveUpKeys https://www.gnu.org/licenses/gpl-faq.html#GiveUpKeys clarifies that this applies to cryptographic keys.)
- dvzk 4y agoI think this is a good argument for the advocacy of GPL-3+ prevalence. It’s also legal, I think, to publish GPL-3 firmware source code, and to disallow custom firmware flashing, as long as the copyright is self-owned. (IIRC the provisions of the GPL don’t give legal standing for suing the author over self-violations.) In this case, would you call the software or code proprietary (which many confusingly do) or would you call the device proprietary?
- m463 4y agoBut doesn't signature verification happen in proprietary software on my phone?
- dvzk 4y agoSometimes, yes, but not intrinsically. AOSP performs OS and app update authenticity verification via predistributed public keys, as do package managers. In theory, a phone’s firmware can be completely open source and still be unmodifiable. Proprietary software isn’t any more opaque or protected than open source software.
- m463 4y ago> Proprietary software isn’t any more opaque or protected than open source software. lol. Look, in practical terms - as well as by definition - proprietary software is owned by someone else.
- dvzk 4y agoSorry. I meant to write that closed source software isn’t opaque, technologically. (More opaque, yes, opaque... no.) Legally, it’s different. But closed source compilation alone doesn’t grant a program special privileges or confidentiality or non-reversibility, which is sometimes assumed. It’s just machine code or bytecode either way.