4 ms·
I think this is a false dichotomy. Open hardware with open source software would be more protected simply by being more stress tested and vetted by more people.
by fellowmartian 1y ago
I think this is a false dichotomy. Open hardware with open source software would be more protected simply by being more stress tested and vetted by more people. If you need even more protection you can employ zero-knowledge proofs and other trustless technologies. I have long been dreaming about some kind of hardware/software co-op creating non-enshittifying versions of thermostats, electric kettles, EV chargers, solar inverters, etc, etc. Hackable for people who want it, simply non-rent-seeking for everyone else.
- positron26 1y ago> more stress tested and vetted by more people Grandma and grandpa aren't reading the source code and certainly not up at a professional level. This is one of the core misconceptions of the "free/libre" formulation of OSS.
- fellowmartian 1y agoI’m not suggesting grandpa reads code, contributors do. We all know that most commercial code is much shittier than open source. Sure, commercial code usually covers more edge cases and has better UX, but is cobbled together from legacy and random product asks.
- ranger_danger 1y ago> contributors do I would argue most code of any license is not actually regularly audited if at all, and certainly nowhere near the levels people seem to think they are. > We all know that most commercial code is much shittier than open source citation needed
- p_ing 1y ago> I would argue most code of any license is not actually regularly audited if at all, and certainly nowhere near the levels people seem to think they are. Every device should run OpenBSD. And only the audited part.
- positron26 1y ago> contributors do More users != more contributors. As software gets more popular, you begin getting 10, 100, 1000, 1,000,000 users for every contributor. This doesn't just affect non-programmers. We can't even police NPM. People want it to be true so that it will be a talking point, but it's not true, and we need to find new talking points that align with facts that are evident outside the echo chambers.
- dismalaf 1y agoNPM is... special... It's up to platform owners to set standards and police. NPM's failures have nothing to do with open source as a whole.
- jen20 1y ago> We all know that most commercial code is much shittier than open source Citation needed. Seriously.
- rmunn 1y agoI'm not the one who made that assertion, but... Windows Millenium Edition almost makes his case all by itself.
- jen20 1y agoThat makes the case that a _single_ piece of commercial code was shitty. I could make the same argument about MongoDB of a decade ago implying that all open source is trash...
- rmunn 1y agoNorton, McAfee, in fact most virus scanners. Plenty of examples I've heard about but haven't actually used myself so I can't confidently assert the quality of the software. But Windows ME, Norton, and McAfee, I have personal experience with. Oh, and also Windows Vista. Plenty of badly-written open source software, too; won't argue against that. But one of the biggest reasons, for me at least, why I prefer to use open-source software rather than commercial if I have a choice is bug fixes. I've reported over a dozen bugs against open-source software I use over the years; most of them have been fixed (in a couple cases I was able to fix it myself). I've rarely even been able to report a bug against closed-source software, let alone get those bugs fixed. So even if if were true that commercial software as a whole has similar or better quality than open-source, my personal experience is the other way around: open-source quality gets better over time while the closed-source software that I have to use (lacking open-source alternatives) doesn't improve the same way.
- nik282000 1y agoWindows ME, Windows Vista, Internet Explorer, Adobe PDF Reader, Siemens Step7, Norton, McAffe, the list goes on. If you look at it as a function of terribleness * users then corporate ware takes the cake. There are loads of terrible open projects but nobody uses them.
- nik282000 1y ago> Grandma and grandpa aren't reading the source code and certainly not up at a professional level. This is one of the core misconceptions of the anti "free/libre" formulation of OSS. Most users don't need to read the entire Debian source to know that it is safe to use. You are free to look up who maintains any part of the project and look at the history of changes that have been made. A lot of projects have nice, easy to read notes along with the actual code. If you are so paranoid that you can't even trust open release notes then why would you trust a closed project at all?
- positron26 1y ago> A lot of projects have nice, easy to read notes along with the actual code This alone doesn't improve the quality of the source. > Paranoid Nothing to do with it. Please be logical. Having millions of people who can't program trust maintainers doesn't make those maintainers do better work. The whole idea of more eyeballs is an appeal to a vision of crowdsourcing that was a new idea in the early internet. What we found out is that complacency sets in, the notes eventually don't mean anything, and most source code is not read. This vision of more programmers spending more time reading other people's programs is wholly born from within programmer communities, from programmers talking to other programmers, forgetting that the average user will never program and not because they lack access. It's a romanticized ideal that is only even a plausible idea in a room full of programmers. Until you focus on how the non-programmer is going to meaningfully improve the review and production of the open technologies, you will never have a scalable or equitable solution.
- beeflet 1y agoThe non-programmer never going to meaningfully improve the review and production of the open technologies. The solution is to make a society where people are literate in the technology they rely on or suffer otherwise.
- positron26 1y agoAnd the solution to cavities is to increase self-dentistry literacy? The solution to a bridge collapsing is to increase civil engineering literacy? The solution to a plane crash caused by a cracked turbine blade is to increase casual aerospace engineering literacy? How much of how many literacies will we be willing to acquire so as to balance the responsibility we ask of every other profession and even those who are low and unskilled? This incredibly selfish point of view put forth by a particular sect of _OSS polls sufficiently well at the engineer's only meeting in Palo Alto and nowhere else. When people were coming up with the idea of computer literacy being ubiquitous like math, they meant math like addition and subtraction. To make the kind of impact that "free/libre" advocates want the everyday Joe to be responsible for, Joes need to know the CS equivalents of perturbation theory and how to solve partial differential equations. It's not happening, but believing that it can happen allows those ostensibly in favor of it to keep acting like they have a plan, like they want a solution. As long as the hardware hacker is stuck in the mindset of what 0.01% of users want to do with devices, while they may find sympathy from the 0.1% who are software engineers, many of whom gather on this site, this is not even blowing at the gauge from halfway across the room in terms of moving the needle. Either figure out what is important to the consumer and how it aligns with your interests or just go home.
- johncolanduoni 1y agoThe issue here is rarely whether the security features themselves are circumventable. It’s that at some point this turns into trusting users not to give malware apps permissions (whether that’s a dialog, a system wide setting, adding a third-party app store, etc.). Almost no users can usefully evaluate whether a particular bit of digital trust is a good or bad idea, so people will constantly get scammed in practice. If you’re thinking about ZNP as a solution, you’re not trying to solve the actual security problems of normal users.
- beeflet 1y agoI think normal users will figure it out if you give them a couple of generations