7 ms·
For some of us software freedom enthusiasts it is worth noting that PebbleOS contains some proprietary blobs for some peripherals in the watch[1]. This is not j
by mid-kid 11mo ago
For some of us software freedom enthusiasts it is worth noting that PebbleOS contains some proprietary blobs for some peripherals in the watch[1]. This is not just firmware you upload to the peripheral but also properietary .a libraries that run on the main core.
Though to be fair to OpenDevices, this is source code they don't have acces to either.
[1]: https://github.com/coredevices/pebbleos-nonfree/tree/57a94e2a8b7236f41f8e60c039a0342652487517 https://github.com/coredevices/pebbleos-nonfree/tree/57a94e2...
- paxcoder 11mo agoSo not 100% open source. Thanks for the info
- ddlsmurf 11mo agoWell the Pebble specific parts are. This is an unfortunate state of affairs from hardware manufacturers, they are very late to the open source game, if at all.
- paxcoder 11mo agoFrom the article: >Another important note - some binary blobs and other non-free software components are used today in PebbleOS and the Pebble mobile app (ex: the heart rate sensor on PT2 , Memfault library, and others). Optional non-free web services, like Wispr-flow API speech recognizer, are also used. These non-free software components are not required - you can compile and run Pebble watch software without them. This will always be the case. More non-free software components may appear in our software in the future. The core Pebble watch software stack (everything you need to use your Pebble watch) will always be open source. 100% should mean 100%
- darkwater 11mo agoIf they are not mandatory it's 100%. Otherwise according to your standard, Debian is not 100% free software either.
- bayindirh 11mo agoDebian doesn't advertise itself as 100% open source, either. Main and Contrib has to obey DFSG guidelines, and there's an optional non-free repository which you can enable if you prefer. Firmware is a gnarly can of worms though, and while I prefer 100% free firmware myself, companies are not brave enough to open that part of their ecosystem, yet, if ever.
- aallaall 11mo agoCompanies typically move more and more functionality to closed firmware, so they can ”open source” a thin wrapper, like a driver, that is often completely useless, and often encumbered with cryptography restrictions, strict trademarks and software patents anyway.
- bayindirh 11mo agoThis is not always true. NVIDIA does exactly what you said. Move everything to firmware and closed GL libraries, and open source a kernel module to facilitate communication. They even created different firmware versions to prevent open source drivers to use the whole card. AMD did the inverse: They re-implemented a fully open driver from scratch, opened up the specs, made every part which they can make (legally) accessible, accessible, open sourced ROCm and send in packages to major distributions' (main / open source) repositories. Their firmware is closed source, but it's obtainable and doesn't require signatures to enable the card. They even clashed with HDMI forums to make a libre implementation of v2.1, but the forum basically threatened them. Intel's graphics drivers are basically the same with AMD. Broadcom / Intel / Realtek NICs work without their respective firmware blobs, yet their offloading capabilities are disabled. Either way, the drivers are completely open source and in the kernel mainline. Same for most sound cards sans Creative Labs. I want to hit them with a foam cluebat so bad. Logitech's all stuff works with open drivers. They are the primary contributor to V4L standard, standardize their webcam interfaces and provide drivers or help. Do you have any examples in mind?
- paxcoder 11mo ago[dead]
- rnewme 11mo ago100% of their own software.
- paxcoder 11mo ago[dead]
- wafflemaker 11mo agoIMHO, it's much closer to 100% than an iWatch or a Garmin.
- aallaall 11mo ago1% is closer to 100%, than 0% is, yes.
- RobotToaster 11mo ago> More non-free software components may appear in our software in the future. That sounds ominous. I can understand not being able to remove non-free dependencies that were used previously, but that sounds like they intend to create new non-free components.
- bloppe 11mo agoSurprising because you'd think the hardware itself would be their primary moat.
- ddlsmurf 11mo agoHardware isn't that hard to copy paste really, to make it hard you need to use really expensive processes (extreme uv etc), but otherwise, mostly you can pretty much take a picture. (very grossly speaking here, but just saying, the software is definitely a critical part)
- bayindirh 11mo agoBetween the cross-licensing of hardware IP blocks and 3rd party software which never sees the light of the day, hardware manufacturers work like a secretive three letter agency to be able to control every part of their ecosystem. I tend to understand where this comes from. It's part business, part continuation of old customs and the way they did it and being able to control obsolescence to be able push new things to the market. However, if the periphery of the software you put out is closed source, even though this periphery is optional, it's not fair or ethical to say it's 100% open source. From my perspective, it can be said it's open core, and it's pretty fair, and acceptable in my case, but writing 100% Open Source* (*: 100% of the open part of the software stack, exceptions apply) is not fair game. It's misleading.
- ddlsmurf 11mo agoSeems a bunch are angry about this, honestly, 100% of what they made/control is open source was a good enough bar for me. Specially if all closed components are optional. I value the flexibility of being able to use or not even closed stuff. It's unclear to me what the issue is, false advertisement ? This is as good as it gets for things like this, maybe the "100%" was indelicate, but I wouldn't go so far as misleading. I can also understand the hardware companies, history has shown that the vast majority of industry actors have a purely parasitical relation to open source, and have no qualms copying/stealing IP.
- bayindirh 11mo agoPersonally, I'm not angry. On the contrary, I'm pretty neutral about closed-source, optional add-ons. I started playing/working with computers pretty early, and the current state is an utopia when compared to olden times in terms of Free and Open Source software (OTOH, both Free Software and Open Source is under heavy attack because of many reasons I won't enter here). What bothers me is "100%" part of the open source claim. I personally like the Debian model a lot. It's DFSG compliant by default, and if non-free software is needed, it's attainable. Debian is "as Free as you want, as closed as you need". I see, new Pebble follows the same model, and it's perfectly fine, but branding it as 100% Open Source is not. I'll not discuss hardware companies. It's a can of worms that doesn't belong to that reply. Let's say while I understand some of their reservations, these reservation doesn't change that they're greedy and selfish (beyond acceptable limits).
- gf000 11mo agoAbove a certain complexity, there is basically no 100% open-source hardware out there. Like none of the Pinephone, Librem, Framework laptops are "open-source" to the bone.
- squarefoot 11mo agoGiven how easy is to put and keep hidden malware into devices, governments should demand openness in that field as well. By "putting malware" I don't mean script kiddies in their moms basement but malware/spyware planted by design, which is extremely easy to do if you're the manufacturer, extremely easy to demand/force if you're the government above that manufacturer, and extremely hard to detect if you're a different user in a different country under a government that didn't demand full openness. I know it's impossible as business rules go, but ideally it shouldn't be.
- RobotToaster 11mo agoEvery intel processor has a closed source IME, which is probably a NSA backdoor.
- aallaall 11mo agoIsn’t minix open source?
- RobotToaster 11mo agoYes, the original is, but it's under a permissive license so Intel don't have to release the modified source code of their version.
- graemep 11mo agoThe thing is governments are the people doing it, and most governments want to be able to put backdoors in more badly than they want other governments to not put backdoors in.
- cncjchsue7 11mo ago
- pjc50 11mo agoIncidentally, this is one reason why there's not so much open source hardware out there: people get pedantic about it and apply gradually more unreasonable levels of requirement, rather than accepting partially or substantially open source solutions.
- 123pie123 11mo agoThe reason why people get "pedantic" about this stuff, is due the ability in the future to get screwed over when the priority blob owner start to charge money or other pull other license crap
- aallaall 11mo agoEnshittification. Open source is a valuable guarantee against that.
- user3939382 11mo agoRead Reflections on Trusting Trust to understand why having little bits of binary blobs sprinkled all over your compute arch is actually a major problem. Just because it’s a hard problem doesn’t mean we’re gonna pretend it’s fine.
- 0xEF 11mo agoPDF link for those that are curious: https://www.cs.cmu.edu/~rdriley/487/papers/Thompson_1984_ReflectionsonTrustingTrust.pdf https://www.cs.cmu.edu/~rdriley/487/papers/Thompson_1984_Ref... The general sentiment is that you cannot trust code you did not write yourself and that we need to be able to trust the person who did, but you can form your own conclusions about how that fits into the modern tech landscape.
- kchr 11mo agoOne of the points made in that paper is that you can't even trust the compiler, even if you write the code yourself. I think this is one of the stronger points as it shows you it is unfeasible to require everybody to audit all source code before running it. Be pragmatic, know your threat model, decide who you trust and move on with more important things in your life. Full disclosure: am free software advocate.
- Wowfunhappy 11mo agoThey said 100% of Pebble Watch software. The binary blobs are other people's software.
- aallaall 11mo agoClosed verilog I can accept. But in general firmware is also software, for example it has become quite popular in the recent years to execute firmware on an embedded riscv cpu. And move more and more functionality to that kind of firmware.
- Vexs 11mo agoI don't really know that this is avoidable without buckets of work and probably legal issues on behalf of core's (or anyone's) engineers- it's really just something that plagues hardware in general. Hell, lots of sensors/etc these days are running fairly complicated software that's totally opaque.
- bytesandbits 11mo agoBy that reasoning the linux kernel is also not open source. Be reasonable.
- deleted 11mo ago[deleted]
- npteljes 11mo agoAnd, for this reason, different entities ship different versions of the Linux kernel (and system) as well. For example: https://en.wikipedia.org/wiki/Trisquel https://en.wikipedia.org/wiki/Trisquel The simple statement that it's not 100% open source is not an attack on the effort. It needs to be said, because the blog entry's title is "Pebble Watch Software Is Now 100% Open Source".
- jrmg 11mo agoHardware and software are fungible. Do you demand circuit schematics? Hardware description language source code for all the ICs? Does it matter if it’s a FPGA vs a custom IC? What about CAD files for the industrial design - some of that is ‘functional’ (camera lenses and antennas being obvious examples). If you don’t require hardware description language source or circuit schematics, does your position change if it’s a microcontroller with firmware? The functionality could be outwardly identical to a fully ‘hardware’ IC or FPGA, down to pinout and timing (see, for example, the many projects ‘cloning’ obsolete and unavailable custom ICs with microcontrollers in the retrocomputing field).
- deleted 11mo ago[deleted]