4 ms·
One reason that I do not use my iPad as a productivity device is that I do not understand the security model. I would need a terminal app with ssh capabilies. B
by founderling 11y ago
One reason that I do not use my iPad as a productivity device is that I do not understand the security model. I would need a terminal app with ssh capabilies. But how do I know if the maker of the app is sending my SSH credentials to his server or something? Does apple check that? Is the process how apple prevents this documented somewhere?
At the moment, I only use software that is in the debian repos. At least I understand the security model of debian to some degree. And it is open and verifiable to everybody.
I wonder why the Linux distros are so slow to adapt to tablets.
- amyjess 11y ago> I wonder why the Linux distros are so slow to adapt to tablets. Tight hardware integration. Most tablets have locked-down bootloaders that make it difficult to replace the default OS. You've also pretty much got to start over when it comes to drivers. Linux used to have terrible driver support back in the day -- I remember carefully choosing motherboards and laptops because I wanted a Linux-compatible chipset -- those days are over on the desktop (except for a few esoteric peripherals), but it's going to hit hard on mobile. Imagine booting your tablet onto Linux but not being able to use the GPS or some other piece of connectivity. And then, you've got to take all your established GUI code and throw it in the trash and start over. Nothing from the desktop world is going to be usable in a touch environment. The big desktop environments all have heritage going back to the late '90s. You can still see some KDE 1 and GNOME 1 layouts used in their modern KDE Applications and GNOME 3 descendants, and the stuff that was replaced was replaced one app at a time. Throwing everything out and starting over is harder than it looks. But, still, we've got some attempts at this. Look at Ubuntu Touch, Sailfish, and Plasma Active, for example. In the past, we had Maemo 5, which was amazing, and it was everything I wanted in a touch-based Linux distro, but the only company that had pockets deep enough to fund its development turned away from the platform, and the closest thing it has to a successor (Sailfish) has been a disappointment. Also, even that required the distro developer be an established hardware manufacturer: Maemo 5 couldn't have worked if it was just an OS that could only be installed on third-party devices.
- gtk40 11y agoI'm running Ubuntu on my Windows tablet (Acer Iconia W700) now, typing from it in fact. Interestingly enough, I had no driver issues (everything as far as I can tell worked perfectly with a fresh Ubuntu install), but I've had more software issues with touch support. I thought Ubuntu was supposed to be better with that, and while multitouch gestures seem to work with Unity, there are very few places where they are implemented.
- walterbell 11y agoThe Jolla/Sailfish Linux (with Android compatibility) tablet is on the way, http://techcrunch.com/2015/03/03/jolla-tablet-hands-on/ http://techcrunch.com/2015/03/03/jolla-tablet-hands-on/, still available via 5X-oversubscribed crowdfunding for $249, https://www.indiegogo.com/projects/jolla-tablet-world-s-first-crowdsourced-tablet#/story https://www.indiegogo.com/projects/jolla-tablet-world-s-firs...
- mark_l_watson 11y agoI use the Prompt app that provides a SSH enabled terminal. I don't lose any sleep worrying that the app might not be secure, but maybe it should. I also like Juice on my Android. Being able to SSH from my mobile devices is a useful feature.
- gress 11y agoDo you actually read all the sources of all the software you use?
- zimpenfish 11y agoYou'd have to read the entire stack down through the compiler, the libraries, the kernel, and eventually the (whatever is the equivalent of the BIOS these days). To quote "Reflections on Trusting Trust", The moral is obvious. You can't trust code that you did not totally create yourself. (Especially code from companies that employ people like me.) No amount of source-level verification or scrutiny will protect you from using untrusted code. https://www.ece.cmu.edu/~ganger/712.fall02/papers/p761-thompson.pdf https://www.ece.cmu.edu/~ganger/712.fall02/papers/p761-thomp...
- vbezhenar 11y ago> But how do I know if the maker of the app is sending my SSH credentials to his server or something? You have to ask the maker to open source his app and you have to check whether he built app from the same sources (probably with some repeatable build scheme). It's not something I ever saw, so you'll have some things to research, but it's not something impossible. > Does apple check that? Is the process how apple prevents this documented somewhere? They probably do have some kind of firewall monitoring network requests of the app when they check it. But of course they don't read sources, they don't reverse-engineer the app. So their abilities are pretty limited. You shouldn't trust that any app from the AppStore is guaranteed not to be harmful. iOS has a sandbox model which should limit app abilities to read data from other apps. But you shouldn't trust this sandbox model too. Every iOS version was jailbroken which means that crackers can find vulnerabilities to elevate privileges. Overall AppStore is safer than more liberal proprietary app sources. You are not likely to catch some wide-targeted malware there. But it's not a panacea.
- new299 11y agoThere are open source ssh clients (I wrote one called hterm a while back). So you could compile it yourself. I agree that being able to check signatures would be nice though.