Live data from Hacker News

TracePrivately – open-source sample app using Apple's contact tracing framework

github.com

41–45 of 45 posts

Re: TracePrivately – open-source sample app using Apple's contact tracing framework

#41
post #9

Earlier quoted context omitted.

A few private companies are allergic to GPL; there's no particular reason governments would be.

> A few private companies are allergic to GPL; there's no particular reason governments would be. Many large, public (as in publicly-traded) companies also have an aversion to GPL. Most enterprises that have a technology review board or legal review of software dependencies (aka any regulated industry) have a dislike for GPL in customer-facing services.

"private companies" as opposed to "government-run", not as opposed to "publicly traded".

And no, "most" enterprises aren't averse to GPL code for usage. They certainly will have policies about making their own software depend on it, but that's different from simply using it, which was the original topic here.

Re: TracePrivately – open-source sample app using Apple's contact tracing framework

#42
post #13

I don't quite understand why Apple and Google are releasing an API instead of a single system application. This is going to create a gigantic mess as governments with limited software development competence slowly release incompatible and partially broken applications, while Apple and Google could just deploy a single solution via a system update. Also, it's much easier to make it mandatory if it's a system app (and…

I was thinking the same thing, are we going to have a mess of contact tracing apps and services with the similar analogy of the incompatibility with differing messaging protocols?

> Also, it's much easier to make it mandatory if it's a system app (and obviously it needs to be mandatory to be useful).

That might work in the case of Apple, Google Pixel and (some) Android One devices where the firmware is (often) manufacturer controlled. Outside of the Google Play Services approach good luck trying to deploy a new Android feature to all the devices out there.

Re: TracePrivately – open-source sample app using Apple's contact tracing framework

#43
post #13

I don't quite understand why Apple and Google are releasing an API instead of a single system application. This is going to create a gigantic mess as governments with limited software development competence slowly release incompatible and partially broken applications, while Apple and Google could just deploy a single solution via a system update. Also, it's much easier to make it mandatory if it's a system app (and…

I don't understand it either but that doesn't lead me to leap to a conclusion that Apple's and Google's expert cryptographers and system architects don't know what they are doing. I instead blame my own current ignorance, and look forward to gaining more understanding.

But yes as a user, personally I'd prefer to use and trust an app supplied by my OS provider, mandatory or not, built in to the OS or not (and plenty of Apple apps are optional after-the-fact downloads, so it need not be a forced download unless there are reasons for that that overcome all the negatives).

Re: TracePrivately – open-source sample app using Apple's contact tracing framework

#44
I actually turned off auto update on my iPhone and Apple Watch. I'm going to wait for people on here, and other security experts, to analyze the binaries to see what the new stuff really does prior to installing it.

Apple has screwed up software updates before (eg. AirPods Pro[1]).

1. https://medium.com/macoclock/we-need-to-talk-about-airpods-p...

Re: TracePrivately – open-source sample app using Apple's contact tracing framework

#45
post #9

Earlier quoted context omitted.

> A few private companies are allergic to GPL; there's no particular reason governments would be. Many large, public (as in publicly-traded) companies also have an aversion to GPL. Most enterprises that have a technology review board or legal review of software dependencies (aka any regulated industry) have a dislike for GPL in customer-facing services.

"private companies" as opposed to "government-run", not as opposed to "publicly traded". And no, "most" enterprises aren't averse to GPL code for usage . They certainly will have policies about making their own software depend on it, but that's different from simply using it, which was the original topic here.

Gotcha, seems like we just have different definitions of private and using.
Post reply on HN