Live data from Hacker News

Trisquel GNU/Linux

trisquel.info

71–80 of 86 posts

Re: Trisquel GNU/Linux

#71
post #65

Earlier quoted context omitted.

Just pre-fund with kickstarter or similar.

Or through a light taxation system for biggest companies. If say .01% of the revenue of the 100 biggest IT corporations was distributed yearly among the most useful projects, those in need of maintainers etc, the developers living in bad economical conditions etc. the problem would probably cease to exist for thousands of developers while those being taxed would barely notice some missing change from their pockets. N…

Who defines the most useful projects? How do new projects get their start?

I think a simpler and less revolutionary route would be to simplify the registration of open source projects to be able receive tax exempt donations. That’d be a massive boost with only a minor change to the tax code.

Re: Trisquel GNU/Linux

#72
post #38

Earlier quoted context omitted.

How is it “extreme”? The point of the FSF is to foster and support free software. Supporting non-free software is literally the opposite of their mission. The guy you replied to is being childish and exaggerating. The FSF isn’t some extremist organization out to destroy people who dare to write or use closed source software. Do they refuse to include proprietary software in their distributions/projects? Obviously. Ar…

I think you may have too rosy a view of the FSF. Step back and think about what the FSF has done for FOSS in the last 10 years. When people say "I don't want to get into a licensing debate" who do you think they are talking about? > Are they going to tell you to go fuck yourself because you refuse to release the source code to your app? Probably not (I guess if you’re an asshole about it, someone might) I can cite an…

How much of what Mozilla and Google are writing is released under GPL?

Re: Trisquel GNU/Linux

#73
post #2

Why Trisquel? > entirely free software > teach users to value and protect their freedom > no binary-only firmware for wireless cards or proprietary drivers for AMD/ATI and NVIDIA graphics cards are included

Do they have version that doesn't mimic windows? I do understand that it is intended to take on board as many former windows users as possible but honestly some people including me are getting sick just by looking at something that even slightly reminds it ... I wish the project the best, please understand.

I don't think it's mimicking Windows, but you can always install a different GNU/Linux-libre distro, such as Arch-based Parabola or GNU Guix

Re: Trisquel GNU/Linux

#74

Earlier quoted context omitted.

>Plus, the current policies of the FSF are completely inconsistent, out of touch with the reality of computing systems today, and based on arbitrary rules that end up reducing user freedom instead of increasing it (e.g. how they promote devices with firmware ROMs - which you do not have the freedom to inspect, modify, or replace with a free version - while deriding devices with firmware RAM and a blob, where you do h…

> unless everything is absolutely transparent including microcode and hardware it is not acceptable as freedom respecting solution. Where do you draw the line? Is it sufficient if all code executing on a Turing-complete CPU is open? Does the CPU itself need to be open RTL? What about the synthesis process to turn that into a netlist and then into a chip design, does that need to be open? What about the standard cell…

>Freedom isn't the answer. Freedom was a noble idea from the computing paradigm of the 80s that just doesn't work any more as an absolute goal.

I wish to ask you not to portrait reasonable expectations of certain freedoms as some kind of an absolute. It is reasonable to expect your computer to be under your full control and not under control of someone else.

Freedom isn't the answer? Then what we are talking about? You have certain freedom of controlling your own mind and your own body. Freedom isn't the answer there too? The way I see it computer is becoming extension of your mind/body and as such owner should have at least the same level of control over it.

>Where do you draw the line?

It is unclear for me from your post whether you are talking about 'line respecting freedom' or 'line acceptable at the moment because freedom is 80s dream and irrelevant now because we've learned to accept any shit by calling it progress' Let's assume it's the first one because the second one I think you've described.

The question about where you draw the line is a very hard one and I do not think I can or should answer it alone. Discussion is required to define it.

In short it is something along the lines I've described already - every part of the computer design should be transparent and open for inspection to call it a freedom respecting solution.

>Is it sufficient if all code executing on a Turing-complete CPU is open? Does the CPU itself need to be open RTL? What about the synthesis process to turn that into a netlist and then into a chip design, does that need to be open? What about the standard cell library from the chip foundry, does that need to be open? Then what about the actual foundry process - do you need documentation on how the chips are produced? What about all the raw materials? What about the machines used to make the chips? Basically all answers there are Yes. Again what it means in practice should be discussed but basically any reasonable person including you and anyone with your level of expertise should be able to say honestly that, yes indeed this computer is under full control of the owner and the owner only. It has no backdoor or ability to be remotely updated without the owner intention.

I think your question implies that there is one line to draw. If so then it is the one I've described above but I think it is better to draw a few lines with levels of freedom provided and mark every computer produced accordingly.

>Nuance matters. Absolutist positions don't work any more.

Do they? Wouldn't you say that Apple have a full control over their Mac M1? You are working with it so you should know exactly the answer to that question. With all their compromises the main door is under their full control and they hold they key to themselves, correct me if I am wrong.

If you ask today in practical terms what is a reasonable line to draw, let's draw it where Apple have done it except the key should be in the hands of the owner, not Apple. How about that? Would it satisfy? Actually you are the first one to ask about a proper line to draw but you should be honest about. You should be able to say "yes, this computer is under my full control" just like now Apple can say it's under their control and they guard it very carefully so perhaps they have figured where the line is.

Re: Trisquel GNU/Linux

#75

Earlier quoted context omitted.

> unless everything is absolutely transparent including microcode and hardware it is not acceptable as freedom respecting solution. Where do you draw the line? Is it sufficient if all code executing on a Turing-complete CPU is open? Does the CPU itself need to be open RTL? What about the synthesis process to turn that into a netlist and then into a chip design, does that need to be open? What about the standard cell…

>Freedom isn't the answer. Freedom was a noble idea from the computing paradigm of the 80s that just doesn't work any more as an absolute goal. I wish to ask you not to portrait reasonable expectations of certain freedoms as some kind of an absolute. It is reasonable to expect your computer to be under your full control and not under control of someone else. Freedom isn't the answer? Then what we are talking about? Y…

> Again what it means in practice should be discussed but basically any reasonable person including you and anyone with your level of expertise should be able to say honestly that, yes indeed this computer is under full control of the owner and the owner only. It has no backdoor or ability to be remotely updated without the owner intention.

That, unfortunately, is impossible for silicon platforms. Documentation can't prove the lack of a backdoor, because you can't prove that the chip you got is what was documented (even if you have a scanning electron microscope and a lot of time, that's a destructive process and you can't prove that the chip you'll actually use is the same as the one you analyzed).

This is a common fallacy espoused by those who demand ultimate freedom: that along with it comes full trust and control. It doesn't. Because physics. Chips aren't software.

Instead, you should be investing in one of these:

https://www.crowdsupply.com/sutajio-kosagi/precursor

Precursor makes the quite solid argument that general purpose FPGA backdoors are infeasible (because it's an intractable problem for arbitrary logic circuits) and therefore it is a device that can be trusted even if the silicon can't. Of course, then you'd better be happy running all your computing on a 100MHz RISC-V.

> Do they? Wouldn't you say that Apple have a full control over their Mac M1?

Given that it's sitting on my desk, it's running my own OS, there is no Apple code running on it with full system access by the time it boots into Linux, and Apple can't remotely update it (the bootloader doesn't even have USB support let alone networking, and there is no resident supervisor like there is on Intel machines, Android phones, etc), no, I'm pretty sure I have full control over it for all normal practical purposes.

In fact I'm much more sure about that than I would be with the laptops the FSF peddles as "respects your freedom"; last time I looked at the schematics for one of those, it had over a half dozen chips running secret blobs, and at least two or three of them had full access to all system RAM via a DMA capable bus. You'd have to be insane to trust that over an M1, which is designed to sandbox all coprocessors from the main CPU and RAM via IOMMUs, such that even if all firmware is backdoored it can't take over your main CPU.

Is it perfect? No, if I wipe the Flash without a backup the recovery process requires phoning home to Apple, since that's how it re-downloads things like certificates, calibration data, MAC addresses, etc (though at least we have open source tools that implement all that and you can run on Linux). But that's a repairability/longevity argument; while the thing has a proper bootloader installed, it isn't phoning home anywhere during normal operation.

Then again, for those FSF laptops, if you wipe Flash you need a soldering iron to recover them, so from that point of view the M1s are a lot more robust, since you can recover them via USB from any other random machine, no disassembly required.

This is why nuance matters. Absolutist positions like the FSF's and yours lead to less trust, because reality isn't absolute, it's nuanced. If you want absolute trust, you can pre-order a Precursor today. If you want a laptop class machine you can reasonably trust not to be backdoored, you'd do much better getting an M1 than the obsolete ThinkPads the FSF certified, which don't even have modern security features like IOMMUs and have known blobs with full control over the computer. I can't prove the M1 doesn't have any secret silicon backdoors but at least the design is clearly intended to prevent firmware ones, and there are no known bypasses, which can't be said of those ThinkPads.

> If you ask today in practical terms what is a reasonable line to draw, let's draw it where Apple have done it except the key should be in the hands of the owner, not Apple. How about that? Would it satisfy?

That is a very difficult question to answer. Would hacker me like a device where I can burn in my own iBoot signing keys? Sure. Devices where you can do that kind of thing exist; you can get SoC dev kits (e.g. I know the Nvidia Tegra X1 devkit can do it) where you can burn your own keys permanently and become the trust authority, and I wouldn't be surprised if it can be done on open designs like Novena, though it may not be documented. Is it a good idea for the general public? No. The problem is building a platform that is "fully user controlled" (whatever that means, usually "everything that runs after the Boot ROM") means delegating an immense amount of responsibility to the user, which is at odds with security paradigms that attempt to protect you from higher level attackers. Can you build a signing and key storage facility on par with the security of Apple's? Highly unlikely. So yes, you might have full control over the device, but you're getting less security against other attackers as a result. The reason Apple can build a user friendly yet secure device is because they control the early boot stages, so they can build the complex mechanisms on top that make that possible; full control, secure, user friendly: pick two.

Can Apple sell me a backdoored M1? Yes. But the entire point of their design is that nobody else can backdoor it for me. Not even you, if you get ahold of it. Their user-controlled secureboot delegation requires authenticating using your machine owner credentials to install your own kernel, after having asserted physical presence, unless you wipe the whole machine and start fresh. And even then you can't backdoor the recovery mode used to do this, so you couldn't backdoor someone using the Asahi Linux installer since it runs from that secure recovery. Their design is such that compromised third party chips can't compromise the main system. You can't backdoor the motherboard and replace the flash. Etc. You have to trust Apple to an extent, but in exchange you're much safer from threats from other parties than with other machines. You can buy a second hand M1 Mac and be very confident it's every bit as secure as one straight from the Apple store. That is something that cannot be said for the vast majority of consumer hardware.

Those are all worthy things to have. Is it worth the trade-off of letting Apple control the early boot stages? I think it is for many people. Is it possible to build a system with identical security guarantees that is simultaneously fully user controlled and doesn't require every user to have a secure lab, HSM cluster, etc to achieve the same level of threat resistance? I don't know. Maybe. I invite you to try to come up with such a design; it would be very interesting to hear about it :)

The good news is that security is composable. That means that, for example, if I use LUKS encryption from Linux on top of the native hardware keystore and encryption, I know I have top notch security against third party attackers and I know I'm safe from Apple helping some government entity to crack it if they seize it, since they won't be able to break the second encryption layer (and I'm very confident they don't have any remote access backdoors for normal usage, so I'm safe from post facto active targeting since they just have no way of doing that when the thing is running my own OS).

And the fact that I just wrote a wall of text about this is, again, evidence that nuance matters. You can't reduce any of this to "do I control the signing keys" or "does it have any blobs". I'm sure some people will read my story and decide they don't want to touch the M1 machines with a 10 foot pole, and would rather get a Novena or a Pinebook or whatever. And others will be very excited and want to get one ASAP, because it's massively more trustable than any recent Intel or AMD machine by design. And the only way you can decide is if you know the facts and how the machine works and what the threats are and who you need to trust and so on and so forth. A "Respects your Freedom" sticker tells you nothing.

Re: Trisquel GNU/Linux

#76
post #72

Earlier quoted context omitted.

I think you may have too rosy a view of the FSF. Step back and think about what the FSF has done for FOSS in the last 10 years. When people say "I don't want to get into a licensing debate" who do you think they are talking about? > Are they going to tell you to go fuck yourself because you refuse to release the source code to your app? Probably not (I guess if you’re an asshole about it, someone might) I can cite an…

How much of what Mozilla and Google are writing is released under GPL?

I guess I don't understand your point. Are you saying non-GPL open source licenses (Apache, MPL2, MIT) aren't FOSS? That seems like a pretty extreme position.

Re: Trisquel GNU/Linux

#77
post #10

Earlier quoted context omitted.

Hardware manufacturers can ideologically target the libre flavor, but in practice it is next to impossible to deliver. Drivers are built to address specific hardware features. As features grow, so do system complexities and software calls. Every OEM addresses a feature in a specific problem-solving paradigm. Trying to unify most hardware under a standard set of function & procedure calls cannot be fathomed. A real wo…

I don't follow; linux-libre still has drivers; nobody's saying you can't write per-device drivers, just that the whole of the code to run it should be FOSS.

I think I failed to explain the crucial part of the argument so let me try from another viewpoint: OEM like NVIDIA do not make their drivers FOSS because it makes device-specific features and improvements known. To make something work well for the device as well as FOSS, they would have to publish the software instructions specifics. That sort of things enables competition to better understand their silicon and thats exactly what they do not want.

In an ideal world, libre is fine and serves all devices well. But with commercial interest in play and so many differentiation in features, it is hard to imagine libre drivers being able to cater to all device optimally

Re: Trisquel GNU/Linux

#78
post #72

Earlier quoted context omitted.

How much of what Mozilla and Google are writing is released under GPL?

I guess I don't understand your point. Are you saying non-GPL open source licenses (Apache, MPL2, MIT) aren't FOSS? That seems like a pretty extreme position.

> That seems like a pretty extreme position.

I think you're confusing some terms. "Free software" != "Open source software". (although MPL2 is a free software license, like GPL/LGPL).

Ever heard the saying "free as in freedom"? That's what "free software" is about. It has nothing to do with money or pricing. A license like Apache or MIT is not a free software license because it does not provide any freedom to end users.

Look at Android for example: there's something called AOSP on the internet, which contains some code that you can download. However, that code is not the same code that's powering the phone you have in your pocket. Since AOSP is licensed under Apache, Samsung is able to fork it, add/remove features, inject all the spyware they want etc, and then sell it to you as a binary blob without giving you the source code.

If Android were GPL, they'd be obligated to release the source code that's powering their devices. This would be a huge win for consumers, and a huge win for the entire tech industry at large, since everyone can benefit from the development efforts Samsung put in. If Samsung wants to keep that code secret, then they simply must avoid using free (as in freedom) software.

It worries me that devs today don't seem to get this. The tech industry would be 99.999% owned and operated by Microsoft today if not for the efforts of the FSF and Stallman.

More/better info: https://www.fsf.org/resources/what-is-fs

Re: Trisquel GNU/Linux

#79
post #38

Earlier quoted context omitted.

How is it “extreme”? The point of the FSF is to foster and support free software. Supporting non-free software is literally the opposite of their mission. The guy you replied to is being childish and exaggerating. The FSF isn’t some extremist organization out to destroy people who dare to write or use closed source software. Do they refuse to include proprietary software in their distributions/projects? Obviously. Ar…

> The FSF and Stallman are the only assets for FOSS. The FSF doesn't even support the use of the term "FOSS". They support the idea of libre software. The broader "open source" community is much larger than the FSF or RMS. The GPL is the third most popular FOSS license.

> The FSF doesn't even support the use of the term "FOSS".

Personally I use "FOSS" as shorthand for FSF's definition of "free software". If that's misleading, then I guess I should stop using it. Would you happen to have a link to a blog post or something about this?

> They support the idea of libre software. The broader "open source" community is much larger than the FSF or RMS.

I'm not talking about the "open source" community. There's a difference between free software and open source software.

It's obvious that I'm not talking about "open source" here, otherwise it'd suggest that I think FSF and RMS are the only ones writing open source software. I can't even imagine a situation where someone could be led to believe that, especially on HN.

> The GPL is the third most popular FOSS license.

Regardless of what you mean by "FOSS" here, how is that statistic relevant to the discussion?

Re: Trisquel GNU/Linux

#80

Earlier quoted context omitted.

>Freedom isn't the answer. Freedom was a noble idea from the computing paradigm of the 80s that just doesn't work any more as an absolute goal. I wish to ask you not to portrait reasonable expectations of certain freedoms as some kind of an absolute. It is reasonable to expect your computer to be under your full control and not under control of someone else. Freedom isn't the answer? Then what we are talking about? Y…

> Again what it means in practice should be discussed but basically any reasonable person including you and anyone with your level of expertise should be able to say honestly that, yes indeed this computer is under full control of the owner and the owner only. It has no backdoor or ability to be remotely updated without the owner intention. That, unfortunately, is impossible for silicon platforms. Documentation can't…

I do not know if you ever lived under dictatorship but the most popular argument of dictatorship is 'There are Nuances' , 'Be wise, nothing is absolute' and 'Freedom is not the answer'. I would not wish to blame you for anything because I value your efforts and the worst thing I could assume: it's your honest mistake.

Of course nothing is absolute but it doesn't mean that we should be that wise to miss the main point with all nuances and be fooled like idiots to accept things that should never be acceptable. Nuances do matter but only after the main thing is defined and protected.

I am sorry but in that case with all your expertise knowledge and nuances you seem to miss the main thing which is a tendency to close every platform and make it controlled remotely or brick it otherwise stripping the owner from the computer respecting freedom completely.

Apple computers were able to boot from the usb now they don't. I am aware about nuances but you cannot boot in DFU something other then their thing unless they permit it, isnt' it?

Could they do it differently? I presume yes. They choose it to be exactly this way and they choose it to be this way just to keep control because they perfectly know where line is . They keep the very control they could and should give to the owner if he chooses so but they didn't and they didn't because the whole tendency is to make people slowly accept the idea of closed/remotely controlled platform.

Their iphone/ipads are closed completely just because they have found a way to make it acceptable by people. They can't do it with Macs ... for now. They are not idiots and they understand that if they close Macs today they will meet strong opposition with the chance that people would reject to use it completely. And they made a lot of efforts using 'nuances' tactics to make sure that one who wish to fool himself would find a way to do it by saying - look it is not perfect but they are trying to keep it open and there are nuances. Nevertheless they have managed to push things that never perceived as the norm like phoning home for some parameters, this 'secure' (for them) bootloader that owner doesn't have a choice to turn off or this DFU requiring another Mac to boot. What the F is that? Why can't I boot from usb without other Mac? Why there should be some hacking to achieve something like that? Could they do it differently? Of course they could but they didn't and they didn't on purpose because 'frog boiling' is in progress.

>But that's a repairability/longevity argument; while the thing has a proper bootloader installed, it isn't phoning home anywhere during normal operation.

Today, what about tomorrow?

>Can Apple sell me a backdoored M1? Yes. But the entire point of their design is that nobody else can backdoor it for me. Not even you, if you get ahold of it. Their user-controlled secureboot delegation requires authenticating using your machine owner credentials to install your own kernel, after having asserted physical presence, unless you wipe the whole machine and start fresh. And even then you can't backdoor the recovery mode used to do this, so you couldn't backdoor someone using the Asahi Linux installer since it runs from that secure recovery. Their design is such that compromised third party chips can't compromise the main system. You can't backdoor the motherboard and replace the flash. Etc. You have to trust Apple to an extent,

My concerns about third party in general and third party chips are much less then my concerns about Apple itself. Why should one afraid third party less then Apple? What is the difference? Apple as far as I am concerned IS third party as much as another third party is because they can communicate between them and they do such things and Apple is known to accept shit from dictatorships.

"You have to trust Apple to an extent" NO, I do not have to. We do not have to. They should be obligated to deliver something that doesn't require that after their product is shipped. We should demand from suppliers to supply something that doesn't require their control and it should be illegal if they introduce something like that.Only then they could be potentially "trusted" to the certain extent.

>Can you build a signing and key storage facility on par with the security of Apple's? Highly unlikely. So yes, you might have full control over the device, but you're getting less security against other attackers as a result.

What if I prefer that and not some 'big daddy' caring about my safety more then I do? Freedom does matter and it IS the answer and it comes with responsibility. THIS is the main issue here. THIS is what separates society with responsible citizens from the society with 'naive children' who wish to trade their freedom for 'safety' resulting in loosing both.

Post reply on HN